EPITOMYZE PRIVACY STATEMENT

Epitomyze Inc. (“we,” “us,” or “Epitomyze”) provides digital image management solutions and has designed and implemented a mobile application (the “App”) and a cloud storage service “Epitomyze Cloud” (the “Service“), which allow doctors and other healthcare providers to upload, manage, distribute and allow access to patient images acquired using the Epitomyze SolutionTM (“Media”) through the website located at www.epitomyze.com (the “Website”). By using, purchasing or expressing interest in our website, products and services, you have entrusted us with certain personal information and, in many cases, the handling of this sensitive information is subject to various privacy-related laws. Epitomyze is committed to protecting the privacy of your information as set out in this Privacy Policy. In order to stay current with evolving privacy laws and changes to its business, Epitomyze may update this Privacy Policy at any time by posting a revised Privacy Policy on its websites.

This Privacy Statement relates to “Personal Information”, meaning information about an identifiable individual, whether, for example, that individual is our Customer’s provisioned user or is a Patient, as these terms are defined below. Whether a person is “identifiable” means that they can be identified by the information itself or by that information combined with other information reasonably available.

This Privacy Statement applies to Personal Information processed by Epitomyze and also applies to information that is collected via our websites, Data Management portal and Epitomyze Capture application (collectively, the “Epitomyze System”). In this Privacy Statement we will refer to the organization that is primarily responsible for the collection, use and disclosure of Patient information as the “Custodian”.

Practices

Epitomyze has developed extensive policies and procedures to protect your information and comply, as applicable, with privacy regulations, such as HIPAA. Every Epitomyze employee and contractor must sign confidentiality agreements and follow Epitomyze’s privacy and information security policies. At Epitomyze, we regularly communicate with our employees and contractors about our obligation to safeguard confidential and personal information. Epitomyze employs security best practices to protect your data. This includes the use of security encryption technologies for data in transit and at rest. We conduct regular internal and external security testing and we regularly track and apply security updates. Epitomyze’s products, services and websites are not intended for use by, or marketed to, children under 18.

Classification of information

When the Epitomyze System is used by our Customers, we classify the Personal Information we collect, use and disclose into two main categories: The first is information about our Customers and the second is about our Customers’ Patients. Mainly, our “Customers” are organizations and individuals that are involved with Patients. The term “Patient” refers to those individuals whose data are collected and processed using the Epitomyze System.

Where the Epitomyze System is made available to a Patient by a Customer, the Customer is the Custodian. The way we handle Personal Information varies depending on whether it relates to a Customer’s provisioned user (e.g. a Customer employee or other representative) or a Patient, so each is specifically addressed in this Privacy Statement. You should also note that we are managers of Patient Personal Information as service providers to our Customers and as otherwise provided by consent of a Patient. The collection, use, and disclosure of Patient Personal Information will be subject to the privacy practices of the relevant Customers and our Terms of Service, so Patients should refer to them for additional information.

Patients should also be aware that Customers are able to export data from the Epitomyze System. Customers are solely responsible for the use of such data and for safeguarding it. Patients should therefore be aware that their Personal Information may also be directly held by the relevant Customer.

What information we collect

From our Customers, we collect information that is necessary to establish and maintain the provision of the Epitomyze System to them, as well as to understand and improve the usage and performance of the Epitomyze System. Most of our Customers are corporations, so this information is not “Personal Information”. This information includes:

  • Customer name
  • Contact information, including postal and email addresses
  • Billing address
  • Billing details (as necessary for our internal accounting purposes and for processing payments through our contracted processing service)
  • Login information for provisioned users, such as usernames and encrypted passwords

Information about how the Customer and its provisioned users use the Epitomyze System, including information about the Customer and intended use of the Epitomyze System. Information provided by the Customer and its provisioned users in connection with any support given by the Epitomyze team related to the Epitomyze System.

The use of the Epitomyze System may involve the collection and processing of the following Patient Personal Information on behalf of Customers, among other things:

  • Patient name (Title and full name)
  • Patient health card number
  • Patient gender
  • Patient date of birth
  • Patient contact details (including company or school)
  • Patient hire date
  • Patient ID number
  • Care providers (physicians, etc)
  • Information about the Patient’s hearing
  • Patient test results
  • Location and date of the test
  • Home phone number
  • Cell phone number
  • Work phone number
  • Medical imaging
  • Notes
  • Email address
  • Chart number

Providing information is under the control of the Custodian when the Epitomyze System is set up for that Custodian.

Purposes for collection

Patient Personal Information is processed by Epitomyze to provide our Customers with the Epitomyze System and in accordance with authorizations. Patients should refer to the Customer’s privacy policy and our Terms of Service for an understanding of how Patient Personal Information is collected, used, disclosed and otherwise processed through the Epitomyze System before submitting any Personal Information to the Epitomyze System. Further, if you have any questions or concerns about the processing of your Personal Information, you should consult the Custodian.

