Policy summary
Personal Data collected
for the following purposes and using the
following services:
-
-
Access to third-party
accounts
-
-
Analytics
-
Google
Analytics,
Analytics
collected
directly,
MixPanel,
Facebook Ads
conversion
tracking
(Facebook
pixel), Google
Ads conversion
tracking and
Google Analytics
with anonymized
IP
Personal Data:
Cookies; Usage
Data
-
Google Analytics
for Firebase
Personal Data:
Cookies; unique
device
identifiers for
advertising
(Google
Advertiser ID or
IDFA, for
example); Usage
Data
-
Klipfolio Inc.
and Hotjar
-
Backup saving and
management
-
-
-
Content performance and
features testing (A/B
testing)
-
Data transfer outside
the EU
-
Displaying content from
external platforms
-
-
Hosting and backend
infrastructure
-
Infrastructure
monitoring
-
Managing contacts and
sending messages
-
Mandrill
Personal Data:
email address;
Usage Data
-
Firebase
Notifications
Personal Data:
various types of
Data as
specified in the
privacy policy
of the service
-
Mailchimp
Personal Data:
email address
-
Twilio
Personal Data:
phone number
-
Operations
-
Error Tracking
and Logging
-
Registration and
authentication
-
Google OAuth and
Facebook
Authentication
Personal Data:
various types of
Data as
specified in the
privacy policy
of the service
-
Direct
registration
Personal Data:
academic
background;
address; company
name; country;
email address;
field of
activity; first
name; last name;
password; phone
number; profile
picture; state;
various types of
Data
-
-
Traffic optimization and
distribution
-
Further information about
Personal Data
-
-
Selling goods and
services online
The Personal Data
collected are used to
provide the User with
services or to sell
goods, including payment
and possible
delivery.
The
Personal Data collected
to complete the payment
may include the credit
card, the bank account
used for the transfer,
or any other means of
payment envisaged. The
kind of Data collected
by Nova Telehealth depends on
the payment system used.
-
Privacy Shield
Participation
Provider
Nova Telehealth
Purpose
Further
information about
Personal
Data
Personal
Data
collected
Various
types of data as
specified in the privacy
policy of the
service
Privacy
Policy
The
Owner participates in
and complies with the
EU-U.S. Privacy Shield
Framework and the
Swiss-U.S Privacy Shield
Framework as set forth
by the U.S. Department
of Commerce regarding
the collection, use, and
retention of Personal
Data transferred from
the European Union and
Switzerland to the
United States. The
policies and rights
outlined below are
therefore equally and
explicitly applicable to
Users from Switzerland,
except if stated
otherwise. The Owner has
certified to the
Department of Commerce
that it adheres to the
Privacy Shield
Principles.
If
there is any conflict
between the terms in
this privacy policy and
the Privacy Shield
Principles, the Privacy
Shield Principles shall
govern. To learn more
about the Privacy Shield
program, and to view the
Owner’s certification,
please visit
https://www.privacyshield.gov/
(or find the direct link
to the certification
list of Privacy Shield
participants maintained
by the Department of
Commerce
https://www.privacyshield.gov/list).
What
does this mean for
the European
User?
The
Owner is responsible for
all processing of
Personal Data it
receives under the
Privacy Shield Framework
from European Union
individuals and commits
to subject the processed
Personal Data to the
Privacy Shield
Principles.
This,
most importantly,
includes the right of
individuals to access
their personal data
processed by the
Owner.
The Owner
also complies with the
Privacy Shield
Principles for all
onward transfers of
Personal Data from the
EU, which means that it
remains liable in cases
of onward transfers to
third
parties.
With
respect to Personal Data
received or transferred
pursuant to the Privacy
Shield Framework, the
Owner is subject to the
investigatory and
regulatory enforcement
powers of the FTC, if
not stated otherwise in
this privacy
policy.
The Owner
is further required to
disclose Personal Data
in response to lawful
requests by public
authorities, including
to meet national
security or law
enforcement
requirements.
Dispute
resolution under the
Privacy
Shield
In
compliance with the
Privacy Shield
Principles, the Owner
commits to resolve
complaints about its
collection or use of the
User’s Personal Data.
European Union
individuals with
inquiries or complaints
regarding this Privacy
Shield policy should
first contact the Owner
at the contact details
supplied at the
beginning of this
document referring to
“Privacy Shield” and
expect the complaint to
be dealt with within 45
days.
In case of
failure by the Owner to
provide a satisfactory
or timely response, the
User has the option of
involving an independent
dispute resolution body,
free of
charge.
In this
regard, the Owner has
agreed to cooperate with
the panel established by
the EU data protection
authorities (DPAs), the
Swiss Federal Data
Protection and
Information Commissioner
(FDPIC), and comply with
the advice given by the
panel with regard to
data transferred from
the EU. The User may
therefore contact the
Owner at the email
address provided at the
beginning of this
document in order to be
directed to the relevant
DPA
contacts.
Under
certain conditions –
available for the User
in full on the Privacy
Shield website
(https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint)
– the User may invoke
binding arbitration when
other dispute resolution
procedures have been
exhausted.
Choice
Principle
The
User has the choice to
not agree to disclose
personal information
when first creating
account by accepting the
Owner's terms of service
and this Privacy Policy.
The User further can
contact support@novatelehealth.com
anytime and remove their
affirmation of this
choice.
-
Analysis and predictions
based on the User’s Data
(“profiling”)
The Owner may use the
Personal and Usage Data
collected through
Nova Telehealth to create or
update User profiles.
This type of Data
processing allows the
Owner to evaluate User
choices, preferences and
behaviour for the
purposes outlined in the
respective section of
this document.
User
profiles can also be
created through the use
of automated tools like
algorithms, which can
also be provided by
third parties. To find
out more about the
profiling activities
performed, Users can
check the relevant
sections of this
document.
The User
always has a right to
object to this kind of
profiling activity. To
find out more about the
User's rights and how to
exercise them, the User
is invited to consult
the section of this
document outlining the
rights of the User.
-
Automated
decision-making
Automated decision-making
means that a decision
which is likely to have
legal effects or
similarly significant
effects on the User, is
taken solely by
technological means,
without any human
intervention. Nova Telehealth
may use the User's
Personal Data to make
decisions entirely or
partially based on
automated processes
according to the
purposes outlined in
this document. Nova Telehealth
adopts automated
decision-making
processes as far as
necessary to enter into
or perform a contract
between User and Owner,
or on the basis of the
User’s explicit consent,
where such consent is
required by the law.
Automated decisions are
made by technological
means – mostly based on
algorithms subject to
predefined criteria –
which may also be
provided by third
parties.
The
rationale behind the
automated decision
making is:
- to enable or
otherwise improve
the decision-making
process;
- to grant Users fair
and unbiased
treatment based on
consistent and
uniform criteria;
- to reduce the
potential harm
derived from human
error, personal bias
and the like which
may potentially lead
to discrimination or
imbalance in the
treatment of
individuals etc.;
- to reduce the risk
of User's failure to
meet their
obligation under a
contract. To find
out more about the
purposes, the
third-party
services, if any,
and any specific
rationale for
automated decisions
used within Nova Telehealth,
Users can check the
relevant sections in
this document.
Consequences of
automated
decision-making
processes for Users and
rights of Users
subjected to it
As a consequence, Users
subject to such
processing, are entitled
to exercise specific
rights aimed at
preventing or otherwise
limiting the potential
effects of the automated
decisions taken.
In
particular, Users have
the right to:
- obtain an
explanation about
any decision taken
as a result of
automated
decision-making and
express their point
of view regarding
this decision;
- challenge a decision
by asking the Owner
to reconsider it or
take a new decision
on a different
basis;
- request and obtain
from the Owner human
intervention on such
processing.
To learn more about the
User’s rights and the
means to exercise them,
the User is invited to
consult the section of
this document relating
to the rights of the
User.
-
-
Owner and Data
Controller
Nova Telehealth
Owner contact
email:
support@novatelehealth.com
Full policy
Owner and Data
Controller
Nova Telehealth
Owner contact email: support@novatelehealth.com
Types of Data collected
Among the types of Personal Data that
Nova Telehealth collects, by itself or through third
parties, there are: Cookies; Usage Data;
unique device identifiers for advertising
(Google Advertiser ID or IDFA, for example);
email address; first name; last name; phone
number; address; password; company name;
country; state; various types of Data; field
of activity; profile picture; academic
background; website; Data communicated while
using the service.
Complete details on each type of Personal
Data collected are provided in the dedicated
sections of this privacy policy or by
specific explanation texts displayed prior
to the Data collection.
Personal Data may
be freely provided by the User, or, in case
of Usage Data, collected automatically when
using Nova Telehealth.
