Last Updated: December 1, 2022
Please read the following carefully to understand Our views and practices regarding Your Personal Data.
WE AT CAREPICS, LLC (“We”, “Us”, “the Company”) VALUE YOUR PRIVACY AND ARE COMMITTED TO KEEPING YOUR PERSONAL DATA CONFIDENTIAL. WE USE YOUR DATA SOLELY IN THE CONTEXT OF PROVIDING A PLATFORM (“PLATFORM”) AND VARIOUS RELATED SERVICES DEFINED BELOW TO SUPPORT THE DELIVERY OF REMOTE CLINICAL CARE SERVICES PROVIDED BY QUALIFIED PHYSICIANS (“PROVIDER USERS”) TO PATIENTS (“PATIENT USERS”). YOU ARE EITHER A PROVIDER USER OR A PATIENT USER. THE SERVICES INCLUDE, IN ADDITION TO THE PLATFORM, THE FACILITATION OF COMMUNICATING THE FOLLOWING BETWEEN PROVIDERS AND PATIENTS: 1) PHOTOS OF A PATIENT’S WOUND; 2) ANALYSIS OF SUCH WOUND; AND 3) TREATMENT MANAGEMENT (THE “SERVICES”).
SOME OF THE PERSONAL DATA WE COLLECT AND TRANSMIT MAY BE CONSIDERED “HEALTH DATA” (data related to a Your physical or mental health), “Protected Health Information” or “PHI” (information that relates to Your past, present, or future physical or mental health or condition(s); the provision of health care to You; or the past, present, or future payment for the provision of health care to You), and/or MEDICAL RECORDS as defined by state law.
THEREFORE, OUR PRIVACY PRACTICES ARE INTENDED TO COMPLY WITH THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (“HIPAA“) AND NORTH CAROLINA STATE LAW RELATED TO THE USE AND DISCLOSURE OF MEDICAL RECORDS, WHERE APPLICABLE. FOR ADDITIONAL INFORMATION RELATED TO HOW WE USE AND DISCLOSE YOUR HEALTH DATA, PHI, AND/OR MEDICAL RECORDS DATA, PLEASE CONTACT OUR PRIVACY OFFICER AT PRIVACY@CarePICS.com.
Links to Other Sites
What Personal Data do We collect?
The types of Personal Data We collect are described below.
We may collect demographic information, such as Your name, birth year, gender, height, weight, phone number, and email address, and if you are a Provider User, Your National Provider Identifier (“NPI”). Primarily, the collection of Your Personal Data assists Us in creating Your User Account, which You can use to securely to receive the Services.
If You make payments via Our Platform, We may require that You provide to Us Your financial and billing information, such as billing name and address, credit card number or bank account information.]
Device, Telephone, and ISP Data
We use common information-gathering tools, such as log files, to automatically collect anonymized information from your computer or mobile device as you navigate our services. The information we collect will include application identification numbers and date/time stamps associated with your anonymous usage. This information is used to analyze overall trends, to help Us provide and improve Our Services and to guarantee their security and continued proper functioning.
For Patient Users: Health Data
In addition to demographic information, We will collect information regarding Your health conditions, including images, age, gender, weight, height, medical history, symptoms, and communications between You and the healthcare provider providing healthcare services to You via the Platform. We collect this information to provide You with the Services and to provide Your healthcare provider providing healthcare services through the Platform with the information required to provide medical treatment.
How will We use Your Personal Data?
We process Your Personal Data based on legitimate business interests, the fulfillment of Our Services to You, compliance with Our legal obligations, and/or Your consent. We only use or disclose Your Personal Data when it is legally mandated or where it is necessary to fulfill those purposes described herein.
Where required by law, We will ask for Your prior consent before doing so.
Specifically, We process Your Personal Data for the following legitimate business purposes:
To communicate with You about and manage Your User Account; To properly store and track Your data within Our system;
To respond to lawful requests from public and government authorities, and to comply with applicable state/federal law, including cooperation with judicial proceedings or court orders;
To protect Our rights, privacy, safety, or property, and/or that of You or others by providing proper notices, pursuing available legal remedies, and acting to limit Our damages;
To handle technical support and other requests from You;
To manage and improve Our operations and the Platform, including the development of additional functionality;
To manage payment processing;
To evaluate the quality of service You receive, identify usage trends, and thereby improve Your user experience;
To keep Our Platform safe and secure for You and for Us;
To send You information about changes to Our terms, conditions, and policies;
To allow Us to pursue available remedies or limit the damages that We may sustain; and
If you are a Patient User, to enable You to connect with (or share Personal Data with) the authorized Provider User to enable that individual to monitor Your progress and overall condition, as she/he deems appropriate.
