Sobriety Health LLC DBA SobrietyMeds Privacy Policy

Your privacy is important to us. It is Sobriety Health LLC DBA SobrietyMeds' policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, including across our website, https://www.sobrietymeds.com, and other sites we own and operate.

Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and even information about how you use a website or online service.

In the event our site contains links to third-party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third-party content, you should read their posted privacy policy information about how they collect and use personal information. This Privacy Policy does not apply to any of your activities after you leave our site.

This policy is effective as of June 1, 2025

Last updated: August 22, 2025

Information We Collect

Information we collect falls into one of two categories: “voluntarily provided” information and “automatically collected” information.

“Voluntarily provided” information refers to any information you knowingly and actively provide us when using or participating in any of our services and promotions.

“Automatically collected” information refers to any information automatically sent by your devices in the course of accessing our products and services.

Log Data

When you visit our website, our servers may automatically log the standard data provided by your web browser. It may include your device’s Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details about your visit.

Additionally, if you encounter certain errors while using the site, we may automatically collect data about the error and the circumstances surrounding its occurrence. This data may include technical details about your device, what you were trying to do when the error happened, and other technical information relating to the problem. You may or may not receive notice of such errors, even in the moment they occur, that they have occurred, or what the nature of the error is.

Please be aware that while this information may not be personally identifying by itself, it may be possible to combine it with other data to personally identify individual persons.

Device Data

When you visit our website or interact with our services, we may automatically collect data about your device, such as:

  • Device type
  • Operating system
  • Unique device identifiers
  • Device settings
  • Geo-location data

Data we collect can depend on the individual settings of your device and software. We recommend checking the policies of your device manufacturer or software provider to learn what information they make available to us.

Personal Information

We may ask for personal information — for example, when you subscribe to our newsletter or when you contact us — which may include one or more of the following:

  • Name
  • Email
  • Social media profiles
  • Date of birth
  • Phone/mobile number
  • Home/mailing address

Sensitive Information

“Sensitive information” or “special categories of data” is a subset of personal information that is given a higher level of protection. Examples of sensitive information include information relating to your racial or ethnic origin, political opinions, religion, trade union or other professional associations or memberships, philosophical beliefs, sexual orientation, sexual practices or sex life, criminal records, health information, or biometric information.

The types of sensitive information that we may collect about you include:

  • Racial or ethnic origin
  • Health information
  • Biometric information

We will not collect sensitive information about you without first obtaining your consent, and we will only use or disclose your sensitive information as permitted, required, or authorized by law.

User-Generated Content

We consider “user-generated content” to be reviews, ratings, image, and/or video materials voluntarily supplied to us by our users for the purpose of publication on our website or re-publishing on our social media channels. All user-generated content is associated with the account or email address used to submit the materials.

Please be aware that any content you submit for the purpose of publication will be public after posting (and subsequent review or vetting process). Once published, it may be accessible to third parties not covered under this privacy policy.

Legitimate Reasons for Processing Your Personal Information

We only collect and use your personal information when we have a legitimate reason for doing so. In which instance, we only collect personal information that is reasonably necessary to provide our services to you.

Collection and Use of Information

We may collect personal information from you when you do any of the following on our website:

  • Register for an account
  • Purchase any products and/or services
  • Purchase a subscription
  • Enter any of our competitions, contests, sweepstakes, and surveys
  • Sign up to receive updates from us via email or social media channels
  • Use a mobile device or web browser to access our content
  • Contact us via email, social media, or on any similar technologies
  • When you mention us on social media

We may collect, hold, use, and disclose information for the following purposes, and personal information will not be further processed in a manner that is incompatible with these purposes:

  • to provide you with our platform's core features and services
  • to enable you to customize or personalize your experience of our website
  • to process any transactional or ongoing payments
  • to deliver products and/or services to you
  • to contact and communicate with you
  • for analytics, market research, and business development, including to operate and improve our website, associated applications, and associated social media platforms
  • for advertising and marketing, including to send you promotional information about our products and services and information about third parties that we consider may be of interest to you
  • to consider your employment application
  • to enable you to access and use our website, associated applications, and associated social media platforms
  • for internal record keeping and administrative purposes
  • to run competitions, sweepstakes, and/or offer additional benefits to you
  • to comply with our legal obligations and resolve any disputes that we may have
  • to attribute any content (e.g. posts and comments) you submit that we publish on our website
  • for security and fraud prevention, and to ensure that our sites and apps are safe, secure, and used in line with our terms of use
  • for technical assessment, including to operate and improve our app, associated applications, and associated social media platforms

We may combine voluntarily provided and automatically collected personal information with general information or research data we receive from other trusted sources. For example, if you provide us with your location, we may combine this with general information about currency and language to provide you with an enhanced experience of our site and service.

Security of Your Personal Information

When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification.

