Thank you for using the RxWallet
application as provided by RxEOB.Com, LLC. (“RxEOB”) application. This privacy
policy tells you how we use personal information collected in this application.
Please read this privacy policy before using the application or submitting any
personal information. By using the application, you are accepting the practices
described in this privacy policy. These practices may be changed or updated
from time to time. You are encouraged to review the privacy policy whenever you
use the application to make sure you understand how any personal information
you provide will be used. If you are a registered user, you have already agreed
and are additionally subject to either (1) the Terms of Use, or (2) any
relevant client service contract entered into between your pharmacy benefit
provider and RxEOB, each of which expressly incorporates this Privacy Policy.
NOTE: the privacy practices set forth
in this privacy policy are for the RxEOB application. If you link to other
websites within RxEOB application, please review the privacy policies posted
for those sites.
1. Collection of Information
2. Tracking Technologies
3. Distribution of
Information
4. Updating/Accessing/Amending/Correcting
Personal Information
5. Customer
Testimonials/Comments/Reviews
6. Commitment to Data
Security
7. Notification of Changes
8. Your Consent
9. California Consumer
Privacy Act Notice
9.a. CCPA Consumer Request
Form
10. Privacy Contact Information
Collection of Information
We may collect personal information,
like names, postal addresses, email addresses, mobile phone numbers etc. that
are volunteered by you if you are required to register or by volunteering for
messaging services. Upon this registration you are given a unique RxEOB ID, and
you are no longer anonymous to us. Once you are registered you are granted
access to features of the RxEOB application. This information is used to
fulfill your specific requests unless you authorize us to use it in another
manner, for example to report an issue or discrepancy with our application or
services.
Tracking Technologies
Technologies such as: cookies, tags,
and scripts are used by RxEOB and our partners, Pharmacy Benefit Sponsors,
affiliates, for analytics. These technologies are used in analyzing trends,
administering the application, tracking users’ movements around the application,
and to gather demographic information about our user base as a whole. We may
receive reports based on the use of these technologies by these companies on an
individual as well as aggregated basis.
We use cookies to remember users’
settings. Users can control the use of cookies at the individual browser level.
If you reject cookies, you may still use our application, but your ability to
use some features or areas of our application may be limited.
As is true of most applications, we
gather certain information automatically and store it in log files. This
information may include internet protocol (IP) addresses, browser type,
internet service provider (ISP), referring/exit pages, operating system, type
of device used, date/time stamp, and/or clickstream data.
We may combine this automatically
collected log information with other information we collect about you. We do
this to improve the services we offer you, to improve marketing, analytics, or application
functionality.
RxEOB does not display advertising on
our application or allow advertising with other applications. RxEOB does not
share any tracking with third party advertisers, nor do our applications
respond to DNT browser signals.
Distribution of Information
RxEOB will only share personal
information with your health plan, governmental agencies, or other companies
assisting us in fraud prevention or investigation. We may do so when:
(1) permitted or required by law such
as to comply with a subpoena.
(2) trying to protect against or
prevent actual or potential fraud or unauthorized transactions; or,
(3) investigating fraud which has
already taken place and when we believe in good faith that disclosure is
necessary to protect our rights, protect your safety or the safety of others,
or respond to a government request.
RxEOB will not share any personal
data with third parties for marketing purposes. If we are involved in a merger,
acquisition, or sale of all or a portion of our assets, you will be notified
via email and/or a prominent notice on our application of any change in
ownership or uses of your personal information, as well as any choices you may
have regarding your personal information. RxEOB will not disclose any of your
personal information except when we have your permission or under special circumstances
described in more detail below.
When using RxEOB application and
sharing personal information, you will be sharing that information with RxEOB
and/or your benefit sponsor. You can choose not to allow the transfer of your
personal information by not using that particular service.
In the event of a promotion sponsored
by other companies or cosponsored with RxEOB, you will still have the choice of
sharing your information and will be notified during the time of data
collection and decide to share or not to share your data.
