privacy

WEBSITE PRIVACY POLICY

Your privacy matters to ISHI Health Inc. We follow a privacy framework that helps us manage and protect your information stored in our products, services, and websites. This Privacy Policy Notice (“Notice”) describes how ISHI Health collects, uses, and shares the information you provide. This Notice describes your rights and choices, and how you can contact us about our privacy practices. (For information on ISHI Health’s terms of use, please also visit ISHI Health’s Website Terms of Use.) ISHI Health’s Sites and Services may contain links to third-party websites, products, and services. This Notice does not apply to third party websites and mobile applications, products, or services that may link to or are linked from our Sites and Services or services we offer as a Business Associate on behalf of health care organizations.  Please consult those websites and applications directly to understand their privacy practices.

INFORMATION WE COLLECT
1. Information We Collect About You.
a. Our company collects, processes, and retains information from you when you interact with our Sites and Services. We may collect the following information from you:
i. Log-in credentials (such as user ID and password) and security questions and answers;
ii. Your name, email address, contact information, including your mailing address, phone number, title, and information about the organization with which you are affiliated
iii. Any information you choose to include in your messages or responses when interacting with us through our Sites and Services, including via online forums, inquiry forms, our support portal, or our messaging services, including any information you provide when you complete a survey administered by us or a supplier acting on our behalf
iv. Payment information and associated contact information when you engage in transactions; or
v. Information about your device and your device’s operating system and browser information, transaction information related to the ISHI Health mobile application such as product download ID, account contact information, device ID, information about the way you use the Application including administrative user account contact information, device event information such as errors, system activity, hardware settings, the date and time of your request.

2. Information We Collect Automatically.
a. Types of Tracking Technologies. We may automatically collect certain information through browser cookies and other tracking technologies when you access, use, or interact with our Sites and Services, including:
i. Browser and device data, such as your device type, operating system and version, IP address, general geographic location as indicated by your IP address, browser type, screen resolution, device manufacturer and model, language, plug-ins, add-ons, and the language version of the Site you are visiting;
ii. Usage data, including information about the time you spend on our Sites and Services, the content you view or download and features you access, the pages that led or referred you to our Sites and Services, language preferences, how you interact with available content, and entered search terms;
iii. Interactions with ads and newsletters (as applicable), such as information about how you interact with our ads and newsletters, including whether you open or click links in any correspondence; or
iv. Information that you make available to us on social media platforms (such as by clicking on a social media icon linked from our Sites and Services), including your account ID or username and other information included in your posts.

b. Interest-Based Tracking.
When you visit or use our Sites and Services, we and our partners may collect information about your online activities over time and across different sites to provide you with advertising about products and services tailored to your individual interests (called “interest-based advertising”). Our partners may place or recognize a unique cookie or other tracking technology on your browser (including the use of pixel tags). Where required by applicable law, we will rely on your consent prior to processing personal information from your device or computer for the purpose of interest-based advertising.

c. Use of Cookies.
Cookies are small text files that are stored in a devices’ web browser memory. Cookies store information when you use, access or interact with our Sites and Services, such as your IP address or other identifier, your browser type, and information about the content you view and your interactions. Other tracking technologies, such as pixel tags (also known as web beacons and clear GIFs), page tags, and script, may contain small transparent image files or lines of code to, among other things, track the actions of users (such as email recipients), measure the success of our marketing campaigns and compile statistics about usage of our Sites and Services. We may use cookies and other tracking technologies for any of the following purposes:
i. Site operations, including to enable features on our Sites and Services, such as remembering your preferences, tracking the number of times you have been shown an advertisement, generating aggregate statistics about how people use our Sites and Services, and for error management and troubleshooting;
ii. Analytics, including to allow us to understand how our Sites and Services are being used, track the performance of our Sites and Services and make improvements;
iii. Interest-based advertising (as applicable), including to deliver tailored communications or advertising based on your preferences or interests across services and devices and measure the effectiveness of advertisements;
iv. Social media, including to enable the sharing of content from our Sites through social networking and other sites.

As a general rule, we do not collect personal information via cookies unless you have given us your permission to do so. Most web browsers automatically accept cookies but, if you prefer, you can usually modify your browser setting to disable or reject cookies. If you delete your cookies or if you set your browser to decline cookies, some features of our Sites and Services may not be available, work, or work as designed. You may also be able to opt out of or block tracking by interacting directly with the other companies who conduct tracking through our Services. You can learn about your options to opt out of mobile app tracking by certain advertising networks through your device settings and by resetting the advertiser ID on your Apple or Android device.

