Effective April 1, 2020
Your privacy and trust are important to us. This Privacy Notice (“Privacy Notice”) explains how Complete Medical Services, LLC (dba CMS Solutions) and Achieve Patient Safety And Quality Improvement LLC (“CMS,” “Achieve,” “we”, “us” or “our”) collects, handles, stores and protects personal information about you in the context of our products and services. It also provides information about your rights and about how you can contact us if you have questions about how we handle your information.
WHO THIS STATEMENT APPLIES TO AND WHAT IT COVERS
Depending on the Service, we may provide additional or different privacy statements or notices for specific interactions you have with us or to highlight how we use your personal information for specific Services. Where we do this, it will be clear which statements apply to which interactions and Services.
Within our Services, there may be links to third-party websites or applications. We are not responsible for the content or privacy compliance of third-party websites or applications. You should check those websites or applications for their privacy statements and terms that apply to them.
WHO WE ARE
CMS and Achieve are United States Quality Improvement Consulting Companies.
We obtain personal information from you: through your interactions with us and our Services, such as when you purchase or use our Services, browse or register on our Websites, register for an event or service, attend a training course, request information or call us.
Our servers, logs and other technologies automatically collect system/device and usage information to help us administer, protect and improve our Services, analyze usage and improve users’ experience through cookies and similar technologies included on our Services.
The type of personal information we collect depends on how you are interacting with us and which Services you are using. In many cases, you can choose whether or not to provide us with personal information, but if you choose not to, we may not be able to provide you Services, or you may not get full functionality from the Services.
The personal information we collect consists of the following:
- Name and contact data, such as, first and last name, email address, postal address, phone number, and other similar contact data.
- Your organization or practice, role or title, and credentials (e.g. MD, DO, MBD, NP).
- Employment and education history.
- Account Credentials, such as, passwords and other security information for authentication and access.
- User content, such as, communications and files provided by you in relation to your use of the Services.
- Device information, such as, information about your device, such as IP address, location or provider.
- Usage information and browsing history, such as, information about how you navigate within our Services, your browsing history and which elements of our Services you use the most.
- Location data for Services with location-enhanced features. If we need your consent to collect geo-location data, we will collect this separately. If you do not want to provide us with location-tracking information, you can disable location tracking functions on your device, provided your device permits you do this.
- Demographic information, such as, your country, and preferred language
HOW WE USE PERSONAL INFORMATION
This section includes details of the purposes for which we use personal information and also the different legal grounds upon which we process that personal information. We use personal information to provide and improve Services and for other purposes that are in our legitimate interests, as well as for compliance purposes. Further information is set out below.
Some laws require us to explain our lawful reason for processing your personal information. We process personal information about you on the basis that it is:
- Necessary for the performance of a contract: where we have a contract with you, we will process your personal information in order to fulfill that contract (i.e., to provide you with Services).
- In our or a third parties’ legitimate interests: details of those legitimate interests are set out in more detail below (e.g., provision of Services that we are contractually obliged by a third party, such as your employer or our subscriber, to deliver to you).
- Where you give us your consent: we only ask for your consent in relation to specific uses of personal information where we need to and, if we need it, we will collect it separately and make it clear that we are asking for consent
- For compliance with a legal obligation (e.g., to respond to a court order or a regulator)
You are welcome to contact us for further information on the legal grounds that we rely on in relation to any specific processing of your personal information.
LEGITIMATE INTERESTS FOR USE
We use personal information for a number of legitimate interests, including to provide and improve Services, administer our relationship with you and our business, for marketing and in order to exercise our rights and responsibilities. More detailed information about these legitimate interests is set out below.
- To set up and administer your account, provide technical and customer support and training, verify your identity, and send important account, subscription and Service information.
- To administer our relationship with you, our business and our third-party providers (e.g., to send invoices).
- To fulfill bookings for training or events, which includes processing your application.
- To personalize your experience with our Services. We may retain your browsing and usage information to make your searches within our Services more relevant and use those insights to target advertising to you online on our Websites and apps and via e-mail.
- We share your personal information across our Services so that we can make all of the Services we deliver to you more intuitive (e.g., rather than requiring you to enter the same data many times) to contact you in relation to, and conduct, surveys or polls you choose to take part in and to analyze the data collected for market research purposes.
