Last updated on April 8, 2021. You can find previous versions in the archive.
Wellframe may process your personal information for the following purposes:
- Providing you with the service accessed through this mobile application including through service providers, such as our cloud hosting provider, that are contractually bound to protect your personal information;
- As directed by your sponsor (ex: your health insurer or healthcare provider) per our business associate agreement governed by HIPAA;
- Hosting your personal information in data centers within the United States of America;
- De-identifying your personal information (so it no longer identifies you) and using the resulting information in aggregated or non-aggregated form for product improvement, marketing, research, and to provide services to our customers; and
- Meeting our legal obligations.
INFORMATION COLLECTION AND USE
What information Wellframe collects
- Information you provide: We may ask and collect information such as your name, email address, phone number, address, birthdate, and gender to register your account as well as other information in the below categories. We use this information to manage your account, verify your identity, and deliver the Service to you.
- Information we receive from third parties: We may receive information about you, including what is listed in other categories, from your Sponsor or other third parties as directed by your Sponsor. This information may include demographic information, medical history, health insurance information, or other information that your Sponsor has directed us to process. We use this information to fulfill contractual obligations to your Sponsor, as directed by your Sponsor, and to deliver the Service to you. The collection, processing, and sharing of this information is controlled by your Sponsor.
- Health Information: Since we are a health related application, we collect information about your health. This category can include diagnoses, symptoms, medical procedures, medications, discharge dates, clinical notes, physical characteristics, provider information, and other biometric information. We use this information to provide the Service to you such as using your medication information to provide medication notifications.
- Communications: We collect the content of communications made through our Service between your Sponsor and you. This content can include information under other categories as well as any other information you decide to communicate. We use this content to provide you a record of your communications as well as use it in de-identified form as discussed below.
- Integration data: We may use automated methods to track data from your other apps, fitness wearables, biometric monitoring devices, and other integrations that you have allowed to communicate with our Service. This integration data is then contained in our application for both you and your Sponsor to see and use. You may be prompted to provide access to the camera functionality of your device, we use this access to scan for optical character recognition (OCR) features, and to allow you to include attachments in communications. We do not otherwise collect images or recordings you have on your device. If using the Android version of our app, you may be prompted to allow access to location data for the purposes of the Bluetooth connection, however, we do not collect your location data.
- Information unrelated to the application: Wellframe may also collect personal information outside of the Service such as through our websites. This information can include your browsing activities on our site, your IP address, cookie information, and the pages you request. We use this information for such uses including security, content improvements, sales, and marketing. For more details about this and other uses outside of our application (such as through our website) please go to this link.
- Analytics information: We may collect usage data about how you use our Service such as how you use the application, what content you read and favorite, content of messages within our Service, integration data, and device information. We use this analytics information to improve the Service for you, your Sponsor, and other users.
- Log files: To maintain security, fulfill compliance requirements, and generally make sure the Service is operating correctly, we collect information such as IP addresses, server requests, login events, device information, crash reports, usage activity, or other information to discover and respond to events indicating possible service interruptions, security threats, fraud, or other illegal activity. We may also use this information to enforce our EULA, for compliance, and other legal obligations. Where feasible we limit the identifiable and sensitive information contained in these log files.
- Support information: If you contact us regarding questions, issues, or requests regarding the use of our Service, our support team may view your Personal Information, as well as any additional information you provide, in order to assist. We may also ask follow-up questions to gather more information as necessary to address your issue. This information is stored as a record of your support request.
- Optional information: We may also collect additional information, with your consent, that is not necessary for use of our Services such as product feedback, surveys, usage analytics, and testimonials. We use this information to improve and market our Service. Your Sponsor may request this information as well to improve their products and services. You have the right to object to processing of your personal data for direct marketing purposes by contacting firstname.lastname@example.org or by using the “unsubscribe” link in an email you receive.
Wellframe does not rent, lease, or sell your Personal Information. We share your Personal Information with your Sponsor as per our agreement with your Sponsor that allows you to use the Service. Your Sponsor may share your Personal Information or direct us to share your Personal Information to third parties such as your Sponsor’s affiliates or service providers. Your Sponsor may also provide us Personal Information or direct us to use your Personal Information in ways not specifically mentioned above. Contact your Sponsor to learn more about how they use your Personal Information.