Although we will do our best to protect the personal information you provide to us, we advise that no method of electronic transmission or storage is 100% secure and no one can guarantee absolute data security.

You are responsible for selecting any password and its overall security strength, ensuring the security of your own information within the bounds of our services. For example, ensuring any passwords associated with accessing your personal information and accounts are secure and confidential.

How Long We Keep Your Personal Information

We keep your personal information only for as long as we need to. This time period may depend on what we are using your information for, in accordance with this privacy policy. For example, if you have provided us with personal information as part of creating an account with us, we may retain this information for the duration your account exists on our system. If your personal information is no longer required for this purpose, we will delete it or make it anonymous by removing all details that identify you.

However, if necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation or for archiving purposes in the public interest, scientific, or historical research purposes or statistical purposes.

Children’s Privacy

We do not aim any of our products or services directly at children under the age of 13 and we do not knowingly collect personal information about children under 13.

Disclosure of Personal Information to Third Parties

We may disclose personal information to:

  • a parent, subsidiary or affiliate of our company
  • third-party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, ad networks, analytics, error loggers, debt collectors, maintenance or problem-solving providers, marketing providers, professional advisors, and payment systems operators
  • our employees, contractors, and/or related entities
  • our existing or potential agents or business partners
  • sponsors or promoters of any competition, sweepstakes, or promotion we run
  • credit reporting agencies, courts, tribunals, and regulatory authorities, in the event you fail to pay for goods or services we have provided to you
  • courts, tribunals, regulatory authorities, and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise, or defend our legal rights
  • third parties, including agents or sub-contractors who assist us in providing information, products, services, or direct marketing to you
  • third parties to collect and process data
  • an entity that buys, or to which we transfer all or substantially all of our assets and business

Third parties we currently use include:

  • Google Analytics
  • MailChimp
  • Intercom
  • Klaviyo
  • SendGrid
  • Stripe
  • li>Metali>Twilio

International Transfers of Personal Information

The personal information we collect is stored and/or processed in United States, or where we or our partners, affiliates, and third-party providers maintain facilities.

The countries to which we store, process, or transfer your personal information may not have the same data protection laws as the country in which you initially provided the information. If we transfer your personal information to third parties in other countries: (i) we will perform those transfers in accordance with the requirements of applicable law; and (ii) we will protect the transferred personal information in accordance with this privacy policy.

Your Rights and Controlling Your Personal Information

Your choice: By providing personal information to us, you understand we will collect, hold, use, and disclose your personal information in accordance with this privacy policy. You do not have to provide personal information to us, however, if you do not, it may affect your use of our website or the products and/or services offered on or through it.

Information from third parties: If we receive personal information about you from a third party, we will protect it as set out in this privacy policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person’s consent to provide the personal information to us.

Marketing permission: If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by contacting us using the details below.

Access: You may request details of the personal information that we hold about you.

Correction: If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, please contact us using the details provided in this privacy policy. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading, or out of date.

Non-discrimination: We will not discriminate against you for exercising any of your rights over your personal information. Unless your personal information is required to provide you with a particular service or offer (for example processing and fulfilling orders), we will not deny you goods or services and/or charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties, or provide you with a different level or quality of goods or services.

Notification of data breaches: We will comply with laws applicable to us in respect of any data breach.

Complaints: If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint.

Unsubscribe: To unsubscribe from our email database or opt-out of communications (including marketing communications), please contact us using the details provided in this privacy policy, or opt-out using the opt-out facilities provided in the communication. We may need to request specific information from you to help us confirm your identity.

Use of Cookies

We use "cookies" to collect information about you and your activity across our site. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit, so we can understand how you use our site. This helps us serve you content based on preferences you have specified.

Please refer to our Cookie Policy for more information.

Business Transfers

If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data, including your personal information, among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may, to the extent permitted by applicable law, continue to use your personal information according to this policy, which they will be required to assume as it is the basis for any ownership or use rights we have over such information.

Limits of Our Policy

Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.

Changes to This Policy

At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at the same link by which you are accessing this privacy policy.

If the changes are significant, or if required by applicable law, we will contact you (based on your selected preferences for communications from us) and all our registered users with the new details and links to the updated or changed policy.

If required by law, we will get your permission or give you the opportunity to opt in to or opt out of, as applicable, any new uses of your personal information.

Additional Disclosures for General Data Protection Regulation (GDPR) Compliance (EU)

Data Controller / Data Processor

The GDPR distinguishes between organisations that process personal information for their own purposes (known as "data controllers") and organisations that process personal information on behalf of other organisations (known as "data processors"). We, Sobriety Health LLC DBA SobrietyMeds, located at the address provided in our Contact Us section, are a Data Controller and/or Processor with respect to the personal information you provide to us.

