Privacy Notice
Last Updated: June 1, 2026
This privacy notice ("Privacy Notice") is intended to provide you with specific details about how FindMyDirectDoctor, LLC, which owns and operates findmydirectdoctor.com ("FindMyDirectDoctor," "we," and "us"), collects and processes your personal and personally identifiable information through your use of its website and its associated services (collectively, the "Services").
You understand and agree that FindMyDirectDoctor may store and process your personal information on computers located outside of your jurisdiction, including, but not limited to, in the United States. By using the Services, you agree to the collection and processing of your personal or personally identifiable information outside of your jurisdiction.
Before using the Services or providing information to us, please carefully review this Privacy Notice. By using or accessing the Services, you agree that we may collect and use your personal and personally identifiable information in accordance with this Privacy Notice, as revised from time to time. FindMyDirectDoctor may modify, amend, replace, or suspend this Privacy Notice at any time. If you have any questions or suggestions regarding our Privacy Notice, or if your personal information is not accurate or complete, please contact us at:
FindMyDirectDoctor, LLC
[email protected]
3225 McLeod Dr, Suite 100
Las Vegas, NV 89121
FindMyDirectDoctor operates as a HIPAA Business Associate to OpenLoop Healthcare Partners, PC (principal offices at 317 6th Avenue, Des Moines, IA 50309) and its affiliated professional corporations (together, the "Healthcare Provider"). FindMyDirectDoctor is not a healthcare provider, is not licensed to practice medicine, and does not provide medical advice, diagnosis, treatment, or pharmacy services. All clinical services are provided by the Healthcare Provider in its independent professional judgment. FindMyDirectDoctor's role is limited to operating the Services as a technology and fulfillment platform and as a HIPAA Business Associate of the Healthcare Provider. When you interact with clinical features of the Services, Protected Health Information ("PHI"), as defined under the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), generated through those interactions is handled in accordance with our Business Associate Agreement with the Healthcare Provider and is governed by the section below titled "Protected Health Information and Our Role as Business Associate." All other personal information we collect through our public-facing pages and non-clinical interactions is governed by the remainder of this Privacy Notice. The Healthcare Provider is licensed to practice medicine only in specified U.S. states, and the Healthcare Provider determines state eligibility at clinical intake. The Services and the Healthcare Provider's Telehealth Services are not intended for medical emergencies; if you are experiencing a medical emergency, dial 911 or your local emergency number.
By providing FindMyDirectDoctor with personal or personally identifiable data and using the Services, you represent that you are at least eighteen (18) years of age. The Services are not directed to, and we do not knowingly permit use by, individuals under eighteen (18). If you are under eighteen (18), please do not use the Services and please do not provide personal information to us. Certain Services have higher minimum-age and other eligibility requirements set by the Healthcare Provider, including age 25 and older for treatment involving controlled substances such as testosterone replacement therapy.
Certain medications offered through the Healthcare Provider, including GLP-1 medications such as semaglutide and tirzepatide, may be compounded medications. For information about compounded medications, including applicable disclosures, please see our Terms of Service and the Healthcare Provider's Informed Consent.
Our Services may include links to websites or may include the use of analytics tools that are owned, operated, and maintained by third parties. FindMyDirectDoctor does not exercise control over the privacy practices of such third-party websites or analytics tools, and you are encouraged to review the privacy practices of all such third-party websites or analytics tools disclosed within this Privacy Notice.
What information do we collect and how do we use it?
When you use the Services, we may collect personal or personally identifiable information from you ("PII"). PII may include any information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual. It does not include anonymized data.
We may collect and process the following categories of PII about you:
  • Communication Data. Communication data includes any communication that you may send to us through the Services, email, or social media. We process this data to communicate with you by email or other means, to provide you with customer support, to record logs of our communication, and to store information to respond to legal claims. FindMyDirectDoctor's lawful ground for collecting and processing this PII is to respond to communications sent by you to us, to keep records of our communication, and to pursue or defend against legal claims.
  • User Data. User data includes data about how you use the Services and any data that you post to or authorize through the Services, such as your name, address, country, phone number, and email address. This includes data stored in persistent cookies when you login to the Services and analytics data that is collected when you use the Services. We collect and process this data to operate the Services, to authenticate you as a user of the Services, to ensure that timely and relevant content is provided to you, to secure the Services, to ensure that the Services operate in a fast and efficient manner, and to maintain backups of the Services. FindMyDirectDoctor's lawful ground for processing this user data is its legitimate business interests in administering and offering the Services and to fulfill your orders made through the Services.