Unless specified
otherwise, all Data requested by Nova Telehealth is
mandatory and failure to provide this Data
may make it impossible for Nova Telehealth to
provide its services. In cases where Nova Telehealth
specifically states that some Data is not
mandatory, Users are free not to communicate
this Data without consequences to the
availability or the functioning of the
Service.
Users who are uncertain about
which Personal Data is mandatory are welcome
to contact the Owner.
Any use of Cookies
– or of other tracking tools – by Nova Telehealth or
by the owners of third-party services used
by Nova Telehealth serves the purpose of providing
the Service required by the User, in
addition to any other purposes described in
the present document and in the Cookie
Policy, if available.
Users are responsible for any third-party
Personal Data obtained, published or shared
through Nova Telehealth and confirm that they have
the third party's consent to provide the
Data to the Owner.
Mode and place of
processing the Data
Methods of processing
The Owner takes appropriate security measures
to prevent unauthorized access, disclosure,
modification, or unauthorized destruction of
the Data.
The Data processing is carried
out using computers and/or IT enabled tools,
following organizational procedures and
modes strictly related to the purposes
indicated. In addition to the Owner, in some
cases, the Data may be accessible to certain
types of persons in charge, involved with
the operation of Nova Telehealth (administration,
sales, marketing, legal, system
administration) or external parties (such as
third-party technical service providers,
mail carriers, hosting providers, IT
companies, communications agencies)
appointed, if necessary, as Data Processors
by the Owner. The updated list of these
parties may be requested from the Owner at
any time.
Legal basis of processing
The Owner may process Personal Data relating
to Users if one of the following applies:
- Users have given their consent for one
or more specific purposes. Note: Under
some legislations the Owner may be
allowed to process Personal Data until
the User objects to such processing
(“opt-out”), without having to rely on
consent or any other of the following
legal bases. This, however, does not
apply, whenever the processing of
Personal Data is subject to European
data protection law;
- provision of Data is necessary for the
performance of an agreement with the
User and/or for any pre-contractual
obligations thereof;
- processing is necessary for compliance
with a legal obligation to which the
Owner is subject;
- processing is related to a task that is
carried out in the public interest or in
the exercise of official authority
vested in the Owner;
- processing is necessary for the purposes
of the legitimate interests pursued by
the Owner or by a third party.
In any case, the Owner will gladly help to
clarify the specific legal basis that
applies to the processing, and in particular
whether the provision of Personal Data is a
statutory or contractual requirement, or a
requirement necessary to enter into a
contract.
Place
The Data is processed at the Owner's
operating offices and in any other places
where the parties involved in the processing
are located.
Depending on the User's
location, data transfers may involve
transferring the User's Data to a country
other than their own. To find out more about
the place of processing of such transferred
Data, Users can check the section containing
details about the processing of Personal
Data.
Users are also entitled to learn about the
legal basis of Data transfers to a country
outside the European Union or to any
international organization governed by
public international law or set up by two or
more countries, such as the UN, and about
the security measures taken by the Owner to
safeguard their Data.
If any such
transfer takes place, Users can find out
more by checking the relevant sections of
this document or inquire with the Owner
using the information provided in the
contact section.
Retention time
Personal Data shall be processed and stored
for as long as required by the purpose they
have been collected for.
Therefore:
- Personal Data collected for purposes
related to the performance of a contract
between the Owner and the User shall be
retained until such contract has been
fully performed.
- Personal Data collected for the purposes
of the Owner’s legitimate interests
shall be retained as long as needed to
fulfill such purposes. Users may find
specific information regarding the
legitimate interests pursued by the
Owner within the relevant sections of
this document or by contacting the
Owner.
The Owner may be allowed to retain Personal
Data for a longer period whenever the User
has given consent to such processing, as
long as such consent is not withdrawn.
Furthermore, the Owner may be obliged to
retain Personal Data for a longer period
whenever required to do so for the
performance of a legal obligation or upon
order of an authority.
Once the
retention period expires, Personal Data
shall be deleted. Therefore, the right to
access, the right to erasure, the right to
rectification and the right to data
portability cannot be enforced after
expiration of the retention period.
The purposes of
processing
The Data concerning the User is collected to
allow the Owner to provide its Service,
comply with its legal obligations, respond
to enforcement requests, protect its rights
and interests (or those of its Users or
third parties), detect any malicious or
fraudulent activity, as well as the
following: Analytics, Registration and
authentication, Handling payments, Hosting
and backend infrastructure, Managing
contacts and sending messages, Traffic
optimization and distribution, User database
management, Access to third-party accounts,
Infrastructure monitoring, Operations, Data
transfer outside the EU, Commercial
affiliation, Backup saving and management,
Contacting the User, Displaying content from
external platforms, Tag Management, Content
performance and features testing (A/B
testing) and Advertising.
For specific information about the Personal
Data used for each purpose, the User may
refer to the section “Detailed information
on the processing of Personal Data”.
Detailed
information on the processing of Personal
Data
Personal Data is collected for the following
purposes and using the following services:
-
Access to third-party accounts
This type of service allows
Nova Telehealth to access Data from
your account on a
third-party service and
perform actions with it.
These services are not
activated automatically, but
require explicit
authorization by the User.
Stripe account access
(Stripe Inc)
This service allows
Nova Telehealth to connect with
the User's account on
Stripe, provided by
Stripe, Inc.
Personal Data processed:
various types of Data as
specified in the privacy policy
of the service.
Place of
processing: United States –
Privacy
Policy.
Category of personal data
collected according to CCPA:
internet information.
-
Advertising
This type of service allows
User Data to be utilized for
advertising communication
purposes. These
communications are displayed
in the form of banners and
other advertisements on
Nova Telehealth, possibly based on
User interests.
This
does not mean that all
Personal Data are used for
this purpose. Information
and conditions of use are
shown below.
Some of
the services listed below
may use Cookies or other
Identifiers to identify
Users or they may use the
behavioral retargeting
technique, i.e. displaying
ads tailored to the User’s
interests and behavior,
including those detected
outside Nova Telehealth. For more
information, please check
the privacy policies of the
relevant services.
In
addition to any opt-out
feature offered by any of
the services below, Users
may opt out by visiting the
Network
Advertising Initiative
opt-out page.
Users may also
opt-out of certain
advertising features
through applicable
device settings, such as
the device advertising
settings for mobile
phones or ads settings
in general.
Google Ad Manager (Google
LLC)
Google Ad Manager is an
advertising
service provided by
Google LLC that allows
the Owner to run
advertising campaigns in
conjunction with
external advertising
networks that the Owner,
unless otherwise
specified in this
document, has no direct
relationship with. In
order to opt out from
being tracked by various
advertising networks,
Users may make use of Youronlinechoices.
In order to
understand Google's
use of data, consult Google's
partner
policy.
This
service uses the
“DoubleClick” Cookie,
which tracks use of
Nova Telehealth and User
behavior concerning ads,
products and services
offered.
Users may decide to
disable all the
DoubleClick Cookies by
going to: Google
Ad Settings.
Personal Data processed:
Cookies; Usage Data.
Place
of processing: United States
– Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
This processing constitutes a
sale based on the definition
under the CCPA. In addition
to the information in this
clause, the User can find
information regarding how to
opt out of the sale in the
section detailing the rights
of Californian consumers.
-
Analytics
The services contained in
this section enable the
Owner to monitor and analyze
web traffic and can be used
to keep track of User
behavior.
Google Analytics (Google
LLC)
Google Analytics is a web
analysis service
provided by Google Inc.
(“Google”). Google
utilizes the Data
collected to track and
examine the use of
Nova Telehealth, to prepare
reports on its
activities and share
them with other Google
services.
Google may
use the Data collected
to contextualize and
personalize the ads of
its own advertising
network.
Personal Data processed:
Cookies; Usage Data.
Place
of processing: United States
– Privacy
Policy – Opt
Out.
Category of personal data
collected according to CCPA:
internet information.
Google Analytics for
Firebase (Google LLC)
Google Analytics for
Firebase or Firebase
Analytics is an
analytics service
provided by Google
LLC.
In
order to understand
Google's use of
Data, consult Google's
partner
policy.
Firebase Analytics may
share Data with other
tools provided by
Firebase, such as Crash
Reporting,
Authentication, Remote
Config or Notifications.
The User may check this
privacy policy to find a
detailed explanation
about the other tools
used by the Owner.
Nova Telehealth uses identifiers
for mobile devices and
technologies similar to
cookies to run the
Firebase Analytics
service.
Users may opt-out of
certain Firebase
features through
applicable device
settings, such as the
device advertising
settings for mobile
phones or by following
the instructions in
other Firebase related
sections of this privacy
policy, if available.
Personal Data processed:
Cookies; unique device
identifiers for advertising
(Google Advertiser ID or IDFA,
for example); Usage Data.