Legal Bases for Processing Your Personal Information

We will only collect and use your personal information when we have a legal right to do so. In which case, we will collect and use your personal information lawfully, fairly, and in a transparent manner. If we seek your consent to process your personal information, and you are under 16 years of age, we will seek your parent or legal guardian’s consent to process your personal information for that specific purpose.

Our lawful bases depend on the services you use and how you use them. This means we only collect and use your information on the following grounds:

Consent From You

Where you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time using the facilities we provide; however this will not affect any use of your information that has already taken place. You may provide a physical address for the purpose of receiving orders. While you may change or delete this address at any time, this will not affect orders that have already been sent. If you have any further enquiries about how to withdraw your consent, please feel free to enquire using the details provided in the Contact Us section of this privacy policy.

Performance of a Contract or Transaction

Where you have entered into a contract or transaction with us, or in order to take preparatory steps prior to our entering into a contract or transaction with you. For example, if you purchase a product, service, or subscription from us, we may need to use your personal and payment information in order to process and deliver your order.

Our Legitimate Interests

Where we assess it is necessary for our legitimate interests, such as for us to provide, operate, improve and communicate our services. We consider our legitimate interests to include research and development, understanding our audience, marketing and promoting our services, measures taken to operate our services efficiently, marketing analysis, and measures taken to protect our legal rights and interests.

Compliance with Law

In some cases, we may have a legal obligation to use or keep your personal information. Such cases may include (but are not limited to) court orders, criminal investigations, government requests, and regulatory obligations. If you have any further enquiries about how we retain personal information in order to comply with the law, please feel free to enquire using the details provided in the Contact Us section of this privacy policy.

International Transfers Outside of the European Economic Area (EEA)

We will ensure that any transfer of personal information from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means.

Your Rights and Controlling Your Personal Information

Restrict: You have the right to request that we restrict the processing of your personal information if (i) you are concerned about the accuracy of your personal information; (ii) you believe your personal information has been unlawfully processed; (iii) you need us to maintain the personal information solely for the purpose of a legal claim; or (iv) we are in the process of considering your objection in relation to processing on the basis of legitimate interests.

Objecting to processing: You have the right to object to processing of your personal information that is based on our legitimate interests or public interest. If this is done, we must provide compelling legitimate grounds for the processing which overrides your interests, rights, and freedoms, in order to proceed with the processing of your personal information.

Data portability: You may have the right to request a copy of the personal information we hold about you. Where possible, we will provide this information in CSV format or other easily readable machine format. You may also have the right to request that we transfer this personal information to a third party.

Deletion: You may have a right to request that we delete the personal information we hold about you at any time, and we will take reasonable steps to delete your personal information from our current records. If you ask us to delete your personal information, we will let you know how the deletion affects your use of our website or products and services. There may be exceptions to this right for specific legal reasons which, if applicable, we will set out for you in response to your request. If you terminate or delete your account, we will delete your personal information within 90 days of the deletion of your account. Please be aware that search engines and similar third parties may still retain copies of your personal information that has been made public at least once, like certain profile information and public comments, even after you have deleted the information from our services or deactivated your account.

Additional Disclosures for U.S. States Privacy Law Compliance.

The following section includes provisions that comply with the privacy laws of these states (California, Colorado, Delaware, Florida, Virginia, and Utah) and is applicable only to the residents of those states. Specific references to a particular state (in a heading or in the text) are only a reference to that state's law and applies only to that state's residents. Non-state specific language applies to all of the states listed above.

Do Not Track

Some browsers have a "Do Not Track" feature that lets you tell websites that you do not want to have your online activities tracked. At this time, we do not respond to browser "Do Not Track" signals.

We adhere to the standards outlined in this privacy policy, ensuring we collect and process personal information lawfully, fairly, transparently, and with legitimate, legal reasons for doing so.

Cookies and Pixels

At all times, you may decline cookies from our site if your browser permits. Most browsers allow you to activate settings on your browser to refuse the setting of all or some cookies. Accordingly, your ability to limit cookies is based only on your browser’s capabilities. Please refer to the Cookies section of this privacy policy for more information.

California Privacy Laws - CPPA

Under California Civil Code Section 1798.83, if you live in California and your business relationship with us is mainly for personal, family, or household purposes, you may ask us about the information we release to other organizations for their marketing purposes. In accordance with your right to non-discrimination, we may offer you certain financial incentives permitted by the California Consumer Privacy Act, and the California Privacy Rights Act (collectively, CCPA) that can result in different prices, rates, or quality levels for the goods or services we provide. Any CCPA-permitted financial incentive we offer will reasonably relate to the value of your personal information, and we will provide written terms that describe clearly the nature of such an offer. Participation in a financial incentive program requires your prior opt-in consent, which you may revoke at any time.