  • Technical Data. Technical data includes data about your use of the Services, such as your IP address, your login data, your phone number, your mobile device model, your operating system, your geolocation, and your time zone. We may collect this data from your use of the Services and from advertising IDs. FindMyDirectDoctor processes this data to analyze your use of the Services, to route Services traffic, to administer and secure the Services, to provide location-relevant content, and to troubleshoot problems with the Services. FindMyDirectDoctor's lawful ground for collecting and processing this technical data is its legitimate interests in administering and offering the Services and to grow its business and marketing strategy.
  • Marketing Data. Marketing data includes data about your preferences in receiving and interacting with FindMyDirectDoctor's advertisements or content on the Services or on third-party websites or applications. We collect this data from your use of the Services and from third-party advertising IDs created through advertising programs, such as Google Advertising IDs and Facebook Advertising IDs. FindMyDirectDoctor does not link advertising identifiers to persistent device identifiers, such as MAC addresses or mobile device IDs, within our patient intake, enrollment, or care-delivery systems. FindMyDirectDoctor's lawful ground for collecting and processing this marketing data is its legitimate interests in administering and offering the Services and to grow its business and marketing strategy by providing advertisements, including remarketing advertisements, to you.
  • Personally Sensitive Data. Personally sensitive data includes data about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, or union membership. Other than PHI as described in the section titled "Protected Health Information and Our Role as Business Associate" below, FindMyDirectDoctor does not collect personally sensitive data.
  • Biometric Data. Biometric data is any data relating to "biometric identifiers," which includes a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Biometric identifiers do not include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color, or eye color. Other than incidental capture during communications routed through our messaging or telecommunications vendors on behalf of the Healthcare Provider, FindMyDirectDoctor does not collect or use biometric data for identification purposes.
FindMyDirectDoctor will only use your PII for the purpose for which it was collected. If FindMyDirectDoctor needs to use your PII for an unrelated, new purpose, FindMyDirectDoctor will provide you with notice of this new use and will explain the lawful ground for such processing. FindMyDirectDoctor may process your PII without your knowledge or consent where required or permitted by law.
Protected Health Information and Our Role as Business Associate
FindMyDirectDoctor provides a technology platform that enables users to identify and engage licensed healthcare providers. Clinical services accessed through the Services are delivered by OpenLoop Healthcare Partners, PC and its affiliated professional corporations (collectively, the "Healthcare Provider"). In connection with operating the scheduling, payment-routing, and member-interface functionality of the Services on the Healthcare Provider's behalf, FindMyDirectDoctor receives and processes a limited set of Protected Health Information described below.
Under the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), FindMyDirectDoctor acts as a "business associate" of the Healthcare Provider and is contractually obligated to handle "protected health information" ("PHI") in accordance with HIPAA's Privacy and Security Rules and the terms of our Business Associate Agreement. The Healthcare Provider, for purposes of this Notice, means OpenLoop Healthcare Partners, PC and its affiliated professional corporations (with principal offices at OpenLoop Tower, 317 6th Avenue, Des Moines, IA 50309). The Healthcare Provider, not FindMyDirectDoctor, is the Covered Entity that delivers clinical services to you, determines treatment eligibility, and maintains your medical record. In our role as Business Associate, the PHI we may receive, create, store, or transmit on the Healthcare Provider's behalf is limited to: (i) identifiers such as your name, date of birth, home and email address, and phone number; (ii) appointment and scheduling data; (iii) payment metadata such as transaction confirmations and tokenized card identifiers (FindMyDirectDoctor does not process card payments or store card data); (iv) communications between you and the Healthcare Provider's clinicians that route through FindMyDirectDoctor's messaging vendors (text and email); and (v) any care-plan content the Healthcare Provider elects to surface to you through the member interface. Clinical intake responses, medical history, BMI, comorbidities, visit notes, prescriptions, and medical records are collected and stored directly by the Healthcare Provider through its own intake forms and electronic health record, and do not pass through FindMyDirectDoctor's systems. How we use and share this PHI, the HIPAA rights available to you, the safeguards we maintain, and our obligations in the event of a breach are described in the sections that follow. You may also request a copy of the Healthcare Provider's Notice of Privacy Practices, which describes the Healthcare Provider's HIPAA privacy and security practices in further detail. For questions about your medical record or to exercise HIPAA rights, contact the Healthcare Provider directly using the contact information provided through your member account.
How We Use and Share Your PHI
FindMyDirectDoctor operates the patient-facing components of the Services, including the website, appointment scheduling functionality, account management, the payment interface that routes patient charges to the Healthcare Provider's merchant account, and the messaging infrastructure through which the Healthcare Provider's clinicians communicate with patients. Clinical information provided through the Services, including intake responses, medical history, visit notes, and medical records, is collected and stored directly by the Healthcare Provider through the Healthcare Provider's own intake forms and electronic health record, and does not pass through FindMyDirectDoctor's systems. The PHI that FindMyDirectDoctor may receive or transmit is limited to identifiers and account information, scheduling and appointment data, payment metadata such as transaction confirmations and tokenized card identifiers, communications between patients and the Healthcare Provider's clinicians that route through FindMyDirectDoctor's messaging vendors (text and email), and any care plan content that the Healthcare Provider elects to surface to patients through the member interface.
