Patient Privacy Policy

Effective: August 08, 2023

THIS PATIENT PRIVACY POLICY APPLIES TO PERSONAL INFORMATION COLLECTED BY SPIRE, INC., DOING BUSINESS AS SPIRE HEALTH (“SpireHealth”, “We”, “Us” and/or “Our”) FROM USERS OF OUR APPLICATIONS (THE “APPLICATION”) OR OTHER SERVICES (COLLECTIVELY, THE “SERVICES”).

PERSONAL INFORMATION” INCLUDES ANY INFORMATION THAT CAN BE USED ON ITS OWN OR WITH OTHER INFORMATION TO IDENTIFY OR CONTACT A SINGLE PERSON. IF WE CAN LINK PARTICULAR INFORMATION (DIRECTLY OR INDIRECTLY) TO AN INDIVIDUAL, WE WILL CONSIDER THIS INFORMATION PERSONAL INFORMATION, AND WE WILL PROTECT IT. CAPITALIZED TERMS, IF NOT AVAILABLE IN THIS PRIVACY POLICY, ARE DEFINED IN THE TERMS OF USE, WHICH IS ALSO ACCESSIBLE THROUGH THE APPLICATION.

Introduction

We at Spire Health value keeping Your Personal Information confidential and using it solely in the context of Our mission to provide Our Services that gather information related to Your health in order to aid You and Your healthcare providers (“Providers”) in making informed decisions about Your care.

BECAUSE THE PERSONAL INFORMATION WE COLLECT AND TRANSMIT ON BEHALF OF OTHER ORGANIZATIONS MAY INCLUDE PROTECTED HEALTH INFORMATION, INCLUDING MEDICAL INFORMATION, OUR PRIVACY PRACTICES ARE INTENDED TO COMPLY WITH THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (“HIPAA”). WE WILL MAINTAIN THE PRIVACY OF YOUR HEALTH INFORMATION AS REQUIRED BY HIPAA AND THE REGULATIONS PROMULGATED UNDER THAT ACT.

We believe that transparency about the use of Your Personal Information is important.  In this Privacy Policy, We provide You detailed information about Our collection, use, maintenance, and disclosure of Your Personal Information. The policy explains what kind of information We collect, when and how We might use that information, how We protect the information, and Your rights regarding Your Personal Information. Wherever Spire Health collects Personal Information, We make an effort to provide a link to this Privacy Policy.

YOU ARE ACKNOWLEDGING THAT YOU HAVE READ AND AGREE TO THE TERMS OF THIS POLICY.  IF YOU DO NOT AGREE, PLEASE DO NOT ACCESS THE APPLICATION OR SERVICES AND DO NOT SUBMIT ANY INFORMATION TO US.

As a patient of one or more of Our participating Provider customers (a “Patient” and/or “You”), You have received an enrollment kit, which contains health and activity-monitoring devices, including Spire Health Tags (“Tags”) and a mobile device pre-loaded with Our Application (the “Hub,” collectively the Tags and Hub are the Spire “Devices”). By using Our Devices and Services, You will make information related to Your health and activities (“Health Data”) available to Your Providers.

What Information Do We Collect and Why?

Personal Data that You Provide through the Services: We collect Personal Information, including certain demographic information, from You when You voluntarily provide such information, such as when You agree to enroll in the Services, use the Devices in connection with the Services (including, without limitation, use of the Application featured on the Devices and/or platforms made available by the third-party providers of the Devices (collectively, the “Integrated Services”)), contact Us (by phone, email or in writing) with inquiries, engage with Spire representatives through our Remote Patient Monitoring service, enter information into Our Site contact form, or use certain features of the Services. We use this information to create Your account and provide the Services to You.

To deliver the Services, We may ask You to provide demographic information, in addition to Your contact preferences and certain contact information, including Your home address, email address and telephone number. When You use the Devices along with the Application, Spire Health collects other Health Data in order to create Your account and provide You the Services. Such Health Data may include information including Your name, gender, height, weight, as well as data about Your use of Our Services and Devices, such as detailed information collected while monitoring Your movements and activity. This information may include data on Your posture and movements, and other related biomechanical information such as Your respiration, pulse rate, and sleep activity. We collect this information to provide You more customized Services and to communicate information to Your Provider.

Support Information:

IP Addresses; Device ID Information: If You are accessing the Services through the Spire Hub, We may also request access to settings and location information to analyze and report upon usage of the Services; to diagnose and prevent service or technology problems affecting the Services; and to monitor and prevent fraud and abuse.

Non-Identifiable Data Related to Operation of the Services: When You interact with Spire Health through the Services, We receive and store certain de-identified information. Such information, which We collect passively using various technologies, cannot presently be used to specifically identify You. We may store such information Ourselves or include it in databases owned and maintained by Spire Health affiliates, agents or service providers. The Services may use such information and pool it with other information to track, for example, the total number of users of the Services, the number of visitors to each page of Our Site, and the domain names of Our visitors' Internet service providers. It is important to note that Spire Health does not use Personal Information for this process.

