PRIVACY POLICY

Medical Design Technologies (“MD Tech”, the “Company”, and/or “We”) values your privacy. In this Privacy Policy (“Policy”), We describe how We collect, use, and disclose information that We may obtain about visitors to the Website, www.mdtech.com and any related sites (together with its subdomains, the “Site” or “Sites”), users/subscribers of MD Coder, MD Message and MDTech’s other interactive applications, and the services related to the foregoing (collectively, the “Services”).

By using the Services and/or Sites, you agree to the terms and conditions of this Policy. You should also read this Policy with the terms and conditions associated with the use of the Services and/or Sites found at www.mdtech.com/terms.

Persons with disabilities may obtain this notice in alternative format upon request by contacting us at the number listed below.

PLEASE READ THIS PRIVACY POLICY CAREFULLY BEFORE USING THE SERVICES AND/OR SITES. IF YOU DO NOT ACCEPT THIS PRIVACY POLICY, DO NOT USE THE SERVICES AND/OR SITES. When you use the Services and/or Sites, you understand that We may collect, use, and disclose technical data and related information about you in various ways in accordance with this Privacy Policy.

By accessing or using the Services and/or Sites, you expressly accept all of the provisions of this Privacy Policy and the Terms of Service and represent to us that you are at least 18 years of age, are located in and accessing the Services and/or Sites from the United States, and are legally competent to enter into and agree to both the Privacy Policy and Terms of Service.

We reserve the right, at Company’s sole discretion, to modify or replace this Privacy Policy at any time in accordance with the ‘Changes to Company’s Privacy Policy’ section below. If you have questions about this Privacy Policy, please contact Company per the information listed in ‘Contact Information’ below.

United States Only

The Services and/or Sites are intended solely for users located in the United States and its territories, and this Policy is drafted to comply with United States federal and state privacy law. We do not offer or direct the Services and/or Sites to individuals located outside the United States, and We do not knowingly collect personal information from individuals located outside the United States.

All information We collect is stored and processed on servers located in the United States. If you access the Services and/or Sites from outside the United States, you do so on your own initiative and at your own risk, and you understand that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those of your jurisdiction. We make no representation that the Services and/or Sites, or this Policy, comply with the data protection laws of any jurisdiction outside the United States, including the European Union General Data Protection Regulation (“GDPR”) or the United Kingdom GDPR. Individuals located outside the United States should not use the Services and/or Sites or submit any personal information to us.

Information We Collect and How We Collect It

We collect information from and about users of the Services and/or Sites:

Information You Provide

When you use the Services and/or Sites, We may ask you to provide certain personal information such as name, address, e-mail address, location, and/or telephone number (“Personal Information”). This information includes, but is not limited to:

Information That May Be Automatically Collected

IF YOU DO NOT WANT MD TECH TO COLLECT AND STORE USAGE DATA OR INPUT DATA, DO NOT DOWNLOAD OR USE THE SERVICES AND/OR SITES OR DELETE IT FROM YOUR DEVICE AND STOP USING THE SERVICES AND/OR SITES. The Services and/or Sites may use technology to automatically collect certain information, including but not limited to:

Information Collection and Tracking Tools

The technologies We use for automatic information collection may include, but are not limited to:

Information Third Parties Provide About You

We may, from time to time, receive information about you from third-parties for various purposes, including enhancing MDTech’s ability to serve you, tailoring MDTech content to you and offering you opportunities that may be of interest to you.

Protected Health Information

We may receive, transmit, create or maintain certain patient health information, that is subject to certain applicable privacy and confidentiality laws, including without limitation the Health Insurance Portability and Accountability Act of 1996 and its regulations (“HIPAA”). In addition, We are a Business Associate of some users of the Services and/or Sites and are bound by certain contractual and regulatory duties to safeguard any such information.

How We Use Your Information

We use information that We collect about you or that you or a third-party provides to MDTech, including any personal information, to perform certain functions such as:

The usage information We collect helps us to improve Company Services and/or Sites and to deliver a better and more personalized experience by enabling us to:

Disclosure of Your Information

We may disclose aggregated information about Company users, and information that does not identify any individual. In addition, in compliance with applicable law, We may disclose personal information that We collect or you provide:

We do not disclose any personal information to any third-party for marketing purposes.

Your Choices about Company’s Collection; Use and Disclosure of Your Information

We strive to provide you with choices regarding the personal information you provide to Company. This section describes mechanisms We provide for you to control certain uses and disclosures of your information.

Data Security

We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, and disclosure. The safety and security of your information also depend on you. Where We have given you (or where you have chosen) a password for access to certain parts of the Services and/or Sites, you are responsible for keeping this password confidential. Pursuant to various state and federal laws, We may be required to send you notice of security breaches or suspected security breaches that impact your personal information and protected health information. We will send you any security breach notices to the email address contained in your account information or that We otherwise have on file.

