PRIVACY POLICY

IDENTIPlatform – Platform, SMS & Data Practices

This Privacy Policy describes how IDENTI HEALTHCARE US INC. (doing business as IDENTI Medical) (“IDENTI,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with IDENTIPlatform and related SMS communications (“Services”). This policy is incorporated by reference into our Terms of Service.

 

1. Scope and Applicability

This Privacy Policy applies to:

 

This policy supplements any Business Associate Agreement (BAA) executed between IDENTI and your organization. To the extent of any conflict between this policy and a BAA, the BAA shall govern with respect to Protected Health Information (PHI).

 

2. Information We Collect

2.1 Information You Provide Directly

 

2.2 Information Collected Automatically

 

2.3 Information from Your Organization

If you access IDENTIPlatform through your employer or healthcare facility, we may receive account information from your organization’s administrator, including your name, role, department, and contact details. Your use of the Platform is subject to your organization’s agreement with IDENTI.

 

2.4 Information from Third Parties

We may receive information about you from third-party sources, including identity verification services, business partners, and publicly available sources, to the extent permitted by applicable law.

 

2.5 Information We Do Not Collect via SMS

SMS notifications sent through IDENTIPlatform are operational and logistical in nature. We do not intentionally collect or transmit Protected Health Information (PHI) via SMS. If you believe a message you received contains PHI in error, contact us immediately at info@identimedical.com.

 

3. How We Use Your Information

We use the information we collect for the following purposes:

 

We do not use your personal information for behavioral advertising or sell it to third-party advertisers.

 

4. Legal Basis for Processing

Where required by applicable law (including GDPR), we process personal information on the following legal bases:

 

5. SMS-Specific Data Practices

5.1 Use of Mobile Numbers

Mobile phone numbers collected for SMS communications are used exclusively to deliver messages you have consented to receive. We do not sell, rent, or share your mobile number with third parties for their own marketing purposes.

5.2 Consent Records

We maintain records of SMS opt-in consent and opt-out requests, including the date, time, and method of consent, in accordance with TCPA requirements. These records are retained for a minimum of four (4) years.

5.3 Opt-Out Processing

Opt-out requests submitted by replying STOP are processed within ten (10) business days. Following opt-out, no further SMS messages will be sent to the relevant number unless the recipient re-enrolls.

5.4 Message Rates

Standard message and data rates may apply based on the recipient’s mobile carrier plan. IDENTI is not responsible for carrier charges.

 

6. How We Share Your Information

We do not sell your personal information. We may share your information only in the following limited circumstances:

6.1 Service Providers

We engage third-party vendors and service providers (including SMS delivery platforms, cloud infrastructure providers, analytics providers, and payment processors) who process data solely on our behalf, pursuant to written agreements imposing confidentiality and data protection obligations at least as protective as those set forth in this policy.

6.2 Your Organization

If your account is administered by a healthcare facility or employer, authorized administrators of that organization may access your account information, usage logs, and notification records to the extent permitted by the applicable agreement between your organization and IDENTI.

6.3 Legal and Regulatory Disclosure

We may disclose information when required by applicable law, regulation, legal process, or valid governmental request. Where permitted by law, we will provide you with prior notice of such disclosure and cooperate with you in seeking a protective order or other relief.

6.4 Protection of Rights

We may disclose information where reasonably necessary to investigate, prevent, or take action regarding suspected fraud, violations of our Terms of Service, threats to the safety of any person, or illegal activity.

6.5 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your information may be transferred to the successor entity. We will notify you via the Platform or email prior to your information becoming subject to a materially different privacy policy, and you will have the opportunity to delete your account before the transfer takes effect.

6.6 Aggregated or De-Identified Data

We may share aggregated or de-identified information — which cannot reasonably be used to identify you — with third parties for research, analytics, marketing, or other purposes.

 

7. Data Retention

 

When data is no longer required, it is securely deleted or anonymized using industry-standard methods designed to prevent recovery. Upon written request following termination of a customer relationship, we will confirm the deletion or return of personal data within thirty (30) days, subject to applicable legal retention requirements.

