PRIVACY POLICY
IDENTIPlatform – Platform, SMS & Data Practices
This Privacy Policy describes how IDENTI HEALTHCARE US INC. (doing business as IDENTI Medical) (“IDENTI,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with IDENTIPlatform and related SMS communications (“Services”). This policy is incorporated by reference into our Terms of Service.
1. Scope and Applicability
This Privacy Policy applies to:
- Users of IDENTIPlatform (the web-based and on-premises application);
- Recipients of SMS communications sent through the Platform;
- Visitors to https://identimedical.com; and
- Any individual whose personal information is processed by IDENTI in connection with the Services.
This policy supplements any Business Associate Agreement (BAA) executed between IDENTI and your organization. To the extent of any conflict between this policy and a BAA, the BAA shall govern with respect to Protected Health Information (PHI).
2. Information We Collect
2.1 Information You Provide Directly
- Account registration details: name, job title, email address, phone number, and organizational affiliation.
- Mobile phone number provided during SMS opt-in enrollment.
- Communication preferences and notification settings within the Platform.
- Content submitted through contact forms, support requests, webinars, or newsletter sign-ups.
- Feedback, suggestions, or bug reports submitted to IDENTI.
2.2 Information Collected Automatically
- Platform usage data: login activity, feature interactions, session duration, pages visited, and actions taken within the Platform.
- Device information: hardware model, operating system, browser type and version, and unique device identifiers.
- Log data: IP address, access timestamps, referring URLs, and error logs.
- SMS delivery data: message delivery status, timestamps, carrier information, and opt-out records.
- Cookies and similar tracking technologies (see Section 10).
2.3 Information from Your Organization
If you access IDENTIPlatform through your employer or healthcare facility, we may receive account information from your organization’s administrator, including your name, role, department, and contact details. Your use of the Platform is subject to your organization’s agreement with IDENTI.
2.4 Information from Third Parties
We may receive information about you from third-party sources, including identity verification services, business partners, and publicly available sources, to the extent permitted by applicable law.
2.5 Information We Do Not Collect via SMS
SMS notifications sent through IDENTIPlatform are operational and logistical in nature. We do not intentionally collect or transmit Protected Health Information (PHI) via SMS. If you believe a message you received contains PHI in error, contact us immediately at info@identimedical.com.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, maintain, and improve IDENTIPlatform and related Services.
- To deliver SMS alerts, notifications, and operational updates that you have consented to receive.
- To manage your account, preferences, and notification settings.
- To maintain records of SMS consent and opt-out requests as required by the Telephone Consumer Protection Act (TCPA), 47 U.S.C. § 227.
- To authenticate users and maintain the security of the Platform.
- To process transactions and send related billing communications.
- To respond to your inquiries and provide customer support.
- To send service-related communications, including technical notices, updates, and security alerts.
- To generate aggregated, de-identified analytics and statistics to improve our Services.
- To comply with applicable legal obligations and protect the rights of IDENTI and its users.
- To enforce our Terms of Service and other agreements.
We do not use your personal information for behavioral advertising or sell it to third-party advertisers.
4. Legal Basis for Processing
Where required by applicable law (including GDPR), we process personal information on the following legal bases:
- Performance of a contract: processing necessary to provide the Services under our Terms of Service.
- Legitimate interests: improving our Services, ensuring platform security, and communicating with users about the Services, where such interests are not overridden by your rights.
- Consent: where you have provided express consent, including for SMS communications and cookies.
- Legal obligation: processing required to comply with applicable law, including TCPA consent recordkeeping and applicable data protection laws.
5. SMS-Specific Data Practices
5.1 Use of Mobile Numbers
Mobile phone numbers collected for SMS communications are used exclusively to deliver messages you have consented to receive. We do not sell, rent, or share your mobile number with third parties for their own marketing purposes.
5.2 Consent Records
We maintain records of SMS opt-in consent and opt-out requests, including the date, time, and method of consent, in accordance with TCPA requirements. These records are retained for a minimum of four (4) years.
