Introduction
We respect your privacy and take the protection of your personal data seriously. This Privacy Policy explains how IDAHealth Inc. ("IDAHealth", "we", "us", "our") collects, uses, and protects your personal data when you visit our website and use our services. It also describes your rights and choices regarding your personal data.
This Privacy Policy covers the following topics
-
What personal data we collect
-
Why we process your personal data and our legal bases for doing so
-
With which parties we share personal data
-
How we transfer personal data internationally
-
How we protect and store personal data
-
How long we retain your personal data
-
How to exercise your rights
-
Use of cookies
-
Links to other websites
-
U.S. state privacy rights
-
HIPAA notice (if applicable)
-
Automated decision-making
-
Contact details
-
Changes to this Privacy Policy
We advise you to read this Privacy Policy carefully and to consult it regularly when you use our website and services.
1. What Personal Data We Collect
Personal data is any information that identifies you directly or in combination with other information. We collect personal data in the following categories:
Contact details, such as your name, telephone number, email address, country/region, and other personal data you voluntarily provide when contacting us or communicating with us, for example via the "Contact Us" form on our website.
Automatically collected data, such as IP address, browser type and version, operating system, application version, geographic location, and information about the pages you visit on our website. We collect this data through cookies and similar tracking technologies. For more information, please see Section 8 (Use of Cookies) below.
Professional or employment information, such as your current and/or previous employer, job title, and education history or background that you voluntarily provide to us, for example when applying for a job.
Health-related information, to the extent you voluntarily provide such information when using our services or communicating with us.
In many cases, you can determine which data you provide to us. In some cases, however, we can only respond to your request or provide our services if you give us certain data - for example, your email address or telephone number to respond to an enquiry. If that is the case, we will inform you. Not providing this data may mean we cannot process your request, in full or in part, or that you may not be able to use our services.
Our website and services are not directed to children under the age of 13 (or under 16 where required by applicable law), and we do not knowingly collect personal data from children under these ages without verifiable parental consent. If you believe we have collected personal data from a child without the required consent, please contact us immediately at info@idahealth.us so we can take appropriate action.
2. Why We Process Your Personal Data and Our Legal Bases
We use your personal data for the following purposes. Where we are required to identify a legal basis for processing (for example, under the GDPR), we have noted it alongside each purpose.
Communicating with you - We use your personal data to respond to your enquiries, questions, and requests submitted through our website or other channels. Legal basis: Legitimate interests (responding to communications and managing our business); or performance of a contract where applicable.
Record keeping and administration - We use your personal data to maintain records of how services were provided and how claims and complaints were handled. Legal basis: Legitimate interests (managing our business operations and maintaining accurate records); Legal obligation where applicable.
Recruiting - When you apply for a job through our website or otherwise, we use your personal data and other information you provide to review your application and manage our recruitment process. Legal basis: Legitimate interests (managing recruitment); Pre-contractual steps at your request.
Maintaining, analyzing, and improving our website - We analyze information about how you use our website in order to improve the user experience for all visitors. Legal basis: Legitimate interests (improving our services); Consent where required under applicable law, such as for analytical cookies.
Providing our services - We use your personal data to deliver the services you have requested or contracted with us for. Legal basis: Performance of a contract; Legitimate interests.
Complying with legal obligations - We use your personal data where necessary to comply with applicable laws and regulations, including responding to orders or requests from public authorities or courts. Legal basis: Legal obligation.
Protecting rights and interests - We may use your personal data to protect our rights, property, or safety, or those of our users or third parties, including for fraud prevention and security purposes. Legal basis: Legitimate interests; Legal obligation.
If you have provided your consent for any specific processing activity, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
3. With Which Parties We Share Personal Data
We handle your personal data carefully and in confidence. Your personal data is only accessible to IDAHealth employees to the extent necessary to operate our website, provide our services, or comply with our legal obligations.
We may share your personal data with the following categories of third parties:
Group companies - We share your personal data with affiliated companies within the IDAHealth group as necessary to analyze and optimize our website and services, respond to your queries, fulfill legal obligations, and maintain the security of our systems.
Service providers - We share your personal data with trusted third-party service providers who assist us in operating our website, securing and analyzing our systems, managing our business administration, and delivering our services. These providers are contractually required to handle your personal data securely and only for the purposes we specify.
Professional advisers - We may share your personal data with lawyers, accountants, auditors, and other professional advisers where necessary in connection with the operation of our business.
Successors or assigns - We may share your personal data with actual or proposed successors or assigns in connection with a merger, acquisition, sale, restructuring, or other transfer of the business or assets of any member of the IDAHealth group.
Public authorities and regulators - We may share your personal data with courts, regulators, law enforcement agencies, and other public authorities where required by law, court order, or regulatory requirement, or where necessary to protect our rights or the rights of third parties, or to prevent or report fraud or criminal activity.
We do not sell your personal data to third parties for their own marketing purposes.
4. How We Transfer Personal Data Internationally
IDAHealth operates globally, and the third parties with whom we share data may be located in countries outside the country or region in which you reside. These countries may have data protection laws that differ from, and in some cases provide less protection than, the laws of your country.
Where we transfer personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of protection, we rely on appropriate safeguards, including:
-
Standard Contractual Clauses (SCCs) as approved by the European Commission (including the updated 2021 SCCs);
-
The EU-U.S. Data Privacy Framework (DPF), UK Extension to the DPF, and Swiss-U.S. DPF, where applicable;
-
Other legally recognized transfer mechanisms under applicable data protection law.
If you have questions about international transfers of your personal data or the safeguards we have put in place, please contact us at info@idahealth.us.
5. How We Protect Your Personal Data
We have implemented physical, technical, and organizational security measures designed to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include access controls, encryption, and regular security assessments. We evaluate and update these measures on a regular basis.