Under California Civil Code Section 1798.83, if you live in California and your business relationship with us is mainly for personal, family, or household purposes, you may ask us about the information we release to other organizations for their marketing purposes. To make such a request, please contact us using the details provided in this privacy policy with “Request for California privacy information” in the subject line. You may make this type of request once every calendar year. We will email you a list of categories of personal information we revealed to other organisations for their marketing purposes in the last calendar year, along with their names and addresses. Not all personal information shared in this way is covered by Section 1798.83 of the California Civil Code.

California Notice of Collection

In the past 12 months, we have collected the following categories of personal information enumerated in the CCPA:

  • Identifiers, such as name, email address, phone number, account name, IP address, and an ID or number assigned to your account.
  • Customer records, such as billing and shipping address, and credit or debit card data.
  • Demographics, such as your age or gender. This category includes data that may qualify as protected classifications under other California or federal laws.
  • Commercial information, such as products or services history and purchases.
  • Internet activity, such as your interactions with our service.
  • Audio or visual data, such as photos or videos you share with us or post on the service.
  • Geolocation data.
  • Employment and education data, such as data you provide when you apply for a job with us.
  • Inferences, such as information about your interests, preferences and favorites.

For more information on information we collect, including the sources we receive information from, review the “Information We Collect” section. We collect and use these categories of personal information for the business purposes described in the “Collection and Use of Information” section, including to provide and manage our Service.

Right to Know and Delete

You have rights to delete your personal information we collected and know certain information about our data practices in the preceding 12 months. In particular, you have the right to request the following from us:

  • The categories of personal information we have collected about you;
  • The categories of sources from which the personal information was collected;
  • The categories of personal information about you we disclosed for a business purpose or sold;
  • The categories of third parties to whom the personal information was disclosed for a business purpose or sold;
  • The business or commercial purpose for collecting or selling the personal information; and
  • The specific pieces of personal information we have collected about you.

To exercise any of these rights, please contact us using the details provided in this privacy policy.

Shine the Light

In addition to the rights discussed above, you have the right to request information from us regarding the manner in which we share certain personal information as defined by applicable statute with third parties and affiliates for their own direct marketing purposes.

To receive this information, send us a request using the contact details provided in this privacy policy. Requests must include “Privacy Rights Request” in the first line of the description and include your name, street address, city, state, and ZIP code.

Contact Us

For any questions or concerns regarding your privacy, you may contact our privacy officer using the following details:

privacy@sobrietymeds.com
+1 (386) 284-2069

Privacy Compliance

We adhere to all privacy laws and regulations, including the Health Insurance Portability and Accountability Act (HIPAA) for US-based operations. All transmissions of Protected Health Information (PHI) are encrypted using Secure-Socket Layer (SSL) technology.

Licensure or Registration

All pharmacies and medical practitioners associated with Sobriety Health LLC doing business as SobrietyMeds are licensed or registered in all required jurisdictions.

Legal Compliance

Sobriety Health LLC doing business as SobrietyMeds complies with all applicable laws and regulations, including state laws, the Federal Food, Drug, and Cosmetic Act, and the Federal Controlled Substances Act.

BELUGA HEALTH FULL PRIVACY POLICY
Version 2
Last Updated: Feb 7, 2025

WE AT BELUGA HEALTH, P.A. ("We", "Us", or "Beluga") VALUE YOUR PRIVACY AND ARE COMMITTED TO KEEPING YOUR ("You/Your") PERSONAL DATA CONFIDENTIAL.

WE USE YOUR DATA SOLELY IN THE CONTEXT OF PROVIDING A WEB PORTAL ("WEB PORTAL") AND VARIOUS RELATED SERVICES DEFINED BELOW ("SERVICES") TO SUPPORT THE DELIVERY OF REMOTE CLINICAL CARE AND PRESCRIPTION SERVICES BY QUALIFIED PHYSICIANS ("PROVIDER USERS") TO PATIENTS OF BELUGA HEALTH ("PATIENT USERS").

YOU ARE EITHER A PATIENT USER OR A PROVIDER USER.

THE SERVICES INCLUDE, IN ADDITION TO THE WEB PORTAL, THE FACILITATION OF (1) SECURE INFORMATION COLLECTION, (2) SHORT MESSAGE SERVICE ("SMS") AND MULTIMEDIA MESSAGING SERVICE ("MMS") COMMUNICATIONS BETWEEN PATIENTS AND PROVIDERS, AND (3) ELECTRONIC PRESCRIBING OF MEDICATIONS.

THIS PRIVACY POLICY APPLIES TO PERSONAL DATA BELUGA COLLECTS FROM USERS OF THE SERVICES.

"PERSONAL DATA" INCLUDES ANY INFORMATION THAT CAN BE USED ON ITS OWN OR WITH OTHER INFORMATION IN COMBINATION TO IDENTIFY OR CONTACT ONE OF OUR PATIENT OR PROVIDER USERS.

