Nurselink Privacy Policy

March 26, 2025

Nurselink, Inc. ("Nurselink", Platform, "we," "us," or "our") recognizes the importance of protecting your privacy, and we are committed to taking great care with your personal information gathered during the access and use of www.nurselink.com and related applications and services controlled and administered by Nurselink that link to or refer to this Privacy Policy (collectively, the "Services").

We have prepared this Privacy Policy to provide the users ("Users", "you" or "your") with information about the treatment of your personal data and privacy practices applicable to Nurselink. For purposes of this Privacy Policy, Users include both Nurselink account holders and visitors who visit our website(s) and/or download our application(s) without creating a Nurselink account ("Visitors").

You acknowledge and accept the terms set under this Privacy Policy by using or accessing the Services in any manner and you hereby consent to the collection, use and share of the information you provide. The usage of the Services by you or on behalf of someone (such as your child) is solely permitted if you agree with and accept this Privacy Policy.

HIPAA and PHI

  1. Certain demographic, health and/or health-related information that Nurselink collects about Users on behalf of our Healthcare Providers as part of providing the Services may be "protected health information" ("PHI") governed by the Health Insurance Portability and Accountability Act ("HIPAA").
    1. Specifically, this may be true when Nurselink is providing administrative, operational, or other services to a Healthcare Provider that is a "Covered Entity" (as defined by HIPAA); and
    2. In order to provide those services, Nurselink receives identifiable information about a User on behalf of the Healthcare Provider, where Nurselink is acting as a "Business Associate" (as defined by HIPAA); and
    3. This identifiable information is regulated as PHI. This Privacy Policy does not apply to PHI, which is instead regulated by HIPAA.
    4. HIPAA provides specific protections for the privacy and security of PHI and restricts how PHI is used and disclosed.

Please read the Notice of Privacy Practices of your Healthcare Provider to understand how your PHI can be used and disclosed. Personal data that a User provides to Nurselink when Nurselink is not acting as a Business Associate is not PHI and Nurselink's use of this information is therefore covered by this Privacy Policy. To provide just a few examples, we are collecting personally identifiable information ("PII") when you create an account, search for Healthcare Providers or available appointments with Healthcare Providers; post reviews; provide device/IP Information or Web Analytics information by browsing our websites (see below); or (v) direct your Covered Entity healthcare provider to disclose PHI to Nurselink outside of its Business Associate capacity (e.g. pursuant to a HIPAA Authorization or access request).

Personal Data We Collect

  1. Account Holders and Visitors.
    1. Online Identifiers such as your internet protocol (IP) Address, IP address-based location information, your mobile device's GPS signal, or information about nearby Wi-Fi access points and cell towers, type of device, device ID, advertising identifiers, domain server, operating system, internet service provider, browser type used to access the Services;
    2. Web Analytics such as webpage interactions, web analytics, referring webpage, source through which you access the Services, the date and time of your access, non-identifiable request IDs, statistics associated with the interaction between your device or browser and the Services and other standard server login information;
    3. Other Identifying Information that you voluntarily choose to provide through means, such as emails, letters, or other communications you send us. We may use cookies, pixel tags, Local Shared Objects, and similar technologies to automatically collect this information.
  2. Account Holders Only.
    1. Patients
      1. Personal Identifiers, such as your full legal name, email address, phone number, address, zip code;
      2. Payment Information, such as your credit card number, expiration date, credit card security code;
      3. Booking Appointment Data, such as appointment date/time, Healthcare Provider information, appointment procedure, whether you are a new patient of a particular Healthcare Provider;
      4. Health Information such as health conditions, diagnosis, previous treatments, laboratory and pathology test results and reports, social histories, any family history of illness, and records about phone calls and emails related to your illness, Healthcare Provider(s) visited, reasons for these visit, dates of visits, medical history;
      5. Other Identifying Information that you voluntarily choose to provide through means, such as emails, letters, or other communications you send us.
    2. Healthcare Professionals.
      1. Personal Identifiers, such as your full legal name, social security number (SSN), email address, phone number, address, zip code, a photograph;
      2. Professional Information, such as your job title, practice area, primary specialty, certification, professional license/license status;
      3. Demographic Data, such as date of birth, gender/gender identity, sexual orientation, race, language spoken;
      4. Online Identifiers, such as your internet protocol (IP) Address, IP address-based location information, your mobile device's GPS signal, or information about nearby Wi-Fi access points and cell towers, type of device, device ID, advertising identifiers, domain server, operating system, internet service provider, browser type used to access the Services;
      5. Web Analytics such as webpage interactions, web analytics, referring webpage, source through which you access the Services, the date and time of your access, non-identifiable request IDs, statistics associated with the interaction between your device or browser and the Services and other standard server login information;
      6. Other Identifying Information that you voluntarily choose to provide through means, such as emails, letters, or other communications you send us.
    3. Healthcare Providers.
      1. Identifiers, such as facility name, address, contact information, Tax ID/ Employer Identification Number (EIN), National Provider Identifier (NPI) number;
      2. Professional Information, such as types of medical facilities (e.g., hospitals, specialty centers, clinics), specializations of medical facilities (e.g., general hospitals, cardiology hospitals, orthopedic hospitals);
      3. Online Identifiers, such as your internet protocol (IP) Address, IP address-based location information, type of device, device ID, advertising identifiers, domain server, operating system, internet service provider, browser type used to access the Services;
      4. Web Analytics such as webpage interactions, web analytics, referring webpage, source through which you access the Services, the date and time of your access, non-identifiable request IDs, statistics associated with the interaction between your device or browser and the Services and other standard server login information;
      5. Other Identifying Information that you voluntarily choose to provide through means, such as emails, letters, or other communications you send us.

