Medtep Privacy Policy

Effective date: 2016/09/30

We, at Medtep, know you care about how personal information is used and shared, and we take privacy seriously. Please read the following to learn more about our Privacy Policy.

By using or accessing medtep.com, our Mobile applications, Medtep Professionals and Medtep (collectively, the “Services”) in any manner, you acknowledge that you accept the practices and policies outlined in this Privacy Policy, and you hereby consent that we will collect, use, and share personal information in the following ways.

Remember that your use of Medtep’s Services is at all times subject to the Medtep Professionals Terms of Use if accessing our Medtep Professionals Services or the Medtep Terms of Use if accessing our Medtep Services, each of which incorporates this Privacy Policy. Any terms we use in this Policy without defining them have the definitions given to them in the applicable Medtep Professionals Terms of Use orMedtep Terms of Use.

U.S. –Swiss Safe Harbor

Medtep complies with the U.S. – Swiss Safe Harbor framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data from Switzerland. Medtep has certified that it adheres to the Safe Harbor Privacy Principles of notice, choice, onward transfer, security, data integrity, access, and enforcement.
.

EU-U.S. Privacy Shield

Medtep participates and has certified its compliance with the EU-U.S. Privacy Shield Framework. Medtep is committed to subjecting all personal data received from the European Union (EU) member countries, in reliance on the Privacy Shield Framework, to the Framework’s applicable principles.

Medtep is responsible for the processing of data it receives, under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. Medtep complies with the Privacy Shield Principles for all onward transfers of personal data from the EU, including the onward transfer liability provisions.

With respect to the personal data received or transferred pursuant to the Privacy Shield Framework, Medtep is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Medtep may be required to disclose personal data in response to lawful requests by public authorities, including to meet the national security or law enforcement requirements.

Under certain conditions, more fully described on the Privacy Shield website, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.

What does this Privacy Policy cover?

This Privacy Policy covers our treatment of personally identifiable information (“Personal Information”) that we gather when you are accessing or using our Services, but not to the practices of companies we don’t own or control, or people that we don’t manage. We gather various types of Personal Information from our users, as explained in more detail below, and we use this Personal Information internally in connection with our Services, including to personalize, provide, and improve our services, to allow you to set up a user account and profile, to contact you and allow other users to contact you, to fulfill your requests for certain products and services, and to analyze how you use the Services. In certain cases, we may also share some Personal Information with third parties, but only as described below.

This paragraph applies only if you’re accessing our Medtep Professionals Services. The Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) defines policies, procedures and guidelines for maintaining the privacy and security of individually identifiable health information. You understand and agree that it is your responsibility to ensure your compliance with HIPAA and other applicable laws. Where we are required by law to be subject to a business associate agreement (“BAA”) to work with you and your patients, the BAA here https://www.medtep.com/legal/internet-services/medtep-professionals/baa will apply. It will not apply unless explicitly required by law. You should seek professional legal advice regarding your compliance with HIPAA and other applicable laws; Medtep does not assume any responsibility or liability for any damages resulting from your failure to do so.

The Children’s Online Privacy Protection Act (“COPPA”) requires that online service providers obtain parental consent before they knowingly collect personally identifiable information online from children who are under 13. We do not knowingly collect or solicit personally identifiable information from a child under 13 without obtaining verifiable consent from that child’s parent or guardian (“Parental Consent”), except for the limited amount of personally identifiable information we need to collect in order to obtain Parental Consent (“Required Information”). Until we have received Parental Consent, we will only use Required Information for the purpose of obtaining Parental Consent. If you are a child under 13, please do not attempt to send any personal information about yourself to us before we obtain Parental Consent, except for the Required Information in the context of the Parental Consent process. If you believe that a child under 13 has provided us with personal information (beyond the Required Information) without our obtaining Parental Consent, please contact us.

Will Medtep ever change this Privacy Policy?

We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time as well. If we make any material changes, we will alert you to changes by placing a notice on the applicable https://www.medtep.com, https://pro.medtep.com or https://my.medtep.com website, by sending you an email, and/or by some other means of notice prior to the change becoming effective. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes.

If we make material changes to how we use Personal Information collected from children under 13, we will notify parents by email in order to obtain verifiable parental consent for the new uses of the child’s Personal Information.

What Information does Medtep Collect?

