This Privacy Policy describes how Reclaim Health (legal name: MyA Health, Inc., hereby referred to as "Reclaim") protects your personal information when you use this Reclaim app (the "App"). Reclaim is located at 45 Prospect Street, Cambridge, MA 02139. All references to you include your Authorized Individuals, if any. Your use of the App is subject to this Privacy Policy as well as our Terms of Use.
Reclaim takes individual privacy seriously and we endeavor to inform you of the uses that we have for information that we obtain from you through the App. We will take reasonable commercial steps to protect your privacy consistent with the guidelines set forth in this Privacy Policy and with applicable federal and state laws. Please review this Privacy Policy and the Terms of Use carefully. If you do not agree with our practices, do not access or use any part of the App.
By accessing and/or using any part of the App, you are agreeing to the terms and conditions of this Privacy Policy and the Terms of Use. Additionally, please note that the manners in which we obtain information from you and our uses for your information may change on occasion. As a result, we encourage you to return to and reread this Privacy policy from time to time.
A. Summary of Reclaim’s Data Practices
B. Definitions
- Activity Logs: Activity logs are Reclaim's records of when Personal Information is created, accessed, modified, deleted, released, or exported from and/or within the App.
- Aggregate Data: Aggregate Data is Claims Data that is: (1) grouped so it does not connect to you as an individual and (2) has names and other identifiers removed or altered. In other words, Aggregate Data is de-identified data that cannot reasonably be used to identify you or any other User of the App as an individual.
- App Providers: An App Provider is an entity that is hired to perform certain functions for Reclaim to support the development, maintenance, and implementation of Reclaim. App Providers may include software or website designers and data storage providers.
- Authorized Individuals: An Authorized Individual is someone you authorize to access your Claims Data on your behalf.
- Authorized Individual-Representative. An Authorized Individual-Representative is an individual who has authority to create and manage a Reclaim account on behalf of a Dependent and may include a parent, guardian, or other legal representative.
- Dependent: A Dependent is a minor child or other individual over whom an Authorized Individual has legal authority.
- Personal Data: Personal Information means information about you that reasonably can be linked to you that we obtain directly from you or from a third-party such as your Plan Sponsor in accordance with applicable law and/or consents that you have provided, or that we otherwise receive through the App. By way of example (but not limitation), we may receive your Personal Information through the App where you, an Authorized Individual, or an Authorized Individual-Representative uploads it to your account, includes it with any communication sent through the App, or links your HSA/FSA to the App. Personal Information might include, but is not limited to, the following:
- Your name and contact information, such as your address, phone number, or email address
- Your medical history, conditions, treatments, and medications
- Your healthcare claims, health plan account numbers, bills, insurance information, and other financial information
- Demographic information, such as your age, gender, ethnicity, and occupation
- Any other data described in the chart listed under Section A above
- Information about the browser or device you use to access or use the App (e.g., browser type, domain names, access times, and operating system), Internet protocol (“IP”) address; how you interact with the App; time zone; or information about the cookies installed on your device (within the broader definition of “Personal Information,” this this browser or device information will be specifically referred to as “Device Information” for the purposes of this Privacy Policy)
- Plan Sponsor: A Plan Sponsor is an entity that provides you health coverage, such as your employer or your insurer.
- Reporting: Reclaim might report about business activities and users (you) to others, such as investors, auditors, potential business partners, or public communities. Reports will not include Personal Information without your specific permission or as permitted or required by law.
- Security Measures: Security measures can include computer safeguards, secured files, and employee security training. In addition, Reclaim may be required by law to notify you about particular data breaches.
C. What Information Does Reclaim Collect?
- Before you register for the App, Reclaim may collect your Personal Information in two ways: (1) if you contact Reclaim through the Internet and provide Reclaim with your contact information (e.g., name, mailing address, email address and other information); or (2) Reclaim may obtain your contact information from a healthcare Plan Sponsor with which Reclaim partners. In either case, Reclaim will use such Personal Information at this stage for the sole purpose of informing you about the App and inviting you to register for the App.
