Privacy Policy

Curve Health. PRIVACY POLICY
This PrivacyPolicy describes the types of information Curve Health, Inc. (“Curve” or “We”or “us”)  may collect from you or that you may provide when you visit the website https://www.curvehealth.com (our “Website”) or Curve’s service platform and any website or service that links to or refers to this Privacy Policy(collectively, the “Services”) and our practices for collecting, using, maintaining, protecting, and disclosing that information.

Individually identifiable information that you provide to us for purposes of obtaining medical care from physicians' or other healthcare providers' (“Providers”)(such information is also referred to as “Protected Health Information” or“PHI”) may be subject to the Health Insurance Portability and AccountabilityAct (“HIPAA”) and the Health Information Technology for Economic and ClinicalHealth Act (“HITECH”).

INFORMATION WE COLLECT
We collect several types of information from and about the users of our Website andServices, including Personal Information, Non-Personal Information, and any other information you provide to Us. By using the Website or Services, you are consenting to the collection of this technical data.

Personal Information: Personal Information is any information that      uniquely identifies you that you might consider highly confidential or sensitive and includes your Personal Account Information, Protected Health Information and Personal Employment Information. We treat all Personal Information as private and confidential.

We collect three types of Personal Information:

Personal Account Information: We use Personal Information, such as your name, address, telephone number, email address, organization affiliation address, user name and password, to uniquely identify you and your use of the Services or the Website. For health care providers, information about your employment, such as your job title, practice area, primary specialty, and medical license status, gender, date of birth, languages spoken, educational background, address, photograph, social security number, Tax ID, NPI number, professional license information and bank account information.

Protected Health Information: Protected Health Information that we collect includes:

Medical Information: Medical Information includes any personal health information, including age, weight, height, gender, ethnicity, medical history such as diagnosis, previous treatments, general health, laboratory and pathology test results and reports, family history, social history, medical images and reports, records from your past, current, and future health care providers, and records about phone calls and emails related to Protected Health Information

Personal Employment Information: We use Personal Information, such as your name, address, telephone number, email address, organization affiliation address, user name and password, to uniquely identify you and your use of the Services or the Website. For job applicants, information about your employment history, such as your job title and responsibilities, gender, race or ethnicity, date of birth, languages spoken, educational background, disability status, address, photograph, social security number, TaxID, professional license information and bank account information.

Non-Personal Information: Non-Personal Information includes any information that we gather as you navigate our Website such as Internet protocol (IP) address, device and advertising identifiers, browser type, operating system, Internet service provider, pages that you visit before and after using the Services, the date and time of your visit, information about the links you click and pages you view within the Website or while using the Services, and other standard server log information. We may also collect certain location information when you use our Services, such as your computer’s IP address, your mobile device’s GPS signal, or     information about nearby WiFi access points and cell towers, your browser type, pages viewed, and the time spent on the Website. We may also collect technical data to address and fix technical problems and improve our Website and Services, including the memory state of your device when a system or app crash occurs while using our Services. Your device or browser settings may permit you to control the collection of this technical data. This data may include parts of a document you were using when a problem occurred, or the contents of your communications.      

How Information is Collected

We may collect information that is directly provided or through one or more of the automatic data collection techniques below.  

Directly Provided

We collect information you provide directly to us such as when you register on the Website, use the Services, subscribe to any of our alerts, or contact us directly.

Automatic Data Collection Technologies

As you navigate through and interact with our Website and Services, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns. The technologies we use for this automatic data collection may include: Cookies(or browser cookies). A cookie is a small file placed on the hard drive of your computer. You may refuse to accept browser cookies by activating the appropriate setting on your browser. However, if you select this setting, you may be unable to access certain parts of ourWebsite. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Website.                                             

WebBeacons. Pages of our Website and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit Curve for example, to count users who have visited those pages or opened an email and for other related website statistics).                                         

FlashCookies. Certain features of ourWebsite or Services may use local stored objects or website objects (or Flash cookies) to collect and store information about your preferences and navigation to, from, and on our Website. Flash cookies are not managed by the same browser settings as are used for browser cookies.               

