Web and Mobile Privacy Policy
Effective date: 09/01/2023
Whole Health Rheumatology PLLC, makes certain telehealth related information available to you and/or facilitates your access to telemedicine, chronic condition management, and expert medical services.
This Privacy Policy applies to visitors of the following websites: www.wholehealthrheum.com.For the purposes of this Disclaimer, "you" and "your" means you as the visitor of the Websites.
Scope of this Web and Mobile Privacy Policy
This Privacy Policy describes the types of Personal Information we collect from visitors of our public Websites and our practice for using, maintaining, sharing, and protecting it. It also describes the rights and choices you may have with respect to your Personal Information and how you may contact us.
This Privacy Policy does not apply to information collected from visitors who register and log-in ("Members") to the password-protected and secure portions of our websites, including login pages and registration pages ("Secure Platforms"). The Secure Platforms allow eligible Members to use Whole Health Rheumatology PLLC Services. All information collected and stored by Whole Health Rheumatology PLLC or added by our Members into such Secure Platforms is considered Protected Health Information ("PHI") and/or medical information and is governed by laws that apply to that information, for example the Health Insurance Portability and Accountability Act (HIPAA). How Whole Health Rheumatology PLLC uses and discloses such PHI is in accordance with the Whole Health Rheumatology PLLC Notice of Privacy Practices. The Notice of Privacy Practices (and not this Privacy Policy) also applies to Personal Information collected on our websites if specific symptoms or health conditions is also collected, as such information may be considered PHI under HIPAA.
California and Virginia residents should read the information available in Sections below about the categories of personal information to be collected from them and the purposes for which the personal information will be used.
This Privacy Policy is not a contract and does not create any contractual rights or obligations.
1. TYPES OF PERSONAL INFORMATION WE COLLECT
While using our Websites, you may provide us with certain information about you. We or our advertising partners also may automatically collect information through the use of cookies and other tracking technologies (see below).
Personal Information that we collect through your use of the Websites may include IP Address, Device ID, and online identifier. We may use that Personal Information and link it to Internet or other electronic network activity information, and we may draw inferences about you from the information we collect. We may also collect your name, title, business contact information, phone number, date of birth, state, country, zip code, your health plan, email address or login identification information only if you provide such information directly to us when you begin registration to use a Secure Platform or complete a web form seeking more information. If you are a member this may be considered PHI and governed by our Notice of Privacy Practices and not this Privacy Policy.
2. HOW WE COLLECT PERSONAL INFORMATION
We may collect Personal Information using the following methods:
- Directly from you when you provide it to us (such as information you enter into web forms, inquiries, responses, activity on the Websites, and during registration to use a Secure Platform).
- From third parties, such as analytics and email marketing service providers.
- Automatically through tracking technologies such as cookies, web beacons (also known as pixels) and log files, including over time and across our own and third-party websites or other online services.
"Cookies" are small files that a website stores on a user's computer or device. The Websites may use cookies for various purposes, including to keep the information you enter on multiple pages together. Some of the cookies we use are "session" cookies, meaning that they are automatically deleted from your hard drive after you close your browser at the end of your session. Session cookies are used to optimize performance of the Websites and to limit the amount of redundant data that is downloaded during a single session. We also may use
"persistent" cookies, which remain on your computer or device unless deleted by you (or by your browser settings). We may use persistent cookies for various purposes, such as statistical analysis of performance to ensure the ongoing quality of our services. We and third parties may use session and persistent cookies for analytics and advertising purposes, as described herein. Most web browsers automatically accept cookies, but you may set your browser to block certain cookies (see below). As required under applicable laws, we will obtain your consent necessary for utilizing cookies or similar tracking technologies.
Our Websites may use Google Analytics, a vendor's service that uses cookies, web beacons, web pixels and/or similar technology to collect and store information about you. You can learn more about Google Analytics' privacy policy and ways to opt out from Google Analytics tracking by visiting Google Analytics' website.
Our Websites may use Meta, a vendor's service that uses cookies, web beacons, web pixels and/or similar technology to collect and store information about you. You can learn more about Meta’s privacy policy and ways to opt out from Meta tracking by visiting Meta website.