Please be aware that approved applications
that have links on our application may collect personal information about you.
The information practices of applications linked to RxEOB are not covered by
this privacy policy, and you must check those privacy policies to verify how
they may use your personal information.
We may, however, share aggregate
statistical information regarding our customers, traffic patterns, and application
usage with our partners, each of whom is bound by their own privacy policies
and applicable laws. This information will always be in aggregate and will not
be individual and personal in nature. Your RxEOB account can be deleted or
deactivated but doing so will result in termination of access. Please contact
RxEOB for further instructions about deleting or deactivating your RxEOB
account. Residual information will remain within our archive records.
We will retain your information for
as long as your account is active or as needed to provide you with services and
use your information as necessary to comply with our legal obligations, resolve
disputes, and enforce our agreements.
Updating/Accessing/Amending/Correcting
Personal Information
If your personal information changes,
or if you no longer desire our service, you may correct, update, amend,
delete/remove, or deactivate it by making the change on our member information
page, by emailing our Customer Support at operations@rxeob.com, or by
contacting us by telephone or postal mail at the contact information listed
below:
RxEOB.Com, LLC
2810 N Parham Road, Suite 245,
Henrico, Virginia, 23294
804-643-1540
We will respond to your request
within 30 days.
Customer
Testimonials/Comments/Reviews
We post customer
testimonials/comments/reviews on our application which may contain personal
information. We obtain customer’s consent to post their name along with their
testimonial via email prior to posting the testimonial. If you wish to update
or delete your testimonial, please contact us at operations@rxeob.com.
Commitment to Data Security
Your personal information is kept
secure. Only authorized employees, agents, and contractors (who have agreed to
keep information secure and confidential) have access to this information. All
emails and newsletters from this application allow you to opt out of further
mailings. Keeping your personal health-related information private is vitally
important to us. Knowing that you use certain services or features may help us
to offer you more relevant content; however as with all personal information we
do not make this available to any third parties without your permission, except
as required by law. Your RxEOB account information is password-protected and
encrypted with built in lockout features to deter suspicious activity. Only
you, your designated benefit enrollee, or your benefit sponsor have access to
this personal information. We strongly recommend that you do not divulge your
password to anyone. RxEOB will never ask you for your password in an
unsolicited phone call or in an unsolicited email. Also remember to close the
RxEOB application when not in use. This ensures that others cannot access your
personal information and correspondence.
Unfortunately, no data transmission
over the Internet can be guaranteed to be 100% secure. As a result, while we
strive to protect your personal information, RxEOB cannot ensure or warrant the
security of any information you transmit to us or from our online products or
services, and you do so at your own risk. Once we receive your transmission, we
will make reasonable efforts to ensure its security on our systems.
Notification of Changes
If we decide to change our privacy
policy, we will refer to those changes on our Homepage prior to the change
becoming effective, so our users are always aware of what information we
collect, how we use it, and under what circumstances, if any, we disclose it.
If at any point we decide to make any material changes or use personal
information in a manner different from that stated at the time it was
collected, we will notify users by way of an email prior to the change becoming
effective and wait for your consent. As mentioned before, users will have the
choice as to whether or not we use their information in a different manner. We
will use information in accordance with the privacy policy under which the
information was collected.
We reserve the right to make changes
to this policy. Any changes to this policy will be posted.
Your Consent
By using our application, you consent
to the collection and use of the information as outlined above by RxEOB.
California Consumer Privacy Act
Notice
This Privacy Notice for California
Residents applies to individuals who live in the State of California and whose
data is subject to the California Consumer Privacy Act of 2018 (CCPA). Below
describes what information RxEOB collects that is subject to the CCPA, your
rights under the CCPA, and how you can enforce those rights under the CCPA. Any
terms defined in the CCPA have the same meaning when used here.
Information We Collect
We collect information that
identifies, relates to, describes, references, is capable of being associated
with, or could reasonably be linked, directly or indirectly, with a particular
consumer or device (“Personal Information”).