Sources of Personal Data

  1. You
    1. Directly Provided:
      1. Information you provide during an account registration or use of our interactive tools and services, such as searching for Healthcare Providers or available appointments with Healthcare Providers;
      2. Information you provide through booking an appointment with a Healthcare Provider;
      3. Information you provide in free-form text boxes through the Services, through responses to surveys and questionnaires, or post reviews;
      4. Information you provide through means of electronic or other forms of communication.
    2. Automatically Obtained:
      1. Information collected through cookies, including essential cookies, functional cookies, performance/analytical cookies, retargeting/advertising cookies;
      2. Information collected if certain applications and/or software are downloaded and installed are made available. We may receive and collect information transmitted from your device for the purpose of providing you the relevant Services. This includes information such as when you are logged on and available to receive updates or alert notices.
      3. Information collected if you download our mobile application or use a location-enabled browser. We may receive information about your location and mobile device, as applicable.
  2. Obtained from Third Parties
    1. Obtained from Healthcare Providers. We may collect data from Healthcare Providers based on your identification information and other documentation you provided earlier.
    2. Obtained through Government Agencies. We may collect information about you through government agencies, such as Centers for Medicare and Medicaid Services (CMS), National Provider Identifier (NPI) Registry, U.S. Department of Health and Human Services (HHS), Health Resources and Services Administration.
    3. Obtained through Social Networks. We may collect data if you provide your social network account credentials to us or otherwise sign in to the Services through a third-party site or service, thus some content and/or information in those accounts may be transmitted into your account with us.
    4. Obtained from Analytics Partners. We may work with analytics partners to provide us analytics on website traffic or the usage of the Services to optimize and market our Services.
    5. Obtained through Advertising Partners. We may collect information about you from our marketing or promotional service providers in relation to your interaction with our Services, advertisements or communications.

Purposes for Collecting Personal Data

  1. Provision, Customization, and Improvement of the Services
    1. Creation and management of your account or other user profiles;
    2. Customization of the content you see when you use the Services;
    3. Billing our healthcare providers;
    4. Products, services, and information provision based on your request;
    5. Fulfillment of your requests for products, services, and information;
    6. Provision of support and assistance for the Services;
    7. Improvement of the Services, including testing, research, internal analytics, and product development;
    8. Personalizing the Services, website content, and communications based on your preferences and interests;
    9. Prevent potentially prohibited or illegal activities.
  2. Marketing
    1. Marketing and selling the Services;
    2. Advertisements, including interest-based or online behavioral advertising.
  3. Correspondence
    1. Responding to correspondence received from you, contacting you, reminding you of an upcoming appointment, and sending you information in regards to Nurselink or the Services;
    2. Communicating with you through electronic and other means to present content in accord to your preferences, as well as notifying you about certain resources, Healthcare Providers or Services.