Our Websites may use Adobe's analytics and on-site personalization services, which use cookies, web beacons, web pixels and/or similar technology to collect and store information about you or your device or browser. You can learn more about how Adobe may handle information collected through our use of its services, and your options for controlling this activity, by visiting Adobe's website.
For more information about how we use Personal Information collected through tracking technologies and the ways you may be able to manage it, see below.
HOW WE USE YOUR INFORMATION
We may use your Personal Information for the following purposes:
- Operate, maintain, supervise, administer, and enhance the Websites, including monitoring and analyzing the effectiveness of content on the Websites, aggregate site usage data, and other usage of the Websites such as checking your eligibility and assisting you in completing the registration process.
- Provide you with a tailored and user-friendly experience as you navigate our Websites. o Promote and market our Websites to you.
- To complete the activity you specifically asked for, e.g., register on a Secure Platform, obtain more information, request a demo, or request an RFP.
- Conduct research on users' demographics, interests, and behavior based upon information provided during use of our Websites. o Aggregate information for analytics and reporting.
- Respond to law enforcement requests and court orders and legal process and carry out our legal and contractual obligations and enforce our rights.
- Authenticate use, detect potential fraudulent use, and otherwise maintain the security of the Websites and safety of users.
- Develop, test, improve, and demonstrate the Websites. o Any other purpose with your consent.
3. HOW WE SHARE YOUR INFORMATION
We may share Personal Information with third parties including service providers in certain circumstances or for certain purposes, including:
- For business purposes. We may share your Personal Information with vendors and service providers, including our data hosting and data storage partners, analytics and advertising providers, technology services and support, and data security. We also may share Personal Information with professional advisors, such as auditors, law firms, and accounting firms. We may disclose your name, email address, date of birth, phone number, and address if you provided it to us via a form on the website or during an incomplete or failed registration to Service Providers.
- With your direction or consent. We may share your Personal Information with third parties if you request or direct us to do so. This includes your use of social media widgets on our Websites.
- With affiliates within our corporate group. We may share your Personal Information with any subsidiaries or affiliates within our corporate group.
- Compliance with law. We may share your Personal Information to comply with applicable law or any obligations thereunder, including cooperation with law enforcement, judicial orders, and regulatory inquiries.
- In the context of a transaction. We may share your Personal Information in connection with an asset sale, merger, bankruptcy, or other business transaction.
- For other business reasons. We may share your Personal Information to enforce any applicable Legal Disclaimer, and to ensure the safety and security of the Websites and/or our users.
- For advertising. Using cookies and web beacons, we may disclose Personal Information regarding your activity on our Websites to third-party advertising partners to optimize marketing. See Section 7 for additional details.
We also may disclose deidentified information. Note that if you make any Personal Information publicly available on the Websites, anyone may see and use such information.
4. SOCIAL FEATURES
Certain features of the Websites permit you to initiate interactions between the Websites and third-party services or platforms, such as social networks ("Social Features"). Social Features include features that allow you to click and access Whole Health Rheumatology PLLC pages on certain third-party platforms, such as Facebook, Instagram, Youtube, Twitter, TikTok and LinkedIn as applicable, and from there to "like" or "share" our content on those platforms. Use of Social Features may entail a third party's collection and/or use of your data. If you use Social Features or similar third-party services, information you post or otherwise make accessible may be publicly displayed by the third-party service you are using. Both Whole Health Rheumatology PLLC and the third party may have access to information about you and your use of both the Websites and the third-party service. Whole Health Rheumatology PLLC has no control over and is not responsible for the privacy practices of such third parties. This Privacy Policy does not apply to the extent Whole Health Rheumatology PLLC does not own or control any linked websites or features you visit or use. We recommend that you familiarize yourself with the privacy practices of those third parties.
