Privacy Notice
Introduction
In order to ensure transparency and give you more control over your Personal Information (as defined below), this Privacy Notice (“Privacy Notice”) governs how we, TailorMed Medical Inc. (“TailorMed”, “we”, “our” or “us”) use, collect and store Personal Information we collect or receive from or about you (“you”), through our website https://tailormed.com/ (the “Website”), the TailorMed Platform and other services (collectively, the “Services”). This Privacy Notice is integrated into and forms part of our Terms of Use (“Terms”).
We greatly respect your privacy, which is why we make every effort to provide a platform that would live up to the highest user privacy standards. This Privacy Notice was designed to help you understand the information we collect, store, use and share, and it applies whenever you visit, install, or interact with our Services.
We strongly urge you to read this Privacy Notice and make sure that you fully understand and agree to it. If you do not agree to this Privacy Notice, please discontinue and avoid using our Services. You have the right to cease using our Services at any time, pursuant to this Privacy Notice and our Terms. You are not legally required to provide us with any Personal Information, but without it we will not be able to provide you with the best experience of using our Services.
Important note: Nothing in this Privacy Notice is intended to limit in any way your statutory right, including your rights to a remedy or means of enforcement.
Specifically, this Privacy Notice describes:
Table of Contents
1. About Us
2. What Types of Information We Collect?
3. Why we Collect it and Legal Bases for Processing
4. Collection, Disclosure and Sharing of Personal Information
5. Sources of Personal Information
6. Purposes for Collection, Processing and Sharing
7. To Whom do we Disclose Your Personal Information
8. Authorized Agent
9. Direct Marketing Requests
10. How do we Protect Your Personal Information?
11. International Transfer
12. Your Privacy Rights
13. Minors
14. Tracking Technologies
15. Social Features
16. Third-Party Products and Services
17. Marketing
18. Data Retention
19. Updates to This Privacy Notice
20. Contact Us
1. About Us
TailorMed is a provider of a comprehensive suite of solutions to address access, affordability and adherence barriers across the medication journey. TailorMed’s mission is to harness technology to improve the financial performance of healthcare organizations and reduce the friction for patients. This mission is achieved through a software solution that help healthcare organizations and patients, identify opportunities to support patients through their medical journey, and maximize workflow efficiency, at scale. Using data and advanced analytics, the TailorMed platform streamlines all steps of the process, from benefit investigation and remaining out-of-pocket to enrollment and management of approved programs.
For the avoidance of doubt, for the purposes of this Privacy Notice, “Customer(s)” are entities, which executed agreements with TailorMed, including, hospitals and other healthcare-related entities.
If your Personal Information is provided to us as a result of our relationships with Customer (“Individual(s)”), please note that the Customer is the responsible party for obtaining the required consents and complying with any applicable laws and regulations with respect to the collection, processing, transfer and use of your Personal Information. Accordingly, we encourage you to read the privacy policy of the Customer.
2. What Types of Information We Collect?
We collect two types of information from you: Personal Information (“Personal Information” or “Personal Data” under applicable laws) and non-Personal Information.
Personal Information means any information which may potentially allow your identification with reasonable means (for example, email address or name).
Non-Personal Information, by contrast, can be defined as any information that does not relate to an identified or identifiable natural person. This may include, for example, your aggregated usage information and technical information transmitted by your device (e.g. the device you use, the type of browser and operating system your device uses, language preference, access time, etc.). Our use of non-Personal Information is outside the scope of this Privacy Notice.
This section sets out how and when we collect Personal Information from you. If we associate Non-Personal Information with Personal Information, we will treat such information as Personal Information as long as such association exists.
3. Why we Collect it and Legal Bases for Processing
3.1. We may collect and process the following types of Personal Information:
• Information you provide directly to us.We collect Personal Information you provide directly to us, including Personal Information when you browse and make use of our Website and Platform, that may include, full name, business name & address, email address, phone number, employees’ information (including, without limitation, name, email address, phone number).
• If you contact us directly (via email, Website or telephone), we may receive additional information about you such as your name, email address, phone number, the contents of those communications, and/or attachments you may send us, feedback, and/or answers to surveys or questionnaires that you may submit, and any other information you may choose to provide.
