Epsy Privacy Policy

Last Updated: 12.03.2024

LivaNova   USA,   Inc.  and   its   affiliates  (“LivaNova”)  respect   your   concerns   about privacy.   This Epsy Privacy Policy describes the types of personal information we collect in connection with your use of the Epsy mobile application (“App”) and on our website epsyhealth.com (the “Site”) (collectively, the “Platforms”), how we use the information, with whom we may share it and the choices available to you regarding our use of the information.  We also describe measures we take to protect the security of the information and how you can contact us about our privacy practices.

If   you   are   a   California   resident,   please   refer   to   the   “California   Consumer   Privacy Statement' section   of   this   Epsy   Privacy   Policy   for   more information about your privacy rights.

If   you   are   a   Nevada   or   Washington   consumer,   please   refer   to   the   “Nevada   and Washington Consumer Health Data Privacy Statement” for more information   about   our   privacy   practices   and   your   privacy   rights   with   respect   to consumer health data we collect in connection with your use of the Platforms.

Click on one of the links below to jump to the listed section:

Information We Obtain

The types of personal information we may obtain when you use the Platforms include:

 

  • Contact information (such as name, telephone number and postal and email address); 
  • Account   information   (such   as   login   information,   account   preferences,   and whether you are a patient or a caregiver);
  • Demographic information (such as gender and date of birth);
  • Clinical and medical history (such as date and nature of diagnosis, date of electroencephalography, seizure type, seizure frequency, seizure intensity and recovery time, seizure duration, seizure logs, allergies, and information about your treating physician);
  • Medication   history   (such   as   medication   types,   dosages   and   changes   to medications   or   dosages,   medication   adherence,   medication   schedule, medication side effects, and medication refill timings);
  • Physiological   and   other   seizure-related   information   (such   as   vital   signs, symptoms, epilepsy triggers, mood ratings, sleep-related information, heart rate, menstrual cycle data, and information about motions you make);
  • Information about social, psychological, behavioral and medical interventions (such   as   information   about   any   implanted   medical   devices,   medical appointments and discussions with your medical care team, and details about treatments); 
  • Location information;
  • Social media information;
  • Sensory information (such as photographs and audio and video recordings); 
  • Inferences about individual preferences and characteristics, such as inferences drawn from and related to your seizure activity or use of the Platforms; and
  • Other information you choose to provide, such as responses to questionnaires or feedback you provide about the Platforms or your experience using them.

When you use the Platforms, we may collect certain information by automated means, such   as   through   cookies,   web   beacons,   device   logs,   server   logs,   and   other technologies.  A “cookie” is a text file that websites send to a visitor’s computer or other internet-connected device to uniquely identify the visitor’s browser or to store information or settings in the browser.  A “web beacon,” also known as an internet tag, pixel tag or clear GIF, links web pages to web servers and cookies and may be used to transmit information collected through cookies back to a web server.  The information we collect in this manner on our Platforms may include your device IP address, unique device   identifier,   web   browser   characteristics,   device   characteristics,   operating system, language preferences, referring URLs, clickstream data, and dates and times of website visits.  The information we collect in this manner on our App may include the device type used, mobile operating system, device identifier and similar unique identifiers, device settings and configurations, IP address, WiFi network identifier and signal, battery and signal strength, diagnostic and other performance data, usage statistics, referring emails and web addresses, dates and times of usage, actions taken on the App, and other information regarding use of the App.   In addition, we may collect your device’s geolocation information through GPS, Bluetooth, WiFi signals and other   technologies.     Your   device’s   operating   platform   may   provide   you   with   a notification when the App attempts to collect your precise geolocation.  Please note that if you decline to allow the App to collect your precise geolocation, you may not be able to use all of the App’s features or the offers available through the App.

We may use these automated technologies on the Platforms to collect information about your equipment, browsing actions and usage patterns.  These technologies help us:

  • remember your information so you do not have to re-enter it;
  • track and understand how you use and interact with the Platforms;
  • tailor the Platforms around your preferences; 
  • measure   the   usability   of   the   Platforms   and   the   effectiveness   of   our communications; 
  • authenticate your identity, protect against fraud and provide our products and services; and 
  • otherwise manage and enhance our products and services, and help ensure they are working properly.

