Important Note – Is Your Data Covered By HIPAA? Not necessarily. HIPAA only covers certain types of data and data uses. We comply with HIPAA when applicable, such as when we provide services to HIPAA-covered entities as a business associate.
• PERSONAL INFORMATION WE COLLECT
• Personal Information You Provide Us Directly
We may collect personal information that you provide to us, including the following:
• Account and Prescription Information. We will collect personal information from you (like your name, date of birth, email address, credit card information, phone number, and delivery address) when you register for an account, and, in order to provide you with the prescription delivery services, you will need to provide us with certain medical information such as your physician’s name and address, prescription information, insurance information, and in some cases, medical history.
• Your Communications with Us. We may collect personal information, such as email address, phone number, or mailing address when you request information about DISQO or our Services, register for our newsletter, request support, or otherwise communicate with us.
• Surveys. We may contact you to participate in surveys. If you decide to participate, we may collect personal information from you in connection with the survey.
• Interactive Features. We and others who use our Services may collect personal information that you submit or make available through our interactive features (e.g., commenting functionalities, forums, blogs, and social media pages). Any information you provide using the public sharing features of the Services will be considered “public,” unless otherwise required by applicable law, and is not subject to the privacy protections referenced herein.
• Sweepstakes or Contests. We may collect personal information you provide for any sweepstakes or contests that we may offer. In some jurisdictions, we are required to publicly share information of sweepstakes and contest winners.
• Conferences, Trade Shows, and Other Events. We may collect personal information from individuals when we attend or host conferences, trade shows, and other events.
• Business Development and Strategic Partnerships. We may collect personal information from individuals and third parties to assess and pursue potential business opportunities.
• Healthcare Providers. If you are a healthcare provider, we may receive your National Provider Number (“NPI”), medical specialty, or other professional credential information.
• Job Applications. We may post job openings and opportunities on our Services. If you respond to one of these postings, we may collect your personal information, such as your application, CV, cover letter, and/or any other information you provide to us.
• PERSONAL INFORMATION WE COLLECT AUTOMATICALLY
We may collect personal information automatically when you use our Services.
• Automatic Collection of Personal Information. We may collect certain information automatically when you use our Services, such as your Internet protocol (IP) address, user settings, MAC address, cookie identifiers, mobile carrier, mobile advertising and other unique identifiers, browser or device information, location information (including approximate location derived from IP address), and Internet service provider. We may also automatically collect information regarding your use of our Services, such as pages that you visit before, during and after using our Services, items that you search for via the Services, information about the links you click, the types of content you interact with, the frequency and duration of your activities, and other information about how you use our Services.
• Cookies. Cookies are small text files placed in device browsers that store preferences and facilitate and enhance your experience.
• Pixel Tags/Web Beacons. A pixel tag (also known as a web beacon) is a piece of code embedded in our Services that collects information about engagement on our Services. The use of a pixel tag allows us to record, for example, that a user has visited, a particular web page or clicked on a particular advertisement. We may also include web beacons in e-mails to understand whether messages have been opened, acted on, or forwarded.
Our uses of these Technologies fall into the following general categories:
• Operationally Necessary. This includes Technologies that allow you access to our Services, applications, and tools that are required to identify irregular website behavior, prevent fraudulent activity, improve security, or allow you to make use of our functionality;
• Performance-Related. We may use Technologies to assess the performance of our Services, including as part of our analytic practices to help us understand how individuals use our Services (see Analytics below);
• Functionality-Related. We may use Technologies that allow us to offer you enhanced functionality when accessing or using our Services. This may include identifying you when you sign into our Services or keeping track of your specified preferences, interests, or past items viewed;
• Advertising- or Targeting-Related. We may use first party or third-party Technologies to deliver content, including ads relevant to your interests, on our Services or on third-party digital properties.
See the “Your Privacy Choices” section below to understand your choices regarding these Technologies.
