HOPCo Digital Clinic Privacy Notice
HOPCo National MSK Specialty Network LLC, and its affiliates (“HOPCo Digital Clinic”,” “we,” “us,” or “our”) recognizes the importance of protecting the privacy of your personal information, and we have prepared this Privacy Policy to provide you with important information about the privacy practices applicable to the HOPCo Digital Clinic websites, including any website that links to or refers to this Privacy Policy (collectively, the “Sites”). This Policy does not address personal information collected through other means.
Our Key Privacy Commitments
We are committed to protecting your personal information and Protected Health Information (PHI). To support this, we make the following commitments:
- We only collect personal information and PHI as necessary to provide and improve our services.
- We use PHI only as permitted by HIPAA, HITECH, applicable state privacy laws, and our Business Associate Agreements (BAAs).
- We do not use PHI for advertising, marketing, or sales-based analytics.
- We do not sell your personal information or PHI, and we do not “share” PHI for cross-context behavioral advertising You can request access, correction, or deletion of your data at any time where permitted by law.
- We apply industry-standard security measures, including encryption, access controls, continuous monitoring, and third-party security testing.
- Contact information, such as your full name, email address, mobile phone number, and address;
- Other identifying information;
- Username and password;
- Your location;
- Personal health information, including information about your health condition, previous treatments, general health, and health insurance; and
- Any other information you provide to us.
- If you are applying for employment through our website, please see our US Recruiting Privacy Policy
- No sale or rental of data — we never sell or rent your information, and we do not share it with third parties for advertising or marketing.
- Security — messages travel over TLS 1.2 and are stored with AES-256 encryption; our providers apply strong safeguards and are ISO 27001 certified. Where required, service providers are bound by a HIPAA Business Associate Agreement.
- Message frequency — up to 5 texts per appointment (typically: scheduling, confirmation, pre-visit forms (if needed), reminder and a post-visit follow-up message); msg & data rates may apply.
- Opt-out / help — reply STOP at any time to end texts, HELP for help, or email privacy@hopco.com with questions.
- All SMS communications are handled in accordance with applicable privacy and data protection laws, including the Telephone Consumer Protection Act (TCPA).
- Provide and improve the Sites;
- Contact you, including contact you in connection with our Services and appointments, events or offerings that you may have registered for; identify and authenticate your access to the parts of our Portal or other password-protected Services that you are authorized to access; to send you surveys; for recruiting and human resources administration purposes; to protect our rights or our property and to ensure the technical functionality and security of our Services; and as required to meet our legal and regulatory obligations;
- Fulfill your requests for services and information;
- Send you information about us or on behalf of our affiliates and trusted third-party partners, provided that we will not, without your express opt-in permission, use your personal information to send you general marketing emails from our Company and/or on behalf of third parties;
- Analyze the use of the Sites and user data to understand and improve the Sites;
- Customize the content you see when you use the Sites;
- Prevent potentially prohibited or illegal activities;
- To protect our rights and the rights of other users;
- For any other purposes disclosed to you at the time we collect your information or pursuant to your consent.
- Authorized third-party vendors and service providers. We may share your information with third-party vendors and service-providers that help us with specialized services, including billing, payment processing, customer service, email deployment, business analytics, marketing (including but not limited to advertising, attribution, deep-linking, direct-mail, mobile marketing, optimization and retargeting), performance monitoring, hosting, and data processing. These third-party vendors and service providers may not use your information for purposes other than those related to the services they are providing to us.
- Corporate affiliates. We may share your information with our corporate affiliates that are subject to this policy.
- Business transfers. We may share your information in connection with a substantial corporate transaction, such as the sale of the Sites or HOPCo Digital Clinic, a merger, consolidation, asset sale, or in the unlikely event of bankruptcy.
- Legal purposes. We may disclose information to respond to subpoenas, court orders, legal process, law enforcement requests, legal claims or government inquiries, and to protect and defend the rights, interests, health, safety, and security of HOPCo Digital Clinic, our affiliates, users, or the public. If we are legally compelled to disclose information about you to a third party, we will attempt to notify you by sending an email to the email address in our records unless doing so would violate the law or unless you have not provided your email address to us.
- With your consent or at your direction. We may share information for any other purposes disclosed to you at the time we collect the information or pursuant to your consent or direction.
- De-identified Data. We create and use de-identified and/or aggregated data about our users (for example, statistical or demographic data) to help us and our partners evaluate and improve treatments, devices, digital health tools, and patient safety. Once data has been de-identified in accordance with applicable standards, it is no longer considered Personal Information or PHI.
- We may license or share HIPAA-de-identified data (as defined under 45 CFR §164.514(b)), which is no longer Personal Information or PHI. Such data may be used for research, analytics, scientific study, or to support development of technologies that improve patient care.