Your   browser   may   tell   you   how   to   be   notified   about   certain   types   of   automated collection technologies and how to restrict or disable them.  For mobile devices, you can manage how your device and browser share certain device data by adjusting the privacy and security settings on your mobile device.   Without these technologies, however, you may not be able to use all of the features of the Platforms. 

Our Platforms are not designed to respond to “do not track” signals from browsers.

How We Use the Information We Obtain

We may use the personal information we obtain to:

  • Provide our products and services and manage your account;
  • Communicate   with   you,   respond   to   inquiries   and   offer   user   support   and assistance;
  • Personalize your experience with the Platforms, including providing features that allow you to take actions such as (1) tracking and viewing your inputted seizures, triggers and medications;               (2) viewing factors such as stress, diet and sleep that could be impacting your seizures; and                      (3) displaying your medical information that may be used for discussions with your care providers;
  • Determine eligibility to participate in market research, product testing or other similar programs;
  • Administer research studies;
  • Provide you with content or other opportunities to learn more about available therapy;
  • Conduct automated decision making based on algorithms that may provide you with opportunities to learn more about available therapy;
  • Advertise and market our products and services;
  • Administer   participation   in   surveys,   sweepstakes,   promotions   or   other programs;
  • Perform   analytics   and   market,   trend   or   statistical   research   and   solicit   user feedback regarding product research and development; 
  • Operate, evaluate and improve our business and our affiliates’ products and services   (including   developing   new   products   and   services;   improving   and analyzing   our   and   our   affiliates’   products   and   services;   managing   our communications;   providing   technical   support;   and   performing   accounting, auditing and other internal functions);
  • Maintain and enhance the safety and security of our products and services, prevent misuse and troubleshoot technical issues;
  • Verify your identity and protect against fraud and other criminal activity, claims and other liabilities; 
  • Exercise   our   rights   and   remedies,   respond   to   requests   from   government entities, and defend against legal claims; and
  • Comply   with   and   enforce   applicable   legal   requirements,   relevant   industry standards   and   LivaNova   policies,   including   the   Epsy  Terms   of   Use.

We also may use the information in other ways for which we provide specific notice at the time of collection.

Third-Party Analytics Services

We   may   use   third-party   analytics   services   on   the   Platforms,   such   as   Google Analytics.  The providers of these analytics services use technologies such as cookies and web beacons to help us analyze your use of the Platforms.   The information collected through these means may be disclosed to or collected directly by these services.     To   learn   more   about   Google   Analytics,   please   visit

https://www.google.com/policies/privacy/partners/. 

Information We Share

We   may   share   the   categories   of   personal   information   we   obtain   about   you   (as

described above) with the categories of third parties listed in this section.  We may share the information we obtain about you with our affiliated companies and joint marketing partners.  We also may share the information we obtain about you with (1) Internet service providers, operating systems and platforms, (2) professional services organizations, such as auditors and law firms, and (3) third-party vendors and other entities to perform services on our behalf, such as IT support and communications providers, advertising and marketing service providers, and others.   We may share your personal information with social media platforms if you use those services to connect with us. 

We may disclose personal information (1) if we are required to do so by law or legal process, such as a court order or subpoena; (2) in response to requests by government agencies, such as law enforcement authorities; (3) to establish, exercise or defend our legal rights; (4) when we believe disclosure is necessary or appropriate to prevent physical or other harm or financial loss; (5) in connection with an investigation of suspected or actual illegal activity or (6) otherwise with your consent or as directed by your representative.

In addition, we reserve the right to transfer to relevant third parties the personal information we have about you in the event of a potential or actual sale or transfer of all   or   a   portion   of   our   business   or   assets   (including   in   the   event   of   a   merger, acquisition, joint venture, reorganization, divestiture, dissolution, or liquidation), or other business transaction.

Your Rights and Choices

We offer you certain choices in connection with the personal information we collect from you.  You may update certain of your account details and settings, download a copy of certain of your personal information you provided in the App, or delete your account by logging into your account on the App and making the appropriate selection in the Settings menu.  You also may unsubscribe from our marketing mailing lists by following the “Unsubscribe” link in our emails.  For other requests, you can contact us as specified in the “How to Contact Us” section of this Epsy Privacy Policy.