5.3 Opt-Out Processing
Opt-out requests submitted by replying STOP are processed within ten (10) business days. Following opt-out, no further SMS messages will be sent to the relevant number unless the recipient re-enrolls.
5.4 Message Rates
Standard message and data rates may apply based on the recipient’s mobile carrier plan. IDENTI is not responsible for carrier charges.
6. How We Share Your Information
We do not sell your personal information. We may share your information only in the following limited circumstances:
6.1 Service Providers
We engage third-party vendors and service providers (including SMS delivery platforms, cloud infrastructure providers, analytics providers, and payment processors) who process data solely on our behalf, pursuant to written agreements imposing confidentiality and data protection obligations at least as protective as those set forth in this policy.
6.2 Your Organization
If your account is administered by a healthcare facility or employer, authorized administrators of that organization may access your account information, usage logs, and notification records to the extent permitted by the applicable agreement between your organization and IDENTI.
6.3 Legal and Regulatory Disclosure
We may disclose information when required by applicable law, regulation, legal process, or valid governmental request. Where permitted by law, we will provide you with prior notice of such disclosure and cooperate with you in seeking a protective order or other relief.
6.4 Protection of Rights
We may disclose information where reasonably necessary to investigate, prevent, or take action regarding suspected fraud, violations of our Terms of Service, threats to the safety of any person, or illegal activity.
6.5 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your information may be transferred to the successor entity. We will notify you via the Platform or email prior to your information becoming subject to a materially different privacy policy, and you will have the opportunity to delete your account before the transfer takes effect.
6.6 Aggregated or De-Identified Data
We may share aggregated or de-identified information — which cannot reasonably be used to identify you — with third parties for research, analytics, marketing, or other purposes.
7. Data Retention
- SMS consent and opt-out records: minimum four (4) years, as required by TCPA.
- Account and platform data: retained for the duration of the active account and for up to three (3) years thereafter, unless a longer period is required by law.
- Billing and transactional records: retained as required by applicable tax and accounting laws.
- Security and access logs: retained for up to twelve (12) months, unless required for an ongoing investigation.
When data is no longer required, it is securely deleted or anonymized using industry-standard methods designed to prevent recovery. Upon written request following termination of a customer relationship, we will confirm the deletion or return of personal data within thirty (30) days, subject to applicable legal retention requirements.
8. Data Security
We implement and maintain appropriate technical and organizational security measures designed to protect your personal information against unauthorized access, disclosure, alteration, loss, or destruction. These measures include:
- Encrypted data transmission using TLS/HTTPS.
- Encryption of data at rest for sensitive information.
- Role-based access controls and multi-factor authentication.
- Regular vulnerability assessments, penetration testing, and security monitoring.
- Documented incident response procedures.
- Employee security training and confidentiality obligations.
No method of electronic transmission or storage is completely secure. In the event of a data breach that affects your personal information, we will notify you and applicable regulatory authorities as required by applicable law, including state breach notification laws and, where applicable, GDPR Article 33.
9. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal information:
9.1 General Rights (All Users)
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete personal information.
- Deletion: Request deletion of your personal information, subject to applicable legal retention requirements.
- Portability: Request transfer of your personal information in a structured, machine-readable format where technically feasible.
- Objection: Object to processing of your personal information based on our legitimate interests.
- Restriction: Request restriction of processing in certain circumstances.
- SMS Opt-Out: Reply STOP to any SMS message at any time to stop receiving SMS communications.
9.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:
- The right to know what personal information we collect, use, disclose, and sell.
- The right to delete personal information we have collected about you.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information. We do not sell or share personal information as defined under the CCPA.
- The right to limit use and disclosure of sensitive personal information.
- The right to non-discrimination for exercising your CCPA rights.
To submit a CCPA request, contact us at info@identimedical.com. We will respond within forty-five (45) days, with one possible extension of an additional forty-five (45) days where reasonably necessary.
