Privacy Policy

Effective date: July 1, 2019

Sessions, Inc (“us”, “we”, or “our”) operates the www.sessionshealth.com website (hereinafter referred to as the “Service”).

This page informs you of our policies regarding the collection, use and disclosure of personal data when you use our Service and the choices you have associated with that data.

We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, the terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, accessible from app.sessionshealth.com

Definitions:

Service

Service is the app.sessionshealth.com website operated by Sessions, Inc

Personal Data

Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).

Usage Data

Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

Cookies

Cookies are small files stored on your device (computer or mobile device).

Information Collection and Use:

We collect several different types of information for various purposes to provide and improve our Service to you.

Types of Data Collected:

Personal Data

While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Phone number
  • Address, State, Province, ZIP/Postal code, City
  • Cookies and Usage Data

We may use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send.

Usage Data

We may also collect information on how the Service is accessed and used (“Usage Data”). This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

Cookies

We use Cookies to help support certain parts of our Service. You can read more about it at our Cookie Policy.

Use of Data:

Sessions, Inc uses the collected data for various purposes:

  • To provide and maintain our Service
  • To notify you about changes to our Service
  • To allow you to participate in interactive features of our Service when you choose to do so
  • To provide customer support
  • To gather analysis or valuable information so that we can improve our Service
  • To monitor the usage of our Service
  • To detect, prevent and address technical issues
  • To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information

Transfer of Data:

Your information, including Personal Data, may be transferred to - and maintained on - computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to United States and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

Sessions, Inc will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organisation or a country unless there are adequate controls in place including the security of your data and other personal information.

Disclosure of Data:

Business Transaction

If Sessions, Inc is involved in a merger, acquisition or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

Disclosure for Law Enforcement

Under certain circumstances, Sessions, Inc may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Sessions, Inc may disclose your Personal Data in the good faith belief that such action is necessary to:

  • To comply with a legal obligation
  • To protect and defend the rights or property of Sessions, Inc
  • To prevent or investigate possible wrongdoing in connection with the Service
  • To protect the personal safety of users of the Service or the public
  • To protect against legal liability

Security of Data:

The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

Our Policy on “Do Not Track” Signals under the California Online Protection Act (CalOPPA):

We do not support Do Not Track (“DNT”). Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked.

You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.

Service Providers:

We may employ third party companies and individuals to facilitate our Service (“Service Providers”), provide the Service on our behalf, perform Service-related services or assist us in analyzing how our Service is used.

These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. Currently, these include:

  • Healthcare Blocks: This is our partner for hosting our primary web and database services. Healthcare Blocks helps us with maintaining our HIPAA-compliant infrastructure with server monitoring and security, and is itself hosted on Amazon Web Services. All of the main web traffic is encrypted end-to-end and monitored in real-time. All access to the application servers is behind a VPN. Healthcare Blocks helps us maintain database backups, access audits, and various tools to maintain data privacy and security. BAA: yes

  • Google Cloud: This is our partner for hosting our HIPAA-compliant telehealth services. Google helps us monitor and secure our telehealth infrastructure. We do not record any video of telehealth sessions. Audio may be relayed to handle speech-to-text recognition for audio features such as closed captioning, but is never persisted or stored. BAA: yes

  • Datadog: This is our partner for application-level monitoring and security. No client PHI will ever reach Datadog. We use Datadog for monitoring web application performance, along with temporary log storage and a web application firewall for specific application-level threat detection and management. BAA: yes

  • HelpScout: this is our partner for all customer support-related activities. All emails you send to support@sessionshealth.com are relayed through HelpScout and are triaged amongst the team. We also use HelpScout for our support documentation. BAA: yes

  • Claim.MD: This is our primary electronic clearinghouse. For you to submit claims electronically, receive remittances, or check eligibility, we may need to send and receive protected information. These are optional services. BAA: yes

  • Change Healthcare: This is our secondary electronic clearinghouse. Similar to Claim.MD, if you’re connecting with Change Healthcare, we may need to send and receive protected information. BAA: yes

  • Twilio: This is our SMS text and Voice appointment reminder partner. BAA: yes

  • Mailgun: This is our email delivery partner. BAA: yes

  • Stripe: This is our credit card processor. If you setup an account with Stripe and establish a connection between Stripe and Sessions Health, we need to share limited information about you and your clients for you to administer those transactions through Sessions Health. We do not share any health information. BAA: no, payment processors/financial institutions are exempt from the HIPAA Privacy Rule per the HHS.

Our Service may contain links to other sites that are not operated by us. If you click a third party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

Changes to This Privacy Policy:

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the “effective date” at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us:

If you have any questions about this Privacy Policy, please contact us.