People first Technology that follows
We started HumanTec.lk with one belief — that every person in Sri Lanka deserves access to professional healthcare, no matter where they are or what time it is.
PRIVACY POLICY & DATA PROTECTION NOTICE
Face Data & AI Health Analysis Disclosure
See Section 3 for our complete privacy commitments regarding facial image processing, non-diagnostic age estimation, and AWS retention guarantees.
Welcome to HumanTec.lk (referred to as "the Company," "we," "us," or "our"). We act as the Data Controller for the personal information processed through our e-commerce platform and our mobile app ecosystem. Your privacy and the confidentiality of your family’s health data are sacred to us. This policy explains how we collect, use, store, and protect your information.
Quick Navigation
1. Legal Basis for Data Processing
Under Section 5 of the PDPA, we process your personal and sensitive data only when a valid legal ground exists. These include:
Explicit Consent
- When you explicitly opt-in to let us manage your care profile, health records, or utilize optional Face Health Analysis.
Contractual Necessity
- To deliver products purchased online (e.g., Drmini Robo) or facilitate telemedicine sessions via Mydoctor.
Vital Interests
- Processing triggered during emergency SOS alerts to safeguard human life.
Legal Compliance
- Fulfilling statutory obligations under Sri Lankan medical and financial laws.
2. Types of Data We Collect
To provide a fully unified healthcare and wellness ecosystem, we process data through two main streams:
A. Via the Online Web Store (General Personal Data)
When purchasing wellness devices, products, or subscriptions, we collect:
- Identity Data: Full name, delivery address, billing address, and phone numbers.
- Financial Data: Credit/debit card information and payment details (processed securely via compliant gateways such as PayHere and CyberSource).
- Interaction Data: Order history, device telemetry (if applicable), and browser cookies.
B. Via the Humantec Mobile App (Personal & Special Categories of Data)
Because our application offers comprehensive health-related services, we process Personal and Special Categories of Data (health data) under strict statutory safeguards:
- Professional Care & Booking: Full name, phone number, address, and service-related preferences for booking Nurses, Caretakers, and Drivers.
- Interactive AI Voice Coach: Voice inputs, recordings, and transcripts generated during AI-guided voice wellness coaching sessions.
- Face Health Analysis: Voluntary front-facing facial photographs and derived non-biometric wellness metrics (detailed in Section 3).
- Personal Health Records (PHR) Manager: Uploaded medical reports, clinical test results, prescriptions, health summaries, and user-categorized health records.
- Prescription Upload & Product Ordering: Uploaded prescription images/files, ordering records, delivery addresses, and payment receipts.
3. Face Data and AI Health Analysis
HumanTec provides an AI-powered health and wellness estimation feature allowing users to gain non-diagnostic health scoring and lifestyle insights based on voluntary facial image submission, health questionnaire responses, and Personal Health Records (PHR). We are strictly committed to protecting your privacy and handling all facial information with high security and transparency.
1. What Face Data We Collect and Retain
When you voluntarily utilize our Face Health Analysis feature:
- Original Facial Image: The user-captured front-facing photograph is uploaded to our secure cloud storage.
- Facial Measurements & Processing: Our automated image processing algorithm (InsightFace) temporarily scans facial features exclusively to estimate perceived facial age (apparent age). We do NOT collect, generate, or retain facial biometric templates, mathematical face embeddings, or unique facial identifiers used for biometric identity verification.
- Derived Results & Metadata: We retain derived non-biometric numerical outputs, specifically:
- Estimated facial age
- Calculated biological age and holistic wellness score
- Categorized wellness metrics (Gut, Stress, Sleep, and Skin wellness scores)
- Risk level indicator (Low / Medium / High) and lifestyle recommendations
- Associated processing request IDs and timestamps
2. Purpose of Collection and How AI Processes Face Data
- Purpose: Face data is collected strictly and solely to estimate perceived facial age for generating personalized wellness scores, health risk evaluations, and lifestyle suggestions. It is purely for informational and wellness purposes and does not constitute medical diagnosis.
- AI Processing Flow:
- The uploaded facial image is processed by an automated facial age detection service within our secure cloud infrastructure to compute an estimated age value.
- The raw image is never sent to our generative AI model. Only the resulting numeric estimated age, together with the user's questionnaire responses and selected PHR records, is securely passed to Amazon Bedrock (Generative AI Runtime) to generate the wellness report and lifestyle guidance.