- Strict data-minimization practices, accessing only the information necessary for the specific purpose;
- Encryption of Personal Information and PHI in transit (TLS 1.2/1.3) and at rest;
- Role-based access controls ensuring only authorized personnel may access PHI;
- Audit logs and continuous monitoring of PHI access;
- Regular penetration testing and vulnerability scanning by accredited security firms;
- Segregated production, development, and analytics environments with technical safeguards preventing PHI exposure;
- Contractual and technical controls ensuring that third-party processors may not use PHI for any purpose other than delivering the contracted service; and
- A documented incident-response and breach-notification procedure compliant with HIPAA and HITECH.
- PHI retained under HIPAA retention rules;
- Medical record retention laws in the state where you reside;
- Contractual obligations under a Business Associate Agreement; and
- Legal, regulatory, or audit-related retention requirements.
- If we hold PHI on behalf of a Covered Entity, we will notify the Covered Entity, which will determine how the request is fulfilled in accordance with HIPAA and the applicable BAA.
- Provide access to and/or a copy of certain information we hold about you;
- Prevent the processing of your information for direct-marketing purposes (including any direct marketing processing based on profiling);
- Update or rectify information which is out of date or incorrect;
- Delete certain information which we are holding about you;
- Oppose, cancel, or restrict the way that we process and disclose certain information;
- Transfer your information to a third-party provider of services;
- Revoke your consent for the processing of your information.
- Save your location preference if you have set your location on your homepage;
- Remember settings you have applied, such as layout, text size, preferences, and colors;
- Show you when you are logged in; and
- Store accessibility options.
- Better understand our Sites visitors so that we can improve how we present our content;
- Test different design ideas for pages, such as our homepage;
- Collect information about visitors of our Sites such as where they are located and what browsers they are using;
- Determine the number of unique users of our Sites;
- Improve our Sites by measuring any errors that occur; and
- Conduct research and diagnostics to improve product offerings.
- See what cookies or other locally stored data you’ve got and delete them on an individual basis;
- Block third party cookies or similar technology;
- Block cookies or similar technology from websites;
- Block all cookies or similar technologies from being set; or
- Delete all cookies or similar technologies when you close your browser.
- Apple Safari
- Google Chrome
- Microsoft Edge
- Microsoft Internet Explorer
- Mozilla Firefox
- Android (Chrome)
- iPhone or iPad (Chrome)iPhone or iPad (Safari)
- Contract necessity – to provide services you request (such as responding to inquiries or scheduling appointments).
- Legal obligation – where required by applicable law.
- Legitimate interests – for purposes such as maintaining site security, improving our services, and conducting limited analytics, unless your rights and freedoms override these interests.
- Consent – when you choose to provide us with special categories of personal data (such as health information) or for communications that are not otherwise legally required.
- Right to Know Personal Information Collected About You. You have the right to know: (1) the categories of Personal Information we have collected about you; (2) the categories of sources from which the Personal Information is collected; (3) the business or commercial purpose for collecting, selling, or sharing Personal Information; (4) the categories of parties to whom we disclose Personal Information; and (5) the specific pieces of Personal Information we have collected about you. You also have the right to know the list of all third parties to whom we have disclosed Personal Information, as defined under California Civil Code Section 1798.83(e) (a/k/a the “Shine the Light Law”), during the preceding year for third-party direct marketing purposes.
- Right to Know Personal Information Disclosed, Sold or Shared and to Whom. You have the right to request that we disclose to you: (1) the categories of Personal Information that we collected about you; (2) the categories of Personal Information that we sold or shared about you and the categories of third parties to whom the Personal Information was sold or shared, by category or categories of Personal Information for each category of third parties to whom the Personal Information was sold or shared; and (3) the categories of Personal Information that we disclosed about you for a business purpose and the categories of persons to whom it was disclosed for a business purpose.
- Right to Request Deletion of Your Personal Information. You have the right to request that we delete your Personal Information. However, there are a number of situations where you do not have the right to request that we delete your Personal Information. For example, you cannot request that we delete your Personal Information if it is reasonably necessary for us to comply with a legal obligation, complete the transaction for which the Personal Information is collected or provide the services that you have requested or reasonably anticipated by you within the context of our ongoing business relationship, or to otherwise perform a contract between us. We also will not delete your Personal Information from our backup systems to the extent permitted by the CCPA. Following receipt of a request, we will let you know what, if any, Personal Information we can delete. If we cannot delete all of your Personal Information, we will let you know the reason.
- Right to Correct Inaccurate Information. If you believe that any of the Personal Information we maintain about you is inaccurate, you have the right to submit a request for us to correct that information. Upon receipt of a request, we will use commercially reasonable efforts to correct the information as you direct.
