Introduction and Data Controller Identity
Amplifai Health is the data controller for all personal data processed through the NUR Platform (My NUR, NUR Scanner, and NUR HUB). This Privacy Statement describes what data we collect, why we collect it, how we use it, who we share it with, and your rights as a data subject.
This document should be read alongside the NUR Platform Terms of Use and Informed Consent. For data subject requests or privacy questions, contact: support@amplifaihealth.com.
Data We Collect
Identity and Health Profile
Name, email address, date of birth, biological sex, height, and weight.
Clinical Indicators
Self-reported chronic conditions (e.g. diabetes, arthritis, prior injuries), activity levels, recent lifestyle factors (e.g. caffeine intake, physiotherapy sessions, sun exposure), and pain location, intensity, and duration submitted through the digital body map.
Thermal and Biometric Data
Thermal asymmetry patterns, contralateral temperature gradients, COMPASS zone history, and individual thermal baseline data built from longitudinal scan records (a minimum of 8 qualifying scans are required to establish a personal baseline).
Wearable Data (Optional)
Heart rate and heart rate variability (HRV), sleep quality and duration metrics, activity metrics (steps, movement, exercise duration), acute:chronic workload ratio (ACWR), and recovery or stress indicators. Collected only when wearable integration is enabled by the user.
Clinical Records
Injury event records, return-to-play phase status, practitioner notes entered by staff, intervention records, and RTP clearance decisions (including manual override records).
Technical and Device Data
Push notification tokens, application version, session logs, and API call timestamps.
Consent Records
Timestamped, version-tagged acceptance log recording every acceptance of this Privacy Statement and the Terms of Use.
How We Collect Your Data
Direct Collection
You provide data directly when completing your health questionnaire, demographic profile, and body map within the My NUR application.
Automated Collection
The NUR Scanner captures thermal image data automatically during scanning sessions. Wearable data is retrieved from your connected wearable provider via a third-party integration service on a scheduled automated pull.
Staff Entry
Your coaching and practitioner team enters injury events, practitioner notes, intervention records, and RTP clearance decisions through NUR HUB.
QR Session Linking
A Session ID or QR code links your mobile health profile to a specific physical NUR Scanner instance during a scan session. The QR token is single-use and expires immediately after the session is claimed.
Lawful Basis for Processing
Saudi Arabia — PDPL
Explicit consent is the primary lawful basis for processing your health and biometric data under the Personal Data Protection Law (Royal Decree M/19). Legitimate interest applies to operational security logging and immutable audit trail maintenance.
Canada — PIPEDA
Your meaningful express consent is obtained before collecting sensitive health data. Implied consent applies to operational and technical data required to deliver the service. Contractual necessity applies to account management data.
United States
Processing is consent-based. The NUR Platform is a wellness and athletic performance monitoring tool. Amplifai Health is not a HIPAA covered entity or business associate, and therefore HIPAA does not govern NUR Platform data. State-specific rights and obligations are detailed in Appendix C.
Image Processing and Purging Policy
Standard visible-spectrum images are captured by the NUR Scanner solely to perform body-contour mapping and ensure that thermal data is correctly aligned with your anatomy.
These images are automatically and permanently purged upon completion of the scan analysis. They are never stored in your account, are not accessible to Amplifai Health staff after the session ends, and cannot be retrieved once the session is complete.
The derived output — your thermal asymmetry data — is retained in accordance with the data retention schedule in §10.
COMPASS Score Data Processing and AI
Your COMPASS score is computed by NURAI, an AI/ML pipeline that combines your wearable-derived Systemic Readiness score and your Thermal Asymmetry Index into a score between 0 and 100 and a zone assignment.
The exact version of each AI/ML component used to produce your assessment is stored alongside your result, enabling full reproducibility audits and retrospective investigation. You may request an explanation of how a specific score was derived by contacting support@amplifaihealth.com.
No solely automated decision with legal or significantly effect is made by the platform — all COMPASS outputs are decision-support inputs reviewed by qualified coaching and practitioner staff before any training or practitioner action is taken.
