This Privacy Notice is provided by HealthBeacon Limited (“HealthBeacon”) for participants and users of the HealthBeacon program, our electronic smart sharps bin (“HealthBeacon Unit”) and related services, and our website, web portal and mobile application (collectively, “Services”). This Privacy Notice covers the collection and use of your personal information in relation to your use of the Services. You should not use these Services if you do not agree to this Privacy Notice. We are firmly committed to protecting the confidentiality and security of your personal information. This Privacy Notice describes how we may use and disclose personal information, and your rights regarding your personal information. In the United States, HealthBeacon may use or disclose personal health information “PHI” to perform functions, activities and services for, provided that such disclosure would not violate the HIPAA Privacy and Security Rules if done by HealthBeacon.
The personal information we collect and process depends on our relationship with you. We collect personal information directly from you, such as when you (i) input it into our programming forms; (ii) provide it to us over the phone and (iii) sign up to the HealthBeacon program. The information you disclose in connection with the Services is provided strictly on a voluntary basis. HealthBeacon is not responsible for the effects of any incorrect information provided.
We may also collect personal information from third parties. For example, we may collect personal information from service providers that help us to build and maintain our contact lists, that integrate their services into ours, or in other ways work with us for our mutual benefit. We may also collect personal information from you passively. For example, the Services use tracking tools like cookies, pixels, and web beacons to collect usage and browser information. For more information about the trackers that we use, please see the Collection of Cookies and Device Data section of this Notice. Additionally, if you enable location data on your device, this data will be collected based on the location settings on your device.
We may collect personal information from or about you in order to provide, enhance, market, and offer the Services, and to otherwise communicate with you. This section describes the categories of personal information we may collect. You are not required to give us all the personal information identified in this Privacy Notice; however, if you do not provide requested personal information, we may not be able to provide you with some or all of the Services. The personal information collected as part of the Services may include:
Users can only directly interact with the HealthBeacon support team through the App.
Your personal information will be used for:
HealthBeacon will not use or disclose your personal information in a manner inconsistent with applicable law and this Privacy Notice.
In the United States, as permitted by HIPAA, we may disclose your PHI to: Public Health Authorities, The Food and Drug Administration, Health Oversight Agencies, Military Command Authorities, National Security and Intelligence Organization, Correctional Institutions, Organ and Tissue Donation Organizations, Coroners, Medical Examiners and Funeral Directors, Workers Compensation Agents.
Please be aware that we are required as stated in the Health Insurance Portability and Accountability Act (HIPAA) of 1996 to notify you in the event of a breach involving your PHI and will do so as required by law. You have the right to obtain a paper copy of this Privacy Policy by written request to the address below.
We may be required to obtain personal information from you to comply with applicable legal requirements, and certain data may be needed to enable us to fulfil the terms of our contract with you, or in preparation of entering into a contract with you. If you do not provide the relevant data to us, we may not be able to provide our products and benefits to you. In the circumstances where we need your consent to collect and process your personal information, we will ask for such consent. We may need to collect, use and disclose personal information in connection with matters of important public interest, for instance when complying with our legal obligations.
Along with our third-party service providers we may collect user and device data in a variety of ways when you use HealthBeacon services including:
| Methods of Data Collection | Examples |
|---|---|
| Through your internet browser or electronic device | Certain information is collected by most websites or automatically through your electronic device, such as your IP address (i.e. your computer’s address on the internet), internet browser type and version, electronic device manufacturer and model, language, time of the visit, pages visited, and the name and version of the Services (such as the Firmware revision) you are using. We use this information to ensure that the Services function properly. |
| Through your use of an App or Web Portal | When you download and use our mobile application and web portal, we and our service providers may track and collect usage data, such as the date and time your electronic device accesses our servers and what information and files have been downloaded based on your device number. |
| Using cookies and online tracking | To make some of our Services work properly, we sometimes place small data files called cookies on your device. Most websites do this. You can refuse to accept the cookies we use by adjusting your browser settings. However, if you do not accept these cookies, you may experience some inconvenience in your use of the Services and some online products. We currently do not respond to browser do not track signals. |
| Location Data | While navigating the Services, your mobile device or browser may share your location data, both through WiFi and GPS, and IP address or MAC address. We will collect this information based on the settings of your phone and browser.
