PRIVACY & SECURITY
Last updated: December 31, 2019
This Website collects some Personal Data from its Users. Users may be subject to different protection standards and broader standards may therefore apply to some. In order to learn more about the protection criteria, Users can refer to the applicability section.
Privacy Notice for EU Data Subjects
If you are visiting this site from the European Union, please see our EU Data Subject Privacy Notice for information about the processing of your personal data.
Privacy Notice for California Residents
If you are a California resident visiting our website, California law may provide you with additional rights regarding our use of personal Information. Please see our Privacy Notice for California Residents for this information.
We are in compliance with the requirements of COPPA (Children’s Online Privacy Protection Act), we do not knowingly collect any information from anyone under 13 years of age. Our website, products and services are all directed to people who are at least 13 years old or older.
If you are a parent or guardian and you are aware that your Children has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
California Online Privacy Protection Act
According to CalOPPA we agree to the following:
Users can visit our site anonymously.
Users are able to change their personal information through our Service by:
- Emailing us
- Calling us
- Logging in to their account
- Chatting with us or sending us a ticket
Consumer: natural persons who reside in California, including (1) individuals who are in California for other than a temporary and transitory purpose; and (2) individuals who are domiciled in California, but are outside the state for a temporary or transitory purpose.
CCPA: the California Consumer Privacy Act of 2018, effective as of January 1, 2020
Personal information: as defined in the CCPA, and includes information that can be used to identify you, either alone or in combination with other information, and any other information that could reasonably be linked with a particular consumer or device.
Right to Access
As a consumer you have the right to know the following:
- Categories of personal information we collect about you.
- Categories of sources from which personal information is collected.
- Business or commercial purpose for collecting personal information
- The categories of third parties with whom the business shares personal information.
- Request the specific pieces of personal information the business collected about you in a readily usable format.
- If a business sells personal information or discloses it for business purposes
Your access rights under the CCPA are not absolute. Specifically, the CCPA limits the information you can request to personal information collected in the 12-month period preceding our receipt of the request. Additionally, under the CCPA, Seeking Health is not obligated to respond to requests for access to personal information more than twice in a twelve-month period. Seeking Health may, in its sole discretion, choose to provide personal information in response to a consumer’s access request that relate to a time period greater than the preceding 12 months or respond to a consumer request more frequently than required by law; choosing to do so, however, does not constitute an obligation to do so.
Right to Request Deletion
Consumers also have the right to request deletion of personal information, but only where that information was collected from the consumer. Your personal information may not be deleted if the information is necessary to:
- Complete the transaction for which the personal information was collected, provide a good or service requested by the consumer, or reasonably anticipated within the context of a business’s ongoing business relationship with the consumer, or otherwise perform a contract between the business and the consumer.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity.
- Comply with a legal obligation.
Only you or someone legally authorized to act on your behalf may make a verifiable consumer request related to your personal information. Your request must provide sufficient information that allows us to verify you are the person about whom we collected personal information or an authorized representative. Your request must describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
Seeking Health will deliver the required data to the consumer in an electronic readable format within 45 days of receipt of the verifiable consumer request. This information will be provided free of charge to the consumer.
Right to Opt Out
As a consumer you have the right to opt-out of having your personal information sold. Seeking Health does not sell personal information to 3rd parties.
Right to Equal Services and Non-Discrimination
The CCPA prohibits businesses from discriminating against consumers by denying goods or services, charging a different price or rate for goods or services, providing a different level or quality of goods or services, or suggesting that they will do any of these things based upon a consumer’s exercise of any CCPA rights.
The right to equal services and prices does not place any restrictions on a business’ ability to collect information or deny service if a consumer does not want to participate in collection; it only applies where the consumer exercises specific CCPA rights, such as opting out of downstream sale of the data.
Exercising Consumer Rights
To request a summary of your personal information or to request deletion of your personal information please use our Personal Information Request Form or contact us at email@example.com.
Information We Collect
Category – Identifiers
Examples: Real name, alias, postal address, unique personal identifier, online identifier, internet protocol address, email address, account name
Category – Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))
Examples: Registration information such as name, address and contact information. Some information included in this category may overlap with other categories
Category – Protected classification characteristics
Examples: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
Category - Commercial information
Examples: Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies
Category - Geolocation data
Examples: Web-Behavior Information that includes the identification or estimation of physical location or movement.
Category – Internet or Other Electronic Network Activity Information
Examples: Browsing history, search history, and information regarding consumer’s interaction with an internet site.
The CAN-SPAM Act sets the rules for commercial email, establishes requirements for commercial messages, and gives recipients the right to have emails stopped from being sent to them.