- To use the App, you must complete the registration process, which includes agreeing to abide by the Terms of Use, a copy of which is available online here: reclaimhealth.com/terms-of-use. As part of the registration process, you may be asked to provide certain Personal Information, such as your name, mailing address, and email address.
- In general, Reclaim collects all Personal Information that you supply directly to the App. Further, Reclaim may collect Personal Information from other third-party information providers that you expressly authorize to send Personal Information to your Reclaim account (e.g., your HSA/FSA bank).
- Reclaim passively collects Device Information from you as you navigate through the App. Reclaim may track IP addresses, use industry standard tracking devices (e.g., session and persistent cookies, flash cookies, web beacons), and electronically gather information about the technology you use to access the App and the areas of the App you utilize.
D. How Does Reclaim Use Your Information?
- Reclaim uses your Personal Information for a variety of purposes including, but not limited to, providing the App as described on the website and Terms of Use, as well as to enhance the performance of the App and/or create new services. From time to time, we may further use Personal Information as needed to deliver our services to you, communicate with you regarding our products and services; establishing and maintaining your accounts; providing customer service; verifying user information; detecting security incidents that may compromise the confidentiality of Personal Information in our possession; or enforcing our legal rights or as required by applicable law or requested by any judicial process or government agency. Device Information may additionally for purposes including, but not limited to, be used to help us screen for and prevent potential risk and fraud (in particular, through any IP address we collect from you); diagnose and mitigate any App errors; administer the App; or generate analytics about how users interact with the App.
- Please note that by sending us messages or inquiries, uploading files, inputting data, or engaging in any other form of communication through the App, you are granting us a license to use, reproduce, disclose, publish, distribute, and otherwise exploit in any manner the content of any such message, inquiry, file, data, or communication. This license is granted to us without restriction and without the requirement that we compensate you in any way. We are under no obligation to maintain any such message, inquiry, file, data, or communication in confidence, or to provide you with any response or confirmation of receipt.
- If you provide us with your email address, we may in the future begin to send you administrative or promotional emails, including newsletters. If you wish to opt out of newsletters and promotional emails, you may do so by following the "unsubscribe" instructions in the email.
- Reclaim will not use Personal Information for product development or product enhancement without your express, written permission. Reclaim also will not sell or rent your Personal Information without your written consent. Reclaim will not use or disclose your Personal Information, except as described in this Privacy Policy, the Terms of Use, or as permitted or required by law.
E. Sharing Your Information With Third Parties
- Reclaim may make your Personal Information available to third-parties participating in the App that are authorized by you or as necessary to complete transactions you authorize.
- Reclaim may disclose your Personal Information to Reclaim App Providers that provide technical support or other services to Reclaim related to the App. All such App Providers are subject to confidentiality obligations and may only access and utilize your data for purposes of fulfilling their obligations to Reclaim. However, please note that use of the App may require the use of third-party search engine or telecommunications operators. These operators are not our App Providers, and any information these operators collect from you in connection with your use of the App is not part of our collected Personal Information and is not subject to this Privacy Policy. We are not responsible for the acts or omissions of these operators.
- Reclaim may provide or sell Aggregate Data that is de-identified to third-parties. However, Aggregate Data will not include any of your Personal Information or be individually identifiable.
- If a third-party acquires the assets of Reclaim related to the App and its products and services (whether by sale, merger, change of control, bankruptcy or otherwise), your Personal Information may be transferred to the new owner(s). In such case, your Personal Information would remain subject to the provisions of the Reclaim privacy policy that was in effect immediately prior to the transfer unless Reclaim provides you notice otherwise.
- Reclaim may disclose your Personal Information to any parent company, subsidiary, joint venture, or other entity under common control with us in order to achieve any of the purposes described in this Privacy Policy.
- Reclaim may further disclose your Personal Information for the purposes of detecting, preventing, or otherwise addressing any security, fraud, or technical issues; ensuring the personal safety of any individual (including our employees, users, or members of the general public); complying with legal obligations, processes, or requests; enforcing our contracts or agreements (including this Privacy Policy or the Terms of Service); or protecting or defending our legal rights.
