Information from Other Sources.
We combine your Personal Information with data from the following third-party sources:
Third-Party Data Sources
- Health and medical data providers who provide aggregated health and medical claims data, diagnostic and treatment information, and related health data.
- Data providers, including data licensors and data brokers.
- Consumer data providers who provide data enrichment, audience modeling, and enhanced targeting capabilities.
- Data management platforms that securely transfer audience segments and facilitate data distribution.
- Research partners, including universities, non-profit organizations, and companies, for research and advocacy purposes.
- Service providers, including IT, analytics, advertising, ad networks, lead generation, and customer data platforms.
- Public records or widely available sources, such as government records.
- Social networks, such as Meta or Google, when you connect third-party network accounts to sign into the Services.
Information of Healthcare Professionals (HCPs).
We also have advertising Services for our partners who want to reach medical professionals. Depending on how you use the Services, you may directly provide us with your National Provider Identifier (NPI), job title, professional qualifications, certifications and credentials, medical license number, specialty or area of practice, and affiliation with a medical facility or organization.
Combining Professional and Personal Data: We maintain a proprietary database of HCPs and may combine that professional information (like your specialty or NPI number) with information about your online activity to show you relevant medical-related ads. This allows us to reach you in both your professional (“white coat”) and personal (“blue jean”) moments.
User Trends Inform HCP Ads: We may analyze anonymized, high-level trends from our patient communities to help optimize the advertising shown to HCPs. For example, if we see a surge of User interest in a new type of treatment, we may use that insight and information from medical claims data to inform marketing campaigns directed at relevant medical specialists. We collect professional information about licensed U.S. HCPs from public sources and third-party data providers. Where required by law or contract, we may also process and share HCP compensation data to facilitate our clients’ compliance with legal obligations, such as the Physician Payments Sunshine Act or Open Payments (42 U.S.C. § 1320a-7h).
Information of Health or Patient Leaders.
Our relationship with Health and Patient Leaders is governed by a separate agreement and Supplemental Terms of Use. Health and Patient Leaders may provide us with their resume, curriculum vitae, education details, social media channels, and certification information. As part of that partnership, we collect any data related to our Health Leader Certification Program, Social Health Network community, and Patient Leadership Council.
How We Use Your Personal Information.
The Appendix Chart provides a comprehensive overview of how we use your Personal Information. We (or our service providers acting on our behalf) use your Personal Information for the following business purposes and as otherwise described when we collect it.
Provide, Maintain, and Improve the Sites and Services. We use your Personal Information to:
- Provide the Sites and Services.
- Create and manage accounts, User Site profiles, and Site experiences.
- Respond to your communications, contact you if necessary or requested, and send you information about Health Union, our Sites, or Services.
- Send you communications such as announcements, updates, security alerts, password resets, support, and other administrative messages. Health Union sends communications via email, Site or social media message or notification, text or SMS message, telephone, and direct mail.
- Administer promotions, events, giveaways, and awards, which may include sharing your contact information and address information to fulfill a prize or award.
Research and Development. We use your Personal Information to:
- Operate and test the Services. For example, conducting surveys, market research, managing communications, and analyzing our current Services, products, and promotions.
- Develop, market, sell, or provide the Services, which include providing tailored advertisements on the Services and other websites.
- Send you communications about opportunities to participate in research surveys, panel interviews, paid clinical trial opportunities, and more.
A Note on Our Research and Insights Offerings.
Our research, such as the “In America” survey and other projects on our Insights Offerings page, is one of the most important ways we gather insights. Your participation in these surveys is voluntary. Your participation helps us, our partners, and the health community better understand the real-world patient experiences. We use anonymized, aggregated research data for insights and to inform our Services.
It is important for you to know that the information from these surveys is a direct and primary source of the Zero-Party Data that fuels our data analysis and audience development capabilities. The data is analyzed to develop the custom advertising programs and audience segments we’ve described within this Notice.
We also conduct market research on behalf of our clients and customers, which may offer a paid incentive for your time. These research opportunities will be clearly labeled as “on behalf of a sponsor” and will have a separate and specific notice for obtaining your consent.