Place of processing: United
States – Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
identifiers; internet
information.
Analytics collected directly
(Nova Telehealth)
Nova Telehealth uses an internal
analytics system that
does not involve third
parties.
Personal Data processed:
Cookies; Usage Data.
Category of personal data
collected according to CCPA:
internet information.
MixPanel (MixPanel)
MixPanel is an analytics
service provided by
Mixpanel Inc.
Personal Data processed:
Cookies; Usage Data.
Place
of processing: United States
– Privacy
Policy – Opt
Out.
Category of personal data
collected according to CCPA:
internet information.
Klipfolio Inc.
Klipfolio is
an online service that
enables Nova Telehealth to aggregate
diverse data from multiple
sources and quickly create a
new, actionable perspective
on the business. Nova Telehealth
integrates data from sources
to aggregate usage data,
payment history data, and
account signup or churn
data. Klipfolio combines
only data from sources
detailed within the Nova Telehealth
Privacy Policy and does not
collect or generate new
data.
Facebook Ads conversion
tracking (Facebook pixel)
(Facebook, Inc.)
Facebook Ads conversion
tracking (Facebook
pixel) is an analytics
service provided by
Facebook, Inc. that
connects data from the
Facebook advertising
network with actions
performed on Nova Telehealth.
The Facebook pixel
tracks conversions that
can be attributed to ads
on Facebook, Instagram
and Audience Network.
Personal Data processed:
Cookies; Usage Data.
Place
of processing: United States
– Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
This processing constitutes a
sale based on the definition
under the CCPA. In addition
to the information in this
clause, the User can find
information regarding how to
opt out of the sale in the
section detailing the rights
of Californian consumers.
Google Ads conversion
tracking (Google LLC)
Google Ads conversion
tracking is an analytics
service provided by
Google LLC that connects
data from the Google Ads
advertising network with
actions performed on
Nova Telehealth.
Personal Data processed:
Cookies; Usage Data.
Place
of processing: United States
– Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
This processing constitutes a
sale based on the definition
under the CCPA. In addition
to the information in this
clause, the User can find
information regarding how to
opt out of the sale in the
section detailing the rights
of Californian consumers.
Google Analytics with
anonymized IP (Google LLC)
Google Analytics is a web
analysis service
provided by Google LLC
(“Google”). Google
utilizes the Data
collected to track and
examine the use of
Nova Telehealth, to prepare
reports on its
activities and share
them with other Google
services.
Google may
use the Data collected
to contextualize and
personalize the ads of
its own advertising
network.
This
integration of Google
Analytics anonymizes
your IP address. It
works by shortening
Users' IP addresses
within member states of
the European Union or in
other contracting states
to the Agreement on the
European Economic Area.
Only in exceptional
cases will the complete
IP address be sent to a
Google server and
shortened within the US.
Personal Data processed:
Cookies; Usage Data.
Place
of processing: United States
– Privacy
Policy – Opt
Out. Privacy Shield
participant.
Category of personal data
collected according to CCPA:
internet information.
This processing constitutes a
sale based on the definition
under the CCPA. In addition
to the information in this
clause, the User can find
information regarding how to
opt out of the sale in the
section detailing the rights
of Californian consumers.
Hotjar
Hotjar is an
analytics and heat mapping
service used to display the
areas of a page where users
most frequently move the
mouse or click. This shows
where the points of interest
are, and helps us to
understand how providers
navigate the site so we can
improve Nova Telehealth
All data
is completely anonymous, and
you can
opt-out
at any
time.
ProviderHotjar
Ltd.
Personal
Data
collectedCookies
Usage data
This processing constitutes a
sale based on the definition
under the CCPA. In addition
to the information in this
clause, the User can find
information regarding how to
opt out of the sale in the
section detailing the rights
of Californian consumers.
-
Backup saving and management
This type of service allows
the Owner to save and manage
backups of Nova Telehealth on
external servers managed by
the service provider itself.
The backups may include the
source code and content as
well as the data that the
User provides to Nova Telehealth.
Backup on Google Drive
(Google LLC)
Google Drive is a service
to save and manage
backups provided by
Google LLC.
Personal Data processed:
various types of Data as
specified in the privacy policy
of the service.
Place of
processing: United States –
Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
-
Commercial affiliation
This type of service allows
Nova Telehealth to display
advertisements for
third-party products or
services. Ads can be
displayed either as
advertising links or as
banners using various kinds
of graphics.
Clicks on
the icon or banner posted on
the Application are tracked
by the third-party services
listed below, and are shared
with Nova Telehealth.
For
details of which data are
collected, please refer to
the privacy policy of each
service.
Amazon Affiliation (Amazon)
Amazon Affiliation is a
commercial affiliation
service provided by
Amazon.com Inc.
Personal Data processed:
Cookies; Usage Data.
Place
of processing: United States
– Privacy
Policy.
Category of personal data
collected according to CCPA:
internet information.
This processing constitutes a
sale based on the definition
under the CCPA. In addition
to the information in this
clause, the User can find
information regarding how to
opt out of the sale in the
section detailing the rights
of Californian consumers.
-
Contacting the User
Contact form (Nova Telehealth)
By filling in the contact
form with their Data,
the User authorizes
Nova Telehealth to use these
details to reply to
requests for
information, quotes or
any other kind of
request as indicated by
the form’s header.
Personal Data processed:
email address; first name; last
name; website.
Category of
personal data collected
according to CCPA:
identifiers; internet
information.
-
Content performance and features
testing (A/B testing)
The services contained in
this section allow the Owner
to track and analyze the
User response concerning web
traffic or behavior
regarding changes to the
structure, text or any other
component of Nova Telehealth.
Google Optimize (Google LLC)
Google Optimize is an A/B
testing service provided
by Google LLC
("Google").
Google may use Personal
Data to contextualize
and personalize the ads
of its own advertising
network.
Personal Data processed:
Cookies; Usage Data.
Place
of processing: United States
– Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
This processing constitutes a
sale based on the definition
under the CCPA. In addition
to the information in this
clause, the User can find
information regarding how to
opt out of the sale in the
section detailing the rights
of Californian consumers.
-
Data transfer outside the EU
The Owner is allowed to
transfer Personal Data
collected within the EU to
third countries (i.e. any
country not part of the EU)
only pursuant to a specific
legal basis. Any such Data
transfer is based on one of
the legal bases described
below.
Users can inquire
with the Owner to learn
which legal basis applies to
which specific service.
Other legal basis for Data
transfer abroad (Nova Telehealth)
If no other legal basis
applies, Personal Data
shall be transferred
from the EU to third
countries only if at
least one of the
following conditions is
met:
- the transfer is
necessary for the
performance of a
contract between the
User and the Owner
or of
pre-contractual
measures taken at
the User’s request;
- the transfer is
necessary for the
conclusion or
performance of a
contract concluded
in the interest of
the User between the
Owner and another
natural or legal
person;
- the transfer is
necessary for
important reasons of
public interest;
- the transfer is
necessary for
establishment,
exercise or defence
of legal claims;
- the transfer is
necessary in order
to protect the vital
interests of the
data subject or of
other persons, where
the data subject is
physically or
legally incapable of
giving consent. In
such cases, the
Owner shall inform
the User about the
legal bases the
transfer is based on
via Nova Telehealth.
Personal Data processed:
various types of Data.
Category of personal data
collected according to CCPA:
internet information.
Data transfer abroad based
on consent (Nova Telehealth)
If this is the legal
basis, Personal Data of
Users shall be
transferred from the EU
to third countries only
if the User has
explicitly consented to
such transfer, after
having been informed of
the possible risks due
to the absence of an
adequacy decision and
appropriate
safeguards.
In such
cases, the Owner shall
inform Users
appropriately and
collect their explicit
consent via Nova Telehealth.
Personal Data processed:
various types of Data.
Category of personal data
collected according to CCPA:
internet information.
Data transfer from the EU
and/or Switzerland to the
U.S based on Privacy Shield
(Nova Telehealth)
If this is the legal
basis, the transfer of
Personal Data from the
EU or Switzerland to the
US is carried out
according to the EU -
U.S. and Swiss - U.S.
Privacy Shield.
In
particular, Personal
Data is transferred to
services that
self-certify under the
Privacy Shield framework
and therefore guarantee
an adequate level of
protection of such
transferred Data. All
services are listed
within the relevant
section of this document
and those that adhere to
Privacy Shield can be
singled out by checking
their privacy policy and
possibly also by
specifically checking
for Privacy Shield
adherence in the
official Privacy Shield
List. Privacy Shield
also specifically
guarantees rights to
Users which can be found
in its most current form
on the website run by
the US Department of
Commerce.
Personal
Data may be transferred
from within the EU or
Switzerland to the U.S.
to services that are
not, or not anymore,
part of Privacy Shield,
only based on other
valid legal grounds.