3. Third-Party Sharing and Names of Processors
- No Sale or Commercial Transfer: HumanTec never sells, rents, leases, or trades facial images, biometric data, or derived health analysis results to any third parties, advertisers, or data brokers.
- Authorized Infrastructure & Cloud Processors: Facial data is processed and hosted exclusively using dedicated enterprise cloud infrastructure provided by Amazon Web Services (AWS) (Amazon Web Services, Inc.):
- Amazon S3: Secure object storage for uploaded image files.
- Amazon DynamoDB: Managed NoSQL database storing numeric health scores, age calculations, and analysis metadata.
- Amazon Bedrock: Cloud-hosted foundation model runtime used to generate textual health scores and recommendations (receives numeric age and text data only; does not receive raw face images).
4. Storage Location and Hosting Region
All facial images and derived health data are securely stored and hosted within Amazon Web Services (AWS) cloud facilities in the Asia Pacific / US East (`us-east-1`) region(s). All data processing remains restricted to HumanTec's private, isolated cloud tenancy.
5. Data Retention Period
- Original Face Images (Amazon S3): Uploaded face images are retained only for the duration required to process the analysis and maintain the user's active health assessment history, or for a maximum default retention period of 30 to 90 days, unless deleted earlier by the user.
- Derived Health Scores & Metadata (Amazon DynamoDB): Calculated numerical health scores, wellness summaries, and recommendations are linked to your user account and retained while your account remains active, enabling you to view historical progress.
- Once an account is deleted or a deletion request is completed, both original images and derived results are permanently removed from production databases.
6. How Users Can Request Deletion and Turnaround Time
- In-App Deletion: Users may initiate complete account and associated data deletion at any time directly within the HumanTec mobile application by navigating to Profile / Settings > Account > Delete Account.
- Direct Deletion Request: Users can request immediate deletion of their facial photos, health records, or entire account by emailing our dedicated privacy and support team at info@humantec.lk.
- Deletion Turnaround Time:
- In-app requests immediately revoke account access, invalidate active authentication tokens, and mark data for deletion in real-time.
- Complete permanent deletion of all stored images and database records across production cloud systems is finalized within 24 to 72 hours of the request (and no later than 30 business days).
7. Data in Backups
- Routine encrypted disaster recovery backups containing snapshot data are retained on a rolling cycle for up to 30 days.
- Once deleted from production systems, data remains inaccessible in backups and will be completely overwritten and permanently eradicated in accordance with our regular automated backup rotation cycle.
8. Prohibited Uses (No Tracking, Advertising, or AI Training)
We strictly enforce the following privacy guarantees:
- No Identity Recognition: Face data is never used to recognize, identify, or track individuals across different apps, websites, or physical locations.
- No Advertising or Marketing: Face data is never used, shared, or analyzed for targeted advertising, promotional marketing, or user profiling.
- No AI Model Training: We do NOT use, sell, or allow third parties to use your facial photos, facial measurements, or health analyses to train, retrain, or improve general-purpose AI or machine learning models.
9. Security Protections for Transmission and Storage
We implement industry-standard administrative, physical, and technical safeguards:
- In-Transit Security: All face image uploads and API transmissions are encrypted using Transport Layer Security (TLS 1.2 / TLS 1.3 / HTTPS).
- At-Rest Security: All stored facial files in Amazon S3 and analytical records in Amazon DynamoDB are encrypted using AES-256 server-side encryption.
- Access Control: Access to raw images and databases is strictly restricted using AWS Identity and Access Management (IAM) least-privilege principles and protected by multi-factor authentication.
4. How We Use Your Data
We strictly limit the processing of data to the specified, explicit, and proportionate purpose for which it was gathered:
Purpose Boundaries
- To facilitate the booking and scheduling of certified health professionals (Nurses, Caretakers, and specialized Drivers).
- To power the interactive AI voice coaching system and generate personalized wellness recommendations.
- To estimate perceived facial age and compute non-diagnostic wellness insights upon voluntary user submission.
- To store, organize, and retrieve your medical history safely within your encrypted Personal Health Records (PHR) cabinet.
- To process prescription uploads, execute product orders, and complete transactions securely via premium payment gateways.
5. Data Sharing with Third Parties & Service Providers
We do not sell your personal data. We only share the minimum necessary information with third parties to facilitate our services:
A. Service Booking Fulfillment
- Nurses & Caretakers: Your name, contact number, age, relevant medical preferences, and service location/address are shared with assigned health professionals to facilitate care delivery.