- Right to Opt-Out of the Sale and Sharing of Your Personal Information. You may opt-out of the sale or sharing of your Personal Information, to the extent applicable, by (i) clicking here: Do Not Sell or Share My Personal Information, or (ii) enabling a browser-based opt-out preference signal, such as Global Privacy Control (“GPC”). We honor GPC signals as valid opt-out requests under the CCPA/CPRA.
- Right to Limit the Use of Your Sensitive Personal Information. You have the right to limit the use of Sensitive Personal Information under certain circumstances. You do not have this right where we collect, use or disclose your Sensitive Personal Information for the following purposes: (i) to that use which is necessary to perform the services or provide the goods reasonably expected by you; (ii) to help to ensure security and integrity; (iii) to perform services on our behalf; (iv) to undertake activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by us; and (v) to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by us. You also do not have the right to limit the use of Sensitive Personal Information where we only collect or process Sensitive Personal Information without the purpose of inferring characteristics about you as is the case with us. Given the purpose for our collection, use and/or disclosure of your Sensitive Personal Information, this right does not apply to you.
- Right to Not Be Retaliated Against. If you choose to exercise any of your rights, you have the right to not be retaliated against.
- Right to Non-Discrimination. You have the right not to receive discriminatory treatment for exercising any of your privacy rights.
- Identifiers, such as name, postal address, email address, phone number, and online identifiers (including IP address and device identifiers);
- Commercial information, such as records of services obtained or considered;
- Internet or other electronic network activity information, such as browsing history, search history, and information regarding your interaction with our Sites;
- Geolocation data, such as your device’s GPS signal or information about nearby Wi-Fi access points and cell towers;
- Inferences drawn from the above categories to create a profile about you; and
- Sensitive Data, including health-related information you voluntarily provide through our Sites (note: Protected Health Information governed by HIPAA is exempt from these state privacy laws and is addressed in our Notice of Privacy Practices).
- Right to Access. You have the right to confirm whether we are processing your Personal Data and to access such Personal Data.
- Right to Correction. You have the right to correct inaccuracies in your Personal Data, taking into account the nature of the data and the purposes of the processing.
- Right to Deletion. You have the right to request deletion of your Personal Data, subject to certain exceptions (such as data we are required to retain for legal or regulatory purposes).
- Right to Data Portability. You have the right to obtain a copy of your Personal Data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another controller.
- Right to Opt Out of Targeted Advertising. You have the right to opt out of the processing of your Personal Data for purposes of targeted advertising. You may exercise this right by adjusting your cookie preferences through the “Manage Cookies” link at the bottom of our Sites or, for Colorado and Connecticut residents, by enabling an opt-out preference signal such as Global Privacy Control (“GPC”) in your browser. We honor GPC signals as a valid opt-out request under the CPA and CTDPA.
- Right to Opt Out of Sale. You have the right to opt out of the sale of your Personal Data. As noted above, we do not sell your Personal Data.
- Right to Opt Out of Profiling. You have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. “Profiling” means any form of automated processing of Personal Data to evaluate, analyze, or predict personal aspects concerning an identified or identifiable individual’s economic situation, health, personal preferences, interests, reliability, behavior, location, or movements. We do not engage in profiling that produces legal or similarly significant effects.
- To exercise your privacy rights under the CPA, CTDPA, NDPA, TDPSA, or VCDPA, please submit a request by emailing privacy@hopco.com. Please include “State Privacy Rights Request” in the subject line and provide your name, state of residence, and a description of the right(s) you wish to exercise. We will respond to your request within 45 days. In certain circumstances, we may extend this period by an additional 45 days, in which case we will notify you of the extension and the reason for it.
- With respect to the processing of Personal Data belonging to a known child, a parent or legal guardian of the child may exercise the consumer rights on behalf of the known child.
- If we decline to take action on your request, you have the right to appeal our decision. To appeal, please email privacy@hopco.com with the subject line “State Privacy Rights Appeal” within a reasonable time after receiving our decision. We will respond to your appeal within 45 days (or 60 days for Virginia residents). If your appeal is denied, you may contact your state’s Attorney General to submit a complaint:
- Colorado: coag.gov
- Connecticut: portal.ct.gov/ag
- Nebraska: ago.nebraska.gov
- Texas: texasattorneygeneral.gov
- Virginia: oag.state.va.us
- Colorado and Connecticut — Universal Opt-Out Mechanism. We honor opt-out preference signals, such as Global Privacy Control (“GPC”), as a valid request to opt out of targeted advertising and the sale of Personal Data under the CPA and CTDPA. You may enable GPC in your browser settings to automatically communicate your opt-out preference to websites you visit.
- Nebraska and Texas — Teen Protections. If we have actual knowledge that you are between 13 and 17 years of age, we will not, without your consent: (i) process your Personal Data for purposes of targeted advertising; (ii) sell your Personal Data; or (iii) engage in profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.
