Privacy Notice
Last Updated: December 21, 2022
This Privacy Notice (“Notice”) explains how your personal information, sometimes referred to as personal data, is collected, used, and disclosed by Evidation Health, Inc. and its subsidiaries (collectively, “Evidation,” “Health Programs,” “we,” “us,” or “our”) in connection with your use of our websites such as https://my.evidation.com, mobile applications, and other online services (collectively, our “Services”). For the purposes of certain of our Services, Evidation may also be known as “Achievement” or “MyEvidation”. This Notice applies to only those websites, services, and applications included within the Services. This Notice does not apply to any third-party websites, services, or applications (including those of our partners or vendors), even if accessible through the Services.
Evidation may provide other offerings and services, which are not subject to this Notice. The Privacy Notice for our website at www.evidation.com, or any online services related to that website, is available at: https://evidation.com/privacy. Participation in research, studies, or other programs offered to you as part of your participation in the Evidation community, including sponsored programs, run by Evidation may be subject to specific informed consent and/or other disclosures for the relevant research or other program.
When you use the Services, you consent to our collection, use, retention, disclosure, and protection of information about you, as described in this Notice.
IF YOU DO NOT AGREE TO THIS PRIVACY NOTICE, PLEASE DO NOT USE THE SERVICES.
This Notice contains the following sections:
- Information We Collect About You
- How We Use Your Information
- How We Share Your Information
- How We Protect Your Information
- Retention of Your Information
- Your Choices
- Links to Other Sites
- Children’s Privacy
- International Transfer
- Additional Information for Participants in Health Programs
- Supplemental Privacy Notice for California, Colorado, Virginia, Utah, & Connecticut
- Nevada Privacy Notice
- Contact Us
- Changes to this Notice
General Privacy Statement
Information We Collect About You
We may collect and store information about you in various ways. For example, we may collect information that you provide to us, information that we collect via social networking sites or Third-Party Applications (as described below), information that we automatically collect through your use of the Services, and information from publicly available sources or non-affiliated third parties. If we intend to make material changes to the information we collect, or how we use and handle that information, we will provide you with additional pre-collection notice, which may include references to other privacy policies, notices, disclosures, or statements. Otherwise, this Notice serves as our notice at collection.
Information You Provide to Us
Information about yourself. When you use the Services, you may be invited to provide your information directly to us, which may include personal information. We may collect the following illustrative (but not exhaustive) types of information from you when you use the Services:
- Registration information and account set-up, such as your email and password, and including any additional information necessary for multi-factor authentication or other similar technology to secure your Evidation account (though neither your password nor the information used for such security features is visible to anyone at Evidation);
- Account or profile information that you submit, such as name, gender, date of birth, address, and certain health information, like height, weight, etc.;
- Survey responses and information you submit regarding your eligibility to participate in a study; including, but not limited to: information about your demographics, health (such as conditions, diagnoses, or other similar information, general wellness, etc.), household, employment, education, salary, and health goals;
- Documents or other records that you choose to share with us; including, metadata associated with such documents (for example, if you share a photo, depending on your device’s settings, location data may be associated with the photo);
- Information from Third-Party Applications that you may connect with your Evidation account and subject to the permissions you may set on those Third-Party Applications, such as activity data (like your steps, movement, sleep, etc.);
- The communications or requests you submit to us through the Services, including any documents or attachments you may provide and any information contained therein;
- Information needed to provide you rewards, such as your PayPal username or address; and
- Any other information as may be necessary to operate and secure our Services, and provide them to you.
Information about others. In the process of using the Services, you may provide us with information about others (such as a family member or dependent, or contact information for referrals). If you choose to share information about others with us, we will use the information you provide about the other person only to facilitate the indicated action or service.
Other information collected with your express consent. In addition to the information collected pursuant to this Notice, we may collect information about you if we have your express consent to do so or at your direction. For example, if you opt in to participate in a study, research, or program (including any Health Programs, as discussed in additional detail below), we will collect information for that research or program. This would likely include information you submit directly to us, information that you authorize us to pull from your Evidation account, or information we obtain from third parties at your consent or direction. To participate in a study, program, or research, you must agree to the terms of any associated informed consent, patient authorization, or an equivalent project-specific disclosure. Please review all informed consent or other associated documents carefully as they will outline the specific information to be collected and how it will be used and/or shared for a given study, project, or program, and any related rights you may have (such as to unenroll or revoke authorization for collecting your information).
Information from Third-Party Applications and Services
If you opt in to connect the Services, such as your Evidation account, with any other applications, devices, services, or third-party accounts that you maintain (collectively “Third-Party Applications”), we may collect certain information as permitted by your privacy settings in the Third-Party Application; including, but not limited to any health, activity, and wellness data, geolocation, or contacts, as well as any associated metadata.
Additionally, if you choose to register for the Services via a Third-Party Application or service with which you have an account, such as Facebook or Google, we may collect certain information from your third-party account, such as name, email address, profile picture, birthday, list of friends, people you follow, likes, work and education history, current city or other third-party account information that your privacy settings in your third-party account permit us to access. Third-party services, such as Facebook and other social networking services and other Third-Party Applications, have their own policies concerning the collection, use, sharing, and protection of your information. Evidation does not have any control over the way any third-party service or Third-Party Application uses or discloses the information they collect about you.
Automatically Collected Information
When you utilize our Services, certain information is automatically collected. For example, we and our third-party service providers may automatically collect your Internet Protocol (IP) address (and associated city and state, province, or country for the IP address), computer operating system, browser type, other system settings, as well as the language your system uses and the country and time zone where your device is located, device identifiers, the website you visited before our Services, the number of clicks, pages viewed and the order of those pages, the amount of time spent on particular pages, the date and time you used the Services and upload or post content, error logs, and other similar information. Even if you do not register with our Services, or submit information directly to us, our Services may nevertheless collect this information automatically. The below sections will provide you additional information about automatically collected information.