We collect your email address in order to:
- Send information, respond to inquiries, and/or other requests or questions
- Process orders and to send information and updates pertaining to orders
- Market to our mailing list or continue to send emails to our clients after the original transaction has occurred
To be in accordance with CAN-SPAM we agree to the following:
- We do not use false, or misleading subjects or email addresses.
- Messages are identified as advertisements in some reasonable way.
- Messages include the physical address of our business headquarters.
- We will honor opt-out/unsubscribe requests quickly.
- We allow users to unsubscribe by using the link at the bottom of each email.
Types of Data collected
Among the types of Personal Data that this Website collects, by itself or through third parties, there are: first name, last name, phone number, email address, Cookies, Usage Data, various types of Data, province, state, country, ZIP/Postal code, gender, city, address, date of birth and geographic position.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Website.
Unless specified otherwise, all Data requested by this Website is mandatory and failure to provide this Data may make it impossible for this Website to provide its services. In cases where this Website specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Users are responsible for any third-party Personal Data obtained, published or shared through this Website and confirm that they have the third party’s consent to provide the Data to the Owner.
Mode and place of processing the Data
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Website (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Legal basis of processing
The Owner may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes. Note: Under some legislations the Owner may be allowed to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. This, however, does not apply, whenever the processing of Personal Data is subject to European data protection law;
- provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
- processing is necessary for compliance with a legal obligation to which the Owner is subject;
- processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
- processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
The Data is processed at the Owner’s operating offices and in any other places where the parties involved in the processing are located.
Depending on the User’s location, data transfers may involve transferring the User’s Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
If broader protection standards are applicable, Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
If any such transfer takes place, Users can find out more by checking the relevant sections of this document or inquire with the Owner using the information provided in the contact section.
- Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
- Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
The purposes of processing
The Data concerning the User is collected to allow the Owner to provide its Services, as well as for the following purposes: Contacting the User, Interaction with external social networks and platforms, Analytics, Handling payments, Traffic optimization and distribution, SPAM protection, Managing contacts and sending messages, Social features, Managing support and contact requests, Interaction with live chat platforms, Registration and authentication and Location-based interactions.
Users can find further detailed information about such purposes of processing and about the specific Personal Data used for each purpose in the respective sections of this document.
Detailed information on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
Definitions and Legal References
This EU Data Subject Privacy Notice (“EU Privacy Notice”) explains how Seeking Health LLC (“Seeking Health”, “we”, “us”) fulfills our responsibilities under the EU General Data Protection Regulation (“GDPR”) in relation to the collection, retention, use, and other processing of personal information that is obtained when EU data subjects visit and interact with our Website (www.seekinghealth.com) and use the Services.
Seeking Health LLC is the data controller for our Website and Services. You can contact us by e-mail sent to firstname.lastname@example.org or by writing to us at the following address:
Seeking Health LLC
3140 Mercer Avenue
Bellingham, WA 98225
We may collect and process the following personal data when you visit our Website and use our Services:
- Contact data. You may provide us with your contact details, such as name, email address, physical address, phone number, or other similar information, which we may use to respond to you or for administrative purposes.
- Log data. As with most websites and technology services delivered over the Internet, our servers automatically collect information when you access or use our Website and record that data in log files. This log data may include your Internet Protocol (IP) address, the address of the web page visited before using our Website, browser type and settings, the date and time that the Website was used, information about browser configuration and plugins, language preferences, and cookie data.
- Device Information. We may obtain information about devices that access our Website, including the type of device, its operating system, device settings, unique device identifiers, and crash data.
- Authentication Data. To verify the identity of registered users on our Website and Services, we may collect a user name, password, password hint(s), and other similar authentication information.
- Other Information You Provide. This includes emails and other communications that you send us or otherwise contribute, such as customer support inquiries and reviews. If you purchase a product, this will include information that is necessary to complete your purchase such as your credit card information.
We do not collect personal data that is considered to be sensitive or special categories of personal data under the GDPR.
Note that our Website and Services are dynamic. We may introduce new features, which may involve new or different personal data processing activities. If we make a material change to how we process your personal data, we will notify you and may also modify this EU Privacy Notice. If we have relied upon your consent for a particular use of your personal data, we will seek your consent to use such personal data for any other purpose.
How and Why We Use Your Personal Data
We may use the personal data we obtain to:
- Communicate with you
- Provide you with customized services
- Ensure the security and integrity of our Website and Services
- Maintain and promote our Website and Services
- Analyze and learn about how our Website and Services are accessed and used
- Manage our customer and partner relationships
- Enforce our legal terms and policies
- Protect our and others’ interests, rights, and property
- Comply with applicable legal requirements.
