This privacy notice applies to all users of our website where Surpass Behavioral Health (“Surpass”, “We”) is the data controller for your personal data and explains the purposes for which we process your personal data, how we collect and use your personal data, how long we retain your personal data, and the rights you have in relation to your personal data. Personal data means any information that relates to an identified or identifiable living individual.
Information we may collect from you
We collect personal data from:
Any references in this policy to “you” or “your” should be interpreted in the context in which the information is processed.
Our legal bases for processing your personal data include your consent, fulfilment of a contractual obligation, and where we have a legitimate interest to process your personal data, provided that our interests do not outweigh your individual rights and freedoms.
Our legitimate interests include:
Personal Data Collection
We collect personal data that you provide to us directly, as well as information provided by your browser or device when you visit our website. We also collect personal data via the portals connected to our site (as described below).
Personal Data You Submit
We collect personal data only when you submit it to us, such as when you submit an intake form, fill out a general inquiry, apply for a job, or sign up for job alerts. The Personal Data you submit may include, but is not limited to, your name, postal address, telephone number, mobile number, email address, or gender.
Personal Data We Receive From Third Parties
To the extent permitted by applicable law, we may receive Personal Data about you from third parties, such as social media services and commercially available sources. The Personal Data we receive from third parties may include your name, contact information, or relationships with various product and service providers, and your use of certain applications. For example, if you access the Surpass site through a social media service or connect Surpass to a social media service, the information we collect may also include your user ID and/or user name associated with that social media service, any information or content the social media service will share with us, such as your profile picture, or email address. The information we obtain depends on your privacy settings on the applicable social media service. When you access Surpass through social media services or when you connect Surpass to social media services, you are authorizing Surpass to collect, store, and use such information and content in accordance withthis Privacy Notice.
Other Information
“Other Information” is any information that is not intended to reveal your specific identity to us, such as browser information, usage data, information collected through cookies and other technologies, demographic information, Protected Health Information, geolocation data obtained with your consent where required by applicable law, and aggregated information.
2.2.1 Other Information You Submit
We collect Other Information when you submit it to us. This may include your password, birthday, education or graduation year, occupation, financial information (such as your experience, professional licensing, and other information), and interests.
2.2.2 Other Information We Receive From Third Parties
We may receive Other Information about you from third parties, including, for example, demographic data, social media account number, information about your interests, and information about your activities on other websites.
2.2.3 Other Information Collected Automatically
Our servers use cookies and other tracking technologies to function effectively and deliver certain features. For more information about how we use cookies and tracking technologies, read the Personal Data Collected via Web-Based Technologies section below.
Surpass may also be linked to sites or apps operated by third parties, and may carry advertisements or offer content, special offers, functionality, games or applications developed and maintained by third parties, using iframes, tools, or plug-ins (“Linked Services”). These third party Linked Services may use automated means to collect information about you and your use of these features. Some of these third party sites may be co-branded with a Surpass logo, even though they are not operated or maintained by us.
Surpass is not responsible for the privacy practices of such third parties, and once you leave a Surpass or subsidiary site or click an advertisement, or sign up for a special offer, you should check the applicable third party privacy notice.
HOW WE USE YOUR PERSONAL DATA AND OTHER INFORMATION
We may use the Personal Data we collect from and about you for the purposes set forth below. We may use and disclose Other Information for any purpose, except if it is considered Personal Data under applicable law. If we combine Other Information with your Personal Data, we treat the combined information as Personal Data.
To improve the quality of our products and services and to personalize your experience by presenting content, products and offers tailored to you, we may also combine the Personal and Other Information we collect with information relating to your use of other Surpass products, services and websites. In addition, we may supplement the Personal Data and Other Information we collect with information from other sources, such as publicly available information from social media services, commercially available sources, and information from Surpass Affiliates or business partners.
Through third party analytics providers, ad networks, and advertisers, we can track your online activities over time and across third party websites, apps and devices, by obtaining information through automated means.