We may share PHI with a limited set of vendors and subcontractors only when needed to operate the patient-facing functions described above, most commonly our email and text messaging providers when the Healthcare Provider's clinicians communicate with you. Where any subcontractor receives or transmits PHI on our behalf, we require, by written agreement consistent with 45 CFR 164.504(e), that the subcontractor apply HIPAA safeguards substantially equivalent to those that apply to us. Other operational functions related to clinical care, including cloud hosting and storage of medical records, payment processing, and clinical patient support, are performed by the Healthcare Provider directly rather than by FindMyDirectDoctor, and the Healthcare Provider's own service providers handle such data under the Healthcare Provider's privacy practices.
We may also disclose PHI when required by law applicable to us as a Business Associate, including making our records available to the U.S. Department of Health and Human Services or its Office for Civil Rights for HIPAA compliance review, and responding to valid subpoenas or court orders. Disclosures for public health, law enforcement, or similar purposes are made by the Healthcare Provider as the Covered Entity, not directly by us. If FindMyDirectDoctor is involved in a corporate transaction such as a merger, acquisition, or sale of assets, any transfer of PHI would be subject to HIPAA, the terms of our Business Associate Agreement, and any required Covered Entity authorization, and the receiving party would be bound by the same HIPAA obligations that apply to us today.
We use and disclose PHI only as permitted by HIPAA and the terms of our Business Associate Agreement with the Healthcare Provider. We apply the minimum necessary standard, meaning we limit each use and disclosure to the smallest amount of PHI reasonably needed to accomplish the purpose. The Healthcare Provider is the party that primarily holds the right to create and use de-identified or aggregate data derived from your information. To the extent permitted by HIPAA's de-identification standards and our Business Associate Agreement, FindMyDirectDoctor may also create or use de-identified or aggregate data derived from the information we receive or process in our role as Business Associate, for purposes such as service operation, product analytics, and business improvement. Once data is de-identified in accordance with HIPAA standards, it is no longer Protected Health Information.
Your HIPAA Rights
FindMyDirectDoctor ("we" or "us") operates as a HIPAA Business Associate to the Healthcare Provider. The Healthcare Provider is the Covered Entity that maintains your medical record and issues the Notice of Privacy Practices ("NPP") that describes your rights under HIPAA. FindMyDirectDoctor cooperates with the Healthcare Provider in fulfilling those rights. The summary provided below is for informational purposes only and does not modify or replace the Healthcare Provider's NPP, which controls.
Under HIPAA, you generally have the right to: (a) access and obtain a copy of the protected health information ("PHI") your Healthcare Provider maintains about you in a designated record set (the records used by the Healthcare Provider to make decisions about your care, as defined under HIPAA); (b) request an amendment to PHI you believe is inaccurate or incomplete; (c) receive an accounting of certain disclosures of your PHI made by your Healthcare Provider; (d) request restrictions on certain uses and disclosures of your PHI for treatment, payment, or healthcare operations; (e) request confidential communications by alternative means or at alternative locations; (f) receive a paper copy of your Healthcare Provider's NPP, even if you previously agreed to receive it electronically; and (g) file a complaint if you believe your privacy rights have been violated, without fear of retaliation.
Because your Healthcare Provider is the Covered Entity that holds your medical record, requests to exercise these rights are fulfilled by your Healthcare Provider in accordance with its NPP, applicable timelines, and any cost-based fees permitted by HIPAA. If you submit a HIPAA rights request to us, we will route it to the Healthcare Provider for fulfillment and will provide any PHI in our systems reasonably necessary for the Healthcare Provider to respond. The Healthcare Provider, as the Covered Entity, controls timing, format, and any applicable fees for fulfillment under HIPAA. Where the Healthcare Provider has delegated a HIPAA rights function to us in writing, we will fulfill that function on the Healthcare Provider's behalf in accordance with applicable law.
You may contact us at [email protected]. You may also contact your Healthcare Provider's Legal Department directly at [email protected] (OpenLoop Tower, 317 6th Avenue, Des Moines, IA 50309), or refer to your Healthcare Provider's Notice of Privacy Practices for additional contact information.
You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights at 200 Independence Avenue SW, Washington, DC 20201, or by phone at 1-877-696-6775. We will not retaliate against you for filing a complaint or exercising any of your HIPAA rights.
