“Company” or the terms “we” or “us” or similar terms refer to Album Health, Inc. “You” or “your” or similar terms refer to you as a user of our Services.
Personal Information – In General.
Protected Health Information.
WHAT PERSONAL INFORMATION DO WE COLLECT?
We collect Personal Information you choose to provide us (e.g., through registrations, applications, use of the Services, surveys, and in connection with your inquiries), starting from the time that you initially access our Site, our Mobile App or use our Services. The information we gather from you enables us to administer your account, provide you with the Services, respond to your inquiries and send you communications regarding the Services and your access to and use of the same, obtain your feedback on our Site, our Mobile App and our Services, analyze user behavior and activity, personalize and improve our Services, conduct research activities and contact you about the services that we offer.
From time to time, we may use or augment the Personal Information we have about you with information obtained from third parties (e.g., FitBit or Apple). For example, we may use such third party information to confirm contact information, to verify eligibility, or to better understand your interests by associating demographic information with the information you have provided.
We collect the following types of information:
Personal Information You Provide to Us.
We receive and store any information you enter on our Site, our Mobile App or provide to us through the Services, including any third party services that you connect with our Services (e.g., FitBit or Apple). Personal Information that we collect may include things like your full name, gender, mobile phone number, your email address and the email address of your contacts, home and business postal addresses, IP address, browser information, username, password, certain health information (e.g., height, weight, blood pressure, blood glucose, pre-existing medical conditions, tracking of food, sleep and/or activity and insurance information), and any other information or data that you provide when using our Site, our Mobile App and/or our Services. You can choose not to provide us with certain information, but that may result in our inability to provide you access to or use of many of our special features. Our goal is to use the Personal Information you provide for such purposes as answering questions and communicating with you about the Company’s products and services, including updates and new features.
PLEASE NOTE: By using the Services, you consent to and authorize us to disclose your eligibility for and participation in the Services (i.e., you meet the clinical enrollment criteria for the Services, which may identify those individuals at risk for certain chronic diseases or living with certain chronic diseases and have elected at your own discretion to participate in the same) to the other users of the Site, the Mobile App and the Services. The users, including but not limited to administrators, health coaches and other authorized Album Health personnel will have access to a range of Personal Information such as your user name, linking you to your diagnosis and/or reason for program participation. Moreover, as we group participants based on certain characteristics, fellow support group members may be co-workers or other acquaintances.
We take great efforts in protecting your privacy; however, we cannot control, and expressly disclaim any responsibility for, whether or how users will subsequently use or disclose posted or previously disclosed information. If you do not consent to the disclosure of this information, you should not access or use the Site, the Mobile App or the Services.
Personal Information Collected Automatically.
We receive and store certain types of information whenever you interact with the Site, the Mobile App and / or use the Services. We automatically receive and record information on our server logs from your browser, including your IP address, and the page you requested. In addition, we may use personal identifiers to recognize you when you arrive at the Site via an external link, such as a link appearing on a third-party site or in an Album-generated email presented to you. See also our “What About Tracking Technologies?” section below. We will also use your information to provide customer service and support.
Generally, our Services automatically collect usage information, such as the numbers and frequency of visitors to the Site and Mobile App and its components, similar to TV ratings that indicate how many people watched a particular show. We only use this data in aggregate form, that is, as a statistical measure, and not in a manner that would permit us to identify you personally (“De-identified Information”). This type of aggregate data enables us to figure out how often users or customers use parts of the Site, Mobile App or Services so that we can make the Site, Mobile App and Services as appealing to as many users and customers as possible and improve our Services. We may provide this de-identified, aggregate data to our partners and/or customers to identify how our users use our Site, Mobile App and/or Services. Again, we never disclose information to a partner or customer in a manner that would identify you personally.
You may set your browser to refuse or disable these data collection methods, but doing so may change your experience with the Site, the Mobile App or the Services, diminish certain aspects of the Site’s or Mobile App’s functionality or render certain features of the Site, the Mobile App or the Services inoperable. The Site may not recognize or respond to “do not track” technologies employed by your browser.
We often receive a confirmation when you open an email from us if your computer supports this type of program. We use this confirmation to help us make emails more interesting and helpful. We also compare our customer list to lists received from other companies in an effort to avoid sending unnecessary messages to our customers. When you receive e-mail from us, you can opt out of receiving further e-mails by following the included instructions to unsubscribe. However, by opting out of further email communications after you enroll in the Services, you may limit program reminders and other valuable program content and components.
