Protecting your privacy is important to HealthArc, LLC.

("HealthArc," the "Company", "us" or “we”). This policy describes how the Company may use your data.

UPDATED DATE: April 1, 2024

HealthArc has two online platforms where this Privacy Policy applies:
(1) its corporate website, and
(2) its software system used by clinicians to remotely monitor their patients.

On the website, HealthArc uses the information you provide through contact forms to respond to sales, marketing, and support inquiries.

For its remote patient monitoring system, HealthArc does not sell Personal Data or Health Data to anyone. HealthArc provides clinicians with secure tools for data collection and patient engagement, but it does not sell the data itself.

HealthArc may monitor system usage to improve the software experience. It may also use anonymized data to create aggregated community statistics and trends, and to add new features that improve the functionality and usability of the software.

This Privacy Policy explains how HealthArc uses, protects, and safeguards your data.

By using the Services, you consent to the collection, use, and disclosure of your Personal Data (such as name and email address) and your patients’ Personal Data (such as name, email address, and Health Data) in accordance with this Privacy Policy.

Definitions:

Data Controller (or HCP, including healthcare professionals and supporting staff)
Means the individual or organization that decides why and how Personal Data is processed.

Data Processor (or HealthArc, including subcontractors)
Means the individual or organization that processes Personal Data on behalf of the Data Controller.

Data Subject (or User)
Means the individual whose Personal Data is collected through the Services.

Health Data
Means information related to a person’s physical or mental health, including healthcare services provided, that reveals information about that individual.

Personal Data
Means any information, including Health Data, that relates to an identifiable individual and is collected through the Services.

Why we collect your information:

We collect, use, disclose, and process Personal Data to provide the Services, improve your experience, and support technical assistance.

HealthArc may use your Personal Data to contact you and respond to your questions, keep records of our communications with you, and perform safety backups of your data.

Personal Data may also be used to help you or your healthcare professional track Health Data, generate anonymized and aggregated statistics, and improve the Software.

In addition, HealthArc may use this information to develop new services and software features that better meet your needs.

What information we collect:

We collect Personal Data in different ways when you use and interact with our Services.

  • Active Personal Data Collection: You may choose to share information with us when you sign up for the Services, respond to us, or contact us directly. Depending on your choices, this may include information about you or others, such as your name, email address, mailing address, phone number, date of birth, gender, or a healthcare portal access key. You always decide what information you want to share with us.
  • Health Data Processing: If you use the Services as part of your medical care with a healthcare professional, you may share Health Data through the Services with that healthcare professional. In this case, HealthArc acts only as a Data Processor for your Health Data.
  • Passive Information Collection: We also collect information about how you use the Services. This may include your IP address, pages visited, date and time of visits, referring website URL, and the device used to access the website or app. We may also collect usage details such as which features you use, how long you use them, and when. In some cases, we may ask for demographic information such as age or gender. This information does not directly identify you and is used to improve the performance and appearance of the Services.
  • Third-Party Program Data: If you choose to connect third-party applications, devices, or apps to the Services (“Third-Party Programs”), HealthArc may receive Personal Data collected by those programs in order to integrate them with the Services. These Third-Party Programs are not owned or controlled by HealthArc. HealthArc is not responsible for how those programs collect, use, or share your data, which is governed by their own privacy policies. If you connect Bluetooth devices that are directly supported by our Services, no third party is involved in collecting your data.

Necessary collection, use and disclosure:

HealthArc collects and uses your Personal Data only as needed to provide the Services. We do not use your Personal Data for any purpose other than the reason it was originally collected.

We keep your Personal Data secure, encrypted, and confidential. We do not disclose it except in the situations described below.

