Last Updated: 10/29/2021
The following terms apply to users of the Site who are also End User subscribers to the Platform and Services under the EULA:
“Business Associate Agreement” or “BAA” means the agreement entered into between an End User that is legal entity or business and operates as a medical provider to patients (as a Covered Entity) and Licensor (as the Business Associate) that governs Licensor’s right to access, receive, and /or create individually identifiable health information in carrying out its obligations to the Covered Entity as part of the Services provided to End User under this EULA and in compliance with the Privacy Rule, the Security Rule, and HIPAA, as defined therein.
“End User” means collectively, the individual (i) who has accepted the EULA and has registered an End User Account solely for themselves, (ii) who is an Originating End User, has agreed to this EULA, has created an Enterprise Account and their own End User Account under that Enterprise Account; (iii) who has an End User Account created for them by the Originating End User under an Enterprise Account; or (iv) who is a member of an Originating End User’s practice and has created their own End User Account under the Originating End User’s Enterprise Account.
“End User Account” means a personal right of access to the Platform and Services (i) assigned by Licensor to an End User or Originating End User upon that individual’s successful completion of the registration process, or (ii) added by an Originating End User to their Enterprise Account, provided, that in all cases, End User Accounts must be activated by Licensor to enable access the Platform and Services.
“End User Content” means PII, PHI, and such other data and information that an End User uploads to the Platform.
“Enterprise Account” means an End User Account that is established by the Originating End User, and which may be used by such Originating End User and its employees or contractors pursuant to the terms in the EULA.
“Originating End User” is the End User who enters into the EULA and creates an Enterprise Account.
“Personal Identifiable Information” or “PII” means information that could be used to personally identify you.
“Platform” means the location on the Site to which registered End Users having active End User Accounts are given access to the Services, and is comprised of Licensor’s proprietary Software and other intellectual property owned by or licensed to Licensor.
“Protected Health Information” or “PHI” has the meaning found in 45 CFR § 164.501, and is limited to information created or received by Business Associate from or on behalf of Covered Entity, as these terms are defined in the BAA.
THE TYPE OF INFORMATION WE COLLECT AND HOW WE COLLECT IT
Information You Provide to Us
In order to become a registered End User subscriber to the Platform and Services, during the registration process, you or the Originated End User who is creating your End User Account, will be prompted to provide certain Personal Identifiable Information.
If you are registering as an individual End User, you will be asked to provide your name, email, cell phone number, and your password (“Personal Registration Information”). If you are being added to an Enterprise Account, your Personal Registration Information will be provided by the Originating End User.
If you are a health practitioner End User (a doctor or a veterinarian), in addition to the Personal Registration Information, you will also be asked to provide your license number and the state you are licensed in (the “License Information”).
Your Personal Registration Information is the only information that we will directly collect from you or your Originating End User that can be connected to you personally and used to identify you. Your Personal Registration Information will be used to establish your End User Account profile in the Platform. Once your profile is complete, we will only use your Personal Registration Information on a limited basis to serve your needs as more particularly described in the section below.
HOW WE USE THE INFORMATION WE COLLECT.
Enterprise Account End Users
If you represent a business as the Originating End User and would like to register an Enterprise Account, during your End User Account registration process you must provide us with certain business information and Personal Identifiable Information that we require as necessary to confirm your identity and the identity of your business.
You are not required to provide any Personal Identifiable Information in order to use the Site as available when not logging into the Platform.
Information You Upload
An individual End User may, at their sole option, populate their End User profile with End User Content consisting of their own Personal Identifiable Information or PHI, send messages to other End Users, update their address, upload their photograph, and provide such other information or PII as such End User sees fit. A health practitioner End User may, in addition to the foregoing and subject in all cases to compliance with HIPAA and obtaining all appropriate consents, upload to the Platform PII or PHI of that End User’s patients.. . You are not obligated to upload any End User Content in order to have access to the Platform or to view materials on the Platform. You have the sole choice and discretion to decide if you want to upload your End User Content and the type and amount of End User Content you choose to upload by completing the information fields made available to you or leaving them blank. Any End User Content you choose to upload is processed through our automated proprietary software program which compiles your End User Content with information, resources, materials, products, services, and other content that may be of interest and/or value to you (collectively, “Materials”).
End User Content You Allow to be Uploaded
If you are a patient of or the legal guardian of a patient of an End User that is a health practitioner, you may have the option of allowing that health practitioner End User to upload your Personal Identifiable Information on your behalf in accordance with HIPPA laws and regulations. My Medical Connections is not responsible for an End User’s compliance with HIPPA when uploading an End User’s patient information, nor it is responsible for updating your End User Content or for confirming its accuracy.
Participation in New Platform and Services Features.
From time to time, we may offer End Users the opportunity to participate in new features geared towards specific topics. When new features or Services are offered through the Platform that require you to change, edit or update your access and/or End User Content in order to use the new My Medical Connections feature, you will receive a notification and a link allowing you to access that new feature and update your End User Content accordingly. If you choose to participate in a new feature offering, you will have the option of inputting or changing your End User Content in the fields indicated. Participation in any and all My Medical Connections features is entirely optional. You may opt-out of notices of new features at any time.
From time to time, we may work with participating health practitioner End Users to publish case studies and outcomes through the Platform. If you are a health practitioner End User who has either worked on a case study or desires access to case study information and results, you may be given the option of publishing, sharing, or viewing case studies and outcomes by selecting this Services option and completing the opt-in process and providing all required consents. Under no circumstances will we publish the PII or PHI of any individual in connection with a case study or outcomes.
Support and Services.
If you are an End User experiencing technical support issues or have questions, please contact us directly through the Site by clicking the support option in your homepage; by phone at +1 (408) 203-3646 or via email at: email@example.com.
