PRIVACY POLICY
Effective date: September 7, 2021
Introduction
This Privacy Policy applies to www.jointhera.com and all other websites, applications, services, and other offerings (collectively, the “Services”) owned and operated by Jointhera Inc. (“Jointhera,” “We,” “Us”). Here we describe how we collect, use, and handle your personal data when you use our Services.
Our Terms and Conditions (“Terms”) govern all use of our Services and together with the Privacy Policy constitutes your agreement with us (“Agreement”).
How Jointhera Collects Your Data
We may collect your personal information in the following situations:
a. Account registration. If you decide to create an account, you will provide us with certain personal information, such as your username and password.
b. Purchasing Jointhera Services. When you purchase Jointhera Services, you will provide us with personal information, such as your name, email address, payment information, and billing address.
c. Making a payment. When you make a payment to Jointhera , we may collect your personal information from our third-party payment processors, such as your credit card number.
d. User content. When you post a review of a Jointhera product on Jointhera.com or refer a friend to Jointhera on Jointhera.com, we receive the information in your submission, including any personal information.
e. Communicating with us. You may send us personal information by emailing us, calling our customer support, filling out an online support form.
f. Taking a survey. You may be asked to provide personal information for survey purposes.
g. Information we automatically collect. Our websites may collect and store information that is generated automatically as you use them, including your preferences and anonymous usage statistics. This information may include Internet protocol (IP) addresses, cookie identifier, browser type, Internet Service Provider (ISP), referring/exit pages, the files viewed on our websites and applications (e.g., HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data. We use this data to analyze trends in the aggregate and administer our Services. Information that we automatically collect may be combined with other information about you, including personal information such as when you are logged into your Jointhera account.
h. If you download our mobile application or use a location-enabled browser, we may receive information about your location and mobile device, as applicable.
i. Website tracking technologies. We use cookies, pixels, server logs, and other similar technology to analyze trends, administer the website, and track users’ movements around the website.
j. Information provided by third parties. Jointhera may collect information about you from third parties. If you place an order with a third-party retailer, that retailer will send your personal information to Jointhera so that we can fulfill your order.
How Jointhera Uses Your Data
We may use the collected data for various purposes:
a. to provide and maintain our Services;
b. to notify you about changes to our Services;
c. to allow you to participate in interactive features of our Services when you choose to do so;
d. to provide customer support;
e. to improve our services;
f. to detect, prevent and address technical issues;
g. to fulfill any other purpose for which you provide;
h. to carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including billing and collection purposes;
i. to provide you with notices about your account and/or subscription, including expiration and renewal notices, email-instructions, etc.;
j. to provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information;
k. in any other way we may describe when you provide the information;
l. for any other purpose with your consent.
How Jointhera Discloses Your Data
We may disclose personal information that we collect, or you provide for the following purposes:
a. Disclosure for Law Enforcement.
Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities.
b. Business Transaction.
If we or our subsidiaries are involved in a merger, acquisition or asset sale, your Personal Data may be transferred.
c. Other cases. We may disclose your information also:
i. to our subsidiaries and affiliates;
ii. to contractors, service providers, and other third parties we use to support our business;
iii. to fulfill the purpose for which you provide it;
iv. for the purpose of including your company’s logo on our website;
v. for any other purpose disclosed by us when you provide the information;
vi. with your consent in any other cases;
vii. if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of the Company, our customers, or others.
HIPAA Authorization and PHI
Jointhera may collect certain demographic, health, and/or health-related data on Users as part of providing the Services to our Healthcare Providers under the Health Insurance Portability and Accountability Act (“HIPAA”). Under HIPAA, specific categories of personal information are defined as "protected health information" or "PHI." When Jointhera, as a "Business Associate" (defined under HIPAA), receives identifiable information about a User from or on behalf of a Healthcare Provider and such Healthcare Provider is a "Covered Entity" (as defined in HIPAA), this information is treated as PHI.
HIPAA protects the privacy and security of your PHI by limiting the uses and disclosures of PHI by healthcare providers and health plans, like your physical therapists (“Covered Entities”) as well as companies like Jointhera, which provides certain assistance services to Covered Entities (“Business Associates”). Under HIPAA, in certain situations, you will need to sign a HIPAA Authorization form before a physical therapist can disclose PHI to a third party.
Personal data that a User provides to Jointhera in addition to the aforementioned scenario is not considered PHI (“Non-PHI”). For example, when you:
a. create an account or use our interactive tools and services, search for Healthcare Providers or available appointments with Healthcare Providers,
b. complete general medical history forms that are not associated with a particular
Healthcare Provider (“Medical History Forms”).
c. voluntarily provide information in free-form text boxes through the Services or through responses to surveys and questionnaires.
d. post reviews on our website.
e. provide device/IP Information or Web Analytics information by browsing our websites (see below); or
f. send us an email or otherwise contact us directly, that information is not PHI.
HIPAA specifically provides protections to PHI so that it is kept private and secure, and it restricts how the PHI may be used and disclosed. HIPAA only permits Jointhera to utilize and disclose PHI in the ways permitted by HIPAA or as authorized by the User.