Location Information. When you use the Services, we and our service providers may automatically collect general location information (for example, IP address, city/state and or zip code associated with an IP address) from your computer or mobile device. If you access the Services through a mobile device, we may also ask your permission to collect specific geolocation information. Such information may also be discerned from certain metadata or other permissioned data from Third-Party Applications. If you do not wish to have specific geolocation information collected and used by us and our service providers, you may disable the location sharing features on your device. For more information regarding location services, please contact your device manufacturer or mobile carrier. Turning off location sharing may impact certain features of the Services.
Cookies & Similar Technologies. We and our third-party service providers may also collect information about you, your usage of the Services, and your devices through cookies, web beacons, pixels, and similar technologies. For convenience, we will use the term “cookie” to apply to all of these sorts of technologies.
- More about “cookies”. A ”cookie” is a small data file placed on your device to identify it in the future. “Cookies” can also help us better understand your behavior as a user of our Services, personalize your preferences, perform research and analytics, deliver tailored advertising to you, and improve the products and services we provide, including the Services and your Evidation account. A ”session cookie” disappears after you close your web browser, or may expire after a fixed period of time. A ”persistent cookie” remains after you close your web browser and may be accessed every time you use our Services, like if you have settings in place to remember your login credentials or other preferences you may have.
We or our third-party service providers may use certain of these technologies to understand how you interact with our applications or use the Services, what offers you engage with, and other indicators of your engagement with the Services. In some cases, we may also use these technologies in emails to end users like yourself to help us do things like track email response rates, whether our emails are forwarded, and when our emails are viewed. We and our third-party service providers may use both session and persistent cookies on our Services.
We may utilize the services of third parties in conjunction with this automatically collected information. These third parties may collect information about you over time such as about your use of our Services, as well as your online activities across other websites or online services.
You should consult your web browser to modify your cookie settings. Please note that if you delete or choose not to accept cookies from us, you may not be able to use certain features of our Services. In addition to cookies, we may also use technologies such as local storage objects to collect information (for example, HTML5). Various browsers may offer their own tools for removing these sorts of technologies. Please consult your browser settings.
Online Analytics. We may use third-party analytics services for our websites, such as those provided by Google Analytics, as well as for mobile application analytics. These service providers use cookies and other technologies described in this Notice to help us analyze how users, like yourself, use our Services. The information collected by these technologies will be disclosed to or collected directly by these service providers. To prevent Google Analytics from using your information for analytics, you may install the Google Analytics Opt-Out Browser Add-on by clicking here.
We neither have access to, nor does this Notice govern, the use of cookies or other tracking technologies that may be placed on your computer, mobile phone, or other device you use to access the Services by non-affiliated, third-party ad technology, ad servers, ad networks or any other non-affiliated third parties. Those parties that use these technologies may offer you a way to opt out of ad targeting in addition to the methods described below.
Advertising. You may receive tailored advertising on your computer through a web browser. If you are interested in more information about tailored browser advertising and how you can generally control cookies that deliver tailored advertising from being put on your computer, you may visit the Network Advertising Initiative (NAI) NAI Opt-Out link, or the Digital Advertising Alliance’ (DAA) DAA Opt-Out link, to opt out of receiving tailored advertising from companies that participate in those programs. To opt out of Google Analytics for display advertising or customize Google display network ads, you can visit the Google Ads Settings page.
Each operating system, iOS for Apple phones, Android for Android devices, and Windows for Microsoft devices, provides its own instructions on how to prevent the delivery of tailored in-application advertisements. We do not control how the applicable platform operator allows you to control receiving personalized in-application advertisements. You should contact the platform provider for further details on opting out of tailored in-application advertisements. You may review the support materials and/or the device settings for the respective operating systems to opt out of tailored in-application advertisements.
Information from Other Sources
We may, at times, and typically at your direction or consent, seek to obtain information about you from other sources, including affiliated and non-affiliated third parties. We may receive or affirmatively gather information about you from such sources. The extent to which we may obtain information from such sources is governed by the terms of your relationship with that source, including any sharing settings or other permissions that you may have in place.
How We Use Your Information
We, and our service providers, use the information collected to provide our Services to you or as otherwise described in this Notice. For example, we may use your information to:
- Operate, manage, maintain, and improve our business, and in particular the Services, including development of new products, features and functionalities, and any required submissions to regulatory authorities or agencies;
- Provide, develop, improve, repair, and maintain our products and services, including the Services;
- Process and deliver rewards;
- Contact you, or otherwise provide you with information about:
- ~your account;
- ~referrals;
- ~current and future programs and initiatives offered via the Services;
- ~studies, research, or programs in which you are currently participating; or
- ~participation in studies, programs or other opportunities for which you may be eligible, based upon information previously collected or from which we may make inferences;
- Respond to your feedback, comments, or questions, or to otherwise send you information about our Services;
- Ask you to complete surveys, read articles, or engage in other activities as part of the Services or other programs and monitor your completion of and engagement in those activities;
- Combine the information collected, including from Third-Party Applications and services, with other information about you or the Evidation community;
- Perform analysis and/or research, including for publication (in a manner that does not identify you personally) pursuant to Institutional Review Board approval, waiver, or exemption, as necessary;
- When we have your consent, such as pursuant to your participation in a study, research, or other program, such as a Health Program;
- Analyze how you use and interact with our Services, as well as how our Services are used across the Evidation community and our products more generally;
- Protect our Services and the information collected against fraudulent, illegal, or otherwise unauthorized activity, including any investigation into and remediation of such activity;
- De-identify, tokenize, or aggregate your information (or otherwise render the information so you are not reasonably identifiable), or to create or derive datasets, as part of the Services and for other purposes consistent with why the information was collected and Evidation’s mission;
- Identify and correct technical errors in our products and services, including the Services;
- Personalize, advertise, and market our products and services to you, including the Services;
- Conduct or perform research, analytics, and data analysis;
- Conduct and implement risk and security controls and monitoring, and secure the Services;
- Maintain our facilities and infrastructure;
- Detect and prevent fraud;
- Comply with law, legal process, and internal policies;
- Exercise and defend legal claims;
- Otherwise accomplish our business purposes and objectives; and
- For any other purpose described in this Notice or the Terms of Use.