California residents should also refer to the “California Consumer Privacy Statement” section of this Epsy Privacy Policy for more information about their privacy rights.

Nevada and Washington consumers should refer to the “Nevada and Washington Consumer Health Data Privacy Statement” for more information about their   privacy   rights   with   respect   to   consumer   health   data   we   collect   in connection with your use of the Platforms.

How We Protect Personal Information

We maintain administrative, technical and physical safeguards designed to protect personal information against accidental, unlawful or unauthorized access, destruction, loss, alteration, disclosure or use.

Children’s Privacy

This section describes our personal information practices with respect to your child’s creation and use of the Platforms, and the services and features available to your child.  

Information We Obtain from Children

When   you   first   create   an   account   for   your   child,   we   may   ask   for   certain information such as your child’s name, telephone number, postal and email address, and birthdate.  

When your child uses the Platforms and the available features and services, we may also collect the following information:

  • Account information (such as login information and account preferences);
  • Demographic information (such as your child’s gender and date of birth);
  • Clinical   and   medical   history   (such   as   your   child’s   date   and   nature   of diagnosis,   date   of   electroencephalography,   seizure   type,   seizure frequency, seizure intensity and recovery time, seizure duration, seizure logs, allergies, and information about your child’s treating physician);
  • Medication history (such as your child’s medication types, dosages and changes to medications or dosages, medication adherence, medication schedule, medication side effects, and medication refill timings);
  • Physiological and other seizure-related information (such as your child’s vital   signs,   symptoms,   epilepsy   triggers,   mood   ratings,   sleep-related
  • information,   heart   rate,   menstrual   cycle   data,   and   information   about motions that your child makes);
  • Information   about   your   child’s   social,   psychological,   behavioral   and medical interventions (such as information about any implanted medical devices, medical appointments and discussions with your child’s medical care team, and details about treatments); 
  • Location information;
  • Social media information;
  • Sensory   information   (such   as   photographs   and   audio   and   video recordings); 
  • Inferences   about   individual   preferences   and   characteristics,   such   as inferences drawn from and related to your child’s seizure activity or use of the Platforms; and
  • Other information you choose to provide on behalf of your child, such as responses to questionnaires or feedback you provide about the Platforms or your child’s experience using them.

We also collect certain information from your child by automatic means as described above in the “Information We Obtain” section of this Privacy Policy. 

The   Platforms   do   not   permit   your   child   to   make   their   personal   information publicly available.

How We Use the Information We Obtain from Children

Once a parent has authorized an account for their child, our information use practices described above in the “How We Use the Information We Obtain” section of our Privacy Policy generally apply.  We also may use the information in other ways for which we provide specific notice at the time of collection.

Parents’ Rights 

You have the option at any time to review the personal information collected from your child.  You may do so by submitting a review request here.

You can also delete your child’s account and/or refuse to permit our  further collection or use of your child’s personal information.  To do so, log in to your child’s account, and select “Delete account” in the Settings menu.

Sharing of Children’s Information

Once a parent has authorized an account for their child, our information sharing practices described above in the “Information We Share” section of our Privacy Policy generally apply.

In addition, certain third-party operators may collect or maintain your child’s personal   information   through   your   child’s   use   of   their   account.     Namely customer.io, Zendesk and Amazon web services. 

Please contact us as indicated in the “How to Contact Us” section   below   with   questions   about   the   operators’   privacy   policies   and collection and use practices.

For your convenience and information, the Platforms may provide links to other onlineservices (such as other health apps, websites or social media platforms), and may include third-party features such as apps, tools, widgets and plug-ins.  These online services and third-party features may operate independently from us.   The privacy practices of the relevant third parties, including details on the information they may collect about you, are subject to the privacy statements of these parties, which we strongly suggest you review.  To the extent any linked online services or third-party features are not owned or controlled by LivaNova, we are not responsible for these third parties’ information practices.

Updates to Our Epsy Privacy Policy

We may update this Epsy Privacy Policy from time to time and without prior notice to you to reflect changes in our personal information practices.  We will indicate at the top of the policy when it was most recently updated.