- Connecticut — Social Security Number Protections. If collected through our website or otherwise, we will take reasonable measures to protect the confidentiality of Social Security numbers and limit access to those with a need for such information. We prohibit the unlawful disclosure of Social Security numbers collected through our website or any other means.
- Virginia — Appeal Response Timeline. Virginia residents have 60 days (rather than 45 days) to receive a response to an appeal. We will inform you in writing of any action taken or not taken in response to your appeal within 60 days, including a written explanation of the reasons for the decision.
- We will not discriminate against you for exercising any of your privacy rights under the CPA, CTDPA, NDPA, TDPSA, or VCDPA. We will not deny you goods or services, charge you different prices, provide a different level or quality of goods or services, or suggest that you will receive a different price or level or quality of goods or services, because you exercised your rights under these state privacy laws.
- First and Last Name;
- Physical Address;
- Email Address;
- Telephone Number; and
- User Name.
- Password Protected Accounts. If you have a password-protected account with us, we may use existing authentication practices to verify your identity but will require re-authentication before disclosing, correcting or deleting data. If we suspect fraudulent or malicious activity relating to your account, we will require further verification (as described below) before complying with the request.
- Verification for Non-Accountholders. If you do not have, or cannot access, a password-protected account with us, we will generally verify your identity as follows:
- For valid requests to know categories of Personal Information, we will verify your identity to a reasonable degree of certainty by matching at least two data points provided by you with reliable data points maintained by us.
- For valid requests to know specific pieces of Personal Information, right of access and right to data portability, we will verify your identity to a reasonably high degree of certainty by matching at least three data points provided by you with reliable data points maintained by us.
- For valid requests to correct or delete Personal Information, we will verify your identity to a reasonable degree or a reasonably high degree of certainty depending on the sensitivity of thePersonal Information and the risk of harm posed by unauthorized deletion. We will act in good faith when determining the appropriate standard to apply.
HIPAA Notice of Privacy Practices (NPP)
If you use our Sites as part of a healthcare service provided by a HIPAA Covered Entity, you may also receive a separate Notice of Privacy Practices (NPP) from that provider. The NPP describes how your PHI may be used and disclosed and how you can access your PHI. This Privacy Policy supplements but does not replace any HIPAA NPP issued by your provider.
Information We Collect though the Sites
We may collect the following kinds of information when you use the Sites:
Information you provide directly to us. For certain activities, such as when you use our Sites, subscribe to our alerts, or contact us directly such as through completing our “Contact Us” form, we may collect some or all of the following types of information:
We may combine such information with information we already have about you.
Information we collect automatically. We may collect certain information automatically when you use our Sites, such as your Internet protocol (IP) address, device and advertising identifiers, browser type, operating system, Internet service provider, pages that you visit before and after using the Sites, the date and time of your visit, information about the links you click and pages you view within the Sites, and other standard server log information. We may also automatically collect technical information (such as time zone setting and location, and other technology on the devices) used to access the Sites. We may also use other automatic technologies such as web server logs, pixels and web beacons. We may also collect certain location information when you use our Sites, such as your mobile device’s GPS signal, or information about nearby Wi-Fi access points and cell towers.
We may also receive information about you from other sources, including through third-party services and organizations. We may combine our first-party data, such as your email address or name, with third-party data from other sources and use this to contact you (e.g. through direct mail). For example, if you access third-party services, such as Facebook, Google, or Twitter, through the Sites to log into the Sites or to share information about your experience on the Sites with others, we may collect information from these third-party services.
SMS / MMS PRIVACY NOTICE
We use SMS messaging to send important service-related communications, such as appointment or treatment reminders and other care-related messages. These messages are delivered through trusted third-party providers who act as data processors on our behalf.
No mobile Opt-in Data will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
How We Use Your Information
We generally use the information we collect online to:
HOW WE SHARE YOUR INFORMATION
We are committed to maintaining your trust, and we want you to understand when and with whom we may share the information we collect.
If you access third-party services, such as Facebook, Google, or Twitter, through the Sites to login to the Sites or to share information about your experience on the Sites with others, these third-party services may be able to collect information about you, including information about your activity on the Site, and they may notify your connections on the third-party services about your use of the Site, in accordance with their own privacy policies. Information you submit may be received, maintained, or transmitted on our systems or those of contractors, third parties, or affiliates, including offshore or overseas locations.
NOTE: The Sites are intended for use in the United States only by users over the age of 18. If you access this Sites from outside the United States, if you choose to provide Personal Information, you do so on your own initiative and at your own risk and are responsible for compliance with all applicable laws and regulations.
USER COMMUNICATIONS
Email communications that you send to us via the email links on our Services may be shared with a customer service representative, employee, medical expert or agent that is most able to address your inquiry. We make reasonable efforts to respond in a timely fashion once communications are received. Once we have responded to your communication, it is discarded or archived, depending on the nature of the inquiry and all applicable laws, rules and regulations.