WE BELIEVE THAT TRANSPARENCY ABOUT THE USE OF YOUR PERSONAL INFORMATION IS OF UTMOST IMPORTANCE.

IN THIS PRIVACY POLICY, WE PROVIDE YOU DETAILED INFORMATION ABOUT OUR COLLECTION, USE, MAINTENANCE, AND DISCLOSURE OF YOUR PERSONAL DATA. THE POLICY EXPLAINS WHAT KIND OF INFORMATION WE COLLECT, WHEN AND HOW WE MIGHT USE THAT INFORMATION, HOW WE PROTECT THE INFORMATION, AND YOUR RIGHTS REGARDING YOUR PERSONAL INFORMATION.

SOME OF THE PERSONAL DATA WE COLLECT AND TRANSMIT WILL, IN SOME CIRCUMSTANCES, BE CONSIDERED "HEALTH DATA" (data related to a Patient User's physical or mental health) or "Protected Health Information" (information that relates to the past, present, or future physical or mental health or condition of a Patient User; the provision of health care to a Patient User; or the past, present, or future payment for the provision of health care to a Patient User).

THEREFORE, OUR PRIVACY PRACTICES ARE INTENDED TO COMPLY WITH THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT ("HIPAA") AND WITH STATE LAW RELATED TO HEALTH DATA, WHERE APPLICABLE.

FOR ADDITIONAL INFORMATION RELATED TO YOUR HEALTHCARE INFORMATION, PLEASE CONTACT OUR PRIVACY OFFICER AT security@belugahealth.com.

BY SUBMITTING YOUR PERSONAL DATA THROUGH THIS WEB PORTAL OR THROUGH THE SERVICES, YOU ARE ACKNOWLEDGING THAT YOU HAVE READ AND AGREE TO THE TERMS OF THIS POLICY. IF YOU DO NOT AGREE, PLEASE DO NOT LOG INTO OR ACCESS THE WEB PORTAL AND DO NOT SUBMIT ANY PERSONAL DATA TO US.

PLEASE NOTE THAT WE OCCASIONALLY UPDATE THIS PRIVACY POLICY AND THAT IT IS YOUR RESPONSIBILITY TO STAY UP TO DATE WITH ANY AMENDED VERSIONS. IF WE MODIFY THE PRIVACY POLICY, WE WILL POST A LINK TO THE MODIFIED TERMS ON THE WEB PORTAL AND WILL ALSO NOTIFY YOU VIA EMAIL. YOU CAN STORE THIS POLICY AND/OR ANY AMENDED VERSION(S) DIGITALLY, PRINT IT, OR SAVE IT IN ANY OTHER WAY. ANY CHANGES TO THIS PRIVACY POLICY WILL BE EFFECTIVE IMMEDIATELY UPON PROVIDING NOTICE, AND SHALL APPLY TO ALL INFORMATION WE MAINTAIN, USE, AND DISCLOSE. IF YOU CONTINUE TO USE THE SERVICES FOLLOWING SUCH NOTICE, YOU ARE AGREEING TO THOSE CHANGES.

In case You have any questions or concerns after reading this Privacy Policy, please do not hesitate to contact Us at admin@belugahealth.com. We appreciate Your feedback. If You do not agree or no longer agree to the processing of Personal Data as described in this Privacy Policy, You can delete Your account or request Beluga terminate the processing of your Personal Data by notifying Us by email at admin@belugahealth.com.

Responsible Entity

Beluga is the controller of Your Personal Data and may process Personal Data in accordance with the Privacy Policy. If We are processing Personal Data on behalf of a third party that is not an agent or affiliate of Beluga, the terms of this Privacy Policy do not apply-instead, the terms of that third party's privacy policy will apply. You can contact Us with any questions about Our Privacy Policy at admin@belugahealth.com.

What Personal Data do We collect?

The types of Personal Data We collect are described below.

Demographic Data

We collect demographic information, such as Your name, birth year, gender, phone number, and email address. Primarily, the collection of Your Personal Data assists us in creating Your account ("User Account") if You are a Provider User, which You can use to securely receive the Services. If You are a Patient User, the collection of Your Personal Data assists us in securely providing you with the Services.

Payment Data

If you make payments via our Services, We may require that You provide to Us Your financial and billing information, such as billing name and address, credit card number or bank account information.

For Patient Users: Health Data

In addition to demographic information, We will collect information regarding Your health conditions, allergies, medical history, symptoms, and communications between You and the Provider User providing healthcare services to You via the Services. We collect this information to provide You with the Services.

