PostureCo, Inc. Privacy Policy

Last revised: May 23, 2018

Personal/Clinic/Facility Information Collection, Methods and Use

By using any PostureCo, Inc. services or applications you agree that you are over the age of 18. You may be asked to provide your personal information anytime you are in contact with PostureCo, Inc. or an PostureCo affiliated companies. PostureCo, Inc. and its affiliates may share this customer information with each other and use it consistent with this Privacy Policy. They may also combine it with other information to provide and improve our products, services, content, and advertising.

Examples of the types of personal information PostureCo, Inc. may collect and how we may use it. This information includes everything except your personal passwords under the "Clinic Info" form in our application settings of the applications, which includes the following: Clinic/facility Name, Phone Number, Website address, physical address including state and zip code, along with the email address you are utilizing for all email fields. This is what is specified as "Personal Information" throughout this privacy policy.

What Types of information will PostureCo, Inc. collect?

How will PostureCo, Inc use your information?

Non-Personal Information

We also choose to collect non-personal information - data in a form that does not permit direct association with any specific individual. We may collect, use, transfer, and disclose non-personal information for any purpose. If we do combine non-personal information with personal information the combined information will be treated as personal information for as long as it remains combined.

When utilizing emails to you directly from our company, we will track open status and read or clicked links and they tell us whether mail has been opened. We may use this information to reduce or eliminate messages sent to customers. We will retain this information until you ask our company to delete such information.

Cookies and Other Technologies

PostureCo, Inc.'s website, applications, email messages, and web based advertisements may use "cookies" or other methods/utilities to obtain your information. You must be opt-in to this at time of your first exercise prescription otherwise your personal data will not be shared. These tools help tell us which parts of our website people have visited, and aid and gauge the efficacy of advertisements and web searches. We treat information collected by cookies and other technologies as non-personal information. However, to the extent that Internet Protocol (IP) addresses or similar identifiers are considered personal information by local law, we also treat these identifiers as personal information. Similarly, to the extent that non-personal information is combined with personal information, we treat the combined information as personal information for the purposes of this Privacy Policy.

PostureCo, Inc. and its partners use utilities and "cookies" in advertising services to control the number of times you are served an advertisement, and thus measure its reach and effectiveness.

PostureCo, Inc. and our partners also use cookies and other technical data collection to remember personal information when you use our website, online services, and applications. Our goal in these cases is to make your experience with our website and applications from PostureCo, Inc. are more personal and easier to use.

If you want to disable cookies please review steps with your internet browser. For information gathered with our mobile apps, you can not utilize the WebExercises service without sharing your clinic information with our company as well as affiliates as this is required to modify the client's outgoing email from you. With our website, we collect some information automatically and store it in log files. This information includes Internet Protocol (IP) addresses, browser type and language, Internet service provider (ISP), referring and exit pages, operating system, date/time stamp, and clickstream data.

We use this information to understand and analyze trends, to manage the site, to learn about user performance on the site, and to gather demographic information about our user base as a whole. PostureCo, Inc. may use this information in our marketing and advertising services.

In some of our email messages, we use a "click-through URL" linked to content on the PostureCo, Inc. website or the WebEexercises, Inc website when prescribing exercise prescriptions. When customers click one of these URLs, they pass through a separate web server before arriving at the destination page on our website. We track this data to help us determine interest in particular topics and measure the effectiveness of our customer communications. If you prefer not to be tracked in this way, you should not click text or graphic links in the email messages.

When utilizing emails to you directly from our company, we will track open status and read or clicked links and they tell us whether mail has been opened. We may use this information to reduce or eliminate messages sent to customers.

3rd Party Disclosures

At times PostureCo, Inc. may make certain personal information available to strategic partners that work with PostureCo, Inc. to provide products and services, or that help PostureCo, Inc. market to customers. Personal information will only be shared by PostureCo, Inc. to provide or improve our products, services and advertising; it will not be shared with third parties for their marketing purposes. Our current partners include WebExercises, Inc. and CBP Seminars, Inc.

Legal Disclosure Requests

It may be necessary - by law, legal process, litigation, and/or requests from public and governmental authorities within or outside your country of residence - for PostureCo, Inc. to disclose your personal information. We may also disclose information about you if we determine that for purposes of national security, law enforcement, or other issues of public importance, disclosure is necessary or appropriate.

We may also disclose information about you if we determine that disclosure is reasonably necessary to enforce our terms and conditions or protect our operations or users. Additionally, in the event of a reorganization, merger, or sale we may transfer any and all personal information we collect to the relevant third party.