We may combine information that we collect from you through the Services with information that we obtain from affiliated and non-affiliated third parties, and information derived from any other products or services we provide.
We may aggregate, de-identify, and/or tokenize information collected through the Services and use such data for any purpose; including, without limitation, for our own research and commercial purposes, or to prepare analyses or reports for our blog, public presentations, publication, partners or others regarding the use of our Services and/or data about our user population and subsets thereof. Aggregated, tokenized, and/or de-identified data may also be shared with our research, awareness, and other partners and customers through dashboards and metrics, so that we can run the specific project in which you may have enrolled and also to operate, improve, and provide our Services.
- More About Aggregated and De-Identified Information. If information is de-identified or aggregated, it is not considered “personal information” or “personal data” because it is not associated directly with you or any other specific person. Aggregate information is information about a group of people where names and contact information are stripped and the remaining data is combined with that of other individuals. Once combined, the data can be analyzed or evaluated as a whole, such that no specific individual (like yourself) may be reasonably identified. Similarly, when data is “de-identified” it should not be able to be reasonably associated with a specific individual, such as yourself. There are different ways to define what it means when information has been de-identified. Generally, it means the information has been stripped of any identifying data (like your name, contact information, and other identifying characteristics) such that an individual cannot reasonably be identified.
- More About Tokenized Data. Tokenization of data is a way to render information less identifiable to a specific person. More precisely, it’s a process where any personally identifying or sensitive information in a set of data - such as contact information or other identifiers - has been removed and replaced with a token or unique code. That token or code still retains all of the information necessary to conduct research or analysis (for example), but maintains the confidentiality of the individual because if exposed the token would not be able to be directly associated with or identify you (or any other individual). Tokenized data is also sometimes referred to as “coded” data. Depending on the applicable law, tokenized (or coded) data may meet the standard of “de-identified” data, but that is not always the case.
Communication via Text or SMS
By providing your mobile phone number as part of your enrollment in a study, research, or other program, you expressly consent to receive text or other SMS messages at the number provided for the administration of the study. Standard message and data rates may apply.
Use of Information Collected from Across Devices and Applications
Sometimes, we (or our service providers) may use the information we collect – for instance, usernames, IP addresses, geolocation, and unique mobile device identifiers – to locate or try to locate the same unique users across multiple browsers or devices (such as smartphones, tablets, or computers), or work with providers that do this, in order to better tailor content and features (like language) and provide you with a seamless experience across devices. Sometimes this information is also helpful to detect and prevent fraud. As stated above, if you wish to opt out of cross-device tracking for purposes of interest-based or tailored advertising, you may do so through your device settings, or by using the Network Advertising Initiative (NAI), Digital Advertising Alliance’ (DAA) and your online choices NAI Opt-Out link DAA Opt-Out link.
Retention of Your Information
The length of time for which we retain information depends on the purposes for which we collect and use it and/or as required to comply with our legal obligations, resolve disputes, enforce our agreements or rights, and fulfill other legitimate and lawful business purposes. In general, we will retain the information in your Evidation account and other information you may provide to us for so long as you have your account so that we can provide the Services and to meet any legal or regulatory requirements. Because there are numerous types of Personal Information we may collect in each category and reasons for the collection and processing of that information, actual retention periods may vary.
We may also retain specific limited information related to your account and any data deletion or other access request you may submit as necessary to document our fulfillment of your requests. In other words, if you ask us to delete your Personal Information, we may retain certain information so that we can document we completed your request and defend against any complaint related to our response to your request. Information retained for these purposes would likely include, but not limited to, your email address, IP address (if collected), account request or device identifier, communications related to inquiries, questions, or complaints, and legal agreements. We will retain this information for a limited period of time as required by policy, law, contractual obligations, and/or as necessary for the establishment, exercise or defense of legal claims and for audit and compliance purposes, and will not use that information for any other purposes.
In some cases, we may need to retain your personal information to meet the specific legal, regulatory, or contractual requirements that apply to certain of our studies, research, or programs. If you participate in a study, research, or program, including a Health Program, you should refer to the informed consent document or other associated documents and disclosures for that program or research to learn more about the applicable retention period.
Your Choices
Manage Your Account Information. You may modify your account information by accessing the Settings area of your Evidation account.
Email & Text Messages. You may opt out of receiving certain communications from us. To opt out of any communications, follow the instructions in that communication (like using the “unsubscribe” link in the footer of an email) or visit the Settings tab of your account. You may opt out of receiving text messages from us by replying to a text from us with the words “STOP”, “QUIT”, or “UNSUBSCRIBE.” You will not be able to opt out of transactional or relationship email messages, including those related to the management of your account or customer support.
Cookies and Other Automated Technologies. For information about opt-out options relating to data collected using cookies and other automated technologies (e.g., for analytics), please review the hyperlinks in the “Automatically Collected Information” section of this Notice, above.
In certain states, you may have additional choices and privacy rights. Please review the “Supplemental Notice for California, Colorado, Virginia, Utah, & Connecticut” (referred to as the “Supplemental Notice”), below, for more information.
