BEEMS

Privacy Policy & PDPA Notice

Operator / Data Controller: Rainbow Care Pte. Ltd. (“Rainbow Care“, “we“, “us“, “our“), a company incorporated in Singapore (UEN 200822869G), with its registered office at 3007 Ubi Rd 1, #02-410, Singapore 408701.
Service: the BEEMS in-bed monitoring system, comprising the BEEMS sensor device(s), the BEEMS mobile applications (iOS and Android), the BEEMS web application, and related cloud services (collectively, the “Service“).

Effective date: 31 August 2026

This Privacy Policy explains how we collect, use, disclose, store and protect personal data in connection with the Service, and constitutes our notice and (where applicable) request for consent under the Singapore Personal Data Protection Act 2012 (“PDPA”). It should be read together with our Terms & Conditions, Hardware Support & Replacement Policy and Disclaimers.

By creating an account, installing or using a BEEMS device, or otherwise using the Service, you acknowledge that you have read and understood this Policy.

1. Important note about health-related and vulnerable-person data

1.1 Bed Users

The Service processes supported in-bed activity and related information for individuals registered with the Service (each a “Bed User”). Bed Users may include elderly persons or other individuals receiving care.
Depending on the supported features available, the Service may process information relating to a Bed User’s:

  • bed presence;
  • bed-exit activity;
  • movement;
  • time in bed;
  • supported heart-rate readings;
  • room and environmental conditions;
  • alert activity; and
  • other supported in-bed information.

Because some of this information may relate to an individual’s health, behaviour, routine or care needs, we apply safeguards appropriate to the sensitivity of the information and the circumstances in which the Service is used.

1.2 Providing information about another person

Where you provide personal data about another individual — for example, where you register a parent, relative or care recipient as a Bed User, or invite a Caregiver or family member to a household — you confirm that you have the appropriate authority and, where required, consent from that individual or their legal representative to:

  • provide their personal data to us;
  • register them with the Service;
  • permit the relevant supported monitoring; and
  • allow their information to be made available to authorised users in accordance with this Policy.

Account holders and household administrators are responsible for informing Bed Users and other individuals about the monitoring arrangement and how their personal data will be handled.

1.3 BEEMS is not a medical service

BEEMS is an assistive care monitoring service designed to support Caregiver awareness.It is not a medical device, does not provide medical advice or diagnosis, and is not an emergency response service.See our Terms & Conditions for further information.

2. The personal data we collect

2.1 Account and contact data

When you register for or use the Service, we may collect:

  • full name;
  • username or account identifier;
  • email address;
  • mobile or telephone number;
  • postal, delivery or facility address;
  • gender, where voluntarily provided or supported;
  • password credentials, stored only in securely hashed form;
  • household membership;
  • your role within the Service, such as household owner, administrator or Caregiver;
  • invitation and account-verification information; and
  • other account information you provide to us.

We do not store passwords in readable form.

2.2 Data about Bed Users

For each Bed User registered with the Service, we may collect:

  • name or identifying label;
  • household;
  • room;
  • bed assignment;
  • monitoring mat or Device assignment;
  • authorised Caregivers and administrators associated with the Bed User;
  • dates on which access or assignments are created or changed; and
  • information required to operate the Bed User’s monitoring setup.

The Service does not ordinarily require a Bed User’s NRIC/FIN, formal medical records or detailed medical diagnosis information for normal monitoring use.

Please do not enter such information into free-text fields unless it is reasonably necessary for the relevant purpose.

Separate documentation may be requested in limited circumstances described in Section 2.7.

2.3 Supported in-bed activity and sensor data

The BEEMS monitoring mat is placed on top of the mattress and underneath the bedsheet.Together with the connected BEEMS Device, it generates and processes supported sensor information associated with the Bed User's in-bed activity.Depending on the supported features available, this information may include:

  • bed presence or occupancy;
  • time in bed;
  • bed-exit or ‘Leave Bed’ events;
  • supported movement or activity information;
  • supported heart-rate readings, where available;
  • underlying sensor readings required to determine supported bed activity;
  • timestamps associated with supported readings and events; and
  • derived or summarised information used to provide supported care insights.

