Privacy Policy

Last Updated: 10/29/2021

 

PRIVACY POLICY

 

This Privacy Policy applies to all users (“you” or “your” or “user”) of eprogresstracker.com (the “Site”), the Platform, and the Services, all of which are developed, owned, and operated by My Medical Connections, Inc. (“My Medical Connections” or “we” or “our” or “Licensor”). This Privacy Policy describes the information we collect, how we use and share that information, and your rights and options. This Privacy Policy applies to all users of the Site and if you are an End User subscriber to the Platform and Services pursuant to the End User License Agreement (the “EULA”) this Privacy Policy is incorporated into the EULA.

 

YOUR PRIVACY IS IMPORTANT TO US. PLEASE READ THIS PRIVACY POLICY CAREFULLY BEFORE USING THE SITE, THE SERVICES, AND/OR THE PLATFORM. THIS PRIVACY POLICY IS LINKED TO AND INCORPORATED IN THE EULA BETWEEN YOU AND MY MEDICAL CONNECTIONS AND/OR SUCH OTHER USER AGREEMENT THAT WE MAY REQUIRE FROM TIME TO TIME. A LINK TO THIS PRIVACY POLICY IS ALSO PROMINENTLY DISPLAYED ON THE SITE FOR ALL SITE USERS.

 

AFFIRMATIVE CONSENT:

BY ACCESSING AND USING THE SITE, THE SERVICES, AND/OR THE PLATFORM, YOU AFFIRMATIVELY ACCEPT THE EULA AND THIS PRIVACY POLICY, AND YOU REPRESENT THAT YOU ARE AT LEAST THE AGE OF MAJORITY IN YOUR STATE OR PROVINCE OF RESIDENCE AND YOU CONSENT TO ANY OF YOUR MINOR DEPENDENTS USING THIS SITE. MY MEDICAL CONNECTIONS IS NOT RESPONSIBLE FOR UPDATING YOUR PERSONALLY IDENTIFIABLE INFORMATION OR FOR CONFIRMING ITS ACCURACY.

 

DEFINITIONS

 

The following terms apply to users of the Site who are also End User subscribers to the Platform and Services under the EULA:

 

Business Associate Agreement” or “BAA” means the agreement entered into between an End User that is legal entity or business and operates as a medical provider to patients (as a Covered Entity) and Licensor (as the Business Associate) that governs Licensor’s right to access, receive, and /or create individually identifiable health information in carrying out its obligations to the Covered Entity as part of the Services provided to End User under this EULA and in compliance with the Privacy Rule, the Security Rule, and HIPAA, as defined therein.

 

“End User” means collectively, the individual (i) who has accepted the EULA and has registered an End User Account solely for themselves,  (ii) who is an Originating End User, has agreed to this EULA, has created an Enterprise Account and their own End User Account under that Enterprise Account; (iii)  who has an End User Account created for them by the Originating End User under an Enterprise Account; or (iv) who is a member of an Originating End User’s practice and has created their own End User Account under the Originating End User’s Enterprise Account.

 

End User Account” means a personal right of access to the Platform and Services (i) assigned by Licensor to an End User or Originating End User upon that individual’s successful completion  of the registration process, or (ii) added by an Originating End User to their Enterprise Account, provided, that in all cases, End User Accounts must be activated by Licensor to enable access the Platform and Services.

 

End User Content” means PII, PHI, and such other data and information that an End User uploads to the Platform.

 

Enterprise Account” means an End User Account that is established by the Originating End User, and which may be used by such Originating End User and its employees or contractors pursuant to the terms in the EULA.

 

Originating End User” is the End User who enters into the EULA and creates an Enterprise Account.

 

Personal Identifiable Information” or “PII” means information that could be used to personally identify you.

 

Platform means the location on the Site to which registered End Users having active End User Accounts are given access to the Services, and is comprised of Licensor’s proprietary Software and other intellectual property owned by or licensed to Licensor.

 

Protected Health Information” or “PHI” has the meaning found in 45 CFR § 164.501, and is limited to information created or received by Business Associate from or on behalf of Covered Entity, as these terms are defined in the BAA.

 

“Services” means the provision to End User by Licensor of access to the Platform and certain services offered through the Platform, as selected by the End User which may include, without limitation,  as may be updated from time to time by Licensor in its sole discretion, and where necessary, subject to appropriate consents, (i) viewing and downloading information on case studies and related outcomes, (ii) uploading, downloading, managing, processing, and creating data (iii) sharing PHI and patient records, (iv) communicating messages among those End Users who are patients, providers, and medical practices, (v) scheduling appointments, and (vi) downloading and making limited copies of End User Content subject to the restrictions in this Privacy Policy and the EULA.