Support Data

If You contact Us for support or to lodge a complaint, We may collect technical or other information from You through log files and other technologies, some of which may qualify as Personal Data. (e.g., Internet Protocol ("IP") address). Such information will be used for the purposes of troubleshooting, customer support, software updates, and improvement of the Services in accordance with this Privacy Policy. Calls with Beluga may be recorded or monitored for training, quality assurance, customer service, and reference purposes.

For Provider Users: Device, Telephone, and ISP Data

We use common information-gathering tools, such as log files, cookies, web beacons, and similar technologies to automatically collect information, which may contain Personal Data, from Your computer as You navigate Our Services, or interact with emails We have sent You. The information We collect may include Your IP address (or proxy server), device and application identification numbers, location, browser type, Internet service provider and/or mobile carrier, the pages and files You viewed, Your searches, Your operating system and system configuration information, and date/time stamps associated with Your usage. This information is used to analyze overall trends, to help Us provide and improve Our Services and to guarantee their security and continued proper functioning.

How will We use Your Personal Data?

We process Your Personal Data for purposes based on legitimate business interests, the fulfillment of Our Services to You, compliance with Our legal obligations, and/or Your consent. We only use or disclose Your Personal Data when it is legally mandated or where it is necessary to fulfill the purposes described herein. Where required by law, We will ask for Your prior consent before using or disclosing Personal Data.

Specifically, We process Your Personal Data for the following legitimate business purposes:

  • To provide You with Our Services.
  • To fulfill Our obligations to You under the Terms of Use (for Provider Users);
  • To communicate with You about and manage Your User Account (for Provider Users);
  • To properly store and track Your data within Our system;
  • To respond to lawful requests from public and government authorities, and to comply with applicable state/federal law, including cooperation with judicial proceedings or court orders;
  • To protect Our rights, privacy, safety, or property, and/or that of You or others by providing proper notices, pursuing available legal remedies, and acting to limit Our damages;
  • To handle technical support and other requests from You;
  • To enforce and ensure Your compliance with Our Terms of Use or the terms of any other applicable services agreement We have with You;
  • To manage and improve Our operations and the Services, including the development of additional functionality;
  • To manage payment processing;
  • To evaluate the quality of service You receive, identify usage trends, and thereby improve Your user experience;
  • To keep Our Services safe and secure for You and for Us;
  • To send You information about changes to Our terms, conditions, and policies;
  • To allow Us to pursue available remedies or limit the damages that We may sustain; and
  • If applicable, to provide access to the authorized Provider User/caregiver (with Your consent), to enable that individual to monitor Your progress and overall condition and to follow up with You, as they deem appropriate.

Where is Your Personal Data processed?

Personal Data Beluga collects through the Services will be stored on secure servers in the United States. Personal Data may be transmitted to third parties, which parties may store or maintain the data on their secure servers on Our behalf. These third parties are not permitted to transfer Your Personal Data outside of the United States.

Will We share Your Personal Data with anyone else?

For Patient Users: Yes, with the Provider User with whom You connect via the Services.

We will share information you provide to Us via the Services with the Provider User with whom connect via the Services. If, at any point, you want to deny access to one or more Provider Users, you can do so by emailing admin@belugahealth.com.

Yes, with third parties that help us power Our Services

Beluga has a limited number of service providers and other third parties ("Business Partners") that help Us run various aspects of Our business. These Business Partners are contractually bound to protect Your Personal Data and to use it only for the limited purpose(s) for which it is shared with Us. Business Partners' use of Personal Data may include, but is not limited to, the provision of services such as data hosting, IT services, customer service, and payment processing.

Yes, with third parties and the government when legal or enforcement issues arise

We may share Your Personal Data, if reasonable and necessary, to (i) comply with legal processes or enforceable governmental requests, or as otherwise required by law; (ii) cooperate with third parties in investigating acts in violation of this Agreement; or (iii) bring legal action against someone who may be violating the Terms of Use or who may be causing intentional or unintentional injury or interference to the rights or property of Beluga or any third party, including other users.

Yes, with third parties that provide advisory services

We may share Your Personal Data with Our lawyers, auditors, accountants, or banks when We have a legitimate business interest in doing so.

Yes, with Payors

We may share Your Personal Data and medical information with payors, including insurance companies and other reimbursement entities, to facilitate billing, claims processing, and payment for the services provided. This sharing is conducted in compliance with applicable laws and regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), to ensure the privacy and security of Your information. Information shared may include, but is not limited to, medical records, treatment details, and other data necessary for reimbursement purposes.

Yes, with third parties in the event of a reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of Beluga's corporate entity, assets, or stock (including in connection with any bankruptcy or similar proceedings)

If We share Your Personal Data with a third party other than as provided above, You will be notified at the time of data collection or transfer, and You will have the option of not permitting the transfer.

How long do We retain Personal Data?