Please note that opting out of advertising network services does not mean that you will not receive advertising on our Sites or on other websites, nor will it prevent the receipt of interestbased advertising from other companies that do not participate in these programs. It will, however, exclude you from interest-based advertising conducted through participating networks, as provided by their policies and choice mechanisms. If you delete your cookies, you may also delete your opt-out preferences.

3. Information We Collect from Other Sources.
We may obtain information about you from other sources such as data brokers, credit reporting agencies, social networks, partners with which we offer co-branded services or engage in joint marketing activities, and publicly available sources such as data in the public domain. We also may receive information about you from outside suppliers through your online activities on websites and connected devices over time and across websites, devices, apps and other online features and services. These other sources help us update, expand, and analyze our records; identify new customers; determine you or your organization’s advertising or purchasing preferences; or prevent or detect fraud. We combine such information with information we have collected about you through our Sites and Services. We will treat the combined information in accordance with this Privacy Notice.

4. How We Use Your Information.
a. Generally We use the information we collect about you for the following purposes:
i. To provide you with our Sites and Services, including to facilitate client interactions, enter into contracts, process payments, fulfill orders, send service communications, send email marketing communications, and conduct general business operations such as accounting, recordkeeping, and audits;
ii. To provide you with the best service and to improve and grow our business, including to understand how our Sites and Services are being used, conduct data analyses of user experiences and behavior, understand our customer base and purchasing trends, understand the effectiveness of our marketing, and develop new products and services;
iii. To deliver targeted advertising on our Sites based on your preferences or interests across services and devices and measure the effectiveness of ads;
iv. To protect and secure our Sites and Services, assets, network, and business operations, and to detect, investigate, and prevent activities that may violate our policies or be fraudulent or illegal; and
v. To comply with legal process, such as warrants, subpoenas, court orders, and lawful regulatory or law enforcement requests and to comply with legal requirements regarding the provision of products and services.

b. Marketing Emails. From time to time, we may send you promotional or marketing materials. If at any time you would like to unsubscribe from receiving promotional or commercial emails from us, you can click the unsubscribe link at the bottom of any email or email us at: info@ishi.health. We will meet your request as soon as reasonably practicable. Please note that if you opt out of receiving marketing-related emails from us, we may still send you important administrative messages.

5. How and With Whom We Disclose Your Information.
a. With our suppliers. We may share your information with suppliers that provide services on our behalf, such as marketing and survey services, payment processors, website and customer experience hosting, data analysis, data storage, customer service, auditing and accounting firms and security suppliers. We contract with suppliers to use or disclose information to perform services on our behalf or to comply with legal requirements. We require our suppliers to contractually commit to protect the security and confidentiality of data they process on our behalf.

b. With our advertising partners. We may share your information with our advertising partners.

c. With social media platforms. Where you choose to interact with us through social media, your interaction with these programs typically allows the social media company to collect some information about you through cookies they place on your device and other tracking mechanisms. In some cases, the social media company may recognize you through its digital cookies even when you do not interact with their application. Please visit the social media companies’ respective privacy policies to better understand their data collection practices and controls they make available to you.d. Where required or permitted by law or in the context of an audit or other review. We may share information with law enforcement agencies, courts, or other government authorities where we believe it is necessary to comply with a legal or regulatory obligation; to protect the rights, safety, and property of our company, you or others; or to respond to requests from courts, law enforcement agencies, regulatory agencies and other public and government authorities.

e. In the context of a change of ownership or corporate organization. We may transfer to another entity or its affiliates or service providers some or all information about you in connection with, or during negotiations of, any merger, acquisition, sale of assets or any line of business, change in ownership control, or financing transaction. We cannot promise that an acquiring party or the merged entity will have the same privacy practices or treat your information the same as described in this Policy.

PERSONAL INFORMATION SECURITY AND STORAGE
6. Safeguards Provided.We implement and maintain organizational, technical, and administrative security measures designed to safeguard the information we process within our organization against unauthorized access, destruction, loss, alteration, or misuse. These measures are aimed at providing on-going integrity and confidentiality for your personal information. We evaluate and update these measures on an ongoing basis. Your information is only accessible to personnel who need access to the information to perform their duties. However, while we take precautions to safeguard your information, we cannot guarantee the security of the networks, systems, servers, devices, and databases we operate or that are operated on our behalf.