Security and Legal Compliance. We use your Personal Information to:
- Detect and protect against fraud, errors, or criminal activity.
- Prevent, detect, and investigate security incidents and possibly illegal or prohibited activities.
- Protect the rights, property, and safety of you, Health Union, or another party.
- Resolve disputes and respond to claims that a post or other content violates third-party rights.
- Meet our legal obligations and maintain internal organization functions, such as for compliance, tax purposes, or for an audit.
Marketing and Advertising. We use your Personal Information to:
- Direct Marketing Communications.
We use your Personal Information to send you direct marketing communications via physical or electronic mail. These communications may include news, updates, and other relevant information relating to our Services.
You can opt out of receiving marketing emails by clicking the unsubscribe link included at the bottom of our marketing communications, emailing privacy@health-union.com, or updating your communication preferences in your account profile settings.
Even if you opt out of marketing communications, we will continue to send you essential non-marketing communications related to your account, transactions, or legal notices.
- Site or Community Notifications.
If you choose to create an account or join the Site community, we use your Personal Information to send you notifications about Site activity, such as when another User replies to your post or interacts with you on the Site. Site notifications are sent by email and received on-site.
To customize your Site notification settings, visit the notifications settings section of your user profile. You can also unsubscribe from these Site emails by clicking the unsubscribe link at the bottom of the email or by emailing helpdesk@health-union.com.
IMPORTANT: The following information regarding Interest-Based Advertising does not apply to Users located in the European Union (EU) or European Economic Area (EEA). In compliance with EU privacy laws including GDPR, Health Union does not use cookies, beacons, or similar tracking technologies for targeting or advertising purposes for Users we know to be in the EU/EEA.
Interest-Based Advertising. We use your Personal and Non-Personal Information to:
- Facilitate and display contextual advertisements from third parties on our Sites and Services.
- Engage in targeted advertising on other websites or mobile applications, even if those websites or mobile applications are owned by third parties.
Health Union supports our Site communities through advertising partnerships with other companies. This advertising revenue enables us to offer our communities to you at no cost.
Interest-based advertising (also known as “personalized,” “tailored,” or “targeted” advertising) uses previously collected data about a person, web browser, or device to create customized advertisements based on your interests and preferences. These ads use User attributes, preferences, interests, or intent linked to or inferred about that User, browser, or device. These advertisements can appear on various websites, applications, or devices.
We may use consumer data obtained from data brokers, marketing vendors, and other third-party data providers to supplement the Personal Information you provide to us. We use this combined information for marketing and interest-based advertising services, data services, insights offerings, community sponsorships, influencer marketing solutions, sponsored community content, and health advocate partnerships. We may also provide aggregated or de-identified patient experience insights through these offerings.
This section describes how and why we share Personal Information with third parties. To see all the categories of information we share or disclose, please refer to our Appendix Chart.
To provide our Services and deliver relevant advertising, we partner with various third parties as described below:
- Service Providers: We use third-party vendors to help operate our business and provide, maintain, and improve the Sites and Services. We provide these vendors access to your Personal Information to perform specific tasks on our behalf. These services include i) website hosting and cloud storage, ii) IT and data analytics, iii) system administrators, iv) consent management, and v) payment processors. We also use service provider technologies that allow us to provide certain features through our Sites or Services, such as video, podcasts, or chat technologies.
- Individuals or Other Parties with Your Consent: We share your information with other parties that you identify through our Sites or Services, at your direction or request. For example, if you request information about a clinical trial, we will share your Personal Information with the clinical trial sponsor as necessary to facilitate your request.
- Other Users of our Services. If you choose to post content or engage in our Site communities or Social Health Network, forums, social media pages, or in connection with other community-based features. Our Sites are publicly viewable. Use caution when posting and sharing your Personal Information.
- Business Partners: Our business partners, including pharmaceutical and life science companies, medical device manufacturers, healthcare organizations, and other companies operating in the healthcare industry with whom we share information to provide sponsored content, educational resources, and research insights relevant to your health condition.