SECURITY
The security of your personal information is important to us. We implement administrative, technical, and physical safeguards consistent with HIPAA and industry standards. However, no security safeguards are 100% secure and we cannot guarantee the security of your information.
Additional Security Measures
In addition to the safeguards described above, we implement:
How Long We Keep Your Information
We will keep your information for as long as reasonably necessary for the purposes described in this Privacy Policy, while we have a legitimate business need to do so, or as required by law (e.g. for regulatory reporting including to government entities who may oversee the safety and efficacy of research, legal, tax, accounting or other purposes), whichever is longer.
To determine the appropriate retention period for your information, we will consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure of your information, the purposes for which we use your information, and whether we can achieve those purposes through other means, and the applicable legal requirements.
YOUR CHOICES
You may request that we update or delete your personal information by sending us an email at privacy@hopco.com. We will use commercially reasonable efforts to correct or delete your information. Please see “Your Rights” below for more about your data rights.
Deletion Requests
You may request deletion of your personal information by contacting privacy@hopco.com. Deletion will occur except where we are legally required to retain information, including:
Opt-out of Communications:
You may opt out of communications or marketing-related emails by clicking the “Unsubscribe” link at the bottom of each such email. You may continue to receive service-related and other non-marketing communications by following the instructions in a particular communication (such as a text message) or by sending an email with your communication preferences to privacy@hopco.com.
Disabling Cookies:
You may be able to refuse or disable cookies by adjusting your web browser settings. Because each web browser is different, please consult the instructions provided by your web browser (typically in the “help” section). Please note that you may need to take additional steps to refuse or disable local shared objects and similar technologies. For example, local shared objects can be controlled through the instructions on Adobe’s Setting Manager page. If you choose to refuse, disable, or delete these technologies, some of the functionality of the Sites may no longer be available to you.
Do Not Track Signals
Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. Our Sites currently do not respond to “Do Not Track” (DNT) signals and operates as described in this Privacy Policy whether or not a DNT signal is received. If we do respond to DNT signals in the future, we will update this Privacy Policy to describe how we do so. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
YOUR RIGHTS
Your local laws may permit you to request that we:
We will consider all requests and provide our response within the time period stated by applicable law. Please note, however, that certain information may be exempt from such requests in some circumstances, which may include if we need to keep processing your information for our legitimate interests, to comply with a legal obligation. We may request you provide us with information necessary to confirm your identity before responding to your request as required or permitted by applicable law. If you would like further information in relation to your legal rights under applicable law, or would like to exercise those rights, please email us at privacy@hopco.com. Please be sure to include your name, address (including the state where you reside), and email address so we can respond to your request in the time frame required under your state’s laws. For state specific rights, please click here.
We will not discriminate against you for exercising any of your rights described in this Privacy Policy.
THIRD-PARTY ADVERTISING, LINKS, AND CONTENT
The advertising technologies described in this section are used only as stated above: on non-clinical pages, only after opt-in consent, and never on PHI or PHI-adjacent pages.
Subject to those limits:
Some of the Sites may contain links to content maintained by third parties that we do not control. We allow third parties, including business partners, advertising networks, and other advertising service providers, to collect information about your online activities through cookies, pixels, local storage, and other technologies. These third parties may use this information to display advertisements on our Sites and elsewhere online tailored to your interests, preferences, and characteristics. We are not responsible for the privacy practices of these third parties, and the information practices of these third parties are not covered by this Privacy Policy.
Some third parties collect information about users of our Sites to provide interest-based advertising on our Sites and elsewhere, including across browsers and devices. These third parties may use the information they collect on our Sites to make predictions about your interests in order to provide you ads (from us and other companies) across the internet. Some of these third parties may participate in an industry organization that gives users the opportunity to opt out of receiving ads that are tailored based on your online activities. Due to differences between using apps and websites on mobile devices, you may need to take additional steps to disable targeted ad technologies in mobile apps.
Many mobile devices allow you to opt out of targeted advertising for mobile apps using the settings within the mobile app or your mobile device. For more information, please check your mobile settings. You also may uninstall our apps using the standard uninstall process available on your mobile device or app marketplace.
To opt out of interest-based advertising across browsers and devices from companies that participate in the Digital Advertising Alliance or Network Advertising Initiative opt-out programs, please visit their respective websites. You may also be able to opt out of interest-based advertising through the settings within the mobile app or your mobile device, but your opt-out choice may apply only to the browser or device you are using when you opt out, so you should opt out on each of your browsers and devices if you want to disable all cross-device linking for interest-based advertising. If you opt out, you will still receive ads, but they may not be as relevant to you and your interests, and your experience on our Sites may be degraded.
