Privacy and personal data protection policy

A. INTRODUCTION

H2O Therapeutics Co. ("Company" or "We") respects your privacy and is committed to protecting it through our compliance with this privacy policy (“Policy”). This Policy describes:

  • How we collect, use, disclose and process personal data we collect through our website www.h2otherapeutics.com, web-based portals including Parky Provider Portal (“Portal”), mobile application Parky (“App”) or other digital products that link to or refer to this Policy (collectively, the “Services”);
  • The types of information we may collect or that you may provide when you access, or use these platforms;
  • Our practices for collecting, using, maintaining, protecting, and disclosing that information as a data controller.

This Policy applies to information we collect including Information (as defined below) of any visitor or user of our Services.and other electronic communications sent through or in connection with the Services

This Policy DOES NOT apply to information that:

  • You provide to or is collected by any third party (see Third-Party Information Collection).

“User,” “you” and “your” refer to the individual or entity that accesses or otherwise uses the Services, and each of your heirs, assigns, and successors.
“HCP User” means the User who uses the Services for symptom tracking and care management of his/her patients through the Portal, creates prescriptions through the Portal, enters the necessary patient Information into the Portal and transfers it to the Company after informing the patient and if necessary, obtaining the patient's consent. “Patient User” means the User who uses the Services through the App for purposes such as symptom tracking, remote monitoring, care management, medication reminders, etc.
Please read the Terms of Use to understand the general rules about your use of the Services.
Please read this Policy carefully to understand our policies and practices regarding your personal information and non-personal information (collectively “Information”) as well as our use of Information and how we will treat it. Please see below for a definition of personal information, and how We may use it.

If you do not agree with our policies and practices, do not download, register with, or use the Services. By downloading, registering with, or using the Services, you agree to this Policy. This Policy may change from time to time. We will endeavor to notify you of any changes to this Policy. Your continued use of our Services after we revise this Policy means you accept those changes, so please check the Policy periodically for updates.

B. WHAT PERSONAL INFORMATION DO WE PROCESS AND FOR WHAT PURPOSE?

Personal Information is information we collect through the method described in this Policy that can specifically identify you or personally identifiable information as defined under applicable law.

Company shall process the following Personal Information and for the following purposes:

PERSONAL INFORMATION CATEGORY PROCESSED PERSONAL INFORMATION PURPOSE OF INFORMATION PROCESSING
Identity Information Name, Surname, Gender, Date of Birth - To perform the agreements concluded between you and us, to enable you to use and benefit from the Services including the App, Portal and to create a membership/profile.
- To provide you with the Services and its contents, including the App, Portal and any other information, products, or services that you request from us.
- To carry out our obligations and enforce this Policy and our rights arising from any contracts entered into between you and us.
- To administer the Services, enable you to use its features, and improve the overall user experience.
- For legal purposes, such as to comply with laws or to establish, exercise, or defend our legal rights.
Contact Information E-Mail Address, Phone Number, State information - To give you notices about your subscription/registration, including expiration and renewal notices.
- To notify you when Services updates are available, and of changes to any products or services we offer or provide through it.
- To send information including confirmations, technical notices, security alerts, and support messages.
- To send you notifications and respond to your requests, comments and questions and provide technical support and customer support.
- To protect, investigate, and deter against fraudulent, unauthorized, or illegal activity.
- To compare information for accuracy, update our records, and verify it with third parties.
Professional Information Title, Specialty, NPI, institution/workplace - To perform the agreements concluded between you and us, to enable you to use and benefit from the Services including the Portal and to create a membership/profile.
- To provide you with the Services and its contents, including the, Portal and any other information, products, or services that you request from us.
- To protect, investigate, and deter against fraudulent, unauthorized, or illegal activity.
- To compare information for accuracy, update our records, and verify it with third parties.
Device Information Your mobile device's model number, operating system, browser type, mobile network information. - In case it is necessary for future optimizations, design decisions and to effectively solve the possible issues you may face.
- To provide technical support and customer support.
Geolocation Information Only time zone information. - To generate symptom reports correlating your symptoms with medications based on your time zone.
- To remind you of your medicines according to your time zone
Transaction Information Data about purchases of services or transactions facilitated by the Services. - Provide you with the most optimal Services and their content, including the App, Portal.
Health Information Such as movements, dyskinesia, tremors, steps, information related to medications that are used, fitness and exercise information, recording time - To graph and provide a symptom status report for your symptoms (dyskinesia, tremors, steps and sleep etc.) on a daily, weekly and monthly basis.
- To remind you to take your medicines for which you have entered information on the dates and times you have specified.
- To protect your health, safety or welfare.

We may combine Information that we collect from you through the Services with information that we obtain from affiliated and nonaffiliated third parties, and information derived from any other products or services we provide.

We also use Information that we collect about you or that you provide to us to create a set of data that has non-personal or de-identified information. In this case, we would remove your personal identifiers (your name, email address, biometric data, etc.) and we may treat it like other non-personal or de-identified information. In this context, we may anonymize, aggregate or otherwise make such information non-personally identifiable for a variety of purposes, including those listed in this section. The use and disclosure of such de-identified information is not subject to any restrictions under this policy.