F. Choices You Have About How Reclaim Uses Your Information
- Managing Your Account. Generally, you may access, review, correct, or add to your Personal Information on the App, or change how this Personal Information is used and disclosed, through the account setting and account management features. You may access your Reclaim account at any time to review your Personal Information. For technical questions related to the Reclaim product, please access the messaging support link on the Reclaim App.
- Privacy Settings / Right to Remove. If you would like your Personal Information to be deleted or removed from the App and our database, please contact us by email at compliance@reclaim.health. Reclaim will accommodate such deletion or removal requests to the best of our ability, as required by applicable law. Please note that we generally are not responsible for ensuring that any third-party (e.g., a Plan Sponsor) stops sharing your Personal Information with us. As a result, if Reclaim has received Personal Information about you from a third-party, we may respond to your deletion or removal request in part by instructing you to submit an additional request to the third-party directing it to stop sharing your Personal Information with us. Importantly, the deletion or removal of certain Personal Information from our database may impede or prevent our ability to continue providing the App or other services to you, and we may opt to cease doing so if we determine in our sole discretion that we no longer have sufficient Personal Information to service you.
We may ask you to provide a copy of your driver’s license or other identifying documents to assist us in processing a deletion or removal request. Reclaim may also continue contacting users who have submitted a deletion or removal request for administrative or other legal purposes. The deletion or removal of your Personal Information may take some time to complete, consistent with applicable law. Please note that the deletion or removal of any Personal Information will not necessarily result in the destruction of records of past transactions or information stored in our data archives. Aggregated Data is not subject to deletion or removal requests. - Authorized Individuals. You may grant access to your Reclaim account to one or more Authorized Individuals. You may grant an Authorized Individual access to your Reclaim account by specifically authorizing Reclaim to permit access by such Authorized Individual to your Reclaim account. When you grant access to an Authorized Individual, you may permit the Authorized Individual to: (a) have the same level of access to your Reclaim account as you have; or (b) have limited access to your Reclaim account (i.e., the Authorized Individual will be authorized to access and read only a subset of your Personal Information that you specify) Whether or not to grant an Authorized Individual access to your Reclaim account is your decision. You acknowledge and agree that: (a) you are solely responsible for verifying the identity of, and monitoring the use by, any Authorized Individual you select; (b) Reclaim has no responsibility or liability in connection with any access to, or use of, your account and information by any Authorized Individual or Authorized Individual-Representative; and (c) by logging in as an Authorized Individual, you represent and warrant that you have received permission from a user.
G. Data from Children
- In General. The App is not intended for use by children younger than 18 years old. Reclaim will not knowingly collect information from website visitors or App users younger than 18 years old and no part of the App is directed at persons under 18 years old. If you are under 18 years old, please do not use the App on your own.
- Parents and Guardians. While the App is not intended for children under the age of 18 years old, a parent or guardian may elect to establish a Reclaim account for a child through the App and establish themself as the Authorized Individual-Representative in connection with the account. In doing so, the Authorized Individual-Representative may have access to their child’s Personal Information uploaded through the App and expressly consent to Reclaim utilizing any of such Personal Information for the purposes set forth in this Privacy Policy and the Terms of Use.
- Data Requests. Under certain circumstances, a parent or guardian of a child who is not an Authorized Individual-Representative on the child’s account may request that Reclaim provide access to the child’s Personal Information. Upon receipt of such a request, Reclaim may require the parent or guardian to provide identification or other legal documentation to confirm their relationship with the child. Requests will then be managed as follows: (i) if the child is under 12 years old, Reclaim will provide the parent or guardian with a copy of the Personal Information that has been uploaded to the child’s account; or (ii) if the child is over 12 years old, Reclaim will generally require the parent or guardian to produce a written consent from the child that authorizes Reclaim to provide a copy of their Personal Information, unless the child is located in a state that expressly permits such access without the child’s written consent.