What About Tracking Technologies?
In addition to any Personal Information or other information that you choose to submit to us via the Site, Mobile App or Services, we and our third party service providers may use a variety of technologies that automatically (or passively) store or collect certain information when you visit or interact with the Site, Mobile App or Services (“Usage Information”). This Usage Information may be stored or accessed using technologies that may be downloaded to your Device whenever you visit or interact with the Site, Mobile App or Services. To the extent we associate Usage Information with your Personal Information that we collect directly from you, we will treat it as Personal Information. Examples of Usage Information include: your IP address or other unique device identifier (e.g., a number that is automatically assigned to your Device used to access the Site which our computers use to identify your Device), your Device’s functionality (e.g., browser, operating system, mobile network information, etc.), the areas within the Site or Services that you visit and your activities there, your Device location, your Device characteristics and certain other data regarding your Device.
We may use various methods or technologies to store or collect your Usage Information, including your visits to or interactions with our Site, Mobile App and Services (“Tracking Technologies”). We may use these Tracking Technologies for a variety of purposes, including but not limited to uses deemed to be necessary or useful to assess the performance of our Site, Mobile App and Services (including as part of our analytic practices or otherwise to improve our Site, Mobile App and Services) or uses required to offer you enhanced functionality when accessing our Site, Mobile App and Services (including identifying you when you sign in to the Site or the Mobile App or keeping track of your specified preferences).
Tracking Technologies that may include the following (and may include subsequent technologies and methods later developed which perform a similar function):
Embedded Scripts. An embedded script is programming code that is designed to collect information about your interactions with the Site, Mobile App and Services, such as the links that you click on. The code is temporarily downloaded onto your Device, is active only while you are connected to the Site or Mobile App, and is deactivated or deleted thereafter.
Web Beacons. Small graphic images or other web programming code called “web beacons” (also known as “1×1 GIFs” or “clear GIFs”) may be included in pages and messages of our Site, Mobile App and Services. Web beacons may be invisible to you, but any electronic image or other web programming code inserted into a page or e-mail can act as a web beacon. Web beacons or similar technologies may be used for a number of purposes, including to count visitors to the Site, Mobile App and Services, to monitor how users navigate the Site, the Mobile App and Services, to count how many sent e-mails were actually opened or to count how many particular articles or links were actually viewed.
WHAT PERSONAL INFORMATION DO WE SHARE?
User Profiles: In the future, we may provide functionality to permit you to create a user profile page in which you may provide information about yourself, including, without limitation, your health information, symptoms, treatments, as well as your feelings about your health information and/or yourself (“User Submissions,” as further defined in our Terms). You may also be able to upload pictures, videos and stories to your profile page as part of the User Submissions. User Submissions may be displayed to other users (including members of your group(s), who may be from the same deployment or otherwise affiliated) to facilitate user interaction within the Services. Email addresses may be used to add new User Submissions to user profiles and to communicate through User Submissions. Users’ email addresses will not be directly revealed to other users by us, except when the user is “connected” to another user via a shared group membership, or an invitation, or if the user has chosen to include their email address in their User Profile. Please note that any User Submissions you make, including Personal Information, on or through your profile page may be available for other users, the Company, administration, moderators, and other staff. Additionally, other users may be able to post comments and view posted comments on your profile page.
Communication in Response to User Submissions: As part of the Site and Services, you will receive from us email and other communication relating to your User Submissions. You acknowledge and agree that by posting such User Submissions, we may send you email and other communications (e.g., phone calls or text messages) that we determine, in our sole discretion, are related to your User Submissions.
Agents: We employ other companies and people to perform tasks on our behalf and need to share your information with them to provide products and/or services to you. Without specific authorization and/or consent, we limit the rights of our agents to use Personal Information we share with them to that which is minimally necessary to assist us. You hereby consent to our sharing of Personal Information for the above purposes.
Sponsors and Third Party Administrators; As Required by Law: We may, in our sole discretion, share, transfer or otherwise disclose certain of your Personal Information (e.g., reports containing data related to enrollment, engagement, retention, and outcomes) to your sponsor or your sponsor’s third party administrators (e.g., incentives vendors, wellness administrators, etc.) for treatment, payment, or healthcare operations purposes and for other purposes permitted or required by law, as more fully described in our HIPAA Notice.
