Part One: Introduction

We at Jukebox Health, Inc.(“Jukebox Health”) value “your” privacy and are committed to keeping your personal data confidential. We use your data solely in the context of facilitating non-clinical in-home assessments provided by Jukebox Health’s professionals (“professionals”) to individuals requiring such assessments (“clients”). In addition to these assessments, “services” may include scheduling appointments for such in-home assessments and using clients’ personal data to generate recommendation reports.

This privacy policy applies to personal data Jukebox Health collects from users of the Jukebox Health platform (the “platform”) “personal data” includes any information that can be used on its own or with other information in combination to identify or contact one of our users. We believe that transparency about the use of your personal data is of utmost importance. In this privacy policy, we provide you detailed information about our collection, use, maintenance, and disclosure of your personal data. The policy explains what kind of information we collect, when and how we might use your personal data, how we protect personal data, and your rights regarding your personal data.

Please read the following carefully to understand Our Views and practices regarding Your Personal Data.

By submitting your personal data through this platform, you are acknowledging that you have read and agree to the terms of this privacy policy. If you do not agree, please do not log into or access platform and do not submit any personal data to us.

Please note that we occasionally update this privacy policy and that it is your responsibility to stay up to date with any amended versions. If we modify the privacy policy, we will post a link to the modified terms on our website and notify you via the email address you have provided to us. You can store this policy and/or any amended version(s) by using the save or print feature of the internet browser you are using to read this privacy policy. Any changes to this privacy policy will be effective immediately upon providing notice, and shall apply to all personal data we maintain, use, and disclose. If you continue to use the platform following such notice, you are agreeing to those changes.

In case you have any questions or concerns after reading this Privacy Policy, please do not hesitate to contact us at privacy@jukeboxhealth.Com. We appreciate Your feedback.

Part Two: Policy Summary

For “Your” convenience, We have summarized the key takeaways from Our Privacy Policy, below in this Part Two. You may access Our full Privacy Policy by scrolling down to Part Three on this page.

Responsible Entity

Jukebox Health, Inc. (“We”, “Us”, “the Company”, or “Jukebox Health”) is the controller of Your Personal Data, and may process this data in accordance with this Privacy Policy. If We are processing Personal Data on behalf of a third party, the terms of this Privacy Policy do not apply—instead, the terms of that third party’s privacy policy will apply. You can contact Us with any questions about Our Privacy Policy at privacy@jukeboxhealth.com.

What information do We collect and why?

We collect “Personal Data”, which includes any information that can be used on its own or with other information in combination to identify or contact You. For a description of the types of Personal Data We collect, review this section in the full Privacy Policy. In some cases, if You are a Client, this Personal Data may be or may include healthcare information or “Protected Health Information”.

We may use Personal Data to (1) provide You with the Services; (2) communicate with You about and manage Your User Account; (3) store data; (4) comply with the law; (5) respond to requests from public and government authorities; (6) to enforce Our terms and conditions; (7) manage and improve Our operations and applications; (8) provide additional functionality; (9) protect Our rights, privacy, safety or property, and/or that of You or others; and (10) allow Us to pursue available remedies or limit the damages that We may sustain. Additional uses are described in this section of the full Privacy Policy.

We only use or disclose Your Personal Data when it is legally mandated or where it is necessary to fulfill the purposes described above (and in the full Privacy Policy). Where required by law, We will ask for Your prior consent before doing so.

Failure to Provide Data.

Providing Your Personal Data is not statutorily or contractually mandated. However, if You choose not to provide this information, We cannot create a User Account, and You will be unable to use Our Services.

Will We share Your Personal Data with anyone else?

  • If You are a Client, Yes, We may share Your Personal Data with Your healthcare provider(s) per Your request.
  • Yes, with third parties that help Us power Our Platform.
  • Yes, with third parties and the government when legal or enforcement issues arise.
  • Yes, with third parties in the event of a reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of Jukebox Health’s corporate entity, assets, or stock (including in connection with any bankruptcy or similar proceedings).

For more details regarding the above, review this section in the full Privacy Policy.

Where is Your Personal Data stored, transmitted and/or maintained?

Personal Data Jukebox Health collects through the Platform will be stored on secure servers in the United States. Some Personal Data may be transmitted to third parties, which parties may store or maintain the data on their secure servers. These third parties are not permitted to transfer Your Personal Data outside of the United States.