Personal Information does not
include:
• Publicly available information
lawfully made available from government records.
• Deidentified or aggregated consumer
information.
• Information excluded from the
CCPA’s scope, like:
o health or medical information covered by the Health Insurance
Portability and Accountability Act of 1996 (HIPAA) and the California
Confidentiality of Medical Information Act (CMIA) or clinical trial data
o personal information covered by certain sector-specific privacy
laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley
Act (GLBA) or California Financial Information Privacy Act (FIPA), and the
Driver’s Privacy Protection Act of 1994
If certain types of information are
exempt from CCPA, and therefore this policy, the RxEOB privacy policy will
apply.
RxEOB has collected the following
categories of Personal Information from its users within the last twelve (12)
months:
Category
|
Examples
|
Collected?
|
A.
Identifiers.
|
A
real name, alias, postal address, unique personal identifier, online
identifier, Internet Protocol address, email address, account name, Social
Security number, driver's license number, passport number, or other similar
identifiers.
|
YES
|
B.
Personal information categories listed in the California Customer Records
statute (Cal. Civ. Code § 1798.80(e)).
|
Information
that is protected against security breaches such as: name, signature, Social
Security number, physical characteristics or description, address, telephone
number, passport number, driver's license or state identification card
number, insurance policy number, education, employment, employment history,
bank account number, credit card number, debit card number, or any other
financial information, medical information, or health insurance information.
Some
personal information included in this category may overlap with other
categories and may not be subject to all the rights under the CCPA.
|
YES
|
C.
Protected classification characteristics under California or federal law.
|
Age
(40 years or older), race, color, ancestry, national origin, citizenship,
religion or creed, marital status, medical condition, physical or mental
disability, sex (including gender, gender identity, gender expression,
pregnancy or childbirth and related medical conditions), sexual orientation,
veteran or military status, genetic information (including familial genetic
information).
|
NO
|
D.
Commercial information.
|
Records
of personal property, products or services purchased, obtained, or
considered, or other purchasing or consuming histories or tendencies.
|
NO
|
E.
Biometric information.
|
Genetic,
physiological, behavioral, and biological characteristics, or activity
patterns used to extract a template or other identifier or identifying
information, such as, fingerprints, faceprints, and voiceprints, iris or
retina scans, keystroke, gait, or other physical patterns, and sleep, health,
or exercise data.
|
NO
|
F.
Internet or other similar network activity.
|
Browsing
history, search history, information on a consumer's interaction with a,
application, or advertisement.
|
YES
|
G.
Geolocation data.
|
Physical
location or movements.
|
YES
|
H.
Sensory data.
|
Audio,
electronic, visual, thermal, olfactory, or similar information.
|
NO
|
I.
Professional or employment-related information.
|
Current
or past job history or performance evaluations.
|
NO
|
We generally do not collect
additional categories of personal information or use the personal information
we collected for significantly different or meaningfully unrelated purposes
without providing you with notice.
Where We Obtain Personal Information
We obtain the categories of personal
information listed above from the following categories of sources:
• Directly from you or your devices.
For example, from forms you complete on our web application.
• Indirectly from you. For example,
from observing your actions on our application or interactions with our
advertisers.
• Business partners. For example,
pharmacy benefit managers or providers.
• Publicly accessible sources. For
example, National Provider Identifier.
Use of Personal Information
We may use, or disclose the personal
information we collect for one or more of the following business and commercial
purposes:
• Fulfilling or meeting the reason
you provided the information. For example, if you share personal information in
order to be a registered user of RxEOB applications, we will use that personal
information for the credentialing process.
• Providing you with information,
products, or services that you request from RxEOB.
• Providing you with text messages, email
alerts, and other notices concerning RxEOB’s services, or news that may be of
interest to you.
• Sending you text messages or push
notifications.
• Facilitating the connection of
third-party services or applications, such as social networks.
• Facilitating transactions and
payments.
• De-identifying and aggregating
information collected through our services and using it for any lawful
purpose.