Personal Data We Share

  1. Disclosure to Our Service Providers
    1. Disclosure to Our Payment Processing Partner, currently, Stripe, Inc., that collects the payment information you provide voluntarily. The information provided is necessary to process your payment. Please visit Stripe, Inc's Privacy and Terms via https://stripe.com/privacy for detailed information on its use and storage of Personal Data.
    2. Disclosure to Our Security and Fraud Prevention Consultants We share your personal Data for the purposes of detection and protection against security incidents, malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that.
    3. Disclosure to Our Healthcare Providers, Laboratories, Government Agencies, Insurance Companies, Organ Procurement Organizations, Medical Examiners and Other entities We may share your information for the purposes of providing you with relevant and necessary treatment options and support;
    4. Disclosure to Authorized third-party vendors and service providers. We may share your information with third-party vendors and service providers that help us with specialized services, including billing, customer service, email deployment, business analytics, performance monitoring, hosting, data processing and more;
    5. Disclosure to Our Research Partners We may share your information with our research partners to conduct health-related research; such sharing may be subject to your separate written authorization;
    6. Disclosure to Our Corporate Affiliates. We may share your information with our corporate affiliates that are subject to this policy.
    7. Disclosure to Other Parties Any information that you may reveal in a review posting or online discussion, or forum is intentionally open to the public and is not in any way private. We recommend that you carefully consider whether to disclose any Personal Data in any public posting or forum. What you have written may be seen and/or collected by third parties and may be used by others in ways we are unable to control or predict.
    8. Legal Purposes We may disclose information to respond to subpoenas, court orders, legal process, law enforcement requests, legal claims or government inquiries, and to protect and defend the rights, interests, health, safety, and security of Nurselink, Inc., our affiliates, users, or the public. If we are legally compelled to disclose information about you to a third party, we will attempt to notify you by sending an email to the email address in our records unless doing so would violate the law.

Notice

  1. In addition, each of the above referenced categories of Personal Data may be collected, used, and disclosed with the government, including law enforcement, or other parties to meet certain legal requirements and enforcing legal terms including: fulfilling our legal obligations under applicable law, regulation, court order or other legal process, such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities; protecting the rights, property or safety of you, Nurselink or another party; enforcing any agreements with you; responding to claims that any posting or other content violates third-party rights; and resolving disputes.
  2. All Personal Data may be transferred to a third party if we undergo a merger, acquisition, bankruptcy, or other transaction in which that third party assumes control of our business (in whole or in part). Should one of these events occur, we will make reasonable efforts to notify you before your information becomes subject to different privacy and security policies and practices.

Security

We use appropriate physical, technical, organizational, and administrative security measures based on the type of Personal Data and how we process that data to help protect information from loss, theft, misuse, and unauthorized access, disclosure, alteration, and destruction. We endeavor to follow generally accepted industry standards to protect the Personal Data submitted to us, both during transmission and in storage. reasonable measures.

For instance, the Services use industry-standard Secure Sockets Layer (SSL) technology to allow for the encryption of Personal Data. We store and process your information on our servers in the United States and abroad. We maintain what we consider industry-standard backup and archival systems. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanisms; limiting access to your computer or device and browser; and signing off after you have finished accessing your account.

Although we endeavor to protect the security of your account and other data that we hold in our records, for example, by making good faith efforts to store Personal Data in a secure operating environment that is not open to the public, you should be aware that no data storage system or transmission of data over the Internet or any other public network can be guaranteed to be 100 percent secure. Please note that to our best knowledge all third parties are HIPAA compliant and, the information they collect have the same extent of security protection as the information you submit to us however, we are not and cannot be held responsible for protecting the security of such information.

Your Choices

  1. You may opt-out of receiving general health and wellness or treatment options that may be relevant to you by emailing us at privacy@nurselink.com. You may also request that we delete your personal information by sending us an email at privacy@nurselink.com. In addition, you may opt out of all unessential Cookies at any time here. You can also decide whether to accept Cookies through your internet browser's settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on your browser software) allowing you to decide on acceptance of each new Cookie in a variety of ways. You may also be able to reject mobile device identifiers by activating the appropriate setting on your mobile device. You can also delete all Cookies that are already on your device. Although you are not required to accept Nurslink's Cookies, if you block, reject, or delete them, you may have to manually adjust some preferences every time you access the Services, as some functionalities may not work.
  2. We may not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect. For more information about your choices, see the HIPAA Notice referenced above. You may be able to refuse or disable cookies by adjusting your web browser settings. Because each web browser is different, please consult the instructions provided by your web browser (typically in the "Help" section). Please note that you may need to take additional steps to refuse or disable Local Shared Objects and similar technologies. For example, Local Shared Objects can be controlled through the instructions on Adobe's Setting Manager page. If you choose to refuse, disable, or delete these technologies, some of the functionality of the Services may no longer be available to you.

