Last Updated: November 6, 2018
This policy applies where the Company is acting as a data controller with respect to your personal data (i.e. where we determine the purposes and means of processing that personal data).
Unless otherwise noted, the legal basis for processing your personal data is your consent to the processing of your personal data.
“Company” or the terms “we” or “us” or similar terms refer to Oculus Health, Inc. “You” or “your” or similar terms refer to you as a user of our Services.
Personal Information – In General.
Protected Health Information.
2. WHAT PERSONAL INFORMATION DO WE COLLECT?
We collect personal information you choose to provide, e.g., through registrations, applications and surveys, and in connection with your inquiries, from the time that you initially access our Sites or use our Services. The information we gather from customers enables us to personalize and improve our Services.
From time to time, we may use or augment the personal information we have about you with information obtained from third parties. For example, we may use such third party information to confirm contact or financial information, to verify eligibility, or to better understand your interests by associating demographic information with the information you have provided.
We collect the following types of information from our customers:
Personal Information You Provide to Us.
We receive and store any information you enter on our Sites or provide to us in several ways. Personal Information that we collect may include things like your full name, mobile phone number, credit card and/or other payment information (if applicable), your email address and the email address of your contacts, home and business postal addresses, IP address, browser information, username, password, certain health information (e.g., weight, insurance information), and any other information or data that you provide when using our Sites and/or our Services. You can choose not to provide us with certain information, but that may result in our inability to provide you access to many of our special features. Oculus’s goal is to use the Personal Information you provide for such purposes as answering questions and communicating with you about the Company’s products and services, including updates and new features.
PLEASE NOTE: By using the Services, you consent to, and authorize Oculus to disclose your diagnosis to the other users of the Sites and Services. The users, including but not limited to Site administrators, Health Coaches, and your fellow support group members will have access to a range of Personal Information such as your name and picture, linking you to your diagnosis and reason for program participation. Specifically, as we group participants based on certain characteristics, fellow support group members may be co-workers or other acquaintances.
We take great efforts in protecting your privacy, however,we cannot control, and expressly disclaim any responsibility for, whether or how users will subsequently use or disclose posted or previously disclosed information. If you do not consent to the disclosure of this information, you should not access or use the Sites or the Services. The Services include the ability for users to share Personal Information, including information regarding your medical condition. Any information you choose to provide or upload to the group Sites, including Personal Information about your medical condition, will be visible to your group, as well as Health Coaches, Site administrators, and other Site users. As your information will be viewable to the other users of the Sites, you should provide only the information you feel comfortable disclosing. There may be an opportunity to speak on the phone or via video chat in a group conference call. Participation in such opportunities is not mandatory, but should you choose to participate, you should share only as much information as you feel comfortable sharing in these additional forums.
Personal Information Collected Automatically.
We receive and store certain types of information whenever you interact with our Sites and / or use our Services. We automatically receive and record information on our server logs from your browser, including your IP address, and the page you requested. In addition, we may use personal identifiers to recognize you when you arrive at the Site via an external link, e.g., such as a link appearing on a third party site or in an Oculus-generated email presented to you. See alsoour What About Cookies? section below. We will also use your information to provide customer service and support.
Generally, our Services automatically collect usage information, such as the numbers and frequency of visitors to our Sites and its components, similar to TV ratings that indicate how many people watched a particular show. We only use this data in aggregate form, that is, as a statistical measure, and not in a manner that would identify you personally. This type of aggregate data enables us to figure out how often customers use parts of the Sites or Services so that we can make the Sites appealing to as many customers as possible, improving our Services. We may provide this de-identified, aggregate data to our partners to identify how our customers, collectively, use our Sites or Services. We share this type of statistical data so that our partners also understand how often people use the Sites or Services, so that they, too, may provide you with an optimal online experience. Again, we never disclose aggregate information to a partner in a manner that would identify you personally.
We often receive a confirmation when you open an email from us if your computer supports this type of program. We use this confirmation to help us make emails more interesting and helpful. We also compare our customer list to lists received from other companies, in an effort to avoid sending unnecessary messages to our customers. When you receive e-mail from us, you can opt out of receiving further e-mails by following the included instructions to unsubscribe.
What About Cookies?