 

8. Data Security

We implement and maintain appropriate technical and organizational security measures designed to protect your personal information against unauthorized access, disclosure, alteration, loss, or destruction. These measures include:

 

No method of electronic transmission or storage is completely secure. In the event of a data breach that affects your personal information, we will notify you and applicable regulatory authorities as required by applicable law, including state breach notification laws and, where applicable, GDPR Article 33.

 

9. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

9.1 General Rights (All Users)

 

9.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:

 

To submit a CCPA request, contact us at info@identimedical.com. We will respond within forty-five (45) days, with one possible extension of an additional forty-five (45) days where reasonably necessary.

 

9.3 How to Exercise Your Rights

To exercise any of the rights described in this Section, please contact us at info@identimedical.com. We will respond within thirty (30) days of receiving a verifiable request. We may require verification of your identity before processing your request, and we will not discriminate against you for exercising your rights.

 

10. Cookies and Tracking Technologies

When you access IDENTIPlatform or our website via a web browser, we and our service providers may use the following technologies:

 

You may configure your browser to block non-essential cookies. Please note that blocking certain cookies may affect the functionality of the Platform. For more information on our website-specific cookie practices, please refer to our website Privacy Policy at https://identimedical.com/privacy-policy/.

 

11. HIPAA and Healthcare Data

11.1 Business Associate Agreement

IDENTIPlatform serves healthcare organizations subject to the Health Insurance Portability and Accountability Act (HIPAA). To the extent IDENTI processes Protected Health Information (PHI) on behalf of a covered entity customer, the parties must execute a Business Associate Agreement (BAA) prior to any such processing. The BAA governs the handling of PHI and supplements this Privacy Policy.

11.2 SMS and PHI

SMS communications sent through the Platform are intended to contain operational and logistical information only. Customer and its users must not transmit PHI via SMS Services. IDENTI is not liable for any PHI transmitted by Customer through SMS Services in violation of this restriction or the applicable BAA.

11.3 Minimum Necessary Standard

Where IDENTI processes health-related data under a BAA, it applies the HIPAA minimum necessary standard, accessing and using only the PHI reasonably necessary to perform its obligations under the applicable agreement.

 

12. International Data Transfers

12.1 Processing Location

Your personal information may be stored and processed in the United States or other countries where IDENTI or its service providers operate. By using the Services, you acknowledge that your information may be transferred to and processed in countries with data protection laws that may differ from those in your home jurisdiction.

12.2 GDPR

For individuals located in the European Economic Area (EEA), United Kingdom, or Switzerland, IDENTI relies on appropriate transfer mechanisms — including Standard Contractual Clauses (SCCs) approved by the European Commission — for transfers of personal data outside the EEA. For full details on our GDPR compliance, please refer to our GDPR Statement at https://identimedical.com/identi-gdpr-statement/.

12.3 Data Localization

Where Customer’s agreement with IDENTI specifies data localization requirements, IDENTI will comply with such requirements as set forth in the applicable Order or BAA.

 

13. Children’s Privacy

IDENTIPlatform is intended exclusively for use by healthcare professionals and authorized business users aged 18 or older. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected personal information from a minor, we will take prompt steps to delete such information. If you believe we have collected information from a minor, please contact us at info@identimedical.com.

 

14. Third-Party Links and Services

IDENTIPlatform may contain links to third-party websites, integrations, or services (such as EHR/ERP systems). This Privacy Policy does not apply to those third-party services, and IDENTI is not responsible for their privacy practices or content. We encourage you to review the privacy policies of any third-party services you access through or in connection with IDENTIPlatform.

 

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. When we make material changes, we will:

 

Your continued use of IDENTIPlatform or SMS Services following the effective date of any update constitutes your acceptance of the revised policy. If you do not agree with the updated policy, you should discontinue use of the Services and contact us to close your account.

 

16. Contact Us – Privacy Inquiries

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

 

IDENTI HEALTHCARE US INC. (d/b/a IDENTI Medical)

U.S. Head Office: 999 South Oyster Bay Rd #307, Bethpage, NY 11714, USA

EIN: 45-2344224

Phone: +1-800-697-5956

Email: info@identimedical.com

Website: https://identimedical.com

Privacy Policy: https://identimedical.com/privacy-policy/

GDPR Statement: https://identimedical.com/identi-gdpr-statement/