top of page

Privacy Policy

ChinaCureLink, a Medebound HEALTH company, respects the privacy of the individuals about whom we receive information, and we treat that information as strictly confidential. In this privacy policy we explain what personal data we collect, for what purposes and on what basis. This is done by looking at the different situations in which we process personal data. We may update this policy from time to time and thus recommend that you read this policy regularly.

 

This privacy policy applies to our website (www.chinacurelink.com) and the services we provide through our website.

 

Personal data

In order to provide our website and services, we process personal data. Personal data is data that can be used to reveal your identity, such as: Name, address and email address.

 

Who is responsible for processing your personal data?

The controller for all processing of personal data listed below is Medebound HEALTH of 260 Madison Ave 8th Floor #8001 New York, NY 10016 ("Medebound HEALTH", "we", "our" or "us")

 

Our data protection principles

We handle the data transferred to us in a trusting and responsible manner and observe the legal provisions on data protection, in particular the NY Privacy Act (NYPA), the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA).

 

  • Personal data is only collected by us if and to the extent that you yourself provide it to us with your knowledge.

  • We do not sell, lend or give away your personal data. We only pass on your data to third parties without your consent if we are legally entitled to do so, e.g., in the event of a corresponding court order.

  • We use state-of-the-art security technologies to protect your data from misuse.

  • We want to provide you with a safe, smooth, efficient and personal user experience.

 

Security measures

We take appropriate technical and organizational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.

 

The measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input of, disclosure of, assurance of availability of and segregation of the data. We also have procedures in place to ensure the exercise of data subjects' rights, the deletion of data and responses to data compromise. Furthermore, we already take the protection of personal data into account in the development or selection of hardware, software and procedures in accordance with the principle of data protection, through technology design and through data protection-friendly default settings.

 

SSL encryption (https)

In order to protect your data transmitted via our website, we use SSL encryption. You can recognize such encrypted connections by the prefix https:// in the address line of your browser.

 

Relevant legal basis

In the following, we share the legal bases of the General Data Protection Regulation (GDPR) on the basis of which we process personal data. Please note that in addition to the regulations of the GDPR, the national data protection regulations in your or our country of residence and domicile may apply. Furthermore, should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.

 

  • Consent (Art. 6 para. 1 p. 1 lit. a GDPR) - The data subject has given his/her consent to the processing of personal data relating to him/her for a specific purpose or purposes.

 

  • Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b. GDPR) - Processing is necessary for the performance of a contract to which the data subject is a party or for the performance of pre-contractual measures carried out at the data subject's request.

 

  • Legal obligation (Art. 6 para. 1 p. 1 lit. c. GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.

 

  • Protection of vital interests (Art. 6 para. 1 p. 1 lit. d. GDPR) - Processing is necessary in order to protect the vital interests of the data subject or of another natural person.

 

  • Legitimate interests (Art. 6 para. 1 p. 1 lit. f. GDPR) - Processing is necessary to protect the legitimate interests of the controller or a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.

 

Your Rights

 

GDPR Specific Rights

Under the GDPR you have a number of “Data Subject Rights” in particular you have the right to:

 

  • information about the processing of your personal data;

  • obtain access to the personal data held about you;

  • ask for incorrect, inaccurate or incomplete personal data to be corrected;

  • request that personal data be erased when it’s no longer needed or if processing it is unlawful;

  • object to the processing of your personal data for marketing purposes or on grounds relating to your particular situation;

  • request the restriction of the processing of your personal data in specific cases;

  • receive your personal data in a machine-readable format and send it to another controller (‘data portability’);

  • request that decisions based on automated processing concerning you or significantly affecting you and based on your personal data are made by natural persons, not only by computers. You also have the right in this case to express your point of view and to contest the decision; and

  • Where the processing of your personal information is based on consent, you have the right to withdraw that consent without detriment at any time through our contact form.

 

New York Specific Rights

According to the NY Privacy Act, you have the right to:

 

  • Confirmation whether your personal data is being processed by us;

  • Correct inaccuracies in your data;

  • Delete personal data obtained from or about you;

  • Obtain a copy of the data you previously provided us in a portable and “readily usable” format; and

  • Opt-out of data collection if the data is collected “for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning on you.

 

Your HIPAA Rights

When it comes to your health information, you have additional rights, in particular:

 

  • You can ask to see or get an electronic or paper copy of your medical record and other health information we have about you.

  • You can ask us to correct health information about you that you think is incorrect or incomplete.

  • You can ask us to contact you in a specific way (for example, home or office phone) or at a specific location (for example, to send mail to a different address).

  • You can tell us your choices about what we share.

  • You can ask us to limit what we use or share

  • You can get a list of those with whom we have shared information

  • You can get a copy of this Notice

  • You can choose someone to act for you

  • You can file a complaint if you feel your rights are violated

 

If you wish to rely on any of your data subject rights or have a request, please contact us.

 

Why do we process personal data?

If you fill out a form on our website, contact us by e-mail or via the contact form on the website, the data you provide (your e-mail address, name and telephone number, if applicable) will be stored by us in order to process your request, inform you about our services and/or answer your questions. The legal basis for processing the data is our legitimate interest in responding to your request in accordance with Art. 6 (1) f GDPR. If your contact aims at the conclusion of a contract, the additional legal basis for the processing is Art. 6 (1) lit. b GDPR.

 

If you provide us with personal data via a user account. We delete the data accruing in this context after storage is no longer necessary unless there is a legal obligation to retain the data.

 

In the following, we inform you in detail about the processes of individual functions offered by us, for which we make use of commissioned service providers. In doing so, we also state the defined criteria for the storage period.

 

Website

In the case of purely informational use of the website, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure its stability and security (legal basis is Art. 6 para. 1 p. 1 lit. f GDPR):

 

  • IP address (anonymised)

  • Date and time of the request

  • Access status/HTTP status code

  • Amount of data transmitted in each case

  • Website from which the request comes

  • Browser

  • Language and version of the browser software.

 

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended.

 

In the case of storage of data in log files, this is the case after seven days at the latest. Storage beyond this period is possible. In this case, the IP addresses of the users are deleted or alienated so that an assignment of the calling client is no longer possible.

 

Cookies

In addition to the data mentioned above, cookies are stored on your device when you use our website. Cookies are small text files that your computer, smartphone or tablet stores when you visit our website.

 

We use cookies to provide you with a well-functioning website that makes your browsing experience more pleasant and prevents you from receiving or having to enter the same information each time you visit. Cookies also allow us to see how the website is used and how we can improve it further.

 

In our Cookie Policy we explain which cookies we use and how you can change your choices.

 

Contact us

If you send us inquiries, your data from the inquiry, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not pass on this data without your consent. The processing of the data entered in the contact form is therefore based exclusively on your consent. You can revoke this consent at any time. For this purpose, an informal communication by e-mail to us is sufficient. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation. The data you entered in the contact form will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g., after we have completed processing your request). Mandatory legal provisions - in particular retention periods - remain unaffected.

 

User account

As a user, you can open a user account. When you open an account, you consent to the storage of your inventory data (name, e-mail address) and your usage data (username, password). This allows us to identify you as a customer and gives you the opportunity to manage your account. Your data is processed on the basis of the contracts concluded with you (legal basis is Art. 6 para. 1 p. 1 lit. b GDPR).

 

Social Media Log-In and Sign Up

You may also Log-In and/or Sign Up using social log in from Facebook or Google. Using those however, is subject to the relevant providers privacy obligations. The legal basis for the storage is Article 6 lit. f) GDPR.

 

Care and business services

We process data of our contractual and business partners, e.g. customers and interested parties (collectively referred to as "contractual partners") in the context of contractual and comparable legal relationships as well as related measures and in the context of communication with contractual partners (or pre-contractual), e.g. to answer inquiries.

 

We process this data to fulfill our contractual obligations, to secure our rights and for the purposes of the administrative tasks associated with this information as well as for business organization. Within the framework of applicable law, we only disclose the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or for the fulfillment of legal obligations or with the consent of the persons concerned (e.g., to participating telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisers, payment service providers or tax authorities). Contractual partners will be informed about other forms of processing, e.g., for marketing purposes, within the framework of this privacy policy.

 

We inform the contractual partners which data is required for the aforementioned purposes before or in the course of data collection, e.g., in online forms, by means of special labeling (e.g., colors) or symbols (e.g., asterisks or similar), or in person.

 

We delete the data after the expiry of legal warranty and comparable obligations, i.e., generally after 4 years, unless the data is stored in a customer account, e.g., as long as it must be kept for legal archiving reasons (e.g. for tax purposes generally 10 years). We delete data disclosed to us by the contractual partner within the scope of an order in accordance with the specifications of the order, generally after the end of the order.

 

If we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms apply in the relationship between the users and the providers.

 

As a Physician, you have access to various applications with which you can process health data of your patients. The health data may be processed on the basis of the treatment contract existing between you as a practitioner and your patient, provided that this data is processed by you or under your responsibility as a healthcare professional and you are subject to professional secrecy in accordance with national law or the regulations of national competent bodies, as set out in Art. 9 (3) of the GDPR. The processing carried out by you is necessary for the provision of healthcare or treatment and medical diagnostics within the meaning of Art. 9(2)(h) of the GDPR. We will enter into a data processing agreement with you which will specify how the data processed by you or under your supervision will be processed. In all cases, you remain the controller. We are considered a processor and follow your instructions taking into account what is specified in the data processing agreement.

 

As a patient, your data will be processed within Medebound HEALTH on the basis of the treatment contract between you and your practitioner. We only process the data on behalf of your practitioner as they are the data controller by law. To enable this processing, your practitioner enters into a data processing agreement with us. This agreement specifies how this data will be handled. For example, we cannot access or process your data without your practitioner's permission, and we are bound by confidentiality obligations. We will not process or store your personal data for longer than the end of the data processing agreement between your practitioner and Medebound HEALTH. Upon termination of this agreement, your data will be removed from our system.

 

When you send a data subject access request

The legal basis for the processing of your personal data in the context of handling your data subject access request is our legal obligation and the legal basis for the subsequent documentation of t data subject access request is both our legitimate interest and our legal obligation.

 

The purpose of processing your personal data in the context of processing data when you send a data subject access request is to respond to your request. The subsequent documentation of the data subject access request serves to fulfill the legally required accountability.

 

Your personal data will be deleted as soon as they are no longer required to achieve the purpose for which they were collected. In the case of the processing of a data subject access request, this is three years after the end of the respective process.

 

You have the possibility at any time to object to the processing of your personal data in the context of the processing of a data subject access request for the future. In this case, however, we will not be able to further process your request. The documentation of the legally compliant processing of the respective data subject access request is mandatory. Consequently, there is no possibility for you to object.

 

Legal defense and enforcement of our rights

The legal basis for the processing of your personal data in the context of legal defense and enforcement of our rights is our legitimate interest.

 

The purpose of processing your personal data in the context of legal defense and enforcement of our rights is the defense against unjustified claims and the legal enforcement and assertion of claims and rights. Your personal data will be deleted as soon as they are no longer necessary to achieve the purpose for which they were collected.

 

The processing of your personal data in the context of legal defense and enforcement is mandatory for legal defense and enforcement of our rights. Consequently, there is no possibility for you to object.

 

Newsletters and electronic notifications

We send newsletters, e-mails and other electronic notifications (hereinafter "newsletters") only with the consent of the recipients or a legal permission. If the contents of the Newsletter are specifically described in the context of a registration, they are decisive for the consent of the users. In addition, our newsletters contain information about our services and us.

 

In order to subscribe to our newsletters, it is generally sufficient to provide your e-mail address. However, we may ask you to provide a name, for the purpose of personal address in the newsletter, or further details, if these are necessary for the purposes of the newsletter.

 

The logging of the registration process takes place on the basis of our legitimate interests for the purpose of proving its proper course. If we commission a service provider to send e-mails, this is done on the basis of our legitimate interests in an efficient and secure sending system.

 

The newsletter is sent on the basis of the recipients' consent or, if consent is not required, on the basis of our legitimate interests in direct marketing, if and to the extent that this is permitted by law, e.g., in the case of advertising to existing customers. Insofar as we commission a service provider to send e-mails, this is done on the basis of our legitimate interests. The registration process is recorded on the basis of our legitimate interests to demonstrate that it has been carried out in accordance with the law.

 

NY Privacy Act (NYPA) (PII) Statement

Commercial Partners: Individual(s) or companies that have been approved by us as a recipient of organizational PII and from which Medebound HEALTH has received confirmation of their data protection practices conformance with the requirements of this policy. Commercial Partners include all external providers of services to Medebound HEALTH and include proposed Commercial Partners. No PII information can be transmitted to any vendor in any method unless the vendor has been pre-certified for the receipt of such information.

 

PII Training: All new hires entering Medebound HEALTH who may have access to PII are provided with introductory training regarding the provisions of this policy, a copy of this policy and implementing procedures for the department to which they are assigned. Employees in positions with regular ongoing access to PII or those transferred into such positions are provided with training reinforcing this policy and procedures for the maintenance of PII data and shall receive annual training regarding the security and protection of PII data and company proprietary data

 

PII Audit(s): Medebound HEALTH conducts audits of PII information maintained by Medebound HEALTH in conjunction with fiscal year closing activities to ensure that this policy remains strictly enforced and to ascertain the necessity for the continued retention of PII information. Where the need no longer exists, PII information will be destroyed in accordance with protocols for destruction of such records and logs maintained for the dates of destruction.

 

Data Breaches/Notification: Databases or data sets that include PII may be breached inadvertently or through wrongful intrusion. Upon becoming aware of a data breach, Medebound HEALTH will notify all affected individuals whose PII data may have been compromised, and the notice will be accompanied by a description of action being taken to reconcile any damage as a result of the data breach. Notices will be provided as expeditiously as possible after the breach was discovered.

 

Confirmation of Confidentiality: All company employees must maintain the confidentiality of PII as well as company proprietary data to which they may have access and understand that that such PII is to be restricted to only those with a business need to know. Employees with ongoing access to such data will sign acknowledgment reminders annually attesting to their understanding of this company requirement.

 

Violations of PII Policies and Procedures: Medebound HEALTH views the protection of PII data to be of the utmost importance. Infractions of this policy or its procedures will result in disciplinary actions under Medebound HEALTH’s discipline policy and may include suspension or termination in the case of severe or repeat violations. PII violations and disciplinary actions are incorporated in Medebound HEALTH’s PII on-boarding and refresher training to reinforce Medebound HEALTH’s continuing commitment to ensuring that this data is protected by the highest standards.

 

Health Insurance Portability and Accountability Act (HIPAA) Statement

The following categories describe different ways that we are permitted to use and disclose your health information.

  • We may use or disclose your Protected Health Information (PHI) for to provide our services

  • We can use and share your health information to run our testing locations, improve your care, and contact you when necessary.

  • We can use and share your health information to bill and get payment.

  • We may provide your PHI to other companies or individuals that need the information to provide services to us.

  • We may use and disclose your health information for other purposes if we have de-identified it in accordance with applicable law.

  • We are allowed or required to share your information in other ways – usually in ways that contribute to the public good, such as public health and research. We have to meet many conditions in the law before we can share your information for these purposes.

  • We will share information about you if laws require it, including with the United States Department of Health and Human Services (HHS), if it wants to see that we are complying with privacy law.

  • We can share health information with a coroner, medical examiner, or funeral director when an individual dies.

  • We can share health information about you in response to a court or administrative order, or in response to a subpoena, discovery request, or other lawful process in certain situations.

 

Do we share your data with other countries?

We may use the services of third parties to process your data in accordance with this privacy policy. We try to process personal data within the United States wherever possible, however we also use processors including our subsidiaries who are based outside the USA or use servers outside the USA, including Shanghai and Hong Kong.

 

To protect your privacy, we will only transfer your personal data to countries outside the USA if an adequate level of protection is guaranteed, or if other appropriate safeguards are offered, such as the unchanged use of standard data protection clauses, with additional measures where necessary.

 

How do we protect your personal data?

We have taken appropriate technical and organizational measures to protect your personal data against loss or any form of improper processing. These measures ensure a level of security appropriate to the data we process. For example, access to personal data is limited to those persons who need the data to perform their tasks. In addition, pseudonymization and encryption are used where appropriate when processing personal data.

 

If you have the impression that your data is not properly secured or there are indications of misuse, please send an e-mail to support@medebound.com.

 

How long will your data be stored?

Unless otherwise stated, we only store your personal data for as long as it is required for the purposes for which it is processed or until your consent is revoked. Insofar as statutory retention obligations must be observed, the storage period for certain data can be up to 10 years, irrespective of the processing purposes.

 

Wix

We use the services of the homepage provider Wix.com Ltd, Namal 40, 6350671 Tel Aviv, Israel. Hereinafter referred to as "wix.com". The registered office in Europe: Wix.com Luxembourg S.a.r.l., 5 Rue Guillaume Kroll, L - 1882 Luxembourg. Wix.com collects two types of data: personal data (which can be used to uniquely identify an individual) and non-personal data (which is not used for identification purposes). Wix.com collects such information about our users and visitors, as well as users of users and others who provide it to us. Wix.com may also collect, solely for and in the interest of our users, similar data related to visitors and users of our users' web sites or services. Wix.com collects and uses data to provide our services and make them better and safer, as well as to contact our visitors, users and job applicants, and to comply with legal requirements applicable to Wix.com.

 

Wix.com may store and process personal data in the United States, Europe, Israel or other jurisdictions - either itself or through our affiliated companies and service providers. The data storage providers with whom Wix.com works are contractually obligated to protect your data. Wix.com may also collect, process and store such data in other locations, including the United States.

 

Wix may collect and process data about our users. We do so solely on behalf of and at the direction of our users. Our users are solely responsible for their users of users data, including for its legality, security and integrity. Wix has no direct relationship with users of users.

 

We may share the data of our visitors, users and their users of users with various third parties, including certain service providers, law enforcement agencies and application developers. In doing so, the data may only be shared in accordance with this policy.

 

Online presences and advertising measures in social media

We maintain online presences within social networks and platforms in order to be able to communicate with the customers, interested parties and users active there and to inform them about our services there.

 

We would like to point out that user data may be processed outside the USA. This may result in risks for the users because, for example, it could make it more difficult to enforce the rights of the users.

Furthermore, user data is usually processed for market research and advertising purposes. For example, usage profiles can be created from the usage behaviour and resulting interests of the users. The usage profiles can in turn be used, for example, to place advertisements within and outside the platforms that presumably correspond to the interests of the users. For these purposes, cookies are usually stored on the users' computers, in which the usage behaviour and the interests of the users are stored. Furthermore, data may also be stored in the usage profiles irrespective of the devices used by the users (in particular if the users are members of the respective platforms and are logged in to them).

 

The processing of users' personal data is based on our legitimate interests in effectively informing users and communicating with users. If users are asked by the respective providers to consent to data processing, the legal basis for processing is consent.

 

For a detailed description of the respective processing and the possibilities to object (opt-out), we refer to the information of the providers linked below.

 

In the case of requests for information and the assertion of user rights, we would also like to point out that these can be asserted most effectively with the providers. Only the providers have access to the users' data and can take appropriate measures and provide information directly. If you still need help, you can contact us.

 

Facebook (Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) - Privacy policy: https://www.facebook.com/about/privacy/, Opt-Out: https://www.facebook.com/settings?tab=ads and http://www.youronlinechoices.com,

 

Twitter (Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA) - Privacy policy: https://twitter.com/de/privacy, Opt-Out: https://twitter.com/personalization,

 

LinkedIn (LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland) - Privacy policy: https://www.linkedin.com/legal/privacy-policy , Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out,

 

Changes to this privacy policy

We occasionally update this privacy policy, for example when we adapt our website or when legal or regulatory requirements change. We will document material changes in this privacy policy and, where necessary, obtain our customers' consent. In these cases, we will also adapt our privacy policy accordingly. Therefore, please refer to the respective current version of our privacy policy.

 

Contact

If you have any questions or comments about this privacy policy, please contact us at support@medebound.com or +1 718-213-8508.

 

If you have a complaint about the use of your personal data, you can address your complaint to us by sending an email to support@medebound.com. You also have the right to lodge a complaint about Medebound HEALTH's use of your personal data with the national supervisory authority.

bottom of page