LAST UPDATED: August 30, 2018

Mytonomy Privacy Policy

Mytonomy Inc. (“Mytonomy,” “we,” or “us”) wants you to be familiar with how we collect, use and disclose information. This Privacy Policy describes our practices in connection with information that we collect:

  • Through websites operated by us, or through your provider’s patient portal, from which you are accessing this Privacy Policy (the “Websites”);
  • Through the software applications made available by us for use on or through computers and mobile devices (the “Apps”);
  • Through our social media pages located at (collectively, our “Social Media Pages”); and
  • Through HTML-formatted email messages that we send to you that link to this Privacy Policy (the “Emails”).

Collectively, we refer to the Websites, the Apps, our Social Media Pages, and the Emails as (the “Services”).


PERSONAL INFORMATION

Personal Information” is information that identifies you as an individual or relates to an identifiable individual

  • Name
  • Telephone/cell phone number
  • Email address
  • User ID
  • Social media account ID
  • Demographic information, such as your gender, race, ethnicity.

If you are a patient using the Services at the direction of your healthcare provider, we also collect health-related information including medical condition and diagnosis, treatment, medications.

If you are an employee using the Services at the direction of your employer, we also collect employment-related information, including the name of your employer and your title.


Collection of Personal Information

We and our service providers collect Personal Information in a variety of ways, including:

  • Through the Services
    • We collect Personal Information through the Services, for example, when you register an account to access the Services and/or when you use the Services.

  • From Other Sources

    • We receive your Personal Information from other sources, including from any third party that directs you to use the Services (a “Mytonomy Customer”), for example:
      • Your healthcare provider, if you are using the Services at the direction of your healthcare provider.
      • Your employer, if you are using the Services at the direction of your employer.
      • Your virtual care management organization, if you are using one.

    • If you connect your social media account to your Services account, you will share certain Personal Information from your social media account with us, for example, your name, email address, photo, list of social media contacts, and any other information that may be or you make accessible to us when you connect your social media account to your Services account.

We need to collect Personal Information in order to provide the requested Services to you. If you do not provide the information requested, we may not be able to provide the Services.


Use and Disclosure of Personal Information Under HIPAA

If you are using the Services at the direction of a Mytonomy Customer that is subject to the Health Insurance Portability and Accountability Act (“HIPAA”), such as your healthcare provider, we will use and disclose your Protected Health Information (“PHI”) as permitted in our agreement with the Mytonomy Customer. This generally means that we will use and disclose your PHI to provide the Services, for our own internal management or as required to comply with applicable law.


Use of Personal Information

We and our service providers use Personal Information for business purposes including:

  • Providing the functionality of the Services and fulfilling your requests.
    • To provide the Services’ functionality to you, such as arranging access to your registered account, and providing you with related customer service.
    • To respond to your inquiries and fulfill your requests when you send us questions, suggestions, compliments or complaints.
    • To send administrative information to you, such as changes to our terms, conditions and policies.
    • To allow you to send messages to another person if you choose to do so.

    We will engage in these activities to manage our contractual relationship with you and/or to comply with a legal obligation.

  • Providing you with our newsletter and/or other marketing materials and facilitating social sharing
    • To send you marketing related emails, with information about our services, new products and other news about Mytonomy.
    • To facilitate social sharing functionality that you choose to use.

    We will engage in this activity with your consent or where we have a legitimate interest.

  • Analysis of Personal Information for business reporting and providing personalized services.
    • To better understand you, so that we can provide you with personalized content, as chosen by the Mytonomy Customer, such as your healthcare provider and/or employer.
    • To analyze or predict our users’ preferences in order to prepare aggregated trend reports on how our digital content is used, so we can improve our Services.
    • To better understand your preferences so that we can deliver content via our Services that we believe will be relevant and interesting to you.

    We will provide personalized services either with your consent or because we have a legitimate interest.

  • Aggregating and/or anonymizing Personal Information.
    • We may aggregate and/or anonymize Personal Information so that it will no longer be considered Personal Information. We do so to generate other data for our use, which we may use and disclose for any purpose.

  • Accomplishing our business purposes.
    • For data analysis, for example, to improve our Services.
    • For audits, to verify that our internal processes function as intended and are compliant with legal, regulatory or contractual requirements.
    • For fraud and security monitoring purposes, for example, to detect and prevent cyberattacks or attempts to commit identity theft.
    • For developing new products and services.
    • For enhancing, improving, or modifying our current products and services.
    • For identifying usage trends, for example, understanding which parts of our Services are of most interest to users.
    • For determining the effectiveness of our promotional campaigns, so that we can adapt our campaigns to the needs and interests of our users.
    • For operating and expanding our business activities, for example, understanding which parts of our Services are of most interest to our users so we can focus our energies on meeting our users’ interests.

