I. About This Statement
This California Privacy Statement supplements the Teledris Health Privacy Policy and applies only to natural persons who are residents of the State of California. It describes how Teledris Health collects, uses, discloses, and otherwise processes Personal Information about California Residents, and the rights California Residents have under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
II. Important Note on Medical Information and CMIA
Most of the health information you provide to Teledris Health to receive care is medical information under the California Confidentiality of Medical Information Act and protected health information under HIPAA. That information is largely exempt from CCPA.
However, the CCPA continues to apply to other Personal Information we collect about California Residents that is not CMIA medical information or HIPAA PHI, including account, billing, marketing, and website-usage information.
III. Categories of Personal Information We Collect
In the 12 months preceding the effective date, and on an ongoing basis, we may collect the following categories of Personal Information about California Residents:
| CCPA Category | Examples | Collected? |
|---|---|---|
| A. Identifiers | Real name, alias, email address, postal address, phone number, IP address, account name, online identifiers | Yes |
| B. Customer records | Name, address, telephone number, payment information | Yes |
| C. Protected classifications | Age, sex, gender as relevant to clinical care | Yes |
| D. Commercial information | Records of products or services purchased | Yes |
| E. Biometric information | — | No |
| F. Internet/electronic activity | Browsing and search history, interactions with the Platform, device and connection information | Yes |
| G. Geolocation | Approximate location based on IP address; state of residence. Precise geolocation only with consent | Yes (approximate); No (precise) |
| H. Sensory information | Audio recordings of customer support calls, where consented | Yes |
| I. Professional or employment information | — | No |
| J. Education information | — | No |
| K. Inferences | Profiles reflecting preferences, characteristics, behavior | Yes |
| L. Sensitive Personal Information | See Section IV | Yes |
We do not knowingly collect PI from children under 16.
IV. Sensitive Personal Information
The CCPA defines a category of Sensitive Personal Information that California Residents have the right to limit. We may collect the following categories of SPI:
- Government-issued identifiers used solely for identity verification.
- Account log-in credentials.
- Precise geolocation, only if you grant access.
- Racial or ethnic origin collected only when you choose to disclose it for clinical relevance.
- Contents of your communications with Teledris Health unless you initiated them.
- Health, biometric, sex life, or sexual orientation information, most of which is exempt under HIPAA and CMIA as described above.
We use SPI only for purposes permitted by CCPA, including providing the goods and services you request, preventing fraud, maintaining service quality and safety, and complying with law.
V. Sources of Personal Information
- Directly from you through intake forms, account creation, communications, and payments.
- Automatically through your use of the Platform, including cookies, web beacons, and analytics.
- From service providers and partners such as clinical vendors, partner pharmacies, payment processors, and identity verification providers.
- From publicly available sources where applicable for fraud or identity verification.
VI. Business and Commercial Purposes
- Providing telehealth and care services you request.
- Communicating with you about your care, your account, and our services.
- Processing payments.
- Verifying identity and preventing fraud.
- Improving and maintaining the Platform.
- Marketing and advertising consistent with this Statement and your choices.
- Complying with legal obligations and enforcing our terms.
- Ensuring information security and operational integrity.
VII. Disclosure of Personal Information
In the 12 months preceding the effective date, we disclose or have disclosed PI in the following categories to the following types of recipients:
- Identifiers, customer records, and commercial information to affiliated providers, partner pharmacies, payment processors, identity verification providers, cloud hosting providers, communications platforms, and analytics providers.
- Internet activity and inferences to analytics providers, cloud hosting providers, and advertising partners only if applicable.
- Sensitive PI on a limited basis to identity verification providers and payment processors.
- Audio recordings to telephony providers and customer support tooling.
All recipients acting as service providers or contractors under CCPA are bound by written contracts that prohibit selling, sharing, or using PI for purposes other than performing services for us.
A. Sale of PI
We do not sell PI for monetary consideration.
C. Sale or Sharing of Sensitive Personal Information
We do not sell or share SPI.
VIII. Retention
We retain PI for as long as necessary to fulfill the purposes for which it was collected, including:
- Medical records retained per HIPAA and California medical record retention requirements.
- Billing records retained per applicable tax and financial regulations, typically 7 years.
- Account records retained as long as the account is active and for a reasonable period afterward to support reactivation, fraud prevention, and dispute resolution.
- Marketing records retained until you opt out or for the period required to honor your preferences.
IX. Your California Privacy Rights
California Residents have the following rights with respect to non-exempt PI we hold about them:
A. Right to Know
You may request that we disclose the categories of PI we have collected about you, the sources of that information, the categories disclosed or shared, the categories of recipients, the business or commercial purpose for collection or sharing, and the specific pieces of PI we hold about you.
B. Right to Delete
You may request that we delete PI we have collected about you, subject to legal and operational exceptions.
C. Right to Correct
You may request that we correct inaccurate PI we maintain about you. We will use commercially reasonable efforts to correct PI as directed.
D. Right to Opt Out of Sale or Sharing
We do not sell PI and do not currently share PI for cross-context behavioral advertising. You may still submit an opt-out request, which we will honor as confirmation.
E. Right to Limit Use of Sensitive Personal Information
We limit our use of SPI to purposes permitted by CCPA Section 1798.121(a). You may submit a request to limit, which we will treat as a request to confirm our practices.
F. Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights.
G. Right to Portability
When you exercise your right to know specific pieces of PI, we will provide your PI in a portable and, to the extent technically feasible, readily usable format.
X. How to Exercise Your Rights
To submit a request to know, delete, correct, opt out, or limit, use one of the following methods:
- Web form: [request URL — to be set]
- Email: privacy@teledrishealth.com with the subject line California Privacy Request
- Mail: Privacy Officer, Teledris Health, 7800 SW 87th Ave, Miami, FL 33155
We will respond within 45 days, with one 45-day extension permitted under CCPA, with notice to you.
Verification
For your protection, we will verify your identity before honoring a request. Sensitive requests may require additional verification.
Free of Charge
Most requests are free. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline, with notice and an explanation of your right to appeal.
XI. Shine the Light
California Residents who have an established business relationship with us may request information about our disclosures of certain categories of PI to third parties for those third parties' direct marketing purposes. We do not currently disclose PI for third-party direct marketing purposes.
XII. Do-Not-Track and GPC Signals
Some browsers send a Do Not Track signal. There is no industry consensus on how to interpret DNT, and we do not currently respond to DNT signals.
We do honor browser-based Global Privacy Control signals as an opt-out of sale or sharing under CCPA, where applicable.
XIII. CMIA and HIPAA
Medical information governed by CMIA and PHI under HIPAA are not subject to CCPA. For details about how we handle medical information and your rights, see:
- Teledris Health Notice of Privacy Practices.
- Teledris Health Privacy Policy.
XIV. Aggregate Metrics
We process the PI of fewer than 10,000,000 California Residents. We are therefore not currently required to publish CCPA aggregate metrics under 11 CCR §7102. If our threshold changes, we will publish required metrics annually.
XV. Changes
We may update this Statement from time to time. The Last Updated date above reflects the most recent revision. Material changes will be communicated through the Platform or by email.
XVI. Contact
Privacy Officer
Teledris Health
7800 SW 87th Ave, Miami, FL 33155
privacy@teledrishealth.com