Users can ask the Owner
to learn about such
legal grounds.
Personal Data processed:
various types of Data.
Category of personal data
collected according to CCPA:
internet information.
-
Displaying content from external
platforms
This type of service allows
you to view content hosted
on external platforms
directly from the pages of
Nova Telehealth and interact with
them.
This type of
service might still collect
web traffic data for the
pages where the service is
installed, even when Users
do not use it.
Google Fonts
Google Fonts is a
typeface visualization
service provided by
Google LLC or by Google
Ireland Limited,
depending on the
location Nova Telehealth is
accessed from, that
allows Nova Telehealth to
incorporate content of
this kind on its pages.
Personal Data processed:
Usage Data; various types of
Data as specified in the privacy
policy of the service.
Place
of processing: United States
– Privacy
Policy; Ireland – Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
YouTube video widget
YouTube is a video
content visualization
service provided by
Google LLC or by Google
Ireland Limited,
depending on the
location Nova Telehealth is
accessed from, that
allows Nova Telehealth to
incorporate content of
this kind on its pages.
Personal Data processed:
Cookies; Usage Data.
Place
of processing: United States
– Privacy
Policy; Ireland – Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
-
Handling payments
Payment processing services
enable Nova Telehealth to process
payments by credit card,
bank transfer or other
means. To ensure greater
security, Nova Telehealth shares
only the information
necessary to execute the
transaction with the
financial intermediaries
handling the
transaction.
Some of
these services may also
enable the sending of timed
messages to the User, such
as emails containing
invoices or notifications
concerning the payment.
Stripe (Stripe Inc)
Stripe is a payment
service provided by
Stripe Inc.
Personal Data processed:
various types of Data as
specified in the privacy policy
of the service.
Place of
processing: United States –
Privacy
Policy.
Category of personal data
collected according to CCPA:
internet information.
-
Hosting and backend
infrastructure
This type of service has the
purpose of hosting Data and
files that enable Nova Telehealth to
run and be distributed as
well as to provide a
ready-made infrastructure to
run specific features or
parts of Nova Telehealth. Some of
these services work through
geographically distributed
servers, making it difficult
to determine the actual
location where the Personal
Data are stored.
Amazon Web Services (AWS)
(Amazon Web Services, Inc.)
Amazon Web Services (AWS)
is a hosting and backend
service provided by
Amazon Web Services,
Inc.
Personal Data processed:
various types of Data as
specified in the privacy policy
of the service.
Place of
processing: United States –
Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
DigitalOcean (DigitalOcean
Inc.)
DigitalOcean is a hosting
service provided by
DigitalOcean Inc.
Personal Data processed:
various types of Data as
specified in the privacy policy
of the service.
Place of
processing: United States –
Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
iubenda Consent Solution
(iubenda srl)
iubenda Consent Solution
is a service that
facilitates the
collection and
management of proofs of
consent provided by
iubenda srl.
Personal Data processed:
Data communicated while using
the service.
Place of
processing: Italy – Privacy
Policy.
Category of personal data
collected according to CCPA:
internet information.
-
Infrastructure monitoring
This type of service allows
Nova Telehealth to monitor the use
and behavior of its
components so its
performance, operation,
maintenance and
troubleshooting can be
improved.
Which Personal
Data are processed depends
on the characteristics and
mode of implementation of
these services, whose
function is to filter the
activities of Nova Telehealth.
Uptime Robot (Buzpark
Bilisim Tarim Urunleri
Sanayi Tic. Ltd. Sti.)
Uptime Robot is a
monitoring service
provided by Buzpark
Bilisim Tarim Urunleri
Sanayi Tic. Ltd. Sti.
Personal Data processed:
various types of Data as
specified in the privacy policy
of the service.
Place of
processing: Turkey – Privacy
Policy.
Category of personal data
collected according to CCPA:
internet information.
-
Managing contacts and sending
messages
This type of service makes it
possible to manage a
database of email contacts,
phone contacts or any other
contact information to
communicate with the
User.
These services may
also collect data concerning
the date and time when the
message was viewed by the
User, as well as when the
User interacted with it,
such as by clicking on links
included in the message.
Mandrill (The Rocket Science
Group, LLC.)
Mandrill is an email
address management and
message sending service
provided by The Rocket
Science Group, LLC.
Personal Data processed:
email address; Usage Data.
Place of processing: United
States – Privacy
Policy.
Category of personal data
collected according to CCPA:
identifiers; internet
information.
Firebase Notifications
(Google LLC)
Firebase Notifications is
a message sending
service provided by
Google LLC. Firebase
Notifications can be
integrated with Firebase
Analytics to target
analytics-based
audiences and track
opening and conversion
events.
Personal Data processed:
various types of Data as
specified in the privacy policy
of the service.
Place of
processing: United States –
Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
Mailchimp (The Rocket
Science Group, LLC.)
Mailchimp is an email
address management and
message sending service
provided by The Rocket
Science Group, LLC.
Personal Data processed:
email address.
Place of
processing: United States –
Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
identifiers.
Twilio (Twilio, Inc.)
Twilio is a phone numbers
management and
communication service
provided by Twilio, Inc.
Personal Data processed:
phone number.
Place of
processing: United States –
Privacy
Policy.
Category of personal data
collected according to CCPA:
identifiers.
-
Operations
Error Tracking and Logging
This type of
service is used to report
and log errors to the
Nova Telehealth team in real time.
This helps Nova Telehealth improve
it's product and catch
errors before Users need to
make reports to
Nova Telehealth
TrackJs
TrackJS
is a JavaScript Error
Logging from TrackJS that
monitors your web
applications for JavaScript
errors, alerting you with
amazing context about how
the user, application, and
network got into
trouble.Personal Data
collected: various types of
Data as specified in the
privacy policy of the
service.Place of
processing: See the TrackJS
privacy policy –
https://trackjs.com/privacy/
loggly
Loggly
is an error logging and
monitoring service by
SolarWinds. Personal Data
collected: various types of
Data as specified in the
privacy policy of the
service.Place of
processing: See the Loggly
privacy policy -
https://www.loggly.com/about/privacy-policy/
-
Registration and authentication
By registering or
authenticating, Users allow
Nova Telehealth to identify them and
give them access to
dedicated services.
Depending on what is
described below, third
parties may provide
registration and
authentication services. In
this case, Nova Telehealth will be
able to access some Data,
stored by these third-party
services, for registration
or identification purposes.
Google OAuth (Google LLC)
Google OAuth is a
registration and
authentication service
provided by Google Inc.
and is connected to the
Google network.
Personal Data processed:
various types of Data as
specified in the privacy policy
of the service.
Place of
processing: United States –
Privacy
Policy.
Category of personal data
collected according to CCPA:
internet information.
Direct registration
(Nova Telehealth)
The User registers by
filling out the
registration form and
providing the Personal
Data directly to
Nova Telehealth.
Personal Data processed:
academic background; address;
company name; country; email
address; field of activity;
first name; last name; password;
phone number; profile picture;
state; various types of Data.
Category of personal data
collected according to CCPA:
identifiers; commercial
information; internet
information; sensorial
information; employment
related information.
Facebook Authentication
(Facebook, Inc.)
Facebook Authentication
is a registration and
authentication service
provided by Facebook,
Inc. and is connected to
the Facebook social
network.
Personal Data processed:
various types of Data as
specified in the privacy policy
of the service.
Place of
processing: United States –
Privacy
Policy.
Category of personal data
collected according to CCPA:
internet information.
-
Tag Management
This type of service helps
the Owner to manage the tags
or scripts needed on Nova Telehealth
in a centralized
fashion.
This results in
the Users' Data flowing
through these services,
potentially resulting in the
retention of this Data.
Google Tag Manager
Google Tag Manager is a
tag management service
provided by Google LLC
or by Google Ireland
Limited, depending on
the location Nova Telehealth is
accessed from.
Personal Data processed:
Usage Data.
Place of
processing: United States –
Privacy
Policy; Ireland – Privacy
Policy. Privacy
Shield participant.
Category of personal data
collected according to CCPA:
internet information.
-
Traffic optimization and
distribution
This type of service allows
Nova Telehealth to distribute their
content using servers
located across different
countries and to optimize
their performance.
Which
Personal Data are processed
depends on the
characteristics and the way
these services are
implemented. Their function
is to filter communications
between Nova Telehealth and the
User's browser.
Considering the widespread
distribution of this system,
it is difficult to determine
the locations to which the
contents that may contain
Personal Information of the
User are transferred.
Cloudflare (Cloudflare)
Cloudflare is a traffic
optimization and
distribution service
provided by Cloudflare
Inc.
The way
Cloudflare is integrated
means that it filters
all the traffic through
Nova Telehealth, i.e.,
communication between
Nova Telehealth and the User's
browser, while also
allowing analytical data
from Nova Telehealth to be
collected.