Information You or Your Healthcare Partners Provide to Us

We receive and store any information you, your child, or your healthcare partners knowingly provide to us. For example, we may collect Personal Information such as name, email address, parent’s email address, phone number, parent’s phone number, mailing address, affiliated organizations, gender, age, weight, height, photograph, and health and well-being related information (including, without limitation, health-related records, results, data, or information you or your healthcare partners provide to us). Certain information may be required to register with us or to take advantage of some of our features. When you download and use our mobile application, we automatically collect data on the type of device you use, operating system version, and the device identifier (or “UDID”). We may ask you for, access or track location based data from your mobile while downloading or using our mobile apps or services for the purposes of providing our services to you. You may opt-out of having your location information used by turning it off at the device level. We may occasionally send you push notifications through our mobile applications to send you information about your medication, alerts, reminders or other information you setup that may be of importance to you. You may at any time opt-out from receiving these types of communications by turning them off at the device level through your settings.

We may communicate with you if you’ve provided us the means to do so. For example, if you’ve given us your email address, we may send you promotional email offers on behalf of other businesses, or email you about your use of the Services. Also, we may receive a confirmation when you open an email from us. This confirmation helps us make our communications with you more interesting and improve our services. If you do not want to receive promotional or newsletter communications from us, please indicate your preference by following the unsubscribe link in our communications or contacting us.

We will also send you service related email announcements on rare occasions when it is necessary to do so. For instance, if our Service is temporarily suspended for maintenance, we might send you an email. You do not have an option to opt out of these emails, which are not promotional in nature.

Information Collected Automatically, including Cookies and Other Tracking Technologies

Whenever you interact with our Services, we automatically receive and record information on our server logs from your browser or device, which may include your internet protocol (IP) address, device identification, “cookie” information, the type of browser and/or device you’re using to access our Services, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, clickstream data and the page or feature you requested. We may combine this automatically collected log information with other information we collect about you. We do this to improve services we offer you.

“Cookies” are identifiers we transfer to your browser or device that allow us to recognize your browser or device and tell us how and when pages and features in our Services are visited and by how many people. Technologies such as: cookies, beacons and scripts are used by Medtep and our partners, affiliates, or analytics or service providers. These technologies are used in analyzing trends, administering the Website, tracking users’ movements around the Website and to gather demographic data about our user base as a whole. We may receive reports based on the use of these technologies by these companies on an individual as well as aggregated basis. You may be able to change the preferences on your browser or device to prevent or limit your device’s acceptance of cookies, but this may prevent you from taking advantage of some of our features.

If you click on a link to a third party website or service, a third party may also transmit cookies to you. Again, this Privacy Policy does not cover the use of cookies by any third parties, and we aren’t responsible for their privacy policies and practices. Please be aware that cookies placed by third parties may continue to track your activities online even after you have left our Services, and those third parties may not honor “Do Not Track” requests you have set using your browser or device.

We may use this data to customize content for you that we think you might like, based on your usage patterns. We may also use it to improve the Services – for example, this data can tell us how often users use a particular feature of the Services, and we can use that knowledge to make the Services interesting to as many users as possible.

Medtep informs you that this website uses the following cookies, owned by us or by third parties, with the following objectives:

Name of Third Party PartnerWhat info is shared with or collected by this partnerPartner’s purposeLink to Partner’s privacy policy
GoogleIP address, computer and connection informationAnalyticshttps://google.com/intl/en/policies/privacy/
New RelicPerformance DataService providerhttp://newrelic.com/privacy
DoubleClick by GoogleDemographic and analytics dataAnalyticshttps://google.com/intl/en/policies/privacy/
FacebookSingle sign on data (over13 users)Single Sign onhttps://www.facebook.com/about/privacy
CloudFarePerformance DataService providerhttps://www.cloudflare.com/security-policy/

If you have any inquiries regarding our partner’s privacy practices or how they use your child’s personal information, please contact us directly.

By using cookies, the platform is able to recognize, for instance, the users that have a specific area, section or service reserved exclusively for them without having to register every time into the application. Cookies also are used to analyze parameters of traffic and usage and to control the progress and number of visits of a user.

As noted above, at any time, you can withdraw consent to the use of cookies, refusing to use them and accepting that the functionalities of the Services may be limited. You may block or delete cookies installed on your computer through your browser settings. When users navigate through and use the Services, Medtep or a contracted third party may use the tools of “Local Storage” and “Session Storage,” each of which are web application software methods and protocols used to store data in a web browser.

To fully use the Services, it may be necessary to enable the use of “Session Storage” and “Local Storage”. At any time, you may withdraw consent to the use of “Session Storage” and “Local Storage”, refusing to use them and accepting that the functionalities of the Services may be limited. You may block or delete the use of “Session Storage” and “Local Storage” on your computer through your browser settings.