How We Protect Your Information
We use technical, physical, and administrative safeguards to protect the confidentiality, integrity, and availability of your information. In other words, we use different types of controls and procedures to protect your personal information from misuse and unauthorized access or disclosure. We employ a range of measures that are commensurate with the dynamic cyber-threat landscape to secure your information, but we also recognize that electronic communications, and the processing and storage of data, can be inherently insecure and may contain unknown weaknesses. Consequently, while we cannot guarantee absolute security in such a dynamic threat landscape, we are strongly committed to continuously keeping your data as secure as possible. Please keep this in mind when disclosing any information to us via the Internet or other electronic means, including through the Services.
How You Can Help Protect Your Information. Please also recognize that protecting your personal information is also your responsibility. Be mindful of keeping your password and other authentication or verification information safe from third parties. Immediately notify Evidation of any unauthorized use of your login credentials or email or if you observe any suspicious activity associated with your Evidation account or the Services. Your password is not visible to anyone at Evidation, and we encourage you not to share your password with Evidation or any third parties. Evidation cannot secure personal information that you release on your own or that you request us to release or disclose.
Reporting Potential Security Vulnerabilities. If you want to report a potential cyber security vulnerability, please contact us at security@evidation.com.
Links to Other Sites
Our Services may contain links to other websites and services, including certain Third-Party Applications. Any information that you provide on or to a third-party website or service is provided directly to the owner of the website or service and is subject to that party's privacy policy. Our Notice does not apply to such websites or services and we are not responsible for the content nor privacy or security practices and policies of those websites or services. To protect your information, we recommend that you carefully review the privacy policies of other websites and services that you access, even if you do so via the Services.
Children’s Privacy
Our Services are not intended for children under the age of 18. If we become aware that we have collected “personal information” (as defined by the United States Children’s Online Privacy Protection Act) from children under the age of 13 without valid parental consent, we will take reasonable steps to delete that information as soon as possible and remove the underage users’ access to our application(s). We will also not sell or otherwise knowingly process the information.
Law Enforcement
We will not voluntarily share your personal information with law enforcement. More specifically, while we may be required in some cases to disclose certain information we possess about our members and users, we will not release your individually-identifiable personal information to law enforcement, regulators, governmental authorities, or other parties for legal reasons without your consent, unless legally required to do so. If we receive a request compelling our disclosure of your personal information, we will closely scrutinize that request and will only comply subject to court orders, subpoenas, search warrants or other requests that we determine are legally valid, and then only after exercising any appropriate legal processes to limit the scope and applicability of the request.
In certain circumstances, we may be obligated to provide certain identifiable information to regulators for your health, welfare, or safety. For example, if you are participating in a study or other sponsored program and suffer an adverse event or health incident, or as required as part of public health reporting. In those instances, we may disclose your personal information as described in the informed consent document or other disclosures that apply to that research or program.
International Transfer
Your information may be transferred to, and maintained on, computers or servers located outside of your state, province, country, or other governmental jurisdiction where the privacy laws may not be as protective as those in your jurisdiction. Our Services are intended for use only in the United States. If you are located outside the United States and choose to provide your information to us, we may transfer your information to the United States and process it there (or any other country in which we operate). Your submission of information using the Services represents your agreement to such transfer.
Additional Information for Participants in Health Programs
As part of the Services, and as an optional part of your use of the Evidation application and engagement in the Evidation community, we may also offer certain types of programs and initiatives in which you may choose to participate. For convenience, we will generally refer to these opportunities as Health Programs. In Health Programs, we focus on specific conditions, diseases, and illnesses, in many cases those that are chronic or communicable, or may present acute public health interest. The intent of these programs is both to gather important information that can contribute to research into these diseases and conditions, but also to help empower you to improve your health as well as the health of those in the broader Evidation community. Often these Health Programs involve third-party partner(s) or sponsor(s). If you choose to participate in one of our Health Programs, in addition to the information collection, use, sharing, and other privacy practices described in the General Privacy Statement (as apply to the the Services, such as the Evidation application and community), and any specific privacy rights that may apply to you as described in the Supplemental Notice below, the following will also apply:
Additional Personal Information We May Collect as Part of a Health Program
If you choose to participate in a Health Program, in addition to the personal information we may collect and process as part of the Services, you may be asked to provide us with the following illustrative (but not exhaustive) types of information:
- Health and Treatment Information:
- ~Diagnosis information specific to the specific condition(s), disease(s), or illness(es) of the relevant Health Program;
- ~Information related to prescription medications or other treatments that you are taking or may have been prescribed (including how frequently and regularly you take that medication, awareness of and access to alternative medications or other treatments, and other similar information);
- ~Appointments you have with various medical providers (including general information about type(s) of providers, frequency, etc.);
- ~Clinical events that you experience (for example, if you have to go to the emergency room or an urgent care clinic, have recurring or ad hoc provider visits, etc.); and
- ~Vaccination status and information related to that status (including why you received or chose to forego vaccination);
- Wellness and Wellbeing Information:
- ~Information you provide us related to your mood, symptoms, activities;
- ~Your knowledge and understanding of condition(s), disease(s), or illness(es), including any preventative measures and/or treatments, and other questions or topic areas that may help provide insight into your experience regarding your condition(s), disease(s), or illness(es); and
- ~Information about your activity (like your steps, sleep, etc.), as may be collected from your wearable device and applications (if connected) or self reported;
- Medical Record and Claims Information:
- ~With your specific authorization, your medical records (in which case we may ask for you to connect your Evidation account with your electronic medical record application or account); or
- ~With your specific authorization, information from your medical record or claims history that may be provided to us by a third party;
- Biometric Information: such as your height, weight, blood pressure, heart rate, pulse, and other similar information;
- Profile Information: such as demographic information, education information, professional, or economic information, etc. from your Evidation account profile, which we may want to combine with any personal information or other data we have collected specific to the Health Program; and
- Other similar information, as may be requested by us that is specific to the relevant Health Program.