Personal Data processed:
Cookies; various types of Data
as specified in the privacy
policy of the service.
Place
of processing: United States
– Privacy
Policy.
Category of personal data
collected according to CCPA:
internet information.
-
User database management
This type of service allows
the Owner to build user
profiles by starting from an
email address, a personal
name, or other information
that the User provides to
Nova Telehealth, as well as to track
User activities through
analytics features. This
Personal Data may also be
matched with publicly
available information about
the User (such as social
networks' profiles) and used
to build private profiles
that the Owner can display
and use for improving
Nova Telehealth.
Some of these
services may also enable the
sending of timed messages to
the User, such as emails
based on specific actions
performed on Nova Telehealth.
Intercom (Intercom Inc.)
Intercom is a User
database management
service provided by
Intercom Inc. Intercom
can also be used as a
medium for
communications, either
through email, or
through messages within
Nova Telehealth.
Personal Data processed:
Cookies; email address; Usage
Data; various types of Data as
specified in the privacy policy
of the service.
Place of
processing: United States –
Privacy
Policy.
Category of personal data
collected according to CCPA:
identifiers; internet
information.
Further information about
Personal Data
-
Selling goods and services
online
The Personal Data
collected are used to
provide the User with
services or to sell
goods, including payment
and possible
delivery.
The
Personal Data collected
to complete the payment
may include the credit
card, the bank account
used for the transfer,
or any other means of
payment envisaged. The
kind of Data collected
by Nova Telehealth depends on
the payment system used.
-
Privacy Shield Participation
Provider
Nova Telehealth
Purpose
Further
information about Personal
Data
Personal Data
collected
Various
types of data as specified
in the privacy policy of the
service
Privacy
Policy
The Owner
participates in and complies
with the EU-U.S. Privacy
Shield Framework and the
Swiss-U.S Privacy Shield
Framework as set forth by
the U.S. Department of
Commerce regarding the
collection, use, and
retention of Personal Data
transferred from the
European Union and
Switzerland to the United
States. The policies and
rights outlined below are
therefore equally and
explicitly applicable to
Users from Switzerland,
except if stated otherwise.
The Owner has certified to
the Department of Commerce
that it adheres to the
Privacy Shield
Principles.
If there
is any conflict between the
terms in this privacy policy
and the Privacy Shield
Principles, the Privacy
Shield Principles shall
govern. To learn more about
the Privacy Shield program,
and to view the Owner’s
certification, please visit
https://www.privacyshield.gov/
(or find the direct link to
the certification list of
Privacy Shield participants
maintained by the Department
of Commerce
https://www.privacyshield.gov/list).
What
does this mean for the
European
User?
The
Owner is responsible for all
processing of Personal Data
it receives under the
Privacy Shield Framework
from European Union
individuals and commits to
subject the processed
Personal Data to the Privacy
Shield
Principles.
This,
most importantly, includes
the right of individuals to
access their personal data
processed by the
Owner.
The Owner also
complies with the Privacy
Shield Principles for all
onward transfers of Personal
Data from the EU, which
means that it remains liable
in cases of onward transfers
to third
parties.
With respect
to Personal Data received or
transferred pursuant to the
Privacy Shield Framework,
the Owner is subject to the
investigatory and regulatory
enforcement powers of the
FTC, if not stated otherwise
in this privacy
policy.
The Owner is
further required to disclose
Personal Data in response to
lawful requests by public
authorities, including to
meet national security or
law enforcement
requirements.
Dispute
resolution under the
Privacy
Shield
In
compliance with the Privacy
Shield Principles, the Owner
commits to resolve
complaints about its
collection or use of the
User’s Personal Data.
European Union individuals
with inquiries or complaints
regarding this Privacy
Shield policy should first
contact the Owner at the
contact details supplied at
the beginning of this
document referring to
“Privacy Shield” and expect
the complaint to be dealt
with within 45
days.
In case of
failure by the Owner to
provide a satisfactory or
timely response, the User
has the option of involving
an independent dispute
resolution body, free of
charge.
In this
regard, the Owner has agreed
to cooperate with the panel
established by the EU data
protection authorities
(DPAs), the Swiss Federal
Data Protection and
Information Commissioner
(FDPIC), and comply with the
advice given by the panel
with regard to data
transferred from the EU. The
User may therefore contact
the Owner at the email
address provided at the
beginning of this document
in order to be directed to
the relevant DPA
contacts.
Under
certain conditions –
available for the User in
full on the Privacy Shield
website
(https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint)
– the User may invoke
binding arbitration when
other dispute resolution
procedures have been
exhausted.
Choice
Principle
The
User has the choice to not
agree to disclose personal
information when first
creating account by
accepting the Owner's terms
of service and this Privacy
Policy. The User further can
contact support@novatelehealth.com
anytime and remove their
affirmation of this choice.
-
Analysis and predictions based
on the User’s Data (“profiling”)
The Owner may use the
Personal and Usage Data
collected through
Nova Telehealth to create or
update User profiles.
This type of Data
processing allows the
Owner to evaluate User
choices, preferences and
behaviour for the
purposes outlined in the
respective section of
this document.
User
profiles can also be
created through the use
of automated tools like
algorithms, which can
also be provided by
third parties. To find
out more about the
profiling activities
performed, Users can
check the relevant
sections of this
document.
The User
always has a right to
object to this kind of
profiling activity. To
find out more about the
User's rights and how to
exercise them, the User
is invited to consult
the section of this
document outlining the
rights of the User.
-
Automated decision-making
Automated decision-making
means that a decision
which is likely to have
legal effects or
similarly significant
effects on the User, is
taken solely by
technological means,
without any human
intervention. Nova Telehealth
may use the User's
Personal Data to make
decisions entirely or
partially based on
automated processes
according to the
purposes outlined in
this document. Nova Telehealth
adopts automated
decision-making
processes as far as
necessary to enter into
or perform a contract
between User and Owner,
or on the basis of the
User’s explicit consent,
where such consent is
required by the law.
Automated decisions are
made by technological
means – mostly based on
algorithms subject to
predefined criteria –
which may also be
provided by third
parties.
The
rationale behind the
automated decision
making is:
- to enable or
otherwise improve
the decision-making
process;
- to grant Users fair
and unbiased
treatment based on
consistent and
uniform criteria;
- to reduce the
potential harm
derived from human
error, personal bias
and the like which
may potentially lead
to discrimination or
imbalance in the
treatment of
individuals etc.;
- to reduce the risk
of User's failure to
meet their
obligation under a
contract. To find
out more about the
purposes, the
third-party
services, if any,
and any specific
rationale for
automated decisions
used within Nova Telehealth,
Users can check the
relevant sections in
this document.
Consequences of
automated
decision-making
processes for Users and
rights of Users
subjected to it
As a consequence, Users
subject to such
processing, are entitled
to exercise specific
rights aimed at
preventing or otherwise
limiting the potential
effects of the automated
decisions taken.
In
particular, Users have
the right to:
- obtain an
explanation about
any decision taken
as a result of
automated
decision-making and
express their point
of view regarding
this decision;
- challenge a decision
by asking the Owner
to reconsider it or
take a new decision
on a different
basis;
- request and obtain
from the Owner human
intervention on such
processing.
To learn more about the
User’s rights and the
means to exercise them,
the User is invited to
consult the section of
this document relating
to the rights of the
User.
The rights of Users
Users may exercise certain rights regarding
their Data processed by the Owner.
In particular, Users have the right to do the
following:
- Withdraw their consent at any
time. Users have the right to
withdraw consent where they have
previously given their consent to the
processing of their Personal Data.
- Object to processing of their
Data. Users have the right to
object to the processing of their Data
if the processing is carried out on a
legal basis other than consent. Further
details are provided in the dedicated
section below.
- Access their Data. Users have the
right to learn if Data is being
processed by the Owner, obtain
disclosure regarding certain aspects of
the processing and obtain a copy of the
Data undergoing processing.
- Verify and seek rectification.
Users have the right to verify the
accuracy of their Data and ask for it to
be updated or corrected.
- Restrict the processing of their
Data. Users have the right,
under certain circumstances, to restrict
the processing of their Data. In this
case, the Owner will not process their
Data for any purpose other than storing
it.
- Have their Personal Data deleted or
otherwise removed. Users have
the right, under certain circumstances,
to obtain the erasure of their Data from
the Owner.
- Receive their Data and have it
transferred to another
controller. Users have the right
to receive their Data in a structured,
commonly used and machine readable
format and, if technically feasible, to
have it transmitted to another
controller without any hindrance. This
provision is applicable provided that
the Data is processed by automated means
and that the processing is based on the
User's consent, on a contract which the
User is part of or on pre-contractual
obligations thereof.