• Personal Information Collected By Third-Party Services and Sources.
• We may obtain personal information about you from other sources, including through third-party services and organizations. For example, if you access our Services through a third-party application, we may collect personal information about you from that third-party application that you have made available via your privacy settings.
• How We Use the Information We Collect
• Provide Our Services
We use the information we collect to provide our Services (or the information you request), including to:
• fulfill your prescriptions and delivering them to you;
• process and complete any transactions;
• manage your information and accounts;
• provide you with access to certain areas, functionalities, and features of our Services;
• answer requests for customer or technical support;
• communicate with you about your account, activities on our Services, and policy changes;
• process your financial information and other payment methods for products or Services purchased;
• process applications if you apply for a job we post on our Services; and
allow you to register for events.
• Administrative Purposes
We use your personal information for various administrative purposes, such as:
Pursuing our legitimate interests such as direct marketing, research and development (including marketing research), network and information security, and fraud prevention;
Detecting security incidents, protecting against malicious, deceptive, fraudulent or illegal activity, and prosecuting those responsible for that activity;
Measuring interest and engagement in our Services;
Improving, upgrading, or enhancing our Services;
Developing new products and services;
Ensuring internal quality control and safety;
• Debugging to identify and repair errors with our Services;
• Auditing relating to interactions, transactions, and other compliance activities;
• Sharing personal information with third parties as needed to provide the Services;
• Enforcing our agreements and policies; and
• Carrying out activities that are required to comply with our legal obligations.
• Marketing and Advertising our Products and Services
We may use personal information to tailor and provide you with content and advertisements. We may provide you with these materials as permitted by applicable law.
Some of the ways we may market to you include email campaigns, text messages, custom audiences advertising, and “personalized advertising” or “targeted advertising,” including through cross-device tracking.
If you have any questions about our marketing practices, you may contact us at any time as set forth in “Contact Information” section below.
• With Your Consent
We may use personal information for other purposes that are clearly disclosed to you at the time you provide personal information or with your consent.
• Other Purposes
We use your personal information for other purposes as requested by you or as permitted by applicable law.
We may also use personal information to create de-identified and/or aggregated information, such as demographic information, information about how you use the Services, information about the device from which you access our Services, or other analyses we create. De-identified and/or aggregated information is not personal information, and we may use, disclose, and retain such information as permitted by applicable laws including, but not limited to, for research, analysis, analytics, and any other legally permissible purposes. If we create or receive de-identified information, we will not attempt to reidentify such information, unless permitted by, or required to comply with, applicable laws.
• HOW WE DISCLOSE YOUR PERSONAL INFORMATION
We disclose your personal information to third parties for a variety of business purposes, including to provide our Services, to protect us or others, or in the event of a major business transaction such as a merger, sale, or asset transfer, as further described below.
• Disclosures to Provide Our Services
The categories of third parties with whom we may share your personal information are described below.
• Pharmacies. In order to fulfill and deliver your prescription, we may share your Personal Information with a third-party pharmacy (“Pharmacy”). The Pharmacy will then use your Personal Information to fulfill your prescription. From the Pharmacy, we may receive your address, physician’s name, prescription information, prescription refill orders, and information on how to hand your prescription.
• Service Providers. Your information may be accessed and used by our service providers who are working with us in connection with the operation of our Services (these service providers may have access to your information but only to the extent necessary to perform services on our behalf and are obligated not to disclose that information or use it for any other purposes).
• Affiliates. We may share your personal information with our corporate affiliates.
• Advertising Partners and Sponsors. We may share your personal information with third-party advertising partners. These third-party advertising partners may set Technologies and other tracking tools on our Services to collect information regarding your activities and your device (e.g., your IP address, cookie identifiers, page(s) visited, location, time of day). These advertising partners may use this information (and similar information collected from other services) for purposes of delivering personalized advertisements to you when you visit digital properties within their networks. This practice is commonly referred to as “interest-based advertising”, “personalized advertising”, or “targeted advertising.”
