Vitaport® Privacy Policy

Vitaport® is a product and brand operated by Aspen Medical Pty Ltd and its related entities. References to “Aspen Medical” in this Privacy Policy include Aspen Medical Pty Ltd, Aspen Technology Pty Ltd, and any entity involved in delivering Vitaport services. As such, personal information collected through Vitaport may be handled by one or more Aspen Medical entities in accordance with this Privacy Policy.

If you are a citizen or resident of the United States of America, please see our Privacy Notices for United States (U.S.)  and California residents more information.

Vitaport® is a product and brand operated by Aspen Medical Pty Ltd and its related entities. References to “Aspen Medical” in this Privacy Policy include Aspen Medical Pty Ltd, Aspen Technology Pty Ltd, and any entity involved in delivering Vitaport services. As such, personal information collected through Vitaport may be handled by one or more Aspen Medical entities in accordance with this Privacy Policy.

If you are a citizen or resident of the United States of America, please see our Privacy Notices for United States (U.S.)  and California residents more information.

1. Objective

Aspen Medical is committed to complying with the Privacy Act 1988 (the Act).  The Act is an Australian law which regulates the handling of personal information about individuals. The 13 Australian Privacy Principles (APP) are contained in Schedule 3 of the Act.  The APPs provide guidance on how personal information is to be managed by organisations such as Aspen Medical.

Aspen Medical is committed to complying with the Privacy Act 1988 (the Act).  The Act is an Australian law which regulates the handling of personal information about individuals. The 13 Australian Privacy Principles (APP) are contained in Schedule 3 of the Act.  The APPs provide guidance on how personal information is to be managed by organisations such as Aspen Medical.

2. Scope

This policy applies to the management of personal information collected by Aspen Medical. This policy does not apply to the storage, use or disclosure of employee records. Employee records may be held, used or disclosed by Aspen Medical in any way that is directly connected to the employment relationship under the section 7B (3) of the Act.

This policy applies to the management of personal information collected by Aspen Medical. This policy does not apply to the storage, use or disclosure of employee records. Employee records may be held, used or disclosed by Aspen Medical in any way that is directly connected to the employment relationship under the section 7B (3) of the Act.

3.  The Privacy Framework

The APPs are grouped into 5 parts that direct how personal information is to be regulated by Aspen Medical:

·       Part 1 – Consideration of personal information privacy (APP 1 and 2)

·       Part 2 – Collection of personal information (APP 3, 4 and 5)

·       Part 3 – Dealing with personal information (APP 6, 7, 8 and 9)

·       Part 4 – Integrity of personal information (APP 10 and 11)

·       Part 5 – Access to, and correction of, personal information (APP 12 and 13)

The APPs are grouped into 5 parts that direct how personal information is to be regulated by Aspen Medical:

·       Part 1 – Consideration of personal information privacy (APP 1 and 2)

·       Part 2 – Collection of personal information (APP 3, 4 and 5)

·       Part 3 – Dealing with personal information (APP 6, 7, 8 and 9)

·       Part 4 – Integrity of personal information (APP 10 and 11)

·       Part 5 – Access to, and correction of, personal information (APP 12 and 13)

4.        Definitions

“Employee” has the same meaning as under the Fair Work Act 2009.


“Employee record” has the same meaning as under the Act, and includes any record of personal information relating to the employment of an employee


“Health information” is a subset of personal information and means:

·       information or an opinion about:

·       the health or a disability (at any time) of an individual; or

·       an individual's expressed wishes about the future provision of health services to them; or

·       a health service provided, or to be provided, to an individual;

that is also personal information; or

·       other personal information collected to provide, or in providing, a health service; or

·       other personal information about an individual collected in connection with the donation, or intended donation, by the individual of his or her body parts, organs or body substances; or

·       genetic information about an individual in a form that is, or could be, predictive of the health of the individual or a genetic relative of the individual.


“Individual” means a person for whom Aspen Medical has collected or holds personal information and includes workplace participants and patients.


“Other workplace participants” means all contractors, subcontractors, and agents of Aspen Medical or any subsidiary company or organisations of Aspen Medical.


“Patient” means a person who has been provided with health services by Aspen Medical.


“Personal information” is any information or any opinions (including that stored in databases), whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion.


“Sensitive information” means:

·       Information or opinions about an individual’s:

·       racial or ethnic origin; or

·       political opinions; or

·       membership of a political association; or

·       religious beliefs or affiliations; or

·       philosophical beliefs; or

·       membership of a professional or trade association; or

·       membership of a trade union; or

·       sexual preferences or practices; or

·       criminal record;

that is also personal information; or

·       health information about an individual; or

·       genetic information about an individual that is not otherwise health information.


"Tech Customer" means an entity that has entered into an agreement with Aspen Medical for the use of a Tech Platform.


"Tech Platform" a technology product or service made available by Aspen Medical to its business customers.


"Tech Platform User" means a person authorized by a Tech Customer to use a Tech Platform made available by Aspen Medical to that Tech Customer.

“Employee” has the same meaning as under the Fair Work Act 2009.


“Employee record” has the same meaning as under the Act, and includes any record of personal information relating to the employment of an employee


“Health information” is a subset of personal information and means:

·       information or an opinion about:

·       the health or a disability (at any time) of an individual; or

·       an individual's expressed wishes about the future provision of health services to them; or

·       a health service provided, or to be provided, to an individual;

that is also personal information; or

·       other personal information collected to provide, or in providing, a health service; or

·       other personal information about an individual collected in connection with the donation, or intended donation, by the individual of his or her body parts, organs or body substances; or

·       genetic information about an individual in a form that is, or could be, predictive of the health of the individual or a genetic relative of the individual.


“Individual” means a person for whom Aspen Medical has collected or holds personal information and includes workplace participants and patients.


“Other workplace participants” means all contractors, subcontractors, and agents of Aspen Medical or any subsidiary company or organisations of Aspen Medical.


“Patient” means a person who has been provided with health services by Aspen Medical.


“Personal information” is any information or any opinions (including that stored in databases), whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion.


“Sensitive information” means:

·       Information or opinions about an individual’s:

·       racial or ethnic origin; or

·       political opinions; or

·       membership of a political association; or

·       religious beliefs or affiliations; or

·       philosophical beliefs; or

·       membership of a professional or trade association; or

·       membership of a trade union; or

·       sexual preferences or practices; or

·       criminal record;

that is also personal information; or

·       health information about an individual; or

·       genetic information about an individual that is not otherwise health information.


"Tech Customer" means an entity that has entered into an agreement with Aspen Medical for the use of a Tech Platform.


"Tech Platform" a technology product or service made available by Aspen Medical to its business customers.


"Tech Platform User" means a person authorized by a Tech Customer to use a Tech Platform made available by Aspen Medical to that Tech Customer.

5.  Kinds of personal information that Aspen Medical may collect and hold

5.1      Patients;

Aspen Medical collects and holds the following types of information about patients to enable Aspen Medical to provide health services:

·       health history;

·       family history;

·       ethnic background;

·       current and past lifestyle.