Third-Party Advertising, Links, and Content

  1. Nurselink uses third-party vendors and service providers that help us provide you the Services. These third-party vendors and service providers only collect information about your use of our Platform in order to support us in providing you the Services. Some of our websites may contain links to content maintained by third parties that we do not control. These third parties may use this information to display advertisements on our websites and elsewhere online tailored to your interests, preferences, and characteristics. Some of these third parties may participate in an industry organization that gives users the opportunity to opt-out of receiving ads that are tailored based on your online activities.
  2. Due to differences between using apps and websites on mobile devices, you may need to take additional steps to disable targeted ad technologies in mobile apps. Many mobile devices allow you to opt-out of targeted advertising for mobile apps using the settings within the mobile app or your mobile device. For more information, please check your mobile settings. You also may uninstall our apps using the standard uninstall process available on your mobile device or app marketplace. We are not responsible for the privacy practices of these third parties, and the information practices of these third parties are not covered by this Privacy Policy. To opt-out of interest-based advertising across browsers and devices from companies that participate in the Digital Advertising Alliance or Network Advertising Initiative opt-out programs, please visit their respective websites. You may also be able to opt-out of interest-based advertising through the settings within the mobile app or your mobile device, but you opt-out choice may apply only to the browser or device you are using when you opt-out, so you should opt-out on each of your browsers and devices if you want to disable all cross-device linking for interest-based advertising. If you opt-out, you will still receive ads, but they may not be as relevant to you and your interests, and your experience on our Services may be degraded.

Do-Not-Track Signals and Similar Mechanisms.

Some web browsers transmit "do-not-track" signals to websites, which allows you to signal to operators of websites and web applications, and services that you do not wish such operators to track your online activities over time and across different websites. Because of differences in how web browsers incorporate and activate this feature, it is not always clear whether users intend for these signals to be transmitted, or whether they even are aware of them. We currently do not take action in response to these signals.

Data Retention

We retain Personal Data about you as necessary to provide our Services or to perform our business or commercial purposes for collecting your Personal Data. When establishing a retention period for specific categories of data, we consider who we collected the data from, our need for the Personal Data, why we collected the Personal Data, and the sensitivity of the Personal Data. In some cases, we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, provide our Services, or is otherwise permitted or required by applicable law, rule or regulation. We may further retain information in a de-identified and/or aggregated form where that information would not identify you personally.

For example:

  1. We retain your account information and credentials for as long as you have an account with us.
  2. We retain your device/IP data for as long as we need it to ensure that our systems are working appropriately, effectively, and efficiently.
  3. We retain any PHI consistent with our obligations under our Business Associate Agreements with Covered Entities and HIPAA.

Children's Privacy

  1. The Services are not directed to or intended for use by anyone under the age of 18. If you are a child under 18 years of age, please do not attempt to register for or otherwise use the Services or send us any Personal Data. By accessing, using and submitting information to or via the Services, you represent that you achieved the age of 18.
  2. Please note, that we do not deliberately collect or solicit Personal Data from children under the age of 18. In the event we learn that any Personal Data has been provided directly by a child under 13 years of age without first receiving their parent's verified consent, we will use that Personal Data only to respond directly to that child or their parent or legal guardian to inform that the child is not permitted to use the Services. We will then subsequently delete that child's Personal Data. If you believe that a child under 18 may have provided us with Personal Data, please contact us at privacy@nurselink.com.
  3. If you are between the age 13 and 18, you may use the Services only with the consent of or under the supervision of your parent or legal guardian.
  4. If you are a parent or legal guardian of a minor child, you may, in compliance with the Agreement, use the Services on behalf of such minor child. Any information that you provide us while using the Services on behalf of your minor child will be treated as Personal Data as otherwise provided herein.
  5. If you use the Services on behalf of another person, regardless of age, you agree that Nurselink may contact you for any communication made in connection with providing the Services or any legally required communications. You further agree to forward or share any such communication with any person for whom you are using the Services on behalf of.