Where is Your Personal Data processed?
Personal Data We through the Platform will be stored on secure servers in the United States. Personal Data may be transmitted to third parties, which parties may store or maintain the data on their secure servers. These third parties are not permitted to transfer Your Personal Data outside of the United States.
Will We share Your Personal Data with anyone else?
For Patient Users: Yes, with the Provider User with whom You connect via the Services.
We will share information you provide to Us via the Services with the Provider User with whom You connect via the Services. If, at any point, You want to deny access to one or more Provider Users, you can do so by emailing PRIVACY@CarePICS.com.
Yes, with third parties that help Us power Our Services
We have a limited number of service providers and other third parties (“Business Partners”) that help Us run various aspects of Our business. These Business Partners are contractually bound to protect Your Personal Data and to use it only for the limited purpose(s) for which it is shared with Us. Business Partners’ use of Personal Data may include, but is not limited to, the provision of services such as data hosting, IT services, customer service, and payment processing.
Yes, with third parties and the government when legal or enforcement issues arise
We may share Your Personal Data, if reasonable and necessary, to (i) comply with legal processes or enforceable governmental requests, or as otherwise required by law; (ii) cooperate with third parties in
Yes, with third parties that provide advisory services
We may share Your Personal Data with third parties that provide use services, including but not limited to, Our lawyers, auditors, accountants, or banks, when We have a legitimate business interest in doing so.
Yes, with third parties in the event of a reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of CarePICS’ corporate entity, assets, or stock (including in connection with any bankruptcy or similar proceedings)
If We share Your Personal Data with a third party other than as provided above, You will be notiﬁed at the time of data collection or transfer, and You will have the option of not permitting the transfer.
How long do We retain Personal Data?
We do not collect cookies.
How do We protect Your Personal Data?
We are committed to protecting the security and conﬁdentiality of Your Personal Data. We use a combination of reasonable physical, technical, and administrative security controls to maintain the security and integrity of Your Personal Data, to protect against any anticipated threats or hazards to the security or integrity of such information, and to protect against unauthorized access to or use of such information in Our possession or control that could result in substantial harm or inconvenience to You. However, internet data transmissions, whether wired or wireless, cannot be guaranteed to be 100% secure. As a result, We cannot ensure the security of information You transmit to Us. By using the Services, You are assuming this risk.
We store Your Personal Data on secure servers, and protect this data using a combination of technical, administrative, and physical security safeguards, such as authentication, encryption, backups, and access controls, in accordance with federal privacy law. If We learn of a security concern, We may attempt to notify You and provide information on protective steps to mitigate any potential harm, if available, through the email address that You have provided to Us. Depending on where You live, You may have a legal right to receive such notices in writing.
You are solely responsible for protecting information entered or generated via the Platform that is stored on Your device and/or removable device storage. We have no access to or control over Your device’s security settings, and it is up to You to implement any device-level security features and protections You feel are appropriate (e.g., password protection, encryption, remote wipe capability, etc.). We recommend that You take any and all appropriate steps to secure any device that You use to access Our Services.
NOTWITHSTANDING ANY OF THE STEPS TAKEN BY US, IT IS NOT POSSIBLE TO GUARANTEE THE SECURITY OR INTEGRITY OF DATA TRANSMITTED OVER THE INTERNET. THERE IS NO GUARANTEE THAT YOUR PERSONAL DATA WILL NOT BE ACCESSED, DISCLOSED, ALTERED, OR DESTROYED DESPITE THE IMPLEMENTATION OF OUR PHYSICAL, TECHNICAL, OR ADMINISTRATIVE SAFEGUARDS. THEREFORE, WE DO NOT AND CANNOT ENSURE OR WARRANT THE SECURITY OR INTEGRITY OF ANY PERSONAL DATA YOU TRANSMIT TO US AND YOU TRANSMIT SUCH PERSONAL DATA AT YOUR OWN RISK.