• Account information. If you choose to register an account with our Services, we may collect your full name, username, password, email address and phone number. We collect this information to create, maintain and secure your account. If you choose to register an account, you are responsible for keeping your account credentials safe.
• Sensitive personal health information. During your use of the Services, you may choose to provide us with your personal health information, such as information pertaining to your particular medications, insurance, medical conditions or other related information, so we can provide you with our Services and assist you in assessing your eligibility for locating suitable assistance programs or offering other related services and content pertaining your health.
• Information provided in the context of TailorMed Services.TailorMed may receive Personal Information in the context of providing its Services to the Customers (including, without limitation, patients’ data, doctor details, patients’ health needs, insurance information), in such cases, please note that the Customer is the responsible party for of Personal Information. Please make sure that you contact the Customer for any inquiry.
• Information from other sources.TailorMed may also obtain information (that in general will not contain Personal Information) about you from other sources, including private and publicly – or commercially – available information, and through third-party partners and service providers.
• Device and technical information.We may automatically collect certain Personal Information through your use of TailorMed Services and from your device, such as your Internet protocol (IP) address, cookie identifiers and other device identifiers that are automatically assigned to your device, browser type and language, geo-location information, hardware type, operating system, internet service provider and other information about actions taken through the use of TailorMed Services.
• Marketing and Communications Information. When you send us an email or contact us via the support on our Website, we collect the Personal Information you provide us. This may include your name, email address and any other information you choose to provide. This may also include your preferences regarding marketing communications, your responses to our surveys or promotions, and information about your interactions with marketing emails or other communications.
3.2. We Process Personal Information for the following purposes:
a. To provide you with TailorMed Services. TailorMed will use your Personal Information to provide TailorMed Services, including: (i) process your request; (ii) share your Personal Information with some of our partners and and/or third party companies (to the extent provided under this Policy); (iii) communicate with you about the options that you may have for the requested information; (iv) fulfill any orders for services or products made by you; (v) track requests sent by you; (vi) provide you with information about our products or services or the products and services we offer jointly with or on behalf of other organizations; and (vii) to personalize your experience with TailorMed Services.
b. For administrative purposes.TailorMed may use your Personal Information (i) to respond to your questions, comments, and other requests for Customer support, or information, including information about potential or future services; (ii) to provide you with TailorMed Services; (iii) for internal quality control purposes; (iv) to establish a business relationship; (v) for testing, research, analysis, and product development, including to develop and improve our Website and Services and in connection with providing and maintaining our products, and Services; and (vi) to generally administer TailorMed Services.
c. To market TailorMed Services.TailorMed may use Personal Information to market TailorMed Services. Further information can be found under section 17 of this Privacy Notice.
d. Security purposes.Some of the aforementioned Personal Information will be used for detecting, taking steps to prevent, and prosecution of fraud or other illegal activity, to identify and repair errors, to conduct audits, and for security purposes. Personal Information may also be used to comply with applicable laws, with investigations performed by the relevant authorities, law enforcement purposes, and/or to exercise or defend legal claims.
e. De-identified and aggregated information use.In certain cases, we may or will anonymize or de-identify your Personal Information and further use it for internal and external purposes, including, without limitation, to improve the Services and for research purposes. “Anonymous Information” means information which does not enable identification of an individual user, such as aggregated information about the use of our services. We may use Anonymous Information and/or disclose it to third parties without restrictions (for example, in order to improve our services and enhance your experience with them).
f. Tracking Technologies.We, as well as third parties that provide content, advertising or other functionality on the TailorMed Website, may use cookies, pixel tags, local storage, and other Tracking Technologies (“Tracking Technologies”). Further information can be found under section 14 of this Privacy Notice.
g. Integrity, security and compliance with applicable laws. Please note that some of the aforementioned Personal Information will be used for detecting, taking steps to prevent, and prosecuting fraud or other illegal activity, to identify and repair errors, to conduct audits, and for security purposes. Personal Information may also be used to comply with applicable laws, with investigations performed by the relevant authorities, law enforcement purposes, and/or to exercise or defend legal claims.