This information, along with information you submit, can be used to understand use across sites and devices to help improve our products, remember your preferences, provide content recommendations, and show you advertisements on the Surpass or other third party websites and apps that may be tailored to your individual interests.
3.1 To Provide, Measure And Improve Our Products And Services
We use the information we collect from and about you to provide our products, services and features to you, including: to process and fulfill your subscription, to create and manage your accounts, to send you information about your relationship or transactions with us, to measure and improve services and features, to allow you to engage with us (e.g., to comment on content and participate in online games, contests, promotions, special events, rewards programs, surveys or market research), to use collaboration tools to share content and collaborate with other users, to conduct research for potential articles if you choose to respond to a journalism survey, to provide you with customer support, including online chat or chat bot, and to respond to inquiries. If you choose to use the collaboration tools, some of your Personal Data may be included in a directory that can be viewed and used by other users of these collaboration tools.
3.2 To Deliver Relevant Content And Recommendations
To make your experience more interesting and personalized, we may use any of the Personal Data and Other Information we collect to assist us in delivering content on any Surpass or subsidiary services.
3.3 To Deliver Advertising And Interest-Based Advertising
Surpass and our service providers may use any of the information we collect from and about you (in certain cases, such as with respect to financial information, only with your express permission) to assist us in delivering ads about products and services tailored to your individual interests to you when you use Surpass or another service provided by Surpass, Surpass Affiliates, or unaffiliated third parties. (See What We Collect, above, for details on the types of information we may use.) We may work with third party online advertising companies, advertisers and ad networks who help deliver these ads to you. These third parties may collect and use information about your activities on our Surpass and on other websites, and Other Information about you which may include offline purchases, to limit the online ads you encounter to those we believe are consistent with your interests.
To the extent required by applicable law, we will obtain your consent before using your information for interest-based advertising. To learn how to opt out of online interest-based advertising, please email [email protected].
If you provide your mobile phone number to us, we may ask for your consent to receive text message alerts from us containing product, event, or promotional information in a text or SMS message (“Text Messages”). Your consent to receive Text Messages is not required to purchase goods or services from us.
3.4 To Allow Social Sharing Functionality
If you log in with or connect a social media service account with Surpass or one of its subsidiaries, we may use Personal Data and Other Information to facilitate your sharing of information between Surpass and your social media service.
3.5 To Contact You
Surpass and Surpass Affiliates may periodically send promotional materials, with your permission where required, surveys, market research, contest or promotional awards, or notifications related to our products and services. To help make these materials more relevant to you, we may use and combine any of the Personal Data and Other Information we collect to assist us in sending you these materials. We may also use your information (including a telephone or mobile number you may have provided for this purpose) to contact you, including to respond to your comments, inquiries, or requests. If you want to stop receiving these materials, please follow the instructions in the Your Rights and Choices section below.
3.6 To Protect The Rights Of Surpass And Others
Surpass may use your Personal Data as we believe to be necessary or appropriate in order to: protect, enforce, or defend the legal rights, privacy, safety, or property of Surpass, our Surpass Affiliates or their employees, agents and contractors (including enforcement of our agreements and our terms of use); protect the safety, privacy, and security of users of our products and services or members of the public; protect against fraud and other unlawful activity or for risk management purposes; comply with and enforce the law or legal process, including laws outside your country of residence, contractual obligations, and our policies; or respond to requests from public and government authorities, including public and government authorities outside your country of residence, to the extent permitted by applicable law.
Lawful basis/es: The processing is necessary for our legitimate interests, or the legitimate interests of a third-party.
Register for Updates
If you choose to register for updates from Surpass, we collect information for the purpose of providing you with periodic updates regarding new product offerings, job opportunities, clinical research and product or company updates.
Lawful basis/es: You must have provided your clear consent to us processing your personal data for a specific purpose.
Personal Data Collected via Our Website Portals
Submit a Job Application
Any personal information, including the submission of your resume and/or cover letter, will be used to evaluate your candidacy for employment, as well as contact you regarding your application.