The Service does not visually monitor the Bed User and does not use the BEEMS monitoring mat to record video or audio.

2.4 Environmental data

Where supported by the connected BEEMS Device, we may collect environmental readings such as:

  • room temperature;
  • CO₂;
  • TVOC or other supported air-quality information; and
  • the timestamps associated with those readings.
2.5 Device and technical data

We may collect technical information required to operate, secure and troubleshoot the Service, including:

  • BEEMS Device identifiers;
  • monitoring mat or MAT ID;
  • Device UUID, SSID or serial number, where applicable;
  • Device connection and online/offline status;
  • Device configuration and assignment information;
  • mobile push-notification tokens;
  • cloud notification endpoint identifiers;
  • app language preference;
  • selected application and Device settings;
  • network metadata such as IP addresses contained in system or server logs;
  • browser and application information;
  • authentication and session information;
  • one-way hashes used for security and abuse-prevention purposes; and
  • failed-login counts and other security events.
2.6 Alerts, acknowledgements and audit information

We may collect and retain information associated with alerts and Caregiver actions, including:

  • alert type;
  • alert status;
  • time of the alert;
  • Bed User associated with the alert;
  • supported readings or information associated with the alert;
  • whether an alert requires attention;
  • whether the alert has been acknowledged;
  • the authorised user who acknowledged or responded to the alert;
  • the time of acknowledgement;
  • alert configuration and preferences;
  • notification delivery information; and
  • household invitations, roles and access changes.

Where an alert-escalation or call-for-assistance feature is supported and enabled, we may also process the information required to provide that feature.

2.7 Subscription, cancellation and billing data

We may collect:

  • subscription Plan;
  • subscription start and expiry dates;
  • minimum commitment period;
  • subscription status;
  • billing and payment history;
  • add-ons associated with the subscription;
  • introductory or promotional offer eligibility and usage;
  • billing customer identifiers issued by our payment processor;
  • cancellation requests;
  • Early Termination Fee information; and
  • records relating to a request for waiver of an Early Termination Fee.

We do not store full credit or debit card numbers on our systems. Payment-instrument information is collected and processed directly by our payment processor.

Hospitalisation waiver documentation
Where you request an Early Termination Fee waiver because a registered Bed User has been continuously hospitalised for more than two consecutive weeks, we may collect official documentation reasonably necessary to verify:

  • the identity of the Bed User;
  • the relevant hospital or healthcare institution; and
  • the period of inpatient hospitalisation.

We do not require information about the Bed User’s medical diagnosis beyond what is reasonably necessary to verify eligibility for the waiver.

Death of a Bed User
Where an Early Termination Fee waiver is requested following the death of a Bed User, we may collect:

  • a copy of the Bed User’s death certificate; or
  • other official documentation we have agreed to accept.

Such documents may contain personal identifiers or other personal data that is not otherwise required for normal use of BEEMS.

We will use such information only for purposes reasonably connected with verifying and administering the relevant cancellation request, complying with legal or accounting requirements, and preventing fraud or misuse.

2.8 Delivery and Setup information

Where you request Delivery & Setup or another fulfilment service, we may collect information necessary to provide that service, including:

  • recipient name;
  • mobile number;
  • delivery or installation address;
  • selected delivery or setup timeslot;
  • Device or monitoring-mat information associated with the installation; and
  • relevant service records.
2.9 Introductory-offer and abuse-prevention information

Where we operate introductory or promotional offers, we may process information reasonably necessary to determine eligibility and prevent repeated or improper use of those offers.

Depending on the controls implemented, this may include comparing information such as:

  • account history;
  • monitoring mat or MAT ID;
  • household;
  • registered Bed User;
  • contact information;
  • delivery information;
  • billing customer identifiers;
  • payment-related identifiers made available to us by our payment processor; and
  • previous BEEMS subscriptions or promotional redemptions.