How long will We maintain Your Personal Data?

We store Your Personal Data for as long as You maintain a User Account and up to 60 days or longer if certain state laws require us doing so after the account is closed. For more information on Personal Data retention, review this section of the full Privacy Policy.

How do We protect Your Personal Data?

Jukebox Health uses a combination of reasonable physical, technical, and administrative security controls to maintain the security and integrity of Your Personal Data, to protect against any anticipated threats or hazards to the security or integrity of such information, and to protect against unauthorized access to or use of such information in Our possession or control that could result in substantial harm or inconvenience to You. However, Internet data transmissions, whether wired or wireless, cannot be guaranteed to be 100% secure. As a result, We cannot ensure the security of information You transmit to Us. By using the Platform, You are assuming this risk. For more information on the safeguards We have in place to protect Your Personal Data, review this section of the full Privacy Policy.

Your rights

You have certain rights relating to Your Personal Data, subject to local data protection laws. These rights may include:

  • to access Your Personal Data held by Us;
  • to erase/delete Your Personal Data, to the extent permitted by applicable data protection laws;
  • to receive communications related to the processing of Your personal data that are concise, transparent, intelligible, and easily accessible;
  • to restrict the processing of Your Personal Data to the extent permitted by law (while We verify or investigate Your concerns with this information, for example);
  • to object to the further processing of Your Personal Data, including the right to object to marketing;
  • to request that Your Personal Data be transferred to a third party, if possible;
  • to receive Your Personal Data in a structured, commonly used, and machine-readable format;
  • to lodge a complaint with a supervisory authority;
  • to rectify inaccurate Personal Data and, taking into account the purpose of processing the Personal Data, ensure it is complete;
  • to not be subject to a decision based solely on automated processing, including profiling, which produces legal effects ("Automated Decision-Making"); and
  • to the extent We base the collection, processing, and sharing of Your Personal Data on Your consent, to withdraw Your consent at any time, without affecting the lawfulness of the processing based on such consent before its withdrawal.

For more details on Your rights and choices and how to exercise them, please review the full Privacy Policy.

How do You contact Us with questions or concerns?

If You have any questions about this Privacy Policy, please contact Us by email at privacy@jukeboxhealth.com or please write to: Jukebox Health at PO Box 12, Shelter Island Heights, NY 11965. Please note that email communications are not always secure; so please do not include sensitive information in Your emails to Us.

Part Three: Full Privacy Policy

Version 1 - Last Updated: May 3, 2022

We at Jukebox Health value “your” privacy and are committed to keeping your personal data confidential. We use your data solely in the context of facilitating non-clinical in-home assessments provided by Jukebox Health’s professionals (“professionals”) to individuals requiring such assessments (“clients”). In addition to these assessments, “services” may include scheduling appointments for such in-home assessments and using clients’ personal data to generate recommendation reports.

This privacy policy applies to personal data Jukebox Health collects from users of the Jukebox Health platform (the “platform”). “personal data” includes any information that can be used on its own or with other information in combination to identify or contact one of our users. We believe that transparency about the use of your personal information is of utmost importance. In this privacy policy, we provide you detailed information about our collection, use, maintenance, and disclosure of your personal data. The policy explains what kind of information we collect, when and how we might use that information, how we protect the information, and your rights regarding your personal information.

If you are a client, some of the personal data we collect and transmit will, in some circumstances, be considered “Health Data”(data related to a user’s physical or mental health) or “Protected Health Information” (information that relates to the past, present, or future physical or mental health or condition of a user; the provision of health care to a user; or the past, present, or future payment for the provision of health care to user). Therefore, our privacy practices are intended to comply with both the health insurance portability and accountability act (“HIPAA“) and the general data processing regulation (“GDPR”) provisions regarding sensitive personal data. In addition, we intend to comply with state law related to health data, where applicable. For additional information related to your healthcare information, please contact our privacy officer at privacy@jukeboxhealth.com.

By submitting your personal data through this platform, you are acknowledging that you have read and agree to the terms of this policy. If you do not agree, please do not log into or access the platform and do not submit any personal data to us.