- To provide any third party, who has made our Services available to you (e.g., your employer or our subscriber), insights about use of the Services to fulfil contractual obligations, for internal research, for development purposes, and to improve, test, and enhance the features and functions of our Services.
- To provide you with marketing as permitted by law to meet our internal and external audit requirements, including our information security obligations (and if your employer or our subscriber provides for your access to our Services, to meet their internal and external audit requirements).
- To enforce our terms and conditions to protect our rights, privacy, safety, networks, systems and property, or those of other persons for the prevention, detection or investigation of a crime or other breach of law or requirement, loss prevention or fraud.
- To comply with requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, including where they are outside your country of residence.
- In order to exercise our rights, and to defend ourselves from claims and to comply with laws and regulations that apply to us or third parties with whom we work.
- In order to participate in, or be the subject of, any sale, merger, acquisition, restructure, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings).
Where we rely on legitimate interests as a lawful ground for processing your personal information, we balance those interests against your interests, fundamental rights and freedoms. For more information on how this balancing exercise has been carried out, please contact our Privacy Team at firstname.lastname@example.org.
We deliver marketing and communications to you across various platforms such as email, telephone, text messaging, direct mail and online. Where required by law, we will ask you to explicitly opt in to receive marketing from us. If we send you a marketing communication it will include instructions on how to opt out of receiving these communications in the future.
Honoring your marketing preferences is important to us. You have the right to opt out of receiving direct marketing and targeted online advertising.
HOW TO OPT OUT OF EMAIL MARKETING
Where we send marketing emails, we provide unsubscribe options for your use within our emails. To update your email marketing preferences, please visit the applicable email preference center, a link to which will normally be included in emails you receive from us. In addition, you can also use the “Contact Us” feature of a particular Service, or contact our Privacy Team.
Even if you opt out of receiving marketing communications by email, we may still send you service communications or important transactional information related to your accounts and subscriptions (for purposes such as providing customer support).
ADVERTISING ON MOBILE DEVICES
Mobile devices have an identifier that gives companies the ability to serve targeted ads to a specific mobile device. In many cases, you can turn off mobile device ad tracking or you can reset the advertising identifier at any time within your mobile device privacy settings. Another tool you can use to control advertising on your mobile device is the AppChoices App: http://youradchoices.com/appchoices. You may also choose to turn off location tracking on your mobile device. If you turn off ad tracking or location tracking, we will no longer use information collected from your device’s advertising identifier for the purposes of advertising. You may still see the same number of ads but they may be less relevant because they will not be based on your interests. Where we need your consent to gather information about your location we will obtain this from you.
HOW WE SHARE PERSONAL INFORMATION
We share your personal information within the Company, with our business partners and third party service providers, to the person providing for your access to our Services (if that is not you) and in accordance with law. Our third-party service providers are not permitted to share or use personal information we make available to them for any purpose other than to provide services to us.
We share your information for the purposes set out in this Policy, with the following categories of recipients:
- Our Company and our subsidiaries.
- Business partners with whom we deliver co-branded Services, provide content, or to host events, trainings, conferences and seminars.
- Third parties that help us deliver Services or act on our behalf.
- Third parties where we have a duty to or are permitted to disclose your personal information by law (e.g., government agencies, law enforcement, courts and other public authorities).
- Third parties in order to participate in, or be the subject of, any sale, merger, acquisition, restructure, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings), in which case we may disclose your personal data to prospective buyers, sellers, advisers or partners and your data may be a transferred asset in a business sale.
- Third parties where reasonably required to protect our rights, users, systems and Services (e.g., legal counsel and information security professionals)
- Any person you have asked us to share information with (e.g., if you upload information into a public forum it is shared publicly).
We are a United States organization and your personal information may be stored and processed outside of your home country, including in countries that may not offer the same level of protection for your personal information as your home country. We have measures in place to ensure that when your personal information is transferred internationally, it is subject to appropriate safeguards in accordance with data protection laws. Often, these include contractual safeguards. More information about these safeguards (including copies, where relevant) can be obtained by contacting us at email@example.com.
We collaborate with third parties like cloud hosting services, suppliers and technology support located around the world to serve the needs of our business, workforce and customers.