- Marketing and Advertising Service Providers: We use third-party vendors, such as email marketing platforms, customer relationship management providers, Google Analytics, Meta and LinkedIn to i) assist with lead generation, ii) host information relating to customers and business partners and potential customers or business partners, iii) marketing automation, iv) advertisement placement and targeting, and v) marketing campaigns and communications.
- Ad Network Partners: To deliver relevant advertising on other websites, applications, and platforms, we share the audience segments we create with a wide range of third-party advertising and technology partners. We do not share your name or email address for these purposes without your explicit consent, but we do share technical identifiers (such as cookie IDs, mobile ad IDs, or hashed email addresses) linked to your inferred interests and health-related characteristics.
Our network of partners includes the following categories which we periodically review and update to reflect our current business relationships. The specific partners within these categories may change from time to time without requiring an update to this Privacy Notice:
-
- Data Management Platforms (DMPs): Services that help us securely transfer our audience segments to the broader advertising ecosystem.
- Demand-Side Platforms (DSPs) and Ad Exchanges: Technology platforms that advertisers use to purchase and manage ad placements across the internet.
- Social Media Platforms: To deliver interest based advertising and content within their networks.
- Connected TV (CTV), Online Video, and Audio Platforms:To show relevant ads on streaming services and other digital media channels.
- Analytics and Measurement Partners:
- To ensure the accuracy and relevance of the audience segments we create, we work with specialized data partners to verify our information. This process involves comparing the information we hold with external data sources, such as de-identified medical claims data, to confirm that our audience segments meet the quality standards required by our advertising partners.
- Analytics partners help us and our clients measure the effectiveness of our advertising campaigns and Services. We use data analytics to perform specific analyses on Site and client customer data, understand traffic and usage patterns, track marketing conversions, optimize our Sites, and identify potential new customers or Users. We also use business intelligence and visualization platforms to process and visualize our data for internal analysis.
- Affiliates, Related Entities, Investors, and Operational Partners: As stated above, when you interact with a Health Union Site or Service, we make your Personal Information available to each of our business divisions and operating brands or Sites.
- Professional Advisors: We may also share your Personal Information with our professional advisors, which include lawyers, accountants, licensed medical professionals, and other similar professional advisors.
- Buyers or business transferees: Acquiring and other relevant parties (and their advisors) to business transactions (or potential transactions) involving a corporate divestiture, merger, consolidation, change in control, acquisition, reorganization, sale or other disposition of all or any portion of the business or assets of, or equity interests in, Health Union or our affiliates (including, in connection with a bankruptcy, reorganization, liquidation or similar proceedings).
- Regulatory and governmental authorities. As necessary to comply with applicable laws and regulations, respond to a subpoena, search warrant, or other lawful request for information, or to otherwise protect our rights, we may disclose your Personal Information to regulatory and government authorities, law enforcement agencies, and courts.
- Protection of rights, property, or safety. When we have a good faith belief that access, use, preservation, or disclosure of such Personal Information is reasonably necessary as required or permitted by law, or to protect the rights, property, or safety of Health Union, its clients, Users, or the public. We share your information to enforce, defend, or advance our agreements with you, as well as with our clients and partners
In some situations, the technology service providers we use may collect your Personal Information at the same time we collect it.
Non-Personal Information We Share or Disclose.
As stated above, we aggregate, de-identify, or anonymize your Personal Information in accordance with applicable legal standards and industry best practices. We use this aggregated and de-identified data to create insights, analytics, and data products that we provide to our business partners and clients to help them better understand patient experiences and healthcare trends.
We may share such Non-Personal Information about your use of our Sites and Services with our advertising and analytics partners, who may combine it with other information that you have previously provided to them. We share or make available Non-Personal Information, including aggregated or anonymized data:
- with analytics, search engines, or other service providers that help us provide, deliver, and improve our Services.
- to report to our affiliates, licensors and service providers, advertising partners, and ad networks about the use of various aspects of the Services.
