WELLNESSWRX PRIVACY POLICY
Last Updated: October, 2020
Thank you for using WellnessWrx! We are so pleased to offer you this Service. In order to make use of this Service you will be required to provide WellnessWrx with various types of information about you. We take your privacy very seriously and offer this privacy policy (the “Policy”) to explain how we collect, use, disclose, manage and safeguard your personal PI and PHI.
For the purposes of this Policy, “personal information” means information about an identifiable individual. “Personal health information” or “PHI” means information about an identifiable individual that relates to the individual’s physical or mental health , including name of patient, the name of their Wellness provider and the services rendered by their Wellness provider.
PHI may be found in communications between patients and their Wellness professionals such as booking information which is stored on our server.
WellnessWrx will collect personal information and PHI from you when you access and use our App or the website or our other software products (collectively referred to as the “Site” and the “Services”).
By accessing or using the Services you are agreeing to the terms of the Policy. The Policy should be read in conjunction with the Terms of Use. If you see any undefined term in this Policy it will have the same definition as it does in the Terms of Use. You should not use the Site or Services unless you fully understand and agree to the Terms of Use and the Policy.
We are committed to safeguarding your PI and PHI. If you have any questions about the Policy or our privacy practices, please contact our Designated Privacy Contact with your questions at privacy@wellnesswrx.ca
WellnessWrx collects different types of information from you and about you when you use the Site. This information is necessary for the adequate performance of the contract between you and us and to allow us to comply with our legal obligations. Without it, we may not be able to provide you with all the requested services. These include:
1.1 Information You Give to Us.
Account Information. When you sign up for a WellnessWrx account, you will be asked to provide certain information which will allow you to book appointments with WellnessWrx providers. This may include your first name, last name, name of the business, type of business, email address, mailing and/or business address, and telephone number.
Provider & Clinic Information. (Only applicable to providers with listings on our site). Providers and Clinics with specific qualifications will be asked to provide proof of their qualifications including copies of any licenses, certifications, diplomas and professional registration numbers. You will also be asked to provide proof current insurance to be updated annually.
Identity Verification Information. To help create and maintain a trusted environment, we may collect identity verification information (such as images of your government-issued ID as permitted by applicable laws) or other authentication information.
Payment Information. All payment transactions for services will be completed using PayPal on the website, and Braintree on the App.
Communications with WellnessWrx. When you communicate with WellnessWrx we collect information about your communication and any information you choose to provide. This may include information about renting clinic space, looking for clinic providers, inquiries about insurance, legal issues, bookkeeping, administrative services or any questions or comments about your account and any other information you choose to share with us.
Other Information. You may otherwise choose to provide us information when you fill in a form, conduct a search, update or add information to your Account, send us a resume, respond to surveys, post to community forums, write reviews, participate in promotions, or use other features of the Site.
1.2 Information We Automatically Collect from Your Use of the WellnessWrx Site
When you use and access the WellnessWrx Site and Services, we automatically collect information, including personal information, about the services you use and how you use them. This information allows us to comply with legal obligations and also provide you with the most effective and safe services that we can.
Geo-location Information. When you use certain features of the Site, we may collect information about your precise or approximate location as determined through data such as your IP address or mobile device’s GPS to offer you an improved user experience. Most mobile devices allow you to control or disable the use of location services for applications in the device’s settings menu. WellnessWrx may also collect this information even when you are not using the app if this connection is enabled through your settings or device permissions.
Usage Information. We collect information about your interactions with the Site such as the pages or content you view, your searches for providers or businesses, bookings you have made, and other actions on the Site to assist us in making the Site better and improving our Services.
Log Data and Device Information. We automatically collect log data and device information when you access and use the Site, even if you have not created an Account or logged in. That information includes, among other things: details about how you’ve used the Site (including if you clicked on links to third-party applications), IP address, access dates and times, hardware and software information, device information, device event information, unique identifiers, crash data, cookie data, and the pages you’ve viewed or engaged with before or after using the Site.
Cookies and Similar Technologies. We use cookies and other similar technologies, such as web beacons, pixels, and mobile identifiers. We may also allow our business partners to use these tracking technologies on the Site, or engage others to track your behaviour on our behalf. While you may disable the usage of cookies through your browser settings, the Site currently does not respond to a “Do Not Track” signal in the HTTP header from your browser or mobile application due to lack of standardization regarding how that signal should be interpreted.
Payment Transaction Information. Providers and Clinics will receive emailed notice that Users have booked an appointment and the amount paid for the appointment.
WellnessWrx does not store any payment information or share any payment information with any other person or provider or clinic.
WellnessWrx tries to limit the use of your personal information to that which is necessary for the effective operation and use of the Services and fulfillment of its contract with you. This may include the following:
The information you provide us enables:
2.2 Create and Maintain a Trusted and Safer Environment.
WellnessWrx may process your information to ensure the safety and security of the Site and all its members and to comply with applicable laws. This includes:
We may process your information to better serve you and customize your experience with WellnessWrx. This may include the promotion and marketing of products, businesses and services we think will be of interest to you based on your preferences. You can opt-out of receiving marketing communications from us by following the unsubscribe instructions included in our marketing communications or changing your notification settings within your Account.
2.4 Processing Payments
WellnessWrx processes this information to operate and improve upon payment services. Processing of this information is intended to:
To help facilitate bookings or other interactions we may need to share certain information, including personal information, between Users, Providers and Clinics as it is necessary for the adequate performance of the contract between you and us, as follows:
WellnessWrx lets you publish information, including personal information, that is visible to the general public. For example, although not personal information, all professionals and providers consent to their name and contact information being listed on the site.
Information you share publicly on the WellnessWrx Site may be indexed through third party search engines. In some cases, you may opt-out of this feature in your Account settings. If you change your settings or your public-facing content, these search engines may not update their databases. We do not control the practices of third party search engines, and they may use caches containing your outdated information.
3.3 Compliance with Law, Responding to Legal Requests, Preventing Harm and Protection of our Rights.
WellnessWrx may disclose your information, including personal information, to courts, law enforcement or governmental authorities, or authorized third parties, if and to the extent we are required or permitted to do so by law or if such disclosure is reasonably necessary: (i) to comply with our legal obligations, (ii) to comply with legal process and to respond to claims asserted against WellnessWrx, (iii) to respond to verified requests relating to a criminal investigation or alleged or suspected illegal activity or any other activity that may expose us, you, or any other of our users to legal liability, (iv) to enforce and administer our Terms of Service, or other agreements with you, or (v) to protect the rights, property or personal safety of WellnessWrx, its employees, its Users, Clinics and Providers, or members of the public.
These disclosures may be necessary to comply with our legal obligations, for the protection of your or another person’s vital interests or for the purposes of our or a third party’s legitimate interest in keeping the Site secure, preventing harm or crime, enforcing or defending legal rights, or preventing damage.
Where appropriate, we may notify Users, Clinics or Providers about legal requests unless: (i) providing notice is prohibited by the legal process itself, by court order we receive, or by applicable law, or (ii) we believe that providing notice would be futile, ineffective, create a risk of injury or bodily harm to an individual or group, or create or increase a risk of fraud upon WellnessWrx’s property, its Users, Clinics and Providers and the Site. In instances where we comply with legal requests without notice for these reasons, we will attempt to notify that User, Clinic or Provider about the request after the fact where appropriate and where we determine in good faith that we are no longer prevented from doing so.
3.4 Service Providers.
WellnessWrx uses a variety of third party service providers in Canada and the US to help us provide services related to the WellnessWrx Platform and the Payment Services
For example, service providers may help us: (i) verify your identity or authenticate your identification documents, (ii) check information against public databases, (iii) conduct background or police checks, fraud prevention, and risk assessment, (iv) perform product development, maintenance and debugging, (v) allow the provision of the Services through third party platforms and software tools (e.g. through the integration with our APIs), or (vi) provide customer service, advertising, or payments services. These providers have limited access to your information to perform these tasks on our behalf, and are contractually bound to protect and to use it only for the purposes for which it was disclosed and consistent with this Privacy Policy.
WellnessWrx will need to share your information, including personal information, in order to ensure the adequate performance of our contract with you.
3.5 Business Transfers.
If WellnessWrx undertakes or is involved in any merger, acquisition, reorganization, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer or share some or all of our assets, including your information in connection with such transaction or in contemplation of such transaction (e.g., due diligence). In this event, we will notify you before your personal information is transferred and becomes subject to a different privacy policy.
3.6 Aggregated Data.
We may also share aggregated information (information about our users that we combine together so that it no longer identifies or references an individual user) and other anonymized information for regulatory compliance, industry and market analysis, demographic profiling, marketing and advertising, and other business purposes.
4.1 Analyzing your Communications.
We may review, scan, or analyze your communications on the Site for fraud prevention, risk assessment, regulatory compliance, investigation, product development, research, and customer support purposes. For example, as part of our fraud prevention efforts, we scan and analyze messages to mask contact information and references to other websites. In some cases, we may also scan, review, or analyze messages to debug, improve, and expand product offerings. We use automated methods where reasonably possible. However, occasionally we may need to manually review some communications, such as for fraud investigations and customer support, or to assess and improve the functionality of these automated tools. We will not review, scan, or analyze your communications to send third party marketing messages to you, and we will not sell reviews or analyses of these communications.
These activities are carried out based on WellnessWrx’s legitimate interest in ensuring compliance with applicable laws and our Terms, preventing fraud, promoting safety, and improving and ensuring the adequate performance of our services.
4.2 Linking Third Party Pages.
WellnessWrx Providers and Clinics may link their personal or professional websites with their WellnessWrx booking page. WellnessWrx is not responsible for any privacy or other terms and conditions applicable to the websites belonging to the Providers and Clinics listed on the Site.
4.3 Google Maps/Earth.
Parts of the Site use Google Maps/Earth services, including the Google Maps API(s). Use of Google Maps/Earth is subject to Google Maps/Earth Additional Terms of Use and the Google Privacy Policy.
The Site may contain links to third party websites or services, such as third party integrations, co-branded services, or third party-branded services (“Third Party Partners”). WellnessWrx doesn’t own or control these Third Party Partners and when you interact with them, you may be providing information directly to the Third Party Partner, WellnessWrx, or both. These Third Party Partners will have their own rules about the collection, use, and disclosure of information. We encourage you to review the privacy policies of the other websites you visit.
You may exercise any of the rights described in this section through your account settings or by sending an email to privacy@wellnesswrx.ca. Please note that we may ask you to verify your identity before taking further action on your request.
6.1 Managing Your Information.
You may access and update some of your information through your Account settings. If you have chosen to connect your Account to a third-party application, like Facebook or Google, you can change your settings and remove permission for the app by changing your Account settings. You are responsible for keeping your personal information up-to-date.
6.2 Rectification of Inaccurate or Incomplete Information.
You have the right to ask us to correct inaccurate or incomplete personal information concerning you (and which you cannot update yourself within your Account).
6.3 Data Access and Portability.
In some jurisdictions, applicable law may entitle you to request copies of your personal information held by us. You may also be entitled to request copies of personal information that you have provided to us in a structured, commonly used, and machine-readable format and/or request us to transmit this information to another service provider (where technically feasible).
6.4 Data Retention and Erasure.
We generally retain your personal information for as long as is necessary for the performance of the contract between you and us and to comply with our legal obligations. If you no longer want us to use your information to provide the Services to you, you can request that we erase your personal information and close your Account. Please note that if you request the erasure of your personal information:
6.5 Withdrawing Consent and Restriction of Processing.
Where you have provided your consent to the processing of your personal information by WellnessWrx you may withdraw your consent at any time by changing your Account settings or by sending a communication to WellnessWrx specifying which consent you are withdrawing. Please note that the withdrawal of your consent does not affect the lawfulness of any processing activities based on such consent before its withdrawal. Additionally, in some jurisdictions, applicable law may give you the right to limit the ways in which we use your personal information, in particular where (i) you contest the accuracy of your personal information; (ii) the processing is unlawful and you oppose the erasure of your personal information; (iii) we no longer need your personal information for the purposes of the processing, but you require the information for the establishment, exercise or defence of legal claims; or (iv) you have objected to the processing pursuant to Section 6.6 and pending the verification whether the legitimate grounds of WellnessWrx override your own.
6.6 Objection to Processing.
In some jurisdictions, applicable law may entitle you to require WellnessWrx not to process your personal information for certain specific purposes (including profiling) where such processing is based on legitimate interest. If you object to such processing WellnessWrx will no longer process your personal information for these purposes unless we can demonstrate compelling legitimate grounds for such processing or such processing is required for the establishment, exercise or defence of legal claims.
Where your personal information is processed for direct marketing purposes, you may, at any time ask WellnessWrx to cease processing your data for these direct marketing purposes by sending an e-mail to connect@wellnesswrx.ca.
6.7 Lodging Complaints.
You have the right to lodge complaints about the data processing activities carried out by WellnessWrx before the competent data protection authorities.
We are continuously implementing and updating administrative, technical, and physical security measures to help protect your information against unauthorized access, loss, destruction, or alteration. Some of the safeguards we use to protect your information are firewalls and data encryption, and information access controls. If you know or have reason to believe that your Account credentials have been lost, stolen, misappropriated, or otherwise compromised or in case of any actual or suspected unauthorized use of your Account, please contact us following the instructions in the Contact Us section below.
Secure Storage: WellnessWrx stores all PI and PHI on a fully managed, dedicated GoDaddy Server. Please refer to the GoDaddy privacy policy for information on their practices.
Network Security: WellnessWrx has implemented network security controls to protect against unauthorized access.
End-to-End Encryption: WellnessWrx encrypts all Consultations. Data transmissions and communications on the Site are end-to-end encrypted.
Privacy Policies and Training: WellnessWrx delivers privacy training to employees on how to safeguard personal information and mitigate operational risks. All employees and contractors are legally bound to confidentiality.
7.2 Breach Response
There is no guarantee against data breaches. However, WellnessWrx has taken reasonable measures to prevent a breach, as described above. In the event of a data breach, Dialogue will:
7.3 Children and Minors
Persons under the age of 18 are not permitted to register for an Account. However, WellnessWrx cannot control unauthorized use by minors and will not be held liable for the inadvertent collection of their information if unauthorized use is performed.
WellnessWrx reserves the right to modify this Privacy Policy at any time in accordance with this provision. If we make changes to this Privacy Policy, we will post the revised Privacy Policy on the Site and update the “Last Updated” date at the top of this Privacy Policy. We will also provide you with notice of the modification by email at least thirty (30) days before the date they become effective. If you disagree with the revised Privacy Policy, you may cancel your Account. If you do not cancel your Account before the date the revised Privacy Policy becomes effective, your continued access to or use of the Site will be subject to the revised Privacy Policy.
If you have any questions or complaints about this Privacy Policy or WellnessWrx information handling practices, you may email us or contact us at: privacy@wellnesswrx.ca