We take appropriate steps to ensure that personal information is processed, secured and transferred according to applicable law. In some cases, we may need to disclose or transfer your personal information within our Company or to third parties in areas outside of your home country, including to countries that have not been declared adequate for the purposes of data protection by US Protection Law or GDPR as applicable.
When we transfer personal information internationally, we put in place safeguards in accordance with applicable law (including Articles 44 to 50 of the EU General Data Protection Regulation). If you would like to know more about our data transfer practices and obtain copies of any relevant safeguarding measures, please contact our Privacy Team.
HOW WE SECURE PERSONAL INFORMATION
We take the security of personal information seriously and we use appropriate technologies and procedures to protect personal information (including administrative, technical and physical safeguards) according to the risk level and the service provided.
Our Data Compliance Officer, which is responsible for implementing secure data handling practices at the Company.
Our information security policies and procedures are closely aligned with widely accepted international standards and are reviewed regularly and updated as necessary to meet the sensitivity of the personal information we handle, our business needs, changes in technology and regulatory requirements. We have implemented appropriate information security controls.
HOW LONG WE KEEP PERSONAL INFORMATION
We keep personal information for five years, and as long as reasonably necessary afterwards to fulfill any legal requirements.
You may have rights under European and other laws to have access to your personal information and to ask us to rectify, erase and restrict use of, your personal information. You may also have rights to object to your personal information being used, to ask for the transfer of personal information you have made available to us and to withdraw consent to the use of your personal information. Further information on how to exercise your rights is set out below.
We will honor your rights under applicable data protection laws.
- Right of subject access: The right to make a written request for details of your personal information and a copy of that personal information.
- Right to rectification: The right to have inaccurate information about you corrected or removed.
- Right to erasure (‘right to be forgotten’): The right to have certain personal information about you erased.
- Right to restriction of processing: The right to request that your personal information is only used for restricted purposes.
- Right to opt out of marketing: You can manage your marketing preferences by unsubscribe links found in the communications you receive from us or by visiting the applicable preference center.
- Right to object: The right to object to processing of your personal information in cases where our processing is based on the performance of a task carried out in the public interest or we have let you know the processing is necessary for our or a third party’s legitimate interests.
- Right to data portability: The right to ask for the personal information you have made available to us to be transferred to you or a third party in machine-readable format.
- Right to withdraw consent: The right to withdraw any consent you have previously given us to handle your personal information. If you withdraw your consent, this will not affect the lawfulness of our use of your personal information prior to the withdrawal of your consent.
These rights are not absolute, and they do not always apply in all cases.
In response to a request, we will ask you to verify your identity if we need to, and to provide information that helps us to understand your request better. If we do not comply with your request, whether in whole or in part, we will explain why.
In order to exercise your rights please contact us at firstname.lastname@example.org.
COOKIES AND SIMILAR TECHNOLOGIES
WHAT IS A COOKIE?
A cookie is a small text file that is placed on a computer or other device and is used to identify the user or device and to collect information. Cookies are typically assigned to one of four categories, depending on their function and intended purpose: absolutely necessary cookies, performance cookies, functional cookies, and cookies for marketing purposes.
TYPES OF COOKIES AND WHY WE USE THEM
Absolutely necessary cookies: These cookies are essential to enable you to move around a website and use its features. Without these cookies, Services you have asked for, like adding items to an online shopping cart, cannot be provided.
Performance cookies: These cookies collect information about how you use our Websites. Information collected includes, for example, the Internet browsers and operating systems used, the domain name of our Websites previously visited, the number of visits, average duration of visit, and pages viewed. These cookies only collect information in an aggregated format. Performance cookies are used to improve the user-friendliness of a website and enhance your experience.
Functionality cookies: These cookies allow our Websites to remember choices you make (such as your username or ID, language preference, or the area or region you are in) and provide enhanced, more personal features. These cookies can also be used to remember changes you have made to text size, fonts, and other customizable parts of web pages. They may also be used to provide Services you have asked for, such as watching a video or commenting on a blog. These cookies cannot track your browsing activity on other websites.
Targeting and advertising cookies: These cookies track browsing habits and are used to deliver targeted (interest-based) advertising. They are also used to limit the number of times you see an ad and to measure the effectiveness of advertising campaigns. They remember that you have visited a website and this information is shared with other organizations, such as advertisers.