 

THE TYPE OF INFORMATION WE COLLECT AND HOW WE COLLECT IT

 

Information You Provide to Us

In order to become a registered End User subscriber to the Platform and Services, during the registration process, you or the Originated End User who is creating your End User Account, will be prompted to provide certain  Personal Identifiable Information.

 

End Users

If you are registering as an individual End User, you will be asked to provide your name, email, cell phone number, and your password (“Personal Registration Information”). If you are being added to an Enterprise Account, your Personal Registration Information will be provided by the Originating End User.

 

If you are a health practitioner End User (a doctor or a veterinarian), in addition to the Personal Registration Information, you will also be asked to provide your license number and the state you are licensed in (the “License Information”).

 

Your Personal Registration Information is the only information that we will directly collect from you or your Originating End User that can be connected to you personally and used to identify you. Your Personal Registration Information will be used to establish your End User Account profile in the Platform. Once your profile is complete, we will only use your Personal Registration Information on a limited basis to serve your needs as more particularly described in the section below.

 

HOW WE USE THE INFORMATION WE COLLECT.

 

Enterprise Account End Users

If you represent a business as the Originating End User and would like to register an Enterprise Account, during your End User Account registration process you must provide us with certain business information and Personal Identifiable Information that we require as necessary to confirm your identity and the identity of your business.

 

You are not required to provide any Personal Identifiable Information in order to use the Site as available when not logging into the Platform.

 

Information You Upload

An individual End User may, at their sole option, populate their End User profile with End User Content consisting of their own Personal Identifiable Information or PHI, send messages to other End Users, update their address, upload their photograph, and provide such other information or PII as such End User sees fit. A health practitioner End User may, in addition to the foregoing and subject in all cases to compliance with HIPAA and obtaining all appropriate consents, upload to the Platform PII or PHI of that End User’s patients.. . You are not obligated to upload any End User Content in order to have access to the Platform or to view materials on the Platform. You have the sole choice and discretion to decide if you want to upload your End User Content and the type and amount of End User Content you choose to upload by completing the information fields made available to you or leaving them blank. Any End User Content you choose to upload is processed through our automated proprietary software program which compiles your End User Content with information, resources, materials, products, services, and other content that may be of interest and/or value to you (collectively, “Materials”).

 

End User Content You Allow to be Uploaded

If you are a patient of or the legal guardian of a patient of an End User that is a health practitioner, you may have the option of allowing that health practitioner End User to upload your Personal Identifiable Information on your behalf in accordance with HIPPA laws and regulations. My Medical Connections is not responsible for an End User’s compliance with HIPPA when uploading an End User’s patient information, nor it is responsible for updating your End User Content or for confirming its accuracy.

 

Participation in New Platform and Services Features.

From time to time, we may offer End Users the opportunity to participate in new features geared towards specific topics. When new features or Services are offered through the Platform that require you to change, edit or update your access and/or End User Content in order to use the new My Medical Connections feature, you will receive a notification and a link allowing you to access that new feature and update your End User Content accordingly.  If you choose to participate in a new feature offering, you will have the option of inputting or changing your End User Content in the fields indicated. Participation in any and all My Medical Connections features is entirely optional. You may opt-out of notices of new features at any time.

 

Case Studies.

From time to time, we may work with participating health practitioner End Users to publish case studies and outcomes through the Platform. If you are a health practitioner End User who has either worked on a case study or desires access to case study information and results, you may be given the option of publishing, sharing, or viewing case studies and outcomes by selecting this Services option and completing the opt-in process and providing all required consents. Under no circumstances will we publish the PII or PHI of any individual in connection with a case study or outcomes.

 

Support and Services.

If you are an End User experiencing technical support issues or have questions, please contact us directly through the Site by clicking the support option in your homepage; by phone at  +1 (408) 203-3646 or via email at: support@eprogresstracker.com.

 

Information Automatically Collected

We may automatically collect information from your browser when you use or access the Site or the Platform through your Services. This information (“Non-Personal Information”) is not Personal Identifiable Information and may include, without limitation, your IP address, browser type and language, operating system, access times, and the referring IP address.