How We Use Your Data
We use your personal data to:
- Generate your daily readiness assessment and COMPASS zone assignment;
- Power Return-to-Play phase monitoring and clearance workflows;
- Build and continuously update your individual thermal baseline;
- Deliver push notifications and practitioner alerts to you and your practitioner team;
- Provide your coaching and medical staff with access to your athlete health dashboard through NUR HUB;
- Maintain platform security, access logs, and compliance records.
We do not use your personal data for advertising, marketing profiling, or resale to third parties under any circumstances.
Data Sharing and Disclosure
Within Your Organisation
Athlete health data is visible to coaching and medical staff members at your club or organisation, scoped strictly by role-based access controls (RBAC). Staff may only access data for athletes within their assigned organisation.
Trusted Service Providers
We share data with the following service providers, all of whom are contractually bound by data processing agreements:
- Google Cloud Platform — cloud infrastructure and data services
- Spike — wearable data integration
- Firebase (Google) — mobile notification services
Legal Obligations
We may disclose your data where required by applicable law, court order, or regulatory authority.
No Sale
We do not sell your personal health data or wearable data to any third party, including advertisers, data brokers, or research organisations.
Third-Party Wearable Providers
When you connect a wearable device, data from that device is retrieved through the Spike API and may transit Spike's infrastructure. You remain subject to your wearable device manufacturer's own privacy policy and terms of service. Amplifai Health does not control how wearable device manufacturers collect, store, or process data outside the NUR Platform.
You may revoke wearable integration at any time through the app settings. Revocation stops future data pulls but does not automatically delete previously retrieved wearable metrics from the NUR Platform. Submit a deletion request to support@amplifaihealth.com to remove historical wearable data.
Data Retention Schedule
| Data Type | Retention Period | Basis |
|---|---|---|
| Thermal asymmetry outputs | Account + 3 years | Longitudinal baseline integrity |
| COMPASS history | Account + 3 years | Clinical audit |
| Clinical notes | Account + 7 years | Professional records compliance |
| RTP workflow records | Account + 7 years | Clinical audit |
| Wearable metrics | Account + 2 years | Wellness insight continuity |
| Consent records | Permanent | Legal compliance |
| QR session tokens | Expired immediately post-use | Session security |
| Visible scan images | Purged at session end | Privacy by design |
| Notification logs | 90 days | Operational |
All retention periods calculated from account deletion or closure where "Account" is specified.
Your Rights as a Data Subject
Regardless of your jurisdiction, you have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Correction: Request correction of inaccurate or incomplete data.
- Right to Deletion: Request deletion of your personal data, subject to retention obligations. Clinical notes and consent records must be retained for compliance purposes and cannot be deleted.
- Right to Data Portability: Receive a structured, machine-readable export of your health profile and COMPASS history.
- Right to Withdraw Consent: Withdraw consent for specific processing activities at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Right to Object: Object to specific processing activities.
To exercise any of these rights, contact support@amplifaihealth.com or use the data request portal in the My NUR application. We will respond within 30 calendar days.
Minors and Parental Consent
User accounts for individuals under 18 years of age require verified parental or guardian consent, obtained and recorded by the club or organisation administrator before the account is activated. Accounts for users under 13 years of age are not permitted on the platform.
Parents and guardians may exercise data subject rights on behalf of their child by contacting support@amplifaihealth.com. Upon reaching the age of majority, the athlete assumes independent consent responsibility and will be prompted to review and re-accept this Privacy Statement and the Terms of Use.
Security Measures
We implement the following technical and organisational safeguards to protect your personal data:
- Encryption at rest for all health and personal data
- Encrypted data transmission for all API communications
- Passwordless multi-factor authentication — no stored passwords
- Device-level authentication for NUR Scanner hardware
- Single-use session tokens for device linking
- Role-based access control (RBAC) with strict organisation-level data isolation
- Append-only audit records for practitioner notes
- AI algorithm version tracking enabling full assessment reproducibility
- Ephemeral session data with automatic expiry
- API rate limiting
- MDM device provisioning for NUR Scanner hardware
Cross-Border Data Transfers
Your personal data is processed on cloud infrastructure, which may involve transfers of data across borders. Such transfers are governed by the applicable cross-border transfer mechanisms for your jurisdiction.