How to Contact Us

You can update your preferences, ask us to remove your information from our mailing lists, submit a request or ask us questions about this Epsy Privacy Policy by contacting us at:

LivaNova USA, Inc.

100 Cyberonics Boulevard

Houston, TX 77058

DataProtection@LivaNova.com

(866) 518-0999

***

Epsy California Consumer Privacy Statement

Last Updated: 12.03.2024

This California Consumer Privacy Statement supplements the Epsy Privacy Policy and applies solely to personal information collected about California consumers on the Platforms (as defined in the Epsy Privacy Policy).  This California Consumer Privacy Statement does not apply to (1) personal information collected about our personnel or job applicants, or (2) medical information subject to the California Confidentiality of Medical Information Act that is collected through the Platforms.  

This   California   Consumer   Privacy   Statement   uses   certain   terms   that   have   the meaning given to them in the California Consumer Privacy Act of 2018 (as amended by   the   California   Privacy   Rights   Act   of   2020)   and   its   implementing   regulations (collectively, the “CCPA”).

1. Notice of Collection and Use of Personal Information   

We may collect (and may have collected during the 12-month period prior to the Last Updated date of this California Consumer Privacy Statement) the following categories of personal information about you, in addition to those described in the Epsy Privacy Policy:

  • Identifiers: identifiers   such   as   a   real   name,   alias,   postal   address,   unique personal identifier (such as a device identifier; cookies, beacons, pixel tags, mobile   ad   identifiers,   and   similar   technology;   customer   number,   unique pseudonym, or user alias; telephone number and other forms of persistent or probabilistic identifiers), online identifier, IP address, email address and other similar identifiers;
  • Protected Classifications: characteristics of protected classifications under California or federal law, such as medical condition;
  • Commercial   Information: commercial   information,   including   records   of personal property, products or services purchased, obtained, or considered, and other purchasing or consuming histories or tendencies;
  • Online Activity: Internet and other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding your interaction with websites, applications or advertisements;
  • Geolocation Data; and
  • Inferences: inferences drawn from any of the information identified above to create   a   profile   about   you   reflecting   your   preferences,   characteristics, psychological   trends,   predispositions,   behavior,   attitudes,   intelligence, abilities, and aptitudes.

We   may   use   (and   may   have   used   during   the   12-month   period   prior   to   the   Last Updated   date   of   this   California   Consumer   Privacy   Statement)   your   personal information for the purposes described in the Epsy Privacy Policy and for the following business purposes:

  • Performing   services,   including   maintaining   or   servicing   accounts,   providing customer   service,   processing   or   fulfilling   orders   and   transactions,   verifying customer   information,   processing   payments,   providing   financing,   providing analytics services, providing storage, or providing similar services;
  • Providing advertising and marketing services;
  • Auditing   related   to   counting   ad   impressions   to   unique   visitors,   verifying positioning and quality of ad impressions, and auditing compliance;
  • Short-term, transient use, such as nonpersonalized advertising shown as part of your current interaction with us;
  • Helping to ensure security and integrity;
  • Undertaking activities to verify or maintain the quality or safety of our services or devices and to improve, upgrade, or enhance them; 
  • Debugging to identify and repair errors; and
  • Undertaking   internal   research   for   technological   development   and demonstration. 

On the Platforms, we do not collect or process sensitive personal information pursuant to the CCPA for purposes of inferring characteristics about consumers.  To the extent we   process   deidentified   information,   we   will   maintain   and   use   the   information   in deidentified form and will not attempt to reidentify the information unless permitted by applicable law.

2. Retention of Personal Information    

We will retain your personal information for the time period reasonably necessary to achieve   the   purposes   described   in   the   Epsy   Privacy   Policy   and   this   California Consumer Privacy Statement, or any other notice provided at the time of collection, taking   into   account   applicable   statutes   of   limitation   and   records   retention requirements under applicable law. 

3. Sources of Personal Information   

During the 12-month period prior to the Last Updated date of this California Consumer Privacy Statement, we may have obtained personal information about you from the following categories of sources:

  • Directly from you, such as when you contact us
  • Your devices, such as when you visit our Platforms
  • Our affiliates
  • Service providers, contractors and other vendors who provide services on our behalf
  • Our joint marketing and business partners
  • Online advertising services
  • Data analytics providers
  • Internet service providers (“ISPs”)
  • Operating systems and platforms
  • Social networks

4. Sale or Sharing of Personal Information   

We   do   not   sell   or   share   (for   cross-context   behavioral   advertising)   your   personal information collected in connection with your use of the Platforms.