3.3. Legal bases for processing
Where applicable, we rely on one or more of the following lawful bases for processing Personal Information:
a. You gave us your consent to the processing of your Personal Information (for one or more specific purposes) including through our Website(s) in order to implement Tracking Technologies.
b. Processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
c. We process Personal Information about individuals in accordance with our legitimate interests, such as, as applicable, to improve and enhance our Services, to understand how our Services are used, to optimize our marketing, advertising, customer services and support operations, to maintain the security of our Services, to enforce any applicable terms and conditions of service, and to protect or defend the Services and our rights.
d. Processing is necessary for compliance with a legal obligation to which we are subject.
4. Collection, Disclosure and Sharing of Personal Information
(a) We do not “Sell” or “Share” Personal Information about you (in the meaning assigned to these terms under US Privacy Laws).
(b) In the preceding twelve (12) months, we have disclosed your Personal Information as follows:
When we disclose Personal Information, we ensure that the recipient only have access to such information that is strictly necessary for us to provide the Services. These parties are required to secure the Personal Information they receive, and to use it for pre-agreed purposes only, while ensuring compliance with all applicable data protection regulations.
(c) In the preceding twelve (12) months, we have collected, disclosed or shared the following categories of Personal Information:
5. Sources of Personal Information
In the preceding twelve (12) months, we have collected the above-mentioned categories of Personal Information from the following categories of sources:
• Directly, through your activity on our Services: for example, from your interaction with the Website, our Services and when you provide information via our Services;
• Indirectly from you: we track your activities across the internet, for example, when you view or interact with certain content, web pages or ads.
• From third parties: for example, from service providers who assist us in performing the Services.
We do not offer financial incentive to end users for providing Personal Information.
6. Purposes for Collection, Processing and Sharing
In addition to the practices detailed in this Privacy Notice, we also use and disclose the Personal Information we collect for the following commercial and business purposes:
• Auditing related to our interactions with you;
• Legal compliance;
• Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and necessary prosecution;
• Debugging;
• Performing services (for us or our partners);
• Internal research for technological improvement;
• Internal operations;
• Activities to maintain and improve our services; and
• Other one-time or short-term uses.
7. To Whom do we Disclose Your Personal Information
We may disclose your Personal Information as described below:
8. Authorized Agent
In some jurisdictions, you can use an authorized agent to make a request to exercise your right under applicable laws on your behalf if:
• The authorized agent is a natural person or a business entity; and
• You sign a written declaration that you authorize the authorized agent to act on your behalf. If you use an authorized agent to submit a request to exercise your right, please provide us with a certified copy of your written declaration authorizing the authorized agent to act on your behalf using the contact information below.
The request must:
• Provide sufficient information to allow us to reasonably verify you are the person about whom we collected Personal Information or an authorized agent. We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you; and
• Describe your request with sufficient details to allow us to properly understand, evaluate, and respond to it.
• We will only use Personal Information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
Please note that making a verifiable consumer request does not require you to create an account with us.
9. Direct Marketing Requests
• California Privacy Rights.California Civil Code Section 1798.83 permits our customers who are California residents to request certain information regarding disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request, please send an email to support@tailormed.co. Please note that we are only required to respond to one request per customer each year.
10. How do we Protect Your Personal Information?
We have implemented administrative, technical and physical, safeguards to help prevent unauthorized access, use, or disclosure of your Personal Information. Your Personal Information is protected by robust safeguards to ensure secured processing. For example, we ensure Personal Information is encrypted both in transit and at rest, and any access is strictly limited to a minimum number of authorized individuals who are subject to confidentiality commitments. However, please note that we cannot guarantee that the information will not be compromised as a result of unauthorized penetration to our servers. As the security of information depends in part on the security of the computer, device or network you use to communicate with us and the security you use to protect your user IDs and passwords, please make sure to take appropriate measures to protect this information.
TailorMed maintains a Security Management Program (SMP) which complies with the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act (found in Title XIII of the American Recovery and Reinvestment Act of 2009), and their associated regulations.