C. CHILDREN UNDER THE AGE OF 16

The Services are not intended for children under 16 years of age, and we do not knowingly collect personal information from children under 16. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will delete that personal information. If you believe we might have any personal information from or about a child under 16, please contact us at support@parkynow.com.

D. HOW WE COLLECT INFORMATION

We collect the following Information from and about users of our Services :

  • Information you provide to us;
  • Information automatically collected when you use the Services;
  • Information from non-affiliated third parties.

1. Information You Provide to Us

When you download, register with, or use our Services, we may ask you to provide Information. This Information may include:

  • Information that you provide by filling in forms correlating to the Services. This includes Information provided at the time of registering to use the Services, subscribing to our Service, and requesting further services. We may also ask you for Information when you report a problem with Services .
  • Records and copies of your correspondence (including email addresses and phone numbers), if you contact us.
  • Your responses to surveys that we might ask you to complete for research purposes.
  • Your communications with us and your event log when you contact us for troubleshooting or support for our Services in order to diagnose the issue that you are facing at that exact time.

2. Information automatically collected when you use the Services

When you download, access, and use the Services, it may use technology to automatically collect the following:
Browser and device information and information collected through tracking technologies such as cookies, pixel tags, and other technologies.

You may delete and block all cookies from our Services, but in doing so, it may affect the optimability of the Services.

The technologies we use for automatic Information collection may include:

  • Cookies (or mobile cookies). A cookie is a small file placed on your smartphone. It may be possible to refuse to accept mobile cookies by activating the appropriate setting on your smartphone. However, if you select this setting you may be unable to access certain parts of our Services.
  • Web Beacons. Pages of the App may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages and for other related app statistics./li>

We do not control third parties' collection or use of your Information to serve interest-based advertising. However these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of receiving targeted ads from members of the Network Advertising Initiative ("NAI") on the NAI's website. If you disable or restrict cookies, (a) your use of the Services may be adversely affected (and possibly entirely prevented), (b) your experience of this and other sites that use cookies to enhance or personalize your experience may be adversely affected, and (c) you may not be presented with advertising that reflects the way that you use our and other sites.

Further to the above, the Services may contain links to other applications or websites. We provide the links for your convenience, but we do not review, control, or monitor the privacy practices of websites or apps operated by others and they are subject to their own terms of use and privacy policies. We are not responsible for the performance of applications or websites operated by third parties or for your business dealings with them. Therefore, whenever you leave our Services, we recommend that you review each application or website's privacy practices and make your own conclusions regarding the adequacy of these practices.
Residents in certain states, such as California, may have additional personal information rights and choices. Please see Your State Privacy Rights for more information.

3. Information From Non-Affiliated Third Parties

We may also collect information about you from other parties, such as when you are referred to us by another user, or when you authorize us to collect information about you from other parties. We may also collect information about potential customers of our Services, such as healthcare professionals who may find our Services useful.

E. DISCLOSURE/TRANSFER OF YOUR INFORMATION

Company will not disclose/transfer your Information collected with any unrelated third party without your permission, except as described below in this Policy.

We may disclose aggregated Information about our users, and Information that does not identify any individual or device, without restriction.

In addition, we may disclose personal information that we collect or you provide:

  • To our subsidiaries and affiliates.
  • To contractors, service providers, and other third parties we use to support our business and who are bound by contractual obligations to keep personal information confidential and use it only for the purposes for which we disclose it to them. We work with a wide range of third party providers, notably our database administrators, cloud computing services, advertising services, data analysts, application service providers, bulk SMS services, and other governmental or non-governmental organizations.
  • To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of H2O Therapeutics Co.'s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by H2O Therapeutics Co. about our App users is among the assets transferred.
  • To fulfill the purpose for which you provide it.
  • For any other purpose disclosed by us when you provide the information.
  • With your consent. We may disclose your information to nonaffiliated third parties based on your consent to do so. For example, you may direct us to allow third parties such as family members and care providers to access information in your account.
  • To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
  • If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of H2O Therapeutics Co., our customers, or others. This includes exchanging Information with other companies and organizations for the purposes of fraud protection and credit risk reduction.
    We may be required to release your personal information in response to a court order, subpoena, search warrant, law, or regulation. We may cooperate with law enforcement authorities in investigating and prosecuting App users who violate our rules or engage in behavior which is harmful to other users (or illegal). In addition, we may keep, disclose, and use your personal information in order to comply with U.S. FDA and other governmental guidance, directions, regulations, and laws.
    We may disclose your personal information to third parties if we feel that the disclosure is necessary to:
    - Enforce this Policy and the other rules about your use of the App;
    - Protect our rights or property;
    - Protect someone's health, safety, or welfare;
    - Comply with a law or regulation, court order, or other legal process.
  • To use and disclose your Information as permitted under the Privacy Rule of the Health Insurance Portability and Accountability Act (HIPAA), including for treatment and healthcare operations. These disclosures are essential for providing you with the necessary health services and ensuring efficient operations of our healthcare services:
    - To the Individual: We may disclose protected health information to the individual who is the subject of the Information.
    - Treatment And HealthCare Operations: We may use and disclose protected health information for your own health care management activities.