You can manage website cookies in your browser settings, and you always have the choice to change these settings by accepting, rejecting, or deleting cookies. If you choose to change your settings, you may find that certain functions and features will not work as intended on the Services. All browser settings are slightly different, so to manage cookies, you should refer to the relevant settings within your browser.
We use certain other tracking technologies in addition to cookies:
Local shared objects/Flash cookies: Flash cookies, also known as local shared objects, are designed to support browser content supported by Adobe® Flash. They are usually used to enable ads and video content on websites. Like other cookies, they will store information on your device, some of which will be specific to the Flash-enabled content. Flash cookies can only be deleted within Adobe Flash rather than via your browser. Please refer to the following help page for information on how to manage your privacy settings and deletion of Flash cookies: http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html.
Web beacons: Our web pages may contain electronic images known as web beacons (also called single-pixel gifs and transparent graphic images) that we use to help deliver cookies on our sites, count users who have visited those sites, deliver Services, and analyze the effectiveness of our promotional campaigns, for example. We may also include web beacons in our marketing email messages or newsletters to determine whether an email is opened or if links are clicked. Web beacons are also used to deliver you interest-based advertising.
Web server & application logs: Our servers automatically collect certain information to help us administer and protect the Services, analyze usage, and improve users’ experience. The information collected includes:
- IP address and browser type
- Device information including Unique Device Identifier (UDID), MAC address, Identifier For Advertisers (IFA), and similar identifiers we or others may assign
- Device operating system and other technical facts
- The city, state, and country from which you access our Websites
- Pages visited and content viewed, stored, and purchased
- Information or text entered
- Links and buttons clicked
- URLs visited before and after you use our Services
“Do Not Track” Signals
Some browsers transmit Do Not Track (DNT) signals to websites. Due to the lack of a common interpretation of DNT signals throughout the industry, we do not currently alter, change, or respond to DNT requests or signals from these browsers. We continue to monitor industry activity in this area and reassess our DNT practices as necessary.
Connecting via social networks
Some of our Services may include social networking features, such as the Facebook® “Like” button and widgets, “Share” buttons, and interactive mini-programs. Additionally, you may choose to use your own social networking logins from, for example, Facebook or LinkedIn®, to log into some of our Services. If you choose to connect using a social networking or similar service, we may receive and store authentication information from that service to enable you to log in and other information that you may choose to share when you connect with these Services. These Services may collect information such as the web pages you visited and IP addresses, and may set cookies to enable features to function properly. We are not responsible for the security or privacy of any information collected by these third parties. You should review the privacy statements or policies applicable to the third-party services you connect to, use, or access. If you do not want your personal information shared with your social media account provider or other users of the social media service, please do not connect your social media account with your account for the Services and do not participate in social sharing on the Services.
WHERE TO FIND FURTHER PRIVACY INFORMATION ON OUR PRODUCTS AND SERVICES
This Privacy Notice generally relates to the personal information we collect about users in connection with the Services, where we make decisions about how that personal information is handled.
Where we need to give you additional information about how your personal information is used in relation to specific Services we will provide separate or additional privacy notices.
HOW TO CONTACT US
If you have any questions, comments, complaints or suggestions in relation to data protection or this Statement, or any other concerns about the way in which we process information about you, please contact our Privacy Team at email@example.com.
If you are not satisfied with the response, we encourage you to escalate your query to our Data Compliance Officer at firstname.lastname@example.org or at 888-267-6280.
Filing a Complaint. If you are not content with how we manage your personal information, you can lodge a complaint with a privacy supervisory authority. In the United States, Consumer Privacy and Security Enforcement rests with the Federal Trade Commission. In the European Economic Area, the relevant supervisory authority is the one in the country or territory where:
- you are resident
- you work, or
- the alleged infringement took place
UPDATES TO THIS PRIVACY NOTICE
This Privacy Notice may be subject to updates. Any material future changes or additions to the processing of personal information as described in this Privacy Notice affecting you will be communicated to you through an appropriate channel. For example, we may place a prominent notice on a product site or email you to let you know of an updated Privacy Notice.
If you have any questions or concerns about your data, how we are handling it, wish to ask us not to process your data or wish to ask us to erase your data, please contact:
Data Compliance Officer