SerenePractice Privacy Policy
Last Updated: November 2, 2023
​
This Privacy Policy explains how SerenePractice manages and discloses Personal Information customers provide using our linked services. Please review it before using our services. Some services have privacy notices; those apply instead of this policy for those services. This policy doesn't create legal rights or obligations.
​
1. Note to SerenePractice Customers and their Clients
It's important to note that this Privacy Policy only applies to the Personal Information we collect from our customers, not to their patients and clients ("Clients") that we may collect while providing the Services. To understand how we collect and process personal information for Clients on behalf of our customers, please refer to the Client Portal Privacy Policy. Our agreements with our customers, including our Terms of Service and HIPAA Business Associate Agreement, govern our treatment of Client Personal Information. In case of any conflicts between our Agreement and this Privacy Policy, the provisions in our Agreement will control the extent of such conflict.
​
We have a limited relationship with our customers' Clients. If we receive any requests or inquiries from Clients regarding their Personal Information, we will honor those requests as applicable data privacy laws require. We will also direct Clients to our Customers, who are the controllers of their personal information, for further assistance.
​
2. Personal Information We Collect
Personal Information refers to any information that can be used to identify you or your household, directly or indirectly. This may include your name, email address, IP address, telephone number, and broader categories of information such as your professional, educational, or health information, commercial information, and internet activity. It's important to note that Personal Information does not include aggregated or de-identified information that cannot be associated with or linked to a person.
​
As we offer our services to you and conduct our business, we may collect Personal Information directly from you or automatically through cookies and other data-collection technologies. Personal Information may also be collected from third-party sources, such as our business partners, affiliates, and social media platforms (if you interact with us through your social media account). We will treat Personal Information collected from third-party sources by this Privacy Policy. However, we are not responsible for the accuracy of information provided by third parties or for their policies or practices.
​
The categories of Personal Information we collect from you depend on your interactions with us. For example, we may collect:
-
Identifiers and contact information include your name, email address, mailing address, phone numbers, government-issued IDs (such as driver’s licenses), IP addresses, and unique identifiers such as your usernames and passwords. We collect this information directly from you and third-party sources to create and manage your SerenePractice account (“Account”) for communicating with you, verifying your identity, and providing our Services to you.
-
Professional and employment-related information, such as your business name, your license information, calendar and scheduling information, and other information related to your business. We collect this information directly from you to administer your Account and provide you with our Services, including facilitating your use of our Continuing Education (CE) Marketplace.
-
Billing information, such as credit or debit card numbers and tax IDs. We collect this information directly from you to process your payments for our Services. We also collect your insurance information to process payments made to you by your Clients.
-
Audio, electronic, and visual information, such as your photograph or image, voice, and other similar information. We process this information to enable your use of our Telehealth service and to verify your identity when you send in images of your government-issued IDs. With your consent, we may also use videos of you for optional customer testimonials that we share internally.
-
Internet, device, and other electronic network activity information, such as browsing, search history, and interactions with our Services and advertisements. We collect this information through our cookies and other tracking technologies to conduct business analytics to improve our business functionality and Services. Please review the “Data Collection Technologies and Cookies” section below to learn more about our use of cookies and data collection technologies.
-
Commercial information, such as products and services you have purchased from us. We collect this information to maintain customer records, identify trends in our customer relationships, and conduct business analytics.
-
Profile information and inferences, such as information about your preferences and characteristics. We collect profile information by drawing inferences from the above categories of Personal Information to understand your preferences and tailor our services and communications to you.
-
Sensitive personal information includes your account login information, credit or debit card number, social security number, race or ethnic origin, sexual orientation and preferences, and religious or philosophical beliefs. We collect this information for you to log in, access, and pay for the Services. Your social security number (SSN) is only collected if you enter it in your Billing Settings. The last four digits of your SSN may also be collected if you apply for an Online Payments account. Race, ethnic origin, sexual orientation and preferences, and religious or philosophical beliefs are only collected if you enter it into the Services for your Professional Website, as applicable.
​
​
3. How We Use Personal Information
​
Apart from the purposes of collection mentioned earlier, we collect and use your Personal Information for various general purposes which include:
-
Maintaining and servicing your account includes providing requested product and service information and sending you product and service updates.
-
Responding to your customer service requests and addressing your queries and concerns.
-
Sending you newsletters and marketing communications. You can opt out of receiving our marketing and promotional communications as described in this Privacy Policy's “Access and Choice” section.
-
Administering and improving our services (including the Services) and marketing efforts. This includes measuring the effectiveness of our websites, diagnosing problems with our servers, and analyzing traffic.
-
Understanding and responding to your needs and preferences. This includes contacting and communicating with you regarding surveys, research, and evaluations. You can opt out of product research communications as described in this Privacy Policy's “Access and Choice” section.
-
Developing, enhancing, marketing, selling, or providing products and services.