Additional Ways We May Use Your Personal Information as Part of a Health Program
If you choose to participate in a Health Program, in addition to ways we may use your personal information as described above, we may use your information in the following ways:
- Perform research, including for publication or submission to regulatory authorities or agencies (provided such publication or submission does not identify you personally) and potentially pursuant to Institutional Review Board approval, waiver, or exemption, as necessary;
- Send you reminders and other outreach or encouragement to help you to manage your condition(s), disease(s), or illness(es) or events that are occurring to you, provide you with information, or otherwise gather additional relevant information;
- Respond to your feedback, comments, or questions, or to otherwise send you information about the Health Program;
- Review our communications with you and your responses so we can find the most effective way to communicate with you and others about health-related topics and in particular topics relevant to the specific Health Program;
- Review your activities and responses to see if they provide us with insight on the types of programs or information that might be helpful to you, other Health Program participants, and/or the Evidation community to help manage their own condition(s), disease(s), or illness(es), and health and wellness more generally;
- Operate, improve, and evaluate the usefulness of the Health Program(s), and any potential future programs; and
- Other similar purposes consistent with the purpose of the collection as part of the Health Program and Evidation’s mission.
Additional Ways We May Share Your Personal Information as Part of a Health Program
If you choose to participate in a Health Program, in addition to the ways and purposes we may share your personal information as described above, we may share your information with our Health Program partners and/or sponsors (if any), who are interested in developing strategies for managing or coping with specific condition(s), disease(s), or illness(es); provided that unless otherwise stated in the relevant Health Program supporting documentation, such information will be aggregated, de-identified, or tokenized.
When we are working with a partner or sponsor, please be advised: Those partners could include pharmaceutical, medical device, or in vitro diagnostic, or other biomedical or life science companies, health plan or health care providers, or other organizations interested in promoting healthy lifestyles, wellness, or managing or coping with specific condition(s), disease(s), or illness(es). We may be compensated for providing the aggregated, de-identified, and/or tokenized data, but we will never sell or disclose your personally identifiable information without your specific and direct consent with any partners or sponsors, unless required to do so by law or regulation or for your health or safety; for instance, for adverse event reporting.
How We May Serve as Your Third-Party Authorized Representative to Help You Collect Your Data
If you choose to participate in a Health program, we may ask you if you would like us to act as your authorized representative to help you gain access to or obtain a copy of your medical records from your various providers or electronic medical record applications or software. We will always ask for your specific permission prior to doing so. If we seek your permission to obtain these records, the collection of the information will be solely to meet the purpose of the Health Program. However, in some cases, even if you would like us to help you gain access to your medical records, we may not be able to fulfill your request. Depending on the Health Program, if access to these medical records is a requirement for participation in the program, and we are unable to fulfill your request to obtain your records, you may need to be unenrolled from the Health Program. We will let you know if that is the case.
Supplemental Privacy Notice for California, Colorado, Virginia, Utah, & Connecticut
This section is intended to constitute a Supplemental Privacy Notice (“Supplemental Notice”) that applies only to information collected about California, Colorado, Virginia, Utah, and Connecticut Consumers (as the term “Consumer” or other similar term may be defined under applicable law). It provides information required under the California Consumer Privacy Act of 2018 and California Privacy Rights Act of 2020 (collectively, the “CPRA”), the Colorado Privacy Act of 2021 (the “CPA”), the Virginia Consumer Data Protection Act of 2021 (the “VCDPA”), the Utah Consumer Privacy Act of 2022 (the “UCPA”), and the Connecticut Data Privacy Act of 2022 (“CDPA”), (collectively, “U.S. Privacy Law(s)”) .
This Supplemental Notice also provides a brief paragraph regarding California’s Shine the Light law, under the heading “Additional California Privacy Information”. We also provide a brief paragraph regarding information collected about Nevada Consumers under the heading “Nevada Privacy Notice” at the end of this section. The other portions of this Supplemental Notice do not apply to Nevada Consumers.
This Supplemental Notice describes our practices regarding the collection, use, and disclosure of Personal Information and provides instructions for submitting data subject requests to meet U.S. Privacy Law requirements. This Supplemental Notice is parallel in scope to the preceding General Privacy Statement and should be read to provide additional information to Consumers that reside in the applicable states. Some portions of this Supplemental Notice apply only to Consumers of particular states. We have included language providing that additional information when it applies. For residents of states without Consumer privacy rights, we will consider requests related to the rights described in this Supplemental Notice, but will apply our discretion in how we process such requests.
Definitions
Because these laws have very specific definitions for different terms, we’ve included a definition section to help you better understand how these words will be used in this Supplemental Notice. Where applicable, terms defined in the General Privacy Statement will retain the same definition in this Supplemental Notice. The terms defined here should be understood to apply only to this Supplemental Notice.
- “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or household. Personal Information includes “personal data” as that term is defined in the CPA, VCDPA, UCPA, and CDPA. Personal Information also includes “Sensitive Personal Information,” as defined below, except where otherwise noted. Personal Information does not include information that has been aggregated, de-identified, or is considered publicly available (as each such term is defined in the CPRA, CPA, VCDPA, UCPA, and CDPA, respectively and as applicable).
- “Sensitive Personal Information” means Personal Information that reveals a Consumer’s social security, driver’s license, state identification card, or passport number; account log-in, financial account number, debit card number, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; precise geolocation; racial or ethnic origin, religious beliefs, or union membership; contents of email or text messages; and genetic data. Sensitive Personal Information also includes processing of biometric information for the purpose of uniquely identifying a Consumer and Personal Information collected and analyzed concerning a Consumer’s health, sex life, or sexual orientation. Sensitive Personal Information also includes “sensitive data” as that term is defined in the CPA, VCDPA, UCPA, and CDPA, respectively.