H. How Reclaim Protects Your Information
Reclaim uses both technical and procedural Security Measures to maintain the integrity and security of the Reclaim databases, including the use of secure servers and firewalls. These Security Measures will be appropriate and commercially reasonable based on the nature of the underlying Personal Information they protect. Reclaim encrypts all Personal Information during transmission. Within Reclaim, all Personal Information is encrypted at three levels: each individual has a unique encryption key; demographic information is encrypted; and healthcare data is separately encrypted. Reclaim also requires comprehensive security training for our workforce.
Please note that no Internet Transmission is completely secure and Reclaim cannot guarantee that security breaches will not occur in connection with your use of the App. We are not responsible for the actions of hackers and other unauthorized third-parties that breach our appropriate, commercially reasonable Security Measures. This Privacy Policy is not intended to confer, nor does it confer, any rights or remedies to users.
Additionally, the safety and security of your Personal Information also depends on you. Never share your password with anyone else. Notify Reclaim promptly if you believe your password has been breached.
Unless you ask us to delete your Personal Information sooner, we will maintain it until such time that we determine, in our sole discretion, that (1) it is no longer necessary for any purpose for which Reclaim may use it in accordance with this Policy; and (2) it may be destroyed or deleted in accordance with applicable law.
I. Security Breach Notification Requirements
Pursuant to applicable law, Reclaim may be required to send you notice of security breaches or suspected security breaches that impact your Personal Information. In the unlikely event that Reclaim must provide you a notice of a security breach, Reclaim will send you security breach notices to the e-mail address or telephone number contained in your account information unless we are otherwise required by law. Please note: many e-mail systems have built in SPAM filters. If you have one in place, you should check with your system administrator or the available instructions to confirm that e-mails from Reclaim are not blocked by the filter (e.g., by confirming that the App domain name (reclaim.health) is a permitted domain name.
J. Changes to this Privacy Policy
Reclaim reserves the right to change the Privacy Policy in its sole discretion. In such case, Reclaim will post the new Privacy Policy on the website and the effective date of the new Privacy Policy will be clearly marked. If Reclaim updates this Privacy Policy, your continued use of the App (following the posting of the revised Privacy Policy) means that you accept and agree to the terms of the revised Privacy Policy. Remember, by using any part of the App, you accept and agree to our Privacy Policy and privacy practices. Accordingly, we encourage you to review this Privacy Policy from time to time.
K. App Users from Outside the United States
- No Marketing to Such Residents. We do not market our services to residents of Europe, the United Kingdom (UK), or Switzerland, and are not subject to Regulation 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of Personal Information and free movement of Personal Information, known as the General Data Protection Regulation (“GDPR”). If you reside in the European Economic Area (“EEA”), UK, or Switzerland, please be aware that if you voluntarily provide us with any Personal Information, that information will be transferred from your location to data centers located in the United States for processing, and this transfer will be deemed to have been made with your consent.
- Rights Honored. Although we are not subject to the GDPR, we will generally make commercially reasonable efforts to honor your data privacy rights upon request, subject to certain limitations. If you reside in the EEA, UK, or Switzerland, you have the rights, as applicable under the GDPR, to:
- Request an accounting of Personal Information that we possess that pertains to you in an electronically portable format.
- Request that we correct or update Personal Information that pertains to you.
- Request that we delete Personal Information that pertains to you.
- Fully or partially withdraw your consent to the collection, processing, and/or transfer of your Personal Information.
- Requests and Complaints. To request an accounting of your Personal Information, a correction or update to your Personal Information, deletion of your Personal Information, or to withdraw your consent to the collection, processing, and/or transfer of your Personal Information, please contact us by email at compliance@reclaim.health. Once we receive your request, we will no longer process your Personal Information for the above purposes unless there are legitimate grounds for further processing which override your interests, rights, and freedoms, or unless we do so for the establishment, exercise, or defense of legal claims. If you believe we are unlawfully possessing your Personal Information, you have the right to complain to your local data protection supervisory authority. You can find contact details here: https://edpb.europa.eu/about-edpb/board/members_en.
L. More information
If you have additional questions, please contact Reclaim any time. Or write to the company at:
MyA Health, Inc.
ATTN: Reclaim Privacy Matters
45 Prospect Street
Cambridge, MA 02139 (USA)
compliance@reclaim.health