CHILDREN
We do not knowingly allow individuals under the age of 18 to create accounts on our Sites. Our Sites are not intended for use by, and we do not knowingly collect personal information from, children under 13. By using our Sites, you confirm that you are at least 13 years old. If you are between the ages of 13 and 17, you may only use our Sites with permission from a parent or legal guardian. If we become aware that we have collected personal information from a child under 13 without verified parental consent, we the age of 13 through our Sites, we will take reasonable steps to delete that information as soon as practicable If you believe that we may have collected information from a child under 13, please contact us at privacy@hopco.com.
CHANGES TO THE PRIVACY POLICY
We may update this Privacy Policy from time to time. When we update the Privacy Policy, we will revise the “Effective Date” date above and post the new Privacy Policy. We recommend that you review the Privacy Policy each time you visit the Sites to stay informed of our privacy practices. If we make material changes to this Privacy Policy, we will notify you by email or through the Sites as required.
QUESTIONS?
If you have any questions or concerns about our Privacy Policy, or if you wish to submit a data subject access, deletion, or opt-out request according to the state law where you reside, please contact our privacy officer at privacy@hopco.com. Please be sure to include your name, address (including the state where you reside), and email address so we can respond to your request in the time frame required under your state’s laws.
Cookie Notice
Our approach to tracking and consent: We do not load any non-essential cookies, tags, pixels, analytics, or advertising technologies until you provide opt-in consent through our cookie banner. Only strictly necessary technologies required to operate the Sites run before consent.
Separately, we never place advertising or analytics technologies on any page that collects, displays, or transmits health information, or that concerns a specific medical condition, symptom, treatment, procedure, or provider; for example, condition pages, appointment or intake forms, records or prescription requests, and the patient portal. Those pages are not tagged or tracked, whether or not you have consented.
When we do use cookies, it is to collect information about your browsing activities over time and across different websites following your use of our Sites. They allow us to recognize and count the number of users, to see how users move around the Sites when they are using it and assess our internal performance and functionality needs. This helps us to improve the services we provide to you and the way the Sites works. You can find more information about cookies and how to manage them at http://www.allaboutcookies.org/.
In addition to cookies that are “strictly necessary” which are required for the proper operation of our Sites, we may use the following cookies:
Functionality cookies: these cookies record information about choices you’ve made and allow us to tailor our Sites to you. These cookies mean that when you continue to use or come back to our Sites, we can provide you with our Sites as you have asked for them to be provided.
These cookies allow us to:
Performance and Analytics cookies: these cookies help us analyze how our Sites are accessed, used, or are performing in order to provide you with a better user experience and to maintain, operate and continually improve our Sites. They allow us to count visitors and traffic to our Sites. All information collected from analytic cookies is aggregated so it is not identifiable.
These cookies allow us to:
Marketing: We may use Google pixels and Microsoft Bing marketing cookies to help in our marketing efforts.
We do not use third-party tracking pixels (such as Meta Pixel or similar tools) on pages where PHI is created, viewed, or transmitted.
Detailed Cookie Information: For a complete list of the cookies we use, including specific cookie names, providers, purposes, and retention periods, please click the “Manage Cookies” link at the bottom of our Sites. The cookie preference center provides detailed information about each cookie category and allows you to customize your preferences.
Important Notice Regarding “Sharing” Under California Law: When you consent to marketing cookies through our cookie banner, we may “share” your Personal Information (as defined under the CCPA/CPRA) with third-party advertising partners for cross-context behavioral advertising. This occurs when advertising pixels or tags transmit information about your browsing activity to third parties who use it to serve you targeted advertisements. You have the right to opt out of this sharing by clicking Do Not Sell or Share My Personal Information or by enabling Global Privacy Control (GPC) in your browser. We honor GPC signals as valid opt-out requests under the CCPA/CPRA.
You may opt-out of functionality cookies and performance cookies at any time by clicking the “Manage Cookies” link at the bottom of the page. You can then adjust the available sliders to “On” or “Off,” then clicking “close”.
Alternatively, you can change your preferences by changing the settings in your browser. Most browsers will allow you to choose the level of privacy settings you want. This lets you control your cookie settings so that you can:
Most browsers are set to accept cookies by default. However, you can remove or reject cookies in your browser’s settings. Please be aware that such action could affect the availability and functionality of the Site. For more information on how to control cookies, check your browser or device’s settings for how you can control or reject cookies, or visit the following links:
WHAT IF I AM ACCESSING THIS PORTAL FROM OUTSIDE OF THE UNITED STATES?
If you are visiting our Site from outside the United States, your information may be transferred to, stored or processed in the United States, where our servers are located, and our central database is operated. Although the data protection and other laws of the United States and other countries might not be as comprehensive as those in your country, we take steps to protect your privacy, including, for transfers of personal information from the European Economic Area, the use of contractual clauses (known as “Model Clauses” or “Standard Contractual Clauses”) that have been approved by the European Commission. By using our Site, you understand and agree that your information may be transferred to our facilities and those third parties with whom we share it as described in this Privacy Policy.