• Responding to trust and safety
issues that may arise.
• Carrying out our obligations and
enforcing our rights arising from any contracts or other terms entered into
between you and RxEOB, including billing, or as may be required by applicable
laws and regulations or requested by any judicial process or governmental
agency.
• Auditing related to a current
interaction with you and concurrent transactions, including, but not limited
to, counting logons, clicks and impressions to unique visitors, and auditing
compliance with this specification and other standards.
• Personalizing your experience of
our services, such as presenting tailored content.
• Undertaking activities to verify or
maintain the quality or safety of our services, and to improve, upgrade, or
enhance our services.
• For testing, research, analysis,
and product development, including the development of data models and
algorithms, and for demonstration purposes.
• Detecting security incidents,
protecting against malicious, deceptive, fraudulent, or illegal activity, and
prosecuting those responsible for that activity.
• Debugging to identify and repair
errors that impair existing intended functionality.
• Short-term, transient use.
• For other purposes for which we
provide specific notice at the time the information is collected.
• To respond to law enforcement
requests and as required by applicable law, court order, or governmental
regulations.
• As described to you when collecting
your personal information or as otherwise set forth in the CCPA.
Sharing Personal Information
RxEOB may disclose your personal
information to a third party for a business or commercial purpose. When we
disclose personal information for a business purpose, we enter into a contract
that describes the purpose and requires the recipient to both keep that
personal information confidential and not use it for any purpose except
performing the contract.
In the preceding twelve (12) months,
RxEOB has disclosed the following categories of personal information for a
business purpose:
Category A: Identifiers
Category B: California Customer
Records
Category F: Internet history
In the preceding twelve (12) months,
RxEOB has not disclosed personal information for commercial purposes. However,
for California residents, the California Consumer Privacy Act (CCPA) defines
“selling” personal information to include providing it to a third party in
exchange for money or valuable services.
Pursuant to our Privacy Policy we
share your information with the following categories of third parties for a
commercial purpose:
• Integrated Third Parties: Third
parties integrated into our services.
• Third Parties as Legally Required:
Third parties as required by law and similar disclosures.
• Third Parties in
Merger/Acquisition: Third parties in connection with a merger, sale, or asset
transfer.
• Third Parties with Consent: Other
third parties for whom we have obtained your permission to disclose your
Personal Information.
For avoidance of doubt, we do not
sell health information subject to HIPAA without your express authorization. If
you give us such an authorization, you may revoke it in writing at any time.
Your revocation will not affect any use or disclosure permitted by your
authorization while it was in effect.
Your Rights and Choices
The CCPA provides California
residents with specific rights regarding their personal information. This
section describes your CCPA rights and explains how to exercise those
rights.
Right
|
To Exercise This Right
|
Time Frame and Response from RxEOB
|
If We cannot complete your request
|
Access to specific information and the categories of
sources and purposes for collection, use, disclosure, and sale in the last 12
months, after verification of your identity.
|
Submit request and confirm your "verifiable
consumer request" via the contact information below.
|
We will evaluate and respond to your request
electronically or by mail (at your request) within 45 days. If we require
more time, we will inform you of the reason and extension period in writing.
|
We will explain the reasons we cannot comply with a
request in our response.
|
Deletion of information.
You have the right to request that RxEOB delete your
personal information, subject to certain exceptions and after verification of
your identity.
|
Submit request and confirm your "verifiable
consumer request" via the contact information below.
|
We will evaluate and respond to your request
electronically or by mail (at your request) within 45 days. If we require
more time, we will inform you of the reason and extension period in writing.
Once we confirm your verifiable consumer request, we
will delete (and direct our service providers to delete) your personal
information from our
records, unless an exception applies.
|
We will explain the reasons we cannot comply with a
request in our response.
The law does not require us to honor requests to
delete where it is necessary in certain circumstances for us or service
provider to maintain personal information. These include:
- Provide a good or service, perform our
contract or take action reasonably anticipated in the context of our ongoing
relationship with you.