Please be aware that no information system can be 100% secure. While we strive to protect your personal data, we cannot guarantee its absolute security.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authorities and, where required, affected individuals, in accordance with applicable law.
6. How Long We Retain Your Personal Data
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. The following general retention periods apply:
-
Contact and communication data (e.g., enquiry forms, emails): retained for 3 years from the date of last contact, unless an ongoing relationship requires longer retention.
-
Recruitment data: retained for 6 months after the conclusion of the recruitment process, unless you are hired (in which case it becomes part of your employment record) or a longer period is required by law.
-
Website analytics data: retained for 48 months from collection, in line with standard analytics practices.
-
Legal and compliance records: retained for as long as required by applicable law or as necessary to bring, investigate, or defend legal claims.
When personal data is no longer needed, we securely delete or anonymize it.
7. How to Exercise Your Rights
Depending on your location and applicable law, you may have the following rights with respect to your personal data:
-
Right of access - the right to obtain a copy of your personal data and information about how we process it.
-
Right to rectification - the right to have inaccurate or incomplete personal data corrected.
-
Right to erasure - the right to request deletion of your personal data in certain circumstances.
-
Right to restriction of processing - the right to request that we limit the processing of your personal data in certain circumstances.
-
Right to data portability - the right to receive your personal data in a structured, machine-readable format and to transmit it to another controller.
-
Right to object - the right to object to processing based on legitimate interests or for direct marketing purposes.
-
Right to withdraw consent - where processing is based on your consent, the right to withdraw that consent at any time without affecting the lawfulness of prior processing.
-
Right not to be subject to automated decision-making - the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. See Section 12 below.
To exercise any of these rights, please contact us using the details in Section 13. We will respond to your request within the timeframe required by applicable law (generally within 30 days, with a possible extension of a further two months for complex requests). In certain situations, we may not be able to fully comply with your request, in which case we will explain why.
We will not discriminate against you for exercising your privacy rights.
If you are not satisfied with how we have handled your request, you have the right to file a complaint with your local data protection authority. For EEA residents, a list of supervisory authorities is available at https://edpb.europa.eu. For UK residents, the relevant authority is the Information Commissioner's Office (ICO) at https://ico.org.uk.
8. Use of Cookies
When you visit our website, we use cookies and similar online tracking technologies (collectively, "cookies"). A cookie is a small data file stored on your device (e.g., computer, smartphone, tablet) that allows us to recognize your device and collect certain information about your browsing activity.
Types of cookies we use:
Strictly necessary / functional cookies - These cookies are essential for our website to function properly and cannot be switched off. They enable core features such as navigation, security, and accessibility. No consent is required for these cookies.
Security-enhancing cookies - These cookies help us maintain the security of our website and prevent abusive or unauthorized use of its features.
Analytical cookies - These cookies help us understand how visitors use our website by collecting and reporting information anonymously. We use this data to improve our website and services. Where required by applicable law, we will request your consent before placing analytical cookies.
Third-party cookies - Our website may include embedded links, buttons, or widgets that connect to third-party sites (such as social media platforms). These third parties may set their own cookies when you interact with those features. We do not control these cookies and are not responsible for them. Please consult the privacy policies of the relevant third parties for more information.
Your cookie choices: You can manage your cookie preferences through our cookie consent tool. You can also manage or delete cookies through your browser settings:
To opt out of Google Analytics data collection, please visit the Google Analytics Opt-out Browser Add-on.
Please note that disabling certain cookies may affect the functionality of our website.
Regarding "Do Not Track" (DNT): Some browsers include a DNT feature that sends a signal to websites requesting that your browsing not be tracked. Our website does not currently respond to DNT signals. We will update this policy if our practices change.
9. Links to Other Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policy of any third-party website you visit.
10. U.S. State Privacy Rights
If you are a resident of California, Virginia, Colorado, Connecticut, or another U.S. state with applicable privacy legislation, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), and similar laws.
These rights may include:
-
The right to know what personal data we collect, use, disclose, and sell about you.
-
The right to delete your personal data, subject to certain exceptions.
-
The right to correct inaccurate personal data.
-
The right to opt out of the sale or sharing of your personal data for cross-context behavioral advertising.
-
The right to non-discrimination for exercising your rights.
Do we sell personal data? We do not sell personal data to third parties for monetary consideration.
To exercise your U.S. state privacy rights, please contact us at info@idahealth.us. We will respond within the timeframes required by applicable law. You may also designate an authorized agent to submit requests on your behalf.
For California residents, if you have additional questions about our privacy practices, you may also contact us at the address in Section 13.
11. HIPAA Notice
To the extent that IDAHealth is subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, we comply with all applicable HIPAA requirements with respect to protected health information (PHI). Our use and disclosure of PHI is governed by our HIPAA Notice of Privacy Practices, which is available upon request.
12. Automated Decision-Making and Profiling
We do not currently make decisions about you that are based solely on automated processing (including profiling) and that produce legal effects or similarly significant effects on you.
If this changes, we will update this Privacy Policy and, where required by applicable law, inform you and provide you with the right to request human review of any such automated decision, to express your point of view, and to contest the decision.
13. Contact Details
If you have any questions, comments, suggestions, or complaints about this Privacy Policy or the way in which we handle your personal data, please contact us:
IDAHealth Inc. Email: info@idahealth.us
14. Changes to This Privacy Policy
We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last Updated" date at the top of this policy. Where changes are material, we will take reasonable steps to notify you - for example, by posting a notice on our website or sending you an email.
We encourage you to review this Privacy Policy periodically so that you are aware of any updates. Your continued use of our website or services after any changes take effect constitutes your acknowledgment of the updated Privacy Policy.