11. International Transfer
Please note that our businesses, as well as our service providers, are located around the world. We are a US and Israeli based company, but we operate globally. Information that we collect, disclose or share, including (but not limited to) your Personal Information, shall be stored exclusively in the US, but could be otherwise processed in the US and Israel, for the purposes detailed in this Privacy Notice and pursuant to any signed agreement by us. Where required by applicable laws, we will transfer your Personal Information only after ensuring an adequate level of data protection, as required under these laws.
12. Your Privacy Rights
Depending on the jurisdiction in which you reside, you may have certain rights under relevant applicable laws regarding the collection and processing of your Personal Information. To the extent these rights apply and concern you, you can exercise your rights by contacting us at support@tailormed.co.
• Rights of access: The right to receive confirmation as to whether or not Personal Information concerning you is being processed, and access your stored Personal Information, together with supplementary information.
• Right of portability: The right to request us to move, copy and transfer your Personal Information easily from one IT environment to another, in a safe and secure way, without affecting its usability.
• Right of rectification: The right to request rectification of your Personal Information that is in our control, in the event that you believe the Personal Information held by us is inaccurate, incomplete or outdated.
• Right of deletion/erasure: The right to request that we erase or delete Personal Information held about you.
• Right to restriction of processing: The right to request to restrict the processing of your Personal Information by us.
• Right to object to processing: The right to request that we cease to conduct certain Personal Information processes at any time.
• Right to withdraw your consent: Where we rely on consent to process Personal Information about you, you have the right to withdraw your consent to the collection, use or processing of your Personal Information at any time. Exercising this right will not affect the lawfulness of processing your Personal Information based on your consent before its withdrawal.
• Right to limit use and disclosure of your sensitive Personal Information: The right to request to limit the processing of your sensitive Personal Information, to that use which is necessary to perform our Services.
• Right not to be subject to automated decision making: The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly effects to you.
• Right to opt-out of the sale or share of Personal Information: In the event that we sell or share your Personal Information for behavioral advertising purposes, you may have the right to submit a request to opt-out of the sale or share of your Personal Information.
• Right to non-discrimination: You have the right to be free from any discrimination for exercising your rights, such as offering you different pricing or products, or by providing you with a different level or quality of services, based solely upon your request.
Please note that these rights are not absolute, and may be subject to our own legitimate interests and regulatory requirements.
12.1. Right to Lodge a Complaint and Appeal Our Decisions
You may exercise these rights by contacting us at support@tailormed.co. We will consider any requests, complaints or queries and provide you with a reply in a timely manner in accordance with applicable law. We take our obligations seriously and we ask that any concerns are first brought to our attention, so that we can try to resolve them.
In some jurisdictions, you have the right to appeal a rejection of your request. The appeal request shall be submitted to support@tailormed.co, or using the contact details specified in the “Contact Us” section in this Privacy Notice. If your appeal is denied, certain jurisdictions allow you to submit a complaint via the local attorney general or another competent authority responsible for handling such matters.
If you think we have infringed data protection laws, you can file a claim with the data protection supervisory authority in your jurisdiction of residency, as applicable to you.
Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly in accordance with applicable law or inform you if we require further information in order to fulfil your request. When processing your request, we may ask you for additional information to confirm or verify your identity and for security purposes, before processing and/or honoring your request. We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive. In the event that your request adversely affect the rights and freedoms of others (for example, if it impacts the duty of confidentiality we owe to others) or if we are legally entitled to deal with your request in a different way than initial requested, we will address your request to the maximum extent possible, all in accordance with applicable law.
12.2. Consumer Health Data Privacy Laws
Depending on the jurisdiction in which you reside, you may have certain rights under some Consumer Health Data privacy laws. For more information regarding your rights, please refer to our Consumer Health Data Privacy Notice.
13. Minors
We do not offer our products or services for use by Minors (as determined under the applicable laws where the individual resides; “Minors”). We do not knowingly collect Personal Information from, and/or about Minors. By accessing or using our Services, you certify to us that you are not a Minor. If you are a Minor, do not provide any Personal Information to us without involvement of a parent or a guardian. In the event that we become aware that we have collected Personal Information from a Minor without verification of parental consent, we will delete that information upon discovery. If you believe that we might have any such information from or about a Minor, please contact us at support@tailormed.co.