Information Automatically Collected
We may automatically collect information from your browser when you use or access the Site or the Platform through your Services. This information (“Non-Personal Information”) is not Personal Identifiable Information and may include, without limitation, your IP address, browser type and language, operating system, access times, and the referring IP address.
Cookies and Use of Cookie Data
HOW WE USE THE INFORMATION WE COLLECT
Personal Identifiable Information
We use your Personal Registration Information to register you as a Platform End User. After registration is complete, your Personal Registration Information will be used as your Platform End User Account profile and login. Personal Identifiable Information collected from End Users will be used for contact information and confirmation purposes.
No individual employee or agent of My Medical Connections will access or read your End User Content unless they are providing technical support or investigating bug reports. Except for technical support and debugging any End User Content you upload or have uploaded is only accessed through our automated proprietary software program which makes your Personal Information anonymous and then creates create custom views and displays of Materials for reporting purposes.
We will not access your Personal Registration Information or End User profile except on a limited basis during your registration process as described above, or at your request to provide technical support.
We may use your Non-Personal Information to:
WITH WHOM WE SHARE YOUR INFORMATION
We may disclose your Personal Identifiable Information under the following circumstances:
We reserve the right to raise or waive any legal objection or right available to us.
Aggregated and/or Non-Personal Information
We may use and share Non-Personal Information we collect under any of the above circumstances. We may also share anonymized aggregated Non-Personal Information, or Personal Identifiable Information to present data at conferences, publish data in research journals or magazines, or share data within the industry (Cannabis societies or companies that make Cannabis products). We may combine your Non-Personal Information that we collect with additional Non-Personal Information collected from other sources.
YOUR CHOICES REGARDING COLLECTION AND USE OF YOUR INFORMATION; OPT-OUT RIGHTS
Updates to your User Profile
If you are an End User, your Personal Registration Information serves as your login and End User profile; therefore, you will not be able to make any changes to your Personal Registration Information without disabling your Platform End User Account. You may update your End User Content at any time by accessing your profile page through the Services. Your End User Content is solely under your control.
Right to Cancel Platform User Account
You may cease using the Platform and/or cancel your End User Account at any time at your sole option and discretion by following the “delete my account” settings on the Platform’s home page. We will respond to your request within 48 hours at which time your End User Account and all related profiles, Personal Information, and End User Content will be permanently deleted from the Platform and you will have no further access to your End User Account or any related information.
Right to Opt-Out of Communications
If you are an End User and you receive communications directly from your medical or veterinary provider with whom you have established a relationship, and not through the Platform, you must contact them directly to request to opt-out of those communications. You may opt out of receiving notices from your practitioner through eprogresstracker or system notices from eprogresstracker.com, by logging into your End User Account and updating the notification settings in your profile. With regard to communications amongst End Users, the Platform is a conduit only between such End Users. We have no access to any communications between End Users within the Platform; nor do we have the ability to control End User’s use of any Personal Identifiable Information that has been voluntarily shared by an End User to another.
Changes to Non-Personal Information Collection Settings
You may control information collected on the Site by cookies. You can delete or decline cookies by changing your browser or device settings. Click “help” in the toolbar of most browsers for instructions.
HOW WE PROTECT YOUR PERSONAL INFORMATION
The Platform is a cloud-based service offering which is located on a secured server. AWS uses industry standard security measures to protect information on its servers. Please contact AWS for more information. To the extent under our control, we have implemented security measures to help safeguard your Personal Identifiable Information from unauthorized access and disclosure. We use industry standard multi-layer protections to protect the End User Content and the Personal Identifiable Information you provide during the End User Account registration process.
Pursuant to the terms of the EULA, we (as the Business Associate) will enter into a separate BAA with each End User that is legal entity or business and operates as a medical provider to patients (as a Covered Entity). The BAA sets forth the legal protections applicable to PHI.
DATA RETENTION POLICY
We do not download copies of your Personal Identifiable Information to any of our databases. If you are an End User, the only Personal Identifiable Information to which we have access is your Personal Registration Information. Your Personal Identifiable Information is retained in the Platform via the AWS secured server and not on our own servers. Personal Identifiable Information is retained only for as long as your End User Account is active. We may create and retain one extract of your Personal Registration Information, the dates of creation and deactivation of your End User Account, and other Non-Personal Information relevant to the existence of your End User Account for archival purposes only. We will not retain or archive any of your other Personal Identifiable Information.
CHILDREN’S ONLINE PRIVACY
We restrict the use of the Platform to adults who are legally  years of age or older. We do not knowingly collect or maintain information from children, and the Site, Services, and Platform are not designed for or intended to be attractive to children. If you believe we might have any information from or about a child, please contact us at: firstname.lastname@example.org or call us at: 408-203-3646.
NO RIGHTS OF THIRD PARTIES
DISCLAIMER AND LIMITATION OF LIABILITY
If you are an End User’s patient, you understand, acknowledge, and agree that we have no control over how such End User uses your Personal Identifiable Information. Accordingly, you hereby release My Medical Connections and our affiliates from all responsibility and liability arising from use by any End User you voluntarily share End User Content with, of any of your Personal Identifiable Information that you choose to share with such End User.
YOUR CALIFORNIA PRIVACY RIGHTS
In addition to the above information as provided herein, California residents who use the Site or Services may request that we disclose how we have applied your Personal Identifiable Information to each of the above four collection and use scenarios by emailing or calling us at: email@example.com or +1 (408) 203-3646 .
We will respond to your request, as applicable to your Personal Identifiable Information only within 45 days of any verifiable request, provided, that we reserve the right to extend this period for an additional 45 days if necessary to verify your information and the veracity of your request. We will notify you of any such extension prior to the end of the initial 45-day period. The information will be provided to you at no cost either by mail or electronically.