Health Vector Privacy Policy

Last revised and effective as of: Oct 26, 2018

This Privacy Policy relates to information collected online by Health Vector, LLC (“Health Vector” "we" or “us” or “our”) through your use of the Health Vector website at [www.healthvector.world] and any subdomains (the “Site”) and the services, features, and information available on the Site and/or any mobile applications we may offer (together with the Site, along with associated and successor websites, applications, features, information, and services, or any part thereof, the “Service”). This Privacy Policy is incorporated into, and part of, and governed by the Health Vector Terms of Use. As used herein, “you” and “your” mean a user of the Service.  

You should carefully read this Privacy Policy. By using the Service, you are signifying your acceptance of this Privacy Policy. If you do not agree to this Privacy Policy, you may not use the Service.

To the extent that the Service is available to individuals located in the European Economic Area and the United Kingdom, this Privacy Policy sets out our practices and obligations under the General Data Protection Regulation 2016/679 (the “GDPR”). If your affiliated organization signs up to use our Service, we may receive personal information about you directly from your affiliated organization, which will only be used as necessary to provide the Service to your affiliated organization and to you and as otherwise specified in this privacy notice. Under the GDPR, to the extent applicable, we will act as a processor (as defined in the GDPR) on behalf of your affiliated organization in respect of that personal information and your affiliated organization will act as a controller (as defined in the GDPR) in respect of that personal information and is responsible for obtaining all necessary consents and providing you with all requisite information as required by applicable law.

As used in this Privacy Policy, the terms “using” and “processing” information include using cookies on a computer, subjecting the information to statistical or other analysis and using or handling information in any way, including, but not limited to collecting, storing, evaluating, modifying, deleting, using, combining, disclosing and transferring information within our organization or among our affiliates within the United States or internationally.

This Privacy Policy serves to notify you of the following:

What information about me is collected?

Where and when is information collected (including through the use of cookies and action tags)?

Does Health Vector collect information from children under 13 years of age?

What does Health Vector do with the information it collects?

When does Health Vector disclose information to third parties?

Does this Privacy Policy apply when I link to other websites or services?

Is the information collected through the Service secure?

Could my information be transferred to other countries?

For how long will my personally identifiable information be kept?

What choices do I have regarding my personally identifiable information?

How will I know if there are any changes to this Privacy Policy?

Who do I contact if I have any privacy questions?

WHAT INFORMATION ABOUT ME IS COLLECTED?

Depending on your use of the Service, we may collect two types of information: personally identifiable information and non-personally identifiable information.

Personally Identifiable Information

Personally identifiable information is information that identifies you or can be used to identify or contact you. Such information may include your name, address and location, e-mail address, telephone number, zip code, health data, marital status, gender, employer, occupation, insurance information, birth date and username.   Additionally our Outside Contractor (as defined below) that is responsible for billing and account services may collect bank account information and credit card information (collectively, “Payment Information”) from you directly. Health Vector does not receive or store such Payment Information. Personally identifiable information amounts to ‘personal data’ for the purposes of and as defined in the GDPR. All references to personally identifiable information shall be deemed to include ‘personal data’ as defined and used in the GDPR.

We may collect from you, or you may make available to us, some special categories of personal data. By agreeing to this Privacy Policy, you explicitly consent to the processing of any such special categories of personal data. “Special categories of personal data” consist of personal data for the purposes of and as defined in the GDPR which is to be treated with particular sensitivity, and includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic or biometric data, data concerning health or data concerning a person’s sex life or sexual orientation.

Non-Personally Identifiable Information

Non-personally identifiable information is information, any single item of which, by itself, cannot be used to identify or contact you, including demographic information (such as age, profession, gender or current location), IP addresses, browser types, unique device identifiers, device types, requested URL, referring URL, browser language, the pages you view, the date and time of your visit, domain names, and statistical data involving the use of the Service. Certain non-personally identifiable information may be considered a part of your personally identifiable information if it were combined with other identifiers (for example, combining your zip code with your street address) in a way that enables you to be identified. However, the same pieces of information are considered non-personally identifiable information when they are taken alone or combined only with other non-personally identifiable information (for example, your viewing preferences).

