Version Effective Date: October 3, 2023
Health Data Consent
By using the Mahana program, I acknowledge and consent to the following:
By clicking or tapping on the button for the intake screen, you acknowledge that you agree to this Mahana Health Data Consent & Product Privacy Notice. Information on exercising your privacy rights (including withdrawing consent) is described in the Product Privacy Notice below. To exercise your privacy right, see Mahana’s Data Subject Portal.
Product Privacy Notice Overview
This digital health product is provided by Mahana Therapeutics, Inc. in the United States (Mahana US, collectively known as ‘Mahana’).
This Privacy Policy describes how Mahana collects, receives, uses, retains, and discloses Personal Data and Sensitive Personal Data of users (also ‘you,’ ‘your’ or ‘patient’). Personal Data includes information about you that is personally identifying such as your name, email address, and phone number and which is not otherwise publicly available, as well as information that can be used to directly identify you, or information that is maintained together with information that can be used to directly identify you. Sensitive Personal Data includes information about your health and medical care. Only the legal definition of Personal Data and Sensitive Personal Data (collectively ‘Personal Data’) that applies to your location will apply to you under this Privacy Notice.
Mahana works with hospitals, clinics, practices, or other medical groups, healthcare providers (including telehealth providers), pharmacies, and healthcare systems to prescribe and/or, with your consent, monitor progress for digital health products by their respective patient populations (‘Clinical Partners’). For US users of prescription digital products, Personal Data collected in connection with your use of Mahana products may be shared with your health plan and ePharmacy to dispense and reimburse for the product and/or associated services.
What Personal Data or information will Mahana collect?
The Mahana programs are provided through a website or mobile applications. To use the application (or ‘app’), you will need to register for an account.
This means that we also may ask for the following Personal Data during the sign-up process:
We may additionally collect insurance information, such as your insurance ID number.
To help you understand if Mahana products are right for you, or to monitor your health and how you are doing on a program, Mahana will have you complete self-reported questionnaires about your health and other diagnostic information. There are also interactive tasks within Mahana, where you may record personal notes. The type of information collected is dependent on the information you provide to answer the associated questions.
Additionally, if you contact us by email at support@mahana.com, mahanacare@mahana.com, or any other Mahana email address, we will collect your name, contact information, recording of the call (with your consent), or the content of your message.
What additional Personal Data is collected automatically?
When you use Mahana programs or websites, we or our third-party service providers may automatically receive and record certain data. For example, this may include your device’s IP address, user-agent string, or internet activity; commercial data, such as records of services procured and information about how you use Mahana products or services during your current session and over time (including tracking to the pages you view and the files you download), the date and time of your visit, the length of time spent logged into Mahana products or services, the number and types of sessions completed, the links you click, searches you conduct, a view into the websites you may have visited before navigating to Mahana products and services, your software and hardware attributes (including browser and operating system type and version, device type, and device identifiers), your email address, and your general location inferred from IP address. To obtain such data, we or our third-party service providers may use the following technologies to recognize your device and collect usage data:
For more information on Mahana’s tracking practices, follow this link to view our Cookie Policy.
How does Mahana use my Personal Data?
Mahana and its service providers use your Personal Data for the following purposes, including to:
With whom does Mahana share Personal Data?
We share Personal Data with third parties for a variety of reasons related to providing the digital therapeutic service, including as follows:
Clinical Partners and health plans. Your Personal Data may be accessed by Clinical Partners (as defined above) such as your healthcare providers, in order to prescribe, manage and provide you with health care services. Your Personal Data may also be shared with your health plan to manage reimbursement.
Mahana. Mahana may access Personal Data to deliver therapeutic services, technical support, or troubleshoot your account.
Mahana Care. Personal Data that we collect from you in connection with your access to and use of MahanaCare™, our optional, web-based therapeutic monitoring platform (collectively, the ‘Digital Platform’). We collect information from you both when you provide it voluntarily and automatically when you access or use Mahana’s products. We may use communication support systems, such as ActiveCampaign, to facilitate the initial participation inquiries. We may also collect personal information from your employer, health plan, and care team, which may consist of physicians and other healthcare professionals, and support personnel, including:
Select 3rd party vendors. Your Personal Data may also be stored and/or processed by service providers under contract with Mahana and strictly adhering to the principles of confidentiality, integrity, and accessibility. For example, Mahana uses Amazon Web Services (AWS) and Google Workspace to host and store our data, and ZenDesk to send you secure email communications in response to your questions or requests for technical assistance. Mahana also uses third parties to assist with operational and security support for the Mahana platform.
From time to time, Mahana may provide your Personal Data to select vendors for the purpose of data processing or specific functionality (e.g. analytics, operational support, or messaging like email or push notifications). Mahana only provides Personal Data to vendors that demonstrate a commitment to compliance with privacy and security laws, regulations and requirements under (as applicable) a data protection agreement and/or, for facilitating US prescriptions and insurance coverage, a business associate agreement as required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Such agreements assure that our vendors must process your Sensitive Data with the same obligations (confidentiality, integrity, accessibility) that apply to Mahana US as a data processor/importer (for UK/EU Personal Data), a business associate (for data regulated under HIPAA), or a personal health records vendor (for data regulated under US Federal Trade Commission or state privacy laws). Otherwise, and if identifiable data is not needed for a particular purpose, vendors are allowed only to process data that is pseudonymised or de-identified and aggregated, so that your identity is not disclosed.
Legal purposes. We also may use or provide your Personal Data to third parties when we believe that doing so is necessary to:
With consent. Mahana may use your Personal Data for purposes other than those described in this Notice with your written consent, such as for text communications or marketing and advertising. However, communications with you for treatment delivery as requested by you, to inform you of similar products and services, allowing you to opt out of future communications, or other legitimate purposes, do not require consent.