In some circumstances, location may become personal information if you are identifiable in relation to the location data. In such cases, the location data will be handled as personal information as described in the earlier sections of this Privacy Notice. |
| By aggregating information | We may group information together so that it does not link to a specific individual, i.e. aggregate, and use that information (for example, we may aggregate information to calculate the percentage of our users who have a particular telephone area code). |
Cookies are small files that download when you access certain websites. For more information about cookies visit: http://www.allaboutcookies.org/.
To assist us with analyzing our website traffic through cookies and similar technologies, we use analytics services such as Google Analytics. For more information on Google Analytics’ processing of your information, please see “How Google uses information from sites or apps that use our services.” You can opt out of Google Analytics by installing Google’s opt-out browser add-on.
These cookies may be placed by us (first-party) or by a third party. These cookies may also be Flash Cookies. To learn how to manage privacy and storage settings for Flash cookies click here. We may use cookies that are session-based or persistent. Session cookies expire when you close your browser or turn off your device. Persistent cookies remain on your device after you close your browser or turn off device.
We may use a variety of cookies:
| Type of Cookies | Description |
|---|---|
| Required | Required cookies are essential for the operation of the Services. They include, for example, cookies that allow you to access and use secure areas of the Services. |
| Functionality | Functionality cookies allow the Services to remember information you have entered or choices you make (such as your username, language, or your region) and provide enhanced, more personal features. These cookies also enable you to optimize your use of the Services after logging in. These cookies can also be used to remember changes you have made to text size, fonts and other parts of web pages that you can customize. |
| Performance | These cookies collect information about how you use the Services, including which pages you go to most often and if they receive error messages from certain pages. These cookies do not collect information that individually identifies you. All information these cookies collect is aggregated and anonymous. It is only used to improve how the Services function and perform. |
| Targeting or Advertising | From time-to-time, we may engage third parties to track and analyze usage and volume statistical information from individuals who visit the Services. We sometimes use cookies delivered by third parties to track the performance of our advertisements. For example, these cookies remember which browsers have visited the Services. The information provided to third parties does not include personal information, but this information may be reassociated with personal information after we receive it. By way of example, as you visit the Services, advertising cookies may be placed on your computer so that we can understand what you are interested in. Our advertising partners then enable us to present you with retargeted advertising on other sites based on your previous interaction with the Services. Third parties, with whom we partner to provide certain features on the Services or to display advertising based upon your web browsing activity, use Flash cookies to collect and store information. Flash cookies are different from browser cookies because of the amount of, type of, and how data is stored. |
Most internet browsers accept cookies by default. You can also accept, or block cookies by activating the setting on your browser that allows you to reject all or some cookies, or by changing your cookie preferences via the Services. The help and support area on your internet browser should have instructions on how to block or delete cookies. Some web browsers (including some mobile web browsers) provide settings that allow you to control or reject cookies or to alert you to when a cookie is placed on your computer, tablet or mobile device. Although you are not required to accept cookies, if you block or reject them, you may not have access to all of the features available through the Services.
We are not responsible for the privacy practices of any third parties, including any third party operating any site or service to which our Services link.
The inclusion of a link on our Services does not imply endorsement of the linked site or service by us or by our group companies. Please note that we are not responsible for the collection, usage and disclosure policies and practices (including the information security practices) of other organizations, such as Facebook®, Twitter®, Apple®, Google®, Microsoft®, RIM/Blackberry® or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider or electronic device manufacturer, including any personal information you provide them.
To ensure that we can meet the needs of our members we may record telephone calls to:
We may also monitor electronic communications between us (for example, emails) to protect you, our business and IT infrastructure, and third parties. This monitoring may include identifying and dealing with inappropriate communications, looking for and removing any viruses, or other malware, and resolving any other information security issues.