Mobile Analytics

We use mobile analytics software to allow us to better understand the functionality of our Mobile Software on your phone. This software may record information such as how often you use the application, the events that occur within the application, aggregated usage, performance data, and where the application was downloaded from. We do not link the information we store within the analytics software to any personal data you submit within the mobile application.

Information Collected From Other Websites, Cookies and Do Not Track Policy

Through cookies we place on your browser or device, we may collect information about your online activity after you leave our Services. Just like any other usage information we collect, this information allows us to improve the Services and customize your online experience, and otherwise as described in this Privacy Policy. Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications and services (including behavioral advertising services) that you do not wish such operators to track certain of your online activities over time and across different websites. If you wish to not have this data used for the purpose of serving you interest-based ads, you may opt-out by clicking here (or if located in the European Union click here). Please note this does not opt you out of being served ads. You will continue to receive generic ads.

Will Medtep Share Any of the Personal Information it Receives?

We do not rent or sell Personal Information in personally identifiable form to anyone, provided certain Personal Information may be transferred in connection with business transfers, as described below. Parent’s have the right to consent to the collection and use of Personal Information from their child without also consenting to its disclosure to Third Parties as we do not share your child’s personal information with third parties. We may share Personal Information with third parties only as described in this section:

Information that’s no longer personally identifiable.
We may anonymize Personal Information so that no person is individually identified, and provide that information to our partners. We may also provide aggregate usage information to our partners, who may use such information to understand how often and in what ways people use our Services, so that they, too, can provide you with an optimal online experience. However, we never disclose aggregate usage information to a partner in a manner that would identify someone personally, as an individual.

Affiliated Businesses.
In certain situations, businesses or third party websites we’re affiliated with may sell or provide products or services to you through or in connection with the Services (either alone or jointly with us). You can recognize when an affiliated business is associated with such a transaction or service, and we will share Personal Information with that affiliated business only to the extent that it is related to such transaction or service. We have no control over the policies and practices of third party websites or businesses as to privacy or anything else, so if you choose to take part in any transaction or service relating to an affiliated website or business, please review all such business’ or websites’ policies.

Agents.
We employ other companies and people to perform tasks on our behalf and need to share your information with them to provide products or services to you; for example, we may use a payment processing company to receive and process credit card transactions for us. Unless we tell you differently, our agents do not have any right to use the Personal Information we share with them beyond what is necessary to assist us. Medtep informs you that we have contracted with GOOGLE INC., located at 1600 Amphitheatre Parkway, Mountain View, CA 94043 (USA), and CLOUDFLARE INC., located at 665 3rd St. Suite 207, San Francisco, CA 94107 (USA) as processors for cloud service delivery and encryption, and for the correct operation of the Services. These companies may provide cloud services internationally, and their servers may be located in the U.S. and the Netherlands (EU) and are attached to entities under the Privacy Shield, Swiss-Safe Harbour, ISO 27001, SOC2 and HIPAA, by which the companies undertake to be fully respectful and mindful of rules regarding protection of Personal Information, consequently applying the security measures necessary to ensure and maintain the security and confidentiality of Personal Information in our Services. By accepting this Privacy Policy, you fully accept and give us your permission to transfer any User Submission to these companies as processors for cloud service delivery and encryption, and for the correct operation of the Services.

User Profiles and Submissions.
Certain user profile information, including your name, location, and any content that such user has uploaded to the Services, may be displayed to other users to facilitate user interaction within the Services or address your request for our Services (for example, sharing information with your healthcare partners). Your account privacy settings may allow you to limit the other users who can see the Personal Information in your user profile and/or what information in your user profile is visible to others. Please remember that any Personal Information or content that you voluntarily disclose online in a manner other users can view (on discussion boards, in forums, in messages and chat areas, etc.) becomes publicly available, and can be collected and used by anyone. Your user name may also be displayed to other users if and when you send messages or comments through the Services and other users can contact you through messages and comments.

Business Transfers.
We may choose to buy or sell assets, and may share and/or transfer certain customer information in connection with such transactions. Also, if we (or our assets) are acquired, or if we go out of business, enter bankruptcy, or go through some other change of control, Personal Information could be one of the assets transferred to or acquired by a third party. In this event, you will be notified via email and/or a prominent notice on our Website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.

Protection of Medtep and Others.
We reserve the right to access, read, preserve, and disclose any information that we reasonably believe is necessary to comply with law or court order such as to comply to a subpoena or similar legal process; enforce or apply the applicable Medtep Professionals Terms of Use or Medtep Terms of Use and other agreements; or when we believe that disclosure is necessary protect the rights, property, or safety of Medtep, our employees, our users, or others.

Is Personal Information about me secure?