Your Data Protection Rights under the California Privacy Protection Act (CalOPPA)
CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require a person or company in the United States (and conceivable the world) that operates websites collecting personally identifiable information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals with whom it is being shared, and to comply with this policy. – See more at: https://consumercal.org/about-cfc/cfc-education-foundation/california-online-privacy-protection-act-caloppa-3/
According to CalOPPA we agree to the following:
a. users can visit our site anonymously;
b. our Privacy Policy link includes the word “Privacy”, and can easily be found on the page specified above on the home page of our website;
c. users will be notified of any privacy policy changes on our Privacy Policy Page;
d. users are able to change their personal information by emailing us at privacy@jointhera.com.
Our Policy on “Do Not Track” Signals:
We honor Do Not Track signals and do not track, plant cookies, or use advertising when a Do Not Track browser mechanism is in place. Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked.
You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.
Your Data Protection Rights under the California Consumer Privacy Act (CCPA)
If you are a California resident, you are entitled to learn what data we collect about you, ask to delete your data and not to sell (share) it. To exercise your data protection rights, you can make certain requests and ask us:
a. What personal information we have about you. If you make this request, we will return to you:
i. The categories of personal information we have collected about you.
ii. The categories of sources from which we collect your personal information.
iii. The business or commercial purpose for collecting or selling your personal information.
iv. The categories of third parties with whom we share personal information.
v. The specific pieces of personal information we have collected about you.
vi. A list of categories of personal information that we have sold, along with the category of any other company we sold it to. If we have not sold your personal information, we will inform you of that fact.
vii. A list of categories of personal information that we have disclosed for a business purpose, along with the category of any other company we shared it with.
Please note, you are entitled to ask us to provide you with this information up to two times in a rolling twelve-month period. When you make this request, the information provided may be limited to the personal information we collected about you in the previous 12 months.
b. To delete your personal information. If you make this request, we will delete the personal information we hold about you as of the date of your request from our records and direct any service providers to do the same. In some cases, deletion may be accomplished through de-identification of the information. If you choose to delete your personal information, you may not be able to use certain functions that require your personal information to operate.
c. To stop selling your personal information. We don't sell or rent your personal information to any third parties for any purpose. You are the only owner of your Personal Data and can request disclosure or deletion at any time.
Please note, if you ask us to delete or stop selling your data, it may impact your experience with us, and you may not be able to participate in certain programs or membership services which require the usage of your personal information to function. But in no circumstances, we will discriminate against you for exercising your rights.
To exercise your California data protection rights described above, please send your request(s)
by one of the following means:
By email: privacy@jointhera.com
Your data protection rights, described above, are covered by the CCPA, short for the California Consumer Privacy Act. To find out more, visit the official California Legislative Information website. The CCPA took effect on 01/01/2020.
Third Party Services Providers
We may employ third party companies and individuals to facilitate our Services (“Services Providers”), provide Services on our behalf, perform Service-related services or assist us in analyzing how our Services are used.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
Analytics
We may use third-party Services Providers to monitor and analyze the use of our Services. These third-party Service Providers include but are not limited to:
Google Analytics
Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Services. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.
For more information on the privacy practices of Google, please visit the Google Privacy Terms web page: https://policies.google.com/privacy?hl=en
We also encourage you to review Google's policy for safeguarding your data:
https://support.google.com/analytics/answer/6004245
Google Cloud Platform
Google Cloud Platform is a suite of public cloud computing services offered by Google. The platform includes a range of hosted services for compute, storage and application development that run on Google hardware.
For more information on the privacy practices of Google, please visit the Google Privacy Terms web page: https://policies.google.com/privacy?hl=en
We also encourage you to review Google's policy for safeguarding your data:
https://support.google.com/analytics/answer/6004245
Mailchimp
Mailchimp is an all-in-one marketing platform that helps businesses manage and talk to their clients, customers, and other interested parties.
For more information on the privacy policies of Mailchimp, please visit https://mailchimp.com/legal/privacy/
Agora
Agora is a real time engagement platform connecting businesses with their customers.
For more information on the privacy practices of Agora, please visit https://www.agora.io/en/privacy-policy/
Third-Party Payment Processor
We use the third-party payment processor Stripe to process payments made to us. We do not retain any personally identifiable information or any financial information such as credit card numbers. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
Your Control and Access of Your Data
You have control over your personal data and how it’s collected, used, or shared. You may do so by contacting us at privacy@jointhera.com. For example, you can:
a. Delete Your Content in your Jointhera account or ask the party you are affiliated with to delete Your Content.
b. Change or edit personal data.
c. Access and transfer your data elsewhere.
d. Object to or limit the processing of your personal data. You may request that we stop or limit the processing of your personal data at any time by contacting us at privacy@jointhera.com.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
We will let you know via email and/or a prominent notice on our Services, prior to the change becoming effective and update “effective date” at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, please contact us:
By email: privacy@jointhera.com
Jointhera Inc.
8 The Green Ste B,
Dover DE 19901