5.2   Job Applicants

Aspen Medical collects the following types of information from individuals who apply for employment with us:

·       employment history contained in curricula vitae;

·       history of any disciplinary or performance matters;

·       information relating to any investigations and findings of any registration authority or statutory authority relevant to the professional standing of the applicant;

·       qualifications;

·       information to allow for credentialing;

·       information contained in internet searches about the applicant that are relevant to the purposes of assessing for suitability of employment;

·       information from employers, other than the current employer, regarding suitability for employment;

·       insurance-related information;

·       personal and emergency contact details;

·       salary or wage information;

·       health information.


5.3   Other Workplace Participants

Aspen Medical collects and holds the following types of information about other workplace participants:

·       employment history contained in curricula vitae;

·       qualifications;

·       credentialing information of health practitioners;

·       information contained in internet searches about the applicant that are relevant for the purposes of assessing for suitability of engagement;

·       insurance-related information;

·       terms and conditions of engagement;

·       personal and emergency contact details;

·       performance or conduct records;

·       salary or wage information,

·       health information;

·       details of any training; discipline, resignation or termination records.


5.4   Tech Platform Users

To enable Aspen Medical to provide the Tech Platform to a Tech Customer, Aspen Medical may collect (either directly or from its Tech Customer) personal information relating to Tech Platform Users.


The personal information Aspen will collect regarding Tech Platform Users may include the Tech Platform User's name, contact details, medical history, medical conditions and information about certain work-related qualifications (e.g. whether or not the Tech Customer User holds a current driver's licence).


The Tech Platform may include or use Artificial Intelligence systems, including AI chatbots. Where a Tech Platform User interacts with an Artificial Intelligence system, Aspen Medical may collect personal information provided by a Tech Platform User as part of that interaction.


If Aspen Medical collects personal information about Tech Platform Users from a Tech Customer Aspen Medical will, where appropriate, request that the Tech Customer inform the Tech Platform User that Aspen Medical are holding such information, how Aspen Medical will use and disclose such information, and that the Tech Platform User may contact Aspen Medical to gain access to and correct and update the information.


If Aspen Medical cannot collect this information, it may be unable to provide a Tech Platform User (or the corresponding Tech Customer) with access to the Tech Platform.

5.1      Patients;

Aspen Medical collects and holds the following types of information about patients to enable Aspen Medical to provide health services:

·       health history;

·       family history;

·       ethnic background;

·       current and past lifestyle.


5.2   Job Applicants

Aspen Medical collects the following types of information from individuals who apply for employment with us:

·       employment history contained in curricula vitae;

·       history of any disciplinary or performance matters;

·       information relating to any investigations and findings of any registration authority or statutory authority relevant to the professional standing of the applicant;

·       qualifications;

·       information to allow for credentialing;

·       information contained in internet searches about the applicant that are relevant to the purposes of assessing for suitability of employment;

·       information from employers, other than the current employer, regarding suitability for employment;

·       insurance-related information;

·       personal and emergency contact details;

·       salary or wage information;

·       health information.


5.3   Other Workplace Participants

Aspen Medical collects and holds the following types of information about other workplace participants:

·       employment history contained in curricula vitae;

·       qualifications;

·       credentialing information of health practitioners;

·       information contained in internet searches about the applicant that are relevant for the purposes of assessing for suitability of engagement;

·       insurance-related information;

·       terms and conditions of engagement;

·       personal and emergency contact details;

·       performance or conduct records;

·       salary or wage information,

·       health information;

·       details of any training; discipline, resignation or termination records.


5.4   Tech Platform Users

To enable Aspen Medical to provide the Tech Platform to a Tech Customer, Aspen Medical may collect (either directly or from its Tech Customer) personal information relating to Tech Platform Users.


The personal information Aspen will collect regarding Tech Platform Users may include the Tech Platform User's name, contact details, medical history, medical conditions and information about certain work-related qualifications (e.g. whether or not the Tech Customer User holds a current driver's licence).


The Tech Platform may include or use Artificial Intelligence systems, including AI chatbots. Where a Tech Platform User interacts with an Artificial Intelligence system, Aspen Medical may collect personal information provided by a Tech Platform User as part of that interaction.


If Aspen Medical collects personal information about Tech Platform Users from a Tech Customer Aspen Medical will, where appropriate, request that the Tech Customer inform the Tech Platform User that Aspen Medical are holding such information, how Aspen Medical will use and disclose such information, and that the Tech Platform User may contact Aspen Medical to gain access to and correct and update the information.


If Aspen Medical cannot collect this information, it may be unable to provide a Tech Platform User (or the corresponding Tech Customer) with access to the Tech Platform.

6.   How Aspen Medical collects personal information

Aspen Medical collects personal information only by lawful and fair means.  Aspen Medical will only collect sensitive information with the consent of the individual involved, or where otherwise permitted under the APPs.

Aspen Medical will usually collect personal information directly from individuals. This may occur when individuals interact with Aspen Medical directly, including:

·       when an individual uses one of Aspen Medical's products or services;

·       when an individual makes an inquiry through the Aspen Medical website, or otherwise corresponds with or contacts Aspen Medical;

·       as part of any job application submitted to Aspen Medical; or

·       through any software applications provided by Aspen Medical.

Sometimes, Aspen Medical may collect information about individuals from a third party, but only where it is not reasonable or practical for Aspen Medical to collect this information directly from the individual (for example, when you apply for a job or position with us and we collect information from previous employers or recruitment consultants, or when we collect information on Tech Platform Users from Tech Customers). 

Aspen Medical collects personal information only by lawful and fair means.  Aspen Medical will only collect sensitive information with the consent of the individual involved, or where otherwise permitted under the APPs.

Aspen Medical will usually collect personal information directly from individuals. This may occur when individuals interact with Aspen Medical directly, including:

·       when an individual uses one of Aspen Medical's products or services;

·       when an individual makes an inquiry through the Aspen Medical website, or otherwise corresponds with or contacts Aspen Medical;

·       as part of any job application submitted to Aspen Medical; or

·       through any software applications provided by Aspen Medical.

Sometimes, Aspen Medical may collect information about individuals from a third party, but only where it is not reasonable or practical for Aspen Medical to collect this information directly from the individual (for example, when you apply for a job or position with us and we collect information from previous employers or recruitment consultants, or when we collect information on Tech Platform Users from Tech Customers). 

7.   The purposes for which Aspen Medical collects, holds, uses and discloses personal information

Aspen Medical collects information from individuals so that it can meet the service requirements of its clients.  We collect health information from patients so that we can provide the best possible care.  We collect information from job applicants and workplace participants so that we may determine suitability for engagement and manage the employment relationship.

If an individual does not wish to provide their personal information, this may limit Aspen Medical's ability to provide its products or services, or diminish the quality of those products or services.  Where Aspen Medical is providing services to a patient, an inability to collect relevant Health Information may compromise the quality of the healthcare provided.

 

Aspen Medical only uses and discloses personal information for the purpose for which the information was collected, or for other purposes which are permitted under the APPs.  APP 6 differentiates between the particular purpose (primary purpose) for which the information was collected and other purposes (secondary purposes).    Where Aspen Medical collects information for a primary purpose it will only use or disclose information for a secondary purpose if the individual has consented to the use or disclosure; or one of the following apply:


·       the individual would reasonably expect the Aspen Medical to use or disclose the information for the secondary purpose and the secondary purpose is:

·       if the information is sensitive information — directly related to the primary purpose; or

·       if the information is not sensitive information — related to the primary purpose; or

·       the use or disclosure of the information is required or authorised by or under an Australian law or a court/tribunal order; or

·       a 'permitted general situation' or 'permitted health situation' set out in the Act exists; or

·       Aspen Medical reasonably believes that the use or disclosure of the information is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body.