- with other Users or prospective Users of the Services; and
- to advertisers and advertising networks and data service providers to create, select, and show relevant advertisements.
We implement industry-standard pseudonymization techniques and only share technical identifiers (such as hashed IDs) with associated de-identified interest categories. We prohibit re-identification attempts and require partners to maintain appropriate security measures. This sharing may be considered a “sale” or “sharing” of Personal Information under certain state privacy laws.
For more details on how we share Non-Personal Information, see our Appendix Chart.
Our Use of Artificial Intelligence (“AI”).
We do not use AI to make automated decisions that produce legal or similarly significant effects concerning you, as defined under applicable privacy laws. We use AI and Machine Learning technologies or tools for productivity purposes, content creation, and to support our operations.
Our AI usage is limited to analyzing aggregated and de-identified data for research, advertising, and operational purposes. For example, we may use these tools to analyze your responses to our “In America” surveys, or insights provided by our Patient Leadership Council, to create our offerings. These tools help us identify patterns, trends, and insights for market research purposes. We do not share individual responses. Our findings and reports are presented on an aggregated or de-identified basis.
Links to Third-Party Sites.
Some Services, content, and advertisements on our Sites are hosted on or linked to Third-Party Sites. Health Union does not control, endorse, or assume any responsibility for Third-Party Sites, including their content, privacy practices, or security measures. Your use of Third-Party Sites is entirely at your own risk and subject to their respective terms and policies. Third-Party Site privacy policies apply if you provide Personal Information to Third-Party Sites.
Please be aware that if you click on or interact with an advertisement on our Site, the advertiser may still assume that you meet its target criteria, even though we haven’t shared your Personal Information.
Google Analytics.
We use Google Analytics to analyze the audience of the Services and improve the performance of our Sites and content. For more information on how Google Analytics collects and processes data, please visit the following site: https://policies.google.com/technologies/partner-sites. Google Analytics and our third-party vendors (including Google) may use this information to display relevant ads through remarketing services based on your previous interactions with our Services. Once the visitor leaves the Services, custom advertisements appear on a Google search results page or other web pages. Data collected through “DoubleClick cookies” doesn’t include your Personal Information. By visiting Google’s Ads Settings, set your preferences for how Google advertises to you. http://www.google.com/settings/ads. You can permanently opt out of the Google Analytics Advertising Features by visiting this page: http://tools.google.com/dlpage/gaoptout.
How We Respond to “Do Not Track” Signals.
Our Sites do not currently respond to or support “Do Not Track” browser signals. Some Internet browsers can be configured to send “Do Not Track” signals to websites or services you visit, but these features aren’t uniform across browsers and industry participants disagree on what “Do Not Track” means in this context.
Automated Privacy Control (Global Privacy Control).
We treat a Global Privacy Control (“GPC”) signal as a valid request to opt out of the sale or sharing of your personal information for the browser from which it is sent. To learn more about GPC, visit https://globalprivacycontrol.org/. If you enable GPC, your preferences will only apply to the browser or device you are currently using to interact with our Sites or applications and not to other devices or browsers. If you use a different device or browser, you will need to check that GPC is enabled to ensure your preferences are recognized in connection with the browser or device you’re using.
Digital Advertising Alliance.
Health Union (and some of our third-party advertisers and display networks) take part in the Digital Advertising Alliance’s Self-Regulatory Program for Online Behavioral Advertising and Self-Regulatory Program for Multi-Site Data and allow consumers to opt out of targeted advertising based on web activity tracking. For more information, visit http://www.aboutads.info/choices/. Even if our third-party advertisers or display networks participate in the Digital Advertising Alliance’s Self-Regulatory Program for Online Behavioral Advertising or Self-Regulatory Program for Multi-Site Data, and you opt out of targeted advertising based on web activity tracking, you still will receive standard advertisements from us. You will still receive targeted advertisements from third parties. You will likely need to re-click the link and follow the instructions provided if you delete cookies or other similar technology or use a different computer, device, or browser.
Children’s Privacy.
