Legal

Privacy Policy

Your privacy and the security of your health information are of paramount importance to us. This policy explains how we collect, use, and protect your data.

Last Updated: December 28, 2024

Contents

01

Information We Collect

We collect information to provide you with personalized healthcare assistance and improve our services. The types of information we collect include:

Personal Information

  • Name, email address, and contact information
  • Date of birth and demographic information
  • Account credentials and authentication data

Health-Related Information

  • Health inquiries and symptoms you describe
  • Medical history information you choose to share
  • Medication and treatment information

Technical Information

  • Device type, operating system, and app version
  • Usage patterns and interaction logs
  • IP address and general location data
02

How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide personalized health information, AI-powered assistance, and respond to your inquiries
  • Service Improvement: To analyze usage patterns and enhance app functionality and user experience
  • Communication: To send important updates, security alerts, and service notifications
  • Safety & Compliance: To protect against fraud, ensure security, and comply with legal obligations
03

Protected Health Information

HIPAA Compliance Commitment

We are committed to protecting your health information in accordance with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable healthcare privacy regulations. Your protected health information (PHI) is handled with the highest level of care and confidentiality.

When you use our application for health-related inquiries, we treat all health information with special care:

  • Health data is encrypted both in transit and at rest using industry-standard encryption protocols
  • Access to health information is strictly limited to authorized personnel
  • We maintain audit logs of all access to protected health information
  • Health information is never sold or used for marketing purposes
04

Data Security

We implement comprehensive security measures to protect your information:

Encryption

256-bit AES encryption for data at rest and TLS 1.3 for data in transit

Access Controls

Role-based access with multi-factor authentication requirements

Audit Logging

Comprehensive logging of all system access and data modifications

Regular Backups

Automated encrypted backups with secure disaster recovery procedures

05

Information Sharing

We do not sell, trade, or rent your personal or health information. We may share your information only in the following limited circumstances:

With Your Consent

When you explicitly authorize us to share information with specific healthcare providers or third parties

Service Providers

With trusted vendors who assist in operating our services, bound by strict confidentiality agreements

Legal Requirements

When required by law, court order, or to protect the rights, property, or safety of our users

Emergency Situations

When necessary to protect the vital interests of a user or another person in case of medical emergency

06

Your Rights

You have the following rights regarding your personal and health information:

1
Right to Access

Request a copy of the personal data we hold about you

2
Right to Correction

Request correction of inaccurate or incomplete data

3
Right to Deletion

Request deletion of your data, subject to legal retention requirements

4
Right to Portability

Receive your data in a structured, machine-readable format

5
Right to Restrict

Request limitation of how we process your data

6
Right to Object

Object to certain types of data processing

To exercise any of these rights, please contact us at privacy@nextgenerationmedicine.co. We will respond to your request within 30 days.

07

Data Retention

We retain your information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law:

  • Account Data: Retained for the duration of your account and up to 2 years after account closure
  • Health Records: Retained in accordance with applicable healthcare regulations (typically 6-10 years)
  • Usage Analytics: Retained in anonymized form for service improvement purposes
  • Security Logs: Retained for a minimum of 1 year for security and compliance purposes
08

Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If a parent or guardian becomes aware that their child has provided us with personal information without their consent, please contact us immediately at privacy@nextgenerationmedicine.co.

If we become aware that we have collected personal information from a child under 18 without verification of parental consent, we will take steps to remove that information from our servers promptly.

09

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes:

  • We will notify you via email and/or in-app notification at least 30 days before changes take effect
  • We will update the "Last Updated" date at the top of this policy
  • Continued use of our services after changes take effect constitutes acceptance of the updated policy
10

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Team:

Organization

Next Generation Medicine