How We Safeguard Your Information and Handle Security Incidents
FindMyDirectDoctor maintains administrative, physical, and technical safeguards designed to protect Protected Health Information (PHI) we receive, create, maintain, or transmit on behalf of the Healthcare Provider, consistent with the HIPAA Security Rule (Subpart C of 45 CFR Part 164) and our Business Associate Agreement. FindMyDirectDoctor periodically reviews and updates these safeguards to address evolving technical and security risks. No method of electronic transmission or storage is completely secure, and FindMyDirectDoctor cannot guarantee absolute security; however, FindMyDirectDoctor applies protections appropriate to the nature of the information and its regulatory obligations. Any transmission of personal information to or through the Services is at your own risk.
If we discover a breach of unsecured PHI or a security incident affecting PHI, we will notify the Healthcare Provider without unreasonable delay and in no event later than the timeframe required by our Business Associate Agreement, and we will take reasonable steps to mitigate any harmful effect of the incident that is known to us. Patient-facing breach notification is the responsibility of the Healthcare Provider as the HIPAA Covered Entity, in accordance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D), unless the Healthcare Provider directs us in writing to provide that notification on its behalf. If you have questions or concerns about the security of your information, you may contact us at [email protected].
How do we collect this information?
We collect PII from you through a variety of different means:
  • Direct Collection. We may collect PII from you when you purchase products from our Website, register a User Account or for other services, contact us through the Website, via live chat, social media, or otherwise, respond to a survey, participate in a contest, or when you opt-in to receive marketing emails, or mailings from us.
  • Third-Party Tracking Tools. We use third party tracking tools, such as pixels, web beacons, and cookies, to automatically collect PII from you when you open, view, or click pages or links, emails, or advertisements. These tools are described in the section titled "Tracking Technologies, Cookies, and Analytics" below.
  • Business Partners and Service Providers. We may, from time to time, obtain PII from our business partners or service providers. When we obtain PII from our business partners and service providers, we ensure that all such business partners and service providers have obtained consent from you to transfer all such PII to us for its intended uses.
  • Social Media Networks and Other Platforms. When you interact with our official social media accounts or content posted on third-party platforms such as Facebook, X, or YouTube, those platforms may collect PII about you according to their own privacy practices. To the extent that PII flows to us from such interactions, for example when you click a link from a social platform to our Services, we receive it through the platform's standard interface, not through FDD-deployed tracking pixels on our patient intake, enrollment, or care-delivery interfaces. For more information on how your PII may be disclosed by a particular social media network or platform, you are encouraged to review the privacy notices and policies of those platforms.
  • Analytics Providers. We may also obtain PII from you through our use of third-party analytics providers on our public-facing pages. The categories of providers we use are described in the section titled "Tracking Technologies, Cookies, and Analytics" below. We may create user profiles based on PII obtained through our use of third-party analytics providers to better understand your interests and preferences.
Tracking Technologies, Cookies, and Analytics
FindMyDirectDoctor ("FDD") operates two distinct categories of online surfaces. Our public-facing marketing, landing, educational, and informational pages allow prospective patients and visitors to browse without submitting protected health information ("PHI"); standard web analytics and infrastructure technologies operate on these pages. Our clinical intake, enrollment, and care-delivery interfaces are hosted on the infrastructure of OpenLoop Healthcare Partners, PC (the "Healthcare Provider") for whom we serve as a HIPAA Business Associate, and we do not deploy FDD-controlled tracking on those interfaces. Consistent with our role as a Business Associate, we do not knowingly deploy advertising or social media tracking pixels that transmit PHI to advertising platforms on FDD-controlled patient intake, enrollment, or care-delivery interfaces.
We use a limited set of third-party service providers to operate our public pages, including providers of content delivery and security infrastructure, aggregate analytics, business and communications tools, and payment processing. Where any such provider receives or transmits PHI on our behalf, we require, by written agreement consistent with 45 CFR 164.504(e), that the provider apply HIPAA safeguards substantially equivalent to those that apply to us. For providers that do not handle PHI, or that operate under HIPAA's payment-processor exemption, a Business Associate Agreement is not required. We do not knowingly transmit individually identifiable health information to providers that have not entered into such a written agreement with us.
We use four categories of cookies and similar technologies: strictly necessary cookies, which enable core site functions such as security, load balancing, and session integrity; functional cookies, which remember user preferences such as language and display settings; analytics cookies, which help us understand aggregate usage patterns on non-PHI pages; and advertising cookies, which we do not currently deploy on FDD properties. You can manage cookie preferences through your browser settings, and we honor Global Privacy Control ("GPC") signals as required by applicable state law, including in jurisdictions that recognize universal opt-out mechanisms. Closing or dismissing a cookie or consent notification does not, by itself, constitute consent. For visitors in Washington and Nevada, we treat data on our marketing pages that could reveal consumer health status as "consumer health data" under the Washington My Health My Data Act and Nevada SB 370, and we do not share such data with third parties for advertising purposes. Do Not Track ("DNT") browser signals are no longer maintained as an industry standard, and we therefore honor GPC in their place. Questions about our tracking practices can be directed to [email protected].