-
Developing and managing our databases, businesses, and operations.
-
Engaging in business transactions, including providing products and services involving us and other third parties with whom we establish a relationship.Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and complying with our policies and procedures.
-
Complying with our legal, regulatory, and risk management obligations, including establishing, exercising, and/or defending legal claims.
-
Any other purpose with your consent.
Referral Program:
SerenePractice has a referral program that allows our existing customers to refer our Services to others. If a customer refers someone to SerenePractice, we will notify that person that a referral was generated. For those who receive a referral to our Services, we may collect their contact information from their colleague to send you the referral content. Please visit our Refer-a-Colleague page for more information about the terms of our referral program.
​
4. How We Share and Disclose Personal Information
​
We may share your Personal Information in the following circumstances:
We may share your Personal Information publicly on our websites with your permission. We may also share it with Service Providers, third parties, parent and affiliate companies, and other third parties with your consent. In some cases, we may be required to provide Personal Information to comply with legal processes. If SerenePractice is involved in a corporate transaction, we may share or transfer your Personal Information as part of any such transaction.
5. Access and Choice
Update your personal info by logging in and changing settings. To unsubscribe from marketing emails, click the link. We'll still email you about your account and transactions.
SerenePractice customers can cancel anytime, but export data first. Losing data is your responsibility.
For a copy of our HIPAA Business Associate Agreement, visit https://www.serenepractice.com/baa/. Canceling may mean the loss of some services.
If we contact you for research, we'll provide opt-out instructions.
6. Data Collection Technologies and Cookies
As with many digital properties, we and our third-party partners may automatically gather certain information from or related to your device when you visit or interact with our Services. This information may include:
-
Log Data: This includes internet protocol (IP) address, device type and version, operating system, browser type and version, browser ID, the URL visited and the referring page/campaign, date/time of visit, other user agent string data, the time spent on our Services, and any errors that may occur during the visit.
-
Analytics Data: This includes the electronic path you take to our Services, your usage and activity on our Services, such as the time zone, activity information (first and last active date and time), usage history (emails opened, total log-ins) as well as the pages and links you view, click or otherwise interact with. It also includes UTM sources.
-
Location Data: This includes a general geographic location inferred from your IP address.
We and our third-party Service Providers may use cookies or small data files that are sent to your browser from a web server and stored on your computer’s hard drive, as well as other related technologies such as web beacons, pixels, SDKs, embedded scripts, and data collection technologies to collect this information automatically. We may use this information to monitor and analyze how you use and interact with our Services.
We use the information gathered from these technologies to analyze trends, administer the Services, and track users’ movements around the Services.
If you prefer not to accept cookies, you can adjust your browser settings to: (i) notify you when you receive a cookie so you can choose whether or not to accept it; (ii) disable existing cookies; or (iii) set your browser to automatically reject cookies. However, please note that disabling cookies may negatively affect the functionality of this and many other websites that you visit. It may also result in disabling certain functionalities and features of the Services.
Please note that depending on your device and operating system, you may not be able to delete or block all cookies. Additionally, if you wish to reject cookies across all your browsers and devices, you will need to do so on each browser on each device you actively use. You may also set your email options to prevent the automatic downloading of images that may contain technologies that would provide us with information about your access to and engagement with the email and its contents.
7. Retention and Security
We will keep your Personal Information as long as your Account is active, to provide you with Services, comply with our legal obligations, resolve disputes, and enforce our agreements. We follow widely accepted standards to safeguard the Personal Information you provide to us, during transmission and once it is received. For instance, when you enter sensitive information such as your login credentials, we encrypt the transmission using secure socket layer technology (SSL). However, no method of transmission over the Internet, or method of electronic storage is completely secure. Hence, we cannot guarantee the absolute security of your information.
8. Data Privacy Statement
Residents of California, Colorado, Connecticut, Nevada, Utah, and Virginia have specific privacy rights under state law. The following disclosures apply to individual residents.
Personal Information Disclosures: In general, within the preceding 12 months:
-
We have gathered the types of Personal Information that are mentioned in Section 2. These categories of Personal Information have been collected either directly from you when you use our Services, automatically through data collection technologies, or from third parties. The collection is for the purposes mentioned in Sections 2 and 3.
-
For business purposes, we have shared the following categories of Personal Information: Identifiers and contact information; professional and employment-related information; billing information; audio, electronic, and visual information; commercial information; profile information and inferences; and internet network activity information.
-
We want to clarify that we have not sold your Personal Information.
Data Privacy Rights: Customers who wish to exercise the rights listed below should email support@serenepractice.com.
As our user, you have several rights regarding your personal information, which we take very seriously. These rights include:
-
The right to know: You can request to know what specific pieces of personal information we have about you, the categories of personal information we have collected about you in a designated period, the sources from which we collected that information, the categories of your personal information that we sold or disclosed in a designated period, the categories of third parties to whom your personal information was sold or disclosed in a designated period, and the purpose for collecting and selling your personal information.
