Privacy Policy for WarmTalk Therapy

How We Collect, Store, Use, and Protect Your Data (HIPAA and GDPR Compliant)

We take your information very seriously. We go to great efforts to protect your data and keep it secure. If you ever find a violation of HIPAA or GDPR regulations, please contact us and inform us of the issue. We will resolve the issue as quickly as possible.
Contact
Contact

What is this document?

This Privacy Policy outlines how DMV Therapy & Life Coaching Services (hereinafter referred to as "WarmTalk Therapy") collects, uses, maintains, and discloses information collected from users (each, a "User") of the warmtalk.org website and the app.warmtalk.org platform (collectively, the "Site"). By accessing or using our Site, you agree to the collection and use of information in accordance with this policy.

Users: Any person using the WarmTalk Therapy sites.

Practitioners: Any person providing a service through the WarmTalk Therapy sites including, but not limited to, therapists, counselors, and coaches.

Patients: Any person seeking or actively engaging with a practitioner.

HIPAA Compliance

WarmTalk Therapy is committed to protecting the privacy and security of protected health information (PHI) in accordance with the Health Insurance Portability and Accountability Act (HIPAA). We have implemented safeguards to ensure the confidentiality, integrity, and availability of PHI, including encryption of sensitive data on app.warmtalk.org, except for the intake forms necessary for matching patients with practitioners.

Data Collection & Processing

Main Site (warmtalk.org): Collects non-sensitive visitor data, user IDs, event data, and conversion data. The Main Site uses cookies for tracking purposes and advertising purposes.

You can opt-out of data collection on the main site here:

PLACE TOGGLE HERE

App (app.warmtalk.org): Collects and stores sensitive information including intake forms, practitioner and patient notes, activities, and messages. Ensures end-to-end data encryption for all stored sensitive information, excluding intake forms.

At any time, you can opt-out of data collection on the app by going to Settings > Security & Privacy > Privacy Settings > Data Collection > Toggle Off

Please note that you cannot turn off the collection of user-submitted data such as PHI data as this is critical for app functionality and performance. By using the WarmTalk Therapy app, you agree to this policy.

Some pages on the app, app.warmtalk.org, use a tracking software called Google Analytics 4 (GA4) for performance and optimization purposes, but its tracking capabilities have been modified to be HIPAA compliant. We do not allow GA4 to collect any PII or PHI data. We do not permit GA4 to be used on pages of the app that display, collect, share, or otherwise use any PHI information. In the event that any PII or PHI information is collected by GA4, it is manually redacted and/or deleted. We do not use GA4 to collect any unnecessary data such as IP addresses, patient names, medical records, home address, email address, appointment dates or times, or any diagnosis from a practitioner from users of the app. If a user (practitioner, patient, contractor, employee, sponsor, or other individual engaging with the app) ever finds an instance of these tracking guidelines being violated, they are encouraged to report the event to WarmTalk Therapy immediately via WarmTalk’s contact page at warmtalk.org/contact

Data Sharing

Information collected on the main site, warmtalk.org, may be shared outside of the WarmTalk Therapy organization, including advertisers, third party organizations, and third party sites, such as advertising platforms, social media platforms, and search engines.

However, no information collected on the app, app.warmtalk.org, is shared outside of WarmTalk Therapy, or persons authorized to view the data, at any time. This includes prohibiting the sharing of any information with advertisers, third-party sites, or organizations.

Persons authorized to view data collected on the app, app.warmtalk.org, include the primary user (who is permitted to view, request, and/or delete data that is collected from them or a dependent of whom they are the legal guardian of), the user’s practitioner, individuals within the WarmTalk Therapy organization who have PHI data access, users who the primary user directly authorizes to share data with, and necessary colleagues of the practitioner as permitted by HIPAA guidelines.

Data Retention, Erasure, and Exporting

WarmTalk Therapy retains personal data only for as long as necessary for the purposes it was collected and in compliance with applicable laws. Users have the right to request the deletion or exporting of their personal data, subject to certain conditions and legal requirements.

Security & Anonymity

We implement robust security measures to protect against unauthorized access, alteration, disclosure, or destruction of your personal information and data stored on our Site. Our measures include, but are not limited to, encryption, physical security measures, and IT security solutions.

We also use automatic logouts from session timeouts due to inactivity. This feature can only be disabled in the settings as long as the user understands and accepts the inherent risks of turning off session timeouts.

Cookies & Web Beacons

The main site uses cookies to enhance User experience, track visits, and improve our services. Users can choose to set their web browser to refuse cookies or to alert when cookies are being sent.

California Compliance

In accordance with the California Consumer Privacy Act (CCPA), California residents have specific rights regarding their personal information. This section details these rights and how California residents can exercise them with WarmTalk Therapy.

UK Compliance

WarmTalk Therapy complies with the UK Data Protection Act 2018. This section explains the rights of UK residents under this act and how they can exercise them.

GDPR Compliance

WarmTalk Therapy adheres to the General Data Protection Regulation (GDPR), ensuring the protection and privacy of personal data for individuals within the European Union and European Economic Area. This section details the rights afforded to these individuals and how they can exercise them, including the right to access, correct, delete, or restrict processing of their data.

Non-US/UK/EU Notice

For Users outside the United States, United Kingdom, and European Union, WarmTalk Therapy strives to provide a consistent level of protection for personal information. This section outlines our global privacy practices and how Users can access or manage their personal information.

Document Updates

This Privacy Policy may be updated from time to time to reflect changes in our practices or legal obligations. We encourage Users to frequently check this page for any changes. Your continued use of the Site following the posting of changes to this policy will be deemed your acceptance of those changes.

For any questions or concerns regarding this Privacy Policy or our privacy practices, please contact us via the contact page at warmtalk.org/contact.