9.3 How to Exercise Your Rights
To exercise any of the rights described in this Section, please contact us at info@identimedical.com. We will respond within thirty (30) days of receiving a verifiable request. We may require verification of your identity before processing your request, and we will not discriminate against you for exercising your rights.
10. Cookies and Tracking Technologies
When you access IDENTIPlatform or our website via a web browser, we and our service providers may use the following technologies:
- Essential cookies: required for the Platform to function, including session management and authentication. These cannot be disabled.
- Analytics cookies: used to understand how users interact with the Platform, enabling us to improve performance and user experience.
- Preference cookies: used to remember your settings and preferences within the Platform.
You may configure your browser to block non-essential cookies. Please note that blocking certain cookies may affect the functionality of the Platform. For more information on our website-specific cookie practices, please refer to our website Privacy Policy at https://identimedical.com/privacy-policy/.
11. HIPAA and Healthcare Data
11.1 Business Associate Agreement
IDENTIPlatform serves healthcare organizations subject to the Health Insurance Portability and Accountability Act (HIPAA). To the extent IDENTI processes Protected Health Information (PHI) on behalf of a covered entity customer, the parties must execute a Business Associate Agreement (BAA) prior to any such processing. The BAA governs the handling of PHI and supplements this Privacy Policy.
11.2 SMS and PHI
SMS communications sent through the Platform are intended to contain operational and logistical information only. Customer and its users must not transmit PHI via SMS Services. IDENTI is not liable for any PHI transmitted by Customer through SMS Services in violation of this restriction or the applicable BAA.
11.3 Minimum Necessary Standard
Where IDENTI processes health-related data under a BAA, it applies the HIPAA minimum necessary standard, accessing and using only the PHI reasonably necessary to perform its obligations under the applicable agreement.
12. International Data Transfers
12.1 Processing Location
Your personal information may be stored and processed in the United States or other countries where IDENTI or its service providers operate. By using the Services, you acknowledge that your information may be transferred to and processed in countries with data protection laws that may differ from those in your home jurisdiction.
12.2 GDPR
For individuals located in the European Economic Area (EEA), United Kingdom, or Switzerland, IDENTI relies on appropriate transfer mechanisms — including Standard Contractual Clauses (SCCs) approved by the European Commission — for transfers of personal data outside the EEA. For full details on our GDPR compliance, please refer to our GDPR Statement at https://identimedical.com/identi-gdpr-statement/.
12.3 Data Localization
Where Customer’s agreement with IDENTI specifies data localization requirements, IDENTI will comply with such requirements as set forth in the applicable Order or BAA.
13. Children’s Privacy
IDENTIPlatform is intended exclusively for use by healthcare professionals and authorized business users aged 18 or older. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected personal information from a minor, we will take prompt steps to delete such information. If you believe we have collected information from a minor, please contact us at info@identimedical.com.
14. Third-Party Links and Services
IDENTIPlatform may contain links to third-party websites, integrations, or services (such as EHR/ERP systems). This Privacy Policy does not apply to those third-party services, and IDENTI is not responsible for their privacy practices or content. We encourage you to review the privacy policies of any third-party services you access through or in connection with IDENTIPlatform.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. When we make material changes, we will:
- Revise the Effective Date at the top of this policy;
- Notify you via the Platform or by email at least fourteen (14) days before the changes take effect; and
- Where required by law, obtain your consent before implementing the changes.
Your continued use of IDENTIPlatform or SMS Services following the effective date of any update constitutes your acceptance of the revised policy. If you do not agree with the updated policy, you should discontinue use of the Services and contact us to close your account.
16. Contact Us – Privacy Inquiries
For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
IDENTI HEALTHCARE US INC. (d/b/a IDENTI Medical)
U.S. Head Office: 999 South Oyster Bay Rd #307, Bethpage, NY 11714, USA
EIN: 45-2344224
Phone: +1-800-697-5956
Email: info@identimedical.com
Website: https://identimedical.com
Privacy Policy: https://identimedical.com/privacy-policy/
GDPR Statement: https://identimedical.com/identi-gdpr-statement/