Generally, Aspen Medical holds, uses and discloses personal information to:

·       offer and provide its products and services;

·       manage and administer those products and services, including account keeping procedures;

·       communicate with individuals;

·       manage its employment relationships;

·       comply with its legal and regulatory obligations; and

·       otherwise manage its business, including operating the Tech Platform for Tech Customers and Tech Platform Users.


Aspen Medical may also use personal information for the purposes of quality assurance, accreditation and audit activities, risk and claims management, patient satisfaction surveys and staff training and education. Where possible, this personal information will be de-identified before it is used for these purposes.

Aspen Medical collects information from individuals so that it can meet the service requirements of its clients.  We collect health information from patients so that we can provide the best possible care.  We collect information from job applicants and workplace participants so that we may determine suitability for engagement and manage the employment relationship.

If an individual does not wish to provide their personal information, this may limit Aspen Medical's ability to provide its products or services, or diminish the quality of those products or services.  Where Aspen Medical is providing services to a patient, an inability to collect relevant Health Information may compromise the quality of the healthcare provided.

 

Aspen Medical only uses and discloses personal information for the purpose for which the information was collected, or for other purposes which are permitted under the APPs.  APP 6 differentiates between the particular purpose (primary purpose) for which the information was collected and other purposes (secondary purposes).    Where Aspen Medical collects information for a primary purpose it will only use or disclose information for a secondary purpose if the individual has consented to the use or disclosure; or one of the following apply:


·       the individual would reasonably expect the Aspen Medical to use or disclose the information for the secondary purpose and the secondary purpose is:

·       if the information is sensitive information — directly related to the primary purpose; or

·       if the information is not sensitive information — related to the primary purpose; or

·       the use or disclosure of the information is required or authorised by or under an Australian law or a court/tribunal order; or

·       a 'permitted general situation' or 'permitted health situation' set out in the Act exists; or

·       Aspen Medical reasonably believes that the use or disclosure of the information is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body.

Generally, Aspen Medical holds, uses and discloses personal information to:

·       offer and provide its products and services;

·       manage and administer those products and services, including account keeping procedures;

·       communicate with individuals;

·       manage its employment relationships;

·       comply with its legal and regulatory obligations; and

·       otherwise manage its business, including operating the Tech Platform for Tech Customers and Tech Platform Users.


Aspen Medical may also use personal information for the purposes of quality assurance, accreditation and audit activities, risk and claims management, patient satisfaction surveys and staff training and education. Where possible, this personal information will be de-identified before it is used for these purposes.

8.  How Aspen Medical holds personal information

Aspen Medical holds records in accordance with relevant State and Territory laws.  Aspen Medical holds personal information in a manner that ensures that the security and integrity of the information is maintained and that prevents unauthorised access or use.

Hard copy records are kept securely in locked facilities or locked storage units. Electronic copies are kept secure by limiting access on a need-to-know basis and by using password protected systems. Aspen Medical further protects personal information by restricting access to personal information to only those who need access to the personal information do their job.  Physical, electronic and managerial procedures have been employed to safeguard the security and integrity of your personal information.

For further information about data protection measures used by Aspen Medical, please refer to the Information Security policy available at https://www.aspenmedical.com/our-policies.

Aspen Medical holds records in accordance with relevant State and Territory laws.  Aspen Medical holds personal information in a manner that ensures that the security and integrity of the information is maintained and that prevents unauthorised access or use.

Hard copy records are kept securely in locked facilities or locked storage units. Electronic copies are kept secure by limiting access on a need-to-know basis and by using password protected systems. Aspen Medical further protects personal information by restricting access to personal information to only those who need access to the personal information do their job.  Physical, electronic and managerial procedures have been employed to safeguard the security and integrity of your personal information.

For further information about data protection measures used by Aspen Medical, please refer to the Information Security policy available at https://www.aspenmedical.com/our-policies.

9.   Direct marketing

Aspen Medical does not use or disclose health information or other sensitive information for direct marketing purposes unless the individual involved has provided their consent to this.

Where an individual has not unsubscribed or otherwise opted out, Aspen Medical may use their (non-sensitive) personal information for direct marketing:

·       where the individual has agreed to receive direct marketing from Aspen Medical; or

·       where the individual has engaged directly with Aspen Medical, and it believes that the individual would reasonably expect to receive direct marketing.

Aspen Medical may utilise the services of third parties to assist with undertaking its direct marketing activities.  It will not otherwise disclose personal information to third parties for marketing purposes without consent.

Individuals may opt-out of direct marketing messages from Aspen Medical at any time, by contacting the Privacy Officer using details below.  Where an individual has opted-out of direct marketing, Aspen Medical may still communicate with them from time to time for other purposes, including where it responds to any correspondence it receives from the individual, communicates with the individual about any services being provided them, or is legally required to provide notice of any matters.

Aspen Medical does not use or disclose health information or other sensitive information for direct marketing purposes unless the individual involved has provided their consent to this.

Where an individual has not unsubscribed or otherwise opted out, Aspen Medical may use their (non-sensitive) personal information for direct marketing:

·       where the individual has agreed to receive direct marketing from Aspen Medical; or

·       where the individual has engaged directly with Aspen Medical, and it believes that the individual would reasonably expect to receive direct marketing.

Aspen Medical may utilise the services of third parties to assist with undertaking its direct marketing activities.  It will not otherwise disclose personal information to third parties for marketing purposes without consent.

Individuals may opt-out of direct marketing messages from Aspen Medical at any time, by contacting the Privacy Officer using details below.  Where an individual has opted-out of direct marketing, Aspen Medical may still communicate with them from time to time for other purposes, including where it responds to any correspondence it receives from the individual, communicates with the individual about any services being provided them, or is legally required to provide notice of any matters.

10.  Cookies

When you use our website to browse our products and services and view the information that we make available, a number of cookies are used by us and by third parties to allow the website to function, to collect useful information about visitors, and to help to make your user experience better.

Some of the cookies we use are strictly necessary for our website to function.


10.1    Strictly necessary cookies

Strictly necessary cookies are essential to enable you to navigate around our website and use its core features. Without these cookies, services such as remembering your login details or ensuring what you see looks correct on the device you are using would not be possible. These cookies do not gather information about you that could be used for marketing and do not track your internet usage.


10.2    Preference cookies

Preference cookies enable the website to adapt to the user’s website template design, by gathering information such as the user's preferred language or region.


10.3    Statistical and performance cookies  

These cookies help us understand how you interact with our website by collecting and reporting information about your journey on our website. For example, they help us understand which pages you go to most often, how much time you spend on which pages, which links you choose to click and the journey you took during the website session.

When you use our website to browse our products and services and view the information that we make available, a number of cookies are used by us and by third parties to allow the website to function, to collect useful information about visitors, and to help to make your user experience better.

Some of the cookies we use are strictly necessary for our website to function.


10.1    Strictly necessary cookies

Strictly necessary cookies are essential to enable you to navigate around our website and use its core features. Without these cookies, services such as remembering your login details or ensuring what you see looks correct on the device you are using would not be possible. These cookies do not gather information about you that could be used for marketing and do not track your internet usage.