5. Disclosure of Personal Information   

During the 12-month period prior to the Last Updated date of this California Consumer Privacy   Statement,   we   may   have   disclosed   the   following categories   of   personal information about you for a business purpose to the following categories of third parties:

In addition to the categories of third parties identified above, during the 12-month period prior to the Last Updated date of this California Consumer Privacy Statement, we may have disclosed personal information about you to government entities and third parties in connection with corporate transactions, such as mergers, acquisitions or divestitures.

Categories of Personal Information code Categories of Third Parties
Identifiers

- Our affiliates Vendors who provide services on our behalf

- Our joint marketing and business partners

- Professional services organizations, such as auditors and law firms

- Online advertising services

- Data analytics providers

- Social networks

- ISPs and operating systems and platforms

Protected Classifications

- Our affiliates

- Vendors who provide services on our behalf

- Our joint marketing and business partners

- Professional services organizations, such as auditors and law firms

- Data analytics providers

- ISPs and operating systems and platforms

- Social networks

Commercial Information

- Our affiliates

- Vendors who provide services on our behalf

- Our joint marketing and business partners

- Online advertising services

- Data analytics providers

- Social networks

- ISPs and operating systems and platforms

Online Activity

- Our affiliates

- Vendors who provide services on our behalf

- Our joint marketing and business partners

- Online advertising services

- Data analytics providers

- Social networks

- ISPs and operating systems and platforms

Geolocation Data

- Our affiliates

- Vendors who provide services on our behalf

- Our joint marketing and business partners

- Online advertising services

- Data analytics providers

- Social networks

- ISPs and operating systems and platforms

Categories of Personal Information Categories of Third Parties
Identifiers

- Our affiliates

- Vendors who provide services on our behalf

- Our joint marketing and business partners

- Professional services organizations, such as auditors and law firms

- Online advertising services

- Data analytics providers

- Social networks

- ISPs and operating systems and platforms

6. California Consumer Privacy Rights   

You have certain choices regarding your personal information, as described below.

  • Access: You have the right to request, twice in a 12-month period, that we disclose to you the personal information we have collected, used, disclosed,and sold or shared about you.
  • Correction:   You   have   the   right   to   request   that   we   correct   the   personal information we maintain about you, if that information is inaccurate.
  • Deletion: You   have   the   right   to   request   that   we   delete   certain   personal information we have collected from you.

How to Submit a Request.  You can update your account information, download a copy of your personal information or request to delete your account by logging in to your account in the Epsy App.  You can also submit an access, correction, or deletion request by clicking here or calling us at +1 866 322 1375. To submit a request as an authorized agent on behalf of a consumer, please email  dataprotection@livanova.com  with the subject line “CCPA Authorized Agent Request.” For questions or concerns about our privacy policies and practices, please contact us as described in the “How to Contact Us” section of the Epsy Privacy Policy.

Verifying Requests.  To help protect your privacy and maintain security, we will take   steps   to   verify   your   identity   before   granting   you   access   to   your   personal information or complying with your deletion or correction request.  If you do not have an account with us, or an email address on file with us (such as if you signed up to receive our newsletters), then there may not be a reasonable method by which we can verify your identity to the level of certainty required by the CCPA.  This is because historically   we   have   not   linked   device   identifiers   to   named   actual   persons. 

Accordingly, if you do not have an account with us, or an email address on file, and you request access to, correction of or deletion of your personal information, we will not be able to process your request at this time.  If you have an account with us, we will verify your request either when you log in to your account or if you confirm your email address in our records.  In addition, if you ask us to provide you with specific pieces   of   personal   information,   we   may   require   you   to   sign   a   declaration   under penalty   of   perjury   that   you   are   the   consumer   whose   personal   information   is   the subject of the request.

Additional Information.  If you choose to exercise any of your rights under the CCPA, you have the right to not receive discriminatory treatment by us.  To the extent permitted by applicable law, we may charge a reasonable fee to comply with your request.