I. General Policy

A. Acceptance of Terms

MedBridge Inc. (“MedBridge”) is committed to protecting Your privacy when You visit the MedBridge website located at the URL www.medbridge.com, the MedBridge mobile application, and other websites owned by MedBridge, including personalized white label websites (collectively, the “MedBridge Website”, as defined below). This Privacy Policy explains to You how we collect and use Your information. This document should be read in conjunction with the MedBridge Terms and Conditions, and we reserve the right to append or otherwise modify this privacy statement at any time.

B. Term Definitions

1. The term “MedBridge Website” refers to the MedBridge website accessible through the URL www.medbridge.com, the MedBridge mobile application, and other websites owned by MedBridge, including personalized white label websites.

2. The term “MedBridge” refers to MedBridge, Inc.

3. The term “MedBridge Mobile App” refers to the MedBridge GO Mobile application available as an iOS and Android application that provides patients access to their assigned exercise programs from their phone or tablet.

4. The term “User Profile” refers to a profile posted by a User on the MedBridge Website.

5. The terms ''You'', “Your” and/or ''User'' refer to any individuals and/or entities visiting and/or otherwise accessing the MedBridge Website for any reason.

6. The term “Content” refers to all information, data, text, software, music, sound, photographs, graphics, video, messages, tags, or other materials posted and/or otherwise displayed on, to, or at the MedBridge Website.

7. The term “Personal Information” includes, but is not limited to, any information that identifies or describes an individual, including his or her name, professional licensing information, social security number, physical description, age, gender, marital status, health status, financial status, home address, home telephone number, education, financial matters, and medical or employment history. Personal Information may also include statements made by, or attributed to, a User.

C. Collection of User Data

MedBridge collects user data during registration and use of the MedBridge Website and associated services such as described below with the consent of the user and for the legitimate business purpose of providing the services offered by the MedBridge Website.

II. Your Personal Information

A. Information Collected by MedBridge

By voluntarily creating a User Profile on the MedBridge website, You agree to the MedBridge Terms of Use, and consent to MedBridge’s collection of Personal Information. To establish Your User Profile, MedBridge collects Your name and email address, and in some cases your clinical discipline.

MedBridge collects additional information when You continue the use of the site and agree to our Terms of Use in order to receive MedBridge services and access MedBridge Content. When you assign or complete education courses or patient exercises on the MedBridge website, MedBridge collects data relating to the assignment of and/or completion of courses and/or exercises, as well as applicable clinical licensing information.

Within the last twelve months, MedBridge has collected the following categories of personal information from consumers:

Category Data
Identifiers.

A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers.

Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).

A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.

Protected classification characteristics under California or federal law.

Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).

Commercial information.

Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

Biometric information.

Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.

Internet or other similar network activity.

Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.

Geolocation data.

Physical location or movements.

Professional or employment-related information.

Current or past job history or performance evaluations.

Inferences drawn from other personal information.

Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

Personal Information is provided at Your own risk. By providing Your Personal Information, You are communicating Your consent to MedBridge’s collection, use and disclosure of such Personal Information for the purposes for which You provided the information to MedBridge, and as described in this Privacy Policy.

B. Data Controller

For the majority of the information maintained, collected, or used by MedBridge, MedBridge is the data controller who is responsible for determining the purpose and means of processing personal data. For some healthcare data, Your individual provider and/or their organization may be the data controller for whom MedBridge holds and processes data. Inquiries can be directed to [email protected].

C. Using Your Information

Information is collected about You in order to establish and enhance our relationship with You. MedBridge’s use of this information includes the following: (i) to personalize Your experience, so we are better able to respond to Your individual needs; (ii) improve our website through Your feedback; (iii) more effectively responding to customer service requests and support needs and improve customer service; (iv) process transactions; (v) contacting You; (vi) conducting research and compiling aggregate data for internal and external business purposes; and (vii) any other purpose disclosed to You at the time we collect Your information.

Much of the information collected by MedBridge is necessary for proper functioning of the MedBridge Website and use of the MedBridge products. For example, You may not be able to create a user account or reset your password without provision of a valid email address. Further, MedBridge will store Your log-in credentials on Your device while using the MedBridge Mobile App, to provide a seamless experience. In these situations, if You choose to withhold any personal data requested by MedBridge, it may not be possible for You to gain access to certain parts of the site.

D. Updating and Deleting Your Information

On the MedBridge Website You are able to correct, update, review, or delete information You have submitted by going back to the specific tool and making the desired changes. If you are unable to make the changes on the MedBridge Website, you can request MedBridge to change, correct, or delete information by contacting us at [email protected] or call (888) 824-9839.