 

Cookies and Use of Cookie Data

When you use or access the Site, we may assign your browser one or more cookies to personalize your experience. A cookie is a small file placed on your browser or device. Through the use of cookies, we may automatically collect information about your activity on the Site, such as the pages you visit, the time and date of your visits and the links you click. If we place advertisements or offers of services by us or third parties on the Site, we may use certain data collected and generated through those advertisements. It may be possible to refuse to accept cookies by activating the appropriate setting on your browser.

 

HOW WE USE THE INFORMATION WE COLLECT

 

Personal Identifiable Information

We use your Personal Registration Information to register you as a Platform End User. After registration is complete, your Personal Registration Information will be used as your Platform End User Account profile and login. Personal Identifiable Information collected from End Users will be used for contact information and confirmation purposes.

 

No individual employee or agent of My Medical Connections will access or read your End User Content unless they are providing technical support or investigating bug reports. Except for technical support and debugging any End User Content you upload or have uploaded is only accessed through our automated proprietary software program which makes your Personal Information anonymous and then creates create custom views and displays of Materials for reporting purposes.

 

We will not access your Personal Registration Information or End User profile except on a limited basis during your registration process as described above, or at your request to provide technical support.

 

If we need to notify you of changes to this Privacy Policy, the Services, the Platform, or the EULA, or of Platform service offerings, security patches, bug fixes, or other information that could affect your use of the Platform or Services, we may, at our option, notify you via the e-mail address associated with your End User Account, and/or via a notice the next time you log into your End User Account. You may be required to view and accept the release notice when you log in. Release notices may also be posted on the Site]. Except as stated above, we will not access or use any other of your Personal Identifiable Information.

 

Non-Personal Information

We may use your Non-Personal Information to:

 

WITH WHOM WE SHARE YOUR INFORMATION

 

Unless we are required to share your Personal Identifiable Information pursuant to the “Other Situations” described below, we will not share any of your Personal Identifiable Information with any third parties unless you have specifically asked us to do so in writing. Excluding the Other Situations below, if for any other reason we need to share your Personal Identifiable Information outside the scope of this Privacy Policy, we will provide you with advance notice and allow you an opportunity to opt-out of having your Personal Identifiable Information shared under those circumstances. Note, however, that if you opt-out of allowing us to use your Personal Identifiable Information or Non-Personal Information as described in this Privacy Policy, it is likely that it will impact your ability to use the Platform, Services, and Site. You may not opt-out of having your Personal Identifiable Information shared under Other Situations.

 

Other Situations

We may disclose your Personal Identifiable Information under the following circumstances:

 

We reserve the right to raise or waive any legal objection or right available to us.

 

Aggregated and/or Non-Personal Information

We may use and share Non-Personal Information we collect under any of the above circumstances. We may also share anonymized aggregated Non-Personal Information, or Personal Identifiable Information to present data at conferences, publish data in research journals or magazines, or share data within the industry (Cannabis societies or companies that make Cannabis products). We may combine your Non-Personal Information that we collect with additional Non-Personal Information collected from other sources.

 

YOUR CHOICES REGARDING COLLECTION AND USE OF YOUR INFORMATION; OPT-OUT RIGHTS

 

Updates to your User Profile

If you are an End User, your Personal Registration Information serves as your login and End User profile; therefore, you will not be able to make any changes to your Personal Registration Information without disabling your Platform End User Account. You may update your End User Content at any time by accessing your profile page through the Services. Your End User Content is solely under your control.

 

Right to Cancel Platform User Account

You may cease using the Platform and/or cancel your End User Account at any time at your sole option and discretion by following the “delete my account” settings on the Platform’s home page.  We will respond to your request within 48 hours at which time your End User Account and all related profiles, Personal Information, and End User Content will be permanently deleted from the Platform and you will have no further access to your End User Account or any related information.

 

Right to Opt-Out of Communications

If you are an End User and you receive communications directly from your medical or veterinary provider with whom you have established a relationship, and not through the Platform, you must contact them directly to request to opt-out of those communications. You may opt out of receiving notices from your practitioner through eprogresstracker or system notices from eprogresstracker.com, by logging into your End User Account and updating the notification settings in your profile. With regard to communications amongst End Users, the Platform is a conduit only between such End Users. We have no access to any communications between End Users within the Platform; nor do we have the ability to control End User’s use of any Personal Identifiable Information that has been voluntarily shared by an End User to another.