14. Tracking Technologies
When you visit or access our Services we use (and authorize 3rd parties to use) pixels, cookies, web beacons and other similar Tracking Technologies. These allow us to automatically collect information about you, your device and your online behavior, in order to enhance your navigation in our Services, improve the performance of our Services, perform analytics, serve advertisements, customize your experience and to administer our Services.
Which Tracking Technologies do we Use?
We store first-party and third-party Tracking Technologies when you visit or access our Services (for example, when you visit our Website, purchase our Services, respond to our communications, contact support, or communicate with us via email, the Website or other online platforms). These Tracking Technologies may be stored for the duration of your visit on our Services or for repeat visits.
The main types of Tracking Technologies we use can be categorized as follows:
• Strictly Necessary – These Tracking Technologies are essential to enable you to log in, navigate, and use the features of our Services, or to provide a service requested by you (such as your username). We do not need to obtain your consent to use these Tracking Technologies. They may also be used for security and integrity purposes, such as detecting policy violations and enabling support or security features.
• Functionality – These Tracking Technologies allow our Services to remember choices you make (such as your language) and provide enhanced and personalized features. For example, they are used for authentication (to remember when you are logged-in) and support other features of our Services.
• Performance and Analytics – These Tracking Technologies collect information about your online activity (for example the duration of your visit on our Services). They are used for analytics, research and statistical purposes (based on aggregated information).
Our Website and Services use analytics tools, including Google Analytics, a web analysis service provided by Google Inc. (“Google”) which is based on Tracking Technologies. The information generated by these Tracking Technologies is usually sent to and stored on Google server in the USA. On behalf of TailorMed, Google will use the generated information to evaluate your use of the Website and the Services, to compile reports on website activities, and to provide the website operator with additional services connected with website and internet use. The IP address transmitted by your browser in connection with Google Analytics is not collated with other data by Google. We use the information we get from Google to maintain and improve our Website and Services. We do not combine the information collected through the use of Google with Personal Information we collect. Further information about the privacy practices of Google Analytics is available here. Further information about your option to opt-out of Google Analytics is available here. We may add or remove analytic tools at any time.
• Marketing and Advertising – These Tracking Technologies are used to deliver tailored offers and advertisements, based on your interests, and to perform email marketing campaigns. We may share this information with advertisers or use it to better understand your interests, for example, to show more relevant ads, enable to share pages with social networks, or allow you to post comments on our sites.
• Social Media and Similar – These Tracking Technologies include social media features, such as Facebook “Like” or “Share” buttons, or third-party log-in services. They may be hosted by a third-party or directly on our Services. Your interactions with these features are governed by the privacy statement of the company providing them.
How Can you Control Tracking Technologies?
Except for Strictly Necessary Tracking Technologies, you can always withdraw your consent to non-essential ones through your web browser or device settings, usually found in the ‘Options’ or ‘Preferences’ menu of your browser.
The following links may be helpful for information on how to manage your Tracking Technologies on some browsers: Google Chrome; Internet Explorer; Mozilla Firefox; Safari (Desktop); Safari (Mobile); Android Browser; Microsoft Edge; Opera; and Opera Mobile.
Any such changes may require you to manually adjust preferences each time you visit a site, and some services or functionalities may not work. If you reject Tracking Technologies through your browser, you may still use the Website and Services, but some features may be limited.
Do-Not-Track (DNT) Signals
Cal. Bus. And Prof. Code Section 22575 requires us to notify you about how we handle “Do Not Track” settings in your browser. As of the effective date listed above, there is no commonly accepted response for Do Not Track signals initiated by browsers, therefore, we do not respond to them. Do Not Track is a privacy preference you can set in your web browser to indicate that you do not want certain information about your web page visits tracked and collected across websites. For more details, including how to turn on Do Not Track, visit: www.donottrack.us.
Advertisers Tracking Technologies
If you are primarily concerned about third-party Tracking Technologies generated by advertisers, and you live in the USA, Canada or Europe, you can also opt out from the collection of your data by our advertising partners who participate in the Digital Advertising Alliance. Opt out from the collection of such data by visiting the following websites: www.aboutads.info/choices (USA users); www.youradchoices.ca/choices (Canadian users); and www.yourchoicesonline.com (European users).