You have the right to withdraw consent to MedBridge’s use or processing of Your Personal Information at any time. If You refuse to consent to, opt out of, or withdraw Your consent, we may not be able to offer You certain services or benefits.

E. Retention of Information

MedBridge stores and retains Personal Information based on the level of sensitivity of this information, and for the period specified by the applicable legal and regulatory requirements. For some healthcare data, Your individual provider and/or their organization may require MedBridge to retain data based on their individual legal and contractual requirements.

F. Information Sharing and Disclosure

We may share Your information with trusted third parties who assist us in operating our website, conducting our business, or serving You, as long as those parties agree to keep this information confidential to the extent outlined under this Privacy Policy and consistent with applicable laws and regulations. We may also release Your information when we believe it is needed to comply with the law, enforce our site policies, or protect ours or others’ rights, property, or safety. Non-personally identifiable information may be provided to other parties for marketing, advertising, or other uses.

G. Sale of Personal Information

In the past twelve months, MedBridge has not sold any collected Personal Information to third parties.

H. Changes in MedBridge Inc.

If MedBridge is sold, merged, or otherwise transferred, personal information may be transferred along with it.

I. Information Use related to the Use of the MedBridge Mobile App

You may also opt into receiving Push Notifications from the MedBridge Mobile App. If you wish to stop receiving push notifications, you may turn off this feature in the settings on your device.

When you delete the MedBridge mobile application, any information saved in your device will be deleted, but any information collected and stored by us will remain in our server.

J. Additional Information Use

We may use Your email for transactional purposes, as well as for promotional purposes. Transactional purposes include confirmation and notification of changes to Your account. Promotional purposes include sending You newsletters about new features, special offers, promotional announcements, consumer surveys, and other items concerning our service. During registration at the MedBridge Website, You may be signed up to receive promotional email newsletters from MedBridge, unless disallowed by Your jurisdiction of residence. Email messages may contain code that enables our database to track Your usage of the emails to determine whether the email was opened and what links, if any, were clicked. Should You prefer not to receive promotional emails from us, please edit the preferences in Your account menu or click Unsubscribe at the bottom of any promotional emails.

K. Access to Information

Users may have a right to request access to Your information collected or processed by MedBridge. You can request such access by contacting us at [email protected]. Upon verification of Your identity, we will make sure to provide You with a copy of the data we process about You. In some circumstances we may need to work with Your healthcare provider in order to provide copies of sensitive information.

L. International Privacy Laws

If You are accessing the MedBridge Website and associated services from outside the United States, please be aware that You are sending information (including Personal Data) to the United States where our servers are located.

If You reside within the European Union, You may have the right to lodge a complaint regarding MedBridge’s information collection and processing with your local, national supervisory authority.

M. California Residents’ Rights

This Section applies only to Users of the MedBridge Website who reside in the State of California. Under the California Consumer Privacy Act of 2018 (CCPA) California consumers have the right to:

  • Know the categories of Personal Information we collect and the categories of sources from which we obtained the information;

  • Know the business or commercial purposes for which we collect and share Personal Information;

  • Know the categories of third parties and other entities with whom we share Personal Information; and

  • Access the specific pieces of Personal Information we have collected about you.

To obtain any additional information not found in this Privacy Policy, please send an email to [email protected] and include Your name, email address, California postal address as well as the email associated with Your User Profile, if one exists (“Verification Information”). You may also exercise Your rights by calling (888) 824-9839.

Right to Deletion. In some circumstances You may ask us to delete your Personal Information. To do so, please send an email Verification Information to [email protected]. You may also exercise your right by calling (888) 824-9839.

Submission of Your Request. You may only submit a request to know twice within a 12-month period. Your request to know or delete must:

  • Provide sufficient information that allows us to reasonably verify You are the person about whom we collected personal information or an authorized representative,

  • Describe Your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

We cannot respond to Your request or provide you with Personal Information if we cannot verify Your identity or authority to make the request and confirm the Personal Information relates to You. You do not need to create an account with us to submit a request to know or delete Your Personal Information. We will use the Personal Information provided in Your request only to verify the Your identity or authority.

Right to opt out of Sales. MedBridge does not share Your Personal Information with third parties in ways that may constitute a “sale” under CCPA. In line with this, MedBridge further does not sell Personal Information of consumers under 16 years of age. You may request that we do not “sell” Your Personal Information on a go forward basis. To do so, please email [email protected] and include your Verification Information. You may also exercise Your right by calling (888) 824-9839. If You reengage with MedBridge after opting out of the “sale” of Your Personal Information, such as purchasing a new subscription, Your Personal Information will be collected and used in accordance with this Privacy Notice.