We use such information for fraud, misuse and promotional-eligibility purposes and not for unrelated profiling.

2.10 What we do not collect through the BEEMS monitoring service

Based on the current design of the Service:

  • BEEMS does not require a camera to monitor the Bed User;
  • the BEEMS monitoring mat does not record video or audio;
  • the BEEMS mobile apps do not require location tracking for the core monitoring Service;
  • we do not use BEEMS sensor data for third-party advertising;
  • we do not sell personal data; and
  • we do not use third-party behavioural advertising technologies within the BEEMS monitoring experience.

Where any of these practices change, this Policy will be updated as required.

3. How we collect personal data

We collect personal data:

  • directly from you, when you create an account, verify your contact details, create a household, register a Bed User, invite Caregivers, configure alerts, subscribe to a Plan, arrange Delivery & Setup, contact support or submit a cancellation request;
  • automatically from the BEEMS monitoring mat and Device, when supported readings and events are transmitted to our systems;
  • from your mobile device or web browser, where necessary to operate the Apps, authenticate users, deliver notifications, secure the Service and maintain technical logs;
  • from authorised household users, where another person invites you, assigns you access or provides information required to administer a Bed User’s care arrangement;
  • from documents you provide, where you request an Early Termination Fee waiver or another service requiring verification; and
  • from our service providers, where necessary for payment processing, notification delivery, hosting, security or other Service functions.

4. Purposes for which we use personal data

We may collect, use or disclose personal data for the following purposes.

4.1 Providing the BEEMS Service

To:

  • receive and process supported sensor information;
  • determine supported bed status and events;
  • display supported information to authorised users;
  • provide bed-presence and bed-exit information;
  • provide supported readings;
  • generate supported care insights;
  • maintain Bed User, household and Device assignments; and
  • provide mobile and web access to the Service.
4.2 Providing Insights and historical information

BEEMS Insights are designed to help Caregivers understand supported activity and trends over time.

We may use supported Bed User, alert and environmental information to:

  • calculate daily summaries;
  • plot and tabulate supported information;
  • compare selected periods;
  • display trends such as bed exits, time in bed, supported heart-rate information, room temperature and alert activity; and
  • allow authorised users to review available historical information.

The customer-facing Insights interface currently allows users to review up to 30 days of supported historical information, including views for the last 7 days or last 30 days.

This does not necessarily mean all underlying records are automatically deleted after 30 days. Retention is governed separately by Section 7.

4.3 Alerts and notifications

To:

  • generate supported alerts;
  • deliver push or in-app notifications;
  • display alert activity;
  • record acknowledgement;
  • allow authorised Caregivers to coordinate responses; and
  • provide supported escalation or call-for-assistance functionality where available and enabled.

Alerts and status information may not appear instantaneously. Processing, sensor determination, connectivity and application refresh intervals may result in a short delay before information is reflected in the Apps.

4.4 Accounts, households and access

To:

  • authenticate users;
  • verify account information;
  • administer households;
  • invite Caregivers;
  • manage roles and permissions;
  • assign authorised users to Bed Users; and
  • restrict information to users with appropriate access.
4.5 Subscriptions, payments and fulfilment

To:

  • establish and administer BEEMS Plans;
  • process payments;
  • maintain subscription and billing records;
  • provide Delivery & Setup;
  • administer add-ons;
  • process renewals where requested;
  • process cancellations; and
  • administer applicable Early Termination Fees.
4.6 Hospitalisation and bereavement cancellation requests

To:

  • receive and review requests for Early Termination Fee waivers;
  • verify qualifying hospitalisation or the death of a Bed User;
  • administer subscription termination;
  • maintain appropriate financial and audit records; and
  • prevent misuse of waiver arrangements.

Information provided for these purposes will not be used for medical diagnosis or unrelated profiling.