Protection of the Company and Others: We may release Personal Information when we believe in good faith that release is necessary to comply with the law; enforce or apply our conditions of use and other agreements; or protect the rights, property, or safety of the Company, our employees, our users, or others. This includes exchanging information with other companies and organizations for fraud protection, detection or suppression. If necessary, we will make all legally required disclosures of any breach of the security, confidentiality, or integrity of your Personal Information, including, without limitation, breaches of your unencrypted, electronically stored “personal information” or “medical information” (as defined in applicable state statutes on security breach notification). To the extent permitted by applicable laws, we will make such disclosures to you via email or conspicuous posting on your private profile on the Site or the Mobile App in the most expedient time possible and without unreasonable delay, insofar as consistent with (a) the legitimate needs of law enforcement, or (b) any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
With Your Consent: Except as set forth above, you will be notified when your Personal Information may be shared with third parties, and will be able to control the sharing of this information.
De-identified Information: We may create De-Identified Information from the information that you share with us, including any Personal Information, and use such De-identified Information without restriction. We may, for example, share De-identified Information with the sponsors paying for your participation in the Services (e.g., reports containing data related to enrollment, engagement, retention, and outcomes to evidence overall program success metrics) and with third party administrators working with the sponsors to administer certain services to you (e.g., incentives vendors, wellness administrators, etc.). Again, we never disclose aggregate information in a manner that would identify you personally.
IS MY PERSONAL INFORMATION SECURE?
We employ industry standard administrative, physical, and technical measures designed to safeguard and protect information under our control from unauthorized access, use, and disclosure. In addition, when we collect, maintain, access, use, or disclose your Personal Information, we will do so using systems and processes consistent with information privacy and security requirements under applicable federal and state laws, including, without limitation, HIPAA.
Furthermore, your individual user account is protected by a password for your privacy and security. To ensure that there is no unauthorized access to your account and Personal Information, we suggest that you safeguard your password appropriately and limit access to your computer and browser by signing off after you have finished accessing your account.
WHAT PERSONAL INFORMATION CAN I ACCESS AND CORRECT?
You can access certain information about you for the purpose of viewing, and in certain situations, updating that information. This list may change as the Site, the Mobile APP or the Services change.
- Real name
- Account and user profile information (e.g., nickname)
- User email address
- User mailing address
- User mobile phone number
- Username and password
- Communication preferences
In order to help us maintain and ensure that your information is accurate and up to date, please update your information if it changes or inform us promptly at firstname.lastname@example.org so that we make the appropriate changes.
WHAT CHOICES DO I HAVE REGARDING MY PERSONAL INFORMATION?
As stated previously, you can always opt not to disclose information, even though it may be needed to take advantage of certain features of the Site, the Mobile App and the Services.
You are able to add or update certain information on pages, such as those listed in the “What Personal Information Can I Access And Correct” section, above. When you update information, however, we often maintain a copy of the unrevised information in our records.
If you would like us to remove your records from our system, you may request deletion of your account with us by sending e-mail to email@example.com. Please note that some information may remain in our records after deletion of your account, including any information or records we are legally obligated to retain. We will process your request within a reasonable time, but please note that you may receive additional communications and offers as we process your request.
HOW DO WE PROTECT CHILDREN’S PERSONAL INFORMATION?
The Services are not directed to children. We do not knowingly allow or solicit anyone under the age of 18 to participate independently in any of the Services. We do not knowingly collect Personal Information from children. If a parent or guardian becomes aware that his or her child has provided us with Personal Information, please contact us. If we become aware that a user of the Services is under the age of 18 and has provided us with Personal Information without verifiable parental consent, we will delete such Personal Information from our files.
QUESTIONS OR CONCERNS
If you have any questions, concerns or complaints regarding privacy on our Site or Mobile App or if you want to make a request to access or correct your Personal Information, please contact our Privacy Officer at:
By email: firstname.lastname@example.org
Album Health, Inc.
1717 Ingersoll Avenue
Des Moines, IA 50309
By phone: 888-820-7267
We will make every effort to respond to your questions, concerns complaints and requests within a reasonable time.
Effective Date: June 5, 2018