Privacy policy

Reviewed and Updated: December 13, 2022

It is the commitment of ADHERA HEALTH to inform the Website Users of its policy regarding the treatment and protection of the personal data of Users and clients that it collects from them when viewing the Website or the offered services.

By personal data, it is understood any numerical, alphabetical, graphic, photographic, acoustic information or of any other type concerning identified or identifiable natural persons.

WHO IS RESPONSIBLE FOR THE PROCESSING OF PERSONAL DATA?

In accordance with the provisions of the California Consumer Privacy Act (CCPA) of 2018 [1798.100 – 1798.199.100], the General Data Protection Regulation (EU) 2016/679 (GDPR), and other regulations in force regarding the protection of personal data, we inform you that the personal data that you may provide during the use of the Website www.adherahealth.com (hereinafter, "the Website") will be treated as data controlled by ADHERA HEALTH, with registered office at 101 Cooper St. Santa Cruz, CA 95060, United States of America.

ADHERA HEALTH will only be responsible and will guarantee the confidentiality and security of the personal data processed by ADHERA HEALTH for the purposes specified in this document, not having any type of responsibility regarding the processing and subsequent uses of the personal data that may be carried out by third-party service providers of the information outside the Website.

ARE YOU OBLIGED TO PROVIDE YOUR PERSONAL DATA?

Visiting the Website does not imply that the User is obliged to provide any personal data. However, the use of some of the services available on the Website depends on the completion of personal data forms and the use of cookies.

The data collected through the different forms on the Website are fair and necessary for the provision of the requested services. The refusal to provide the data indicated as necessary implies the impossibility of adequately providing said services. Equally, the User may provide data on a voluntary basis in order that these services can be optimally provided.

WHAT DO WE USE YOUR PERSONAL DATA FOR?

The personal data provided by the User for the provision of the different services made available through the Website will be processed by ADHERA HEALTH in accordance with the following purposes:

  • In the case of subscribing to the newsletter, the purpose is to keep subscribers informed of opportunities in the services provided by ADHERA HEALTH and other information related to the latter.

  • In the case of the contact form, the purpose is to respond to the query made about the services provided by ADHERA HEALTH.

  • We inform you that certain functionalities of the Website depend on the use of cookies, so in the event that you have not denied the possibility of their use, certain information related to your use of the Website will be processed. The conditions for its use are available in the "Cookie Policy".LINK

WHAT IS THE LEGITIMACY OF THE PROCESSING OF YOUR DATA?

The treatment of your personal data by ADHERA HEALTH is covered by your request for the services made available to you through the Website or, where appropriate, in the consent that is requested for the purposes determined above and that you can withdraw at any time. However, in the event of revoking consent, this circumstance does not affect the legality of the processing carried out previously.

WHAT DATA CATEGORIES ARE PROCESSED?

The personal data necessary for the provision of the different services available on the Website will be those indicated in the corresponding form enabled for this purpose.

In any case, the categories of data that are processed are:

  • Identification data: name, email address, telephone.

  • Employment details data: company name.

FOR HOW LONG WILL ADHERA HEALTH KEEP PERSONAL DATA?

Your data will be kept as long as they are necessary for the purpose for which they were collected and during the legally required periods for possible derived responsibilities.

TO WHICH RECIPIENTS WILL THE USER DATA BE COMMUNICATED?

The personal data provided by the User will not be communicated to third parties, unless this is necessary for the provision of the requested services, when the User has expressly accepted their communication or when they are transferred to affiliates of the group in accordance with the stipulated purpose.

WHAT RESPONSIBILITY DOES THE USER HAVE?

You will be responsible for ensuring that the data you provide to ADHERA HEALTH is true, accurate, complete, and up to date. For these purposes, you will be responsible for the veracity of all the data that you communicate and must keep the information provided duly updated, in such a way that you are responsible for your real situation.

Equally, you will be responsible for the false or inaccurate information that you provide through the Website and for the data and damages, direct or indirect, that this causes to ADHERA HEALTH or to third parties.

WHAT RIGHTS DOES THE USER HAVE?

The exercise of the rights by the User is free and can be done at any time, having to send a written communication, together with a valid identification that proves the identity of the User, to the following address: Adhera Health Inc., 1101 Cooper St. Santa Cruz, CA 95060, United States of America, or by email info@adherahealth.com.

The rights you can exercise are:

  • Revoke consent to treatments.

  • Access your personal data.

  • Rectify inaccurate or incomplete data.

  • Request the deletion of your data when, among other reasons, the data is no longer necessary for the purposes for which it was collected.

  • Obtain from ADHERA HEALTH the limitation of the treatment when any of the conditions provided in the data protection regulations are met.

  • Request the portability of your data.

ADHERA HEALTH informs Users that the exercise of these rights is highly personal, so that only the User her/himself may exercise said rights with respect to the personal data of which s/he is the legitimate owner. However, and in cases where it is exceptionally allowed, the authorized representative of the User may exercise the rights that assist her/him in the terms set forth, provided that the aforementioned communication is accompanied by the document certifying such representation.

ADHERA HEALTH informs that the exercise of the aforementioned rights by a third party not legally authorized by the User, could entail the commission of the crime of discovery and disclosure of secrets provided for by the Criminal Code; Without prejudice to other consequences that should be faced as a result of any civil or administrative actions to which both the legitimate User who owns the personal data, as well as ADHERA HEALTH, have the right.

IS IT SAFE TO PROVIDE PERSONAL DATA?

ADHERA HEALTH will treat personal data at all times in an absolutely confidential manner and keep the mandatory duty of secrecy with respect to them, in accordance with the provisions of the applicable regulations, adopting for this purpose the necessary technical and organizational measures that guarantee the security of your data and avoid its alteration, loss, treatment or unauthorized access, taking into account the state of technology, the nature of the stored data and the risks to which they are exposed.

CAN THE PRIVACY POLICY CHANGE?

ADHERA HEALTH reserves the right to modify this Privacy Policy in order to adapt it to new legislation that may be appropriate. In these cases, and if it is mandatory, the changes introduced will be announced on the Website and/or via email with reasonable anticipation of their implementation.

RECOMMENDATIONS TO USERS

ADHERA HEALTH recommends that Users use the latest versions of computer programs given the incorporation in these of greater security measures.

Equally, ADHERA HEALTH recommends that Users use the security mechanisms available to them (secure Web servers, cryptography, digital signature, firewall, etc.) to protect the confidentiality and integrity of their data to the extent that it is necessary, since there are risks of impersonation or violation of communication.

ADHERA HEALTH reminds Users that the Internet is not always as safe as we would like, so they must adopt the necessary and appropriate technical measures in order to avoid the unauthorized processing of their data.

ADHERA HEALTH warns Users that whenever they provide personal information over the Internet through email, newsgroups, discussion forums, etc., keep in mind that such information may be collected and processed for purposes not desired by Users, by what ADHERA HEALTH recommends that Users inform themselves about the confidentiality and privacy policies of the online sites they visit.

ADHERA HEALTH advises Users to keep in mind that, unless they use encryption mechanisms, email on the Internet is not secure. Email messages and discussion forums can be subject to spoofing and impersonation, which should be taken into account whenever they are used. If you do not want to publish your email address, configure your browser so that it does not leave your email address on the web servers that you access.

Information Security (IS) policy

Reviewed and Updated: September 18, 2023

The Management of Adhera Health recognizes the importance of identifying and protecting its information assets, avoiding the destruction, disclosure, modification, and unauthorized use of all information related to customers, employees, prices, knowledge bases, manuals, case studies, source codes, strategy, management, and other concepts; committing itself to develop, implement, maintain, and continuously improve the Information Security Management System (ISMS).

Information Security is based on the preservation of:

  • its confidentiality, ensuring that only those who are authorized can access the information;

  • its integrity, ensuring that the information and its processing methods are accurate and complete;

  • its availability, ensuring that authorized users have access to the information and its associated assets when it is required. Information security is achieved by implementing an appropriate set of controls, such as policies, practices, procedures, organizational structures, and software functions. These controls have been established to ensure that the company's specific security objectives are met.

Adhera Health IS policy establishes that:

  • Information Security objectives are established annually.

  • A risk analysis process is developed and, according to its results, the corresponding actions are implemented to deal with the risks considered unacceptable, according to the criteria established in the IS Management Manual.

  • Thus, corresponding controls are established, in accordance with the needs arising from the risk analysis process.

  • Business, legal or regulatory requirements and contractual security obligations are met.

  • Information security awareness and training is provided to all personnel.

  • The necessary means are established to guarantee the continuity of the company's business.

  • Any violation of this policy and of any ISMS policy or procedure will be sanctioned.

  • Every employee is responsible for recording and reporting confirmed or suspected security violations.

  • Every employee is responsible for preserving the confidentiality, integrity, and availability of information assets in compliance with this policy and the policies and procedures inherent in the ISMS.

  • The Quality and Compliance Manager is directly responsible for maintaining this policy by providing advice and guidance on its implementation, as well as investigating any reported violations by staff.