WHERE AND WHEN IS INFORMATION COLLECTED (INCLUDING THROUGH THE USE OF COOKIES AND ACTION TAGS)?

We will collect personally identifiable information that you submit to us. We may also receive personally identifiable information about you from third parties providing credit and debit card authorization and fraud screening services as part of your use of the Service.

Registering to Use the Service and in the Course of Using the Service.

You may be required to establish an account in order to take advantage of certain features of the Service. If so, if you wish to establish an account you will be required to provide us with information (including personally identifiable information and non-personally identifiable information) such as name, e-mail address, zip code and username. We may also receive personally identifiable information about you from third parties providing credit and debit card authorization and fraud screening services as part of the registration process. In addition, we may obtain your personally identifiable information from you if you identify yourself to us by sending us an e-mail with questions or comments. Also, we will have access to any personally identifiable information that you choose to share through the Service.    

If you choose to access the Service using the Facebook Login feature, you may be providing us with access to all information, attributes, and data in your Facebook public profile.  We may freely store and use such information in accordance with this Privacy Policy and the Terms of Use.  Such information may be stored by Health Vector and may be used in connection with providing the Service or to contact you.

If you choose to access the Service using the Google Sign-in feature, you are providing us with access to information associated with your Google account, including your Google ID, name, profile URL, and email address.  We may freely store and use such information in accordance with this Privacy Policy and the Terms of Use.  Such information may be stored by Health Vector and may be used in connection with providing the Service or to contact you.

If you choose to access the Service using the Sign In with LinkedIn feature, you may be providing us with access to all information, attributes, and data in your LinkedIn public profile.  We may freely store and use such information in accordance with this Privacy Policy and the Terms of Use.  Such information may be stored by Health Vector and may be used in connection with providing the Service or to contact you.

If you choose to access the Service using the Sign In with Twitter feature, you may be providing us with access to all information, attributes, and data in your Twitter public profile.  We may freely store and use such information in accordance with this Privacy Policy and the Terms of Use.  Such information may be stored by Health Vector and may be used in connection with providing the Service or to contact you.

 

Cookies and Action Tags.

We may collect non-personally identifiable information passively using “cookies” and “action tags.”

“Cookies” are small text files that can be placed on your computer or mobile device in order to identify your Web browser and the activities of your computer on the Service and other websites. Cookies can be used to personalize your experience on the Service (such as dynamically generating content on webpages specifically designed for you), to assist you in using the Service (such as saving time by not having to reenter your name each time you use the Service), to allow us to statistically monitor how you are using the Service to help us improve our offerings or to determine the popularity of certain content.

You do not have to accept cookies to use the Service. Although most browsers are initially set to accept cookies, you may reset your browser to notify you when you receive a cookie or to reject cookies generally. Most browsers offer instructions on how to do so in the "Help" section of the toolbar. However, if you reject cookies, certain features or resources of the Service may not work properly or at all and you may experience some loss of convenience.

"Action tags," also known as web beacons or gif tags, are a web technology used to help track website usage information, such as how many times a specific page has been viewed. Action tags are invisible to you, and any portion of the Service, including or e-mail sent on our behalf, may contain action tags.

By using cookies and action tags together, we are able to gain valuable information to improve the Service.

Log Files.

We also collect non-personally identifiable information through our Internet log files, which record data such as user IP addresses, browser types, domain names, and other anonymous statistical data involving the use of the Service. This information may be used to analyze trends, to administer the Service, to monitor the use of the Service, and to gather general demographic information. We may link this information to personally identifiable information for these and other purposes such as personalizing your experience on the Service and evaluating the Service in general.

DOES HEALTH VECTOR COLLECT INFORMATION FROM CHILDREN UNDER 13 YEARS OF AGE?

We are committed to protecting the privacy of children. The Service is not designed for or directed to children under the age of 13. We do not collect personally identifiable information from any person we actually know is under the age of 13.

WHAT DOES HEALTH VECTOR DO WITH THE INFORMATION IT COLLECTS?

