Last Updated: December 31, 2019
mHealth Regulatory Coalition
1.1 This Privacy Policy
mHealth Regulatory Coalition (“MRC,” “mhealthregulatorycoalition.org,” “We,” or “Us”) takes your privacy very seriously. This Privacy Policy describes our collection and protection of the information you provide to us during visits to our website www.mhealthregulatorycoalition.org (the “Site”). By using the Site you agree to and consent to the collection and use of your information as described below.
If you do not want us to use your information as stated in this Privacy Policy, please do not use our Site.
We care about the confidentiality and integrity of the information that is shared with us, and will only process your Personal Data in accordance with this Privacy Policy and applicable laws and regulations.
2. The Personal Data MRC processes about you
When you use our Site MRC may collect the following information from you (collectively referred to as “Personal Data”):
Subscription Data | includes registration date, service areas, and industry focus. |
Contact Data | includes email address. |
Device Data | includes hardware model, unique device identifiers, operating system version, browser type, and device settings and other information related to how your device is interacting with our Site. |
IP Data | includes your approximate position based on your IP address. |
Identity Data | includes first name and last name. |
Marketing Data | includes your preferences in receiving marketing from us. |
Usage Data | includes event information when you visit our Site, such as errors, system activity, and date and times of your activity, and the features that you access. |
We also use cookies, web beacons, HTML local storage, and other similar technology to distinguish you from other visitors of our Site and remember your preferences. This helps MRC provide you with a good experience when you visit Our Site and allows Us to improve your experience while visiting our Site. For more information on cookies, please see Our Cookie Policy at Section 4.3.
3. How MRC collects your personal data
3.1 Information you give us
MRC process Personal Data provided by you when subscribing to receive event invitations and/or publications or otherwise corresponding or interacting with Us and our Site.
You have the right to withdraw your consent at any time by contacting us – see Section 12.4.
3.2 Information we automatically collect about you and your device
When you are visit our Site, we will automatically collect Device, IP, and Usage Data. Some Usage Data is collected by using cookies. Please see Our Cookie Policy for more information.
3.3 Information we receive from third party vendors
We receive Device and Usage Data about you from analytics providers such as Google Analytics.
4. How MRC uses your Personal Data
4.1 To administer the Site and Our relationship with you
We use your User and IP Data to administer the Site and our relationship with you.
Lawful basis | Consent Legitimate interest in running the business, provide and ensure the proper function and use of the Site |
4.2 To secure the quality and develop the Site
We process your User, Usage and Subscription Data to monitor and analyze how our visitors and Subscribers engage and interact with the Site so that we can secure the quality and develop the Site to better align them with your usage patterns and preferences.
Lawful basis | Consent Legitimate interest to analyze how our visitors and Subscribers use the Site and to develop and improve the Site |
4.3 Cookies
A “cookie” is a small data file sent from a website and stored on your device to identify your device in the future and allow for an enhanced personalized user experience. A “session cookie” disappears after you close your web browser, or may expire after a fixed period of time. A “persistent cookie” remains after you close your web browser and may be accessed every time you use our Site. We may use both session and persistent cookies. You should consult your web browser to modify your cookie settings. Please note that if you delete or choose not to accept cookies from us, you may not be able to use certain features of our Site. There may be other tracking technologies now and later devised and used by us in connection with the Site. Further, third parties may use tracking technologies with our Site. We do not control those tracking technologies, and we are not responsible for them. However, you consent to potentially encountering third party tracking technologies in connection with your use of the Site and accept that this Privacy Policy does not apply to the tracking technologies or practices of such third parties. In such cases, you must check the third party websites to confirm how your information is collected and used.
4.4 Marketing Communication
We use Subscription, Device, and Marketing Data of the visitors of Our Site to send you newsletters and other marketing communications. Some Marketing Data is collected by using cookies. These cookies include third party services that may collection information about your visits to our site for analytics, retargeting and conversion tracking purposes. Please see our Cookie Policy at Section 4.3 for further details.
Our Site does not support Do Not Track requests at this time. Do Not Track (DNT) is a privacy preference that you can set in your web browser to indicate that you do not want certain information about your webpage visits collected across websites when you have not interacted with that service on the page. For all the details, including how to turn on Do Not Track, visit donottrack.us.
5. How long MRC keeps your Personal Data
MRC retains your Personal Data for as long as necessary to achieve the purposes set out in this Privacy Policy. In some cases, we may be required to continue to process your Personal Data for a longer period of time to comply with legal obligations (e.g. accounting or audit obligations) or for the establishment, exercise or defense of legal claims.
6. Disclosures of your Personal Data
6.1 Recipients
MRC will never sell your Personal Data and we conduct extensive assessments before engaging any processor to ensure that they have appropriate technical and organizational measures in place that provide adequate protection of your Personal Data. Anyone who is processing Personal Data on MRC’s behalf is bound by contractual obligations to keep Personal Data confidential and secure, and to use it only for the purposes as instructed by us.
MRC may share your Personal Data:
- with Our service providers that we use to support and provide Our business, such as technical service or operation providers;
- with Our successors, if to an acquirer, successor, or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, or in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets, to the extent and in the way as prescribed by applicable law;
- with others with whom you ask Us to share your Personal Data; or
- if we believe, in good faith, is appropriate or necessary to:
- take precautions against liability;
- protect ourselves or others from fraudulent, abusive, or unlawful uses or activity;
- investigate and defend ourselves against any third-party claims or allegations;
- protect the security or integrity of the Site; or
- protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights, property, or safety of others.