- Detect and protect against malicious, deceptive,
fraudulent, or illegal activity, or prosecute those responsible for such
activities.
- Debug products to identify and repair errors that
impair existing intended functionality.
- Exercise and/or support free speech provided for
by law.
- Comply with the California Electronic
Communications Privacy Act (Cal. Penal Code § 1546 et seq.).
- Use internally for purposes aligned with
your expectations and our relationship.
- Comply with a legal obligation or make other
lawful use compatible with the context in which information was provided.
|
Opt out of the "sale" of personal
information in some circumstances. (Note: RxEOB does not sell personal
information)
|
Submit request and confirm your "verifiable
consumer request" via the contact information below.
|
We will evaluate and respond to your request
electronically or by mail (at your request) within 45 days. If we require
more time, we will inform you of the reason and extension period in writing.
|
We will explain the reasons we cannot comply with a
request in our response.
|
"Verifiable Consumer
Request”
To exercise your rights to access or
delete your personal information under the CCPA, you must submit a “verifiable
consumer request.” Only you, or a person registered with the California
Secretary of State that you authorize to act on your behalf, may make a
verifiable consumer request related to your personal information. You may also
make a verifiable consumer request on behalf of your minor child.
A verifiable consumer request
must:
• Provide sufficient information that
allows us to reasonably verify whether you are the person about whom we
collected personal information or an authorized representative.
• Describe your request with
sufficient detail that allows us to properly understand, evaluate, and respond
to it.
If we cannot verify your identity or
authority to make the request, we will not be able to fulfill your request. The
information provided for verification will only be used for that purpose.
If you would like to make a request, please Click Here and fill out the form on the
following page.
Authorizing an Agent
To authorize an agent to make a
request to know or delete on your behalf, please write to the contact address
below in the Privacy Contact Information section. To authorize an agent to make
an opt-out request on your behalf, please send a written authorization signed
by you and the authorized agent to us via the Contact Information
section.
Processing Fees
We do not charge a fee to process or
respond to your verifiable consumer request unless it is excessive, repetitive,
or manifestly unfounded. If we determine that the request warrants a fee, we
will tell you why we made that decision and provide you with a cost estimate
before completing your request.
Personal Information Sales Opt-Out
and Opt-In Rights
RxEOB does not sell your personal
information. If this should change in the future, you will be notified
and have the option to opt-in if you so desire by the process as defined in
such notification.
Non-Discrimination
We will not discriminate against you
for exercising any of your CCPA rights. Unless permitted by the CCPA, we will
not:
• Deny you goods or services.
• Charge you different prices or
rates for goods or services, including through granting discounts or other
benefits, or imposing penalties.
• Provide you with a different level
or quality of goods or services.
• Suggest that you may receive a
different price or rate for goods or services or a different level or quality
of goods or services.
We may offer you certain financial
incentives such as discounted prices, rates, or quality levels. Any permitted
financial incentive we offer will reasonably relate to your personal
information’s value and contain written terms that describe the program’s
material aspects. Participation in a financial incentive program requires your
prior opt in consent, which you may revoke at any time.
“Shine the Light”
California’s “Shine the Light” law
(Civil Code Section § 1798.83) permits users of our application that are
California residents to request certain information regarding our disclosure of
personal information to third parties for their direct marketing purposes. To
make such a request, please send us an electronic message through our application
or write to us at our address listed below.
Changes to Our Privacy Notice
We reserve the right to amend this
privacy notice at our discretion and at any time. When we make changes to this
privacy notice, we will post the updated notice on the application and update
the notice’s effective date. Your continued use of our application following
the posting of changes constitutes your acceptance of such changes.
Privacy Contact Information
If you have any questions, concerns,
or comments about our privacy policy you may contact our designated Privacy
Officer using the information below:
Robert S. Oscar, Privacy Officer
secops@rxeob.com
804-643-1540
RxEOB
2810 N. Parham Road, Suite 245
Henrico, VA 23294