- Lodge a complaint. Users have the
right to bring a claim before their
competent data protection authority.
Details about the right to object to
processing
Where Personal Data is processed for a public
interest, in the exercise of an official
authority vested in the Owner or for the
purposes of the legitimate interests pursued
by the Owner, Users may object to such
processing by providing a ground related to
their particular situation to justify the
objection.
Users must know that, however, should their
Personal Data be processed for direct
marketing purposes, they can object to that
processing at any time without providing any
justification. To learn, whether the Owner
is processing Personal Data for direct
marketing purposes, Users may refer to the
relevant sections of this document.
How to exercise these rights
Any requests to exercise User rights can be
directed to the Owner through the contact
details provided in this document. These
requests can be exercised free of charge and
will be addressed by the Owner as early as
possible and always within one month.
Cookie Policy
Nova Telehealth uses Trackers. To learn more, the
User may consult the Cookie
Policy.
Additional
information about Data collection and
processing
Legal action
The User's Personal Data may be used for
legal purposes by the Owner in Court or in
the stages leading to possible legal action
arising from improper use of Nova Telehealth or the
related Services.
The User declares to be
aware that the Owner may be required to
reveal personal data upon request of public
authorities.
Additional information about User's Personal
Data
In addition to the information contained in
this privacy policy, Nova Telehealth may provide the
User with additional and contextual
information concerning particular Services
or the collection and processing of Personal
Data upon request.
System logs and maintenance
For operation and maintenance purposes,
Nova Telehealth and any third-party services may
collect files that record interaction with
Nova Telehealth (System logs) use other Personal
Data (such as the IP Address) for this
purpose.
Information not contained in this policy
More details concerning the collection or
processing of Personal Data may be requested
from the Owner at any time. Please see the
contact information at the beginning of this
document.
How “Do Not Track” requests are handled
Nova Telehealth does not support “Do Not Track”
requests.
To determine whether any of the
third-party services it uses honor the “Do
Not Track” requests, please read their
privacy policies.
Changes to this privacy policy
The Owner reserves the right to make changes
to this privacy policy at any time by
notifying its Users on this page and
possibly within Nova Telehealth and/or - as far as
technically and legally feasible - sending a
notice to Users via any contact information
available to the Owner. It is strongly
recommended to check this page often,
referring to the date of the last
modification listed at the bottom.
Should the changes affect processing
activities performed on the basis of the
User’s consent, the Owner shall collect new
consent from the User, where required.
Information for Californian consumers
This part of the document integrates with and
supplements the information contained in the
rest of the privacy policy and is provided
by the business running Nova Telehealth and, if the
case may be, its parent, subsidiaries and
affiliates (for the purposes of this section
referred to collectively as “we”, “us”,
“our”).
The provisions contained in this section
apply to all Users who are consumers
residing in the state of California, United
States of America, according to "The
California Consumer Privacy Act of 2018"
(Users are referred to below, simply as
“you”, “your”, “yours”), and, for such
consumers, these provisions supersede any
other possibly divergent or conflicting
provisions contained in the privacy policy.
This part of the document uses the term
“personal information“ as it is defined in
The California Consumer Privacy Act (CCPA).
Categories of personal information
collected, disclosed or sold
In this section we summarize the categories
of personal information that we've
collected, disclosed or sold and the
purposes thereof. You can read about
these activities in detail in the
section titled “Detailed information on
the processing of Personal Data” within
this document.
Information we collect: the categories of
personal information we collect
We have collected the following categories of
personal information about you: identifiers,
commercial information, internet
information, sensorial information and
employment related information.
We will not collect additional categories of
personal information without notifying you.
How we collect information: what are the
sources of the personal information we
collect?
We collect the above mentioned categories of
personal information, either directly or
indirectly, from you when you use Nova Telehealth.
For example, you directly provide your
personal information when you submit
requests via any forms on Nova Telehealth. You also
provide personal information indirectly when
you navigate Nova Telehealth, as personal
information about you is automatically
observed and collected. Finally, we may
collect your personal information from third
parties that work with us in connection with
the Service or with the functioning of
Nova Telehealth and features thereof.
How we use the information we collect:
sharing and disclosing of your personal
information with third parties for a
business purpose
We may disclose the personal information we
collect about you to a third party for
business purposes. In this case, we enter a
written agreement with such third party that
requires the recipient to both keep the
personal information confidential and not
use it for any purpose(s) other than those
necessary for the performance of the
agreement.
We may also disclose your personal
information to third parties when you
explicitly ask or authorize us to do so, in
order to provide you with our Service.
To find out more about the purposes of
processing, please refer to the relevant
section of this document.
Sale of your personal information
For our purposes, the word “sale” means any
“selling, renting, releasing, disclosing,
disseminating, making available,
transferring or otherwise communicating
orally, in writing, or by electronic means,
a consumer's personal information by the
business to another business or a
third party, for monetary or other
valuable consideration”.
This means that, for example, a sale can
happen whenever an application runs ads, or
makes statistical analyses on the traffic or
views, or simply because it uses tools such
as social network plugins and the like.
Your right to opt out of the sale of
personal information
You have the right to opt out of the sale of
your personal information. This means that
whenever you request us to stop selling your
data, we will abide by your request.
Such
requests can be made freely, at any time,
without submitting any verifiable request,
simply by following the instructions below.
Instructions to opt out of the sale of
personal information
If you’d like to know more, or exercise your
right to opt out in regard to all the sales
carried out by Nova Telehealth, both online and
offline, you can contact us for further
information using the contact details
provided in this document.
What are the purposes for which we use your
personal information?
We may use your personal information to allow
the operational functioning of Nova Telehealth and
features thereof (“business purposes”). In
such cases, your personal information will
be processed in a fashion necessary and
proportionate to the business purpose for
which it was collected, and strictly within
the limits of compatible operational
purposes.
We may also use your personal information for
other reasons such as for commercial
purposes (as indicated within the section
“Detailed information on the processing of
Personal Data” within this document), as
well as for complying with the law and
defending our rights before the competent
authorities where our rights and interests
are threatened or we suffer an actual
damage.
We will not use your personal information for
different, unrelated, or incompatible
purposes without notifying you.
Your California privacy rights and how to
exercise them
The right to know and to portability
You have the right to request that we
disclose to you:
- the categories and sources of the
personal information that we collect
about you, the purposes for which we use
your information and with whom such
information is shared;
- in case of sale of personal information
or disclosure for a business purpose,
two separate lists where we disclose:
- for sales, the personal
information categories purchased
by each category of recipient;
and
- for disclosures for a business
purpose, the personal
information categories obtained
by each category of recipient.
The disclosure described above will be
limited to the personal information
collected or used over the past 12 months.
If we deliver our response electronically,
the information enclosed will be "portable",
i.e. delivered in an easily usable format to
enable you to transmit the information to
another entity without hindrance – provided
that this is technically feasible.
The right to request the deletion of your
personal information
You have the right to request that we delete
any of your personal information, subject to
exceptions set forth by the law (such as,
including but not limited to, where the
information is used to identify and repair
errors on Nova Telehealth, to detect security
incidents and protect against fraudulent or
illegal activities, to exercise certain
rights etc.).
If no legal exception applies, as a result of
exercising your right, we will delete your
personal information and direct any of our
service providers to do so.
How to exercise your rights
To exercise the rights described above, you
need to submit your verifiable request to us
by contacting us via the details provided in
this document.
For us to respond to your request, it’s
necessary that we know who you are.
Therefore, you can only exercise the above
rights by making a verifiable request which
must:
- provide sufficient information that
allows us to reasonably verify you are
the person about whom we collected
personal information or an authorized
representative;
- describe your request with sufficient
detail that allows us to properly
understand, evaluate, and respond to it.
We will not respond to any request if we are
unable to verify your identity and therefore
confirm the personal information in our
possession actually relates to you.
If you cannot personally submit a verifiable
request, you can authorize a person
registered with the California Secretary of
State to act on your behalf.
If you are an adult, you can make a
verifiable request on behalf of a minor
under your parental authority.
You can submit a maximum number of 2 requests
over a period of 12 months.
How and when we are expected to handle your
request
We will confirm receipt of your verifiable
request within 10 days and provide
information about how we will process your
request.
We will respond to your request within 45
days of its receipt. Should we need more
time, we will explain to you the reasons
why, and how much more time we need. In this
regard, please note that we may take up to
90 days to fulfill your request.
Our disclosure(s) will cover the preceding 12
month period.
Should we deny your request, we will explain
you the reasons behind our denial.
We do not charge a fee to process or respond
to your verifiable request unless such
request is manifestly unfounded or
excessive. In such cases, we may charge a
reasonable fee, or refuse to act on the
request. In either case, we will communicate
our choices and explain the reasons behind
it.
