Vitality Access Privacy Policy

Version: 2.0 (Draft for Legal Review)

Effective Date: [To be inserted before launch]

Last Updated: [To be inserted before launch]

This draft is provided for internal review and is not a substitute for advice from qualified privacy counsel. Sections addressing HIPAA, state health-data laws, and international transfers in particular should be confirmed against your actual data flows, business-associate relationships, and jurisdictions of operation before publication.

1. Purpose and Scope

This Privacy Policy explains how Vitality Access LLC ("Vitality Access," "we," "our," or "us") collects, uses, stores, shares, and protects information when individuals use our website, mobile application, and related services (collectively, the "Platform"). Vitality Access operates a marketplace and booking platform that connects users ("Users") with independent, third-party healthcare providers ("Providers"), including in connection with international medical travel.

Vitality Access is not a healthcare provider. We do not practice medicine, provide medical advice, diagnose or treat any condition, or maintain a treatment relationship with Users. Providers identified through the Platform are independent businesses responsible for their own care decisions and their own compliance obligations, including as applicable under the U.S. Health Insurance Portability and Accountability Act ("HIPAA") or comparable foreign laws.

Our role with respect to health information you share through the Platform (for example, to describe symptoms, request a procedure, or share records with a Provider) is that of a facilitator and, in some cases, a service provider or business associate to a Provider. Section 4 explains this distinction in more detail.

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email, phone number, date of birth, password, and government ID where required for identity verification.
  • Booking information: appointment details, procedure or service requested, preferred Provider or destination, and travel-coordination details for international bookings.
  • Health information: information you choose to share to facilitate a booking or consultation, such as symptoms, medical history, current medications, allergies, prior procedures, or uploaded medical records and images.
  • Payment-related information, processed through PCI-compliant third-party payment processors; we do not store full payment card numbers.
  • Communications with us, with Providers through the Platform, and with customer support, including recordings or transcripts where legally permitted and disclosed.
  • Any other information you voluntarily submit, such as reviews, survey responses, or support tickets.
  • 2.2 Information Collected Automatically

  • Device and usage information: IP address, device identifiers, browser type, operating system, pages viewed, and referral source.
  • Cookies and similar technologies, described further in Section 10.
  • Approximate location derived from IP address, and precise location only if you separately grant permission (for example, to find nearby Providers).
  • 2.3 Sensitive and Special Category Information

    Health information described in Section 2.1, along with any government ID or precise location we collect, is treated as sensitive personal information (or "special category data" under the UK/EU GDPR, and "sensitive personal information" or "consumer health data" under applicable U.S. state laws). We collect this information only where necessary to facilitate a booking or provide the service you request, and we apply the heightened safeguards described in Section 6.

    We do not use health information for advertising, do not sell it, and do not share it for cross-context behavioral advertising. Where required by law, we obtain your explicit consent before collecting or sharing sensitive information, and you may withdraw that consent as described in Section 8.

    3. Legal Bases for Processing (EEA, UK, and Similar Jurisdictions)

    Where the UK/EU GDPR or a similar law applies, we rely on one or more of the following legal bases for each processing activity:

  • Performance of a contract: to create your account, process a booking, and provide the Platform.
  • Explicit consent: to process health information, to send marketing communications where consent is required, and for any processing where law requires consent.
  • Legitimate interests: to secure the Platform, prevent fraud, and improve our services, balanced against your rights and only where consent or contract is not the appropriate basis.
  • Legal obligation: to comply with tax, accounting, anti-fraud, or regulatory requirements.
  • You may withdraw consent at any time as described in Section 8, without affecting the lawfulness of processing carried out before withdrawal.

    4. How We Use Information

    We use information to: create and maintain accounts; facilitate and coordinate bookings, including international medical travel logistics; enable communication between Users and Providers; process payments; provide customer support; detect, investigate, and prevent fraud and abuse; comply with legal and regulatory obligations; maintain the security and integrity of the Platform; and, where permitted or with your consent, send service updates and marketing communications.

    4.1 Automated Processing

    We may use automated tools to match Users with Providers based on stated needs and location, to flag potentially fraudulent bookings, or to personalize search results. These tools support, but do not replace, human review for any decision that would meaningfully affect your access to the Platform (such as an account suspension). You may request human review of such a decision by contacting us using the details in Section 14.

    5. Our Role Regarding Health Information; HIPAA

    Because Providers are independent businesses, whether HIPAA applies to a given piece of health information depends on who collected it and in what capacity:

  • Information a Provider collects directly from you as part of diagnosis or treatment is generally governed by that Provider's own HIPAA Notice of Privacy Practices (if the Provider is a HIPAA-covered entity) or by the data-protection law of the Provider's jurisdiction.
  • Information you submit through the Platform to facilitate a booking (for example, in an intake form) may make us a "business associate" of a Provider under HIPAA for that specific data, in which case we handle it under a business associate agreement and HIPAA's applicable requirements.
  • Where we are not acting as a business associate, health information you provide is protected under this Policy and, where applicable, state consumer health data laws such as Washington's My Health My Data Act or comparable laws in other states.
  • If you have questions about which framework applies to information you have shared, contact us using the details in Section 14 and we will clarify.