De-identified and Aggregated Personal Data: In an ongoing effort to better understand and serve Our Customers and other users of the Services, Spire Health may conduct research or case studies on Patient demographics and behavior based on the Personal Information We collect from You and the other Health Data information provided to us. This research may be compiled and analyzed on an aggregate basis, and We may share this research and related information in aggregated, de-identified and/or anonymized format with Our affiliates, agents and other entities in the healthcare research and services industry, including without limitation insurance and pharmaceutical companies. For the avoidance of doubt, this aggregate de-identified and/or anonymized information cannot be used to identify You personally. Spire Health may also disclose aggregated, de-identified and/or anonymized information in order to describe Our business and the Services to current and prospective business partners and Customers, and to other third parties for other lawful purposes.

Where Is Your Personal Information Stored And/Or Processed?

Information Spire Health collects through Our Devices will be stored on secure U.S.-based servers.

Will Spire Health Share Personal Information With Anyone Else?

We consider Your information to be a vital part of Our relationship with You. There are, however, certain circumstances in which We may share Your Personal Information with certain third parties without further notice to You, as set forth below:

With Our Customers: We will share Your Personal Information and Health Data with Our Provider customer(s) that provide healthcare services to You.This will enable Your Provider to track Your Health Data and combine such Health Data with other information about You that Your Provider obtains in providing healthcare services to You.

With Patient-Authorized Persons: You may have the option of identifying family and/or friends in the Spire Health application to view certain of Your information and receive alerts regarding Your health and/or activities (“Permissions”). If You designate Permissions, We may make certain of Your Personal Information and Health and Activity Data, and alerts related thereto, available to such authorized person(s).

In the Event of a Business Transfer: Spire Health might sell or buy businesses or assets. In the event of a corporate sale, merger, reorganization, dissolution or similar event, Personal Information may be part of the transferred assets.

With Our Agents, Consultants and Related Third Parties: Spire Health, like many businesses, sometimes hires other companies to perform certain business-related functions. Examples of such functions include mailing information and maintaining databases.  When We employ another entity to perform a function of this nature, We only provide the entity with the information that it needs to perform its specific function.

To Meet Our Legal Requirements: Spire Health may disclose Your Personal Information if required to do so by law or in the good faith belief that such action is necessary to (i) comply with a legal obligation, (ii) protect and defend the rights or property of Spire Health, (iii) act in urgent circumstances to protect the personal safety of You, Us, other users of the Services or the public, or (iv) protect against legal liability.

How Long Will Spire Health Retain Your Personal Information?

We store Your Personal Information for as long as You maintain an account, and/or the device used to collect Your data is retired or rendered inoperable, plus an additional retention period of one (1) year thereafter for our records and legal requirements, and to allow You to access Your data. After such time, We will remove Your Personal Information from Our databases and will request that Our business partners remove Your Personal Information from their databases. However, once We disclose Your Personal Information to third parties, We may not be able to access that Personal Information any longer and cannot force the deletion or modification of any such information by the parties to whom We have made those disclosures.  Written requests for deletion of Personal Information other than as described should be directed to hello@spire.io. We retain anonymized and de-identified data indefinitely.

Does Spire Health Utilize Cookies?

Cookies are used to collect information for business purposes, such as enabling essential website functions and improving Your user experience. Spire Health may use third-party tracking, advertising, and content providers to act on Our behalf to track and analyze Your usage of Our sites and to enable certain essential website functions, such as navigation. These companies protect that data in accordance with their own privacy policies. These third parties may collect, and share with Us, and We may request, website usage information about visits to Our sites, measure and research the effectiveness of our advertisements, and track page usage and paths followed during visits through Our sites. Also, these third-party providers may place Our Internet banner advertisements on other sites that You visit, and track use of Our Internet banner advertisements and other links from Our marketing partners' sites to Our sites. To the extent the information collected on Spire’s behalf by these third parties contains any Personal Information, We will protect it in accordance with this Privacy Policy.

What types of cookies do we use?

Necessary Cookies: These cookies allow Us to offer You the best possible experience when accessing and navigating through Our website and using its features. For example, these cookies let Us recognize that You have created an account and have logged into that account.

Analytical Cookies: These cookies enable Us and third-party services to collect aggregated data for statistical purposes on how Our visitors use the website and are used to improve Your user experience. These cookies do not contain personal information such as names and email addresses.

How can You delete cookies?

If You want to restrict or block the cookies that are set by Our website, You can do so through your browser settings. Alternatively, You can visit www.internetcookies.org, which contains comprehensive information on how to disable cookies on a variety of browsers and devices.

How Does Spire Health Protect My Personal Information?