We will retain Your Personal Data for as long as You maintain a User Account or use Our Services and for the amount of time necessary after the account is closed or Services are terminated, in order to fulfil Our legal obligations. The exact period of retention will depend on the type of Personal Data, Our contractual obligation to You, and applicable law. We keep Your Personal Data for as long as necessary to fulfill the purpose for which it was collected, unless otherwise required or necessary pursuant to a legitimate business purpose outlined herein. At the end of the applicable retention period, We will remove Your Personal Data from Our databases and will request that Our Business Partners remove Your Personal Data from their databases. If there is any data that We are unable, for technical reasons, to delete entirely from Our systems, We will put in place appropriate measures to prevent any further processing of such data. We retain anonymized data indefinitely.

NOTE: Once We disclose Your Personal Data to third parties, We may not be able to access that Personal Data any longer and cannot force the deletion or modification of any such information by the parties to whom We have made those disclosures. Written requests for deletion of Personal Data other than as described should be directed to admin@belugahealth.com.

For Provider Users: What is Our Cookie Policy?

Cookies are small files that a Web server sends to Your computer or device when You visit a web site that uses cookies to keep track of Your activity on that site. Cookies hold a small amount of data specific to that web site, which can later be used to help remember information You enter into the web site (like Your email or other contact info), preferences selected, and movement within the site. If You return to a previously visited web site (and Your browser has cookies enabled), the web site sends the small file to the Web server, which tells it what activity You engaged in the last time You used the web site, and the server can use the cookie to do things like expedite logging in and retrieving user data and keeping Your browser session secure. We use essential cookies to provide user authentication. and other technologies to, among other things, better serve You with more tailored information, and to facilitate efficient and secure access to the Services. We only use essential cookies. Essential cookies are those necessary for Us to provide Services to You. We may also collect information using pixel tags, Web beacons, clear GIFs or other similar technologies. These may be used in connection with some Web Portal pages and HTMLformatted email messages to, among other things, track the actions of users and email recipients, and compile statistics about usage and response rates.

For Provider Users: How can You "Opt Out" of Cookies?

If You prefer, You can usually choose to set Your browser to remove cookies and reject cookies. If You enable a do not track ("DNT") signal or otherwise configure Your browser to prevent Beluga from collecting any cookies, You will no longer be able to access the Web Portal.

How can You Manage Your Cookies?

Most web browsers let You choose whether to accept cookies. Most also let You delete cookies already set. The choices available, and the mechanism used, will vary from browser to browser. Such browser settings are typically found in the "options", "tools" or "preferences" menu. You may also consult the browser's "help" menu. For example:

There are online tools available for clearing all cookies left behind by the websites you have visited, such as www.allaboutcookies.org. Usually, deletion of cookies will anonymize the information associated with the pixel and a website will not receive any further associated information.

How do We protect Your Personal Data?

Beluga is committed to protecting the security and confidentiality of Your Personal Data. We use a combination of reasonable physical, technical, and administrative security controls to maintain the security and integrity of Your Personal Data, to protect against any anticipated threats or hazards to the security or integrity of such information, and to protect against unauthorized access to or use of such information in Our possession or control that could result in substantial harm or inconvenience to You. However, Internet data transmissions, whether wired or wireless, cannot be guaranteed to be 100% secure. As a result, We cannot ensure the security of information You transmit to Us. By using the Services, You are assuming this risk.

Safeguards

The information collected by Beluga and stored on secure servers, is protected by a combination of technical, administrative, and physical security safeguards, such as authentication, encryption, backups, and access controls. If Beluga learns of a security concern, We may attempt to notify You and provide information on protective steps, if available, through the email address that You have provided to Us or the phone number you have provided Depending on where You live, You may have a legal right to receive such notices in writing.

You are solely responsible for protecting information entered or generated via the Services that is stored on Your device and/or removable device storage. Beluga has no access to or control over Your device's security settings, and it is up to You to implement any device-level security features and protections You feel are appropriate (e.g., password protection, encryption, remote wipe capability, etc.). We recommend that You take any and all appropriate steps to secure any device that You use to access Our Services.

NOTWITHSTANDING ANY OF THE STEPS TAKEN BY US, IT IS NOT POSSIBLE TO GUARANTEE THE SECURITY OR INTEGRITY OF DATA TRANSMITTED OVER THE INTERNET. THERE IS NO GUARANTEE THAT YOUR PERSONAL DATA WILL NOT BE ACCESSED, DISCLOSED, ALTERED, OR DESTROYED DESPITE THE IMPLEMENTATION OF OUR PHYSICAL, TECHNICAL, OR ADMINISTRATIVE SAFEGUARDS. THEREFORE, WE DO NOT AND CANNOT ENSURE OR WARRANT THE SECURITY OR INTEGRITY OF ANY PERSONAL DATA YOU TRANSMIT TO US AND YOU TRANSMIT SUCH PERSONAL DATA AT YOUR OWN RISK.

