Last updated on August 22, 2019. You can find previous versions in the archive.
- collecting, storing and using your personal information to provide you with the service accessed through this mobile application. We may use third parties to help provide this service to you on our behalf and may share your personal information with them for this purpose, including our cloud host provider. These third parties are contractually bound to protect your personal information;
- disclosing your personal information to your health care professionals and providers;
- transferring your personal information to and hosting your Personal Information in data centers within the United States of America or the European Union;
- de-identifying your personal information (so it no longer identifies you) and providing it in aggregated or non-aggregated form to selected third parties, including our healthcare partners and/or any of their affiliates; and
- disclosing your Personal Information to the extent required by law.
INFORMATION COLLECTION AND USE
Below are the categories of Personal Information that we collect about you and how we use your Personal Information. Some information may fall under multiple categories and uses. You may be asked additional questions regarding items on this list to ensure we have your consent to collect and use your Personal Information for specific purposes.
What information Wellframe collects
- Information you provide: We may ask and collect information such as your name, email address, phone number, address, birthdate, and gender to register your account. We use this information to manage your account, verify your identity, and deliver to you the Services. Additionally, we collect the content of the communications you make through the use of our Services.
- Information we receive from third parties: We may receive information about you, including what is listed in other categories, from your Sponsor. This information may include additional demographic information about you, medical history, health insurance information, or other information that your Sponsor has decided to share with us. We use this information to fulfill contractual obligations to your Sponsor and to deliver the Service to you. The collection and sharing of this information is controlled by your Sponsor.
- Health Information: Since we are a health related application, we collect information about your health. This category can include diagnoses, symptoms, medical procedures, medications, discharge dates, clinical notes, physical characteristics, and provider information. We use this information to provide the Service to you such as using your medication information to provide medication notifications.
- Communications: We collect the content of communications you make through our Service including the communications of your Sponsor to you. This content can include information under other categories as well as any other information you decide to share through our Service. We use this content to provide you a record of your communications as well use it in de-identified form as discussed below.
- Integration data: We may use automated methods to track data from fitness wearables, biometric monitoring devices, and other integrations that you have allowed to communicate with our Service. This integration data is then contained in our application for both you and your Sponsor to see and use.
- Analytics information: We may collect usage data about how you use our Service such as how you use the application, what content you read and favorite, content of messages, and device information. We use this analytics information to improve the Service for you and other users.
- Log files: To maintain security and protect both our Service and your data, we collect information such as IP addresses, server requests, login events, device information, crash reports, usage activity, or other information to discover and respond to events to protect our product from security threats, fraud, or other illegal activity. We may also use this information to enforce our EULA, compliance, and other legal obligations. Where feasible we limit the identifiable and sensitive information contained in these log files.
- Support information: If you contact us regarding questions, issues, or requests regarding the use of our Services, our support team may view your Personal Information, as well as any additional information you provide, in order to assist. We may also ask follow-up questions to gather more information as necessary to address your issue. This information is stored as a record of your support request.
- Optional information: We may also ask and collect additional information, with your consent, that is not necessary for use of our Services such as product feedback, surveys, usage analytics, and testimonials. We use this information to improve and market our Service. Your Sponsor may request this information as well to improve their products and services. You have the right to object to processing of your personal data for direct marketing purposes by contacting email@example.com or by using the “unsubscribe” button in the email.
Wellframe does not rent, lease, or sell your Personal Information. Wellframe shares your Personal Information to provide the Service, with your consent, or when legally required. For your Sponsor, we share your Personal Information to allow interaction between you through the Service, for reports, fulfill contractual obligations, and to fulfill regulatory or legal requirements. To provide the Service, we share your data with our cloud hosting provider and other third party providers as necessary for functionality. In response to a legal process, such as a law enforcement action or a subpoena, we may be required to share your Personal Information as well. Finally, we may transfer your Personal Information to an entity or individual that acquires, buys, or merges with Wellframe, or through some other business reorganization.
In addition to the categories and uses above, we may remove the identifiable parts of your Personal Information to create de-identified or pseudonymized information (“De-identified Information”). De-identified Information may be combined with other data into aggregated datasets. We use De-identified Information in the following ways:
- Disclosure for Business Purposes: We may license, sell or otherwise share De-identified Information with institutional clients, partners, investors and contractors for any purposes related to our business practices.
- Product Improvement: We may use De-identified Information for product improvement including the Service as well as third-parties to evaluate their products or services.
- Research: We may use De-identified Information for research whether scientific, marketing, or business in nature. This research may be made public through publications such as within a scientific journal.
STORAGE AND RETENTION
Your information will be stored in our cloud hosting provider’s data centers within the United States or the European Union depending on your country of residence or by how you were given access to the Services, such as through your healthcare provider, your sponsor, or through the program or study you enrolled in. We retain your data for as long as reasonably necessary to provide you the Services or to comply with applicable law.
CONFIDENTIALITY AND SECURITY
Wellframe has a legal duty to protect your Personal Information. We have put in place reasonable physical, technical, and administrative controls to safeguard and help prevent unauthorized access, maintain data security, and correctly use your Personal Information. Third party service providers undergo a vetting process and sign confidentiality agreements before we utilize them to provide the Service. Some of these security measures rely upon you. Please keep your login credentials secret, avoid public WiFi networks, and log out of any shared devices. If you ever suspect a security issue with your account, contact firstname.lastname@example.org immediately.
Wellframe does not knowingly collect Personal Information from children under the age of 13, and our Service is not directed at users under the age of 13. If we find that Personal Information has inadvertently been collected for an individual under the age of 13, we will immediately delete it.
RIGHTS TO PERSONAL INFORMATION
You may request access, changes, or deletions to your Personal Information and request information about our collection, use and disclosure of such information by contacting us at email@example.com. We use best efforts to keep our records as accurate and complete as possible. You can help us maintain the accuracy of your information by notifying us of any changes to your Personal Information as soon as possible. Your rights to access, change, or delete your Personal Information are not absolute. Some requests may need to go through your Sponsor and your Sponsor may deny, modify, or fulfill the request themselves. We may also deny you such rights when required by law or if the request would likely reveal Personal Information about a third party.
For EU and UK users, Wellframe commits to responding to your inquiry or complaint about your Personal Information within thirty (30) days. If your privacy complaints remain unresolved, Wellframe has further committed to referring them to the JAMS EU-US Privacy Shield Program, an alternative dispute resolution provider located in the United States. The services of JAMS are provided at no cost to you and is available at https://www.jamsadr.com/eu-us-privacy-shield. Please note that if your complaint is not resolved through these channels, as a last resort and under limited circumstances, a binding arbitration option may be available before a Privacy Shield panel.
The Wellframe Service may contain links or deep links to other websites, open search results, public feeds, or curated channels. Wellframe generally reviews the content of health news articles or publications linked through third party websites, but is not responsible for such content, privacy practices, or any advertisements on third party websites. Users should be aware of this when they leave our Service and are encouraged to review the privacy statements of each third party website. Wellframe is not responsible for any disclosures you make directly to third parties regarding your personal information, including family members and/or friends.
ATTN: Privacy Officer
321 Summer St. Floor 7
Boston, MA 02210, USA
Our Data Protection Officer for EU and UK users is Arno Schlösser, DP-Dock GmbH, firstname.lastname@example.org.