Please note that we occasionally update this privacy policy and that it is your responsibility to stay up to date with any amended versions. If we modify the privacy policy, we will post a link to the modified terms on our website and will also notify you via email. You can store this policy and/or any amended version(s) digitally, print it, or save it in any other way. Any changes to this privacy policy will be effective immediately upon providing notice, and shall apply to all information we maintain, use, and disclose. If you continue to use the platform following such notice, you are agreeing to those changes.

In case You have any questions or concerns after reading this Privacy Policy, please do not hesitate to contact Us at privacy@jukeboxhealth.com. We appreciate Your feedback. If You do not agree or no longer agree to the processing of personal information as described in this Privacy Policy, You can delete Your account by emailing privacy@jukeboxhealth.com.

Responsible Entity

Jukebox Health, Inc. (“We”, “Us”, “the Company”, or “Jukebox Health”) is the controller of Your Personal Data and may process this data in accordance with the Privacy Policy. If We are processing Personal Data on behalf of a third party that is not an agent or affiliate of Company, the terms of this Privacy Policy do not apply—instead, the terms of that third party’s privacy policy will apply. You can contact Us with any questions about Our Privacy Policy at privacy@jukeboxhealth.com.

Links to Other Sites

Our Platform may contain links to websites and services that are owned or operated by third parties (each, a “Third-party Service”). Any information that You provide on or to a Third-party Service or that is collected by a Third-party Service is provided directly to the owner or operator of the Third-party Service and is subject to the owner’s or operator’s privacy policy. We are not responsible for the content, privacy or security practices and policies of any Third-party Service. To protect Your information, We recommend that You carefully review the privacy policies of all Third-party Services that You access.

What Personal Data do We collect?

Demographic Data

We may collect demographic information, such as Your name, birth year, gender, ethnicity, height, weight, phone number, physical location address, and/or e­mail address. Primarily, the collection of Your Personal Data assists Us in creating Your User Account, which You can use to securely to receive the Services.

Payment Data

If You make payments via Our Platform, We may require that You provide to Us Your financial and billing information, such as billing name and address, credit card number or bank account information.

Support Data

If You contact Us for support or to lodge a complaint, We may collect technical or other information from You through log files and other technologies, some of which may qualify as Personal Data. (e.g., IP address). Such information will be used for the purposes of troubleshooting, customer support, software updates, and improvement of the Platform and related services in accordance with this Privacy Policy. Calls with Jukebox Health may be recorded or monitored for training, quality assurance, customer service, and reference purposes.

Device, Telephone, and ISP Data

We may use common information-gathering tools, such as log files, cookies, web beacons, and similar technologies to automatically collect information, which may contain Personal Data, from Your computer or mobile device as You navigate Our Platform, or interact with emails We have sent You. The information We collect may include Your Internet Protocol (“IP”) address (or proxy server), device and application identification numbers, location, browser type, Internet service provider and/or mobile carrier, the pages and files You viewed, Your searches, Your operating system and system configuration information, and date/time stamps associated with Your usage. This information is used to analyze overall trends, to help Us provide and improve Our Services and to guarantee their security and continued proper functioning.

FOR CLIENTS: Health Data

In addition to demographic information, We may collect information regarding Your health conditions, age, gender, weight, height, medical history, symptoms, and related information from You. We collect this information to provide You with the Services and to provide Your healthcare provider per Your request.

How will We use Your Personal Data?

We process Your Personal Data for purposes based on legitimate business interests, the fulfillment of Our Services to You, compliance with Our legal obligations, and/or Your consent. We only use or disclose Your Personal Data when it is legally mandated or where it is necessary to fulfill the purposes described herein. Where required by law, We will make reasonable efforts to ask for Your prior consent before doing so.