In instances where You have authorized the Company to use and disclose Your Personal Data for certain purposes, You may withdraw Your consent in the future. You may withdraw Your consent by sending Your request in writing to: PRIVACY@CarePICS.com or CarePICS, LLC, 6300 Westgate Road, Suite A, Raleigh, NC 27617. Please note that Your withdrawal will not be effective until We receive Your request, and will not apply to uses and disclosures that We have already made in reliance on Your consent.
How can You Protect Your Personal Data?
In addition to securing Your device, as discussed above, We will NEVER send You an email requesting conﬁdential information such as account numbers, usernames, passwords, or social security numbers, and You should NEVER respond to any email requesting such information. If You receive such an email that looks like it is from Us, DO NOT RESPOND to the email and DO NOT click on any links and/or open any attachments in the email, and notify CarePICS support at PRIVACY@CarePICS.com.
You are responsible for taking reasonable precautions to protect Your user ID, password, and other User Account information from disclosure to third parties, and You are not permitted to circumvent the use of required encryption technologies. You should immediately notify Us at PRIVACY@CarePICS.com if You know of or suspect any unauthorized use or disclosure of Your user ID, password, and/or other User Account information, or any other security concern.
You have certain rights relating to Your Personal Data, subject to applicable data protection laws. These rights may include:
to access Your Personal Data held by Us;
to erasure/deletion of Your Personal Data, to the extent permitted by applicable data protection laws;
to receive communications related to the processing of Your Personal Data that are concise, transparent, intelligible, and easily accessible;
to restrict the processing of Your Personal Data, to the extent permitted by law (while We verify or investigate Your concerns with this information, for example);
to object to the further processing of Your Personal Data, including the right to object to marketing;
to request that Your Personal Data be transferred to a third party, if possible;
to receive Your Personal Data in a structured, commonly used, and machine- readable format;
to lodge a complaint with a supervisory authority;
to rectify inaccurate Personal Data and, taking into account the purpose of processing the Personal Data, ensure it is complete;
to not be subject to a decision based solely on automated processing, including profiling, which produces legal effects (“Automated Decision- Making”); and
to the extent We base the collection, processing and sharing of Your Personal Data on Your consent, to withdraw Your consent at any time, without affecting the lawfulness of the processing based on such consent before its withdrawal.
Where the processing of Your Personal Data by Us is based on consent, You have the right to withdraw that consent without detriment at any time or to exercise any of the rights listed above by emailing Us at PRIVACY@CarePICS.com.
How can You update, correct, or delete Personal Data?
You can change Your email address and other contact information by SUPPORT@CarePICS.com. If You need to make changes or corrections to other information, You may also send a request to SUPPORT@CarePICS.com. Please note that in order to comply with certain requests to limit use of Your Personal Data, We may need to terminate Your account and Your ability to access and use the Services, and You agree that We will not be liable to You for such termination or for any refunds of prepaid fees paid by You. You can deactivate Your account by request at SUPPORT@CarePICS.com.
Although We will use reasonable efforts to do so, You understand that it may not be technologically possible to remove from Our systems every record of Your Personal Data. The need to back up Our systems to protect information from inadvertent loss means a copy of Your Personal Data may exist in a nonerasable form that will be diﬃcult or impossible for Us to locate or remove.
Can You “OPTOUT” of receiving communications from Us?
We pledge not to market third party services to You without Your consent. We only send emails or SMS text messages to You regarding Your account unless We have Your express consent to do so. You can choose to ﬁlter these emails using Your email client settings, but We do not provide an option for You to opt out of these emails.
Information submission by minors
We do not knowingly collect Personal Data from individuals under the age of 18. Our Services are not directed to individuals under the age of 18. We request that these individuals not provide Personal Data to Us. If We learn that Personal Data from users less than 18 years of age has been collected, We will deactivate the account and take reasonable measures to promptly delete such data from Our records. If You are aware of a user under the age of 18 using the Web Site, please contact Us at PRIVACY@CarePICS.com.
If You are a resident of California under the age of 18 and have registered for an account with Us, You may ask Us to remove content or information that You have posted to Our Platform.