    We engage in these activities to manage our contractual relationship with you, to comply with a legal obligation, and/or because we have a legitimate interest.


Disclosure of Personal Information

We disclose Personal Information:

  • To the Mytonomy Customer, such as your healthcare provider or employer, to provide them with information about the content that you have viewed to help gauge the effectiveness of their education program. For information on how the Mytonomy Customer uses and discloses your Personal Information, please consult the Mytonomy Customer’s privacy policy.

  • To our third party service providers, to facilitate services they provide to us.
    • These can include providers of services such as website hosting, data analysis, payment processing, information technology and related infrastructure provision, customer service, email delivery, auditing, and other services.
    • Through your social sharing activity. When you connect your Services account with your social media account, you will share information with your friends associated with your social media account, with other users, and with your social media account provider. By doing so, you authorize us to facilitate this sharing of information, and you understand that the use of shared information will be governed by the social media provider’s privacy policy.


Other Uses and Disclosures

We also use and disclose your Personal Information as necessary or appropriate, especially when we have a legal obligation or legitimate interest to do so:

  • To comply with applicable law and regulations.
    • This can include laws outside your country of residence.
  • To cooperate public and government authorities.
    • To respond to a request or to provide information we believe is important
    • These can include authorities outside your country of residence.
  • To cooperate with law enforcement.
    • For example, when we respond to law enforcement requests and orders or provide information we believe is important
  • For other legal reasons.
    • To enforce our terms and conditions; and
    • To protect our rights, privacy, safety or property, and/or that of our affiliates, you or others.
  • In connection with a sale or business transaction.
    • We have a legitimate interest in disclosing or transferring your Personal Information to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings) Such third parties may include, for example, an acquiring entity and its advisors.


OTHER INFORMATION

Other Information” is any information that does not reveal your specific identity or does not directly relate to an identifiable individual

  • Browser and device information
  • App usage data
  • Information collected through cookies, pixel tags, log files, and other technologies
  • Demographic information and other information provided by you that does not reveal your specific identity
  • Information that has been aggregated in a manner such that it no longer reveals your specific identity

If we are required to treat Other Information as Personal Information under applicable law, then we may use and disclose it for the purposes for which we use and disclose Personal Information as detailed in this Policy.


Collection of Other Information

We and our service providers may collect Other Information in a variety of ways, including:

  • Through your browser or device
    • Certain information is collected by most browsers or automatically through your device, such as your Media Access Control (MAC) address, computer type (Windows or Mac), screen resolution, operating system name and version, device manufacturer and model, language, Internet browser type and version and the name and version of the Services (such as the App) you are using. We use this information to ensure that the Services function properly.

  • Through your use of the App
    • When you download and use the App, we and our service providers may track and collect App usage data, such as the date and time the App on your device accesses our servers and what information and files have been downloaded to the App based on your device number.

  • Using cookies
    • Cookies are pieces of information stored directly on the computer that you are using. Cookies allow us to collect information such as browser type, time spent on the Services, pages visited, language preferences and other traffic data. We and our service providers use the information for security purposes, to facilitate navigation, to display information more effectively, and to personalize your experience. We also gather statistical information about use of the Services in order to continually improve their design and functionality, understand how they are used and assist us with resolving questions regarding them. We do not currently respond to browser do-not-track signals. If you do not want information collected through the use of cookies, most browsers allow you to automatically decline cookies or be given the choice of declining or accepting a particular cookie (or cookies) from a particular website. You may also wish to refer to http://www.allaboutcookies.org/manage-cookies/index.html. If, however, you do not accept cookies, some features of the Website and Service may not work or may not work as designed.

  • Using pixel tags and other similar technologies
    • Pixel tags (also known as web beacons and clear GIFs) may be used to, among other things, track the actions of users of the Services (including email recipients), measure the success of our engagement campaigns, and compile statistics about usage of the Services and response rates.

    • Analytics. We use Google Analytics, which uses cookies and similar technologies to collect and analyze information about use of the Services and report on activities and trends. This service may also collect information regarding the use of other websites, apps and online resources. You can learn about Google’s practices by going to www.google.com/policies/privacy/‌partners/, and opt out of them by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.