5. THIRD PARTY WEBSITES AND LINKS
Our Websites may contain links to other online platforms operated by third parties. We do not control such other online platforms and are not responsible for their content, their privacy policies, or their use of your information. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms (such as Facebook, Instagram, YouTube, TikTok, LinkedIn or Twitter or other social media platforms) may also be viewable by other users of the Websites and/or users of those third-party online platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators except as disclosed on the Websites. We expressly disclaim any and all liability for the actions of third parties, including but without limitation to actions relating to the use and/or disclosure of Personal Information by third parties. Any information submitted by you directly to these third parties is subject to that third party's privacy policy.
6. COOKIES AND INFORMATION USED FOR ADVERTISING
As discussed above, on our Websites we may collect and disclose Personal Information about your online activities for use in providing you with advertising about products and services tailored to your individual interests. This section of our Privacy Policy provides details and explains how to exercise your choices. You may see certain ads on other websites because we participate in advertising networks. Ad networks allow us to target our messaging to users through demographic, interest-based and contextual means. These networks track your online activities over time by collecting information through automated means, including through the use of cookies, web server logs, and web beacons (also known as pixels). The networks use this information to show you advertisements that may be tailored to your individual interests. The information our ad networks may collect includes information about your visits to websites that participate in the relevant advertising networks, such as the webpages or advertisements you view and the actions you take on the websites. This data collection takes place both on our Websites and on third-party websites that participate in the ad networks. This process also helps us track the effectiveness of our marketing efforts.
You may disable or delete browser cookies through your browser settings. Cookies generally are easy to disable or delete, but the method varies between browsers. If you disable or delete cookies, or if you are running third-party software that intercepts or deletes cookies, please note that some parts or functionality of our Websites may not work properly. Each type of web browser offers ways to restrict and delete cookies. For more information on how to manage cookies visit the appropriate link below.
Microsoft Internet Explorer
Microsoft Edge
Mozilla Firefox
Google Chrome
Apple Safari
You can opt out of third parties collecting your Personal Information for targeted advertising purposes in the United States by visiting the National Advertising Initiative's (NAI) opt-out page and the Digital Advertising Alliance's (DAA) opt-out page.
Your browser settings also may allow you to transmit a "Do Not Track" signal when you visit various websites. Some of the Websites may not be configured to respond to "Do Not Track" signals received from browsers. To learn more about "Do Not Track" signals, you can visit here.
Finally, Whole Health Rheumatology PLLC maintains a cookie preference center which allows you to customize your cookie preferences when visiting the Websites. If you have further questions regarding the specific information about you that we process or retain, as well as your choices regarding our collection and use practices, please contact us using the information listed below.
7. CHILDREN'S PRIVACY
Our Websites are not intended for children under 13 years of age, and we do not knowingly collect or sell Personal Information from children under 13. If you are under 13, do not use or provide any information on these Websites without your parent first providing consent.. If you are the parent or guardian of a child under 13 years of age whom you believe might have provided us with their Personal Information, you may contact us using the below information to request that it be deleted.
8. SECURITY OF PERSONAL INFORMATION
We take steps to secure Personal Information through administrative, technical, and physical safeguards designed to protect against the risk of accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. Unfortunately, we cannot guarantee the security of information transmitted through the Internet, and where we have given you (or where you have chosen) a password, you are responsible for keeping this password confidential.
9. RETENTION OF PERSONAL INFORMATION
We generally retain records only as long as necessary and as required for our business operations, for archival purposes, and/or to satisfy legal requirements. When determining the appropriate retention period for Personal Information, we consider various criteria, such as the amount, nature, and sensitivity of the Personal Information; potential risk of harm from unauthorized use or disclosure; purposes for which we process your Personal Information; whether we can achieve those purposes through other means; and business operations and legal requirements. Because we maintain our Websites to protect from accidental or malicious loss and destruction, residual copies of your Personal Information may be retained in our backup and archival systems for a limited period of time, after which the information will be automatically deleted or put beyond use where deletion is not possible.
10. INTERNATIONAL USERS
The Websites are controlled and operated by us from the United States and are not intended to subject us to the laws or jurisdiction of any state, country or territory other than that of the United States. Any information you provide to us through use of our Websites may be stored and processed, transferred between and accessed from the United States and other countries that may not guarantee the same level of protection of personal data as the one in which you reside. However, we will handle your Personal Information in accordance with this Privacy Policy regardless of where your Personal Information is stored/accessed.