• Disclosures to Protect Us or Others
• Disclosure in the Event of Merger, Sale, Or Other Asset Transfers
We may transfer and/or provide information about our users in connection with an acquisition, sale of company assets, or other situation where user information would be transferred as one of our business assets.
• YOUR PRIVACY CHOICES.
The privacy choices you may have about your personal information are determined by applicable law and are described below.
• Text Messages. If you receive an unwanted text message from us, you may opt out of receiving future text messages from us by following the instructions in the text message you have received from us or by otherwise contacting us as set forth in “Contact Information” section below.
• Mobile Devices. We may send you push notifications through our mobile application. You may opt out from receiving these push notifications by changing the settings on your mobile device. With your consent, we may also collect precise location-based information via our mobile application. You may opt out of this collection by changing the settings on your mobile device.
• Phone Calls. If you receive an unwanted marketing phone call from us, you may opt out of receiving future phone calls from us by following the instructions which may be available on the call or by otherwise contacting us as set forth in “Contact Information” section below.
• “Do Not Track.” Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.
• Cookies and Personalized Advertising. You may stop or restrict the placement of Technologies on your device or remove them by adjusting your preferences as your browser or device permits. However, if you adjust your preferences, our Services may not work properly. Please note that cookie-based opt-outs are not effective on mobile applications. However, you may opt-out of personalized advertisements on some mobile applications by following the instructions for Android, iOS, and others.
The online advertising industry also provides websites from which you may opt out of receiving targeted ads from data partners and other advertising partners that participate in self-regulatory programs. You can access these and learn more about targeted advertising and consumer choice and privacy by visiting the Network Advertising Initiative, the Digital Advertising Alliance, the European Digital Advertising Alliance, and the Digital Advertising Alliance of Canada.
Please note you must separately opt out in each browser and on each device.
• Your privacy Rights
When it comes to your personal information, you may have certain rights. In accordance with applicable law, you may have the right to:
• Confirm Whether We Are Processing Your Personal Information (the right to know);
• Request Access to and Portability of Your Personal Information, including: (i) obtaining access to or a copy of your personal information; and (ii) receiving an electronic copy of personal information that you have provided to us, or asking us to send that information to another company in a structured, commonly used, and machine-readable format (also known as the “right of data portability”);
• Request Correction of your personal information where it is inaccurate or incomplete. In some cases, we may provide self-service tools that enable you to update your personal information;
• Request Deletion of your personal information;
• Request Restriction of or Object to our processing of your personal information;
• Withdraw your Consent to our processing of your personal information. Please note that your withdrawal will only take effect for future processing, and will not affect the lawfulness of processing before the withdrawal; and
• Appeal our Decision to decline to process your request.
• File a Complaint .You may have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights by sending a letter to 200 Independence Avenue, S.W., Washington, D.C. 20201, calling 1-877-696-6775, or visiting www.hhs.gov/ocr/privacy/hipaa/complaints/.
• RETENTION OF PERSONAL INFORMATION
To determine the appropriate retention period for personal information, we may consider applicable legal requirements, the amount, nature, and sensitivity of the personal information, certain risk factors, the purposes for which we process your personal information, and whether we can achieve those purposes through other means.
• INTERNATIONAL VISITORS
All information processed by us may be transferred, processed, and stored anywhere in the world, including, but not limited to, the United States or other countries, which may have data protection laws that are different from the laws where you live. We endeavor to safeguard your information consistent with the requirements of applicable laws.
If we transfer personal information which originates in the European Economic Area, Switzerland, and/or the United Kingdom to a country that has not been found to provide an adequate level of protection under applicable data protection laws, one of the safeguards we may use to support such transfer is the EU Standard Contractual Clauses.
For more information about the safeguards we use for international transfers of your personal information, please contact us as set forth below.
• CONTACT INFORMATION