Definitions and legal references
Personal Data (or Data)
Any information that directly,
indirectly, or in connection with
other information — including a
personal identification number —
allows for the identification or
identifiability of a natural person.
Usage Data
Information collected automatically
through Nova Telehealth (or third-party
services employed in Nova Telehealth), which
can include: the IP addresses or
domain names of the computers
utilized by the Users who use
Nova Telehealth, the URI addresses (Uniform
Resource Identifier), the time of
the request, the method utilized to
submit the request to the server,
the size of the file received in
response, the numerical code
indicating the status of the
server's answer (successful outcome,
error, etc.), the country of origin,
the features of the browser and the
operating system utilized by the
User, the various time details per
visit (e.g., the time spent on each
page within the Application) and the
details about the path followed
within the Application with special
reference to the sequence of pages
visited, and other parameters about
the device operating system and/or
the User's IT environment.
User
The individual using Nova Telehealth who,
unless otherwise specified,
coincides with the Data Subject.
Data Subject
The natural person to whom the
Personal Data refers.
Data Processor (or Data Supervisor)
The natural or legal person, public
authority, agency or other body
which processes Personal Data on
behalf of the Controller, as
described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public
authority, agency or other body
which, alone or jointly with others,
determines the purposes and means of
the processing of Personal Data,
including the security measures
concerning the operation and use of
Nova Telehealth. The Data Controller, unless
otherwise specified, is the Owner of
Nova Telehealth.
Nova Telehealth (or this Application)
The means by which the Personal Data
of the User is collected and
processed.
Service
The service provided by Nova Telehealth as
described in the relative terms (if
available) and on this
site/application.
European Union (or EU)
Unless otherwise specified, all
references made within this document
to the European Union include all
current member states to the
European Union and the European
Economic Area.
Cookies
Small sets of data stored in the
User's device.
Legal information
This privacy statement has been
prepared based on provisions of
multiple legislations, including
Art. 13/14 of Regulation (EU)
2016/679 (General Data Protection
Regulation).
This privacy policy relates solely to
Nova Telehealth, if not stated otherwise
within this document.
Cookie Policy of Nova Telehealth
This document informs Users about the
technologies that help Nova Telehealth to achieve the
purposes described below. Such technologies
allow the Owner to access and store information
(for example by using a Cookie) or use resources
(for example by running a script) on a User’s
device as they interact with Nova Telehealth.
For simplicity, all such technologies are
defined as "Trackers" within this document –
unless there is a reason to differentiate.
For example, while Cookies can be used on both
web and mobile browsers, it would be inaccurate
to talk about Cookies in the context of mobile
apps as they are a browser-based Tracker. For
this reason, within this document, the term
Cookies is only used where it is specifically
meant to indicate that particular type of
Tracker.
Some of the purposes for which Trackers are used
may also require the User's consent. Whenever
consent is given, it can be freely withdrawn at
any time following the instructions provided in
this document.
Nova Telehealth uses Trackers managed directly by the
Owner (so-called “first-party” Trackers) and
Trackers that enable services provided by a
third-party (so-called “third-party” Trackers).
Unless otherwise specified within this document,
third-party providers may access the Trackers
managed by them.
The validity and expiration
periods of Cookies and other similar Trackers
may vary depending on the lifetime set by the
Owner or the relevant provider. Some of them
expire upon termination of the User’s browsing
session.
In addition to what’s specified in
the descriptions within each of the categories
below, Users may find more precise and updated
information regarding lifetime specification as
well as any other relevant information – such as
the presence of other Trackers - in the linked
privacy policies of the respective third-party
providers or by contacting the Owner.
To find more information dedicated to
Californian consumers and their privacy rights,
Users may read
the privacy policy.
Activities strictly necessary for the operation
of Nova Telehealth and delivery of the Service
Nova Telehealth uses so-called “technical” Cookies and
other similar Trackers to carry out activities
that are strictly necessary for the operation or
delivery of the Service.
Third-party Trackers
-
Traffic optimization and distribution
This type of service allows Nova Telehealth to
distribute their content using servers
located across different countries and
to optimize their performance.
Which
Personal Data are processed depends on
the characteristics and the way these
services are implemented. Their function
is to filter communications between
Nova Telehealth and the User's browser.
Considering the widespread distribution
of this system, it is difficult to
determine the locations to which the
contents that may contain Personal
Information of the User are transferred.
Cloudflare (Cloudflare)
Cloudflare is a traffic optimization and
distribution service provided by
Cloudflare Inc.
The way Cloudflare
is integrated means that it filters all
the traffic through Nova Telehealth, i.e.,
communication between Nova Telehealth and the
User's browser, while also allowing
analytical data from Nova Telehealth to be
collected.
Personal Data processed:
Cookies and various types of Data as
specified in the privacy policy of the
service. Place of processing: United
States – Privacy
Policy.
Other activities involving the use of Trackers
Experience enhancement
Nova Telehealth uses Trackers to provide a personalized
user experience by improving the quality of
preference management options, and by enabling
interaction with external networks and
platforms.
-
Displaying content from external
platforms
This type of service allows you to view
content hosted on external platforms
directly from the pages of Nova Telehealth and
interact with them.
This type of
service might still collect web traffic
data for the pages where the service is
installed, even when Users do not use
it.
YouTube video widget
YouTube is a video content visualization
service provided by Google LLC or by
Google Ireland Limited, depending on the
location Nova Telehealth is accessed from, that
allows Nova Telehealth to incorporate content of
this kind on its pages.
Personal
Data processed: Cookies and Usage Data.
Place of processing: United States – Privacy
Policy; Ireland – Privacy
Policy. Privacy Shield
participant.
Measurement
Nova Telehealth uses Trackers to measure traffic and
analyze User behavior with the goal of improving
the Service.
-
Analytics
The services contained in this section
enable the Owner to monitor and analyze
web traffic and can be used to keep
track of User behavior.
Google Analytics (Google LLC)
Google Analytics is a web analysis
service provided by Google Inc.
(“Google”). Google utilizes the Data
collected to track and examine the use
of Nova Telehealth, to prepare reports on its
activities and share them with other
Google services.
Google may use the
Data collected to contextualize and
personalize the ads of its own
advertising network.
Personal Data
processed: Cookies and Usage Data. Place
of processing: United States – Privacy
Policy – Opt Out.
Google Analytics for Firebase (Google
LLC)
Google Analytics for Firebase or Firebase
Analytics is an analytics service
provided by Google LLC.
In
order to understand Google's use of
Data, consult Google's
partner policy.
Firebase Analytics may share Data with
other tools provided by Firebase, such
as Crash Reporting, Authentication,
Remote Config or Notifications. The User
may check this privacy policy to find a
detailed explanation about the other
tools used by the Owner.
Nova Telehealth uses identifiers for mobile
devices and technologies similar to
cookies to run the Firebase Analytics
service.
Users may opt-out of certain Firebase
features through applicable device
settings, such as the device advertising
settings for mobile phones or by
following the instructions in other
Firebase related sections of this
privacy policy, if available.
Personal Data processed: Cookies, unique
device identifiers for advertising (Google
Advertiser ID or IDFA, for example) and
Usage Data. Place of processing: United
States – Privacy
Policy. Privacy Shield
participant.
MixPanel (MixPanel)
MixPanel is an analytics service provided
by Mixpanel Inc.
Personal Data
processed: Cookies and Usage Data. Place
of processing: United States – Privacy
Policy – Opt
Out.
Facebook Ads conversion tracking
(Facebook pixel) (Facebook, Inc.)
Facebook Ads conversion tracking
(Facebook pixel) is an analytics service
provided by Facebook, Inc. that connects
data from the Facebook advertising
network with actions performed on
Nova Telehealth. The Facebook pixel tracks
conversions that can be attributed to
ads on Facebook, Instagram and Audience
Network.
Personal Data processed:
Cookies and Usage Data. Place of
processing: United States – Privacy
Policy. Privacy Shield
participant.
Google Ads conversion tracking (Google
LLC)
Google Ads conversion tracking is an
analytics service provided by Google LLC
that connects data from the Google Ads
advertising network with actions
performed on Nova Telehealth.
Personal Data
processed: Cookies and Usage Data. Place
of processing: United States – Privacy
Policy. Privacy Shield
participant.
-
Analytics services managed directly by
Nova Telehealth
The services contained in this section
allow the Owner to collect and manage
analytics through the use of first-party
Trackers.
Analytics collected directly (Nova Telehealth)
Nova Telehealth uses an internal analytics system
that does not involve third parties.
Personal Data processed: Cookies and Usage
Data.
-
Anonymized analytics services
The services contained in this section
allow the Owner, through the use of
third-party Trackers, to collect and
manage analytics in an anonymized form.