11. NOTICE TO CALIFORNIA AND VIRGINIA RESIDENTS
If you are a California resident, certain Personal Information that we collect about you is subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
If you are a Virginia resident, certain Personal Information that we collect about you is subject to the Virginia Consumer Data Protection Act (VCDPA).
Please note that these laws may not apply to, among other things,
- Information that is lawfully made available from federal, state, or local government records; o Consumer information that is deidentified or aggregated;
o Protected health information that is collected by a covered entity or business associate governed by HIPAA; or
- Medical information maintained by a provider of health care governed by California's Confidentiality of Medical Information Act (CMIA).
Collection of Personal Information
We collect information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household—this type of information is referred to as “Personal Information,” and includes personal information as defined by CCPA/CPRA as well as personal data as defined by the VCDPA.
Personal Information does not include de-identified or aggregate information; publicly available information that is lawfully made available from federal, state, or local government records; and information covered by certain sector-specific privacy laws. Whole Health Rheumatology PLLC collects the following categories of Personal Information about consumers (and to the extent such Personal Information is subject to the CCPA/CPRA, these categories were collected in the preceding 12 months):
- Identifiers, Internet Protocol (IP) address, online identifier, device identifier. We may collect your name, email address, date of birth, phone number, and address only if you provided it to us via a form on the website or during an incomplete or failed registration. o Commercial information, business contact information if you have provided it to us via a form (such to register for services, obtain more information, request a demo, request an RFP) on the website, including name, company name, physical address, email address, telephone, and fax number; information on actions taken on our Websites, which may include information about Websites considered and information about preferences and behavior that we collect on our Websites or purchase from third parties in order to target consumers for digital advertisements or to personalize content we deliver on our Websites.
- Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with the Websites, applications, or advertisements.
Whole Health Rheumatology PLLC does not collect or share Personal Information on the Websites from any person we know to be under the age of 16.
Whole Health Rheumatology PLLC does not collect Sensitive Personal Information, as those terms are defined under the CCPA/CPRA and the VCDPA, of consumers who visit our public Websites.
Whole Health Rheumatology PLLC collects Personal Information from the following categories of sources:
- Directly and indirectly from you, including through your interaction with the Websites o Social media platforms
- Third party partners such as analytics or marketing providers
- Automatically through tracking technologies. Please note, if you have enabled a Global Privacy Control on your browser, our Websites are configured to recognize and respect those preferences with respect to Personal Information that falls under the CCPA/CPRA. We may use your Personal Information for the following purposes:
- Operate, maintain, supervise, administer, and enhance the Websites, including monitoring and analyzing the effectiveness of content on the Websites, aggregate site usage data, and other usage of the Websites such as checking your eligibility and assisting you in completing the registration process. - Provide you with a tailored and user-friendly experience as you navigate our Websites.
- Promote and market our Websites to you.
- To complete the activity you specifically asked for, e.g., register on a Secure Platform, obtain more information, request a demo, or request an RFP.
- Conduct research on users' demographics, interests, and behavior based upon information provided during use of our Websites. o Aggregate information for analytics and reporting.
- Respond to law enforcement requests and court orders and legal process and carry out our legal and contractual obligations and enforce our rights.
- Authenticate use, detect potential fraudulent use, and otherwise maintain the security of the Websites and safety of users.
- Develop, test, improve, and demonstrate the Websites. o Any other purpose with your consent.
Whole Health Rheumatology PLLC will retain and/or archive Personal Information for a period of time no longer than required by applicable law or no longer than is necessary and proportionate to achieve purposes compatible with the context in which the Personal Information is collected. Whole Health Rheumatology PLLC will not further process Personal Information in a manner incompatible with the purposes noted above.
Disclosure of Personal Information in the Preceding 12 Months
Whole Health Rheumatology PLLC discloses Personal Information with the following categories of third parties and has disclosed the following categories of Personal Information for a business purpose, for commercial purpose, to comply with the law, in the context of a transaction, or for other business reasons:
Personal Information Third Parties
Identifiers-----We may disclose IP address, device ID, or online identifier to service providers, advertising networks, internet service providers, and/or data analytics providers. We may disclose name, email address, date of birth, phone number, and address if you provided it to us via form on the website or during an incomplete or failed registration to Service providers. We may engage in delivering online advertising that is tailored to your interests using analytics and/or targeting cookies however we do not disclose your name, address, or phone number. Before using analytics and/or targeting cookies, the Websites deploy a banner seeking your consent, or opt-in, to the use of such cookies.
Commercial information---- Service providers
Internet or other electronic network activity information------ Service providers, advertising networks, internet service providers, and/or data analytics providers
To the extent such Personal Information is subject to the CCPA/CPRA, these disclosures occurred in the preceding 12 months.
You may have the following rights regarding your Personal Information maintained by Whole Health Rheumatology PLLC:
- Request to know and access the Personal Information we collect, use, and disclose; o Request deletion of Personal Information; o Request to Opt-out of the sale or sharing of Personal Information; o Right to Limit Use and Disclosure of Sensitive Personal Information and
- Not receive discriminatory treatment by Whole Health Rheumatology PLLC for exercising these rights.
The rights described below are limited to those provided under the CCPA/CPRA and VCDPA to the applicable residents of those states. The specific rights may vary based on whether the CCPA/CPRA or VCDPA applies, and should you have any questions regarding your rights, please contact us as per the information in Section 14.
Requests to Know and Access
You may have the right to request that we disclose to you the following information:
- Categories of Personal Information that Whole Health Rheumatology PLLC has collected about you, disclosed about you for a business purpose, or sold or shared;
- Categories of sources from which the Personal Information is collected;
- Categories of third parties with whom Whole Health Rheumatology PLLC shares or to whom
Whole Health Rheumatology PLLC sells Personal Information; o The business or commercial purpose for collecting and selling Personal Information; and o Specific pieces of Personal Information that Whole Health Rheumatology PLLC has collected about you.
Instructions for submitting a verifiable request are provided below.
You may only make a request for access twice within a 12-month period.
Requests to Delete
You may have the right to request that we delete Personal Information associated with you, subject to applicable law and certain exceptions. Instructions for submitting a verifiable request are provided below.
Request to Correct Inaccurate Personal Information
You may have the right to request that Whole Health Rheumatology PLLC corrects Personal Information that is inaccurate. Instructions for submitting a verifiable request are provided below.
Requests to Opt Out of the Sale or Sharing of your Personal Information
You may have the right to submit a request to opt out of any sale or sharing of your Personal Information or the processing of your Personal Information for purposes of targeted advertising. However, Whole Health Rheumatology PLLC does not sell your Personal Information and does not use or share Personal Information collected from users of our public websites to engage in targeted advertising unless you have opted-in to such use. And, in the last 12 month, Whole Health Rheumatology PLLC has not "sold" or "shared" Personal Information (as those terms are defined under the CCPA/CPRA). Instructions for submitting a verifiable request are provided below.
How to Exercise Your Rights
To submit a request to exercise any of your rights, email our Privacy Officer Olga Pinkston, MD [email protected] or call our office number listed 502-429-6049.
As required under applicable law, we must take steps to verify your request before we can provide Personal Information to you, delete Personal Information, or otherwise process your request. To verify your request, we may require you to provide your name, physical address, email address, contact information, and information about your account or previous transactions with us. If you have only visited our public Websites and did not provide any Personal Information to us via a web form or through the registration process, we will need you to provide us with your IP address or device ID in order for us to determine if we have that information. We will not be able to determine if we have your IP address or device ID from your name, physical address, email address, contact information, or account information.
We will further verify and respond to your request consistent with applicable law, taking into account the type and sensitivity of the Personal Information subject to the request. We may need to request additional Personal Information from you, such as your date of birth or government identifier, in order to protect against fraudulent requests.