- Saudi Arabia: Amplifai Health complies with data localisation requirements under the PDPL for Saudi-resident user data. Cross-border transfers are conducted only where an approved mechanism applies or NDMO approval has been obtained.
- Canada: Transfers outside Canada are conducted under Standard Contractual Clauses (SCCs) or equivalent approved mechanisms under PIPEDA.
- United States: Transfers are governed by applicable US state law and our data processing agreements with service providers.
Consent Management and Versioning
Every acceptance of this Privacy Statement and the Terms of Use is recorded with an exact timestamp and the specific version identifier of the documents accepted, forming a permanent, immutable consent audit trail.
When this document is materially updated, you will be prompted to review and re-accept before continuing to use the platform. Your prior consent records are permanently preserved. You may request a copy of your consent history by contacting support@amplifaihealth.com.
Biometric Data (United States)
In US states where thermal asymmetry data collected by the NUR Scanner qualifies as biometric information under applicable state law — including Illinois (Biometric Information Privacy Act, 740 ILCS 14), Texas (Capture or Use of Biometric Identifier Act), and Washington (My Health MY Data Act) — Amplifai Health:
- Collects biometric data only with your informed written consent prior to collection;
- Does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information;
- Retains biometric data only for as long as required to fulfil the stated purpose or as permitted by applicable law;
- Permanently destroys biometric data when the original purpose has been fulfilled, or within three years of your last interaction with the platform, whichever occurs first.
Full details of our biometric data handling, retention schedule, and destruction policy are set out in Appendix C.
Changes to This Privacy Statement
We may update this Privacy Statement from time to time. Material changes — those that affect your rights, how your data is used, or the categories of data collected — will be notified to you by email to your registered address. Continued use of the platform following the effective date of any update constitutes acceptance of the revised Privacy Statement.
Non-material changes (such as updated contact details or clarifications) will be notified by email to your registered address with at least 14 days' notice. The effective date and version number at the top of this document are updated with each revision.
Contact and Complaints
Privacy team: support@amplifaihealth.com
To file a complaint with your applicable supervisory authority:
- Saudi Arabia: National Data Management Office (NDMO) — ndmo.gov.sa
- Canada (Federal): Office of the Privacy Commissioner of Canada (OPC) — priv.gc.ca
- Canada (Quebec): Commission d'accès à l'information — cai.quebec.ca
- United States: Applicable State Attorney General's office, or the Federal Trade Commission (FTC) — ftc.gov
Appendices A · B · C
Saudi Arabia — PDPL Supplement
This appendix sets out the specific rights and obligations applicable to users in the Kingdom of Saudi Arabia under the Personal Data Protection Law (Royal Decree M/19, as amended) enforced by the National Data Management Office (NDMO).
Sensitive Data Classification
Health data collected by the NUR Platform — including thermal scan data, COMPASS scores, wearable health metrics, and practitioner records — is classified as sensitive personal data under the PDPL. Your explicit, specific consent is required before this data is collected and processed. You may withdraw consent at any time.
Your Rights Under the PDPL
- Right to be informed of the purposes for which your data is collected;
- Right to access your personal data;
- Right to correct inaccurate data;
- Right to request erasure of your data (subject to lawful retention requirements);
- Right to restriction of processing in specified circumstances.
Data Localisation
Personal data of Saudi-resident users is processed in compliance with PDPL data localisation requirements. Cross-border transfers are conducted only where an approved mechanism applies or specific NDMO approval has been obtained.
Minor Age Threshold
The applicable minor consent threshold under the PDPL is conservatively treated as 18 years of age. Parental or guardian consent is required for all users under 18 in Saudi-deployed instances, pending confirmation by Saudi legal counsel.