10.2    Preference cookies

Preference cookies enable the website to adapt to the user’s website template design, by gathering information such as the user's preferred language or region.


10.3    Statistical and performance cookies  

These cookies help us understand how you interact with our website by collecting and reporting information about your journey on our website. For example, they help us understand which pages you go to most often, how much time you spend on which pages, which links you choose to click and the journey you took during the website session.

11.  How an individual may access personal information held by Aspen Medical about themself and seek the correction of such information

Individuals have a right to access or correct personal information that Aspen Medical holds, subject to exemptions contained within the Privacy Act.

Aspen Medical will allow access to or make the requested changes unless there is a reason under the Privacy Act 1988 (Cth) or other relevant law to refuse such access or to refuse to make the requested changes. 

If Aspen Medical does not agree to change a record, in accordance with a request, we will permit an individual to make a statement of the requested changes and Aspen Medical will enclose this statement with the record.

Requests to obtain access to, or request changes to, records can be made by email to Aspen Medical's privacy officer at privacy@aspenmedical.com.

Aspen Medical will provide a response to requests to access or amend records  in a reasonable time including providing a reason for any denial of access to records

Aspen Medical may seek to recover reasonable costs associated with supplying any personal information that is held by Aspen Medical.

Individuals have a right to access or correct personal information that Aspen Medical holds, subject to exemptions contained within the Privacy Act.

Aspen Medical will allow access to or make the requested changes unless there is a reason under the Privacy Act 1988 (Cth) or other relevant law to refuse such access or to refuse to make the requested changes. 

If Aspen Medical does not agree to change a record, in accordance with a request, we will permit an individual to make a statement of the requested changes and Aspen Medical will enclose this statement with the record.

Requests to obtain access to, or request changes to, records can be made by email to Aspen Medical's privacy officer at privacy@aspenmedical.com.

Aspen Medical will provide a response to requests to access or amend records  in a reasonable time including providing a reason for any denial of access to records

Aspen Medical may seek to recover reasonable costs associated with supplying any personal information that is held by Aspen Medical.

12.  Disclosure of personal information to overseas recipients

Aspen Medical will not disclose an individual’s personal information to overseas recipients without obtaining the individual’s express consent, unless Tech Customers direct Aspen Medical to send Tech Platform User's information to a particular overseas recipient.  The countries in which those overseas recipients will be located will be the countries nominated by Tech Customers in accordance with their request.

If in future Aspen Medical proposes to disclose personal information overseas, it will do so in compliance with the requirements of the Privacy Act.  Aspen Medical will, where practicable, advise as to the countries in which any overseas recipients are likely to be located.

If you do not want us to disclose your information to overseas recipients, please let us know.     

Aspen Medical will not disclose an individual’s personal information to overseas recipients without obtaining the individual’s express consent, unless Tech Customers direct Aspen Medical to send Tech Platform User's information to a particular overseas recipient.  The countries in which those overseas recipients will be located will be the countries nominated by Tech Customers in accordance with their request.

If in future Aspen Medical proposes to disclose personal information overseas, it will do so in compliance with the requirements of the Privacy Act.  Aspen Medical will, where practicable, advise as to the countries in which any overseas recipients are likely to be located.

If you do not want us to disclose your information to overseas recipients, please let us know.     

13.  How an individual may complain about a breach of an APP and how Aspen Medical will deal with such a complaint

If an individual has any questions, concerns or complaints about this Privacy Policy, or how Aspen Medical handles personal information, please contact our Privacy Officer via email to privacy@aspenmedical.com.

Aspen Medical takes all complaints seriously, and will respond to any complaint within a reasonable period.

If an individual is dissatisfied with the handling of their complaint, they can contact the Office of the Australian Information Commissioner:


Office of the Australian Information Commissioner

GPO Box 52818

Sydney  NSW  2001

Telephone: 1300 363 992

Email: enquiries@oaic.gov.au

If an individual has any questions, concerns or complaints about this Privacy Policy, or how Aspen Medical handles personal information, please contact our Privacy Officer via email to privacy@aspenmedical.com.

Aspen Medical takes all complaints seriously, and will respond to any complaint within a reasonable period.

If an individual is dissatisfied with the handling of their complaint, they can contact the Office of the Australian Information Commissioner:


Office of the Australian Information Commissioner

GPO Box 52818

Sydney  NSW  2001

Telephone: 1300 363 992

Email: enquiries@oaic.gov.au

United States Multi-State Privacy Notice

This Notice provides information to U.S. residents whose privacy laws afford them specific rights regarding the collection, use, and sharing of their personal information. If you are a California resident, please see the California Privacy Notice  for information on your rights regarding the collection, use, and disclosure of your personal information.

This Notice provides information to U.S. residents whose privacy laws afford them specific rights regarding the collection, use, and sharing of their personal information. If you are a California resident, please see the California Privacy Notice  for information on your rights regarding the collection, use, and disclosure of your personal information.

  1. Our Commitment To Privacy

Your privacy is important to us. To better protect your privacy, we provide this notice explaining our online and offline information practices and the choices you can make about the way your information is collected and used (collectively, the “Policy”). To make this Policy easy to find, we make it available on our homepage and at every point where personal information might be requested.

Your privacy is important to us. To better protect your privacy, we provide this notice explaining our online and offline information practices and the choices you can make about the way your information is collected and used (collectively, the “Policy”). To make this Policy easy to find, we make it available on our homepage and at every point where personal information might be requested.

  1. Your Consent

Please read this Policy periodically. You should read this entire Policy before using our Website or submitting information, including personal information, to us in any form. Whenever you submit personal information to us, whether online or offline, you consent to the collection, use, disclosure, transfer and storage of that information in accordance with this Policy.

All personal information may be used for the purposes stated in this Policy. We may make full use of all information that is de-identified, aggregated, or otherwise not in personally identifiable form.

Please read this Policy periodically. You should read this entire Policy before using our Website or submitting information, including personal information, to us in any form. Whenever you submit personal information to us, whether online or offline, you consent to the collection, use, disclosure, transfer and storage of that information in accordance with this Policy.

All personal information may be used for the purposes stated in this Policy. We may make full use of all information that is de-identified, aggregated, or otherwise not in personally identifiable form.

  1. Information Collection And Use

We collect personal information from you in the following ways: 1) from you when you voluntarily submit information directly to us; 2) using automated technology, including when you visit our Website, interact with our electronic communications, or contact us by email; and 3) using third party sources, including our service providers and analytics providers. Automated technology collects information from your computer or mobile device and includes cookies, web beacons, local shared objects, or other similar technology. More information on this is provided in the “HOW WE USE COOKIES AND OTHER TECHNOLOGY” section below.

We collect personal information from you in the following ways: 1) from you when you voluntarily submit information directly to us; 2) using automated technology, including when you visit our Website, interact with our electronic communications, or contact us by email; and 3) using third party sources, including our service providers and analytics providers. Automated technology collects information from your computer or mobile device and includes cookies, web beacons, local shared objects, or other similar technology. More information on this is provided in the “HOW WE USE COOKIES AND OTHER TECHNOLOGY” section below.

We collect, use, and disclose your personal information as described below and in Annex 1.

Internet/Network Activity


We collect information such as your IP address, domain, browser type, device identifiers, operating system, website interactions, API usage, and product reviews or feedback. We use this information to monitor and improve the performance of our services, ensure security, and conduct internal analytics. For a complete list of what we collect, please see Annex 1.


Tech Platform Information


When you use a technology platform provided by Aspen Medical or one of our affiliates (such as Aspen Medical Technology and Vitaport®), we may collect information directly from you or from the business entity that provides you access to the platform. This information may include name, contact details, medical history or conditions, work qualifications (e.g., certifications or licenses), and other related information, including information submitted via interactions with AI tools. Where such information is collected through our customer organizations, we may request that they notify users accordingly. For a complete list of what we collect, please see Annex 1.


Business to Business Information


We may collect personal information in connection with your engagement of our professional services or use of our technology platforms, including but not limited to identifiers, contact information, qualifications, employment or credentialing history, and health or safety information where relevant to the service or platform. For a complete list of what we collect, please see Annex 1.

Internet/Network Activity


We collect information such as your IP address, domain, browser type, device identifiers, operating system, website interactions, API usage, and product reviews or feedback. We use this information to monitor and improve the performance of our services, ensure security, and conduct internal analytics. For a complete list of what we collect, please see Annex 1.


Tech Platform Information


When you use a technology platform provided by Aspen Medical or one of our affiliates (such as Aspen Medical Technology and Vitaport®), we may collect information directly from you or from the business entity that provides you access to the platform. This information may include name, contact details, medical history or conditions, work qualifications (e.g., certifications or licenses), and other related information, including information submitted via interactions with AI tools. Where such information is collected through our customer organizations, we may request that they notify users accordingly. For a complete list of what we collect, please see Annex 1.


Business to Business Information


We may collect personal information in connection with your engagement of our professional services or use of our technology platforms, including but not limited to identifiers, contact information, qualifications, employment or credentialing history, and health or safety information where relevant to the service or platform. For a complete list of what we collect, please see Annex 1.

  1. How We May Disclose Your Personal Information, Internet/Network Activity, and Service-Related Information

We may disclose this information in the following contexts:


·  Service Providers. We may disclose your information to contractors and vendors who help us operate, including communication platforms, hosting services, payment processors, HR platforms, and analytics providers. These service providers are required to keep the information confidential and use it only for the services provided.

·  Third Party Providers. We may share information with providers who support our internal analytics and operational functions.

·  Legal Obligations. We may disclose personal information to legal or governmental authorities if required to do so by law, to comply with legal processes, to protect our rights or property, or to respond to claims or enforcement actions.

·  Sale or Corporate Restructuring. In the event of a sale, merger, acquisition, restructuring, or other business transfer, we may disclose your information to parties involved in the transaction.

·   De-identified and Aggregated Information. We may make full use of data that has been de-identified, aggregated, or otherwise anonymized. We may also fully utilize any user-generated content submitted to us.

We may disclose this information in the following contexts:


·  Service Providers. We may disclose your information to contractors and vendors who help us operate, including communication platforms, hosting services, payment processors, HR platforms, and analytics providers. These service providers are required to keep the information confidential and use it only for the services provided.

·  Third Party Providers. We may share information with providers who support our internal analytics and operational functions.

·  Legal Obligations. We may disclose personal information to legal or governmental authorities if required to do so by law, to comply with legal processes, to protect our rights or property, or to respond to claims or enforcement actions.

·  Sale or Corporate Restructuring. In the event of a sale, merger, acquisition, restructuring, or other business transfer, we may disclose your information to parties involved in the transaction.

·   De-identified and Aggregated Information. We may make full use of data that has been de-identified, aggregated, or otherwise anonymized. We may also fully utilize any user-generated content submitted to us.

5.         How We Use “Cookies and Other Technology”

When you use our website to browse our products and services and view the information that we make available, a number of cookies are used by us and by third parties to allow the website to function, to collect useful information about visitors, and to help to make your user experience better.

Some of the cookies we use are strictly necessary for our website to function.


·  Strictly necessary cookies: Strictly necessary cookies are essential to enable you to navigate around our website and use its core features. Without these cookies, services such as remembering your login details or ensuring what you see looks correct on the device you are using would not be possible. These cookies do not gather information about you that could be used for marketing and do not track your internet usage.


·  Preference cookies: Preference cookies enable the website to adapt to the user’s website template design, by gathering information such as the user's preferred language or region.


·  Statistical and performance cookies: These cookies help us understand how you interact with our website by collecting and reporting information about your journey on our website. For example, they help us understand which pages you go to most often, how much time you spend on which pages, which links you choose to click and the journey you took during the website session.

 

Please Note:


·   Opt-outs are device and browser based.  You must opt out on each device and each browser where you want your choice to apply.

·   Opt-outs maybe stored via cookies.  If you clear cookies, your opt-out may no longer be valid and you must opt out again where you want your choices to apply.

·   We may still share your Personal Information with our service providers that help us perform functions that are necessary for our business such as vendors that host our Site, analytics processors, etc.  These entities are contractually obligated to keep this information confidential and not use it for any purpose other than for the services they provide to our business.

When you use our website to browse our products and services and view the information that we make available, a number of cookies are used by us and by third parties to allow the website to function, to collect useful information about visitors, and to help to make your user experience better.

Some of the cookies we use are strictly necessary for our website to function.


·  Strictly necessary cookies: Strictly necessary cookies are essential to enable you to navigate around our website and use its core features. Without these cookies, services such as remembering your login details or ensuring what you see looks correct on the device you are using would not be possible. These cookies do not gather information about you that could be used for marketing and do not track your internet usage.


·  Preference cookies: Preference cookies enable the website to adapt to the user’s website template design, by gathering information such as the user's preferred language or region.


·  Statistical and performance cookies: These cookies help us understand how you interact with our website by collecting and reporting information about your journey on our website. For example, they help us understand which pages you go to most often, how much time you spend on which pages, which links you choose to click and the journey you took during the website session.

 

Please Note:


·   Opt-outs are device and browser based.  You must opt out on each device and each browser where you want your choice to apply.

·   Opt-outs maybe stored via cookies.  If you clear cookies, your opt-out may no longer be valid and you must opt out again where you want your choices to apply.

·   We may still share your Personal Information with our service providers that help us perform functions that are necessary for our business such as vendors that host our Site, analytics processors, etc.  These entities are contractually obligated to keep this information confidential and not use it for any purpose other than for the services they provide to our business.

6.         Links and Third Parties

Our Website may include links to external websites operated by third parties. We are not responsible for their content or privacy practices. Your interactions with these sites are subject to their respective privacy policies.

Our Website may include links to external websites operated by third parties. We are not responsible for their content or privacy practices. Your interactions with these sites are subject to their respective privacy policies.

7.         Your Rights

RIGHT TO CONFIRM, ACCESS, AND DATA PORTABILITY

You have the right to confirm whether or not we are processing your personal data and to access such personal data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another controller without hindrance, where the processing is carried out by automated means.  We have collected the categories of Personal Information about residents as described in this Notice. To review these categories, click here.

 

RIGHT TO REQUEST DELETION OF PERSONAL DATA

You have the right to request the deletion of your personal data provided by or obtained about you (“Request to Delete”), subject to certain exceptions permitted by law.


RIGHT TO CORRECT (NOT APPLICABLE TO IOWA AND UTAH RESIDENTS)

You have the right to request that we rectify inaccurate information about you.


RIGHT TO OPT OUT OF THE SALE OF PERSONAL DATA AND TARGETED ADVERTISING

We do not and have not sold or used your information for targeted advertising in the preceding 12 months.


RIGHT TO OPT OUT OF PROFILING (NOT APPLICABLE TO UTAH RESIDENTS)

You have the right to opt out of the processing of your personal data for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects (“Request to Opt Out of Profiling”).  We do not process your personal data for profiling purposes.

 

HOW TO MAKE YOUR REQUESTS TO CONFIRM, ACCESS, DATA PORTABILITY, CORRECT AND DELETE

You can make a Rights Request in the following ways: 

·       You may make a request here: privacy@aspenmedical.com

·       Enter your request here https://aspenmedical.jotform.com/251281066147959

We will acknowledge your Request within 10 days and will attempt to respond substantively within 45-90 days.

You must provide sufficient information to allow us to verify that you are the person about whom the personal information was collected and must contain sufficient detail to allow us to properly understand, evaluate and respond to your request.  If we cannot verify your identity, we will not be able to respond to your request.

Once we receive your Request, we will begin the process to verify that you are the person that is the subject of the request (the “Verification Process”).  The Verification Process consists of matching identifying information provided by you with the information we have about you in our records.  You will be asked to provide us with two or three pieces of information that will help us to verify your identity.  We will retain correspondence, documents and information related to any Request to Know, Request to Delete, or Request to Opt-Out for 24 months as required by law.

RIGHT TO NON-DISCRIMINATION FOR EXERCISING CONSUMER PRIVACY RIGHTS

You have the right not to receive discriminatory treatment for exercising your privacy rights , including by exercising the rights specified herein.  As the Right to Non-Discrimination is effective across the board, there is no specific “request” that you need to make in order to exercise this right.


RIGHT TO APPEAL (NOT APPLICABLE TO UTAH RESIDENTS)

You have the right to appeal our decision to deny any of your privacy rights requests above.  Within 60 days of receipt of your appeal (45 days for Colorado residents), we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. 


If your appeal is denied and you remain unsatisfied with our response, you may contact your state’s Attorney General to submit a complaint or seek further assistance. For help locating your state’s Attorney General’s contact information, visit Consumer Resources - File a Complaint.” [make sure link is active and working before posting https://www.consumerresources.org/file-a-complaint/

Making an Appeal

You can make an appeal in the following ways:

·       Enter your appeal here https://aspenmedical.jotform.com/251281066147959

·       You may also make an appeal by email: privacy@aspenmedical.com


1.         Retention of Personal Information

We will retain your Personal Information for as long as it is necessary for the purposes set out in the Privacy Policy and to the extent necessary to comply with our legal obligations (for example, if we are required to retain your Personal Information to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Usage data may be retained longer if necessary for security, product improvement, or legal requirements.


2.         Contact Preferences and Unsubscribing

Aspen Medical may send you promotional communications if you have opted in or we believe you would reasonably expect such communication. You may unsubscribe at any time by following the instructions in the email (e.g., clicking the “unsubscribe” link). Please note that transactional emails (such as service updates or responses to inquiries) will still be sent.


3.         How We Protect Your Information

We use reasonable physical, administrative, and technical safeguards to protect your personal information. Access is limited to those who need it to perform their job functions. While we take steps to secure data, we cannot guarantee complete security. If you believe your information has been compromised, please contact us promptly.


4.         Authorized Agent

You may designate an authorized agent to make a request on your behalf. Authorized agents may make requests on behalf of consumers by emailing privacy@aspenmedical.com . We will require authorized agents to provide proof of the consumer’s consent to and designation of the authorized agent for purpose of making the request, and will require authorized agents to provide information necessary to verify the identity of the consumer who is the subject of the request.  We may also require that a consumer verify his or her own identity directly with us before we respond to an authorized agent’s request. 

 

5.         Contacting Us

For any questions or concerns about this Privacy Policy or how your information is handled, please contact us at: privacy@aspenmedical.com


6.         Revisions to This Privacy Policy

We reserve the right to modify the terms of this Policy at any time and in our sole discretion, by posting the revised Policy on this page. We recommend that you check this page for updates when you visit our Website to ensure you are aware of and understand our current Policy. Your continued use of our website following our posting of a change notice will constitute binding acceptance of those changes.

RIGHT TO CONFIRM, ACCESS, AND DATA PORTABILITY

You have the right to confirm whether or not we are processing your personal data and to access such personal data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another controller without hindrance, where the processing is carried out by automated means.  We have collected the categories of Personal Information about residents as described in this Notice. To review these categories, click here.

 

RIGHT TO REQUEST DELETION OF PERSONAL DATA

You have the right to request the deletion of your personal data provided by or obtained about you (“Request to Delete”), subject to certain exceptions permitted by law.


RIGHT TO CORRECT (NOT APPLICABLE TO IOWA AND UTAH RESIDENTS)

You have the right to request that we rectify inaccurate information about you.


RIGHT TO OPT OUT OF THE SALE OF PERSONAL DATA AND TARGETED ADVERTISING

We do not and have not sold or used your information for targeted advertising in the preceding 12 months.


RIGHT TO OPT OUT OF PROFILING (NOT APPLICABLE TO UTAH RESIDENTS)

You have the right to opt out of the processing of your personal data for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects (“Request to Opt Out of Profiling”).  We do not process your personal data for profiling purposes.

 

HOW TO MAKE YOUR REQUESTS TO CONFIRM, ACCESS, DATA PORTABILITY, CORRECT AND DELETE

You can make a Rights Request in the following ways: 

·       You may make a request here: privacy@aspenmedical.com

·       Enter your request here https://aspenmedical.jotform.com/251281066147959

We will acknowledge your Request within 10 days and will attempt to respond substantively within 45-90 days.

You must provide sufficient information to allow us to verify that you are the person about whom the personal information was collected and must contain sufficient detail to allow us to properly understand, evaluate and respond to your request.  If we cannot verify your identity, we will not be able to respond to your request.

Once we receive your Request, we will begin the process to verify that you are the person that is the subject of the request (the “Verification Process”).  The Verification Process consists of matching identifying information provided by you with the information we have about you in our records.  You will be asked to provide us with two or three pieces of information that will help us to verify your identity.  We will retain correspondence, documents and information related to any Request to Know, Request to Delete, or Request to Opt-Out for 24 months as required by law.

RIGHT TO NON-DISCRIMINATION FOR EXERCISING CONSUMER PRIVACY RIGHTS

You have the right not to receive discriminatory treatment for exercising your privacy rights , including by exercising the rights specified herein.  As the Right to Non-Discrimination is effective across the board, there is no specific “request” that you need to make in order to exercise this right.


RIGHT TO APPEAL (NOT APPLICABLE TO UTAH RESIDENTS)

You have the right to appeal our decision to deny any of your privacy rights requests above.  Within 60 days of receipt of your appeal (45 days for Colorado residents), we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. 