7. Information Retention.We retain your personal information for as long as we have a relationship with you, subject to applicable law and regulation. When deciding how long to keep your personal information, we consider our legal and regulatory obligations and internal personal information management policies. For example, we retain records to investigate or defend against potential legal claims or where required by law. Where we retain data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.

INTERNATIONAL DATA TRANSFERS
8. International Data Transfer Safeguards.Your information may be transferred to, stored, and processed in a country that does not provide the same level of protection for personal information as the laws of your home country and may be available to the government of those countries under a lawful court order made in those countries. We have put in place appropriate safeguards in accordance with applicable legal requirements to provide adequate protections for your personal information and we comply with applicable laws on the transfer of personal information between countries, privacy, data protection and cybersecurity laws where we transact business to help protect your personal information.

FOR CALIFORNIA RESIDENTS: YOUR CALIFORNIA PRIVACY RIGHTS
9. Information Requests Available to You.
Residents of the State of California have the right to request information from us regarding other companies to whom we have disclosed certain categories of information during the preceding year for the other companies’ direct marketing purposes. If you are a California resident and would like to make such a request, please submit your request to info@ishi.care.

10. Right to Receive Disclosures. The California Consumer Privacy Act provides California residents with rights to receive certain disclosures regarding the collection, use, and sharing of “Personal Information,” as well as rights to know/access, delete, and limit sharing of Personal Information. The CCPA defines “Personal Information” to mean “information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.” Certain information we collect may be exempt from the CCPA because it is considered public information (i.e., it is made available by a government entity) or covered by a specific federal privacy law, such as the Gramm–Leach–Bliley Act, the Health Insurance Portability and Accountability Act (HIPAA), or the Fair Credit Reporting Act. To the extent that we collect Personal Information that is subject to the CCPA, that information, our practices, and your rights are described below.

FOR CALIFORNIA RESIDENTS: RIGHT TO INFORMATION REGARDING THE CATEGORIES OF PERSONAL INFORMATION COLLECTED, SOLD, AND DISCLOSED10. Data Collection Practices.
The following is a description of our data collection practices, including the Personal Information we may collect, the sources of that information, the purposes for which we collect information, and whether we disclose that information to external parties. We may use any and all of the information for any of the purposes described in this privacy notice, unless limitations are listed.

a. Personal Identifiers.
i. We may collect your name, phone number, email address, mailing address, and contact address when you create an account or contact us via the site. If you choose to create an account, you may also be asked to create a username, and we may assign one or more unique identifiers to your profile. We use this information to provide our services, respond to your requests, and send information and advertisements to you;
ii. We may collect a unique numerical identifier, assigned to you by a cookie, automatically when you use the Sites and Services in order to identify you, provide our Services, keep you logged in to our Sites, prevent fraud, and provide you with targeted information and offers;
iii. We, or a service provider working on our behalf, may collect your payment information when you provide it in order to complete a transaction. This information includes your credit card number or bank account number. We use this information to facilitate payments and transactions;
iv. We do not collect your Driver’s License number, passport number, or social security number;
v. We may collect your IP address and Device ID automatically when you use our Sites and Services. We use this information to identify you, gauge online activity on our website, measure the effectiveness of online services, applications, and tools, and provide you with targeted advertisements and offers based on your online activities.

b. Protected Classifications. We do not collect your age, gender, racial or ethnic origin, or sexual orientation.

c. Commercial Information. When you engage in transactions with us, we may create records of transactions. We use this information to measure the effectiveness of our services and to provide you with targeted information, advertisements, and offers.

d. Biometric Information. We do not collect information about your physiological, biological, or behavioral characteristics.

e. Internet or Other Electronic Network Activity Information. When you navigate to and use our site, we may collect information such as your Internet domain, the domain of your Internet service provider, the date and time that you access the site, the Internet address of the website from which you linked directly to the site, and the pages you visit on our sites.

f. Geolocation Data. As described above, we may collect your IP address automatically when you visit our sites. We can determine your general location based on your IP address.

g. Audio, electronic, visual, thermal, olfactory, or similar information. We do not collect your audio, electronic, visual, thermal, olfactory, or similar information.

h. Professional or employment-related information. We may collect your business contact information when you contact us regarding our products and services or when you interact with us at trade shows. We otherwise do not collect your professional or employment-related information.

i. Education information. We do not collect any information about the institutions you have attended or the level of education you have attained.

j. Inferences drawn to create a profile about a consumer reflecting the consumer’s preferences or characteristics. We may analyze your actual or likely preferences through a series of computer processes and add our observations to your internal profile. We use this information to gauge and develop our marketing activities, to measure the appeal and effectiveness of our services, applications, and tools, and to provide you with targeted information, advertisements, and offers.