Google Analytics with anonymized IP
(Google LLC)
Google Analytics is a web analysis
service provided by Google LLC
(“Google”). Google utilizes the Data
collected to track and examine the use
of Nova Telehealth, to prepare reports on its
activities and share them with other
Google services.
Google may use the
Data collected to contextualize and
personalize the ads of its own
advertising network.
This
integration of Google Analytics
anonymizes your IP address. It works by
shortening Users' IP addresses within
member states of the European Union or
in other contracting states to the
Agreement on the European Economic Area.
Only in exceptional cases will the
complete IP address be sent to a Google
server and shortened within the US.
Personal Data processed: Cookies and Usage
Data. Place of processing: United States
– Privacy
Policy – Opt Out. Privacy
Shield participant.
-
Content performance and features
testing (A/B testing)
The services contained in this section
allow the Owner to track and analyze the
User response concerning web traffic or
behavior regarding changes to the
structure, text or any other component
of Nova Telehealth.
Google Optimize (Google LLC)
Google Optimize is an A/B testing service
provided by Google LLC ("Google").
Google may use Personal Data to
contextualize and personalize the ads of
its own advertising network.
Personal Data processed: Cookies and Usage
Data. Place of processing: United States
– Privacy
Policy. Privacy Shield
participant.
Targeting & Advertising
Nova Telehealth uses Trackers to deliver personalized
marketing content based on User behavior and to
operate, serve and track ads.
-
Advertising
This type of service allows User Data to
be utilized for advertising
communication purposes. These
communications are displayed in the form
of banners and other advertisements on
Nova Telehealth, possibly based on User
interests.
This does not mean that
all Personal Data are used for this
purpose. Information and conditions of
use are shown below.
Some of the
services listed below may use Cookies or
other Identifiers to identify Users or
they may use the behavioral retargeting
technique, i.e. displaying ads tailored
to the User’s interests and behavior,
including those detected outside
Nova Telehealth. For more information, please
check the privacy policies of the
relevant services.
In addition to
any opt-out feature offered by any of
the services below, Users may opt out by
visiting the Network
Advertising Initiative opt-out
page.
Users may also opt-out of certain
advertising features through
applicable device settings, such as
the device advertising settings for
mobile phones or ads settings in
general.
Google Ad Manager (Google LLC)
Google Ad Manager is an advertising
service provided by Google LLC that
allows the Owner to run advertising
campaigns in conjunction with external
advertising networks that the Owner,
unless otherwise specified in this
document, has no direct relationship
with. In order to opt out from being
tracked by various advertising networks,
Users may make use of Youronlinechoices.
In order to understand Google's use
of data, consult Google's
partner policy.
This service
uses the “DoubleClick” Cookie, which
tracks use of Nova Telehealth and User behavior
concerning ads, products and services
offered.
Users may decide to disable all the
DoubleClick Cookies by going to: Google
Ad Settings.
Personal Data
processed: Cookies and Usage Data. Place
of processing: United States – Privacy
Policy. Privacy Shield
participant.
-
Commercial affiliation
This type of service allows Nova Telehealth to
display advertisements for third-party
products or services. Ads can be
displayed either as advertising links or
as banners using various kinds of
graphics.
Clicks on the icon or
banner posted on the Application are
tracked by the third-party services
listed below, and are shared with
Nova Telehealth.
For details of which data
are collected, please refer to the
privacy policy of each service.
Amazon Affiliation (Amazon)
Amazon Affiliation is a commercial
affiliation service provided by
Amazon.com Inc.
Personal Data
processed: Cookies and Usage Data. Place
of processing: United States – Privacy
Policy.
-
User database management
This type of service allows the Owner to
build user profiles by starting from an
email address, a personal name, or other
information that the User provides to
Nova Telehealth, as well as to track User
activities through analytics features.
This Personal Data may also be matched
with publicly available information
about the User (such as social networks'
profiles) and used to build private
profiles that the Owner can display and
use for improving Nova Telehealth.
Some of
these services may also enable the
sending of timed messages to the User,
such as emails based on specific actions
performed on Nova Telehealth.
Intercom (Intercom Inc.)
Intercom is a User database management
service provided by Intercom Inc.
Intercom can also be used as a medium
for communications, either through
email, or through messages within
Nova Telehealth.
Personal Data processed:
Cookies, email address, Usage Data and
various types of Data as specified in the
privacy policy of the service. Place of
processing: United States – Privacy
Policy.
How to manage preferences
and provide or withdraw consent
There are various ways to manage Tracker related
preferences and to provide and withdraw consent,
where relevant:
Users can manage preferences related to Trackers
from directly within their own device settings,
for example, by preventing the use or storage of
Trackers.
Additionally, whenever the use of Trackers is
based on consent, Users can provide or withdraw
such consent by setting their preferences within
the cookie notice or by updating such
preferences accordingly via the relevant
consent-preferences widget, if available.
It is also possible, via relevant browser or
device features, to delete previously stored
Trackers, including those used to remember the
User’s initial consent.
Other Trackers in the browser’s local memory may
be cleared by deleting the browsing history.
With regard to any third-party Trackers, Users
can manage their preferences and withdraw their
consent via the related opt-out link (where
provided), by using the means indicated in the
third party's privacy policy, or by contacting
the third party.
Locating Tracker Settings
Users can, for example, find information about
how to manage Cookies in the most commonly used
browsers at the following addresses:
Users may also manage certain categories of
Trackers used on mobile apps by opting out
through relevant device settings, such as the
device advertising settings for mobile devices,
or tracking settings in general (Users may open
the device settings, view and look for the
relevant setting).
Advertising industry specific opt-outs
Notwithstanding the above, Users may follow the
instructions provided by YourOnlineChoices
(EU), the Network
Advertising Initiative (US) and the Digital
Advertising Alliance (US), DAAC
(Canada), DDAI
(Japan) or other similar services. Such
initiatives allow Users to select their tracking
preferences for most of the advertising tools.
The Owner thus recommends that Users make use of
these resources in addition to the information
provided in this document.
The Digital Advertising Alliance offers an
application called AppChoices
that helps Users to control interest-based
advertising on mobile apps.
Owner and Data Controller
Nova Telehealth
Owner contact email: support@novatelehealth.com
Since the use of third-party Trackers through
Nova Telehealth cannot be fully controlled by the Owner,
any specific references to third-party Trackers
are to be considered indicative. In order to
obtain complete information, Users are kindly
requested to consult the privacy policies of the
respective third-party services listed in this
document.
Given the objective complexity surrounding
tracking technologies, Users are encouraged to
contact the Owner should they wish to receive
any further information on the use of such
technologies by Nova Telehealth.
Definitions and legal references
Personal Data (or Data)
Any information that directly, indirectly, or in
connection with other information — including a
personal identification number — allows for the
identification or identifiability of a natural
person.
Usage Data
Information collected automatically through
Nova Telehealth (or third-party services employed in
Nova Telehealth), which can include: the IP addresses or
domain names of the computers utilized by the
Users who use Nova Telehealth, the URI addresses
(Uniform Resource Identifier), the time of the
request, the method utilized to submit the
request to the server, the size of the file
received in response, the numerical code
indicating the status of the server's answer
(successful outcome, error, etc.), the country
of origin, the features of the browser and the
operating system utilized by the User, the
various time details per visit (e.g., the time
spent on each page within the Application) and
the details about the path followed within the
Application with special reference to the
sequence of pages visited, and other parameters
about the device operating system and/or the
User's IT environment.
User
The individual using Nova Telehealth who, unless
otherwise specified, coincides with the Data
Subject.
Data Subject
The natural person to whom the Personal Data
refers.
Data Processor (or Data Supervisor)
The natural or legal person, public authority,
agency or other body which processes Personal
Data on behalf of the Controller, as described
in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority,
agency or other body which, alone or jointly
with others, determines the purposes and means
of the processing of Personal Data, including
the security measures concerning the operation
and use of Nova Telehealth. The Data Controller, unless
otherwise specified, is the Owner of Nova Telehealth.
Nova Telehealth (or this Application)
The means by which the Personal Data of the User
is collected and processed.
Service
The service provided by Nova Telehealth as described in
the relative terms (if available) and on this
site/application.
European Union (or EU)
Unless otherwise specified, all references made
within this document to the European Union
include all current member states to the
European Union and the European Economic Area.
Cookie
Cookies are Trackers consisting of small sets of
data stored in the User's browser.
Tracker
Tracker indicates any technology - e.g Cookies,
unique identifiers, web beacons, embedded
scripts, e-tags and fingerprinting - that
enables the tracking of Users, for example by
accessing or storing information on the User’s
device.
Legal information
This privacy statement has been prepared based on
provisions of multiple legislations, including
Art. 13/14 of Regulation (EU) 2016/679 (General
Data Protection Regulation).
This privacy policy relates solely to Nova Telehealth, if
not stated otherwise within this document.