- “Third Party” has the meanings afforded to it in the CPRA, CPA, VCDPA, UCPA, and CDPA, respectively.
- “Vendor” means a service provider, contractor, or processor as those terms are defined in the CPRA, CPA, VCDPA, UCPA, and CDPA, respectively.
To the extent other terms used in this Supplemental Notice are defined under the CPRA, CPA, VCDPA, UCPA, or CDPA they should be read to have the meanings assigned in those statutes, whether or not capitalized in this Supplemental Notice. Since there are some variations between the definitions in each of the various statutes, the definitions applicable to you are those provided in the state in which you are a Consumer. In other words, the rights you may have, and the definition of any specific term, will be based on the state in which you live. For example, if you are a Virginia Consumer, terms used in this Supplemental Notice that are defined terms in the VCDPA shall have the meanings afforded to them in the VCDPA when this Supplemental Notice applies to you.
Collection, Processing & Disclosure of Personal Information
Collection. As described in the “Information We Collect” section of our General Privacy Statement, to provide you with the Services, you may either directly or indirectly provide certain information to us. We typically collect information submitted directly by you; for example, through emails and webforms, added to your Evidation account or profile, via survey responses, and from any Third-Party Applications, services, or devices connected with your Evidation account.
Sources. Most of the information we collect as part of the Services comes directly from you, your use of the Evidation application and participation as a member of the Evidation community, as well as any of your devices or other Third-Party Applications or services you may connect with your Evidation account. We may also collect some information about you automatically, such as through analytics and cookies as described in the General Privacy Statement. In some cases, we may also collect information about you from Third Parties and Vendors when they share information with us, which would usually be at your direction or by your own disclosure. If you are participating in a Health Program, study, or other research, and we are collecting data about you from other sources, we will be sure to specify that in any supporting documentation, such as the applicable informed consent, disclosure, or authorization.
Business Purpose for Collection and Processing of Your Information. We collect information from you in order to provide, operate, and improve the Services and conduct our business, including your Evidation account and the Evidation community. The information we collect allows us to build your Evidation profile, tailor which programs or opportunities we offer to you, and enables us to empower you to participate in better health outcomes so that we can further our mission to create new ways to measure and improve health in everyday life.
Disclosure. We may disclose your Personal Information to our affiliates and Vendors in order to provide the Services, including for the purposes described below, and as stated in our General Privacy Statement. Our Vendors provide us with services for our applications and websites and to help us provide the Services to you. These services may include activities such as web hosting, data analysis, customer service, infrastructure provision and security, technology services, email or communication delivery services, and other similar services.
- Disclosure in Health Programs, Studies, and Other Research. If you are participating in a study, Health Program, or other research that involves a third-party sponsor or partner, we may also share certain information with those parties. Unless specifically stated in the associated informed consent or other similar document, or if required to meet legal or regulatory requirements like to report adverse events, if we share any information with a sponsor or partner, we will do so only in a de-identified, aggregated, or tokenized form.
- Use and Disclosure of Sensitive Personal Information. In certain limited circumstances, we may need to disclose your Sensitive Personal Information to certain of our Vendors performing services on our behalf. If we do so, the Vendors that receive your Sensitive Personal Information will be required to use the information only as necessary to perform those services, which may include maintaining or servicing accounts, providing customer service, securing our Services (including our websites and applications, and your information), processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on our behalf.
Categories of Personal Information & Purposes for Processing
The following table shows the categories of Personal Information we may have already collected and processed about you in the preceding twelve (12) months, or in the future may collect from you and process, as part of your use of the Services, as well as the source(s) of that information, the specific purpose(s) for processing that information, and the Third Parties with which we may disclose that information:
* See also “General Purposes for Collecting and Processing Personal Information” (below)
Partners/Sponsors**
** If disclosed, it will be de-identified, aggregated, or tokenized (unless noted in the documents associated with the study, research or program).
Determining applicability of and offering to you opportunities to participate in research or enroll (and participate) in a study or certain programs, like Health Programs Developing and conducting certain research, studies and other programs
Contacting you to support your use of the Services or one of Evidation’s applications, products, or services
Responding to your request for support or contact
Signing you up to receive, and distributing, our newsletters and other updates, documents, or notices
* See also “General Purposes for Collecting and Processing Personal Information” (below)
Partners/Sponsors**
** If disclosed, it will be de-identified, aggregated, or tokenized (unless noted in the documents associated with the study, research or program).
Determining applicability of and offering to you opportunities to participate in research or enroll (and participate) in a study or certain programs, like Health Programs
Developing and conducting certain research, studies, and other programs
* See also “General Purposes for Collecting and Processing Personal Information” (below)
Partners/Sponsors**
** If disclosed, it will be de-identified, aggregated, or tokenized (unless noted in the documents associated with the study, research or program).
Determining applicability of and offering to you opportunities to participate in research or enroll (and participate) in a study or certain programs, like Health Programs
Developing and conducting certain research, studies and other programs
* See also “General Purposes for Collecting and Processing Personal Information” (below)
Partners/Sponsors**
** If disclosed, it will be de-identified, aggregated, or tokenized (unless noted in the documents associated with the study, research or program).
Determining applicability of and offering to you opportunities to participate in research or enroll (and participate) in a study or certain programs, like Health Programs
Developing and conducting certain research, studies and other programs
* See also “General Purposes for Collecting and Processing Personal Information” (below)
Determining applicability of and offering to you opportunities to participate in research or enroll (and participate) in a study or certain programs, like Health Programs
Developing and conducting certain research, studies and other programs
* See also “General Purposes for Collecting and Processing Personal Information” (below)
Partners/Sponsors**
** If disclosed, it will be de-identified, aggregated, or tokenized (unless noted in the documents associated with the study, research or program).