How do we use your information for marketing communications?
As stated above, FindMyDirectDoctor's lawful ground for sending you marketing communications is either consent or its legitimate business interests, such as to grow its business by advertising products and services to you. FindMyDirectDoctor may send you marketing communications if you have asked for information concerning its goods or services or if you have agreed to, and have not opted out from, receiving marketing communications. You may ask FindMyDirectDoctor to stop sending you marketing messages at any time by logging into the Services to adjust your marketing preferences within your user account or by following the opt-out link in any marketing message sent to you. If you opt out of receiving marketing communications, your opt-out does not extend to PII provided for other purposes.
SMS and Text Messaging Communications
By providing your mobile telephone number to FindMyDirectDoctor or to the Healthcare Provider through our Services, you consent to receive recurring text messages from us or from the Healthcare Provider's clinicians, including appointment reminders, scheduling notifications, account confirmations, and clinical communications relating to your care. Consent to receive marketing SMS messages is obtained through a separate opt-in checkbox at the time of enrollment or registration, in compliance with the Telephone Consumer Protection Act and FCC rules. Marketing SMS consent is not required as a condition of receiving Telehealth Services. Message frequency varies based on your interactions with the Services. Message and data rates may apply, and you are responsible for any charges from your wireless carrier. You may opt out of marketing SMS at any time by replying STOP to any marketing message without affecting clinical communications relating to your care. Opting out of clinical text communications may affect the Healthcare Provider's ability to deliver telehealth services to you. Reply HELP for assistance. You are responsible for notifying us promptly if your mobile telephone number changes or is deactivated, and FindMyDirectDoctor is not liable for messages or notifications sent to a mobile telephone number that is no longer in your control.
Your Account Security
You are responsible for maintaining the confidentiality of any account credentials (including usernames and passwords) used to access the Services, and you are responsible for all activities that occur under your account. If you believe your account has been accessed without authorization, please contact us immediately at [email protected]. FindMyDirectDoctor is not liable for any loss or damage arising from your failure to protect your account credentials or from any unauthorized use of your account.
When do we disclose your information?
This section addresses disclosures of non-PHI personal information collected through our public-facing pages and other non-clinical interactions. Disclosures of Protected Health Information are governed by the section above titled "How We Use and Share Your PHI" and by our Business Associate Agreement with the Healthcare Provider.
Subject to that carve-out, we may share your PII with the following parties:
  • Service providers that provide us with information technology, software-as-a-service, cloud storage, communications, analytics, or other administrative services, in each case under written agreements that restrict their use of your PII to the services they perform for us;
  • Our accountants, auditors, insurers, or attorneys, in each case bound by professional or contractual confidentiality obligations;
  • Law enforcement agencies upon receipt of a subpoena, court order, or other lawful process, or where we believe disclosure is necessary to protect our personnel, property, or rights, or to investigate suspected fraud or violation of our terms;
  • Government bodies that require us to report processing activities or that have lawful jurisdiction over us; and
  • Third parties in connection with a sale, transfer, merger, financing, reorganization, or other change of control involving all or any part of our business or assets, subject to customary confidentiality protections.
For how long do we retain your data?
We will only retain your PII for so long as necessary to fulfill the purposes for which it is collected under this Privacy Notice or for the purposes of satisfying any legal, accounting, or reporting requirements. With respect to location data, technical data, usage and interaction data, and marketing data, we may retain this data for so long as it is relevant to the uses disclosed in this Privacy Notice. We may retain account data, public data, and communications data for so long as you maintain a user account with FindMyDirectDoctor, and we may retain this data for longer periods where there is a need to retain this data to comply with FindMyDirectDoctor's legal obligations, such as the preservation of electronic evidence or compliance with a preservation order.
With respect to Protected Health Information, retention, return, and destruction are governed by our Business Associate Agreement with the Healthcare Provider, which requires us to return or destroy PHI within twenty (20) days of termination of the agreement, except where return or destruction is infeasible, in which case the protections of the Business Associate Agreement continue to apply to such PHI for so long as we retain it.
Your Privacy Rights and How to Exercise Them
Depending on your state of residence, you may have specific rights regarding your personal information under applicable state privacy laws, including the right to access, correct, delete, or port your personal information, the right to opt out of the sale of personal information and certain forms of targeted advertising, and the right to appeal a denied request. The state-specific sections below describe these rights in detail for California, Washington, Nevada, Texas, and other state residents.