The Services are meant for adults, and we will not knowingly collect personal information from any person under the age of 13 without permission from a parent or guardian. The Services is not designed to attract the attention of persons under the age of 13. No information should be submitted to us by any person under the age of 13. Individuals under the age of 18 should consult with their parent or guardian about the use of the Services for their benefit. If you are a parent or legal guardian and think your child has given us information, you can email us at support@healthbeacon.com. Please mark your inquiries “COPPA Inquiry.”
Depending on where you are located, you may have certain choices about how we use your personal information. To opt-out of marketing communications please email us at support@healthbeacon.com or by following the instructions included in the email or text correspondence. To exercise other rights with respect to your personal information, please contact us using the information in this Privacy Notice.
Please note that, even if you unsubscribe from certain correspondence, we may still need to contact you with important transactional or administrative information, as permitted by law. Additionally, if you withdraw your consent or object to processing, or if you choose not to provide certain personal information, we may be unable to provide some or all of the Services to you.
HealthBeacon will use, process, and store personal information only for so long as you require us, or as legally required by set retention periods. As a company recording medical records, there are laws and regulations that apply to us which set minimum periods for retention of personal information.
For example: Where we hold personal information to comply with a legal or regulatory obligation, we will keep the information for at least as long as is required to comply with that obligation. Where we hold personal information in order to provide a product or service (such as a HealthBeacon), we will keep the information for at least as long as we provide the product or service. For further information about the period of time for which we retain your personal information, please contact us.
In certain circumstances, we may be legally compelled to release your personal information in response to a court order, subpoena, search warrant, law or regulation
You can correct or update your personal information at any time by calling the HealthBeacon Customer Care Team using the phone number on the back of your HealthBeacon Unit.
Subject to any applicable business, legal, or regulatory requirements, we securely destroy personal information when it is no longer required to fulfil our services and commitments to you or to enforce our rights or meet our obligations.
We process and store personal information both inside the United States and overseas. If you live outside of the United States, be advised that we may transfer your personal information to the United States and other countries, whose laws may not provide the same protections as the laws in your country. For information related to how we process, store, and transfer personal information of individuals in the European Union and United Kingdom, please review the “Information for Individuals in the EU and UK” section below.
Information security is extremely important to us. HealthBeacon uses appropriate technical, physical, legal and organisational measures, which comply with data protection laws to keep personal information secure. If, despite our efforts, you believe that personal information is no longer secure, please tell us so that we can resolve any security issue.
As most of the personal information we maintain is stored electronically, we have implemented appropriate IT security measures to ensure this personal information is kept secure. For example, we may use anti-virus protection systems, firewalls, and data encryption technologies. We have procedures in place at our premises to keep any hard copy records physically secure. Our HealthBeacon team receives regular training on data protection and information security.
When HealthBeacon engages a third party (including our service providers) to collect or otherwise process personal information on our behalf, the third party will be selected carefully and required to use appropriate security measures to protect the confidentiality and security of personal information.
Unfortunately, no data transmission over the Internet or electronic data storage system can be guaranteed to be 100% secure. If you believe that your interaction with us is no longer secure (for example, if you feel that the security of any personal information you might have sent to us has been compromised), please contact us immediately.
California enacted A.B. 370, amending the California Online Privacy Protection Act to require website operators like us to disclose how we respond to “Do Not Track Signals”; and whether third parties collect personally identifiable information about users when they visit us.
(1) We do not track users, who do not interact with its sharing functionality across the web, and therefore do not use “do not track” signals.
(2) We do not authorize the collection of personally identifiable information from our users for third party use through advertising technologies without separate member consent.
California Civil Code Section 1798.83 also permits our customers who are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to quality@healthbeacon.com. Please note that we are only required to respond to one request per customer each year.
To the extent you are a California resident and your “Personal Information” is subject to the CCPA, this Section applies to our collection and use of Personal Information, as required by the California Consumer Privacy Act of 2018 and its implementing regulations (the “CCPA”). This Section describes (1) the categories of Personal Information, collected and disclosed by us, subject to CCPA, (2) your privacy rights under CCPA, and (3) how to exercise your rights.
When we use the term “Personal Information” in the context of the CCPA, we mean information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular California consumer or household.
If you would like to receive a copy of this Section in an alternate format (e.g., printable) or language, please contact us at support@healthbeacon.com.