Disclosure of Personal Information

Epitomyze may share Personal Information with people within the company who have a “need to know” the information for business or legal reasons, for example, in order to carry out an administrative function, such as processing an invoice or to direct a question that you have submitted to the relevant department at Epitomyze.

We may share Personal Information with third parties, including: government and regulatory authorities, for example to respond to a legal request or comply with a legal obligation, in which case we will make reasonable efforts to give the relevant individual notice of the disclosure, provided we are able to identify the individual and are lawfully able to do so; for the purposes of seeking legal or other professional advice; suppliers of IT services and third service providers engaged by Epitomyze as further detailed earlier in this Privacy Statement and our Terms of Service; and in the event that we sell, buy or merge any business or assets, including to the prospective seller or buyer of such business or assets and their respective professional advisers. We may also share anonymous or de-identified information with other third parties in connection with the purposes outlined in this Privacy Statement and our Terms of Service.

When you use Epitomyze Cloud, we may receive personal health information (PHI) from your use of these services. Any PHI collected by Epitomyze Cloud will be managed in accordance with HIPAA standards. The Epitomyze Terms of Service and our Business Associate Addendum prohibit us from disclosing your confidential information or PHI except under certain narrowly defined circumstances, such as to provide the services, as authorized and otherwise in accordance with applicable law. Epitomyze agrees to use PHI only in accordance with the terms of these agreements.

Right of Access

Pursuant to applicable law, you may have certain rights in relation to your Personal Information, including a right of access. Patients should contact the relevant Custodian directly and the Custodian can facilitate this access directly by use of the Epitomyze System. If we are required to assist the Custodian, we may require additional information to confirm a Patient’s or provisioned end-user’s identity, which will only be used for that.

Data Location: At present, data is stored in the United States from all Customers.

THE FOLLOWING SECTIONS APPLY TO ALL COLLECTION AND USE OF PERSONAL INFORMATION FROM ALL SOURCES VIA OUR WEBSITES, DATA MANAGEMENT PORTAL AND APPLICATION:

When you visit our websites, epitomyze.com or imagestore.md, including our Data Management portal, cloud.epitomyze.com, or use the Epitomyze Capture application, we may use cookies, pixel tags, analytics tools, and other similar technologies to help provide and improve our services to you, and as detailed below:

Cookies: Cookies are pieces of information stored directly on the computer that you are using. Cookies allow us to collect information such as browser type, time spent on the website or application, pages visited, language preferences, and other web or application traffc data. We use the information for security purposes, to facilitate online navigation, to display information more effectively, to personalize your experience while using the website or application, and to otherwise analyze user activity. We can recognize your computer to assist your use of the website or application.

We also gather statistical information about the usage of the website and er to continually improve their design and functionality, the website and application are used, and assist us with resolving questions regarding the website and application. Cookies may further allow us to select which of our advertisements or offers are most likely to appeal to you and to display them to you. We may also use cookies in online advertising to see how you interact with our advertisements, and we may use cookies or other files to understand your use of other websites. If you do not want information to be collected through the use of cookies when using our website or application, there is a simple procedure in most browsers that allows you to automatically decline cookies or gives you the choice of declining or accepting the transfer to your computer of a particular cookie (or cookies) from a particular site. However, if you do not accept these cookies, you may experience some inconvenience in your use of the website. For example, we may not be able to recognize your computer, and you may need to login every time you visit the website or application.

Pixel tags and other similar technologies: Pixel tags (also known as web beacons and clear GIFs) may be used in connection with our website to, among other things, track the actions of users of the website or application and other means of communication with you (including email recipients), measure the success of our marketing campaigns, and compile statistics about usage of the website and response rates.

Analytics tools: We use website and application analytics services provided by third parties that use cookies, JavaScript and other similar technologies to collect information about website or application use, perform data enrichment and to report patterns or trends. We use the following analytics tools which we will update this list as we change our analytics tools:

  • Fabric
  • Google Analytics
  • Facebook
  • Twitter
  • LinkedIn

Safeguarding Personal Information

We are required by law to safeguard the Personal Information in our custody or control. We use industry standard measures to protect Personal Information against loss or theft, as well as unauthorized access, disclosure, copying, use, or modification. We protect Personal Information regardless of the format in which it is held. We recognize that Patient Personal Information is sensitive health information and we protect it accordingly. If you have any questions or concerns in relation to the handling of your sensitive health information, you should contact the Custodian.

Our methods of protection include: (a) physical measures, such as restricted physical access to our information system; (b) organizational measures, including employee training and limiting access on a “need-to- know” basis; and, (c) technological measures, including the use of passwords and encryption. More information about our security practices can be found in our security policy.