Your account is protected by a password for your privacy and security. You must prevent unauthorized access to your account and Personal Information by selecting and protecting your password appropriately and limiting access to your computer or device and browser by signing off after you have finished accessing your account. When you enter sensitive information (such as a credit card number) on our order forms or login credentials on our Service login, we encrypt the transmission of that information using secure socket layer technology (SSL).

We endeavor to protect the privacy of your account and other Personal Information we hold in our records, but unfortunately, we cannot guarantee complete security. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time. If you have any questions about security on our Web site, you can contact us.

What Personal Information can I access?

Upon request Medtep will provide you with information about whether we hold, or process on behalf of a third party, any of your personal information.  To request this information please contact us or go to the edit profile section of your Account.

Through your account settings, you may access, and, in some cases, edit or delete the following information you’ve provided to us name, email address, phone number, mailing address, affiliated organizations, gender, age, weight, height, photograph, and health and well-being related information (including, without limitation, health-related records, results, data, or information you or your healthcare partners provide to us) or you may also contact us by telephone or postal mail at the contact information listed below. We will respond to your request to access within 30 days.

The information you can view, update, and delete may change as the Services change. If you have any questions about viewing or updating information we have on file about you, please contact us.

If you are a parent or guardian of a user of our Services who is under 13, you may contact us at any time to ask that (a) we stop collecting Personal Information from such user, and (b) we delete any Personal Information already collected from such user and refuse further collection and use of such information. Please note that the terms regarding deleted data outlined below in
“What choices do I have?”
 also apply to deleted Personal Information from children under 13.

Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to ask us for a notice identifying the categories of Personal Information which we share with our affiliates and/or third parties for marketing purposes, and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this notice, please submit a written request.

What choices do I have?

You can always opt not to disclose information to us, but keep in mind some information may be needed to register with us or to take advantage of some of our features.

You may be able to add, update, or delete information as explained above. When you update information, however, we may maintain a copy of the unrevised information in our records. You may request deletion of your account by emailing us.

We will retain yours or your child’s information for as long as an account is active or as needed to provide services. We will retain and use the information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Some information may remain in our records after deletion. We may use any aggregated data derived from or incorporating Personal Information after you update or delete it, but not in a manner that would identify someone personally.

Links to 3rd Party Sites

Our Website includes links to other sites whose privacy practices may differ from those of Medtep. If you submit personal information to any of those sites, your data is governed by their privacy policies. We encourage you to carefully read the Privacy Policy of any site you visit.

Blog

Our Website offers publicly accessible blogs or community forums. Our blog is managed by a third party application that may require you to register to post a comment or to ask anything. We do not have access or control of the information posted to the blog. You will need to contact or login into the third party application if you want the personal information that was posted to the comments section removed. To learn how the third party application uses your information, please review their Privacy Policy.

Testimonials

We display personal testimonials of satisfied customers on our Website in addition to other endorsements. With your consent we may post your testimonial along with your name. If you wish to update or delete your testimonial, you can contact us.

Social Media Widgets

Our Website includes Social Media Features, such as the Facebook button and Widgets, such as the Share this button or interactive mini-programs that run on our Website. These Features may collect your IP address, which page you are visiting on our Website, and may set a cookie to enable the Feature to function properly. Social Media Features and Widgets are either hosted by a third party or hosted directly on our Website. Your interactions with these Features are governed by the Privacy Policy of the company providing it.

Single Sign-On

You can log in to our platforms using your login information from other providers. This service will authenticate your identity and provide you the option to share certain personal information with us such as your name and email address to pre-populate our login form. Services like Google or Facebook give you the option to post data about your activities on this Website to your profile page to share with others within your network.

Information Related to Data Collected through the Medtep Professional and Medtep Services

Information Related to Data Collected for our Clients:

  • Medtep collects information under the direction of its Clients, and has no direct relationship with the individuals whose personal information it processes. If you are a customer of one of our Clients and would no longer like to be contacted by one of our Clients that use our service, please contact the Client that you interact with directly. We may transfer personal information to companies that help us provide our service. Transfers to subsequent third parties are covered by the service agreements with our Clients.

Access and Retention of Data Controlled by our Clients:

  • Medtep has no direct relationship with the individuals whose personal information it processes. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate information should direct his query to the Medtep’s Client (the data controller). If requested to remove information we will respond within 30 days.
  • We will retain personal information we process on behalf of our Clients for as long as needed to provide services to our Client. Medtep will retain this personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

What if I have questions about this policy?

If you have any questions or concerns regarding our privacy policies, please send us a detailed message or via postal mail at 1540 Market Street, Suite 100, 94102 San Francisco CA, United States, and we will try to resolve your concerns.