Data Retention

We retain your information only for as long as necessary to fulfill the purposes described in this Policy, to provide the Services and/or Sites to you, and to comply with Company’s legal, regulatory, and contractual obligations. Company’s retention periods reflect, among other requirements, applicable state medical record retention laws, the recordkeeping requirements of HIPAA and its implementing regulations, and Company’s obligations under its Business Associate Agreements. Company’s retention periods for each category of information are as follows:

When a retention period expires, We delete the applicable information or de-identify it so that it can no longer reasonably be associated with you. We may retain information for longer than the periods stated above only where We are required or permitted to do so by law, or where retention is necessary to comply with a legal obligation, respond to a government or regulatory request, preserve information subject to a litigation hold or lawful preservation request, resolve a dispute, detect or prevent fraud or abuse, or enforce Company’s agreements. Information retained for these reasons is deleted once the applicable obligation or purpose has ended.

Backup and archival copies of your information may persist for a limited period after deletion from Company’s active systems, and are purged on Company’s regular backup rotation schedule, which does not exceed ninety (90) days.

You may request deletion of your personal information at any time by contacting us using the details listed in ‘Contact Information’ below. We will honor such requests except where We are required or permitted by law to retain the information, or where it constitutes protected health information that We are obligated to retain under HIPAA or a Business Associate Agreement. If We cannot fulfill your request in whole or in part, We will explain why in Company’s response. California residents should also see the ‘Right to Request Deletion of Information’ section below.

Children and Minors

The Services and/or Sites are intended solely for individuals who are at least 18 years of age. They are not directed at children, and We do not knowingly collect personal information from anyone under 18 years of age, nor do We knowingly permit such individuals to register for or use the Services and/or Sites. If We learn that We have collected or received personal information from an individual under 18 years of age, We will delete that information as quickly as reasonably practicable. If you believe We might have any information from or about an individual under 18 years of age, please contact us as provided below.

Changes to Company’s Privacy Policy

We may update Company’s Privacy Policy from time-to-time. If We make material changes to how We treat Company’s users’ personal information, We will post the new Privacy Policy on this page.

California Residents

See our Addendum to this Policy for such residents.

Contact Information

To ask questions about this Privacy Policy or Company’s privacy practices, contact us at compliance@mdtech.com

For California Residents To The Extent That The California Consumer Privacy Act applies to the Company:

This Privacy Policy Addendum supplements the and describes additional rights of residents of the State of California.

California Consumer Privacy Act:

The California Consumer Privacy Act (“CCPA”) provides California residents with rights to receive certain disclosures regarding the collection, use, and sharing of “Personal Information,” as Well as rights to know/access, delete, and limit sharing of Personal Information. The CCPA defines “Personal Information” as “information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.” Certain information We collect may be exempt from the CCPA because it is considered public information (i.e., it is made available by a government entity) or covered by a specific federal privacy law, such as the Health Insurance Portability and Accountability Act.

To the extent that We collect Personal Information that is subject to the CCPA, that information, Company’s practices, and your rights are described below.

Right to Notice at Collection Regarding the Categories of Personal Information Collected.

You have the right to receive notice of the categories of Personal Information We collect, and the purposes for which those categories of Personal Information will be used. The categories We use to describe the information are those specified in the CCPA.

We may use any of the categories of information listed above for other business or operational purposes compatible with the context in which the Personal Information was collected.

Right to Know/Access Information.

You have the right to request access to Personal Information collected about you over the past 12 months and information regarding the source of that information, the purposes for which We collect it, and the third-parties and service providers with whom We share it. You may submit such a request as described below. To protect Company’s users, We are required to verify your identity before We can act on your request.

Right to Request Deletion of Information.

You have the right to request in certain circumstances that We delete any Personal Information that We have collected directly from you. You may submit such a request as described below. To protect our users, We are required to verify your identity before We can act on your request. We may have a reason under the law why We do not have to comply with your request, or why We may comply with is in a more limited way than you anticipated. If We do, We will explain that to you in Company’s response.

How to Submit a Request.

You may submit a request to exercise your rights to know/access or delete your Personal Information through any of the following means:

(1) By sending an email to compliance@mdtech.com

(2) By calling 1-888-253-8813

Only you or your authorized agent may make a verifiable consumer request related to your personal information. If you use an authorized agent to submit a request on your behalf, We may require that you (1) provide the authorized agent written permission to do so, and (2) provide a copy of the authorization or provide a copy of a power of attorney that complies with state law so that We can verify the identity of the authorized agent.

If We suspect fraudulent or malicious activity on or from the password-protected account, We may decline a request or request that you provide further verifying information.

You may only make a verifiable consumer request twice within a 12-month period. Making a verifiable consumer request does not require you to create an account with the Company. We will only use personal information provided in a verifiable consumer request to verify your identity or authority to make the request. Right to Opt Out of Sale of Personal Information to Third Parties.

You have the right to opt out of any sale of your Personal Information. We do not sell information to third-parties.

Right to Information Regarding Participation in Data Sharing for Financial Incentives.

You have the right to be free from discrimination based on your exercise of your CCPA rights. We do not discriminate against anyone who chooses to exercise their CCPA rights.