11. Purposes for Data Use.We may use any of the categories of information listed above for other business or operational purposes compatible with the context in which the Personal Information was collected. We may share any of the above-listed information with service providers, which are external parties that we engage for business purposes and are restricted from using personal information for any purpose that is not related to our engagement. The categories of service providers with whom we share information and the services they provide are described in this Global Privacy Notice.

12. Information Sold to Third Parties. On certain occasions, we may sell information to third parties. An external party may be considered a third party either because the purpose of sharing the Personal Information is not an enumerated business purpose under California law, or because our contract does not restrict them from using Personal Information for other purposes. To “sell” information means to disclose it to an external party for monetary or other benefit. We sell the following information:

a. Protected Classifications. We may provide your IP address and device ID to our suppliers and online advertising partners.

b. Internet or Other Electronic Network Activity Information. We may provide information about your Internet or other electronic network activity information to our suppliers and online advertising partners.

c. Inferences drawn to create a profile about a consumer reflecting the consumer’s preferences or characteristics. We may provide our observations about you to our suppliers and online advertising partners.

d. Other disclosures. We also may disclose information to external parties who are not listed here when required by law or to protect our company or for other purposes, as described in this Notice.

13. Access to Deidentified Information. We may license access to deidentified health information that is derived from Protected Health Information, as defined by the Health Insurance Portability and Accountability Act. All such information is deidentified according to the safe-harbor or expert determination requirements of HIPAA.

14. Right to Access Information. You have the right to request access to Personal Information collected about you and information regarding the source of that information, the purposes for which we collect it, and the third parties and service providers with whom we share it. To protect our customers’ Personal Information, we will verify your identity before we act on your request.

15. Right to Request Deletion of Information. You have the right to request in certain circumstances that we delete any Personal Information that we have collected directly from you. To protect our customers’ Personal Information, we will verify your identity before we act on your request. We may have a reason under the law why we do not have to comply with your request or why we may comply with it in a more limited way than you anticipated. If we do, we will explain that to you in our response.

16. Right to Information Regarding Participation in Data Sharing for Financial Incentives. We may offer online resources whereby we incentivize you to share certain pieces of information with us. In the event we offer such resources, participation is voluntary and you may opt out of the data sharing at any time.

17. Right to Opt Out of the Sale of Personal Information to Third Parties. You have the right to opt out of any sale of your Personal Information to third parties. To exercise this right, please contact us at info@ishi.care. Please note that your right to opt out does not apply to our sharing of Personal Information with service providers, who are parties we engage to perform a function on our behalf and are contractually obligated to use the Personal Information only for that function.

18. How to Submit a Request. You may submit a request to exercise your rights through either of two means: (1) by emailing a written request to info@ishi.care or (2) by calling us at (844) 989-4744 (ISHI).

MISCELLANEOUS

19. Changes to This Privacy Notice.We will periodically update this Global Privacy Notice, and we will post notice of any material changes to the Global Privacy Notice on this website in advance of making those changes. The “Effective Date” at the top of this page indicates when this Global Privacy Notice was last revised.

20. Third-Party Advertising. From time to time, you may see advertising, logos, or Web site links on our Sites or Services. We do not claim to endorse or evaluate such advertising, logos, or Web site links or the products or services so advertised. We do not make any representation to you as to the accuracy or suitability of any of the information these advertisements contain, and do not accept any responsibility or liability for the conduct or content of those advertisements and sites, as well as the offerings made by the third parties. We also do not take any responsibility for the content of the advertisements, promises made, or the quality or reliability of the products or services offered in the advertisements.

21. How to Contact Us. If you have questions, requests, or complaints related to your privacy, please contact (844) 989-4744 (ISHI). If you would like to exercise data protection rights afforded by certain privacy regulations, please contact our Data Privacy Officer at info@ishi.care or by physical mail addressed to the attention of the Data Privacy Officer at the following address: 1919 Pacific Highway, Unit PH03, San Diego, CA 92101.