To submit a privacy request, please email FindMyDirectDoctor's privacy team at [email protected]. We do not charge a fee to access your personal information or to exercise these rights, although we may charge a reasonable fee if a request is manifestly unfounded, excessive, or repetitive. To confirm your identity, we may request specific information from you as a security measure to ensure that personal information is not disclosed to an unauthorized third party. FindMyDirectDoctor will respond to verified requests within forty-five (45) days of receipt, with one forty-five-day extension where reasonably necessary and as permitted by applicable law.
International Users and EU-U.S. Data Privacy Framework
FindMyDirectDoctor's Services are directed primarily to residents of the United States. With respect to personal data of EU, UK, or Swiss residents that we may receive in connection with the Services, FindMyDirectDoctor adheres to the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework (collectively, the "DPF") administered by the U.S. Department of Commerce, and we comply with the DPF Principles in handling such data. FindMyDirectDoctor is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission with respect to its compliance with the DPF Principles. For more information about the DPF, visit dataprivacyframework.gov.
If you are an EU, UK, or Swiss resident and you wish to exercise privacy rights, or if you have questions or complaints about our handling of your personal data under the DPF, please contact us at [email protected]. As a participant in the DPF, FindMyDirectDoctor has agreed to refer unresolved DPF-related complaints to JAMS, an independent dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, you may contact JAMS at jamsadr.com/eu-us-data-privacy-framework at no cost to you. Under certain conditions described in the DPF Principles, you may also have the right to invoke binding arbitration.
California Residents
The following applies to residents of the State of California. The California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA"), gives you specific rights regarding personal information we collect about you. This section uses the terms "personal information" and "sensitive personal information" as defined under the CCPA. Personal information that we collect, use, or disclose as a Business Associate in the course of providing services to or on behalf of the Healthcare Provider is Protected Health Information governed by HIPAA and is exempt from the CCPA under Cal. Civ. Code Section 1798.146(a). The remainder of this section describes our handling of non-HIPAA personal information.
Categories of personal information collected. Within the preceding twelve (12) months we have collected the following categories of personal information from California residents:
  • A. Identifiers — Real name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name, or other similar identifiers.
  • B. Cal. Civ. Code Section 1798.80(e) information — Name, signature, address, telephone number, and payment-related identifiers.
  • D. Commercial information — Records of products or services purchased or considered.
  • F. Internet or other network activity — Browsing history, search history, and information regarding interaction with the Services, applications, or advertisements.
  • G. Geolocation data — Approximate physical location derived from IP address or device signals.
  • K. Inferences — User profiles or inferences we may create based on personal information obtained from analytics providers and other sources to better understand your interests, preferences, and behavior.
We collect this personal information directly from California residents when they interact with the Services, indirectly through observation of their use of the Services, and from third-party analytics and service providers as described elsewhere in this Privacy Notice. We do not collect categories C, E, H, I, or J.
Sensitive personal information. The only category of sensitive personal information we collect in the ordinary course is health-related information, and we collect, use, and disclose that information solely in our role as Business Associate to the Healthcare Provider. That use is exempt from CCPA's sensitive-personal-information requirements under the HIPAA exemption. We do not collect precise geolocation as defined under Cal. Civ. Code Section 1798.140(w), and we do not use sensitive personal information for purposes that would require us to offer a "Limit the Use of My Sensitive Personal Information" link under Cal. Civ. Code Section 1798.121.
Sale and sharing. We do not sell personal information for monetary consideration, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA. We honor opt-out preference signals, including the Global Privacy Control (GPC), transmitted by your browser or device, in accordance with applicable law. The steps required to opt back in to any sale or sharing will be no less straightforward than the steps used to opt out, and we will not use deceptive design or asymmetric workflows to obtain or retain your consent. To submit a Do Not Sell or Share request, see our Do Not Sell or Share My Personal Data page.
Your rights. Subject to verification and to applicable exemptions, California residents have the right to (i) know the categories and specific pieces of personal information we have collected, the sources of that information, the business or commercial purposes for collecting it, and the categories of third parties to whom we disclose it; (ii) request correction of inaccurate personal information; (iii) request deletion of personal information we have collected from you; (iv) obtain a copy of your personal information in a portable, readily usable format; (v) opt out of any sale or sharing of personal information; (vi) limit the use of sensitive personal information; and (vii) not receive discriminatory treatment for exercising these rights.