3. WHAT PERSONAL INFORMATION DO WE SHARE?
Personal Information about our customers is an integral part of our business. We will not rent, sell, or share Personal Information about you with other people or nonaffiliated companies except to provide Services, when we otherwise have your permission, or under the following circumstances:
Forums: We may make available your Personal Information through the Sites and/or the Services (for example, discussion boards, chat rooms, profile pages, bulletin boards, blogs, instant messaging, activities, polls, games and other communication forums) (each, a “Forum”) to which you post information and materials. Some of these Forums are described more specifically below. Please note that any information, text, and images posted or disclosed by the user on or through such Forums may be visible to the user’s group(s), as well as Health Coaches, Site administrators, visitors to the Sites, and other users of the Sites. Specifically, Personal Information such as the picture you’ve uploaded and your screen name, may be available for other users to view when you make a posting to such Forums. Information regarding your activities in such Services may also be available for view by other users (for example, other users may be able to view a list of all postings you have made in all available Forums). Any postings you have made to a Forum may also be available for view later by users of the Sites by scrolling to older posts on the Forum. We urge you to exercise discretion and caution when deciding to disclose your Personal Information, such as your illness, or any other information, through a Forum or otherwise through the Site. WE ARE NOT RESPONSIBLE FOR THE USE OF ANY PERSONAL INFORMATION DISCLOSED BY YOU OR ON YOUR BEHALF BY YOUR SYSTEM THROUGH A FORUM OR OTHERWISE THROUGH THE SITES.
Discussion Boards and Chat Rooms: We may provide functionality to post on our discussion boards, and permit you to enter into chat rooms and communicate with other users in the chat rooms. Please note that if you use such functionalities to communicate, your name / screen name will be disclosed to all visitors to the discussion boards, present and future, as well as all users in the chat room at that time. Please remember that information posted to discussion boards becomes public information. Use caution when posting. Further, if a comment you make on the discussion board or in the chat room contains Personal Information, we cannot control how the Personal Information will be used or disclosed by the other users of the discussion board or chat room. We urge you to exercise discretion and caution when deciding to disclose your Personal Information, or any other information, in any comment and/or message, and to be careful about the people to whom you send such comments and/or messages. WE ARE NOT RESPONSIBLE FOR THE USE BY OTHERS OF THE INFORMATION THAT IS DISCLOSED BY YOU OR ON YOUR BEHALF BY YOUR SYSTEM ON DISCUSSION BOARDS, IN CHAT ROOMS OR OTHERWISE THROUGH THE SITES.
Messaging Services: We may provide functionality to permit you to send messages, including instant messages, to other users through the Sites. Please note that if you use such functionality to send such a message to another user, your screen name will be disclosed to that user, as well as Site administrators. Further, if a message you send using such functionality contains Personal Information, we cannot control how the Personal Information will be used or disclosed by the recipient of your message. We urge you to exercise discretion and caution when deciding to disclose your Personal Information, or any other information, in any message, and to be careful about the people to whom you send such messages. WE ARE NOT RESPONSIBLE FOR THE USE BY OTHERS OF THE INFORMATION THAT IS DISCLOSED BY YOU OR ON YOUR BEHALF BY YOUR SYSTEM IN SUCH MESSAGES.
User Profiles: We may provide functionality to permit you to create a user profile page in which you may provide information about yourself, including, without limitation, your illness, symptoms, treatments, as well as your feelings about your illness and/or yourself (“User Submissions,” as further defined in our Terms). You may also be able to upload pictures, videos and stories to your profile page as part of the User Submissions. User Submissions may be displayed to other users (including members of your group(s), who may be from the same deployment or otherwise affiliated) to facilitate user interaction within the Sites. Email addresses are used to add new User Submissions to user profiles and to communicate through User Submissions. Users’ email addresses will not be directly revealed to other users by us, except when the user is “connected” to another user via a shared group membership, or an invitation, or if the user has chosen to include their email address in their User Profile. Please note that any User Submissions you make, including Personal Information, on or through your profile page may be available for other users, the Company, administration, moderators, and other staff. Additionally, other users may be able to post comments and view posted comments on your profile page.
Communication in Response to User Submissions: As part of the Sites and Services, you will receive from us email and other communication relating to your User Submissions. You acknowledge and agree that by posting such User Submissions, we may send you email and other communication that we determine, in our sole discretion, as related to your User Submissions.
Affiliated Businesses We Do Not Control: In order to provide you with the optimal user experience, we anticipate that we may become affiliated, and work closely with a variety of third-party businesses. In certain situations, these businesses may sell products or services to you through the Sites. In other situations, we may provide services, or sell products, jointly with affiliated businesses. You should be able to recognize when an affiliated business is associated with your transactions, and throughout the course of the transactions, we will share your Personal Information that is related to such transactions with that affiliated business.
Agents: We employ other companies and people to perform tasks on our behalf and need to share your information with them to provide products and/or services to you. Without specific authorization and/or consent, we limit the rights of our agents to use Personal Information we share with them to that which is minimally necessary to assist us. You hereby consent to our sharing of Personal Information for the above purposes.
Promotional Offers: We will never disclose your personal information to other businesses for their marketing purposes, but we may send you offers that promote the products of other businesses. These offers will be intended to benefit you, your health, or your Oculus experience. If you do not wish to receive these offers, please send an email with your request to privacy@OculusHealth.com, and we will process your request within a reasonable time. Please note that you may receive additional offers as we process your request.