    6. Data Security

    We use administrative, technical, and organizational safeguards designed to protect personal information, calibrated to its sensitivity. For health information and government ID, these include encryption in transit and at rest, role-based access controls limiting internal access to personnel with a legitimate operational need, and logging of access to sensitive records. No system is completely secure, and we cannot guarantee absolute security.

    6.1 Security Incident Notification

    If we become aware of a breach of security that compromises personal information in a manner requiring notice under applicable law, we will notify affected Users and any relevant regulator within the timeframes required by law, and will describe the nature of the incident and the steps we are taking in response.

    7. Sharing Information

    We do not sell personal information, and we do not share health information for cross-context behavioral advertising. We may share information with:

  • The Provider(s) you select or request, to the extent necessary to facilitate your booking or care coordination.
  • Payment processors, to complete transactions.
  • Cloud hosting, analytics, and communications vendors, acting as our service providers under contractual confidentiality and security obligations.
  • Professional advisers such as auditors, insurers, and legal counsel.
  • Regulators or law enforcement, where required by valid legal process.
  • A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to that entity's assumption of the commitments in this Policy.
  • Any vendor that processes health or other sensitive information on our behalf is bound by contract to use it only to provide services to us and to apply security measures consistent with Section 6.

    8. Your Privacy Rights

    8.1 General Rights

    Depending on applicable law, you may have the right to: access the personal information we hold about you; correct inaccurate information; delete information, subject to legal retention requirements; obtain a portable copy of information you provided; object to or restrict certain processing; and withdraw consent for marketing or for processing based on consent, without affecting prior lawful processing.

    8.2 California and Other U.S. State Rights

    If you are a California resident, the CCPA/CPRA gives you the right to know the categories and specific pieces of personal information we have collected, the categories of sources, and the categories of third parties with whom we share it; the right to delete and to correct personal information; the right to opt out of "sharing" for cross-context behavioral advertising (we do not engage in this practice); the right to limit use of sensitive personal information, including health information, to purposes necessary to provide the service you requested; and the right not to receive discriminatory treatment for exercising these rights. Residents of other states with comprehensive privacy laws (for example, Colorado, Connecticut, Virginia, or similar laws) have analogous rights, which we honor in the manner required by the applicable state law.

    8.3 EEA/UK Right to Complain

    If you are located in the EEA or UK, you have the right to lodge a complaint with your local data protection supervisory authority, in addition to any rights you exercise directly with us.

    8.4 Exercising Your Rights

    To exercise any of these rights, contact us using the details in Section 14. We will verify your request using information reasonably necessary to confirm your identity and will respond within the timeframe required by applicable law.

    9. International Data Transfers

    Because Vitality Access facilitates international medical travel, information necessary to coordinate a booking may be transferred to Providers or service providers located outside your home country, including countries that may not have data protection laws equivalent to your own.

    Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on recognized transfer mechanisms, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), an applicable adequacy decision, or another lawful transfer mechanism, together with additional safeguards where required. You may request a copy of the relevant safeguard by contacting us using the details in Section 14.

    10. Data Retention

    We retain personal information only as long as reasonably necessary for the purposes described in this Policy. As general guidelines, absent a longer legal, tax, accounting, or dispute-resolution requirement:

  • Account and booking information is retained for the duration of your account plus a limited period thereafter to address disputes and legal claims.
  • Health information shared to facilitate a booking is retained only as long as necessary to complete that booking and any associated support or dispute process, after which it is deleted or de-identified.
  • Payment records are retained as required by applicable tax and accounting law.
  • Marketing preferences and consent records are retained to demonstrate compliance with consent requirements.
  • [Operational note: insert specific retention periods, e.g., number of months or years for each category, once finalized with the retention schedule.]

    11. Children's Privacy

    Vitality Access is intended only for individuals who are at least 18 years old, and the Platform is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete it promptly. If you believe a child has provided us with information, contact us using the details in Section 14.

    12. Cookies and Analytics

    We use cookies and similar technologies to operate the Platform, remember preferences, measure performance, and, where you consent, personalize content. Where required by law, we present a cookie banner allowing you to accept or reject non-essential cookies before they are set. You may also manage cookies through your browser settings; blocking essential cookies may affect Platform functionality.

    13. Third-Party Services

    The Platform may link to third-party websites or services, including Provider websites. Their privacy practices are governed by their own policies, and we encourage you to review those policies before submitting information to them.

    14. Contact Us

    If you have questions about this Policy or wish to exercise your privacy rights, contact us at:

    Vitality Access LLC

    Email: privacy@vitalityaccess.com

    Website: vitalityaccess.com

    [Operational note: add a mailing address, and, if required by your processing scale or jurisdictions served, the name/contact of a Data Protection Officer and/or EU/UK representative.]

    15. Changes to This Policy

    We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. We will post the updated Policy on the Platform with a new "Last Updated" date, and will provide additional notice (such as email or an in-app notice) for material changes, particularly those affecting how we handle health information.