 

Changes to Non-Personal Information Collection Settings

You may control information collected on the Site by cookies. You can delete or decline cookies by changing your browser or device settings. Click “help” in the toolbar of most browsers for instructions.

 

HOW WE PROTECT YOUR PERSONAL INFORMATION

The Platform is a cloud-based service offering which is located on a secured server. AWS uses industry standard security measures to protect information on its servers. Please contact AWS for more information. To the extent under our control, we have implemented security measures to help safeguard your Personal Identifiable Information from unauthorized access and disclosure. We use industry standard multi-layer protections  to protect the End User Content and the  Personal Identifiable Information you provide during the End User Account registration process.

 

Pursuant to the terms of the EULA, we (as the Business Associate) will enter into a separate BAA with each End User that is legal entity or business and operates as a medical provider to patients  (as a Covered Entity). The BAA sets forth the legal protections applicable to PHI.

 

DATA RETENTION POLICY

We do not download copies of your Personal Identifiable Information to any of our databases. If you are an End User, the only Personal Identifiable Information to which we have access is your Personal Registration Information. Your Personal Identifiable Information is retained in the Platform via the AWS secured server and not on our own servers. Personal Identifiable Information is retained only for as long as your End User Account is active. We may create and retain one extract of your Personal Registration Information, the dates of creation and deactivation of your End User Account, and other Non-Personal Information relevant to the existence of your End User Account for archival purposes only. We will not retain or archive any of your other Personal Identifiable Information.

 

CHILDREN’S ONLINE PRIVACY

We restrict the use of the Platform to adults who are legally [21] years of age or older. We do not knowingly collect or maintain information from children, and the Site, Services, and Platform are not designed for or intended to be attractive to children. If you believe we might have any information from or about a child, please contact us at: support@eprogresstracker.com or call us at: 408-203-3646.

 

NO RIGHTS OF THIRD PARTIES

This Privacy Policy does not create rights enforceable by third parties.

 

DISCLAIMER AND LIMITATION OF LIABILITY

If you are an End User’s patient, you understand, acknowledge, and agree that we have no control over how such End User uses your Personal Identifiable Information. Accordingly, you hereby release My Medical Connections and our affiliates from all responsibility and liability arising from use by any End User you voluntarily share End User Content with, of any of your Personal Identifiable Information that you choose to share with such End User.

 

CHANGES TO THIS PRIVACY POLICY

We will occasionally update this Privacy Policy to reflect changes in the law, our data collection and use practices, the features of our Site, Services, and/or the Platform, or advances in technology. When we post changes to this Privacy Policy, we will revise the “Last Updated” date at the top of this Privacy Policy, and post that date to our Site and Services. We encourage all users to regularly check our Site and/or Services for the most recent version of this Privacy Policy. Your continued use of the Site, Services, and the Platform will mean that you affirmatively consent to and accept the most recently dated Privacy Policy. If you do not consent to such changes you may not use the Site, Services, or the Platform.

 

YOUR CALIFORNIA PRIVACY RIGHTS

If you are a California resident, California Civil Code Section § 1798.83 (the California Consumer Privacy Act or “CCPA”) applies to you. Under the CCAP, we must identify in this Privacy Policy, for the most recent 12 month period, (1) the types of Personal Identifiable Information we have collected about you, (2) the sources from which your Personal Identifiable Information was collected, (3) the business purpose(s) for which we collected your Personal Identifiable Information, and (4) the third parties with whom we have shared your Personal Identifiable Information. This information has been expressly stated throughout this Privacy Policy. We will update this Privacy Policy once every twelve months to reflect any changes to the foregoing information. In addition, we do not sell or share your Personal Identifiable Information with any third parties for marketing or solicitation purposes.

 

In addition to the above information as provided herein, California residents who use the Site or Services may request that we disclose how we have applied your Personal Identifiable Information to each of the above four collection and use scenarios by emailing or calling us at: support@eprogresstracker.com or +1 (408) 203-3646 .

 

We will respond to your request, as applicable to your Personal Identifiable Information only within 45 days of any verifiable request, provided, that we reserve the right to extend this period for an additional 45 days if necessary to verify your information and the veracity of your request. We will notify you of any such extension prior to the end of the initial 45-day period. The information will be provided to you at no cost either by mail or electronically.

 

 GOVERNING LAW

This Privacy Policy and any disputes related thereto shall be governed by and construed in accordance with the laws of the State of California, exclusive of its choice of law provisions.