We will only use your personally identifiable information to the extent that the law allows us to do so. Pursuant to the GDPR, legal bases for our processing your personally identifiable information may include:

(a) where you have given consent to the processing;

(b) where it is necessary to perform the contract we have entered into or are about to enter into with you (whether in relation to the provision of the Service or otherwise); and/or

(c) where it is necessary for the purposes of our legitimate interests (or those of a third party) and your interests or fundamental rights and freedoms do not override those legitimate interests.

We use the information collected to provide the Service to you and process your transactions, to help us understand who uses the Service, for internal operations such as operating and improving the Service, to contact you for customer service and billing purposes, and, if you “opt in”, so that we can contact you about products and services that may be of interest to you.

We may use your information to send you a welcoming e-mail that may confirm your user name and password. We may contact you about the Service and, if you opt in, we may subsequently send you electronic newsletters, contact you about products, services, information and news that may be of interest to you, and provide you with targeted feedback. If you no longer desire to receive these communications, we will provide you with the option to change your preferences in each communication we send to you. You may also inform us by email to: privacy@healthvector.world.

If you identify yourself to us by sending us an e-mail with questions or comments, we may use your information (including personally identifiable information) to respond to your questions or comments, and we may file your questions or comments (with your information) for future reference.

We may also use the information collected to send announcements and updates regarding the Service or, if applicable, about your billing account status. You will not be able to unsubscribe from these Service announcements and updates as they contain important information relevant to your use of the Service and are necessary for the performance of our contract with you.

The Service may send you informational text (SMS) messages as part of the normal business operation of your use of the Service, including to send you one-time passwords for dual factor authentication. You may opt out of receiving text (SMS) messages from Health Vector at any time by texting the word STOP from the mobile device receiving the messages to the number from which messages were sent; provided, however, that opting out of receiving text (SMS) messages may limit or interfere with certain functionality of the Service.

WHEN DOES HEALTH VECTOR DISCLOSE INFORMATION TO THIRD PARTIES?

 We generally disclose information we gather from you through the Service to the following types of third parties and as otherwise set forth in this Privacy Policy or our Terms of Use or as specifically authorized by you.

Healthcare Providers

We may disclose your personally identifiable information, particularly your health data, to your physician or other healthcare provider, as directed by you. Additionally, if you opt in, we may disclose your health data to third parties for the purpose of performing medical research.

Laws and Legal Rights.

We may disclose your information (including personally identifiable information) if we believe in good faith that we are required to do so in order to comply with an applicable statute, regulation, rule or law, a subpoena, a search warrant, a court or regulatory order, lawful requests by public authorities, including to meet national security or law enforcement requirements, or other valid legal process. We may disclose personally identifiable information in special circumstances when we have reason to believe that disclosing this information is necessary to identify, contact or bring legal action against someone who may be violating the Health Vector Terms of Use, to detect fraud, for assistance with a delinquent account, or to protect the safety and/or security of our users, the Service or the general public.

Third Parties Generally.

We may provide to third parties non-personally identifiable information, including where such information is combined with similar information of other users of the Service. For example, we might inform third parties regarding the number of unique users who use the Service or the demographic breakdown of our users of the Service.  The third parties to which we may provide or who may independently directly collect personally identifiable and non-personally identifiable information may include providers of products or services (including vendors and website tracking services), merchants, affiliates and other actual or potential commercial partners, sponsors, licensees, researchers and other similar parties.

Outside Contractors.

We may employ independent contractors, vendors and suppliers (collectively, "Outside Contractors") to provide specific services and products related to the Service, such as hosting and maintaining the Service, providing credit card processing and fraud screening, and developing applications for the Service. In the course of providing products or services to us, these Outside Contractors may have access to information collected through the Service, including your personally identifiable information.  We use reasonable efforts to ensure that these Outside Contractors are capable of (1) protecting the privacy of your personally identifiable information consistent with this Privacy Policy, and (2) not using or disclosing your personally identifiable information for any purpose other than providing us with the products or services for which we contracted or as required by law.

Sale of Business.