  • Law Enforcement: We may share Personal Data to comply with law enforcement requests, court orders, or other legal processes. We may also disclose information if we believe it is necessary to investigate, prevent, or respond to illegal activity, fraud, or threats to your safety or the safety of others, or as required by applicable law or regulation.
  • Bluetooth Devices: You may choose to connect the Services to health measurement devices using Bluetooth technology. These devices use Bluetooth Low Energy (LE) to allow real-time transfer of data. The Services do not use Bluetooth for any other purpose. If you do not want your data transmitted through Bluetooth, you can turn off Bluetooth on your device or disconnect any Bluetooth-enabled devices from the Software.
  • Aggregated Statistics and Reports: HealthArc may use and share data in anonymized or de-identified form for internal analysis, reporting, compliance, and with trusted partners, as long as the data does not identify any individual.
  • Employees and Authorized Contractors: HealthArc employees and authorized independent contractors (“Authorized Personnel”) may access your Personal Data only as needed to operate and support the Services. They may not use the data for their own purposes unless you give consent. All Authorized Personnel access data on a need-to-know basis and are subject to strict confidentiality and security obligations.
  • Business Transfers: HealthArc may be involved in a merger, sale, or transfer of some or all of its assets. If this happens, your Personal Data may be shared with the organization involved in the transaction, as permitted by law. Any such organization will be required to protect your Personal Data in a manner consistent with this Privacy Policy and applicable law.
  • Express Consent: HealthArc may also disclose your Personal Data when you explicitly request or authorize us to do so.

Personal data Hosting and Storing:

HealthArc stores your Personal Data in secure cloud infrastructure and compliant data centers, following applicable data protection and security standards.

Except for anonymized or non-identifiable data, which may be stored indefinitely, HealthArc retains your Personal Data for up to 12 months after you delete your account, request account deletion, or when your healthcare professional deletes your account.

After this retention period, HealthArc may delete your Personal Data in accordance with applicable laws.

Your Personal Data may be stored or processed in locations outside your state or country, as permitted by applicable regional laws. These laws may include, but are not limited to, the General Data Protection Regulation (GDPR) of the European Union, the Health Insurance Portability and Accountability Act (HIPAA) of the United States, and the Personal Information Protection and Electronic Documents Act (PIPEDA) of Canada.

Access and Update:

You have the right to access and receive a copy of your Personal Data.

You also have the right to review, update, correct, or request changes to any Personal Data that you believe is inaccurate or incomplete.

To exercise these rights, please contact us at privacy@healtharc.io

Withdrawal of consent and Opt-out:

If you do not agree with how we use your Personal Data as described in this Privacy Policy, you may withdraw your consent for the collection, use, and disclosure of your Personal Data.

To withdraw your consent, please contact us at privacy@healtharc.io

You may also opt out of receiving electronic communications from us at any time by using the “unsubscribe” or “opt-out” instructions included in those communications.

Generally not suitable for children under the age of [13]:

HealthArc Services are not intended for children under the age of 13.

We do not knowingly collect Personal Data directly from children under this age through the Services.

However, we may collect information about children or babies when it is provided by their parents or legal guardians as part of the Services. Users are asked not to share information about a child or baby unless they have first obtained consent from the child’s parent or legal guardian.

By providing Personal Data about a child or baby, you confirm that you are legally authorized to share that information.

We encourage parents and legal guardians to speak with their children about safe internet use and the information they share through the Services.

Third-Party Programs:

HealthArc is not responsible for the features, content, accuracy, or behavior of Third-Party Programs that are linked to, framed within, or shown as search results in the Services.

Your use of Third-Party Programs is at your own risk and is subject to their own terms of use and privacy policies.

HealthArc does not endorse any product, service, or treatment that may be advertised or promoted through the Services.

HealthArc is not liable for any loss or damage of any kind that may result from your use of Third-Party Programs.

Security

HealthArc uses commercially reasonable physical, electronic, and administrative safeguards to protect the Personal Data we collect.

However, no method of storing or transmitting data over the internet is completely secure. As a result, HealthArc cannot guarantee absolute security or eliminate all security or privacy risks related to Personal Data.

HealthArc acts as a Data Processor and is not responsible for any data breach, unauthorized disclosure, or unlawful use of Personal Data or Health Data that, at the time of the incident, was under the control of your healthcare professional.

Security and Data Breach Notification

HealthArc uses reasonable administrative, technical, and physical safeguards to protect Personal Data.

If a data breach or security incident involving Personal Data occurs, HealthArc will notify affected users as required by applicable laws and regulations. Notification may be provided by email or through in-application messages, as appropriate.

Changes to This Privacy Policy

HealthArc may update this Privacy Policy from time to time.

When we make changes, we will post the updated policy on this page and revise the effective date. Where required by law, we will also notify users through in-application notices where this Privacy Policy is referenced.

Your continued use of the Services after the updated Privacy Policy becomes effective means that you accept the changes.

X
X

    FULL NAME*

    WORK EMAIL*

    WORK PHONE NUMBER*

    MESSAGE*