How to exercise your rights. To submit a verifiable consumer request, email [email protected] or write to FindMyDirectDoctor, LLC, 3225 McLeod Dr, Suite 100, Las Vegas, NV 89121. You may designate an authorized agent to make a request on your behalf by providing the agent with signed written permission and providing us with sufficient information to verify your identity. We will acknowledge receipt of your request within ten (10) business days and respond within forty-five (45) days, subject to a single forty-five-day extension where reasonably necessary. You may appeal a denial of any request by emailing [email protected] with the subject line "CCPA Appeal" within forty-five (45) days of our response and identifying the basis for your appeal. We will review the appeal and respond within sixty (60) days of receipt, in compliance with applicable law.
Washington Residents
The following applies to residents of the State of Washington and to consumer health data we collect about Washington residents through our public-facing pages and other non-clinical interactions. Consumer health data we collect, use, or disclose as a Business Associate in the course of providing services to or on behalf of the Healthcare Provider is Protected Health Information governed by HIPAA and is exempt from the Washington My Health My Data Act ("MHMDA") under RCW 19.373.020(8)(a) and (g). The remainder of this section describes our handling of consumer health data outside that HIPAA-exempt scope.
Scope. "Consumer health data" means personal information linked or reasonably linkable to a Washington consumer that identifies the consumer's past, present, or future physical or mental health status. Outside our Business Associate role, the consumer health data we may collect through our marketing, informational, and pre-clinical pages includes inferences derived from a user's search activity, page views, geolocation, and self-submitted form responses that reveal an interest in a health condition, treatment, or service.
Consent and no sale. We collect consumer health data only with your affirmative opt-in consent, separately obtained from any consent to our general terms or this Privacy Notice. We do not sell consumer health data. If we were ever to sell consumer health data, we would first obtain a separate written authorization that complies with RCW 19.373.040.
No geofencing. We do not implement geofences around any in-person healthcare facility for the purpose of identifying, tracking, collecting data from, or sending notifications, messages, or advertisements to Washington consumers related to their consumer health data, health condition, or healthcare services.
Your rights. Washington consumers have the right to (i) confirm whether we are collecting, sharing, or selling their consumer health data and access such data; (ii) withdraw consent to our collection and sharing of consumer health data; (iii) request deletion of their consumer health data; and (iv) appeal a denied request. To exercise these rights, contact us at [email protected]. We will respond within forty-five (45) days. You may also file a complaint with the Washington Attorney General at atg.wa.gov/file-complaint. MHMDA does not create an independent private right of action; violations may be enforced by the Washington Attorney General and may be actionable under the Washington Consumer Protection Act, RCW 19.86.
Nevada Residents
The following applies to residents of the State of Nevada. Effective March 31, 2024, Nevada Senate Bill 370 (codified at NRS Chapter 603A) regulates the collection, use, and disclosure of "consumer health data" about Nevada consumers. Consumer health data we collect, use, or disclose as a Business Associate in the course of providing services to or on behalf of the Healthcare Provider is Protected Health Information governed by HIPAA and is exempt from SB 370 under NRS 603A.405(1)(b). The remainder of this section describes our handling of consumer health data outside that HIPAA-exempt scope.
Scope. "Consumer health data" means personally identifiable information that is linked or reasonably linkable to a Nevada consumer and that we use to identify the consumer's past, present, or future health status. Outside our Business Associate role, the consumer health data we may collect through our marketing, informational, and pre-clinical pages includes inferences derived from a user's search activity, page views, geolocation, and self-submitted form responses that reveal an interest in a health condition, treatment, or service.
Consent and no sale. We collect consumer health data only with your affirmative opt-in consent. We do not sell consumer health data. If we were ever to sell consumer health data, we would first obtain the separate written authorization required by NRS 603A.420(1).
No geofencing. We do not implement geofences around any in-person healthcare facility for the purpose of identifying, tracking, collecting data from, or sending notifications, messages, or advertisements to Nevada consumers related to their consumer health data, health condition, or healthcare services.
Your rights. Nevada consumers have the right to confirm whether we are collecting, sharing, or selling their consumer health data, to access such data, to request deletion, and to withdraw consent. To exercise these rights, contact us at [email protected]. We will respond within forty-five (45) days. You may also file a complaint with the Nevada Attorney General at ag.nv.gov.
Texas Residents
The following applies to residents of the State of Texas under the Texas Data Privacy and Security Act ("TDPSA"), which took effect July 1, 2024. Personal data that we process as a Business Associate in the course of providing services to or on behalf of the Healthcare Provider is Protected Health Information governed by HIPAA and is exempt from the TDPSA under Tex. Bus. & Com. Code Section 541.003(1). The remainder of this section describes our handling of non-HIPAA personal data about Texas residents.
Notice statement. We do not sell sensitive personal data. We do not sell personal data in exchange for monetary consideration.
Sensitive data and opt-in. "Sensitive data" under the TDPSA includes data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, citizenship or immigration status, precise geolocation data, genetic or biometric data processed for the purpose of uniquely identifying an individual, and personal data collected from a known child. We will not process sensitive data about a Texas resident outside our HIPAA-exempt Business Associate role without that resident's prior affirmative consent.