VISITORS FROM THE EUROPEAN ECONOMIC AREA (EEA) AND UNITED KINGDOM (UK)
Our Sites and services are directed to users in the United States. We do not target, market to, or solicit users in the European Economic Area (EEA) or the United Kingdom (UK), and our Sites are not intended to offer goods or services to individuals in those regions or to monitor their behavior. However, we recognize that incidental access by EEA or UK residents may occur. If you access our Sites from the EEA or UK, the following information applies to you.
If you are located in the EEA or UK, you may have rights under the EU General Data Protection Regulation (EU GDPR) or the UK General Data Protection Regulation and Data Protection Act 2018 (UK GDPR), as applicable. These rights include the right to request access to, rectification of, or erasure of your personal data; to restrict or object to our processing (including where we rely on legitimate interests); to request data portability; and to withdraw consent where consent is the basis for processing. You also have the right to lodge a complaint with your local supervisory authority (in the UK, this is the Information Commissioner’s Office at ico.org.uk).
Legal bases for processing: We process personal data about EEA and UK visitors only where we have a lawful basis under Article 6 of the EU GDPR or UK GDPR (as applicable), which may include:
Special categories of data: If you provide health-related or other sensitive information, we will process such information only with your explicit consent or where another exception under Article 9 of the EU GDPR or UK GDPR applies (for example, healthcare purposes, establishment or defense of legal claims, or where processing is necessary for reasons of substantial public interest).
Cookies and online tracking: For EEA and UK visitors, we use only cookies and similar technologies that are strictly necessary to operate our Sites or maintain security and functionality. We will not place non-essential cookies (such as analytics or marketing cookies) without first obtaining your consent through our cookie banner, as required by the EU ePrivacy Directive and the UK Privacy and Electronic Communications Regulations (PECR). You may withdraw your consent or adjust your preferences at any time via the “Manage Cookies” link at the bottom of our Sites.
International transfers: Your personal data will be transferred to, stored, and processed in the United States, which has not received an adequacy decision from the European Commission or the UK Secretary of State. For transfers from the EEA, we rely on the European Commission’s Standard Contractual Clauses (2021/914/EU), together with supplementary safeguards where appropriate. For transfers from the UK, we rely on the UK International Data Transfer Agreement (UK IDTA) or the UK Addendum to the EU SCCs, as approved by the Information Commissioner’s Office. You may request a copy of these safeguards by contacting us at privacy@hopco.com.
Retention: We retain personal data collected from EEA and UK visitors only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal obligations, or to establish, exercise, or defend legal claims. When personal data is no longer required, we will securely delete or anonymize it.
Automated decision-making: We do not use your personal data for automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
Contact: You may contact us at privacy@hopco.com with any questions or to exercise your rights.
EU and UK Representatives: Although our Sites are directed to the United States and we do not target EEA or UK residents, we have appointed representatives to handle data protection inquiries from these regions. For EEA residents, our representative under Article 27 of the EU GDPR is Olthof Support, Rondeel 2, 2652 GZ Berkel En Rodenrijs, Netherlands (email: ear@myrecovery.com). For UK residents, our representative under Article 27 of the UK GDPR is [UK Representative Name and Address]. These contacts are ear@myrecovery.com for data protection inquiries only and are not patient-support channels.
SPECIAL STATE PRIVACY NOTICES
If you are a resident of any of the following states, you may have additional privacy rights, as set forth below. For residents of Washington State, please click here.
CALIFORNIA RESIDENTS
Your Rights if You Are a Resident of California
California residents may exercise certain privacy rights pursuant to the California Consumer Privacy Act, as amended, and related regulations (CCPA). Your right to submit certain requests as a California resident are described below. Please note that these rights are subject to certain exceptions and certain of these rights are subject to verification mechanisms.
YOUR PRIVACY RIGHTS IF YOU ARE A RESIDENT OF COLORADO, CONNECTICUT, NEBRASKA, TEXAS, OR VIRGINIA
This section applies to residents of Colorado, Connecticut, Nebraska, Texas, and Virginia and supplements the information in our general Privacy Policy. These states have enacted comprehensive consumer privacy laws that provide their residents with specific rights regarding Personal Data: the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Nebraska Data Privacy Act (“NDPA”), the Texas Data Privacy and Security Act (“TDPSA”), and the Virginia Consumer Data Protection Act (“VCDPA”). This notice describes the categories of Personal Data we collect, how we use that data, and your rights under these laws.