Legal Bases for Processing Personal Data
We process your personal data pursuant to the following legal bases:
- You have consented to the use of your personal data. When you consent, you can change your mind at any time.
- The processing is necessary for us to provide you with the services and products you request, or to respond to your inquiries.
- We have a legal obligation to process your personal data, such as to comply with applicable tax and other government regulations or to comply with a court order or binding law enforcement request.
- To protect your vital interests, or those of others.
- We have a legitimate interest in using your personal data. In particular, we have a legitimate interest in the following cases:
- To analyze and improve the safety and security of our Website and Services. This includes implementing and enhancing security measures and protections and protecting against fraud, spam, and abuse.
- To maintain and improve our Website and Services.
- To operate our Website and Services and provide you with certain tailored advertising and communications to develop and promote our business.
- To anonymize personal data and subsequently use the anonymized information.
How We May Share Your Personal Data
We may share your personal data:
- With our affiliates or business partners when it is reasonably necessary or desirable, such as to help provide services to you or analyze and improve the Website and Services.
- With our service providers that perform services on our behalf. For example, we may use third parties to help us provide customer support, authorize and process your payments, manage our advertisements, send marketing and other communications on our behalf, or assist with data storage.
- In order to follow the law or protect rights and interests. For example, we may disclose your personal data if we determine that such disclosure is reasonably necessary to comply with the law, protect our or others’ rights, property or interests, or prevent fraud or abuse. In particular, we may disclose your personal data in response to lawful requests by public authorities, such as to meet national security or law enforcement requirements.
- If we are involved in a reorganization, merger, acquisition, or sale of some or all of our assets.
How We Protect Your Personal Data
We maintain appropriate technical and organizational safeguards designed to help protect personal data from unauthorized disclosure or access and accidental or unlawful destruction, loss, or alteration. Although we use reasonable efforts to safeguard personal data, we cannot guarantee the security of your information obtained through our Website and Services.
How Long We Retain Your Personal Data
We will store your personal data for no longer than is necessary for the performance of our obligations or to achieve the purposes for which the information was collected, or as may be permitted under applicable law. To determine the appropriate retention period, we will consider the amount, nature, and sensitivity of the information; the potential risk of harm from unauthorized use or disclosure of the information; the purposes for which we process the information and whether we can achieve those purposes through other means; and the applicable legal requirements. Unless otherwise required by applicable law, at the end of the retention period we will delete personal data from our systems and records or take appropriate steps to fully anonymize it.
Cross-Border Transfer of Personal Data
Please be aware that your personal data will be transferred to, processed, and stored in the United States. Data protection laws in the U.S. may be different from those in your country of residence.
When we transfer your personal data out of the European Economic Area (“EEA”) to countries not deemed by the European Commission (“EC”) to provide an adequate level of protection for personal data, including the United States, the transfer will be based on one of the following safeguards recognized by the EC as providing adequate protection for personal data, where required by EU data protection legislation:
- Contracts approved by the EC which impose data protection obligations on the parties to the transfer.
- The EU - U.S. Privacy Shield Framework (for transfers to third parties in the United States that have self-certified to the Framework).
Please contact us if you want further information on the specific mechanism used to transfer your personal data.
Under the GDPR, you have certain rights regarding your personal data. Subject to certain conditions, you may ask us to take the following actions in relation to your personal data:
- Provide you with information about our processing of your personal data and give you access to your personal data.
- Update or correct inaccuracies in your personal data.
- Delete your personal data.
- Transfer a machine-readable copy of your personal data to you or a third party of your choice.
- Restrict the processing of your personal data.
- Object to our processing of your personal data for direct marketing purposes.
- Object to reliance on our legitimate interests as the basis for processing of your personal data.
To request a summary of your personal data, or to request revision or deletion of your personal data, please use our Personal Information Request Form. You will be directed to log in to access the form to verify your identity and prevent fraudulent requests.
If you would like to submit a complaint about our use of your personal data or our response to your requests regarding your personal data, you may contact us by email at email@example.com, by writing to us at our postal address as provided below, or by submitting a complaint to the data protection regulator in your jurisdiction. You can find information about your data protection regulator here.
Seeking Health will review and updated this notice as needed. We recommend visiting this page periodically to be aware of any changes.
How to Contact Us
You can contact us by e-mail sent to firstname.lastname@example.org or by writing to us at the following address:
Seeking Health LLC
3140 Mercer Avenue
Bellingham, WA 98225