Spire Health is committed to protecting the security and confidentiality of Your Personal Information. We use a combination of reasonable physical, technical, and administrative security controls to maintain the security and integrity of Your Personal Information, to protect against any anticipated threats or hazards to the security or integrity of such information, and to protect against unauthorized access to or use of such information in Our possession or control that could result in substantial harm or inconvenience to You. However, Internet data transmissions, whether wired or wireless, cannot be guaranteed to be 100% secure. As a result, We cannot ensure the security of information You transmit to us. By using the Application, You are assuming this risk.

Safeguards

The information Spire Health collects and stores on secure servers is protected by a combination of technical, administrative, and physical security safeguards, such as authentication, encryption, backups, and access controls. We recommend that You take any and all of the appropriate steps to secure any Devices that are in Your possession, such as by safely storing them or by password protecting Your Wi-Fi. If Spire Health learns of a security concern, We may attempt to notify You and provide information on protective steps, if available, through the e­mail address that You have provided to us or by an in-­app notification. Depending on where You live, You may have a legal right to receive such notices in writing.

NOT WITHSTANDING ANY OF THE STEPS TAKEN BY US, IT IS NOT POSSIBLE TO GUARANTEE THE SECURITY OR INTEGRITY OF DATA TRANSMITTED OVER THE INTERNET. THERE IS NO GUARANTEE THAT YOUR INFORMATION WILL NOT BE ACCESSED, DISCLOSED, ALTERED, OR DESTROYED BY BREACH OF ANY OF OUR PHYSICAL, TECHNICAL,OR ADMINISTRATIVE SAFEGUARDS. THEREFORE, WE DO NOT AND CANNOT ENSURE OR WARRANT THE SECURITY OR INTEGRITY OF ANY INFORMATION YOU TRANSMIT TO US AND YOU TRANSMIT SUCH INFORMATION AT YOUR OWN RISK.

How Should You Protect Your Personal Information?

We will NEVER send You an e­mail requesting confidential information such as account numbers, or social security numbers, and You should NEVER respond to any e­mail requesting such information. If You receive such an e­mail purportedly from Spire Health, DO NOT RESPOND to the e­mail and DO NOT click on any links and/or open any attachments in the e­mail, and notify Spire Health support at hello@spire.io.

How Can You Update, Correct or Delete Your Personal Information?

If You need to make changes or corrections to your address, phone number, email or other information, You may email hello@spire.io. Please note that in order to comply with certain requests to limit use of Your Personal Information, We may need to terminate Your account and Your ability to access and use the Services, and You agree that We will not be liable to You for such termination or for any refunds of prepaid fees paid by You.  Although We will use reasonable efforts to do so, You understand that it may not be technologically possible to remove from Our systems every record of Your Personal Information. The need to back up Our systems to protect information from inadvertent loss means a copy of Your Personal Information may exist in a non­ erasable form that will be difficult or impossible for Us to locate or remove. Backups of that data will remain associated with Your account and in Our archive servers. You can deactivate Your account by emailing hello@spire.io.

Can You “Opt ­Out” Of Receiving Communications from Spire Health?

We pledge not to market third-party services to You. We only send e­mails to You regarding Your Spire Health account and Services. You can choose to filter these e­mails using Your e­mail client settings, but We do not provide an option for You to opt out of these e­mails. You can opt out of daily emails by emailing hello@spire.io.

Does This Privacy Policy Apply to All Information You Provide?

This Privacy Policy does not apply to any unsolicited information You provide to Spire Health through the Service or through any other means. This includes, but is not limited to, any ideas for new products or modifications to existing products, and other unsolicited submissions(collectively, “Feedback”). All Feedback shall be deemed to be non-confidential and Spire Health shall be free to reproduce, use, disclose, and distribute such Feedback to others without limitation or attribution.

How Spire Health Makes Changes to This Policy

We occasionally update this Privacy Policy. It is Your responsibility to stay up to date with any amended versions. If We modify this Privacy Policy, We will notify You of the changes through either a notice in the Application, an email notification, or other reasonable means. You can store this policy and/or any amended version(s) digitally, print it, or save it in any other way.  Any changes to this Privacy Policy will be effective immediately upon providing notice, and shall apply to all information We maintain, use, and disclose. If You continue to use the Application following such notice, You are agreeing to those changes.

Information Submitted by Minors

Spire Health does not knowingly collect Personal Information or other information from children under the age of 13. If You are under the age of 13, please do not submit any Personal Information or other information through the Service. We encourage parents and legal guardians to help enforce Our Privacy Policy by instructing their children never to provide Personal Information on the Service. If You have reason to believe that a child under the age of 13 has provided Personal Information to Spire Health through the Service, please contact Us, and We will endeavor to delete that information from Our databases.

How Can You Contact Spire Health?

Please feel free to contact Us if You have any questions about this Privacy Policy or the information practices of the Service. You may contact Us by email at the following address: hello@spire.io.

To learn how the Spire RPM service can benefit your practice

Contact Us