Protection of Personal Information

PostureCo, Inc. takes safeguards to best defend your personal information against loss, theft, and misuse, as well as against unauthorized access, disclosure, alteration, and destruction. We utilize SSL encryption when handing off data to WebExercises and/or other affiliates such as electronic health care records systems you have elected to connect to our applications. Doing so protects the confidentiality of your personal information while it's transmitted over the Internet.

Access to Personal Information

If you wish to see what information we have collected about you, simply send us an affidavit notarized in form of a fax to 866-577-7297 or secure email to Info@PostureCo.com and we will disclose your information on file. Proof of identification will need to be verified prior to any such disclosures. Upon proof of identification, if you request us to delete such information, it will be deleted within 72 hours.

Children Under Age

We will not under any circumstances knowingly collect demographic data to be used by PostureCo, Inc or affiliates directly under age of 18. If we learn that we have collected the personal information of a child under 18 we will take steps to delete the information as soon as possible. By using our applications and clicking through this agreement you authenticate that you are 18 years or older. However, a professional can and routinely uses our application to objectively assess adolescents and children.

Location-Based Services

To provide location-based services on PostureCo, Inc. products, PostureCo, Inc. and our partners and licensees may collect, use, and share precise location data, including the real-time geographic location of your PostureCo, Inc. computer or device. This location data is collected anonymously in a form that does not personally identify you and is used by PostureCo, Inc. and we along with our affiliates provide periodic "Push Notifications" which aid in use of our application and/or our services. If you wish to opt out of location based services, you can do so through the operating system management of our applications and turn off location based services. By doing so, the application may not function for anything related to location based services.

Third-Party Sites and Services

PostureCo, Inc. websites, products, applications, and services may contain links to third-party websites, products, and services. Information collected by third parties, which may include such things as location data or contact details, is governed by their privacy practices. We encourage you to learn about the privacy practices of those third parties. For example, the EHR systems you connect our applications with as well as WebExercises, Inc. used for exercise prescriptions.

International Users and GDPR regulations

Information you provide may be transferred or accessed by entities around the world as described in this Privacy Policy. PostureCo, Inc. abides by the "safe harbor" frameworks set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information collected by organizations in the European Economic Area and Switzerland. Specific GDPR regulation questions are addressed below.

The PostureScreen, LeanScreen and SquatScreen apps do not require PII data of the app user. The user may enter non-PII data (business address, clinic name) which is stored on the device itself. The user may enter their own name (Dr. Mary Smith) to be used in outgoing email communications and customized reports which is stored on the device itself. Security, access, addition, removal, and monitoring of the data is the responsibility of the device owner.

The PostureScreen, LeanScreen and SquatScreen apps collect PII data of the user's clients. This data is entered into the apps by the user for the purpose of performing health screenings of the client. This client PII data is stored on the device itself. Security, access, addition, removal, and monitoring of the data is the responsibility of the device owner, which includes arrangements the owner has made with each individual client.

If the user connects to the SyncScreen cloud service they have the option to store client PII data on the PostureCo controlled storage systems. The storage systems are hosted by Amazon Web Services (AWS), which are GDPR compliant. In addition to using GDPR compliant storage systems, PostureCo's technology:

Finally, non-PII data is always stored on the PostureCo controlled analytics system, hosted by Google Cloud Platform which is GDPR compliant. This analytics data includes aggregate human body measurements (range of motion angles, postural translations) but does not contain PII data (name, address, government ID numbers).

If you are a patient or client of a healthcare or other professional who is using our services, you must contact them directly and ask for your record information and or deletion. Given many laws in place with HIPAA, records can not be deleted by PostureCo, Inc as they must be retained by health care providers even when you opt out of their care/services. You can, however ask they delete your electronic records themselves with our company and ask they keep a "paper file" for future records requests common within the healthcare landscape. It is the sole responsibility of the healthcare professional/fitness professional that is utilizing our services to maintain and comply with your requests on your personal electronic records. PostureCo, Inc. does not have patient/client level access to your files if stored within our SyncScreen cloud services, only the provider that placed them there has this "key" to your records.

Commitment to Your Privacy

To make sure your personal information is secure, we communicate our privacy and security guidelines to PostureCo, Inc. employees and strictly enforce privacy safeguards within the company.

Privacy Questions or Concerns

If you have any questions or concerns about PostureCo, Inc.'s Privacy Policy or data processing, please contact info@postureco.com PostureCo, Inc. may update its Privacy Policy from time to time. A copy of our most up to date privacy policy will always be posted at the following URL http://postureanalysis.com/privacy.htm until further notice.