Developing and conducting certain research, studies and other programs
* See also “General Purposes for Collecting and Processing Personal Information” (below)
Partners/Sponsors**
** If disclosed, it will be de-identified, aggregated, or tokenized (unless noted in the documents associated with the study, research or program).
Determining applicability of and offering to you opportunities to participate in research or enroll (and participate) in a study or certain programs, like Health Programs
Developing and conducting certain research, studies and other programs
* See also “General Purposes for Collecting and Processing Personal Information” (below)
Partners/Sponsors**
** If disclosed, it will be de-identified, aggregated, or tokenized (unless noted in the documents associated with the study, research or program).
Determining applicability of and offering to you opportunities to participate in research or enroll (and participate) in a study or certain programs, like Health Programs; provided that we will not disclose your Sensitive Personal Information to a Third Party and or build a profile about you or otherwise alter your experience outside the current interaction with us
Developing and conducting certain research, studies and other programs
Ensuring security and integrity to the extent the use of your Personal Information is reasonably necessary and proportionate for these purposes
Undertaking activities to verify or maintain the quality or safety of one of our services or offerings, or enhance the service or device that is owned or controlled by us
Partners/Sponsors**
** If disclosed, it will be de-identified, aggregated, or tokenized (unless noted in the documents associated with the study, research or program).
Though we do not intend as part of your use of our Services to collect any categories of information other than those listed above, we may also collect, process, and if necessary share with our Vendors any information that you provide us directly as part of your request or contact. For instance, if you upload a document as part of a support request or provide us with additional Personal Information beyond what we have specifically requested to collect.
General Purposes for Collecting and Processing Personal Information. In addition to the specific purposes for processing information listed in the chart above, we, and our Vendors, collect and process Personal Information as described in the “How We Use Your Information” section of the General Privacy Statement.
Retention of Personal Information. As stated in the “Retention of Information” section of the General Privacy Statement, we retain your Personal Information for the period reasonably necessary to provide the Services to you and meet any legal, regulatory, or contractual requirements, or for other legitimate and lawful business purposes.
Additional Third Party Sharing. We may share or otherwise disclose your Personal Information to certain Third Parties for business purposes and in order to provide the Services to you, as set forth in the “How We Share Information” section of the General Privacy Statement. Otherwise, we do not disclose your Personal Information to Third Parties (as defined in the CPRA) without your consent.
Disclosure for California Consumers. We have not sold Personal Information about California Consumers in the past twelve (12) months. To our knowledge, we have not “shared” (as such term is defined under CPRA) Personal Information about California Consumers in the past twelve (12) months. For additional information about how we may disclose your data, please review the descriptions above as well as in the “How We Share Information” section of the General Privacy Statement. Relatedly, we do not have actual knowledge that we sell or share Personal Information of California Consumers under 16 years of age. For purposes of the CPRA, a “sale” is the disclosure of Personal Information to a Third Party for monetary or other valuable consideration, and a “share” is the disclosure of Personal Information to a Third Party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.
Disclosure for Colorado, Virginia, Utah, and Connecticut Consumers. We do not sell or share Personal Information to Third Parties or process Personal Information for purposes of targeted advertising, as the terms “sell,” “share,” “process,” and “targeted advertising” are defined in the CPA, VCDPA, UCPA, and CDPA, respectively.
Data Subject Rights
Your Rights. California, Colorado, Virginia, Utah, and Connecticut Consumers have certain rights with respect to the collection and use of their Personal Information. Those rights vary by state. As required by the CPRA, we provide detailed information below regarding the data subject rights available to California Consumers. Colorado, Virginia, Utah, and Connecticut Consumers have similar rights and can find more detail by referencing the CPA, VCDPA, UCPA, or CDPA, as applicable.
Non-Discrimination. We will not discriminate against you for exercising your data subject rights. For example, we will not deny goods or services to you, or charge you different prices or rates, or provide a different level of quality for products or services as a result of you exercising your data subject rights.
Data Subject Rights Disclosure for California Consumers. California Consumers have the following rights regarding our collection and use of their Personal Information, subject to certain exceptions.
Right to Receive Information on Privacy Practices. You have the right to receive the following information at or before the point of collection of your Personal Information:
- The categories of Personal Information to be collected;
- The purposes for which the categories of Personal Information are collected or used;
- Whether or not that Personal Information is sold or shared;
- If we collect Sensitive Personal Information, the categories of Sensitive Personal Information to be collected, the purposes for which it is collected or used, and whether that information is sold or shared; and
- The length of time we intend to retain each category of Personal Information, or if that is not possible, the criteria used to determine that period.
We have provided the information described in the list above in this Supplemental Notice. Our data practices may differ between updates to this Supplemental Notice; however, if any changes are materially different, we will provide you with additional supplemental pre-collection notice of our current practices, which may include references to other privacy policies, notices, or statements. Otherwise, this Notice serves as our notice at collection. You may request further information about our privacy practices by contacting our Privacy Office at the contact information provided below.
Right to Know. You can request that we provide you with information about how we have handled your Personal Information in the twelve (12) months preceding your request, including:
- The categories of:
- ~Personal Information collected;
- ~Sources from which the Personal Information is collected;
- Personal Information that we have sold, shared, or disclosed about you for a business purpose;
- Third Parties with whom we shared or disclosed that Personal Information;
- The business or commercial purpose for collecting the information; and
- The specific pieces of Personal Information that we have collected about you.
Right to Deletion. You can request that we delete your Personal Information.
Right to Correct. You can request that we correct your personal information.
Please note that in many cases, you may correct any Personal Information we have collected about you by updating your Evidation account profile and settings.