We will deliver Personal Information that we are required by law to disclose to you in the manner required by law within 45 days after receipt of a verifiable request, unless we notify you that we require additional time to respond, in which case we will respond within such additional period of time required by law. We may deliver the Personal Information to you electronically or by mail at your option. If electronically, then we will deliver the information in a portable and, to the extent technically feasible, in a readily useable format that allows you to transmit the information from one entity to another without hindrance.
Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your Personal Information. You may designate an authorized agent to request any of the above rights on your behalf. You may make such a designation by providing the agent with written permission, signed by you, to act on your behalf. Your agent may contact us by the information provided in the "How to Contact Us" section below to make a request on your behalf. Even if you choose to use an agent, we may, as permitted by law, require verification of the agent's authorization to act on your behalf, require you to confirm you have authorized the agent to act on your behalf, or require you to verify your own identity.
Right to Nondiscrimination
You have the right to be free from discriminatory treatment for exercising the privacy rights conferred by applicable law, including not being: denied goods or services; charged different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties; provided a different level or quality of goods or services; or suggested that you will receive a different price or rate for goods or services or a different level or quality of goods or services.
12. UPDATING THIS PRIVACY POLICY
This Privacy Policy may be updated periodically to reflect changes in our privacy practices. It is your responsibility to review the Privacy Policy from time to time to view any such changes.
13. HOW TO CONTACT US
Should you have any questions about our privacy practices or this Privacy Policy, please email us at [email protected]
Accessibility Statement
Whole Health Rheumatology PLLC is committed to ensuring digital accessibility for people of all abilities. If you are having difficulty viewing or navigating the content on this website, or notice any content, feature, or functionality that you believe is not fully accessible to people with disabilities, please email us at us at [email protected] and provide a description of the specific feature you feel is not fully accessible or a suggestion for improvement. We take your feedback seriously and will consider it as we evaluate ways to accommodate all of our customers and our overall accessibility policies.
Whole Health Rheumatology PLLC SHALL NOT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES THAT RESULT FROM THE USE OF, OR THE INABILITY TO USE, THIS WEBSITE, INCLUDING ITS MATERIALS, PRODUCTS OR SERVICES, OR THIRD-PARTY MATERIALS, PRODUCTS OR SERVICES MADE AVAILABLE THROUGH THIS WEBSITE.
These Terms shall be governed by and construed in accordance with the laws of the State of Kentucky, without giving effect to its conflict of laws. The nearest state and federal court to Louisville, Kentucky shall have exclusive jurisdiction over any case or controversy arising from or relating to this website, including but not limited to the Privacy Policy or these Terms. By using this website, you hereby submit to the exclusive jurisdiction and venue of these courts and consent irrevocably to personal jurisdiction in such courts and waive any defense of forum non conveniens.
Whole Health Rheumatology PLLC controls and operates this website from offices in the United States. Whole Health Rheumatology PLLC does not represent that materials on this website are appropriate or available for use in other locations. People who choose to access this website from other locations do so on their own initiative and are responsible for compliance with local laws, if and to the extent local laws are applicable.
Whole Health Rheumatology PLLC may change, modify or update these Terms at any time without notice. Any access or use of this website by you after Whole Health Rheumatology PLLC posts such changes shall constitute consent of such modifications. If you have any questions or concerns about these Terms, contact [email protected]
INDEMNITY
You agree to defend, indemnify and hold harmless Whole Health Rheumatology PLLC and any directors, officers, agents, contractors, partners, assigns, successors-in-interest and its and their employees from and against any and all claims, damages, obligations, losses, liabilities, costs, debt and expenses (including but not limited to attorney’s fees) arising from or in connection with: (i) your use of this website in violation of these Terms of Use, (ii) any breach by you of these Terms of Use or any representation and warranty made by you herein, (iii) any comment, post, or material you submit to this website, (iv) your use of materials or features available on this website (except to the extent a claim is based upon infringement of a third-party right by materials created by Whole Health Rheumatology PLLC or (v) a violation by you of applicable law or any agreement or terms with a third party to which you are subject.
Updated on 10/11/2024