If your appeal is denied and you remain unsatisfied with our response, you may contact your state’s Attorney General to submit a complaint or seek further assistance. For help locating your state’s Attorney General’s contact information, visit Consumer Resources - File a Complaint.” [make sure link is active and working before posting https://www.consumerresources.org/file-a-complaint/

Making an Appeal

You can make an appeal in the following ways:

·       Enter your appeal here https://aspenmedical.jotform.com/251281066147959

·       You may also make an appeal by email: privacy@aspenmedical.com


1.         Retention of Personal Information

We will retain your Personal Information for as long as it is necessary for the purposes set out in the Privacy Policy and to the extent necessary to comply with our legal obligations (for example, if we are required to retain your Personal Information to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Usage data may be retained longer if necessary for security, product improvement, or legal requirements.


2.         Contact Preferences and Unsubscribing

Aspen Medical may send you promotional communications if you have opted in or we believe you would reasonably expect such communication. You may unsubscribe at any time by following the instructions in the email (e.g., clicking the “unsubscribe” link). Please note that transactional emails (such as service updates or responses to inquiries) will still be sent.


3.         How We Protect Your Information

We use reasonable physical, administrative, and technical safeguards to protect your personal information. Access is limited to those who need it to perform their job functions. While we take steps to secure data, we cannot guarantee complete security. If you believe your information has been compromised, please contact us promptly.


4.         Authorized Agent

You may designate an authorized agent to make a request on your behalf. Authorized agents may make requests on behalf of consumers by emailing privacy@aspenmedical.com . We will require authorized agents to provide proof of the consumer’s consent to and designation of the authorized agent for purpose of making the request, and will require authorized agents to provide information necessary to verify the identity of the consumer who is the subject of the request.  We may also require that a consumer verify his or her own identity directly with us before we respond to an authorized agent’s request. 

 

5.         Contacting Us

For any questions or concerns about this Privacy Policy or how your information is handled, please contact us at: privacy@aspenmedical.com


6.         Revisions to This Privacy Policy

We reserve the right to modify the terms of this Policy at any time and in our sole discretion, by posting the revised Policy on this page. We recommend that you check this page for updates when you visit our Website to ensure you are aware of and understand our current Policy. Your continued use of our website following our posting of a change notice will constitute binding acceptance of those changes.

California Consumers Only

Your California Privacy Rights

This Privacy Rights Act Notice (“Notice”) provides additional information to California residents whose Personal Information is collected by us pursuant to California law, including the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”). If you are not a California resident, this Notice does not apply to you. Please visit our United States Privacy Policy (“Policy”) for more information. Any capitalized terms undefined in this Notice have the same definition as the Policy.

This Privacy Rights Act Notice (“Notice”) provides additional information to California residents whose Personal Information is collected by us pursuant to California law, including the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”). If you are not a California resident, this Notice does not apply to you. Please visit our United States Privacy Policy (“Policy”) for more information. Any capitalized terms undefined in this Notice have the same definition as the Policy.

  1. Personal Information Collected and Disclosed

Information Collected
Within the past 12 months, we have collected the categories of personal information about California consumers as described in Annex 1 to this Notice. To review these categories click Annex 1.


Business-to-Business ("B2B") Information
If you are a contact person for any of our business partners, vendors, service providers, contractors, or other entities with which we have a business relationship or potential business relationship, you have the same rights as other consumers set forth in this Notice with respect to the information we collect from you in that role. We collect the contact information you provide to us, including name, phone number, address, email address and other contact and relationship information and communications consistent with your role in facilitating that business relationship. We use that information for internal purposes, including to contact you, send and receive information, and otherwise facilitate the business relationship. We do not disclose that information outside our business relationship without your consent. For more details see Annex 1.


Information Sold or Shared

We have not sold or shared your personal information in the preceding 12 months.

We have not disclosed your personal information for any business purpose in the preceding 12 months. 


CPRA RIGHTS AND REQUESTS

Under the CPRA, you are entitled to certain rights, and you can make requests with regard to those rights as follows:


Right to Know about the Categories of Personal Information Collected (“Right to Know”)

 

Right to Request Deletion of Personal Information (“Right to Delete”)

 

Right to Correct or Rectify Inaccurate Information about you (“Right to Correct”)

 

HOW TO MAKE YOUR REQUESTS TO KNOW, DELETE, OR CORRECT.

You have the right make requests for the aforementioned rights (Request to Know; Request to Delete; or a Request to Correct (a “Request”)).

To make a Request for any of the information set forth above, please submit a verifiable consumer request pursuant to the instructions below. The Request must provide sufficient information to allow us to verify that you are the person about whom the personal information was collected, sold, shared, or disclosed and must contain sufficient detail to allow us to properly understand, evaluate and respond to your request.  If we cannot verify your identity, we will not be able to respond to your request.  We will acknowledge your Request within 10 business days and will attempt to respond substantively within 45-90 days.

You may make a Request the following ways:


·       You may make a request here: privacy@aspenmedical.com.

·       Enter your request here https://aspenmedical.jotform.com/251281066147959

 

Once we receive your Request, we will begin the process to verify that you are the person that is the subject of the request (the “Verification Process”).  The Verification Process consists of matching identifying information provided by you with the information we have about you in our records. You will be asked to provide us with two or three pieces of information that will help us to verify your identification.

We will review all information provided by you to us, to determine whether we can respond to your Request  We will inform you of our decision to deny or grant your Request.

For any Requests to Know, you may make such Requests twice within a 12-month period. 

For Requests to Correct, you will need to provide evidence supporting the inaccuracy of the current information, and we reserve the right to delete the information instead of correcting if such deletion does not impact you or you consent to the deletion.

We will retain correspondence, documents and information related to any Request for 24 months as required by law.


ADDITIONAL CPRA RIGHTS

The following are additional rights afforded to you under the CPRA. 


Right to Know Sensitive Personal Information Collected

We do not collect or process sensitive personal information for the purpose of inferring characteristics or for any purposes other than those set forth in Regulations section 7027(m).


Right to Opt out of Sharing and Selling

We do not share or sell your personal information.

 

RIGHT TO NON-DISCRIMINATION FOR EXERCISING CONSUMER PRIVACY RIGHTS

You have the right not to receive discriminatory treatment for exercising your privacy rights conferred by the California Consumer Privacy Act, including by exercising the rights specified herein.


RIGHT TO ACCESS INFORMATION ABOUT AUTOMATED DECISION MAKING AND THE RIGHT TO OPT-OUT OF AUTOMATED DECISION MAKING

You can request access to information about automated decision making processes Aspen uses and you may request to opt out of automated decision making. We do not engage in automated processing. For more information, please contact us at privacy@aspenmedical.com

Information Collected
Within the past 12 months, we have collected the categories of personal information about California consumers as described in Annex 1 to this Notice. To review these categories click Annex 1.


Business-to-Business ("B2B") Information
If you are a contact person for any of our business partners, vendors, service providers, contractors, or other entities with which we have a business relationship or potential business relationship, you have the same rights as other consumers set forth in this Notice with respect to the information we collect from you in that role. We collect the contact information you provide to us, including name, phone number, address, email address and other contact and relationship information and communications consistent with your role in facilitating that business relationship. We use that information for internal purposes, including to contact you, send and receive information, and otherwise facilitate the business relationship. We do not disclose that information outside our business relationship without your consent. For more details see Annex 1.


Information Sold or Shared

We have not sold or shared your personal information in the preceding 12 months.

We have not disclosed your personal information for any business purpose in the preceding 12 months. 