External Websites. The Mahana platform may include links to other websites or resources over which Mahana does not have control (‘External Websites’). Such links do not constitute an endorsement by Mahana of those External Websites. You acknowledge that Mahana is providing these links to you only as a convenience, and further agree that Mahana is not responsible for the content of such External Websites. Your use of External Websites is subject to the terms of use and privacy policies located on those External Websites. We encourage you to read the privacy notice of any website that you visit before you provide any information to the operator of that website.
Additional information regarding collection, use, and/or sharing of my data.
In addition to any (i) Personal Data or information collected under this Notice, (ii) uses of Personal Data or information described in this Notice, or (iii) third parties with whom Mahana may share such Personal Data or information described in this Notice, Mahana may also collect, use and/or share any Personal Data or other information as described in the Mahana Website Privacy Policy. The collection, use, and/or sharing of any Personal Data or other information described in the Mahana Website Privacy Policy shall not be construed to limit any collection, use, and/or sharing of any Personal Data or other information covered by this Notice and vice versa.
Who can see what I write in Mahana programs?
Mahana will not view the content of your entries in program journals, except for the following scenarios: technical support or troubleshooting, making product improvements, or other legally required or permissible scenarios.
Where is my Personal Data kept?
Data collected via (i) the Mahana platform is held in a database managed by Mahana US and hosted by Amazon Web Services (AWS); and (ii) Customer Support is hosted by ZenDesk, both in centers located in the US and subject to appropriate data protection agreements. For further questions you may have about that, contact privacy@mahana.com. In addition, here are links to Amazon’s privacy policy and ZenDesk’s privacy notice, which you are encouraged to review.
What are my rights regarding my Personal Data?
Your Personal Data will be processed in accordance with your rights under the applicable data protection legislation. For more information on your rights and how to exercise them, including for residents in California, Colorado, Connecticut, Utah, and Virginia, see Mahana’s Website Privacy Notice. Mahana does not sell Personal Data to third parties, nor do we have any arrangement involving an exchange of value (‘consideration’) between Mahana and a third party for Personal Data obtained from users. To exercise your privacy rights, including information access and data correction and deletion, please see Mahana’s Data Subject Portal.
How can I delete my account?
For those who have created user accounts, you can request that your account be deleted either through the mobile app (Under ‘Manage Your Account’ in ‘Settings’) or by contacting Mahana Care (mahana@mahanacare.com or 1.844.624.2620). Note that, once your account is deleted, you will no longer have access to any product content or tools.
How is my Personal Data secured?
We are committed to ensuring that your information is secure. In order to prevent unauthorized access or disclosure, we have put in place commercially reasonable physical, electronic, and managerial procedures to safeguard and secure the information we collect online, such as secure server software (SSL), firewalls, multi-factor authentication, and end-to-end encryption. However, no security program is 100% secure, and thus we cannot guarantee the absolute security of your information.
Mahana’s digital health services are provided to you through your smartphone. Thus, there are steps that you should take to protect your device from unauthorized access. You can find more tips for staying safe online at National Cybersecurity Alliance and Cybersecurity and Infrastructure Security Agency.
Children
Our programs or services are not intended for children. If you believe a child who is under age 13 has provided information to Mahana, please contact us using the information provided below.
Changes to this Policy
This Privacy Notice may change from time to time, so please check back periodically to check the most recent modification date to ensure that you are aware of any changes in our processing of your Personal Data. Your continued use of Mahana products and services after any changes signifies your express, explicit, voluntary, and unambiguous consent to any such changes. If you do not agree to such changes, you must immediately stop using Mahana products and services.
Contact us about Complaints, Questions, or Notices related to this Privacy Notice
Mahana digital health programs are created by Mahana Therapeutics, Inc., on behalf of itself. You can contact us at:
Mahana Therapeutics, Inc., a Delaware corporation (6703171)
505 Montgomery St.
11th Floor
San Francisco, CA 94111
1.844.624.2620
privacy@mahana.com
support@mahana.com
mahanacare@mahana.com
You can also submit named or anonymous complaints via our Data Subject Portal. If your issue is not resolved, you can report to the applicable supervisory authority (such as the California Office of Attorney General, California Privacy Protection Agency, or Federal Trade Commission.)
Right to withdraw consent
In relation to our products, you may have given consent for Mahana to contact you by certain means as part of our digital therapy (e.g., text reminders), to send marketing materials, or to share your Personal Data with Clinical Partners. You have the right to withdraw any consent you may have previously given us at any time. If you withdraw your consent, this will not affect the lawfulness of our collecting, using and sharing of your Personal Data or Sensitive Data as contemplated up to the point in time that you withdraw your consent. Even if you withdraw your consent, we may still use your information that (i) has been fully anonymized and does not personally identify you; or (ii) that has been collected under a legal basis other than consent, to the extent such use continues to be necessary for that other purpose. If you would like to withdraw consent for further processing your Personal Data, please submit a written request to Mahana’s Data Subject Portal. For more information on other types of consents, please see Mahana’s Website Privacy Notice.
Agreement
This Health Care Data Consent & Product Privacy Notice, as well as the Mahana’s Terms of Use, comprise an agreement which takes priority over other conflicting terms, understandings, or agreements you may have or have had with regard to the subject matter covered by the combined terms. However, that being said, any terms of a later consent form signed by you will take priority over conflicting terms of consent which may reside in these combined terms.
© Copyright 2023. Mahana Therapeutics, Inc. All Rights Reserved