Lawful basis/es: The processing is necessary for our legitimate interests, or the legitimate interests of a third-party. In some instances, the processing is necessary for a contract that we have with you, or because we need to take steps to enter into a contract with you.
Personal Data Collected via Web-Based Technologies
Browser or Device Information
When you use the website, we automatically receive certain information provided by the interaction of your mobile phone or web browser and the website. This information includes your internet website provider name, web browser type, type of mobile device (if applicable), and computer operating system. We use this information to analyze trends among our Users to help improve the Website. Such information is collected in anonymous, aggregate form and is typically not considered personal data.
We also collect information on computer operating system, your IP address, the web browser, and information about the websites visited before accessing the website.
We collect this data for the following general purposes:
Lawful basis/es: You must have provided your clear consent to us processing your personal data for a specific purpose.
Cookies and Web Beacons
The website uses “cookies” to identify the areas of the website that you have visited.
A cookie is a small piece of data stored on your computer or mobile device by your web browser and is often used to make websites work, as well as provide information to the website operator.
We may use cookies to personalize the content that you see on our website, analyze our web traffic, and improve your experience while visiting the website. Most web browsers can be set to disable the use of cookies.
Communications you receive from us, as well as pages of our website, may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags and single-pixel gifs) that enable us to analyze email and website statistics, including visits and click-through rates. The web beacons only collect aggregate, anonymous data and cannot be traced back to you individually.
Lawful basis/es: You must have provided your clear consent to us processing your personal data for a specific purpose.
Third-Party Cookies and Web Beacons
Some content or applications on our website are served by third parties, including content providers and application providers. Our third-party partners may use cookies alone or in conjunction with web beacons or other tracking technologies already in your browser to collect information about you when you visit our website. The information they collect may be associated with your personal data or they may collect information, including personal data, about your online activities over time and across different websites and other online services.
Third-party cookies and web technologies are controlled by our advertising partners and not subject to this privacy notice. If you have any questions about the practices of such third party, you should contact the responsible third-party directly.
Lawful basis/es: You must have provided your clear consent to us processing your personal data for a specific purpose.
Conduct Marketing and Advertising
If you request to be updated about our products, services, company news, or other information, we will use the contact information you provided to send you the requested information, to provide you with marketing communications, and to keep you informed about product updates, events, webinars, or other materials.
Lawful basis/es: You must have provided your clear consent to us processing your personal data for a specific purpose.
Third-Party Advertising
We may use Google Ads, LinkedIn, Facebook/Instagram, and other third-party platforms to advertise across the Internet. We share anonymous, aggregate information regarding visitors to our website with some of the platform’s third-party website analytics tools. These companies use this aggregate data, which has been stripped of any personally identifying information about you, to provide us with insight regarding our web usage patterns. As we only share anonymous, aggregate data, this information cannot be traced back to you individually by either us or the website analytics vendors.
Meet Legal and Regulatory Obligations
In certain circumstances, we use your personal data if we are required to by law or legal proceeding. We will only share the information we are required to disclose by law and only when we are required to do so, including to meet national security or law enforcement requirements.
Lawful basis/es: The processing is necessary for us to comply with the law.
Security and Fraud Prevention
When necessary, we will use your personal data to preserve the security of our website, systems, and personal data in our control. If necessary, we will also use your personal data to investigate possible fraud, to identify violations of this Privacy Policy and our Legal Terms, and to prevent any attempted harm to you and other Members.
Lawful basis/es: The processing is necessary for our legitimate interests, or the legitimate interests of a third-party.
Personal Data Sharing and Disclosure
We share your personal data when you have granted us permission to do so, when it is necessary to fulfill our obligations to you, or when it is in the legitimate interest of our business to do so, provided that our interests do not outweigh your individual rights and freedoms.
Website Analytics Companies
We may share anonymous, aggregate information regarding visitors to our website with third-party website analytics companies. These companies use this aggregate data, which has been stripped of any personally identifying information about you, to provide us with insight regarding our web usage patterns. As we only share anonymous, aggregate data, this information cannot be traced back to you individually by either us or the website analytics vendors.