You can learn more and turn off certain third-party targeting and advertising Tracking Technologies by visiting the following third-party webpages: The Interactive Advertising Bureau (USA); The Interactive Advertising Bureau (EU); and European Interactive Digital Advertising Alliance (EU).
If you have enabled Global Privacy Control (“GPC”) (a technological tool that may be used to control your cookies and tracking preferences), you can manage your settings accordingly. To learn more about the GPC, please download and use a browser supporting the GPC browser signal by clicking here: https://globalprivacycontrol.org/.
You are also able to opt out of our use of Tracking Technologies, to the extent our processing of Personal Information via such Tracking Technologies is deemed to be a “sale” or “share” under applicable U.S.A state laws.
Useful Links
For more on Tracking Technologies and their use on the internet, see the following websites: www.allaboutcookies.org and www.youronlinechoices.co.uk.
15. Social Features
Certain features of the Services allow you to initiate interactions between the Services and third-party services or platforms, such as social networks (“Social Features”). Social Features include features that allow you to access our pages on third-party platforms, and from there “like” or “share” our content. Use of Social Features may allow a third party to collect and/or use your information. If you use Social Features, information you post or make accessible may be publicly displayed by the third-party service. Both we and the third party may have access to information about you and your use of both the Services and the third-party service. For more information, see the section below, “Third-Party Products and Services”.
16. Third-Party Products and Services
We enable you to engage with third-party websites, mobile applications and products or services that are not under our ownership or control (referred to as “Third-Party Service”). However, we are not responsible for the privacy practices, security measures, or content of these Third-Party Services. Please note that these Third-Party Services may collect Personal Information from you. Therefore, we strongly encourage you to read the terms and conditions and privacy policies of any Third-Party Service you engage with.
17. Marketing
We may use Personal Information, such as your full name, email address, etc., collected by us or through our trusted third-party service providers for the purpose of providing users with promotional materials such as: (i) notifying you about offers and services that may be of interest to you that we offer and/or that we offer jointly with or on behalf of other organizations; (ii) tailoring content, advertisements, and offers for you, including, targeting and re-targeting practices; (iii) conducting market research; (iv) developing and marketing new products and services, and to measure interest in TailorMed Services; (v) other purposes disclosed at the time you provide Personal Information; and (vi) as you otherwise consent.
The materials are delivered in different marketing techniques such as direct email, as well as products, services, websites and applications, which relate to: (i) other companies within our group, as applicable; or (ii) our business partners and affiliates, which we believe could interest you, subject to obtaining your explicit consent, when required by applicable law.
Users have the possibility at any time to decline receiving further marketing offers from us by either: following the links inserted in the promotional emails (e.g., selecting the opt-out link) or contacting TailorMed’s customer support. Please note that even if you unsubscribe from TailorMed’s marketing mailing list, TailorMed shall continue to send you Service-related updates and notifications.
You may opt-out of receiving our promotional or marketing emails (all or any part thereof) by clicking on the “unsubscribe” link in the emails that you receive from us or by contacting us at support@tailormed.co.
18. Data Retention
We will retain your Personal Information for as long as necessary to provide our Services, and as necessary to comply with our legal obligations, resolve disputes, and enforce our policies. Retention periods will be determined taking into account the type of information that is collected and the purpose for which it is collected, bearing in mind the requirements applicable to the situation and the need to destroy outdated, unused information at the earliest reasonable time.
19. Updates to This Privacy Notice
We reserve the right to change this Privacy Notice at any time. The most current version will always be posted on our Website (as reflected in the “Last Updated” heading). You are advised to check for updates regularly. By continuing to access or use our Services after any revisions become effective, you agree to be bound by the updated Privacy Notice. However, if this Privacy Notice is changed in a significant way, a notice will be posted on the home page of the Website 7 days before the changes take effect, unless the changes originate from any legal or regulatory requirement, in which case, the change shall enter into force in accordance with such requirement.
20. Contact Us
If you have any questions, concerns or complaints regarding our compliance with this notice and the data protection laws, or if you wish to exercise your rights, we encourage you to first contact us at support@tailormed.co.