4.7 Promotional eligibility and fraud prevention

Where applicable, to:

  • determine eligibility for introductory or promotional offers;
  • prevent repeated or improper redemption;
  • identify suspicious account activity;
  • protect the integrity of BEEMS subscriptions and promotions; and
  • enforce applicable promotional and subscription terms.
4.8 Operating and securing the Service

To:

  • diagnose technical issues;
  • provide customer support;
  • maintain security;
  • investigate unauthorised access;
  • prevent fraud and misuse;
  • apply login-attempt throttling and other security controls;
  • maintain service reliability; and
  • carry out necessary system maintenance.
4.9 Communicating with you

To send:

  • account-verification communications;
  • password reset information;
  • household invitations;
  • subscription and billing communications;
  • operational notices;
  • support responses;
  • Device or connectivity notices; and
  • other communications necessary to provide the Service.
4.10 Legal and regulatory purposes

To:

  • comply with applicable law;
  • comply with lawful requests from courts, regulators or public authorities;
  • establish, exercise or defend legal rights;
  • maintain required accounting records; and
  • meet applicable regulatory obligations.

We do not sell personal data.
We do not use BEEMS sensor data to make automated decisions that produce legal or similarly significant effects on a Bed User.
Collection, use and disclosure will be carried out in accordance with the PDPA, including through consent or applicable exceptions where available and appropriate.

5. Disclosure of personal data

We may disclose personal data in the following circumstances.

5.1 Authorised BEEMS users

Information may be made available to household owners, administrators, Caregivers or other authorised users according to the access permissions granted through the Service.

 

An authorised Caregiver should only be able to access information for the Bed User or household to which that Caregiver has been assigned.

5.2 Service providers

We disclose information to service providers that process data on our behalf where reasonably necessary to operate the Service.
See Section 6.

5.3 Alert recipients

Where supported alert or escalation features are enabled, information necessary to provide the relevant notification may be disclosed to the configured recipient.


This does not mean that BEEMS provides an emergency response service.

5.4 Delivery and support providers

Where necessary to fulfil Delivery & Setup, hardware support, returns, troubleshooting or another requested service, relevant information may be disclosed to personnel or service providers involved in carrying out that function.

5.5 Legal and safety purposes

We may disclose information where:

  • required by applicable law;
  • required by a court, regulatory authority or lawful government request;
  • reasonably necessary to investigate fraud or misuse;
  • necessary to protect our legal rights; or
  • otherwise permitted under the PDPA.
5.6 Business transfers

Personal data may be transferred in connection with a proposed or completed merger, acquisition, restructuring, financing or sale of business assets, subject to appropriate safeguards and applicable law.

We do not sell or rent personal data and do not disclose BEEMS data for third-party marketing.

6. Third-party service providers (data processors)

We use the following third-party providers to operate the Service. Each processes only the data needed for its function:
Provider Function Data shared Location
Amazon Web Services (AWS) Cloud hosting, database, storage, streaming, email, push-notification routing All categories of Service data (hosted infrastructure) Singapore (ap-southeast-1)
Google Firebase Cloud Messaging (Google LLC) Delivery of push notifications to mobile devices and browsers Device push tokens; notification content (e.g. alert summaries) Google global infrastructure (may be outside Singapore)
Stripe Payment and subscription processing Billing customer identifier; payment details you enter are collected directly by Stripe United States / global
Google Places API (Google LLC) Address autocomplete when you type an address The address text you type Google global infrastructure
We may also use email delivery (via AWS Simple Email Service, with an SMTP fallback) to send verification, invitation and account emails. Our primary infrastructure and databases are hosted in the AWS Singapore region. Some providers above (notably Stripe, Twilio, and Google services) may process data outside Singapore. Where personal data is transferred outside Singapore, we take steps required under the PDPA to ensure the recipient provides a standard of protection comparable to the PDPA, for example through contractual data-protection commitments. See Section 9.

