MAL-LEG-PP-001Version 1.0·Effective 16 May 2025·Nigeria & United Kingdom

Privacy Policy

Ornia Autonomous Infant Monitoring Ecosystem — Ornia Limited (formerly Rova HealthTech Limited)

This Privacy Policy governs the collection, processing, storage, and transfer of personal data including special category health data relating to infants and caregivers. It has been prepared in compliance with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), the UK General Data Protection Regulation (UK GDPR), and the Data Protection Act 2018.

NDPA 2023NDPR 2019UK GDPRDPA 2018ISO 27001 aligned

1. Identity of the Data Controller

Ornia Limited (formerly Rova HealthTech Limited) is the data controller responsible for your personal data.

Registered Trading Name:Ornia Limited
Former Name:Rova HealthTech Limited
Primary Business Address:Lagos, Federal Republic of Nigeria
Official Website:rovatechltd.co.uk
Data Controller Email:info@rovatechltd.co.uk
Data Protection Enquiries:info@rovatechltd.co.uk

2. Scope and Application

This Privacy Policy applies to all personal data we collect, process, store, or transfer in connection with:

  • The Ornia autonomous infant monitoring platform, including all hardware components (the Sensor Coin, Guardian Hub), associated firmware, the Ornia mobile application and web platform, and cloud infrastructure;
  • The Ornia Limited corporate website and all web-based interfaces operated by us;
  • Clinical research, product evaluation, and pilot programmes conducted in partnership with healthcare institutions;
  • Communications, enquiries, investor relations, and commercial partnerships;
  • Employment applications, contractor agreements, and supplier relationships.

3. Categories of Personal Data We Collect

3.1 Caregiver and Account Data

  • Full name, email address, telephone number, and postal address;
  • Account credentials (processed in encrypted form; we do not store plaintext passwords);
  • Device identifiers, IP addresses, and session data;
  • Billing information (processed exclusively through certified third-party payment processors; we do not store raw card data);
  • Communication preferences and consent records.

3.2 Infant Physiological and Health Data

⚠ SPECIAL CATEGORY DATA

This data constitutes Special Category Data under Article 9 of the UK GDPR and sensitive personal data under the NDPA 2023. We apply the highest available standard of protection.

  • Blood oxygen saturation (SpO₂), including melanin-compensated optical measurements;
  • Heart rate, heart rate variability (HRV), and cardiac rhythm indicators;
  • Respiratory rate, breathing pattern, and apnoea event data;
  • Skin temperature and core temperature estimates;
  • Body position, movement, and orientation via inertial measurement;
  • Ambient environmental parameters including temperature, humidity, and CO₂ concentration;
  • Alert trigger records, threshold breach events, and caregiver response timestamps;
  • Device diagnostics, battery state, signal integrity metrics, and firmware event logs.

A critical design principle: Primary safety logic and alert generation execute locally on the device. We do not transfer real-time physiological data to external servers as a prerequisite for safety functionality.

3.3 Data We Do Not Collect

Ornia Limited does not collect or require:

  • Racial, ethnic, or national origin data as a condition of product use;
  • Religious or philosophical beliefs;
  • Sexual orientation or gender identity (beyond voluntary profile fields);
  • Financial account credentials or banking passwords.

5. Purposes of Processing

We process personal data for the following specific, explicit, and legitimate purposes:

  • Providing, operating, and improving the Ornia monitoring platform and associated applications;
  • Delivering real-time safety alerts, escalation notifications, and caregiver communications;
  • Managing user accounts, authentication, and platform access;
  • Conducting product validation, safety testing, and firmware update delivery;
  • Supporting clinical evaluations, institutional pilots, and academic research partnerships;
  • Complying with medical device regulatory obligations under applicable law;
  • Responding to support queries, incident reports, and complaints;
  • Conducting internal analytics for platform safety improvement (on anonymised or aggregated data only, wherever possible).

We do not sell personal data. We never have and we never will.

We do not use your personal data or infant health data for advertising, targeted marketing profiling, or sale to third parties.

6. Special Protections for Children's Data

The Ornia platform is designed exclusively for the monitoring of infants and young children. All physiological data collected relates to minors. We observe the following mandatory protections:

  • Infant physiological data is never processed or stored in identifiable form unless strictly necessary for clinical continuity, caregiver service delivery, or emergency response;
  • Aggregated and anonymised infant data used for research cannot be re-linked to any individual infant through our systems by design;
  • Caregiver consent is the sole authorised gateway to infant data collection. No data collection commences without verified, explicit caregiver consent;
  • Infant data is not shared with commercial third parties for any purpose whatsoever;
  • Any request by a government authority or law enforcement body to access infant health data will be resisted to the full extent permitted by law. We will notify affected caregivers of such requests wherever legally permissible;
  • Retention of individually identifiable infant health data does not extend beyond the period necessary for the care relationship or research engagement.

