Consumer Health Data Privacy Notice

Last Updated: July 14, 2026

1. Scope

This Notice supplements our Privacy Policy and describes consumer health data practices that may be subject to Washington's My Health My Data Act and similar laws. "Consumer health data" means personal information linked or reasonably linkable to a person that identifies or permits an inference about physical or mental health, health services, or health status.

2. Categories We May Process

  • Allergies, medical conditions, medications, care instructions, and emergency notes.
  • Accessibility, disability, special-needs, mobility, and accommodation information.
  • Mental-health, counseling, prayer, pastoral-care, or similar support information.
  • Dates of birth, age, photographs, guardian relationships, and authorized pickup records.
  • Precise or approximate location used for a check-in, safety, or attendance feature when the user or customer enables it.
  • Inferences about health status derived from information submitted to an AI, search, reporting, care, or workflow feature at a customer's direction.

AIO does not require every category for every Service. Customers decide which optional fields and features to use and must limit collection to what is reasonably necessary and lawful.

3. Sources

Consumer health data may come from:

  • You, a parent or guardian, or another person acting with authority.
  • A customer, staff member, care provider, account administrator, or authorized user.
  • A device, check-in station, mobile app, form, message, file, or recording.
  • An integration or provider that a customer or user directs AIO to connect.
  • Inferences generated from information submitted to requested features.

4. Why We Process It

At a customer's direction, AIO may process consumer health data to:

  • Provide child check-in, authorized pickup, attendance, labeling, safety, and care workflows.
  • Display relevant allergy, medical, accommodation, or emergency information to authorized users.
  • Provide requested pastoral-care, prayer, counseling, communications, reporting, or collaboration features.
  • Provide a location-enabled feature requested by the user or customer.
  • Secure the Services, prevent fraud or abuse, provide support, and comply with law.
  • Carry out another purpose for which the consumer gave valid consent.

AIO does not process consumer health data for purposes materially different from those described here and in the customer's notice unless legally permitted or the required consent is obtained.

5. How It May Be Disclosed

Depending on customer configuration, the categories in Section 2 may be disclosed to the following categories of recipients only for the purposes described above:

  • The customer and its authorized staff, volunteers, administrators, guardians, care teams, or other users according to permissions and workflows.
  • Hosting, storage, security, communications, support, and other processors that help AIO provide the requested Services under contract.
  • AI providers or integrations only when a customer or authorized user directs or configures the Service to send the relevant information to that provider.
  • Authorities or affected parties when disclosure is required or legally permitted.
  • Other recipients at the consumer's direction or with legally valid consent.

AIO does not share consumer health data with an affiliate for the affiliate's independent marketing or advertising. AIO does not sell consumer health data. If that practice changes, AIO will obtain a separate, valid authorization before any sale as required by law.

6. Your Rights

Subject to applicable law and verification, you may have the right to confirm whether consumer health data is collected, shared, or sold; access the data and a list of recipients; withdraw consent for future collection or sharing; request deletion; and appeal a refusal to act.

Submit a request through Your Privacy Choices or email legal@aio.church. You do not need to create a new account. We or the controlling customer may request information reasonably necessary to authenticate you and the request. Where AIO is only a processor, we will route the request to the controlling customer or act on its instructions.

We will respond without undue delay and within the period required by law. Some backup deletions may take longer where law expressly permits. If an appeal is denied, we will provide the explanation and regulator-contact method required by applicable law.

7. Consent and Customer Responsibilities

Customers must provide all required notices and obtain any consent required to collect or share consumer health data before submitting it to AIO. Consent to collect and consent to share must be separate where law requires. A customer may not direct AIO to process consumer health data inconsistently with its published notice, consent, or agreement with AIO.

Customers must not use AIO to geofence a health-care facility for unlawful identification, tracking, collection, messaging, or advertising. Customers must restrict access to people who need the information for the disclosed purpose.

8. Retention and Security

AIO retains consumer health data according to the controlling customer's instructions and only as long as reasonably necessary for the disclosed purpose, security, legal compliance, and permitted backup cycles. AIO uses safeguards designed for the nature and sensitivity of the information, but no system can guarantee absolute security.

9. Changes to This Notice

We may update this Notice prospectively. If a change would add a category of consumer health data or a materially different purpose requiring consent, the controlling entity must provide the required notice and obtain consent before that new collection or processing begins.

10. Contact