Universal opt-out signals. Effective January 1, 2025, we honor universal opt-out mechanisms transmitted by your browser or device, including the Global Privacy Control (GPC), as a valid opt-out of targeted advertising and the sale of personal data.
Your rights. Subject to verification, Texas residents have the right to (i) confirm whether we are processing their personal data and access that data; (ii) correct inaccuracies; (iii) delete personal data we have collected or maintained; (iv) obtain a copy of their personal data in a portable, readily usable format; (v) opt out of the sale of personal data, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects; and (vi) appeal a denied request. To exercise these rights, contact us at [email protected]. We will respond within forty-five (45) days. You may also file a complaint with the Texas Attorney General at texasattorneygeneral.gov.
Other State Residents
Residents of Colorado, Connecticut, Virginia, Oregon, Montana, Iowa, Tennessee, New Jersey, Delaware, New Hampshire, Maryland, Minnesota, Indiana, Kentucky, Rhode Island, and other states with comprehensive consumer privacy laws may have rights to access, correct, delete, or port their personal information, to opt out of the sale of personal information, targeted advertising, and certain profiling activities, and to appeal denied requests. (Wisconsin is not listed because, as of the Last Updated date, Wisconsin has not enacted a comprehensive consumer privacy law; this list will be updated as additional states do so.) Personal information that we process as a Business Associate to the Healthcare Provider is Protected Health Information governed by HIPAA and is exempt from these state laws under their respective HIPAA, business-associate, or covered-entity carve-outs. Where a comprehensive state privacy law applies to FindMyDirectDoctor and we are not exempt, we will honor the access, correction, deletion, portability, and opt-out rights provided by that law, subject to the verification, exemption, and timing requirements of the applicable statute. To exercise applicable rights, contact us at [email protected], and we will respond within the response window set by the applicable state law (typically forty-five (45) days). Where the applicable state law honors universal opt-out mechanisms such as the Global Privacy Control, we honor those signals as a valid opt-out of the sale of personal information and of targeted advertising.
Third-Party Links and Services
FindMyDirectDoctor's Services may include links to, and integrations with, third-party websites, applications, products, or services that FindMyDirectDoctor does not own or control. FindMyDirectDoctor is not responsible for the privacy practices, content, security, terms of service, or other practices of any such third party. By clicking on third-party links or interacting with third-party integrations, you may allow third parties to collect, use, or share information about you in accordance with their own policies, not this Privacy Notice. You are advised to review the privacy policies and terms of any third-party website, application, or service before providing information to such third party or using its offerings.
Children's Online Privacy Protection Act Compliance
We comply with the requirements of the Children's Online Privacy Protection Act ("COPPA"). FindMyDirectDoctor's Services are directed to individuals aged eighteen (18) years and older. We do not knowingly collect personal information from anyone under thirteen (13), and we do not knowingly permit use of the Services by individuals under eighteen (18). If you believe we have collected personal information from someone under thirteen (13), please contact us immediately at [email protected] and we will promptly delete such information.
Changes to Our Privacy Notice
FindMyDirectDoctor may modify, amend, replace, or suspend this Privacy Notice at any time. When we make changes, we will post the updated Privacy Notice on the Services with a revised "Last Updated" date, and we may also notify you through other channels that we deem appropriate. You are responsible for keeping the email address and other contact information associated with your account current and accurate so that we can communicate with you regarding material changes. Your continued use of the Services following the posting of any modification, amendment, or replacement of this Privacy Notice will constitute your acknowledgment and acceptance of the revised Privacy Notice.
Relationship to Terms of Service
This Privacy Notice is incorporated into and forms part of the FindMyDirectDoctor Terms of Service. Your use of the Services, including all matters relating to the collection, use, disclosure, retention, and protection of your personal information and PHI, is governed by the Terms of Service, including without limitation the disclaimers of warranty, limitation of liability, indemnification, binding individual arbitration, class action and representative action waiver, governing law, venue, and one-year limitations period set forth therein. To the extent of any conflict between this Privacy Notice and the Terms of Service on those matters, the Terms of Service govern. Any dispute arising from or relating to this Privacy Notice, including claims under HIPAA, CCPA/CPRA, CMIA, the Washington My Health My Data Act, Nevada SB 370, the Texas Data Privacy and Security Act, or any other state or federal privacy law, is subject to Section 20 of the Terms of Service.
Contacting Us
If you have any questions about this Privacy Notice or the manner by which we collect or use personal information about you, please email us at [email protected] or write to FindMyDirectDoctor, LLC, 3225 McLeod Dr, Suite 100, Las Vegas, NV 89121.