- Specialized Drivers: Your name, contact number, and pickup/drop-off locations are shared to facilitate medical transportation.
B. Payment Gateways & Secure APIs
- Financial transactions are securely routed through certified payment aggregators (PayHere, CyberSource). Your card credentials never pass through or get stored on our servers.
C. AI Voice Processing & Infrastructure
- AI Voice Coach: Microphone inputs and voice command streams are processed temporarily to recognize speech and deliver real-time voice feedback. Voice recordings are processed securely under strict privacy protocols and are never used for general model training or shared with unauthorized third parties.
D. Cloud Infrastructure & AI Processing (AWS)
- Amazon Web Services: Dedicated cloud hosting (Amazon S3, Amazon DynamoDB, Amazon Bedrock) for secure file storage, analytical databases, and foundation model inference under strict tenant isolation. Facial images are never sent to external foundation models.
6. Data Retention Limits
In accordance with Section 9 of the PDPA, we do not store your data longer than necessary for its intended purpose.
Retention Thresholds
- Store & Billing Records: Kept for as long as your account remains active or to meet local financial/taxation auditing laws.
- Face Images & Analysis: Uploaded front-facing face images are retained in secure S3 storage for a maximum of 30 to 90 days. Numerical wellness scores and metadata in DynamoDB are retained while your account remains active and purged permanently upon account deletion.
- App Health Records & Transcripts: Personal Health Records (PHR) files, prescription uploads, and voice coaching session logs are maintained for ongoing wellness continuity. Upon account deletion, all clinical, personal, and voice data will be permanently erased after a 30-day grace period, unless retention is required by mandatory Sri Lankan healthcare laws.
7. Data Security & Integrity
We apply industry-standard technical and organizational security measures to protect your information against unauthorized access, loss, or destruction:
Security Safeguards
- End-to-End Encryption & In-Transit Security: Applied to all medical reports, prescriptions, files uploaded to the Personal Health Records (PHR) Manager, face images, and voice data streams using TLS 1.2 / TLS 1.3 encryption.
- At-Rest Storage Encryption: Stored files and databases are encrypted using AES-256 server-side encryption.
- Access Controls: Restricted, credentialed access ensures that only you and certified care personnel whom you explicitly authorize can view or access booking/medical files.
- Breach Notification: In the highly unlikely event of a data breach, we are legally mandated to notify the Data Protection Authority of Sri Lanka and affected individuals without undue delay.
8. Your Statutory Rights as a Data Subject
Under Part II of the Sri Lankan PDPA, you possess powerful rights regarding your personal and sensitive info:
Data Subject Rights
- Right of Access: You can request a copy of all your personal data, face analysis metrics, voice coaching logs, booking history, and health records held in our systems.
- Right to Rectification: You can instantly complete or correct inaccurate information across your profile, bookings, or PHR records.
- Right to Withdraw Consent: You may withdraw consent for data processing at any time (e.g., opting out of facial health assessments, stopping AI voice coaching sessions, or turning off location permissions).
- Right to Erasure ("Right to be Forgotten"): You have the right to request total deletion of your profile, facial images, uploaded documents, and voice transcripts if the processing lacks a lawful basis or is no longer necessary.
9. Cross-Border Data Transfers
Your personal data is predominantly processed and secured within Sri Lanka and dedicated AWS regional infrastructure (such as Asia Pacific / US East us-east-1). Any external server routing or cloud backup storage (including secure hosting for AI wellness evaluation and coaching) completely conforms to cross-border rules enforced by the Personal Data Protection Act of Sri Lanka and international data security standards, ensuring adequate data protection agreements are structurally instituted.
10. Contact Our Data Protection Officer (DPO)
If you have any questions, concerns, or wish to file a request regarding your data privacy under the PDPA Act or our Face Data Policy, please contact our designated DPO:
DPO Channels
- Email: info@humantec.lk
- Address: No. 14/2 D.S. Senanayake Mawatha, Borella, Colombo, Sri Lanka.
- Help Desk: Accessible directly inside the app via My Help center.

Give them the care they deserve, even when you can't be there.
Your loved ones' safety shouldn't be a source of worry. With one-tap SOS alerts, 24/7 doctor consultations, and a built-in pharmacy, we provide a complete safety net for your parents, right from your phone.
Try a Consultation