Our Services are intended for individuals 18 years of age or older. We do not knowingly collect Personal Information from minors under 18. If we discover that we have inadvertently collected Personal Information from a minor, we will promptly delete it in accordance with applicable privacy laws. Minors may only use our Services with parental permission and supervision and should not provide any Personal Information. If you believe we have received Personal Information from a minor, please contact us immediately at privacy@health-union.com. By registering for an account or submitting Personal Information, you represent and warrant that you are at least 18 years of age.
Security.
We implement industry-standard technical, administrative, and physical safeguards to protect your Personal Information. However, no Internet data transmission or storage can ever be guaranteed entirely secure. It may be possible for third parties not under Health Union’s control to intercept or access transmissions or communications. Please protect your data by carefully selecting and protecting your password. Limit access to your computer, device, and browser. Always sign out of your account when finished. For more detailed information on our security practices, please visit our Health Union Trust Center at https://security.health-union.com/.
Data Retention.
We retain your Personal Information and Sensitive Personal Information for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations, whichever is longer. In some cases, we retain Personal Information for a longer period. We also keep anonymous or aggregated information that cannot identify you personally. We maintain specific retention schedules for different categories of information and regularly review and delete data that is no longer needed. The criteria used to determine our retention periods include i) to fulfill the purpose for which the information was collected, ii) for as long as you have an account with us or until you submit a data deletion request, and iii) as required by a legal obligation.
Data Deletion.
When we delete Personal Information, we use commercially reasonable efforts to remove it from our active systems. However, some information may remain in backup systems or archives for legal, regulatory, or technical reasons.
To request deletion of your Personal Information, please submit your request through the Privacy Rights Request Form or email us at privacy@health-union.com.
Please note that, as stated in our Terms of Use, User Content (such as posts, comments, or other contributions you have made to our public forums and communities) may remain on our Sites in anonymized form even after account deletion; but such anonymized User Content will be disassociated from your account.
Data Transfers.
Health Union is headquartered in the United States, and we transfer, store, and process information in countries where our business partners or service providers operate. When we transfer your Personal Information internationally, we implement appropriate safeguards as required by applicable data protection laws, such as Standard Contractual Clauses.
Your Privacy Rights.
Depending on where you live, you may have specific legal rights regarding your Personal Information. These rights are sometimes called “Opt Out of Targeted Advertising,” “Do Not Sell or Share My Personal Information,” or “Limit the Use of My Sensitive Personal Information.” As stated above, Health Union does not engage in automated decision-making or profiling that has a legal or similarly significant effect.
At Health Union, the data we use for these distinct purposes is the same under these consumer privacy laws We with our partners to show you more relevant ads based on your interests. Different state privacy laws use different terms—such as “sale” and “sharing”—to describe similar practices. However, “sharing” and “selling” both disclose your information to third parties for advertising purposes. Subject to some exceptions, you have the right to opt out of interest based advertising in two ways:
1. Opt Out of Cookies and Tracking Technologies for Targeted Advertising
This option only blocks cookies and tracking technologies on your current browser and device. You may still see personalized advertising on other platforms based on your activity and health interests.
You can opt out of the use of Tracking Technologies by reviewing the “Targeting Cookies” setting in our Cookie Preference Center in Cookie Settings or by enabling the Global Privacy Control on your browser or device.
For more information about opting out of targeted digital advertisements, visit the websites of the Digital Advertising Alliance’s YourAdChoices Self-Regulatory Program for Online Behavioral Advertising or the Network Advertising Initiative.
2. Opt Out of ALL disclosures that may be considered “selling,” “sharing,” or “targeted advertising,” under state privacy laws, including tracking technologies on this Site.
You must complete our Privacy Rights Request Form or email us at privacy@health-union.com.
By submitting the Privacy Rights Request Form, you will be opted out of the use of all disclosures that may be considered “selling”, “sharing”, or “targeted advertising” under state privacy laws.
3. Other Privacy Rights.
You may have – under certain data protection laws – other legal rights when it comes to how we handle your Personal Information. However, these rights aren’t absolute, and in some instances, we may deny your request. We may refuse your request if a legal exception applies, or if we’re legally required to keep or process your Personal Information in a way incompatible with your request. We’ll let you know if this is the case once we process your request.
- Know and Access. Confirm if we are processing your Personal Information and/or access to specific data;
- Data Portability. Obtain a copy of your Personal Information in a readily usable format that allows you to transmit the data to another entity, where the process is carried out by automated means;
- Correct. Update or correct inaccurate Personal Information that we maintain about you. You may update or correct your Site account information, by selecting “Edit my profile” in your User account;
- Delete. Delete Personal Information we have collected from you, subject to certain exceptions;
- Obtain a List of Third Parties. Receive a list of third parties to whom we have disclosed your Personal Information;
- Appeal. If we deny your privacy rights request, you may request an appeal, and we will respond within the timeframe required by applicable law. For some Users, you may have the right to file a complaint with your state Attorney General’s office; and
- No Discrimination. You have the right not to receive discriminatory treatment for exercising any of your privacy rights.
Authorized Agent.
You may designate an authorized agent to submit requests on your behalf. In California, authorized agents must be registered with the California Secretary of State or have written authorization. We may require you to verify your identity directly with us, provide proof that you authorized the agent to act on your behalf, and complete additional verification steps as required by law to prevent fraud.
You may designate an authorized agent to submit a request on your behalf. To do so, you must (1) verify your own identity directly with us; and (2) provide the authorized agent with written documentation of their authority to act on your behalf, such as: (a) a power of attorney; (b) sufficient evidence to show that you have provided the authorized agent signed permission to act on your behalf; or (c) other valid proof of authorization as required by applicable state law and directly confirmed with us that you provided the authorized agent permission to submit the request on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been authorized by you to act on your behalf.
You won’t have to pay a fee to access your Personal Information or exercise your privacy rights. However, as permitted by applicable law, we may charge a reasonable administrative fee if your requests are manifestly unfounded, excessive, or repetitive. We will notify you of any applicable fees before proceeding with your request.
If there are any conflicts between this section and any other provision of this Privacy Notice and the applicable law of your jurisdiction, the more protective provision shall control to the extent of such conflict. If you have questions about this section or whether any of the following rights apply to you, please contact us at privacy@health-union.com.
Our Process for Privacy Rights Requests.
You are not required to create an account with us to submit a verifiable or authenticated consumer request. However, we consider requests made through your password-protected account sufficiently verified when the request relates to Personal Information associated with that specific account. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
We will respond to your Privacy Rights Request Form within 45 days after receipt, except where otherwise noted. If your Privacy Rights Request Form is complex or you have made multiple Privacy Rights Request Forms, we may extend the response time by an additional 45 days when reasonably necessary. If an extension is needed, we will notify you of the extension and the reason for it within the first 45-day period and keep you updated throughout the process. As described below, in some jurisdictions, an authorized agent may submit a Privacy Rights Request Form to exercise your rights on your behalf.
To process your privacy request, we may need to confirm your identity. We typically request additional information from you to confirm your identity, which may include, but is not limited to, your email address, mailing address, account name, and/or the date of your last interaction with us. This security measure protects against inadvertent disclosure and is required under applicable privacy laws. We use the Personal Information you provide only to verify your identity and complete your request. If you are unable to provide sufficient information to verify your identity, we may be unable to process your request. In such cases, we will notify you of the issue and, where possible, provide guidance on alternative verification methods or additional information that may help us verify your identity. You may also contact us at privacy@health-union.com to discuss alternative verification options.
We will confirm receipt of your request within ten (10) business days. If you do not receive confirmation within the 10-day timeframe, please contact privacy@health-union.com. If you do not respond to our request for verification or refuse to provide verification when required, we will be unable to complete your request.
To exercise your “Opt Out” rights related to targeted marketing or exercise privacy rights related to accessing, deleting, or correcting your Personal Information, please visit Your Privacy Choices or email us at privacy@health-union.com.