7. Storage, retention and deletion

  • Where data is stored: primarily in the AWS Singapore region (ap-southeast-1), in managed databases and storage.
  • Raw, second-by-second sensor readings are automatically deleted on a rolling basis (currently after 2 days) once they have been aggregated.
  • Aggregated and summarised data (e.g. hourly/daily averages, time-in-bed, alert counts) is retained to provide history and trend features for as long as your account or the relevant household remains active.
  • Account, alert, notification, billing and audit records are retained for as long as needed to provide the Service and to meet our legal, accounting and security obligations.
  • Hospitalisation and death documentation submitted in support of an Early Termination Fee waiver will be retained only for as long as reasonably necessary to verify and administer the cancellation request, maintain required billing or audit records, resolve disputes, prevent misuse, and comply with applicable legal obligations.
  • Account deletion: when an account is deleted, we deactivate it and remove or de-identify directly identifying details; some records may be retained where required for legal, billing, audit or safety reasons, and backups are cycled out over time.

You may request deletion of personal data as described in Section 8. We will action such requests subject to our legal retention obligations.

8. Your rights under the PDPA

Subject to the PDPA and applicable exceptions, you may:

  • request access to personal data we hold about you and information regarding how it has been used or disclosed within the period required by law;
  • request correction of inaccurate or incomplete personal data;
  • withdraw consent to the collection, use or disclosure of personal data by providing reasonable notice;
  • request closure of your BEEMS account; and
  • request deletion of information that we are not required or permitted to continue retaining.

Withdrawal of consent may affect our ability to continue providing some or all of the Service.
For example, if consent necessary for processing a Bed User’s monitoring information is withdrawn, BEEMS may no longer be able to provide monitoring, alerts or Insights for that Bed User.
Account deletion or withdrawal of consent does not automatically remove information that we are required or permitted to retain for legal, billing, audit, security or other legitimate purposes.
To make a request or raise a concern, contact our Data Protection Officer using the details in Section 11.
We will respond in accordance with the requirements of the PDPA.
If you are not satisfied with our response, you may contact the Personal Data Protection Commission of Singapore.

9. Cross-border transfers

Some service providers may process personal data outside Singapore.
Where personal data is transferred outside Singapore, we will take measures required under the PDPA’s Transfer Limitation Obligation to ensure that the transferred data receives a standard of protection comparable to that required under the PDPA.
Such measures may include contractual obligations, provider data-protection terms or other safeguards permitted by law.

10. How we protect personal data

We implement reasonable technical and organisational safeguards appropriate to the nature of the Service and the sensitivity of the information processed.
Depending on the production architecture, these measures may include:

  • Encryption in transit — HTTPS/TLS for app and web traffic, and MQTT over TLS for device-to-cloud communication;
  • Encryption at rest for our managed databases and storage;
  • Access controls — role-based access so users see only the households and Bed Users they are authorised for; private network isolation of databases;
  • Authentication safeguards — securely hashed passwords (PBKDF2), token-based sessions with rotation, one-time passcodes for sensitive changes, and login-attempt throttling/lockout to deter brute-force attacks;
  • Logging and monitoring of our systems.

No method of transmission or storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security.

11. Contact us / Data Protection Officer

For any request, question or complaint regarding personal data or this Policy, please contact our Data Protection Officer:

Data Protection Officer: Derick Teo
Email: derick@rainbowcare.com.sg
Support email: support@beems.com.sg
Address: Rainbow Care Pte. Ltd., 3007 Ubi Rd 1, #02-410, Singapore 408701

12. Children

The Service is intended to be administered by adults.
Where BEEMS is used in connection with a minor, the Service must be set up and administered by a parent, legal guardian or other person with appropriate legal authority.
That person is responsible for ensuring that the collection, use and disclosure of the minor’s personal data is properly authorised.

13. Changes to this Policy

We may update this Policy from time to time to reflect:

  • changes to the BEEMS Service;
  • new features;
  • changes to our service providers;
  • operational changes;
  • legal or regulatory requirements; or
  • changes to our data-handling practices.

We will publish the updated version with a revised Effective Date.
Where changes are material, we will take reasonable steps to notify affected users and obtain fresh consent where required by law.

Scroll to Top