Controlling Your Personal Data and Notifications

If you are a registered User of the Services, you can modify certain Personal Data or account information by logging in and accessing your account. If you wish to close your account, please e-mail us at privacy@nurselink.com. Nurselink will use reasonable efforts to delete your account as soon as reasonably possible. Please note, however, that Nurselink reserves the right to retain information from closed accounts consistent with our internal data retention policies and procedures. You must promptly notify us if any of your account data is lost, stolen, or used without permission.

California Rights and Disclosures

Under the California Consumer Privacy Act of 2018 (CCPA), California residents have additional privacy rights which are addressed in this Section 7. These rights apply solely to California residents and are in addition to the rights stated in this Privacy Policy. The CCPA does not apply to information regulated either by the California Confidentiality of Medical Information Act (CMIA), the Health Insurance Portability and Accountability Act of 1996 (HIPAA), or the Health Information Technology for Economic and Clinical Health Act (HITECH), nor does it apply to covered entities, including providers of healthcare, and their business associates, who maintain patient information in accordance with those laws.

We do not sell your personal information, have not sold your personal information within the prior 12 months, and only use and disclose your personal information as stated in this Privacy Policy.

You have the right to request we provide you with details about the information we collect and disclose about you within the prior 12 months, including:

  1. the categories of personal information we collect about you,
  2. the categories of the sources of personal information we collect about you,
  3. our business or commercial purpose for collecting that information,
  4. the categories of personal information that were disclosed for a business purpose,
  5. the categories of third parties to whom we disclosed that personal information, and
  6. the specific pieces of personal information we collect about you.

You may also request that we delete your information. These rights are subject to certain exceptions and limitations permitted by CCPA.

To submit an access or deletion request, you may email us at privacy@nurselink.com stating your request with sufficient detail and providing information that allows us to reasonably verify you as the person whose data is the subject of such request. We will not respond to more than two requests from you in a 12-month period. We will not discriminate against you if you exercise your rights under CCPA. By exercising your rights, you will not be:

  1. subject to denial of goods or services,
  2. charged a different price or rate, or
  3. provided a different quality of service.

Other U.S. State Rights and Disclosures

If you are a resident of Virginia, Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Washington State (solely with respect to consumer health information) or another state with a similar comprehensive consumer privacy law, you may have certain rights regarding your information. Please see the "Exercising Your Rights" section below for instructions regarding how to exercise these rights.

Please note that these rights are subject to certain conditions and exceptions under applicable law, which may permit or require us to deny your request.

If you have any questions about this section or whether any of the following rights apply to you, please contact us at privacy@nurselink.com and indicate "State Rights" in the subject line of your communication.

Exercising Your Rights

For the purposes of exercising your rights under the CCPA or other state laws as described above, you must send us a request that provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Data and contains a thorough and detailed description of your request to allow us to understand, evaluate, and respond to it correctly. Each request that meets both of these criteria will be considered a "Valid Request." We will only use Personal Data provided in a Valid Request to verify you and complete your request. If you are a Healthcare Provider with a profile on our Services, you do not need an account to submit a Valid Request.

We will respond to your Valid Request within the applicable time period required by law. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.

If you have questions or difficulty submitting a Valid Request, you can call us at (000) 000-0000 or email us at privacy@nurselink.com.

Changes to this Privacy Policy

We reserve the right to amend our Privacy Policy at our discretion and at any time. If we make material changes to the Privacy Policy, we will notify you by email or through a notice on our website homepage. When we update the Privacy Policy, we will revise the "Effective Date" date above and post the new Privacy Policy. Use of the information we collect is subject to the Privacy Policy in effect at the time such information is collected. We recommend that you review the Privacy Policy each time you visit the Services to stay informed of our privacy practices.

Contact Information

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data, your choices, and rights regarding such use, please do not hesitate to contact us at:

E-mail: privacy@nurselink.com

Address: Nurselink, Inc., 530 West Stocker Street 304, Glendale, CA 91202, USA

Phone:

Fax: