City

,

State

|

Logo Mobile
Date last modified: July 22, 2022

Mindi Privacy Policy

What is this document?

MindiTM and its affiliates ("Mindi," "we," "our," and/or "us") value the privacy of individuals who use our website (the "Site") and related services (collectively, our "Services").

This privacy statement ("Privacy Statement") explains how we collect, use, and share information from or about individuals who use our Services ("Members"). It describes what information other members or doctors can see when they use our Services. This Privacy Statement also tells you about your rights and choices with respect to Personal Information, and how you can contact us if you have any questions or concerns. By using our Services, you agree to the collection, use, disclosure, and procedures this Privacy Statement describes. In addition to this Privacy Statement, your use of our Services is also subject to our Terms of Use.

For the purpose of this Privacy Statement, "Personal Information" means any information that, by itself or in combination with other information, identifies or can reasonably be used to identify an individual, such as their name, email address, telephone number, address, date of birth, or healthcare information. Personal Information does not include information that is anonymized. "Protected Health Information" has the meaning defined in the Health Insurance Portability and Accountability Act ("HIPAA"), and is not Personal Information for the purposes of this Privacy Statement, but is rather subject to our Notice of Privacy Practices described below.

Information We Collect

We may collect a variety of information from or about you or your devices from various sources, as described below.

You can browse many areas of the Site and/or our applications without providing any Personal Information. However, at certain areas of the Site, we may ask that you provide Personal Information. Where applicable, we indicate whether and why you must provide us with your Personal Information, as well as the consequences of failing to do so. If you do not provide your Personal Information when requested, you may not be able to use our Services if that information is necessary to provide you with our Services or if we are legally required to collect it.

Information You Provide to Us

Registration and Profile Information. We collect the information you provide when you create a Mindi account, including your name, email address, password, and date of birth. We will also receive any optional information you choose to add to your Mindi Profile ("Profile"), such as your health goals, medications, medical conditions, location, and other information. Health conditions and treatment recommendations often depend on your age, gender, and where you live. Having robust Profile information lets Mindi give you a personalized experience, and it helps Mindi doctors give you an appropriate treatment plan.

Payment Information. When you add a credit card or payment method to your Profile or make a purchase through our Services, we will collect that payment card information / a third party service provider that handles payments for us will receive your payment card information.

Communications. If you contact us directly, we may receive additional information about you. For example, when you contact us for customer support, we will receive your name, email address, phone number, the contents of a message or attachments that you may send to us, and other information you choose to provide. If you subscribe to our newsletter, then we will collect certain information from you, such as your email address. When we send you emails, we may track whether you open them to learn how to deliver a better customer experience and improve our Services.

Careers. If you decide that you wish to apply for a job with us, you may submit your contact information, cover letter, and your resume online. We will collect the information you choose to provide on your resume, such as your education and employment experience. You may also apply through LinkedIn. If you do so, we will collect the information you make available to us on LinkedIn.

Information We Collect When You Use Our Services

Location Information. When you use our Services, including our mobile application, if you allow us, we may receive your precise location information. We use your location information to connect you with local doctors in order to comply with regulations and to personalize and improve your experience by suggesting service providers that are located near to you. Service providers including but not limited to pharmacies, doctors, and lab test centers. We also use your location information to help our doctors develop an appropriate treatment plan for you. This location information is also used to help troubleshoot network connectivity and user experience issues. We also infer the general physical location of your device and the geographic regions our Members come from. For example, your internet protocol ("IP") address may indicate your general geographic region.

Device Information. We receive information about the device and software you use to access our Services, including IP address, web browser type, operating system version, phone carrier and manufacturer, installed applications, device identifiers, mobile advertising identifiers, and push notification tokens.

Usage Information. To help us understand how you use our Services and to help us improve them, when you use our Services, we automatically receive information about your interactions with our Services, such as the pages or other content you view, any content you post, and the dates and times of your visits.

Information from Cookies and Similar Technologies. A cookie is a small piece of data that a website can send to your computer's internet browser, which is then stored on your computer's operating system. Cookies are how websites recognize users and keep track of their preferences. We and third-party partners collect information using cookies, pixel tags, or similar technologies. Our third-party partners, such as analytics and advertising partners, may use these technologies to collect information about your online activities over time and across different services. Please review your web browser's "Help" file to learn the proper way to modify your cookie settings. Please note that if you delete or choose not to accept cookies from the Service, you may not be able to utilize the features of the Service to their fullest potential.

Information We Receive from Third Parties

Virtual Consult Summaries. At the end of every virtual visit (meaning a consultation between a doctor and a patient through our Services using text chat and/or video), the doctor will prepare a note about the virtual visit (the "Consult Summary"), which may include health information such as symptoms, diagnosis, and treatment. These Consult Summaries will become part of your Profile. When you initiate virtual visits using our Services, the doctor that you see or chat with will be able to view all past Consult Summaries to be able to give you appropriate care.

Social Media Accounts. We may obtain Personal Information about you from third party social media services, such as Facebook and Twitter, if you choose to link our Services with third party social media accounts ("Social Media Account") by either: (i) providing your Social Media Account login information to Mindi through the Services; or (ii) allowing Mindi to access your Social Media Account, as is permitted under the applicable terms and conditions that govern your use of the respective Social Media Account.

How We Use the Information We Collect

Mindi uses the information we collect for the following purposes:

How We Share the Personal Information We Collect

We may share or otherwise disclose Personal Information in the circumstances described below.

Affiliates. We may disclose Personal Information to our affiliates or partners to provide the Services or for other purposes for which the information was collected.

Vendors and Service Providers. We may share Personal Information we receive with vendors and service providers in connection with the provision of the Services

Our service providers, such as prescription services, may be responsible for providing notices to Members. In the event Personal Information is (a) to be used for a purpose that is materially different from the purposes for which the Personal Information was originally collected or subsequently authorized, or (b) transferred to a third party acting as a data controller, Members will be given, where practical and appropriate, an opportunity to opt out of having non-sensitive Personal Information used or transferred. For sensitive information, including health related information, members will opt in before such use or transfer.

In some instances, Mindi may retain other service providers to perform functions on our behalf, including, but not limited to, website developers, IT services providers, shipping or direct mail organizations, storage facilities, or entities assisting us in a recruitment process.

Analytics Partners. We may make certain Personal Information available to third parties for analytics purposes, including: (a) for Mindi's business or marketing purposes, such as to track sales leads; or (b) to leverage third-party tools to understand Members' interests, habits, and usage patterns, and/or functionality available through our Services. We only share your Personal Information with analytics partners to improve our own service and/or to deliver healthcare to you. We do not sell your Personal Information to advertisers.

As Required by Law and Similar Disclosures. We may access, preserve, and disclose Personal Information if we believe doing so is required or appropriate, in our sole discretion, to: (a) comply with any applicable law, regulation, legal process or governmental request, such as a court order or subpoena, or otherwise cooperate with law enforcement or governmental agencies; (b) take precautions against liability; (c) protect your, our, or others' rights, property, or safety; (d) investigate and defend ourselves against any third-party claims or allegations; and (e) protect the security or integrity of our Services and any facilities or equipment used to make our Services available. For the avoidance of doubt, the disclosure of Personal Information may occur if you post any objectionable content on or through the Services.

Member Content. Our Services are social services in which you can pose questions and find answers to other Members' questions. Your questions will be visible and searchable by other users by default and might be read, collected, and used by others. Please note that our Terms of Use do not allow you to include Personal Information (such as your name, email address, or phone number) in any publicly available questions posted to our Services. Mindi cannot control how such content is seen or used. We are not responsible for the other Members' use of available Personal Information, so you should carefully consider whether and what to post. Please email support@mindi.com to request removal of Personal Information.

Social Media Services. Our Services may allow you to, upon your direction, share Personal Information with certain social media services, such as Facebook, Twitter, Pinterest, and Google Plus. Please consider any impact on your privacy and anonymity when posting content to any and all social media services. You understand and agree that the use of Personal Information by any social media services will be governed by the respective privacy policies of those social media services and your settings on their platforms. We encourage you to review their privacy policies.

Marketing. We do not rent, sell, or share Personal Information about you with non-affiliated companies for their direct marketing purposes, unless we have your permission.

Virtual Doctor Visits. We may share Personal Information with Mindi doctors in order to facilitate your treatment and care. Like an in-person patient-doctor interaction, Mindi virtual consults are confidential, but not anonymous. When using Mindi Premium Services, your Profile information, such as your real name and health information, are visible to doctors with whom you see or chat within a virtual visit. This Profile information is not visible to other Members or to doctors who are not providing care or services in a virtual visit.

By initiating a virtual consult, you consent to sharing your name and the health information in your Profile with doctors who treat you in virtual visits.

Mergers, Sales, or Other Asset Transfers. We may disclose and otherwise transfer Personal Information to service providers, advisors, potential transactional partners, or other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company or we sell, liquidate, or transfer all or a portion of our assets.

Security

We make commercially reasonable efforts to protect Personal Information by using physical and electronic safeguards designed to protect the integrity and security of the Personal Information we maintain. We also use certain physical, organizational, and technical safeguards designed to comply with the Health Insurance Portability and Accountability Act ("HIPAA") security standards for interactions subject to HIPAA security regulations. Mindi takes commercially reasonable precautions, considering the risks involved in the processing and the nature of the Personal Information, designed to protect Personal Information from loss, misuse and unauthorized access, disclosure, alteration and destruction. However, as no electronic transmission or storage of Personal Information can be entirely secure, we can make no guarantees as to the security or privacy of Personal Information.

Information Retention

We take measures to retain your Personal Information for a period that is no longer than necessary to fulfill the purposes outlined in this Privacy Statement, unless a longer retention period is required or permitted by law. When determining the retention period, we take into account various criteria, such as the type of Services provided to you, the nature and length of our relationship with you, the impact on the Services we provide to you if we delete some Personal Information from or about you, and mandatory retention periods provided by law and the relevant statute of limitations.

Your Choices and Rights

Required Account Information. Certain Personal Information is required for account functionality and can be edited but not deleted. For example, you can edit, but not remove, the email address and password required for login.

Health Records. You can amend your health information and can add information to your Consult Summaries to make your information more accurate or complete. Accordingly, if you would like to request access to, or to limit the use or disclosure of Personal Information, please contact the doctor to which you provided the Personal Information in connection with our Services. If you contact us with the name of the doctor to which you provided Personal Information, we will refer your request to that doctor and support them in responding to your request.

Public Content. You can request the removal of Public Content by emailing support@mindi.com.

Marketing Communications

You can unsubscribe from our marketing communications, such as announcements of new features or special offers, via the link provided in the promotional emails. Mindi will never share your email address or other contact information to third parties for their own marketing purposes without your explicit permission. Even if you opt out of receiving promotional messages from us, you will continue to receive administrative messages from us.

Notifications

We will ask you if you want to receive notifications when you open an account with Mindi. If you agree, Mindi may send you email, SMS, or mobile push notices, providing you with account-related reminders or updates, or letting you know that you have a message on our Services. You may opt out at any time by adjusting your notification settings in the settings page.

Do Not Track

There is no accepted standard on how to respond to Do Not Track signals, and we do not respond to such signals.

Deactivating Your Account

To deactivate your account, email our support staff at support@mindi.com and request deactivation. Please allow 72 hours for the deactivation process.

Children

Our Services are not intended for or directed to children under 16 years of age, and we do not knowingly collect Personal Information from children under the age of 13. If you learn that your child has provided us with Personal Information without your consent, then you may alert us at support@mindi.com. If we learn that we have collected any Personal Information from children under 13, then we will promptly take steps to delete such information and terminate the child's account.

Google

Our Services use several services provided by Google, Inc. ("Google"), including the services described below.

Google Analytics. This Site uses Google Analytics, a web analytics service that uses cookies, which we use for the purpose of understanding how Members use our Services, compiling reports on website activity, and providing other information relating to website activity and internet usage. Google will not associate your IP address with any other information held by Google.

You may refuse the use of cookies by selecting the appropriate settings on your browser. However, if you delete cookies and/or prevent new ones, you will likely have to reenter preferences and settings every time you visit a website, and some services and functionalities may not work.

You can prevent Google's collection and use of data such as cookies and IP address by downloading and installing the browser plug-in available here.

More information about how Google uses advertising cookies can be found here.

Google Maps. We use visual mapping services on the Site and/or our applications, please be aware that the Google Maps/Earth Terms of Service, including the Google Privacy Policy, at https://www.google.com/intl/en-US_US/help/terms_maps.html also applies.

Google reCAPTCHA. We use Google reCAPTCHA on the Site and/or our applications and it is also subject to Google's Privacy Policy and Terms of Use, which are available for your review.

Third Party Sites

Our Services may contain links to third-party sites. When you click on one of these links, you are visiting a website operated by someone other than Mindi, and the operator of that website may have different privacy policies. Mindi is not responsible for the individual privacy practices of those sites. Please be aware that this Privacy Statement does not apply to your activities on these third-party sites or any information you disclose to these third parties. We encourage you to read the privacy policies of third-party sites before providing any information to them.

