Introduction
Welcome to VitalCX ("we," "our," "us"). We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us. It also outlines your rights under the General Data Protection Regulation (GDPR) and how you can exercise those rights.
Data We Collect
We may collect and process the following types of personal data about you:
- Personal Identification Information: Name, email address, phone number, postal address, etc.
- Technical Data: IP address, browser type, operating system, device type, time zone setting, and location data.
- Usage Data: Information on how you use our website, products, and services, including traffic data, weblogs, and other communication data.
- Marketing and Communications Data: Preferences in receiving marketing from us and your communication preferences.
- Special Categories of Data: Information such as health data, biometric data, or data concerning racial or ethnic origin, only processed where necessary and with explicit consent or other lawful grounds.
- Mobile/SMS Information: Mobile phone number, SMS opt-in consent status, consent source, consent date/time, messaging preferences, opt-out requests, and related SMS communication records.
SMS / Mobile Information Privacy
VitalCX may collect mobile phone numbers and related consent information when users opt in to receive SMS messages from us.
Mobile information collected for SMS communications will not be shared, sold, rented, or disclosed to third parties or affiliates for marketing or promotional purposes.
This includes mobile phone numbers, SMS opt-in consent, SMS communication preferences, opt-out requests, and related mobile messaging information.
Mobile information may only be shared with service providers when necessary to deliver the requested SMS communications, support messaging operations, or comply with legal or regulatory requirements. These service providers are not permitted to use mobile information for their own marketing or promotional purposes.
Users may opt out of SMS communications at any time by replying STOP to any SMS message received.
How We Use Your Data
We use the data we collect for the following purposes:
- To Provide Our Services: To manage and maintain our services, including processing transactions and delivering services to you.
- To Communicate with You: To respond to your inquiries, send administrative information such as changes to our terms, conditions, and policies, and provide customer support.
- For Marketing Purposes: To send promotional materials, updates, and special offers that may interest you, subject to your consent.
- To Improve Our Services: To analyze usage data to enhance user experience, improve our services, and develop new features.
- For Legal and Compliance Purposes: To comply with legal obligations, resolve disputes, enforce agreements, and protect our rights and interests.
- To Ensure Security: To monitor and ensure the security of our services and prevent fraud.
- For Targeted Advertising: To show you relevant advertisements based on your interests using Google Analytics and Google Ads, including the use of profiling and automated decision-making.
- For SMS Communications: To send SMS messages to users who have opted in, including service-related messages, alerts, confirmations, reminders, or other communications requested or authorized by the user.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: When you have given us clear consent for specific processing activities.
- Contractual Necessity: To perform a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Where we need to comply with a legal or regulatory obligation.
- Legitimate Interests: Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
Consent Mechanisms
We use a cookie banner that allows you to manage your consent preferences when you visit our website. The banner includes the following categories:
- Essential (Required): These items are necessary to enable basic website functionality and cannot be disabled.
- Personalization: These items allow the website to remember choices you make (such as your username, language, or region) and provide enhanced, more personal features.
- Marketing: These items are used to deliver advertising that is more relevant to you and your interests.
- Analytics: These items help the website operator understand how its website performs, how visitors interact with the site, and whether there may be technical issues.
Your consent is obtained in a manner that is freely given, specific, informed, and unambiguous. You can withdraw your consent at any time by accessing the cookie settings on our website or by contacting us at info@vitalcx.com.
Automated Decision-Making and Profiling
We partner with third-party platforms to better understand your preferences and offer you personalized and relevant content, including advertisements, with your explicit consent:
- Google Analytics: If you choose to allow it, we use Google Analytics to gather data on how you interact with our website. This information helps us improve your experience and enhance our services.
- Google Ads: With your consent to Google Analytics, the insights gained may be used by Google Ads to present you with advertisements that are more relevant to your interests.
These activities may involve automated decision-making to decide which ads are shown to you, based on your online behavior and profile. This will only happen if you have opted into the Analytics category in our cookie settings. You can easily opt-out or adjust your preferences at any time by updating your cookie settings.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our website. These may include:
- Essential Cookies: These items are required to enable basic website functionality and cannot be disabled.
- Personalization Cookies: These items allow the website to remember choices you make (such as your user name, language, or the region you are in) and provide enhanced, more personal features.
- Marketing Cookies: Used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third-party advertisers.
- Analytics Cookies: These items help the website operator understand how its website performs, how visitors interact with the site, and whether there may be technical issues.
You can manage your cookie preferences using our cookie banner, which allows you to accept all, reject all, or select specific categories of cookies. For detailed information about the cookies we use, the purposes for which we use them, and how you can manage your cookie preferences, please see our Cookie Policy.
Data Sharing
We may share your personal data with:
- Service Providers: Third parties who provide services on our behalf, such as payment processing, data analysis, email delivery, hosting services, customer service, and marketing assistance. These service providers are contractually bound to protect your data and to process it only in accordance with our instructions and applicable law.
- Affiliates: Companies within our corporate family to provide our services to you.
- Legal Obligations: To comply with legal obligations, law enforcement requests, or governmental regulations.
- Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company.
- Google: As part of our use of Google Analytics and Google Ads, data may be shared with Google for the purpose of providing targeted advertising.
- Mobile/SMS Information: We do not share, sell, rent, or disclose mobile phone numbers, SMS opt-in consent, SMS communication preferences, opt-out requests, or related mobile messaging information with third parties or affiliates for marketing or promotional purposes.
We ensure that all third parties respect the security of your personal data and treat it in accordance with the law.
International Data Transfers
Our website is hosted on Cloudflare in the United States. As a result, personal data processed through this website may be transferred to, and stored in, the United States.
Where we transfer personal data outside the European Economic Area (EEA), we rely on appropriate safeguards recognized under GDPR, which may include Standard Contractual Clauses (SCCs) approved by the European Commission, to help ensure your data receives a level of protection consistent with EU data protection law.
Data Security
We take the security of your personal data seriously and implement technical and organizational measures designed to protect it against unauthorized or unlawful processing, accidental loss, destruction, or damage. Our security practices include:
- Encryption: Data is encrypted in transit using TLS 1.2/1.3 and at rest using AES-256 encryption.
- Access Controls: Access to sensitive data and systems is restricted to authorized personnel, with multi-factor authentication (MFA), including phishing-resistant methods, enforced across our platform.
- Continuous Monitoring: We maintain continuous security monitoring and automated alerting across our infrastructure, covering application health, cloud resources, databases, and backups.
- Independent Compliance Attestations: We maintain SOC 2 Type II compliance through independent annual audits and, for services involving payment processing, PCI DSS compliance (SAQ D). Our platform also maintains safeguards aligned with HIPAA and HITECH requirements for the protection of health information, including encryption, automatic session timeouts, and audit logging.
- Logging and Incident Response: We retain security and platform logs to support ongoing monitoring and incident investigation, with dedicated audit records retained separately for extended compliance purposes.
These measures are reviewed and updated on an ongoing basis to reflect evolving security standards and threats.
Data Retention
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements, or to resolve disputes. Our data retention practices include:
- Contact Information for Marketing: We retain contact information such as your name and email address for as long as you are subscribed to our communications. If you choose to unsubscribe, we will add your contact information to a suppression list to respect your request.
- Browser Interaction Data: We retain browser interaction data, such as cookies, according to our cookie policy, typically for up to one year from the date of collection or expiry of the cookie.
- Platform and Security Logs: We retain infrastructure and security logs for 90 days on encrypted storage. Immutable audit records are retained separately for six years to support compliance and incident investigation requirements.
For specific questions about the retention periods that apply to other types of data, please contact us at info@vitalcx.com.
Your Rights
Under GDPR, you have several rights regarding your personal data, which we are committed to upholding. You can exercise these rights by contacting us at info@vitalcx.com. We may take steps to verify your identity before complying with your request to protect your privacy and security.
- Right to Withdraw Consent: When we rely on your consent to process your personal data, you have the right to withdraw your consent at any time. Please note that the withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- Right of Access to and Rectification of Your Personal Data: You have the right to request a copy of your personal data that we hold. We will provide this without undue delay, subject to any applicable fees permitted by law. You also have the right to request the correction of inaccurate or incomplete personal data.
- Right to Erasure (Right to be Forgotten): You may request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, if you withdraw your consent, if you object to the processing (and there are no overriding legitimate grounds for processing), or if the processing was unlawful. Your right to erasure is subject to certain limitations under applicable law.
- Right to Data Portability: If we process your personal data based on your consent or a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format. You may also request that we transfer your data to another data controller where technically feasible.
- Right to Restriction of Processing: You can request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or if the processing is unlawful but you oppose erasure. During the restriction period, we will only process your data with your consent or for specific legal reasons.
- Notification of Erasure, Rectification, and Restriction: We will notify any third parties with whom we have shared your personal data about any rectification, erasure, or restriction of processing, unless this is impossible or involves disproportionate effort. Upon request, we will inform you of these third parties.
- Right to Object to Processing: Where we rely on legitimate interests or consent to process your personal data, you have the right to object to this processing at any time. We may continue to process your data if it is necessary for legal claims or other lawful exceptions.
- Automated Individual Decision-Making, Including Profiling: You have the right not to be subject to decisions based solely on automated processing, including profiling, which have legal or similarly significant effects on you, unless certain exceptions apply under relevant Data Protection Laws.
To exercise any of these rights, please contact us at info@vitalcx.com. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights).
Data Breach Notification
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. We will provide you with the nature of the breach, the likely consequences, and the measures we have taken to address it.
Children's Data
Our services are not intended for children under the age of 16, and we do not knowingly collect personal data from children under this age without obtaining parental consent. If we learn that we have collected personal data from a child under the applicable age without verification of parental consent, we will delete that information as quickly as possible.
Right to Lodge a Complaint
If you believe that our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with a supervisory authority, particularly in the EU country where you live, work, or where the alleged infringement took place.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: info@vitalcx.com