CPRA RIGHTS AND REQUESTS

Under the CPRA, you are entitled to certain rights, and you can make requests with regard to those rights as follows:


Right to Know about the Categories of Personal Information Collected (“Right to Know”)

 

Right to Request Deletion of Personal Information (“Right to Delete”)

 

Right to Correct or Rectify Inaccurate Information about you (“Right to Correct”)

 

HOW TO MAKE YOUR REQUESTS TO KNOW, DELETE, OR CORRECT.

You have the right make requests for the aforementioned rights (Request to Know; Request to Delete; or a Request to Correct (a “Request”)).

To make a Request for any of the information set forth above, please submit a verifiable consumer request pursuant to the instructions below. The Request must provide sufficient information to allow us to verify that you are the person about whom the personal information was collected, sold, shared, or disclosed and must contain sufficient detail to allow us to properly understand, evaluate and respond to your request.  If we cannot verify your identity, we will not be able to respond to your request.  We will acknowledge your Request within 10 business days and will attempt to respond substantively within 45-90 days.

You may make a Request the following ways:


·       You may make a request here: privacy@aspenmedical.com.

·       Enter your request here https://aspenmedical.jotform.com/251281066147959

 

Once we receive your Request, we will begin the process to verify that you are the person that is the subject of the request (the “Verification Process”).  The Verification Process consists of matching identifying information provided by you with the information we have about you in our records. You will be asked to provide us with two or three pieces of information that will help us to verify your identification.

We will review all information provided by you to us, to determine whether we can respond to your Request  We will inform you of our decision to deny or grant your Request.

For any Requests to Know, you may make such Requests twice within a 12-month period. 

For Requests to Correct, you will need to provide evidence supporting the inaccuracy of the current information, and we reserve the right to delete the information instead of correcting if such deletion does not impact you or you consent to the deletion.

We will retain correspondence, documents and information related to any Request for 24 months as required by law.


ADDITIONAL CPRA RIGHTS

The following are additional rights afforded to you under the CPRA. 


Right to Know Sensitive Personal Information Collected

We do not collect or process sensitive personal information for the purpose of inferring characteristics or for any purposes other than those set forth in Regulations section 7027(m).


Right to Opt out of Sharing and Selling

We do not share or sell your personal information.

 

RIGHT TO NON-DISCRIMINATION FOR EXERCISING CONSUMER PRIVACY RIGHTS

You have the right not to receive discriminatory treatment for exercising your privacy rights conferred by the California Consumer Privacy Act, including by exercising the rights specified herein.


RIGHT TO ACCESS INFORMATION ABOUT AUTOMATED DECISION MAKING AND THE RIGHT TO OPT-OUT OF AUTOMATED DECISION MAKING

You can request access to information about automated decision making processes Aspen uses and you may request to opt out of automated decision making. We do not engage in automated processing. For more information, please contact us at privacy@aspenmedical.com

  1. Cookies

As explained in our Cookies section, you can opt out of cookies using your browser.

Please Note:


·  Opt-outs are device and browser based. You must opt out on each device and each browser where you want your choice to apply.

·   Opt-outs may be stored via cookies. If you clear cookies, your opt-out may no longer be valid and you must opt out again where you want your choices to apply.

·   We may still share your information with our service providers that help us perform functions that are necessary for our business such as vendors that host our website, credit card processors, analytics processors. These entities are contractually obligated to keep this information confidential and not use it for any purpose other than for the services they provide to our business.

As explained in our Cookies section, you can opt out of cookies using your browser.

Please Note:


·  Opt-outs are device and browser based. You must opt out on each device and each browser where you want your choice to apply.

·   Opt-outs may be stored via cookies. If you clear cookies, your opt-out may no longer be valid and you must opt out again where you want your choices to apply.

·   We may still share your information with our service providers that help us perform functions that are necessary for our business such as vendors that host our website, credit card processors, analytics processors. These entities are contractually obligated to keep this information confidential and not use it for any purpose other than for the services they provide to our business.

  1. Retention of Personal Information

We will retain your Personal Information for as long as it is necessary for the purposes set out in Annex 1 and to the extent necessary to comply with our legal obligations (for example, if we are required to retain your Personal Information to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

We will retain your Personal Information for as long as it is necessary for the purposes set out in Annex 1 and to the extent necessary to comply with our legal obligations (for example, if we are required to retain your Personal Information to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

  1. Intended Audience of Website; Coppa Compliance

Our Website is not intended for individuals under the age of 18. We do not knowingly collect information from minors. If you become aware that a minor has submitted personal information to us without consent, please contact us so we can take appropriate action.

Our Website is not intended for individuals under the age of 18. We do not knowingly collect information from minors. If you become aware that a minor has submitted personal information to us without consent, please contact us so we can take appropriate action.

  1. Authorized Agent Information

You may designate an authorized agent to make a request on your behalf under the California Consumer Privacy Act. Authorized agents can make requests under the California Consumer Privacy Act by emailing us at email address: privacy@aspenmedical.com .  We will require authorized agents to provide proof of the consumer’s identity and proof of designation as an the authorized agent. We may also require that a consumer verify his or her own identity directly with us before we respond to an authorized agent’s request. We reserve the right to deny requests in certain circumstances, such as where we have a reasonable belief that the request is fraudulent.

You may designate an authorized agent to make a request on your behalf under the California Consumer Privacy Act. Authorized agents can make requests under the California Consumer Privacy Act by emailing us at email address: privacy@aspenmedical.com .  We will require authorized agents to provide proof of the consumer’s identity and proof of designation as an the authorized agent. We may also require that a consumer verify his or her own identity directly with us before we respond to an authorized agent’s request. We reserve the right to deny requests in certain circumstances, such as where we have a reasonable belief that the request is fraudulent.

  1. Changes To This Privacy Policy

This Policy may be revised from time to time for any reason. If this Policy changes, the revised policy will include a new effective date, and we will notify you of such changes by posting the revised policy on this page. Be sure to check the Policy whenever you submit personal information to us.


Contact For More Information

For information and questions about the use of your personal information or this California Consumer Privacy Section or your rights under California law, you may contact us by sending an email to privacy@aspenmedical.com.

This Policy may be revised from time to time for any reason. If this Policy changes, the revised policy will include a new effective date, and we will notify you of such changes by posting the revised policy on this page. Be sure to check the Policy whenever you submit personal information to us.


Contact For More Information

For information and questions about the use of your personal information or this California Consumer Privacy Section or your rights under California law, you may contact us by sending an email to privacy@aspenmedical.com.

Annex 1 – Categories of Personal Information Collected, Used, and Shared

Annex 1 – Categories of Personal Information Collected, Used, and Shared

Lead with Vitaport®
The future of workplace wellbeing

Vitaport®: the future is wellbeing

Security Concerns? Please contact us at security@vitaport.au

2024 All Right Reserved by Vitaport®

Vitaport®: the future is wellbeing

Security Concerns? Please contact us at security@vitaport.au

2024 All Right Reserved by Vitaport®

Vitaport®: the future is wellbeing

Security Concerns? Please contact us at security@vitaport.au

2024 All Right Reserved by Vitaport®

Vitaport®: the future is wellbeing

Security Concerns? Please contact us at security@vitaport.au

2024 All Right Reserved by Vitaport®