To provide the Service, we may also share your Personal Information with our service providers and subcontractors for functionality, to communicate with you, measure performance, or improve our product. We may also disclose your Personal Information in response to a legal process, such as a law enforcement action, a subpoena, or to demonstrate compliance. Finally, we may transfer your Personal Information to an entity or individual that attempts or does acquire, buy, or merge with all or part of Wellframe, or through some other business reorganization.
Parts of the Service may involve the use and development of machine learning. Machine learning includes the use of computer algorithms to automatically detect patterns in data. To develop, support, and use these algorithms we may use the information categorized above and De-identified Information as defined below. We use machine learning to provide functionality, improve your experience, provide services to your Sponsor, optimize our operations, and other related business purposes.
In addition to the categories and uses above, we may remove the identifiable parts of your Personal Information to create de-identified information (“De-identified Information”). De-identified Information may be combined with other information into aggregated datasets. We use De-identified Information in the following ways:
- Disclosure for Business Purposes: We may license, use, disclose, or otherwise share De-identified Information with institutional clients, partners, investors and contractors for any purposes related to our business practices.
- Product Improvement: We may use De-identified Information for product improvement including the Service including the development of machine learning algorithms.
- Research: We may use De-identified Information for research whether scientific, marketing, or business in nature. This research may be made public through publications such as within a scientific journal.
STORAGE AND RETENTION
Your Personal Information will be stored in our cloud hosting provider’s data centers within the United States. We retain your Personal Information for as long as reasonably necessary to provide you the Service, as per your Sponsor’s instructions, or to comply with legal obligations. For details about where and how long your Sponsor stores your Personal Information, please contact your Sponsor. We may retain De-identified Information indefinitely.
CONFIDENTIALITY AND SECURITY
Wellframe has a legal duty under HIPAA to protect your Personal Information as a Business Associate of your Sponsor. We have put in place reasonable physical, technical, and administrative controls designed to safeguard against the unauthorized access, maintain data security, and correctly use your Personal Information. Any third party service providers we use must undergo a vetting process and sign confidentiality agreements before we utilize them to provide the Service. Some of these security measures rely upon you. Please keep your login credentials secret, avoid public WiFi networks, and log out of any shared devices. If you ever suspect a security issue with your account, contact email@example.com immediately.
Our Service is not directed to children. Wellframe does not knowingly collect Personal Information from children under the age of 13 except with permission of a child’s parent or legal guardian through our caregiver account feature. If we find that we collected Personal Information from a child under the age of 13 without proper consent, we will immediately delete that Personal Information.
RIGHTS TO PERSONAL INFORMATION
You or an authorized agent, such as a parent or authorized caretaker, may request access, changes, or deletions to your Personal Information and request information about our collection, use and disclosure of such information by contacting us at firstname.lastname@example.org or (844) 452-4085. We use best efforts to keep our records as accurate and complete as possible. You can help us maintain the accuracy of your information by notifying us or your Sponsor of any changes to your Personal Information as soon as possible. Since we are a HIPAA Business Associate of your Sponsor, we may need to forward your request to your Sponsor who will ultimately decide on how to accommodate your request. Your Sponsor may fulfill your request directly or instruct us to assist in some way, and in the latter case we will coordinate with them to promptly fulfill your request. We, or your Sponsor, may require you to verify your identity before fulfilling the request such as through asking you to log into the app, providing a verification code, answering security questions, or some other means. We may also deny your request when required by law or if the request would likely reveal Personal Information about another individual.
The Service may contain links or deep links to other websites, open search results, public feeds, or curated channels all of which are independent from Wellframe. Wellframe has no control and is not responsible for the content, privacy practices, or advertisements on third party websites or for any loss or damage incurred in connection with your use of such links or dealings with the operators of these non-Wellframe websites. We encourage you to review the privacy statements of each third party website. Wellframe is not responsible for any disclosures you make to third parties regarding your Personal Information, including family members or friends.
ATTN: Privacy Officer
470 Atlantic Ave. Floor 8
Boston, MA 02210, USA