Specifically, We process Your Personal Data for the following legitimate business purposes:

  • To fulfill Our obligations to You under the Terms of Use;
  • To communicate with You about and manage Your User Account;
  • To properly store and track Your data within Our system;
  • To respond to lawful requests from public and government authorities, and to comply with applicable state/federal law, including cooperation with judicial proceedings or court orders;
  • To protect Our rights, privacy, safety, or property, and/or that of You or others by providing proper notices, pursuing available legal remedies, and acting to limit Our damages;
  • To handle technical support and other requests from You;
  • To enforce and ensure Your compliance with Our Terms of Use or the terms of any other applicable services agreement We have with You;
  • To manage and improve Our operations and the Platform, including the development of additional functionality;
  • To manage payment processing;
  • To evaluate the quality of service You receive, identify usage trends, and thereby improve Your user experience;
  • To keep Our Platform safe and secure for You and for Us;
  • To send You information about changes to Our terms, conditions, and policies;
  • To allow Us to pursue available remedies or limit the damages that We may sustain; and
  • If You are a Client, to provide access to the authorized healthcare provider/caregiver (with Your consent), to enable that individual to monitor Your progress and overall condition and to follow up with You, as they deem appropriate.

Where is Your Personal Data processed?

Personal Data Jukebox Health collects through the Platform will be stored on secure servers in the United States. Personal Data may be transmitted to third parties, which parties may store or maintain the data on their secure servers. These third parties are not permitted to transfer Your Personal Data outside of the United States.

Will We share Your Personal Data with anyone else?

If You are a Client, Yes, with Your healthcare provider(s) per Your Request and with Your Consent.

We will share information You enter into the Platform, as well as any reports generated by the Platform based on the information You enter, with Your healthcare provider(s) per Your request. If, at any point, You want to deny access to one or more healthcare provider(s), You can do so by emailing privacy@jukeboxhealth.com.

Yes, with third parties that help us power Our Platform

Jukebox Health has a limited number of service providers and other third parties (“Business Partners”) that help Us run various aspects of Our business. These Business Partners are contractually bound to protect Your Personal Data and to use it only for the limited purpose(s) for which it is shared with Us. Business Partners’ use of Personal Data may include, but is not limited to, the provision of services such as data hosting, IT services, customer service, and payment processing.

Yes, with third parties and the government when legal or enforcement issues arise

We may share Your Personal Data, if reasonable and necessary, to (i) comply with legal processes or enforceable governmental requests, or as otherwise required by law; (ii) cooperate with third parties in investigating acts in violation of this Agreement; or (iii) bring legal action against someone who may be violating the Terms of Use or who may be causing intentional or unintentional injury or interference to the rights or property of Jukebox Health or any third party, including other users.

Yes, with third parties that provide advisory services

We may share Your Personal Data with Our lawyers, auditors, accountants, or banks, when We have a legitimate business interest in doing so.

Yes, with third parties in the event of a reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of Jukebox Health’s corporate entity, assets, or stock (including in connection with any bankruptcy or similar proceedings)

If We share Your Personal Data with a third party other than as provided above, You will be notified at the time of data collection or transfer, and You will have the option of not permitting the transfer.

How long do We retain Personal Data?

We will retain Your Personal Data for as long as You maintain a User Account and up to 60 days or longer if required by state laws after the account is closed. The exact period of retention will depend on the type of Personal Data, Our contractual obligation to You, and applicable law. We keep Your Personal Data for as long as necessary to fulfill the purpose for which it was collected, unless otherwise required or necessary pursuant to a legitimate business purpose outlined in this Privacy Policy. For example, if the Personal Data is part of Your healthcare medical record, We may, at the request of Your provider, retain such Personal Data for the state mandated retention period for medical records. At the end of the applicable retention period, We will remove Your Personal Data from Our databases and will request that Our Business Partners remove Your Personal Data from their databases. If there is any data that We are unable, for technical reasons, to delete entirely from Our systems, We will put in place appropriate measures to prevent any further processing of such data. We retain anonymized data indefinitely.

NOTE: Once We disclose Your Personal Data to third parties, We may not be able to access that Personal Data any longer and cannot force the deletion or modification of any such information by the parties to whom We have made those disclosures. Written requests for deletion of Personal Data other than as described should be directed to privacy@jukeboxhealth.com.

What is Our Cookie Policy?

Cookies are small files that a web server sends to Your computer or device when You visit a web site that uses cookies to keep track of Your activity on that site. Cookies also exist within applications when a browser is needed to view certain content or display certain content within the application. Cookies hold a small amount of data specific to that web site, which can later be used to help remember information You enter into the site (like Your email or other contact info), preferences selected, and movement within the site. If You return to a previously visited web site or application (and Your browser has cookies enabled), the web browser sends the small file to the web server, which tells it what activity You engaged in the last time You used the web site or application, and the server can use the cookie to do things like expedite logging in and retrieving user data and keeping Your browser session secure.