F. RIGHT TO WITHDRAW CONSENT

If you have provided your consent to the collection, processing and transfer of your Information, you have the right to fully or partly withdraw your consent. To withdraw your consent, please follow the opt-out links or contact us via contact form.
Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there are compelling legitimate grounds for further processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.

Uses and Disclosures with Opportunity to Agree or Object:
Informal permission may be obtained by asking you or by circumstances that clearly give you the opportunity to agree, acquiesce, or object. In cases where you are incapacitated or in an emergency, we may use or disclose Information if it is determined to be in your best interests. No restrictions apply to the use or disclosure of de-identified health information, which means any health information that does not identify you and cannot be used to identify you.

G. ACCESSING AND CORRECTING YOUR PERSONAL INFORMATION

You can review and change your personal information by logging into the App or Portal and visiting your account profile page.

You may also send us an email at support@parkynow.com to request access to, correct, or delete any personal information that you have provided to us. We cannot delete your personal information except by also deleting your user account. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.

Your State Privacy Rights

Please check with your own state's privacy laws for additional rights regarding our use of their personal information.

If you are from the European Economic Area, the United States of America or in certain countries, you are also entitled (with some exceptions and restrictions) to:

  • Access: You have the right to request information about how we process your personal data and to obtain a copy of that personal data.
  • Rectification: You have the right to request the rectification of inaccurate personal data about you and for any incomplete personal information about you to be completed.
  • Objection: You have the right to object to the processing of your personal information, which is based on our legitimate interests (as described above).
  • Deletion: You can delete your account by using the corresponding functionality directly on the service.
  • Automated decision-making: You have the right to object to a decision made about you that is based solely on automated processing if that decision produces legal or similarly significant effects concerning you.
  • Restriction: You have the right to ask us to restrict our processing of your personal data.
  • Portability:You have the right to transfer your information to a third-party provider of services.
  • Complaint: You have a right to lodge a complaint with the authorized data protection authority.

H. DATA SECURITY

We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. All Information you provide to us is stored on our secure servers behind firewalls.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Services, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.

We take appropriate and reasonable technical and organizational measures to protect your personal data from loss, misuse, unauthorized access, disclosure, alteration, and destruction, taking into account the risks involved in the processing and the nature of the personal data. Such technical and organizational measures include:

  • Protecting our data servers with state-of-the-art anti-virus programs and similar software.
  • Limiting and recording physical access to our premises and facilities.
  • Limiting and recording access to our data servers.
  • Ensuring regular tests and reviews to our system performed internally or by a third-party agency.

Unfortunately, the transmission of Information via the internet and mobile platforms is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted through our Services. Any transmission of personal information is at your own risk.

I. CHANGES TO OUR PRIVACY POLICY

We reserve the right to make changes to this Policy at any time. When we make changes, we will update the revision date at the top of this page. Significant changes will be communicated to you via e-mail in accordance with HIPAA regulations. We encourage you to review this Policy periodically to stay informed about how we are protecting your information.

The date the Policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you and for periodically visiting this Policy to check for any changes.

J. RETENTION OF YOUR INFORMATION

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements and, where required for our company to provide service, until the end of the relevant retention period.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

Upon expiry of the applicable retention period we will securely delete or destroy your personal data in accordance with applicable laws and regulations.

K. RESIDENTS OF THE EUROPEAN ECONOMIC AREA AND UNITED KINGDOM

Our Company is considered the “data controller” of the “personal data” as defined under the General Data Protection Regulation (“GDPR”), we handle under this Policy. To the extent those laws apply, our legal grounds are as follows:

  • the data subject has given consent to the processing of his or her personal data for one or more specific purposes (GDPR Art. 6(1)(a)),
  • processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (GDPR Art. 6(1)(b)),
  • processing is necessary for compliance with a legal obligation to which the controller is subject (GDPR Art. 6(1)(c)),
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, (GDPR Art. 6(1)(f)).

You may, at any time, exercise any of the above rights under the heading “G. Accessing and Correcting Your Personal Information”, by contacting us via contact form below together with a proof of your identity, i.e. a copy of your ID card, or passport, or any other valid identifying document.

In some cases we may not be able to give you access to personal data we hold regarding you, if making such a disclosure would breach our legal obligations to our other customers or if prevented by any applicable law or regulation.

L. HIPAA COMPLIANCE

In compliance with HIPAA, we ensure that all personal health information (PHI) is handled in accordance with federal regulations. We implement appropriate administrative, physical, and technical safeguards to secure PHI against unauthorized access, use, or disclosure. Should there be any unauthorized access to your PHI, we will notify you as required by HIPAA.

M. CONTACT INFORMATION

To ask questions or comment about this Policy and our privacy practices, contact us at:
support@parkynow.com.

To register a complaint or concern, please contact support@parkynow.com.

Additionally, you may file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights. No retaliation will occur against you for filing a complaint.