Legal Requirements
We may be legally required to disclose your personal data, if such disclosure is:
Security and Fraud Prevention Efforts
When necessary, we will share your personal data to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations or suspected violations of this Privacy Policy, our agreements or arrangements with you or other policies in effect from time to time to which you are subject, or as otherwise required by law.
California Online Privacy Protection Act Compliance
Because we value your privacy we have taken the necessary precautions to be in compliance with the California Online Privacy Protection Act. We therefore will not distribute your personal information to outside parties without your consent.
Third-Party Websites
The website may contain links to other websites that are not under our direct control. This Privacy Policy applies only to our websites and not to any third-party websites, which may have their own policies regarding privacy. We have no control of or responsibility for linked websites and provide these links solely for the convenience and information of our visitors. You access such linked websites at your own risk.
You should check the privacy policies, if any, of those individual websites to see how the operators of those third-party websites will utilize your personal information. In addition, these websites may contain a link to websites of our affiliates. The websites of our affiliates are not subject to this Privacy Policy, and you should check their individual privacy policies to see how the operators of such websites will use your personal information.
Security
We have implemented organizational and technical safeguards for protecting the personal data you share with us. These measures include secure infrastructure, carefully configured access to resources, and best practices around data safety and retention.
HOW WE PROTECT AND RETAIN PERSONAL DATA
Surpass uses a combination of administrative, technical, personnel and physical measures to safeguard Personal Data in its possession against accidental, unlawful or unauthorized loss, use, access, disclosure or modification. We make reasonable efforts to ensure a level of security appropriate to the risk of the processing, taking into account the costs of implementation and nature of the processing of Personal Data. However, no one can guarantee the complete safety of your information. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel the security of any account you might have with us has been compromised), please immediately notify us of the problem by contacting Customer Service in accordance with the instructions below.
We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or allowed by law.
Children Under the Age of 16
We do not knowingly collect personal data from individuals under the age of 16. Our website is not intended for anyone under the age of 16, and no one under the age of 16 may provide information on this website.
Privacy Notice Changes
We reserve the right to modify this privacy notice at any time. You can find the most current version of our privacy notice at any time by clicking on the “privacy notice” link at the bottom of our website. If we make material changes to this policy, we may notify you on our Website, by a blog post, by email, or by any method we determine. The method we chose is at our sole discretion. Any changes we make to our privacy notice are effective as of this Last Updated date and replace any prior privacy notices.
CONTACT US
If you have questions about this Privacy Notice or how we or our service providers handle your Personal Data, please contact us at [email protected].
We will respond to your questions and complaints about our processing of your Personal Data. If you are not satisfied with our response, depending on where you are located you can contact a supervisory authority or your state’s attorney general. Please do not disclose any sensitive Personal Data (e.g., information related to racial or ethnic origin, political opinions, religion or other beliefs, health, or trade union membership), social security numbers, or criminal background information when contacting us.
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU AND/OR YOUR CHILD MAY BE USED AND DISCLOSED
AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
All services provided by Surpass Behavioral Health are delivered as part of a medical model and are, therefore, subject to HIPAA (Health Insurance Portability and Accountability Act) regulations. As such, all clients and their families can expect that the organization will keep all protected health information fully confidential and secure and will provide immediate notification of any suspected breach in accordance with applicable laws.
HIPAA (Health Insurance Portability and Accountability Act) laws and regulations provide all clients and families with the following rights:
The right to receive a notice of our privacy practices
The right to access your child’s clinical record at any time and to obtain a copy
The right to request corrections to your child’s clinical record
The right to request restrictions on uses and disclosures of your health information
The right to request confidential communications
The right to an accounting of disclosures
The right to restrict fundraising solicitations
The right to file a complaint
When using or sharing your information for treatment, payment, or healthcare operations, our responsibilities are as follows:
Surpass Behavioral Health can change the terms of this notice, and the changes will apply to all information we have about you and your child. The new notice will be available upon request, in our office, and on our website.