We use service providers, including data hosting providers, to facilitate providing the Epitomyze System. We use contractual means to make sure that our service providers only deal with Personal Information on our behalf to provide the Epitomyze System and not for any other purposes. We also undertake diligence to satisfy ourselves that our service providers will implement adequate safeguards to protect Personal Information.

If we have reason to believe that there has been a breach of security safeguards that has resulted in the inappropriate loss or disclosure of Personal Information, we will take reasonable measures to notify the affected Customers or Patients, as applicable, promptly and with sufficient detail to enable them to evaluate the breach and understand the likely consequences.

Revisions to this Privacy Statement

Epitomyze may update this Privacy Statement from time to time. If it is updated, the effective date of the revision will be shown at the bottom of the Privacy Statement. In the event of a significant revision, Customers may receive notification by email or through the Epitomyze System itself. All Personal Information collected after that revision date will be subject to the revised Privacy Statement.

Anonymous information

Epitomyze may use de-identified and/or aggregate information derived from Personal Information, for any purposes, including: analytics to understand how our Customers and their provisioned users make use of the Epitomyze System and our website; information used to determine how to make improvements to the Epitomyze System and to develop new capabilities; information that reveals trends in data; as expressly authorized; and, for research purposes, either for Epitomyze or for others. We will take industry standard steps so that this de-identified and/or aggregate information cannot be connected to any particular individual.

EU PERSONAL INFORMATION

This section shall apply only in respect of Personal Information relating to individuals located in the EU (“EU Personal Information”). For the purposes of applicable EU data protection and privacy laws, Epitomyze, with its registered offices at 2537 Post Road, Southport CT 06890 is considered the Data Controller in respect of all EU Personal Information that it collects, uses and otherwise processes for its own purposes as set out in this Privacy Statement. If you are a Customer, website user or other individual with whom we communicate and/or do business and you are located in the EU, you should read this Privacy Statement in full and particularly this section, before you provide us with any Personal Information or browse our website, and make sure that you are comfortable with our privacy practices. Please note that for the purposes of EU data protection and privacy laws, personally identifiable information collected in a business context (for example an individual’s business email address or job title) will be Personal Information. All provisions in this Privacy Statement relating to Personal Information will therefore apply to any Personal Information that we collect about representatives of our Customers, such as Customer employees (and see in particular, the section entitled “What information we collect”).

Purpose of Processing

The purposes for which we process EU Personal Information are as set out in this Privacy Statement and our Terms of Service. In most cases, we will be processing EU Personal Information on behalf of a Customer as a Data Processor, but in certain circumstances we will process EU Personal Information as a Data Controller, including for the purposes of communicating with you, administering your account and for carrying out data analytics and enrichment.

Legal Basis for Processing

In accordance with the purposes for which we collect and use EU Personal Information, as set out above, the legal basis for Epitomyze processing EU Personal Information will typically be one of the following: your consent; the performance of a contract that we have in place with you or other individuals; Epitomyze’s or our third parties’ legitimate business interests; or compliance with our legal obligations.

Sharing of EU Personal Information

Epitomyze may share EU Personal Information with people within the company who have a “need to know” the information for business or legal reasons, for example, in order to carry out an administrative function, such as processing an invoice or to direct a question that you have submitted to the relevant department at Epitomyze. We may share EU Personal Information with third parties, including: government and regulatory authorities, for example to respond to a legal request or comply with a legal obligation, in which case we will make reasonable efforts to give the relevant individual notice of the disclosure, provided we are able to identify the individual and are lawfully able to do so; for the purposes of seeking legal or other professional advice; suppliers of IT services and third party service providers engaged by Epitomyze as further detailed earlier in this Privacy Statement and our Terms of Service; and in the event that we sell, buy or merge any business or assets, including to the prospective seller or buyer of such business or assets and their respective professional advisers. We may also share anonymous or de-identified information with other third parties in connection with the purposes outlined in this Privacy Statement.

Information Transfers

In order to provide the Epitomyze System and our website and as further detailed in the “Data Location” section above, any EU Personal Information that we obtain may be transferred to and stored in a country outside the EEA, including Canada and the US. This may include transferring EU Personal Information to countries where the law provides less protection for Personal Information. If we transfer EU Personal Information to a country outside of the EEA, we will, as required by applicable law, ensure that your privacy rights are protected by appropriate safeguards. Please contact us if you would like more information about these safeguards.

Glossary

For the purposes of this section relating to EU Personal Information, the following terms will have the following meanings:

“Data Controller” an entity which determines the purposes and means of the processing of Personal Information.

“Data Processor” an entity which processes Personal Information on behalf of a Data Controller.

“EEA” European Economic Area.

“process” means any operation that can be performed on Personal Information, including collecting it, storing it, accessing it, combining it with other data, sharing it with a third party, and deleting it.

If you have any questions or concerns about our privacy practices, or if you wish to access your Personal Information, please contact our privacy officer.

Effective Date: May 25, 2018