Categories of Personal Data We Collect
We may collect the following categories of Personal Data:
Purposes for Processing Personal Data
We process your Personal Data for the following purposes: (i) to provide and improve our Sites and services; (ii) to communicate with you about appointments, services, and your account; (iii) to respond to your inquiries and fulfill your requests; (iv) to send you marketing communications (with your consent where required); (v) to personalize your experience on our Sites; (vi) to analyze usage of our Sites and improve our services; (vii) to detect, prevent, and address fraud, security issues, and technical problems; (viii) to comply with legal obligations; and (ix) for other purposes disclosed to you at the time of collection or with your consent.
Categories of Third Parties
We may share your Personal Data with the following categories of third parties: (i) service providers who perform services on our behalf pursuant to written contracts (such as hosting, payment processing, analytics, and customer service); (ii) our corporate affiliates; (iii) professional advisors (such as lawyers, accountants, and auditors); (iv) government authorities when required by law; and (v) business partners in connection with corporate transactions.
Sale of Personal Data and Targeted Advertising
We do not “sell” your Personal Data as that term is defined under these state privacy laws. We may engage in targeted advertising using cookies and similar technologies on non-clinical pages of our Sites, subject to your opt-in consent obtained through our cookie banner. You have the right to opt out of targeted advertising as described below.
Sensitive Data
Under these state privacy laws, “Sensitive Data” generally includes data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship or immigration status, genetic or biometric data processed for identification purposes, Personal Data of a known child, and precise geolocation data. We process Sensitive Data only with your consent, which you may provide through our Sites (for example, when you voluntarily submit health information through a contact form). Protected Health Information subject to HIPAA is exempt from these state privacy laws and is governed by our separate Notice of Privacy Practices.
Your Privacy Rights
If you are a resident of Colorado, Connecticut, Nebraska, Texas, or Virginia, you have the following rights under your state’s privacy law:
Exercising Your Rights
Right to Appeal
State-Specific Provisions
The following provisions apply only to residents of specific states:
Non-Discrimination
YOUR NEVADA PRIVACY RIGHTS
We may collect the following categories of covered information about you through our Site, when you visit the Site such as:
We may share such covered information with categories of third parties such as marketing. Third parties may collect covered information about your online activities over time and across different Internet websites or online services when you use the Site. If you use or visit the Site, you may review and request changes to any of your covered information that is collected through the Site by emailing privacy@hopco.com. You may submit a verified request that we not sell any covered information that we have collected or will collect about you by emailing privacy@hopco.com. After we receive your request and determine that it is a verified request, we will not sell any covered information that we have collected or will collect about you. Nevada law provides that Nevada residents may opt-out of the “sale” of “covered information” to third parties, including but not limited to name, address, social security number, and online service activity. Our uses of your Personal Information are not sales under Nevada law, so no opt-out right applies.
How to Make a Consumer Request
For residents of states listed above: (a) you can exercise your rights to opt-out of the selling and/or sharing of your personal information (to the extent applicable to you) by: (i) clicking the link provided above or (ii) enabling the setting in a browser that supports an opt-out preference signal (also known as universal opt-out mechanisms); and (b) for all other requests (to the extent applicable to you), you can make a request by calling us at (855) 483-3238 or submitting a request through our online webform: Do Not Sell or Share My Personal Information.
When you make certain requests (e.g., a request to know, delete and/or correct; or a request for access or data portability), to help protect your privacy and maintain security, we will take steps to verify your identity. Our verification procedure may differ depending on whether you have an account with us or not and the request you are making. The following generally describes the verification processes we use:
We may also require a declaration, signed under penalty of perjury, that the person requesting the information is the person whose information is the subject of the request or that person’s authorized representative.
If there is no reasonable method by which we can verify your identity, we will state so in response, including an explanation of why we have no reasonable method to verify your identity.
If you use an authorized agent to submit a request to know, delete or correct, we may require the authorized agent to provide proof that you gave the agent signed permission to submit the request. We may also require you to do either of the following: (a) verify your own identity directly with us; or (b) directly confirm with us that you provided the authorized agent permission to submit the request.
There may be situations where we cannot grant your request. For example, if you ask us to delete Personal Information that we are obligated to keep to comply with applicable law we may not be able to fulfill some or all of your request. We may also decline to grant your request where our use of your Personal Information serves a legitimate purpose such as for security purposes. Your request may also be denied if it compromises the privacy of others, is overly repetitive or extremely burdensome to fulfill.
We will respond to valid requests to know, requests to correct and / or delete no later than 45 calendar days. If we cannot verify your request within 45 days, we may deny your request. If necessary, we may take up to an additional 45 days to respond to your request but in such an event will provide you a notice and an explanation of the reason that we will take more than 45 days to respond to your request.
Valid requests under “Right of Access” and “Right to Data Portability” will be transmitted securely. If we cannot fulfill your request, we will notify you of that decision and the reasons why within 45 days.
If you believe our decision was in error, you may have the right to submit an appeal using the method(s) above.