Right to Receive Information About Onward Disclosures. You can request that we provide you with the following information about any disclosure of your Personal Information in the twelve (12) months preceding your request:
- The categories of Personal Information that we have collected about you;
- The categories of Personal Information that we have sold or shared about you and the categories of Third Parties to whom the Personal Information was sold or shared; and
- The categories of Personal Information we have disclosed about you for a business purpose and the categories of persons or entities to whom it was disclosed for a business purpose.
Right to Opt-Out of the Sale of Personal Information or Sharing of Your Personal Information for Certain Behavioral Advertising. We do not and will not sell (as defined by the CCPA and CPRA) your Personal Information. We will not share your Personal Information with our customers without your express consent. In certain circumstances, we may share your information with our affiliates, Vendors, and third-party business partners or sponsors, as described in the General Privacy Statement and this Supplemental Notice.
Right to Limit our Use or Disclosure of your Sensitive Personal Information. You can request that we limit our use and disclosure of your Sensitive Personal Information to that use or disclosure as is necessary to perform the Services or provide the goods reasonably expected by an average Consumer who requests those goods or services. We do not collect, use, or process Sensitive Personal Information for any purposes other than those listed above; all of which are necessary for our business operations and legitimate interests, and to operate and provide you the Services.
Right to Non-Discrimination for Exercising your Rights. You have the right not to be discriminated against if you exercise your privacy rights. We will not discriminate against you for exercising your data subject rights.
Exercising Your Data Subject Rights
Submitting your Data Subject Requests. You may exercise many of the data subject rights applicable to you under the CPRA, CPA, VCDPA, UCPA, or CDPA, respectively, directly in your Evidation account. By logging-in to your Evidation account, you can update the information in your profile, see the programs in which you are enrolled, and make requests to exercise many of your data subject rights. Data subject requests can also be made through the “Submit a Request” function in your Evidation account or by emailing help@evidation.com. You may also exercise your rights by reaching out to our Privacy Office at privacy@evidation.com or the contact information listed below. To fulfill your request, please be sure to respond to any follow-up inquiries we may make. Please be aware that we do not accept or process requests through other means (e.g., via fax, chats, social media etc.).
Verification of Data Subject Requests. All requests will be verified to ensure they are valid. We may ask you to provide information that will enable us to verify your identity to comply with or fulfill your data subject request. The easiest way to verify your request is to log-in to your Evidation Account and either make any necessary changes directly or submit the request. If you submit your request via the “Submit a Request” function (either on our website or in the Evidation application) or by contacting our Privacy Office, we may request the following information to verify your request: name and email, how you’ve used our Services, activity related to your Evidation account, and other similar information.
Authorized Agents. You may also nominate an authorized agent to submit a data subject request on your behalf. We may request additional information from you to verify that the authorized agent is operating on your behalf. In particular, when a California Consumer authorizes an agent to make a request on their behalf, we may require the agent to provide proof of signed permission from you to submit the request, or we may require you to verify your own identity or confirm that you provided the agent with permission to submit the request.
Exceptions. In some instances, we may decline to honor your data subject request if an exception applies. We will respond to your request consistent with applicable law. These exceptions come up most frequently for studies, research, and Health Programs that fall under the review of an Institutional Review Board.
Appeals. Virginia, Colorado, and Connecticut Consumers have the right to appeal our decisions on their data subject requests. This section does not explicitly apply to California or Utah Consumers; however, Consumers in California or Utah may submit a complaint regarding their data subject request by following the process described below. To appeal our decision on your data subject request, you may contact our Privacy Office by using the contact information listed below. In submitting your appeal, please enclose a copy of or otherwise specifically reference our decision on your data subject request, so that we may adequately review and address it. We will respond in accordance with applicable law.
Complaints. To file a complaint related to your data subject request or this Supplemental Notice, you may contact our Privacy Office by using the contact information listed below. In submitting your complaint, please enclose a copy of or otherwise specifically reference our decision on your data subject request, or provide other relevant documentation, so that we may adequately review and address it. We will respond in accordance with applicable law.
Questions. Any queries, questions, or requests in relation to your privacy rights, and specifically any data subject requests, can be made using the contact information listed below or as available on the Evidation application or our website.
Other Disclosures
Additional California Privacy Information
Financial Incentives for California Consumers. Under California law, we may provide financial incentives to California Consumers who allow us to collect, retain, sell, or share their Personal Information. We will describe such programs when we offer them to you. In general, we do not offer financial incentives for Personal Information. If you have an Evidation account, we do reward you for participating in the Evidation program and community, which includes taking part in healthy activities, participating in surveys, or enrolling and participating in certain studies, research, and programs. When you join the Evidation community, you can sync certain health and fitness applications with the Evidation application, or self-report information, to earn points for healthy behaviors. You can learn more about earning points in the Evidation program here.
Shine the Light. California residents have the right, under certain circumstances, to request information regarding the sharing during the prior year of certain categories of “personal information” (as defined by applicable California law) to Third Parties for their direct marketing purposes. As noted above, we do not share your Personal Information with Third Parties for their direct marketing purposes unless we have your explicit permission. For any questions regarding this, please contact the Privacy Office by using the information provided below.
Nevada Privacy Notice
Pursuant to Nevada law, you may direct a business that operates an internet website not to “sell” certain “covered information” (each as defined by such law). As noted above, we do not sell Personal Information. For any questions regarding this, please contact the Privacy Office by using the information provided below.
Contact Us
For any questions, complaints, or inquiries regarding this Notice, or our privacy practices, please direct your inquiry to:
Changes to this Notice
We may update this Notice from time to time to reflect changes or updates to our technology, data practices, and other factors, including changes in law. Changes to this Notice will become effective when published in the revised Notice, unless otherwise noted. Please check the “Last Updated” date at the top of this page to see when this Notice was last revised. Your continued use of the Services following the effective date of these changes indicates your consent to the practices described in the updated Privacy Notice.