We reserve the right to transfer information to a third party in the event of a sale, merger or other transfer of all or substantially all of the assets of Health Vector or any of its Corporate Affiliates (as defined below), or that portion of Health Vector or any of its Corporate Affiliates to which the Service relates, or in the event that we discontinue our business or file a petition or have filed against us a petition in bankruptcy, reorganization or similar proceeding, provided that the third party agrees to adhere to the terms of this Privacy Policy.

Affiliates.

We may disclose information (including personally identifiable information) about you to our Corporate Affiliates. For purposes of this Privacy Policy: "Corporate Affiliate" means any person or entity which directly or indirectly controls, is controlled by or is under common control with Health Vector, whether by ownership or otherwise; and “control” means possessing, directly or indirectly, the power to direct or cause the direction of the management, policies or operations of an entity, whether through ownership of fifty percent (50%) or more of the voting securities, by contract or otherwise. Any information relating to you that we provide to our Corporate Affiliates will be treated by those Corporate Affiliates in accordance with the terms of this Privacy Policy.

DOES THIS PRIVACY POLICY APPLY WHEN I LINK TO OTHER WEBSITES OR SERVICES?

Our Service may provide you with access to other websites and services. This may include providing you with the ability to automatically post updates on Facebook, LinkedIn and Twitter. Please be aware that we are not responsible for the privacy practices of any websites or services other than the Service. We encourage you to read the privacy policies or statements of each and every such website and service. This Privacy Policy applies solely to information collected by us through the Service.

IS THE INFORMATION COLLECTED THROUGH THE SERVICE SECURE?

We want your information (including personally identifiable information) to remain secure. We strive to provide transmission of your information from your computer or mobile device to our servers through techniques that are consistent with commercially reasonable standards and to employ administrative, physical, and electronic measures designed to protect your information from unauthorized access.

Notwithstanding the above, you should be aware that there is always some risk involved in transmitting information over the Internet. There is also some risk that others could find a way to thwart our security systems. As a result, while we strive to protect your information, we cannot ensure or warrant the security or privacy of any information you transmit to us, and you do so at your own risk.

COULD MY INFORMATION BE TRANSFERRED TO OTHER COUNTRIES?

Personally identifiable information collected on the Service may be transferred from time to time to our offices or personnel, or to third parties, located throughout the world, and the Service may be viewed and hosted anywhere in the world, including countries that may not have laws of general applicability regulating the use and transfer of such data. By using the Service and submitting such information on it, you voluntarily consent to the trans-border transfer and hosting of such information. Without limitation of the foregoing, you hereby expressly grant consent to the Health Vector to: (a) process and disclose such information (including special categories of personal data) in accordance with this Privacy Policy; (b) transfer such information (including special categories of personal data) throughout the world, including to the United States or other countries that do not ensure adequate protection for personally identifiable information (as determined by the European Commission); and (c) disclose such information (including special categories of personal data) to comply with lawful requests by public authorities, including to meet national security or law enforcement requirements. If you are a user accessing the Service from a jurisdiction with laws or regulations governing personal data collection, use, and disclosure that differ from those of the United States, please be advised that all aspects of the Service are governed by the internal laws of the United States and the Commonwealth of Massachusetts, USA, regardless of your location.

FOR HOW LONG WILL MY PERSONALLY IDENTIFIABLE INFORMATION BE KEPT?

We will only retain your personally identifiable information for as long as necessary to fulfill the purposes for which we collected it.

To determine the appropriate retention period for personally identifiable information, we consider the amount, nature, and sensitivity of that information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process your personally identifiable information and whether we can achieve those purposes through other means, and the applicable legal requirements.

WHAT CHOICES DO I HAVE REGARDING MY PERSONALLY IDENTIFIABLE INFORMATION?

We generally use personally identifiable information as described in this Privacy Policy or our Terms of Use or as authorized by you or as otherwise disclosed at the time we request such information from you. You generally must "opt in" and give us permission to use your personally identifiable information for any other purpose. You may also change your preference and "opt out" of receiving certain marketing communications from us by following the directions provided in association with the communication or such other directions we may provide or by contacting privacy@healthvector.world.