7. Data Sharing and Disclosure

7.1 Authorised Recipients

We do not sell, rent, or trade personal data. We may share data only with the following categories of authorised recipients:

  • Certified cloud infrastructure providers operating under data processing agreements compliant with UK GDPR Article 28 and NDPA data processor obligations;
  • Healthcare professionals and clinical institutions where the caregiver has explicitly enrolled the infant in a monitored clinical programme;
  • Regulatory bodies including the NDPC, ICO, NAFDAC, and MHRA, as required by law;
  • Professional legal and financial advisors bound by professional secrecy obligations;
  • Emergency services, where disclosure is necessary to protect the immediate life or safety of an infant.

7.2 What We Will Never Do

  • Sell, license, or otherwise transfer personal data or infant health data to advertising networks or data brokers;
  • Share data with any party not subject to binding data protection obligations;
  • Grant law enforcement or government agencies access to user data without a lawful, properly issued court order;
  • Disclose data in response to informal requests, threats, or coercion of any kind.

8. International Data Transfers

Where personal data is transferred outside the country of collection, we ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the UK ICO or the European Commission, as applicable;
  • Adequacy decisions recognising the destination country as providing equivalent data protection;
  • Data processing agreements incorporating obligations no less stringent than those imposed on us by applicable law;
  • Transfer Impact Assessments (TIAs) conducted and documented for each transfer mechanism.

No infant physiological data is transferred to any jurisdiction that has not satisfied our internal transfer risk assessment. Where no adequate safeguard can be established, the transfer will not proceed.

9. Data Security

We implement technical and organisational security measures proportionate to the sensitivity of the data we process:

🔐 End-to-end encryption

TLS 1.3 or equivalent for all physiological data in transit

💾 Encryption at rest

AES-256 or equivalent standards for infant health data

👤 Access controls

Role-based access ensuring only authorised personnel access identifiable personal data

🔑 MFA

Multi-factor authentication for all administrative and clinical data system access

🔍 Penetration testing

Regular independent vulnerability assessments and security testing

📋 Incident response

Formal procedures with mandatory notification timelines compliant with NDPA Section 40 and UK GDPR Article 33

10. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected:

Data CategoryRetention Period
Active Account Data5 years after account closure
Infant Physiological Data90 days after account closure (identifiable); longer with caregiver consent for research
Clinical Research Data10–15 years following conclusion of the research programme
Device Diagnostic & Safety Logs7 years for regulatory compliance and product liability purposes
Marketing Communications DataUntil consent withdrawn or 3 years of inactivity, whichever is earlier

11. Your Rights as a Data Subject

Subject to applicable law, you have the following rights in relation to your personal data:

Right of Access

Request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data where we no longer have a lawful basis to retain it.

Right to Restriction

Request that we limit how we use your data in certain circumstances.

Right to Portability

Where processing is based on consent or contract, request your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Withdraw consent at any time without affecting the lawfulness of prior processing or the continued availability of core safety functionality.

Automated Decision-Making

We do not make decisions solely by automated means that produce significant effects. Human clinical oversight is maintained in all alert escalation pathways.

To exercise any of these rights, contact us at info@rovatechltd.co.uk. We will respond within 30 days.

If unsatisfied with our response, you may lodge a complaint with:

Nigeria: Nigeria Data Protection Commission (NDPC)

UK: Information Commissioner's Office (ICO)

12. Regulatory and Clinical Compliance

The Ornia ecosystem is designed for regulatory submission as a medical device. Our data processing activities are structured to be compatible with:

ISO 13485IEC 62304ISO 14971NAFDAC Medical Devices RegulationUK Medical Devices Regulations 2002EU MDR 2017/745ICH E6 (R2) GCP

13. Cookies and Tracking Technologies

Our websites and web applications use cookies for the following purposes:

Strictly NecessaryRequired for platform functionality, authentication, and security. These cannot be disabled without preventing core service delivery.
Performance & AnalyticsUsed to understand how users interact with our platform, on an aggregated basis. We use privacy-respecting analytics configurations that minimise data collection.
FunctionalUsed to remember your preferences and settings.

We do not use advertising cookies, behavioural tracking technologies, or third-party marketing pixels on platforms that process infant health data.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Where we make material changes, we will notify registered users by email and post an updated Policy with a revised effective date. We will not apply material changes retrospectively to data collected under a prior version of this Policy without obtaining fresh consent where required.

15. Contact and Data Protection Enquiries

All data protection queries, subject access requests, consent withdrawals, and regulatory correspondence should be directed to:

Ornia Limited (formerly Rova HealthTech Limited)

Email: info@rovatechltd.co.uk

Website: rovatechltd.co.uk

Data Protection Lead: Raphael G.U. Eriemo, Founder and Director

Document Reference: MAL-LEG-PP-001 · Version 1.0 · Effective Date: 16 May 2025

Jurisdiction: Federal Republic of Nigeria | United Kingdom

This Privacy Policy is a legally binding document of Ornia Limited. — The guardian that never sleeps.