We may use cookies and other technologies to, among other things, better serve You with more tailored information, and to facilitate efficient and secure access to the Platform. We’d only use essential cookies. Essential cookies are those necessary for Us to provide services to You. We have provided, below, a full list of Our cookies, categorized as described above. We have described the purpose of each, whether they are Jukebox Health or Third-Party cookies, and how to withdraw consent to their use. We have also indicated which cookies are “session cookies” (which last for as long as You keep Your browser open) and “persistent cookies” (which remain on Your hard drive until You delete them or they expire).

We may also collect information using pixel tags, web beacons, clear GIFs, or other similar technologies. These may be used in connection with some web site or application pages and HTML ­formatted email messages to, among other things, track the actions of users and email recipients, and compile statistics about usage and response rates.

How can You “Opt Out” of Cookies?

If You prefer, You can usually choose to set Your browser to remove cookies and reject cookies. If You enable a do not track (“DNT”) signal or otherwise configure Your browser to prevent Jukebox Health from collecting cookies, You will need to re­enter Your user name each time You visit the login page.

How do We protect Your Personal Data?

Jukebox Health is committed to protecting the security and confidentiality of Your Personal Data. We use a combination of reasonable physical, technical, and administrative security controls to maintain the security and integrity of Your Personal Data, to protect against any anticipated threats or hazards to the security or integrity of such information, and to protect against unauthorized access to or use of such information in Our possession or control that could result in substantial harm or inconvenience to You. However, Internet data transmissions, whether wired or wireless, cannot be guaranteed to be 100% secure. As a result, We cannot ensure the security of information You transmit to Us. By using the Platform, You are assuming this risk.

Safeguards

The information collected by Jukebox Health and stored on secure servers, is protected by a combination of technical, administrative, and physical security safeguards, such as authentication, encryption, backups, and access controls. If Jukebox Health learns of a security concern, We may attempt to notify You and provide information on protective steps, if available, through the e­mail address or phone number that You have provided to Us. Depending on where You live, You may have a legal right to receive such notices in writing.

You are solely responsible for protecting information entered or generated via the Platform that is stored on Your device and/or removable device storage. Jukebox Health has no access to or control over Your device’s security settings, and it is up to You to implement any device ­level security features and protections You feel are appropriate (e.g., password protection, encryption, remote wipe capability, etc.). We recommend that You take any and all appropriate steps to secure any device that You use to access Our Platform.

Notwithstanding any of the steps taken by us, it is not possible to guarantee the security or integrity of data transmitted over the internet. There is no guarantee that your personal data will not be accessed, disclosed, altered, or destroyed despite the implementation of our physical, technical, or administrative safeguards. Therefore, we do not and cannot ensure or warrant the security or integrity of any personal data you transmit to us and you transmit such personal data at your own risk.

Optional

The privacy of the individually identifiable health information We collect in connection with some of Our relationships with healthcare providers (“Covered Entities”), may be protected by federal law (the Health Insurance Portability and Accountability Act or HIPAA, the HITECH Act, and their regulations). Your individually identifiable health information may also be protected by state privacy laws in some instances. This health information is referred to as “Protected Health Information” (“PHI”). In providing Our services or products, We may be a “Business Associate” (as defined by HIPAA regulations), but We are not a Covered Entity. Your PHI will only be used for the purpose of supplying You with products or services that You request, for Our own management and administration purposes, or for other purposes for which You have given Your consent, except where otherwise permitted by law.

In instances where You have authorized the Company to use and disclose Your PHI for certain purposes, You may withdraw Your consent in the future. You may withdraw Your consent by sending Your request in writing to: privacy@jukeboxhealth.com or a letter addressed to Jukebox Health at PO Box 12, Shelter Island Heights, NY 11965. Please note that Your withdrawal will not be effective until Jukebox Health receives Your request and will not apply to uses and disclosures that Jukebox Health has already made in reliance on Your consent.

How can You Protect Your Personal Data?