Contact Mindi

Mindi is responsible, or the "data controller", for the processing of your Personal Information processed in connection with the Services. If you have any questions, comments, or concerns about our processing activities, please email us at support@mindi.com, or via traditional mail to 22211 W Interstate 10 STE 1206, San Antonio, TX 78257.

Changes To This Privacy Statement

We reserve the right to change this Privacy Statement at any time. We will post any adjustments to the Privacy Statement on this page, and the revised version will be effective when it is posted. If we materially change the ways in which we use or share Personal Information previously collected from you through the Services, we will notify you through the Services, by email, or other communication.

Mindi HIPAA Notice of Privacy Practices

Date last modified: August 26, 2021

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Overview of Our Responsibilities

If you use the Mindi Premium Services to access virtual, on-demand care provided by doctors, the data generated during this visit may be “protected health information” or “PHI” as defined by the Health Insurance Portability and Accountability Act, commonly referred to as “HIPAA”. PHI is information that is created or maintained by certain entities, including health care providers, that relates to (a) your past, present or future physical or mental health or condition, (b) the provision of health care to you, or (c) the past, present, or future payment for the provision of healthcare to you, and that identifies you, or reasonably could be used to identify you.

The health care providers who are part of Mindi (“Mindi Providers”) are required by law to maintain the privacy and security of your PHI and provide you with this Notice of Privacy Practices (the “Notice”), which describe its duties and your rights with respect to your PHI. We will not use or share your PHI other than as described here unless you tell us we can in writing. Let us know if you change your mind. We will let you know promptly if a breach occurs that may have compromised the privacy or security of your PHI.

The Mindi Providers will abide by this Notice while it is in effect and reserve the right to change the terms of the Notice at any time. The changes will apply to any PHI maintained by Mindi Providers, including PHI created or received by Mindi Providers when the prior Notice was in effect. The new Notice will be posted on Mindi’s website and a copy will be made available to you upon request.

For more information see:

https://www.hhs.gov/hipaa/for-individuals/notice-privacy-practices/index.html

How May Mindi Providers Use and Disclose My Protected Health Information?

  1. Treatment, Payment and Operations. Mindi Providers may use and disclosure your PHI for treatment, payment and operations purposes as permitted by HIPAA. The following are examples of permitted treatment, payment and operations purposes, but not a complete list of all permitted purposes:

Note that Mindi may carry out these health care operational activities on its own, or in certain circumstances, may retain a third party to help them carry out certain functions if those third parties (called “business associates”) also agree to be bound by HIPAA through written agreement.

  1. Pursuant to an Authorization. Mindi Providers may use and disclosure your PHI if you provide written authorization that complies with the requirements under HIPAA, but only to the extent permitted by such authorization. You can revoke your authorization at any time in writing.
  2. As required by law. Mindi Providers may use and disclosure your PHI to the extent required to comply with federal or state law.

Are There Other Circumstances in Addition to the Above in Which Mindi Providers May Use and Disclose My PHI?

Yes. Mindi Providers are allowed or required to share your information in other ways – usually in ways that contribute to the public good, such as public health and research. We have to meet many conditions in the law before we can share your information for these purposes. For more information see:

https://www.hhs.gov/hipaa/for-individuals/notice-privacy-practices/index.html

Note that unlike some other health care providers, Mindi Providers do not currently create the following types of PHI: (a) create or manage a hospital directory, or (b) create or maintain psychotherapy notes.

Also, if certain state laws are more restrictive than HIPAA as to what health information can be shared without first obtaining your consent, we will always follow those laws. For example, some states would not allow us to disclose substance abuse treatment records or HIV status without your written permission, even for a purpose permitted under HIPAA. In these cases, we will follow the more restrictive rule that applies to the Mindi Providers and your health information in that situation.

Finally, Mindi Providers will never use or share your information without first obtaining your written permission for a marketing purposes (unless permitted by HIPAA) or to sell your information.

What Are My Rights When It Comes to My PHI?

When it comes to your PHI, you have certain rights. This section explains your rights and some of our responsibilities to help you access those rights.

Get an electronic or paper copy of your medical record or direct us to share it with others

Ask us to correct your medical record

Request confidential communications

Ask us to limit what we use or share

Get a list of those with whom we’ve shared information

Get a copy of this Notice

Choose someone to act for you

Who Do I Contact at Mindi For a Reason Related to This Notice?

You can contact Mindi in writing at the following address for a reason related to this Notice, such as:

Please write to the Mindi contact for any of these issues: