Privacy Policy
Last updated: September 15th, 2021
K Fortressa, LLC dba Key Med Staff (“We” or “us” or “our”) respects your right to privacy. This Privacy Policy explains who we are, how we collect, share and use information about you and how you can exercise your privacy rights.
Our Privacy Policy applies to all users of our website and services (depending on your use, the “Website” and/or the “Service”).
What Do We Do?
If you have any questions or concerns about our use of your information, then please contact us.
We are a consulting and staffing firm for medical companies for peer review work as well as providing highly qualified staff for medical surgical units and ultrasound and vascular laboratory technicians.
HIPAA Compliance
Certain health and medical information about you is protected under the Health Insurance Portability and Accountability Act (“HIPAA”) and applicable state law. This information may be provided by you online or offline, or may be collected by us from other methods such as through a health care provider. We protect covered health and medical information as we may be required by HIPAA and applicable state law. Similarly, we may use covered health and medical information as permitted by HIPAA and applicable state law.
To read more about our privacy practices regarding health and medical information under HIPAA, please read below.
As we do not control third party websites to which we provide links, the collection and use of your personally identifiable information by such websites shall be subject to the policies and procedures of those third party websites
We do not sell, rent, release or trade personal customer information to outside parties. We reserve the right to disclose information if necessary to comply with any legal proceedings.
We do not sell or distribute healthcare information, but may utilize anonymously submitted health data you give voluntarily for surveys, research projects or data collection.
Our web site may use “cookies” to store information about a visit to its web site. Cookies are text files stored on your computer which can retain small pieces of information between visits to the
web site. This way, your personal preferences may be retained between visits. Most web browser software can be configured to refuse cookies or to notify you when a web site attempts to send you a cookie.
Notice of HIPAA Privacy Practices
THIS NOTICE DESCRIBES HOW CERTAIN MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. To the extent we request and obtain any personal healthcare information (“PHI”) about your medical history and current health that may be protected under the Health Insurance Portability and Accountability Act (“HIPAA”) and applicable state law, this Notice of Privacy Practices explains how that information may be used and shared with others. It also explains your privacy rights regarding this information.
Under HIPAA, certain parties that obtain PHI entities are required by law to abide by the terms of this Notice, to make sure that information that identifies you is kept private, and to provide this Notice of our legal duties and practices with respect to PHI about you. We are also required to notify you in the event there is a breach of your health information.
We may use or disclose your health information:
- When required by federal, state, or local law.
- To cooperate with law enforcement officials for certain law enforcement purposes as directed by a court order, warrant, criminal subpoena, or other lawful process.
- To report abuse or neglect.
- To support health oversight activities that are authorized by law, such as administrative or criminal investigations, inspections, licensure or disciplinary actions and other similar activities necessary for appropriate oversight of government benefit programs or functions.
- When required by a coroner or medical examiner for the purpose of identifying a deceased person, determining a cause of death or other duties as required by law.
- When necessary to prevent or lessen a serious and imminent threat to the health and safety of a person or the public and the disclosure is to a person reasonably able to prevent or lessen the threat, as consistent with applicable law and standards.
- For judicial or administrative proceedings, in response to a valid court order, administrative order, a grand jury subpoena, or with your written consent.
- For research purposes, with your written authorization or as permitted by law. Information Collected
We collect information about users of our Website
Such information is collected from the following sources:
Information We Collect Directly from You: The type of information that we collect directly from you varies based on your interaction with our Website and our Service. We collect information directly from you when you register an account with us, communicate with us on a customer service issue, or use the features of Website in any other way.
We also collect information that you send us via any medium, including, but not limited to email and telephone. In addition, we collect information about you from your social media interactions on third party social media properties, such as your social media handle, username, profile, postings, and messages you exchange with other users.
We collect the following: first name, last name, profile picture, phone number, email address, postal zip code, website, credit card information, profession, licensing information, type of specialty, academic and educational background.
Information Collected Automatically
When you use our Website or use our Service, we may collect certain information automatically from your device.
Specifically, the information we collect automatically may include information like your IP address, device type, unique device identification numbers, browser-type, broad geographic location (e.g. country or city-level location), third party webpages accessed via the Service and other technical information. We may also collect information about how your device has interacted with our Website (including the pages accessed and links clicked) or Service (including content accessed).
Collecting this information enables us to better understand the users of our Website, where they come from, and what content and functionality is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our Website.
Information from Other Sources
We may also collect information from other sources. The following are the categories of sources we collect information from:
Data brokers or resellers from which we purchase data to verify and supplement the data we collect.
Social networks when you engage with our content, reference our Website or Service, or grant us permission to access information from the social networks.
Partners that offer co-branded services, sell or distribute our products, or engage in joint marketing activities.
Use of Information
We process information for business and commercial purposes in accordance with the practices described in this Privacy Policy. Our business purposes for collecting and using information may include the following:
Operate and improve the Website;
Provide users with the Service and other products and services that a user may request or that a user has expressed interest in;
Evaluate user interest and needs in order to improve the Service and make available other offers, products or services;
Evaluate the types of offers, products or services we make available to users and potential users or customers;
Monitor use of the Service;
Provide customer support;
Communicate and provide additional information that may be of interest to users through email or other means, such as special offers, announcements, and marketing materials;
Send you reminders, technical notices, updates, product announcements, security alerts and support and administrative messages, service bulletins, or marketing;
Provide advertisements to you through messages;
Manage our everyday business needs;
Fulfill any other business or commercial purposes at your direction or with your notice and/or consent.
Notwithstanding the above, we may use information that does not identify you (including information that has been aggregated or de-identified) for any purpose except as prohibited by applicable law. For information on your rights and choices regarding how we use information about you, please see “Your Data Protection Rights” below.
To Whom We May Share Your Information
We share information we collect in accordance with the practices described in this Privacy Policy. We will not share personally identifiable information with any third party, but we may share aggregate data about Users as a whole.
The following are the categories of recipients:
to our affiliates, service providers and partners who provide data processing services to us (for example, to support the delivery of, provide functionality on, or help to enhance the security of our Website or Service), or who otherwise process information for purposes that are described in this Privacy Policy or for which we provide you notice when we collect your information. We share information with our affiliates for business and commercial purposes. We prohibit our service providers from retaining, using, or disclosing information about you for any purpose other than performing the services for us, although we may permit them to use information that does not identify you (including information that has been aggregated or de-identified) for any purpose except as prohibited by applicable law.
to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or court order or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person;
to a potential buyer (and its agents, investors, and/or advisors) in connection with any proposed or actual purchase, merger or acquisition of any part of our business, provided that we inform the buyer it must use your information only for the purposes disclosed in this Privacy Policy;
to vendors for business and commercial purposes;
to any other person with notice to you and your consent to the disclosure;
when you make information public through the Website or Service, such as information in your profile or that you post or comment on public boards. Please think carefully before making information public as you are solely responsible for any information you make public. Once you have posted information, you may not be able to edit or delete such information, subject to additional rights set out in the “Your Data Protection Rights” section below; and
when you request or direct us to share information, such as when you choose to share information with a social network or other third party platform about your activities on the Service, which may require you to accept such third party’s terms of use or privacy policy.
Notwithstanding the above, we may share information that does not identify you (including information that has been aggregated or de-identified) except as prohibited by Applicable law. For information on your rights and choices regarding how we share information about you, please see the “Your Data Protection Rights” section below.
In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Social Media and Technology Integrations
Links. Our Website and Service may include links that hyperlink to websites, platforms, and other services not operated or controlled by us.
Brand Pages and Chatbots. We may offer our content through social media. Any information you provide to us when you engage with our content (such as through our brand page or via our chatbot on the Website or Service) is treated in accordance with this Privacy Policy. Also, if you publicly reference our Service on social media (e.g., by using a hashtag associated with us in a tweet or post), we may use your reference on or in connection with our Website or Service.
Please note that when you interact with other entities, including when you leave our Website, those entities may independently collect information about you and solicit information from you. The information collected and stored by those entities remains subject to their own policies, terms, and practices, including what information they share with us, your rights and choices on their services and devices, and whether they store information in the U.S. or elsewhere. We encourage you to familiarize yourself with and consult their privacy policies and terms of use.
Your Data Protection Rights
You have the following data protection rights:
If you wish to access, correct, update or request deletion of your information, you can do so at any time by contacting us.
Note that if you submit a request to delete your information, this may prohibit you from using the Website and/or Service.
You have the right to opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing emails we send you. To opt-out of other forms of marketing (such as postal marketing or telemarketing), then please contact us. Please note that your opt out is limited to the email address, device, and phone number used and will not affect subsequent subscriptions.
Similarly, if we have collected and processed your information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your information conducted in reliance on lawful processing grounds other than consent.
You have the right to complain to a data protection authority about our collection and use of your information. For more information, please contact your local data protection authority.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with Applicable data protection laws. Where we process your information solely on behalf of a customer, we may be legally required to forward your request directly to our customer and/or social media business partners for their review / handling.
Security & User ID/Password
Our Website and/or Service may implement and maintain various reasonable and appropriate administrative, physical, and technical security safeguards to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. These security safeguards include, but are not limited to, network and host security controls (e.g., firewalls, intrusion detection systems, etc.), data encryption (both at rest and during transmission), and operating procedures that are designed to protect your information. You should protect your user ID and password and NOT share it with anyone. Additionally, enabling two-step verification or SSO integration, where available, is also recommended. If you believe your user ID and password have been compromised or you have trouble changing your user ID/password on the Website or Service, please contact our technical support department. Nevertheless, transmission via the internet is not completely secure and we cannot guarantee the security of information about you.
Data retention
We retain information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements).
When we have no ongoing legitimate business need to process your information, we will either delete or anonymize it in accordance with our data retention policy, or, in the limited circumstances where this is not possible (for example, because your information has been stored in backup archives), then we will securely store your information and isolate it from any further processing until deletion is possible.
CAN-SPAM Compliance Notice
We may send periodic promotional or informational emails to you. You may opt-out of such communications by following the unsubscribe or opt-out instructions contained in the email. Please note that it may take up to 10 business days for us to process opt-out requests. If you opt out of receiving emails about recommendations or other information we think may interest you, we may still send you emails about your account or any Service you have requested or received from us.
Children
This Website is intended for a general audience, and is not directed at persons under eighteen (18) years of age. Children under 18 years of age are not allowed to use this Website.
Updates to this Privacy Policy
We may update this Privacy Policy from time to time in response to changing legal, technical or business developments. When we update our Privacy Policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Policy changes if and where this is required by Applicable data protection laws.
You can see when this Privacy Policy was last updated by checking the “last updated” date displayed at the top of this Privacy Policy.
How to Contact Us
If you have any questions or concerns about our use of your information, please contact us using the following details: info@keymedstaff.com.
If you have a disability and would like to access this Privacy Policy in an alternative format, please contact us at info@keymedstaff.com.
Additional Disclosures for California Residents
These additional disclosures for California residents apply only to individuals who reside in California. The California Consumer Privacy Act of 2018 (“CCPA”) provides additional rights to know, delete and opt out, and requires businesses collecting or disclosing personal information to provide notices and means to exercise rights.
Notice of Collection.
In the past 12 months, we have collected the following categories of personal information enumerated in the CCPA:
Identifiers, including name, email address, phone number account name, IP address, and an ID or number assigned to your account.
Commercial information, including purchases and engagement with the Service. Audio or visual data, including pictures or videos you post on our Service. Inferences, including information about your interests, preferences and favorites.
For more information on information we collect, including the sources we receive information from, review the Information Collected and Information Collected Automatically sections. We
collect and use these categories of personal information for the business purposes described in the Use of Information section, including to provide and manage our Service.
We do not generally sell information as the term “sell” is traditionally understood. However, to the extent “sale” under the CCPA is interpreted to include advertising technology activities such as those disclosed in the Cookies, similar tracking technology, and analytics section as a “sale,” we will comply with Applicable law as to such activity. We disclose the following categories of
personal information for commercial purposes: identifiers, demographic information, commercial information, internet activity, geolocation data and inferences. We use and partner with different types of entities to assist with our daily operations and manage our Service. Please review the To Whom We Share Your Information section for more detail about the parties we have shared information with.
Right to Know and Delete
Consumers who are California residents (and not representatives of businesses, whether those businesses are our customers or others) have the right to delete the personal information we have collected from you and the right to know certain information about our data practices in the preceding 12 months. In particular, you have the right to request the following from us:
The categories of personal information we have collected about you;
The categories of sources from which the personal information was collected; The categories of personal information about you we disclosed for a business purpose or sold;
The categories of third parties to whom the personal information was disclosed for a business purpose or sold;
The business or commercial purpose for collecting or selling the personal information; and The specific pieces of personal information we have collected about you.
To exercise any of these rights, please email us at info@keymedstaff.com.
If personal information about you has been processed by us as a service provider on behalf of a customer and you wish to exercise any rights you have with such personal information, please inquire with our customer directly. If you wish to make your request directly to us, please provide the name of our customer on whose behalf we processed your personal information. We will refer your request to that customer, and will support them to the extent required by Applicable law in responding to your request.
Right to Opt-Out
To the extent we sell your personal information as the term “sell” is defined under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information by us to third parties at any time. You may submit a request to opt-out by clicking Do Not Sell My
Personal Information. You may also submit a request to opt-out by emailing us at info@keymedstaff.com.
Authorized Agent
You can designate an authorized agent to submit requests on your behalf. However, we will require written proof of the agent’s permission to do so and verify your identity directly.
Right to Non-Discrimination
You have the right not to receive discriminatory treatment by us for the exercise of any of your rights.
California Shine the Light Law
Pursuant to Section 1798.83 of the California Civil Code, residents of California can obtain certain information about the types of personal information that companies with whom they have an established business relationship have shared with third parties for direct marketing purposes during the preceding calendar year. In particular, the law provides that companies must inform consumers about the categories of personal information that have been shared with third parties, the names and addresses of those third parties, and examples of the types of services or products marketed by those third parties. To request a copy of the information disclosure provided by us pursuant to Section 1798.83 of the California Civil Code, please contact us via email at info@keymedstaff.com.
GDPR Privacy Notice
This notice is for people who are located in the European Economic Area (“EEA”). Our processing of personal data of people who are in the EEA is governed by the General Data Protection Regulation (the “GDPR”), which applies from May 25, 2018. The GDPR requires us to provide certain information to you about your personal data, which we refer to in this notice as your personal information.
Data Controller
We are the data controller for the Services. For our contact information, see the section headed “How to Contact Us”.
Purposes of the Processing
Personal information gathered through cookies is used for the purposes described in this Privacy Policy. Other than information described in our Privacy Policy, the only information collected
through our website is personal information provided voluntarily by visitors for the purpose of receiving additional information about the Services or registering for our Services.
Lawful Basis for the Processing
Generally, we process personal information provided by visitors through our website on the basis of consent.
We may also process personal information on other bases permitted by the GDPR and applicable laws, such as when the processing is necessary for us to comply with our legal obligations.
Categories of Personal Information
We process the following information when provided voluntarily by our website visitors: name, email address (business e-mail address preferred), postal address and/or country, profession, profile picture, licensing information, website, and telephone number (again, business number preferred).
Recipients of Your Personal Information
We use various service providers to manage our website and provide services. Our service providers change from time to time. Note that our service providers have entered into contracts with us that restrict what they can do with your personal information. If you would like specific information about our service providers who have received your information, please contact us and we will provide that information to you.
Information Regarding the Transfers of Personal Data Outside of the European Economic Area (EEA)
Our main offices are based in the USA and that’s where we process personal information collected through our website. When you provide personal information to us, we request your consent to transfer that personal information to the USA. The USA does not have an adequacy decision from the European Commission, which means that the Commission has not determined that the laws of the USA provide adequate protection for personal information. Although the laws of the USA do not provide legal protection that is equivalent to EU data protection laws, we safeguard your personal information by treating it in accordance with this GDPR Privacy Notice. We take appropriate steps to protect your privacy and implement reasonable security measures to protect your personal information in storage. We use secure transmission methods to collect personal data through our website. We also enter into contracts with our data processors that require them to treat personal information in a manner that is consistent with this Notice.
Retention Period for Personal Information
How long we retain personal information varies according to the type of information in question and the purpose for which it is used. We delete personal information within a reasonable period
after we no longer need to use it for the purpose for which it was collected (or for any subsequent purpose that is compatible with the original purpose). This does not affect your right to request that we delete your personal data before the end of its retention period. We may archive personal data (which means storing it in inactive files) for a certain period prior to its final deletion, as part of our ordinary business continuity procedures.
Your Rights to Access, Correct, Restrict or Delete Your Personal Data and Object To Processing
You have the right to request access to your personal data, to have your personal data corrected, restricted or deleted, and to object to our processing of your personal data. You also have the right of data portability, which means that you can request that we provide you (or a third party you designate) with a transferable copy of personal information that you have provided to us. Your rights may be subject to various limitations under the GDPR. If you wish to exercise any of these rights, or if you have any concerns about our processing of your personal data, please contact us.
The Right to Lodge A Complaint With a Supervisory Authority
You have the right to file a complaint concerning our processing of your personal data with your national (or in some countries, regional) data protection authority. The EU Commission has a list here: http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm
Absence of statutory or contractual requirement or other obligation to provide any personal data
Users of our website are under no statutory or contractual requirement or other obligation to provide personal information to us via our website.
How to Contact us
If you have questions about this Privacy Policy please contact us at info@keymedstaff.com.