Under certain circumstances and in compliance with the GDPR, you have the right to:

Request access to your personally identifiable information (commonly known as ‘subject access request’). This enables you to receive a copy of the personally identifiable information we hold about you and to check that we are lawfully processing it;

Request correction of the personally identifiable information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected;

Request erasure of your personally identifiable information. This enables you to ask us to delete or remove your personally identifiable information where there is no good reason for us to continue processing it. You also have the right to ask us to delete or remove all of your personally identifiable information in certain circumstances;

Object to processing of you personally identifiable information where we are relying on a legitimate interest (or that of a third party) and there is something about your particular situation which makes you want to object to processing on this ground;

Request the restriction of processing of your personally identifiable information. This enables you to ask us to suspend the processing of your personally identifiable information, for example, if you want us to establish its accuracy or the reason for processing it;

Request the transfer of your personally identifiable information to another party;

Lodge a complaint with the relevant supervisory authority (as defined in the GDPR). If you have any complaints about the way we process your personally identifiable information, please do contact us. Alternatively, you may lodge a complaint with the supervisory authority which is established in your country.

If you want to review, verify, correct or request erasure of your personally identifiable information, object to the processing of your personally identifiable information, or request that we transfer a copy of your personally identifiable information to another party, please contact privacy@healthvector.world.

Such updates, corrections, changes and deletions will have no effect on other information that we maintain, or information that we have provided to third parties in accordance with this Privacy Policy prior to such update, correction, change or deletion. To protect your privacy and security, we may take reasonable steps (such as requesting a unique password) to verify your identity before granting you profile access or making corrections. You are responsible for maintaining the secrecy of your unique password and account information at all times.

You should be aware that it may not be technologically possible to remove each and every record of the information you have provided to us from our system. The need to back up our systems to protect information from inadvertent loss means that a copy of your personally identifiable information may exist in a non-erasable form that will be difficult or impossible for us to locate. After receiving your request, we will use commercially reasonable efforts to update, correct, change, or delete, as appropriate, all personally identifiable information stored in databases we actively use and other readily searchable media as appropriate, as soon as and to the extent reasonably practicable.

DO NOT TRACK

The term “Do Not Track” refers to a HTTP header offered by certain web browsers to request that websites refrain from tracking the user. We take no action in response to automated Do Not Track requests. However, if you wish to stop such tracking, please contact us with your request, using our contact details provided below.

 

HOW WILL I KNOW IF THERE ARE ANY CHANGES TO THIS PRIVACY POLICY?

We may revise this Privacy Policy from time to time.  We will not make changes that result in significant additional uses or disclosures of your personally identifiable information without allowing you to “opt in” to such changes. We may also make non-significant changes to this Privacy Policy that generally will not significantly affect our use of your personally identifiable information, for which your opt-in is not required. We encourage you to check this page periodically for any changes. If any non-significant changes to this Privacy Policy are unacceptable to you, you must immediately contact us and, until the issue is resolved, stop using the Service. Your continued use of the Service following the posting of non-significant changes to this Privacy Policy constitutes your acceptance of those changes.

WHO DO I CONTACT IF I HAVE ANY PRIVACY QUESTIONS?

If you have any questions or comments about this Privacy Policy or feel that we are not abiding by the terms of this Privacy Policy, please contact our Privacy Agent in any of the following ways:

By e-mail:

privacy@healthvector.net

By postal mail or courier:

Attn: Privacy Agent
Health Vector, LLC P.O. Box 590348, Newton Center, MA 02459 USA

 

BY USING THE SERVICE, YOU SIGNIFY YOUR ACCEPTANCE OF THIS PRIVACY POLICY. IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, YOU SHOULD NOT USE THE SERVICE.  CONTINUED USE OF THE SERVICE, FOLLOWING THE POSTING OF CHANGES TO THIS PRIVACY POLICY THAT DO NOT SIGNIFICANTLY AFFECT THE USE OR DISCLOSURE OF YOUR PERSONALLY IDENTIFIABLE INFORMATION, MEANS THAT YOU ACCEPT THOSE CHANGES.