Breach Notification
In the event of a personal data breach, Amplifai Health will notify the NDMO within 72 hours of becoming aware of the breach, and will notify affected individuals without undue delay where the breach poses a high risk to their rights and freedoms.
Complaints
To file a complaint with the NDMO: ndmo.gov.sa
Canada — PIPEDA and Quebec Law 25 Supplement
This appendix sets out the specific rights and obligations applicable to users in Canada under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, including Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25 / Bill 64).
Accountability
Amplifai Health designates a Privacy Officer responsible for compliance with PIPEDA and applicable provincial laws. Contact: support@amplifaihealth.com.
Consent
Meaningful express consent is obtained before collecting sensitive health data. The purposes for which data is collected are clearly identified at the point of collection. You may withdraw consent at any time, subject to legal or contractual restrictions.
Breach Notification
Amplifai Health will notify the Office of the Privacy Commissioner of Canada (OPC) and affected individuals of any breach of security safeguards that creates a real risk of significant harm, as required under PIPEDA. Breach notification records are maintained for a minimum of 24 months.
Quebec Law 25 Rights
Quebec residents have the following additional rights:
- Right to Data Portability: Receive a copy of your personal data in a structured, commonly-used, technological format;
- Right to De-indexing: Request that personal information that could cause harm be de-indexed from any technology that makes it publicly available;
- Privacy Impact Assessments: Amplifai Health conducts Privacy Impact Assessments (PIAs) for new systems or technologies that process personal information.
Commercial Communications (CASL)
Commercial electronic messages are sent only with your express consent. Every commercial message includes a clear and functional unsubscribe mechanism.
Complaints
- Federal: Office of the Privacy Commissioner of Canada — priv.gc.ca
- Quebec: Commission d'accès à l'information — cai.quebec.ca
United States — State Law Supplement
This appendix sets out the specific rights and obligations applicable to users in the United States under applicable federal and state privacy laws.
California — CCPA / CPRA
California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to know what personal information is collected, used, shared, or sold;
- Right to request deletion of personal information;
- Right to correct inaccurate personal information;
- Right to opt out of the sale or sharing of personal information (note: Amplifai Health does not sell personal data);
- Right to limit the use and disclosure of sensitive personal information, including health data and biometric data.
This Privacy Statement serves as our annual privacy notice to California residents. To exercise your rights, contact support@amplifaihealth.com.
Biometric Data — Illinois BIPA (740 ILCS 14)
For Illinois residents, thermal asymmetry patterns derived from NUR Scanner sessions constitute biometric identifiers under the Biometric Information Privacy Act. Amplifai Health:
- Collects biometric identifiers only with your informed written consent prior to collection;
- Does not sell, lease, trade, or profit from biometric identifiers;
- Retains biometric identifiers only for the duration of the stated purpose and destroys them within 3 years of your last interaction with the platform;
- Has a publicly available retention and destruction schedule (see §10 and this appendix).
You have a private right of action under BIPA for violations of these obligations.
Biometric Data — Texas CUBI and Washington My Health MY Data Act
Equivalent consent, retention, and destruction obligations apply to residents of Texas and Washington. Amplifai Health does not sell biometric identifiers. Biometric data is destroyed when the original purpose has been fulfilled or within three years of last interaction, whichever is earlier.
Children — COPPA
The NUR Platform is not directed at children under 13. Users under 13 years of age are not permitted on the platform. Parental or guardian consent is required for users aged 13–17 in states where applicable law imposes this requirement.
HIPAA — Non-Applicability
The NUR Platform is a wellness and athletic performance monitoring tool used by sports clubs and their athletes. Amplifai Health is not a HIPAA covered entity or business associate as defined under the Health Insurance Portability and Accountability Act, and therefore HIPAA does not govern NUR Platform data.
Complaints
To file a complaint: applicable State Attorney General's office, or the Federal Trade Commission (FTC) — ftc.gov