  • IP Address
    • Your IP address is automatically assigned to your computer by your Internet Service Provider. An IP address may be identified and logged automatically in our server log files whenever a user accesses the Services, along with the time of the visit and the page(s) that were visited. Collecting IP addresses is standard practice and is done automatically by many websites, applications and other services. We use IP addresses for purposes such as calculating usage levels, diagnosing server problems and administering the Services. We may also derive your approximate location from your IP address.

  • Physical Location
    • We may collect the physical location of your device by, for example, using satellite, cell phone tower or WiFi signals. We may use your device’s physical location to inform the Mytonomy Customer of where you consumed their patient/staff education (i.e. at home or in the hospital).


Uses and Disclosures of Other Information

We may use and disclose Other Information for any purpose, except where we are required to do otherwise under applicable law. In some instances, we may combine Other Information with Personal Information. If we do, we will treat the combined information as Personal Information as long as it is combined.


SECURITY

We seek to use reasonable organizational, technical and administrative measures to protect Personal Information within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “Contacting Us” section below.


CHOICES AND ACCESS

Your choices regarding our use and disclosure of your Personal Information

If you no longer want to receive text messages from us, you can reply to the message with “STOP” or “UNSUBSCRIBE.”

We will try to comply with your request(s) as soon as reasonably practicable.


How you can access, change or delete your Personal Information

If you would like to request to review, correct, update, restrict or delete Personal Information, object to the processing of Personal Information, or if you would like to request to receive an electronic copy of your Personal Information for purposes of transmitting it to another company (to the extent this right to data portability is provided to you by applicable law), you may contact us by emailing us at privacy@mytonomy.com or mailing us at 7315 Wisconsin Ave #400 West, Bethesda, MD 20814. You may also updated or correct your Personal Information by visiting your Account profile page. We will respond to your request consistent with applicable law.

In your request, please make clear what Personal Information you would like to have changed, whether you would like to have your Personal Information suppressed from our database. For your protection, we may only implement requests with respect to the Personal Information associated with the particular email address that you use to send us your request, and we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable.

Please note that we may need to retain certain information for recordkeeping purposes and/or to fulfill our obligations to the Mytonomy Customer.


RETENTION PERIOD

We retain Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services);
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them); or
  • Whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations).

THIRD PARTY SERVICES

This Privacy Policy does not address, and we are not responsible for, the privacy, information or other practices of any third parties, including any third party operating any website or service to which the Services link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our affiliates.

In addition, we are not responsible for the information collection, use, disclosure or security policies or practices of other organizations, such as Facebook, Apple, Google, Microsoft, RIM or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider or device manufacturer, including with respect to any Personal Information you disclose to other organizations through or in connection with the Apps or our Social Media Pages.


USE OF SERVICES BY MINORS

The Services are not directed to individuals under the age of thirteen (13), and, unless otherwise disclosed during collection and with parent or guardian consent, we do not knowingly collect Personal Information from individuals under 13. If you are under 13 years of age, do not provide Personal Information to us. If we discover that a child under the age of 13 has provided us with personally identifiable information and we do not have parental consent, we will promptly delete that child’s information from the Website and Service. If you believe that Mytonomy has been provided with Personal Information of a child under the age of 13 without parental consent, please notify us immediately at privacy@mytonomy.com.


JURISDICTION AND CROSS-BORDER TRANSFER

Your Personal Information may be stored and processed in any country where we have facilities or in which we engage service providers. By using the Services you understand that your information will be transferred to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Information.


SENSITIVE INFORMATION

Unless we request it, we ask that you not send us, and you not disclose, any sensitive Personal Information (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the Services or otherwise to us.


UPDATES TO THIS PRIVACY POLICY

The “LAST UPDATED” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes will become effective when we post the revised Privacy Policy on the Services. Your use of the Services following these changes means that you accept the revised Privacy Policy.


CONTACTING US

Mytonomy Inc., located at 7315 Wisconsin Ave #400 West, Bethesda, MD 20814, is the company responsible for collection, use and disclosure of your Personal Information under this Privacy Policy.

If you have any questions about this Privacy Policy, please contact us at info@mytonomy.com or:

7315 Wisconsin Ave #400 West, Bethesda, MD 20814

Because email communications are not always secure, please do not include sensitive information in your emails to us.


ADDITIONAL INFORMATION REGARDING THE EEA

You may also lodge a complaint with a data protection authority for your country or region or where an alleged infringement of applicable data protection law occurs. A list of data protection authorities is available at http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080.