How can You Protect Your Personal Data?

In addition to securing Your device, as discussed above, We will NEVER send You an email requesting confidential information such as account numbers, usernames, passwords, or social security numbers, and You should NEVER respond to any email requesting such information. If You receive such an email purportedly from Beluga, DO NOT RESPOND to the email and DO NOT click on any links and/or open any attachments in the email, and notify Beluga support at admin@belugahealth.com.

For Provider Users: You are responsible for taking reasonable precautions to protect Your user ID, password, and other User Account information from disclosure to third parties, and You are not permitted to circumvent the use of required encryption technologies. You should immediately notify Beluga at admin@belugahealth.com if You know of or suspect any unauthorized use or disclosure of Your user ID, password, and/or other User Account information, or any other security concern.

Your rights

You have certain rights relating to Your Personal Data, subject to local data protection laws. These rights may include:

  • to access Your Personal Data held by Us;
  • to erase/delete Your Personal Data, to the extent permitted or required by applicable data protection laws;
  • to receive communications related to the processing of Your personal data that are concise, transparent, intelligible, and easily accessible;
  • to restrict the processing of Your Personal Data to the extent permitted by law (while We verify or investigate Your concerns with this information, for example);
  • to object to the further processing of Your Personal Data, including the right to object to marketing;
  • to request that Your Personal Data be transferred to a third party, if possible;
  • to receive Your Personal Data in a structured, commonly used, and machine-readable format;
  • to lodge a complaint with a supervisory authority;
  • to rectify inaccurate Personal Data and, taking into account the purpose of processing the Personal Data, ensure it is complete; and
  • to not be subject to a decision based solely on automated processing, including profiling, which produces legal effects ("Automated Decision-Making").

Where the processing of Your Personal Data by Beluga is based on consent, You have the right to withdraw that consent without detriment at any time or to exercise any of the rights listed above by emailing Beluga at admin@belugahealth.com.

How can You update, correct, or delete Personal Data?

You can change Your email address and other contact information by contacting admin@belugahealth.com. If You are a Provider User, and You need to make changes or corrections to other information, You may change your password within the account settings on the Web Portal dashboard. Please note that in order to comply with certain requests to limit use of Your Personal Data, We may need to terminate Your account and/or Your ability to access and use the Services, and You agree that We will not be liable to You for such termination or for any refunds of prepaid fees paid by You. You can deactivate Your account or request termination of Services by contacting admin@belugahealth.com.

Although We will use reasonable efforts to do so, You understand that it may not be technologically possible to remove from Our systems every record of Your Personal Data. The need to back up Our systems to protect information from inadvertent loss means a copy of Your Personal Data may exist in a nonerasable form that will be difficult or impossible for Us to locate or remove.

Can You "OPTOUT" of receiving communications from Us?

We pledge not to market third party services to You without Your consent. We may send emails to You regarding Your Beluga account and/or services. You can choose to filter these account and services emails using Your email client settings or, if you are a Patient User, by emailing admin@belugahealth.com, but We do not provide an option for You to opt out of these emails.

Third Party Links

Our Sites may offer links to other websites which may have information policies and practices different from ours. We do not control and are not responsible for the privacy policies, practices, or content of any third-party websites. We encourage you to review the privacy policies of any third-party website prior to providing them with your Personal Information.

Information submission by minors

We do not knowingly collect Personal Data from individuals under the age of 18 and the Services are not directed to individuals under the age of 13. We request that these individuals not provide Personal Data to Us. If We learn that Personal Data from users less than 18 years of age has been collected, We will deactivate the account and take reasonable measures to promptly delete such data from Our records. If You are aware of a user under the age of 13 using the Services, please contact Us at admin@belugahealth.com. If You are a resident of California, under the age of 18 and have registered for an account with Us, You may ask Us to remove content or information that You have posted to Our Services.

California Residents

California residents may request and obtain from Us, once a year, free of charge, a list of third parties, if any, to which We disclosed their Personal Data for direct marketing purposes during the preceding calendar year and the categories of Personal Data shared with those third parties. If You are a California resident and wish to obtain that information, please submit Your request by sending Us an email at admin@belugahealth.com with "California Privacy Rights" in the subject line.

California's "Shine the Light" law (Civil Code Section § 1798.83) permits California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to admin@belugahealth.com with "California Privacy Rights" in the subject line.

Nevada residents

Nevada residents may contact us to inquire about your right to opt out of the sale of your Personal Information

Contact Us

If You have any questions about this Privacy Policy, please contact Us by email at admin@belugahealth.com or please write to: Beluga Health, P.A., 1321 Upland Dr., Suite 18399, Houston, TX, 77043. Please note that email communications are not always secure; so please do not include sensitive information in Your emails to Us.