You have the right to not be discriminated against for exercising any of Your CCPA rights, and MedBridge will not do any of the following based on any exercise of Your rights:

  • Deny You goods or services.

  • Charge You different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.

  • Provide You a different level or quality of goods or services.

  • Suggest that You may receive a different price or rate for goods or services or a different level or quality of goods or services.

However, we may offer You certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to Your Personal Information's value and contain written terms that describe the program's material aspects. Participation in a financial incentive program requires Your prior opt-in consent, which You may revoke at any time.

III. Automatically Collected Information

As You use MedBridge, certain information may also be passively collected and stored on our or our service providers’ server logs, including Your Internet protocol address, browser type, and operating system. When you enter the MedBridge website, You are required to consent to our use of Cookies in line with this Privacy Policy. MedBridge uses Cookies and navigational data like Uniform Resource Locators (URL) to gather information regarding the date and time of Your visit and the solutions and information for which You searched and viewed, or on which of the advertisements displayed on MedBridge You clicked. This type of information is collected to make MedBridge and solutions more useful to You and to tailor the experience to meet Your interests and needs.

MedBridge, or our service providers acting on our behalf, use the following types of Cookies:

Cookie Type Purpose
Strictly Necessary

These Cookies are necessary to allow us to operate the MedBridge platform as you have requested. They let us recognize what type of subscriber you are and then provide you with services accordingly.

Performance / Analytics

We use Cookies and other similar technologies to analyze how the MedBridge platform is accessed, is used, or is performing. We use this information to maintain, operate, and continually improve the MedBridge platform and understand your use of the MedBridge system.

Functional

These Cookies let us operate the MedBridge platform according to your preferences. For example, when you continue to use or come back to the MedBridge platform, we can provide you with our services based on information you provide to us, such as remembering your username, how you have customized our services, and reminding you of content you have used previously.

Third Party

We may allow our Business Partners to use cookies or other similar technologies on or outside the MedBridge platform for the same purposes identified above, including collecting information about your online activities over time and across different websites, applications, and/or devices.

MedBridge Ads

We may work with website publishers, application developers, advertising networks, and service providers to deliver advertisements and other content promoting MedBridge on other web sites and services. Cookies and other similar technologies may be used to serve you with advertisements that may be relevant to you and your interests on other websites, applications, and devices, and to regulate the advertisements you receive and measure their effectiveness. You may opt out of this ad serving using the Network Advertising Initiative (NAI) opt-out page.

IV. Safety Measures

A. Internet Security

We use a variety of security measures to maintain the safety of Your personal information when You place an order or access Your personal information: (i) A secure server; (ii) All sensitive/credit information is transmitted via Secure Socket Layer (SSL) technology and then entered into our Payment gateway providers database accessible only to those authorized who are required to keep the information confidential; (iii) All data stored on the MedBridge Website server(s) is stored in a database “behind” a secure firewall; (iv) There is no permissible access to the database outside of the hosted environment; and (v) After a transaction, Your credit card information will not be stored on our servers.

B. Security Limitations Disclaimer

MedBridge cannot and does not guarantee that Personal Information You post on the MedBridge Website will not be accessed by unauthorized persons. Despite MedBridge’s efforts to safeguard Your personal information, there is always a risk of security breach. MedBridge is not responsible for circumvention of any privacy settings or security measures of the MedBridge Website. You understand and acknowledge that, even after removal, copies of Personal Information on User Profiles may remain viewable in cached and archived pages or if other Users have copied or stored Your Personal Information.

The MedBridge Website might be linked to other websites, including but not limited to Facebook, LinkedIn, or Twitter, in order to better interact with its users and the public. Please be aware that MedBridge is not responsible for the privacy policies of those other sites. If users provide information directly to websites other than MedBridge, different rules may apply for the use of personal information.

You are solely responsible for Your privacy settings, and MedBridge is not and will not be responsible for Personal Information shared by You via a User Profile or the settings associated therewith.

C. Children’s Privacy

MedBridge does not collect any information from anyone under 13 years of age. Our website and courses are directed at people who are older than 13 years.

Please direct additional Questions or Concerns to [email protected].

D. Changes to this Privacy Policy

MedBridge reserves the right to make changes to this privacy policy at any time by giving notice to its users on this page. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom. If you object to any of the changes to the Policy, you must cease using the MedBridge Website and can request that MedBridge removes the Personal Information. Unless stated otherwise, the then-current privacy policy applies to all Personal Information MedBridge has about its users.

Privacy Policy last updated on July 28, 2021