Protection of the Company and Others: We may release Personal Information when we believe in good faith that release is necessary to comply with the law; enforce or apply our conditions of use and other agreements; or protect the rights, property, or safety of the Company, our employees, our users, or others. This includes exchanging information with other companies and organizations for fraud protection and credit risk reduction.
With Your Consent: Except as set forth above, you will be notified when your Personal Information may be shared with third parties, and will be able to control the sharing of this information.
4. IS MY PERSONAL INFORMATION SECURE?
We employ commercially reasonable administrative, physical, and technical measures designed to safeguard and protect information under our control from unauthorized access, use, and disclosure. These measures include encrypting your communications by utilizing Secure Sockets Layer (“SSL”) software, and using a secured messaging service when we send your Personal Information electronically. In addition, when we collect, maintain, access, use, or disclose your Personal Information, we will do so using systems and processes consistent with information privacy and security requirements under applicable federal and state laws, including, without limitation, the Health Insurance Portability and Accountability Act (“HIPAA”).
Furthermore, your individual user account is protected by a password for your privacy and security. To ensure that there is no unauthorized access to your account and Personal Information, we suggest that you safeguard your password appropriately and limit access to your computer and browser by signing off after you have finished accessing your account.
We endeavor to protect user information to ensure that user account information is kept private. However, we cannot guarantee the security of your personal and other information or the appropriateness of the measures we use to safeguard such information. Unauthorized entry, access, or use; loss; hardware or software failure; and other factors, may compromise the security of user information at any time.
Despite these measures, the confidentiality of any communication or material transmitted to or from us via the Services offered through our Sites, by Internet or email cannot be guaranteed. If you have reason to believe that your data or your interactions with us are no longer secure, you may contact us at the mailing address or telephone number listed at the end of this document. In addition, if you have privacy or data security related questions, please feel free to contact the office identified at the end of this document.
5. WHAT PERSONAL INFORMATION CAN I CONTROL?
We allow you to access and control the following information about you for the purpose of viewing, and in certain situations, updating that information. This list may change as the Sites change.
- Real name
- Account and user profile information (e.g., nickname and picture)
- User email address
- User mailing address
- User mobile phone number
- Username and password
- Communication preferences
6. WHAT CHOICES DO I HAVE REGARDING MY PERSONAL INFORMATION?
As stated previously, you can always opt not to disclose information, even though it may be needed to take advantage of certain features of the Sites and the Services.
You are able to add or update certain information on pages, such as those listed in the “What Personal Information Can I Control” section, above. When you update information, however, we often maintain a copy of the unrevised information in our records.
If you would like us to remove your records from our system, you may request deletion of your account with us by sending e-mail toprivacy@OculusHealth.com. Please note that some information may remain in our records after deletion of your account, including any information or records we are legally obligated to retain. We will process your request within a reasonable time, but please note that you may receive additional offers as we process your request.
Personal data that we process for any purpose shall not be kept for longer than is necessary for that purpose. Notwithstanding, we may retain your personal data where retention of such is necessary for compliance with a legal obligation to which we are subject, or in order to protect your interests.
- YOUR RIGHTS
Below is a brief list of your rights under data protection law. You should read for yourself all relevant laws and guidance from the regulatory authorities for a full explanation of these rights.
Your rights include:
- The right to access your personal data;
- The right to rectify any inaccurate personal data or complete any incomplete personal data;
- The right to erasure under certain circumstances without undue delay;
- The right to restrict processing under certain circumstances;
- The right to object to processing on grounds relating to your particular situation, under certain circumstances, including for direct marketing purposes;
- The right to data portability;
- The right to complain to a supervising authority if you feel our processing has violated data protection laws; and
- The right to withdraw consent.
8. HOW DO WE PROTECT CHILDREN’S PERSONAL INFORMATION?
The Services are not directed to children. We do not knowingly allow or solicit anyone under the age of 18 to participate independently in any of the Services. We do not knowingly collect Personal Information from children. If a parent or guardian becomes aware that his or her child has provided us with Personal Information, please contact us. If we become aware that a user of the Services is under the age of 18 and has provided us with Personal Information without verifiable parental consent, we will delete such Personal Information from our files.
- INTERNATIONAL TRANSFERS OF PERSONAL DATA
We have facilities in the U.S. The European Commission has made an “adequacy decision” with respect to the data protection laws of its member nations. Transfers to counties in the European Economic Area (EEA) will be protected by appropriate safeguards, namely the use of standard data protection clauses adopted or approved by the European Commission, a copy of which can be obtained from https://gdpr-info.eu/.
By using our Services, you acknowledge that personal data that you submit through our website or services may be available, via the internet, around the world. We cannot prevent the use (or misuse) of such personal data by others
11. QUESTIONS OR CONCERNS
If you have any questions or concerns regarding privacy on our Sites, please send us a detailed message at privacy@OculusHealth.comor at the address below. We will make every effort to resolve your concerns. Oculus Health, Inc 210 Broadway Suite 201 Cambridge, MA 02139