LogFiles: When you access our Website or Services our system automatically collects certain information about you for our logs. This data may include your browser type, your computer’s IP address, your Internet Service Provider, operating system, date and time you visited our site, and a list of the pages you visited.

Electronic Transfer: When you and/or your healthcare provider(s) interact with our Services, Personal Information may be transmitted to our system which originates from a providers electronic health record system or from a medical device you have authorized.

Sharing Information

We may disclose aggregated information about our users and information that does not identify any individual without restriction.

We may disclose Personal Information that we collect, or you provide as described in this privacy policy:

To healthcare providers and other healthcare-related entities who are relevant to the Services being provided; or

To contractors, service providers, and other third parties we use to support our business including billing, payment processing, customer service, email deployment, business analytics, marketing, performance monitoring, hosting, chat functionality, and data processing. These third-party vendors and service providers may not use your information for purposes other than those related to the services they are providing to us. These third-party vendors and service-providers may monitor activity (including mouse movements and clicks) on our Website and may collect, store, and use certain information, including but not limited to information regarding your device and your interactions with this website, chat messages, and information provided by you; or

We may share your information in connection with a substantial corporate transaction, such as the sale of a website, a merger, consolidation, asset sale, or in the unlikely event of bankruptcy; or

We may disclose information to respond to subpoenas, court orders, legal process, law enforcement requests, legal claims or government inquiries, and to protect and defend the rights, interests, health, safety, and security of Curve, our users, or the public. We will use reasonable and lawful efforts to limit the scope of any legally required disclosure and we will also make reasonable efforts to notify you in advance of that disclosure, unless doing so would violate the applicable law or the court order; or

With your consent or your direction. We may share information for any other purposes disclosed to you at the time we collect the information or pursuant to your consent or direction; or

If you choose to engage in any public activities on the Website or third-party sites that we link to, you should be aware that any information you share there can be read, collected, or used by other users of these areas. You should use caution in disclosing personal information while participating in these sites. We are not responsible for the information you choose to submit in these public areas.

Your Rights

Opt Out. You may opt out of receiving general health and wellness or treatment options that may be relevant to you by emailing us at privacyoffice@curvehealth.com. You may also request that we delete your personal information by sending us an email at privacyoffice@curvehealth.com.

We may not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect. For example, Curve may be required by applicable law to retain your information fora specified period of time in backup media. Additionally, we may not be able to delete your personal information if Curve is not the system of record for such data. For example, Curve accesses personal information from a provider’s electronic health record for which you have previously provided authorization.

Accessing, Correcting, and Deleting Your Information. 

You can review and change personal information that we uniquely hold by sending us an email at privacyoffice@curvehealth.comto request access to, correct or delete any personal information that you have provided to us. We cannot delete your personal information from a providers electronic health record for which you have provided authorization. We may not accommodate a request to change information if we reasonably believe the change would violate any law or legal requirement or cause the information to be incorrect.

Security

We have implemented appropriate measures designed to secure information from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. You should understand that no data storage system or transmission of data over the Internet or any other public network can be guaranteed to be one hundred percent (100%) secure. Please note that information collected by third parties may not have the same security protections as information you submit to us, and we are not responsible for protecting the security of such information.

Changes to Our Privacy Policy

We reserve the right to update this Privacy Policy from time to time. When we update the Privacy Policy, we will revise the “Effective Date”date above and post the new Privacy Policy to our website. We recommend that you review thePrivacy Policy each time you visit the Services to stay informed of our privacy practices.

Contact Information

To ask questions or comment about this privacy policy and our privacy practices, contact us at:

Curve Health, Inc.

2121 Biscayne Blvd, #1037

Miami, FL 33137

privacyoffice@curvehealth.com

Effective: October 27, 2023