Aggregate information is information that describes the habits, usage patterns and/or demographics of users as a group but does not reveal the identity of particular users. We may use aggregate information to understand the needs of individuals using the Site.
6.2 International transfers
We may transfer your personal data to countries outside of your country of residence, which may have different personal data protection laws than the country in which you initially provided the information. In doing so, we comply with applicable legal requirements pertaining to the transfer of personal data to other countries and will protect that information as described in this Privacy Policy.
Although you may our Site from a location outside of the United States, any personal data collected by us in connection with the Site may be transferred to, processed, and stored within the United States. By using the Site, you consent to the transfer of your personal data, including your contact information and location data, to countries outside of your country of residence, including to the United States.
7. How we protect your Personal Data
All information you provide to us is transferred using TLS encryption (HTTPS) and stored on secure servers. We use generally accepted industry standards, technologies, procedures and methods, such as firewalls, encrypted storage, pseudonymization, regular software updates, security scans, access control, audit logging and review of admin actions as well as external penetration tests to protect the integrity of your Personal Data and to prevent unauthorized access. We also have policies and other organizational measures in place, including recurrent employee training on data protection and strict procedures to deal with any suspected personal data breach.
8. Third party links
mhealthregulatorycoalition.org may provide links to websites of other organizations or companies that may offer materials and services as well as links to other sites. Please note that we do not accept any responsibility or liability for personal data that may be collected through these websites or services. We recommend that you read their privacy policies before you submit any personal data to them or use their services.
9. Your rights in relation to your Personal Data
9.1 Your rights
You have the right to:
- request access to and information about your Personal Data that is being processed by us,
- request correction of your personal data if it is inaccurate or incomplete, including to provide additional data if relevant information is missing,
- request erasure of your Personal Data,
- object to our processing of your Personal Data (i) if the processing is based on our legitimate interest, or (ii) for direct marketing purposes,
- request that we restrict the processing of all or some of your Personal Data in certain situations and to ask us not to send you any direct marketing, and
- request a copy of your Personal Data in a structured, commonly used and machine readable format and that we transfer your personal data to another controller.
MRC may deny your request, including but not limited to request to delete your information, if such information is necessary for Us or Our service providers to:
- Comply with a legal obligation;
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities;
- Debug products to identify and repair errors that impair existing intended functionality; or
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
9.2 How to exercise your rights
You may contact us in writing at any time to exercise your rights, preferably using the email address that is associated with your user account. We may need to request specific information from you to help us confirm your identity.
We do our best to respond to your request within a few days, and at least within one (1) month. If the request is complicated or if we have received a large number of requests, we may need to prolong our response time with one (1) additional month.
You can exercise your rights at no cost to you. However, we may charge you a reasonable fee if your request is clearly unfounded, repetitive or excessive.
10. Children’s Information
MRC does not knowingly collect identifiable information from anyone under the age of 18 through the Site. If you are under 18, please do not give Us any information that would allow Us to identify you. We encourage parents and legal guardians to monitor their children’s Internet usage and to help enforce our Privacy Policy by instructing their children to never provide identifying information through any website without their permission. Please contact Us if you discover an individual under 18 has submitted their information contrary to this Privacy Policy and we will ensure that information is properly removed.
11. California Residents
We permit residents of California to use our Site. Therefore, it is our intent to comply with the California Business and Professions Code § 22575-22579, the California Consumer Privacy Act of 2018 (“CCPA”) and California Civil Code § 1798.83, known as the “Shine the Light” law. If you are a California resident you may request certain information regarding our disclosure of Personal Information to any third parties for their direct marketing purposes. In summary, you must presume that we collect electronic information from all visitors. You may contact us either at Privacy Officer, mHealth Regulatory Coalition, 1227 25th Street NW, Suite 700, Washington, D.C. 20037, or email MRCprivacy@ebglaw.com with any questions or to exercise your rights as a California Resident.
Only you or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
For the purposes of CCPA, personal information does not include:
- Publicly available information from government records.
- De-identified or aggregated consumer information.
- Information excluded from the CCPA’s scope, such as:
- Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data.
- Financial Information covered by the Gramm-Leach-Bliley Act, and implementing regulations.
11.1 Response Timing and Format
We endeavor to respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option. Please provide the method of delivery in addition to the address with such request. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable.
11.2 Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or services.
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
12. Miscellaneous
12.1 Changes of Our Privacy Policy
We reserve the right to change this Privacy Policy, and when updated, the effective date of the new version will be at the top of this policy.
12.2 Applicable Law and Jurisdiction
The Site is operated in the United States. If you are located outside of the United States, please be aware that any information you provide to us will be transferred to the United States. By providing us with any information through the Site, you consent to this transfer and our use of such information in accordance with this Privacy Policy.
12.3 Notice of Electronic Disclosure of Protected Health Information
In representing some clients, we may receive or create documents or other communications containing protected health information (PHI) related to individuals served by our clients. MRC will only use and disclose this PHI as necessary to perform our services for those clients, and only as permitted or required by law.
12.4 Contact
If you have any questions, comments or requests regarding this Privacy Policy or our processing of your information, please contact:
Mail: Privacy Officer, mHealth Regulatory Coalition, 1227 25th Street NW, Suite 700, Washington, D.C. 20037; or
Email: MRCprivacy@ebglaw.com.