In addition to securing Your device, as discussed above, We will NEVER send You an e­mail requesting confidential information such as account numbers, usernames, passwords, or social security numbers, and You should NEVER respond to any e­mail requesting such information. If You receive such an e­mail purportedly from Jukebox Health, DO NOT RESPOND to the e­mail and DO NOT click on any links and/or open any attachments in the e­mail, and notify Jukebox Health support at privacy@jukeboxhealth.com.

You are responsible for taking reasonable precautions to protect Your user ID, password, and other User Account information from disclosure to third parties, and You are not permitted to circumvent the use of required encryption technologies. You should immediately notify Jukebox Health at privacy@jukeboxhealth.com if You know of or suspect any unauthorized use or disclosure of Your user ID, password, and/or other User Account information, or any other security concern.


Your rights


You have certain rights relating to Your Personal Data, subject to local data protection laws. These rights may include:

  • to access Your Personal Data held by Us;
  • to erase/delete Your Personal Data, to the extent permitted by applicable data protection laws;
  • to receive communications related to the processing of Your personal data that are concise, transparent, intelligible, and easily accessible;
  • to restrict the processing of Your Personal Data to the extent permitted by law (while We verify or investigate Your concerns with this information, for example);
  • to object to the further processing of Your Personal Data, including the right to object to marketing;
  • to request that Your Personal Data be transferred to a third party, if possible;
  • to receive Your Personal Data in a structured, commonly used, and machine-readable format;
  • to lodge a complaint with a supervisory authority;
  • to rectify inaccurate Personal Data and, taking into account the purpose of processing the Personal Data, ensure it is complete; and
  • to not be subject to a decision based solely on automated processing, including profiling, which produces legal effects ("Automated Decision-Making").

 

Where the processing of Your Personal Data by Jukebox Health is based on consent, You have the right to withdraw that consent without detriment at any time or to exercise any of the rights listed above by emailing Jukebox Health at privacy@jukeboxhealth.com.

How can You update, correct, or delete Personal Data?

You can change Your e­mail address, and other contact and personal information by logging into your account in the Platform or emailing us at privacy@jukeboxhealth.com. Please note that in order to comply with certain requests to limit use of Your Personal Data, We may need to terminate Your account and Your ability to access and use the Services, and You agree that We will not be liable to You for such termination or for any refunds of prepaid fees paid by You. You can deactivate Your account by emailing privacy@jukeboxhealth.com.

Although We will use reasonable efforts to do so, You understand that it may not be technologically possible to remove from Our systems every record of Your Personal Data. The need to back up Our systems to protect information from inadvertent loss means a copy of Your Personal Data may exist in a non­erasable form that will be difficult or impossible for Us to locate or remove.

Can You “OPT­OUT” of receiving communications from Us?

We pledge not to market third party services to You without Your consent. We only send e­mails or SMS text to You regarding Your Jukebox Health account and services unless We have Your express consent to not do so. You can choose to filter these e­mails using Your e­mail client settings, but We do not provide an option for You to opt out of these e­mails. If and when We send You marketing or other commercial emails or SMS text messages not related to Your account and services, We will provide You with the option to opt out of such marketing emails and SMS text messages within the applicable message.]

Information submission by minors

We do not knowingly collect Personal Data from individuals under the age of 18 and the Platform is not directed to individuals under the age of 13. We request that these individuals not provide Personal Data to Us. If We learn that Personal Data from users less than 18 years of age has been collected, We will deactivate the account and take reasonable measures to promptly delete such data from Our records. If You are aware of a user under the age of 13 using Platform, please contact Us at privacy@jukeboxhealth.com.

If You are a resident of California, under the age of 18 and have registered for an account with Us, You may ask Us to remove content or information that You have posted to Our Platform.

California Residents

California residents may request and obtain from Us, once a year, free of charge, a list of third parties, if any, to which We disclosed their Personal Data for direct marketing purposes during the preceding calendar year and the categories of Personal Data shared with those third parties. If You are a California resident and wish to obtain that information, please submit Your request by sending Us an email at privacy@jukeboxhealth.com with “California Privacy Rights” in the subject line.

Contact Us

If You have any questions about this Privacy Policy, please contact Us by email at privacy@jukeboxhealth.com or please write to: Jukebox Health Inc. at 228 Park Ave S, Suite 36053 New York, NY 10003. Please note that email communications are not always secure; so please do not include sensitive information in Your emails to Us.