-
The right to deletion: You can ask us to delete the personal information we have collected or maintain about you, but we may deny your request under certain circumstances such as legal obligations or the need to complete a transaction for which your personal information was collected. If we deny your request for deletion, we will explain why.
-
The right to correct: You can request correction of any inaccurate personal information we have about you.
-
The right to access and data portability: You have the right to easy and portable access to all pieces of personal information that we have collected or maintained about you.
-
The right to opt in and opt out of selling your personal information: We do not sell your personal information.
-
The right to opt in and opt out of sharing your personal information for cross-contextual behavioral advertising: You can manage your preferences here.
-
The right to limit the use and disclosure of sensitive personal information: You have the right to restrict how we use and disclose your sensitive personal information. We do not use, share, or disclose your sensitive personal information in any way except as outlined in this privacy policy to provide our services to you. We do not exchange sensitive personal information for targeted advertising or any commercial or monetary purposes.
-
The right to opt-out of profiling based upon personal data: You can opt out of any processing of personal data for the purposes of profiling for decisions that produce legal effects or similarly significant effects on you. We do not use your personal information for this purpose.
-
The right to equal service: If you choose to exercise any of these rights, we will not discriminate against you in any way. However, if you exercise certain rights, you may be unable to use or access certain features of our services.
We hope this information is helpful, and please don't hesitate to contact us if you have any questions or concerns about your personal information.
We will take steps to verify your identity before processing your privacy rights requests. We will not fulfill your request unless you have provided sufficient information to verify you are the individual about whom we collected Personal Information. If you have an Account with us and use our Services, we will use our existing Account authentication practices to verify your identity. If you do not have an Account with us, we may request additional information about you to verify your identity. We will only use the Personal Information provided in the verification process to verify your identity or authority to make a request and to track and document request responses unless you initially provided the information for another purpose.
You may use an authorized agent to submit a privacy rights request. When we verify your agent’s request, we may verify both your and your agent’s identity and request a signed document from you that authorizes your agent to request on your behalf. To protect your Personal Information, we reserve the right to deny a request from an agent that does not submit proof that you have authorized them to act on their behalf.
Appealing Privacy Rights Decisions: You may appeal a decision we have made concerning your privacy rights request. All appeal requests should be submitted by emailing us at support@serenepractice.com with the subject line “Privacy Request Appeal.”
​
Shine the Light: Our California customers are also entitled to request and obtain from SerenePractice once per calendar year information about any of your Personal Information shared with third parties for their direct marketing purposes, including the categories of information and the names and addresses of those businesses with which we have shared such information. To request this information, please contact us at support@serenepractice.com.
9. Additional Information
We comply with data protection laws when collecting and using your Personal Information. By using our Services, you acknowledge that your data will be transferred to and processed in the United States and other countries where we and our vendors operate.
Our Services may have social media features and widgets that may collect your IP address and set cookies. These Features are hosted by a third party or hosted directly on our Services.
Please note that the Services may link to other sites not owned or controlled by SerenePractice. This Privacy Policy applies only to information collected by our Services.
We do not knowingly collect any Personal Information from children under 13. If you believe that a child under 13 may have provided us with Personal Information, please get in touch with us at support@serenepractice.com.
We may update this Privacy Policy to reflect changes to our information practices. We encourage you to review this page periodically for the latest information on our privacy practices.
10. Contact Us
For assistance not relating to exercising privacy rights, please contact SerenePractice Support.
11. Google Calendar Integration
​
SerenePractice integrates with Google Calendar to enhance your experience and enable you to manage your practice more effectively by displaying your calendar events within our application. This integration requires the use of OAuth for secure access to your Google Calendar without exposing your login credentials.
To provide this functionality, we request the following Google Calendar permissions:
-
https://www.googleapis.com/auth/calendar.readonly: Allows SerenePractice to view your calendar events to display them within our application.
-
https://www.googleapis.com/auth/calendar.events.readonly: Permits SerenePractice to access details of calendar events including date, time, and description, so you can view these details within our calendar interface.
Data Access and Use:
We access your Google Calendar data only to retrieve calendar events and display them within our application interface. We do not store details of your calendar events in our databases nor do we use them for any other purpose than displaying them to you. Your calendar data remains within your Google account and is subject to Google's privacy policies and practices.​
Revoking Access:
You may revoke SerenePractice's access to your Google Calendar at any time through your Google Account settings. Upon revocation, SerenePractice will no longer be able to access your calendar information and will cease displaying it within our application.
​
For more information on how Google manages your data and your rights over your data, please review Google’s Privacy Policy and terms of service.
​
Security:
We employ industry-standard security measures to protect the data transmitted between your Google Calendar and SerenePractice. However, please note that no method of transmission over the Internet or method of electronic storage is completely secure. SerenePractice use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements
​
​
​
​
​