In accordance with California law, we may have collected and share the following categories of Personal Information within the past 12 months:
We share each of these categories of Personal Information with our service providers to the extent necessary for them to facilitate our business purposes. We also share this Personal Information for the purposes set forth in this Privacy Notice.
If you are a resident of California and your “Personal Information” is subject to the CCPA, you may have the following rights:
| Privacy Right | Description |
|---|---|
| Notice | The right to be notified of what categories of Personal Information will be collected at or before the point of collection and the purposes for which they will be used and shared |
| Access | The right to request the categories of Personal Information that we collected in the previous twelve (12) months, the categories of sources from which the Personal Information was collected, the specific pieces of Personal Information we have collected about you, and the business purposes for which such Personal Information is collected and shared. You may also have the right to request the categories of Personal Information which were disclosed for business purposes, and the categories of third parties in the twelve (12) months preceding your request for your Personal Information. |
| Data Portability | The right to receive the Personal Information you previously have provided to us. |
| Erasure | The right to have your Personal Information deleted. However, please be aware that we may not fulfill your request for deletion if we (or our service provider(s)) are required or permitted to retain your Personal Information for one or more of the following categories of purposes: (1) to complete a transaction for which the Personal Information was collected, provide a good or service requested by you, or complete a contract between us and you; (2) to ensure our website integrity, security, and functionality; (3) to comply with applicable law or a legal obligation, or exercise rights under the law (including free speech rights); or (4) to otherwise use your Personal Information internally, in a lawful manner that is compatible with the context in which you provided it. |
| To Opt Out | The right to opt out of the sale of your Personal Information. |
If you would like to exercise your rights listed above, please send (or have your authorized agent send) an email to support@healthbeacon.com or call us toll-free at: (857) 302-4872. Please note: you will not be discriminated against in any way by virtue of your exercise of the rights listed below, which means we will not deny goods or services to you, provide a different prices or rates for goods or services to you, or provide a different level or quality of goods or services to you. We must verify your identity before fulfilling your requests. If we cannot initially verify your identity, we may request additional information to complete the verification process. Any Personal Information you disclose to us for purposes of verifying your identitywill solely be used for the purpose of verification. If you are an authorized agent making a request on behalf of a California consumer, we will also need to verify your identity, which may require proof of your written authorization or evidence of a power of attorney.
We may deny certain requests, or only fulfil some in part, as permitted or required by law. For example, if you request to delete Personal Information, we may retain Personal Information that we need to retain for legal purposes (e.g., tax accounting). You have a right not to receive discriminatory treatment by any business when you exercise your California privacy rights.
In accordance with European and UK law (collectively, the “GDPR”), individuals in the EU and UK may have additional rights relating to the collection and processing of personal information.
BASIS FOR PROCESSING
Our legal basis for processing the personal information described in this Notice will depend on the personal information concerned and the context in which we process it. We process personal information from you:
YOUR PRIVACY RIGHTS
Depending on applicable law, you may have the right to:
Security issues should be disclosed to quality@healthbeacon.com. We will investigate legitimate security reports and respond within 1-2 business days, and make every effort to quickly correct any issues, while following applicable laws and regulations. If you identify a security issue you should not modify or access data that does not belong to you.
This Privacy Notice was last updated in August 2022. We review this Privacy Notice regularly and reserve the right to make changes at any time to take account of changes in our business activities, legal requirements, and the way we process personal information. We will place updates on this website and where appropriate we will give reasonable notice of any changes.
If you have any questions about this Privacy Notice, or the privacy practices of HealthBeacon please email us at support@healthbeacon.com or write to us at:
HealthBeacon Limited, 423 West Broadway, Ste 301, South Boston, MA 02127
If you are in the European Union and UK, you may contact us at:
HealthBeacon Limited, Naas Road Business Park, 20 Muirfield Dr, Inchicore, Dublin, Ireland.
If you are contacting us to exercise your rights with respect to your personal information as detailed in this Privacy Notice, we ask you to please adhere to the following guidelines:
Please note that you don’t need to create an account with us in order to make a request to exercise your rights hereunder.