Privacy Policy

Last revised August 13, 2018

Sana Benefits, Inc. (the “Company”) is committed to protecting your privacy. We have prepared this Privacy Policy to describe to you our practices regarding the personal information we collect from users of our online portal (the “Application” and the services available therein the “Services”). The Services enable employers who offer self-funded health insurance programs (each, an “Employer’) to their employees (each, an “Employee”) to engage us to use the Services. Through the Services, Employers can manage certain administrative and reporting tasks related to their self-funded health insurance programs, and Employees can access and view benefits. Please note that this Privacy Policy does not apply to any protected health information (as defined by the Health Insurance Protectability and Accountability Act of 1996, as amended (“HIPAA”)) that may be disclosed by insurance providers and the Employer to the Company, and will be governed by a separate business associated agreement between the Company and the insurance provider and/or Employer.

  1. Questions; Contacting Company; Reporting Violations.

    If you have any questions or concerns or complaints about our Privacy Policy or our data collection or processing practices, or if you want to report any security violations to us, please contact us at the following address or phone number:

    • Sana Benefits, Inc.
    • Attn: Legal Department
    • Address: PO Box 660675 #35777, Dallas, TX 75266
    • Email: [email protected]
  2. A Note About Children.

    We do not intentionally gather personal information from visitors who are under the age of 13. If a child under 13 submits personal information to the Company and we learn that the personal information is the information of a child under 13, we will attempt to delete the information as soon as possible. If you believe that we might have any personal information from a child under 13, please contact us at: [email protected].

  3. Types of Data We Collect.

    We collect personal information from users, as described below.

    1. Information You Provide to Us.

      • We may collect personal information from you, such as your first and last name, e-mail, username and password when you create an account to log in to our Services (“Account”).
      • If you are an Employee, the information you upload about yourself, or which your Employer provides us, including your name, age, date of birth, social security number, gender, number of dependents and their enrollment information, as well as any other information you provide in connection with your enrollments (“Profile”).
      • If you are an Employer, we will collect the enrollment information you provide about your Employees, such as their name, date of birth, social security number and any other information voluntarily provided by you.
      • If you provide us feedback or contact us via e-mail, we will collect your name and e-mail address, as well as any other content included in the e-mail, in order to send you a reply.
      • If you use our chat support feature, we will collect your name as well as the content of your messages in order to provide you the support you request.
      • If you sign up for our newsletter we will collect your email address.
      • When you participate in any survey on our Services, we will collect your answers and add it to your profile.
      • If you participate in a sweepstakes, contest or other promotion on our Services, we may ask you for your e-mail address and/or home number (to notify you if you win or not). We may also ask for first and last name, and sometimes postal address to verify your identity. In some situations we may need additional information as a part of the entry process, such as a prize selection choice. These sweepstakes and contests are voluntary. We recommend that you read the rules for each sweepstakes and contest that you enter.
      • We also collect personal information at other points in our Services that state that personal information is being collected.
    2. Information Collected via Technology.

      • Log Files. As is true of most websites and mobile applications, we gather certain information automatically and store it in log files. This information includes IP addresses, browser type, Internet service provider (“ISP”), referring/exit pages, operating system, date/time stamp, and clickstream data. We use this information to analyze trends, administer the Services, track users’ movements around the Application, gather demographic information about our user base as a whole, and better tailor our Services to our users’ needs. Except as noted in this Privacy Policy, we do not link this automatically-collected data to personal information.
      • Cookies. Like many online services, we use cookies to collect information. “Cookies” are small pieces of information that a website sends to your computer’s hard drive while you are viewing the website. We may use both session Cookies (which expire once you close your web browser) and persistent Cookies (which stay on your computer until you delete them) to provide you with a more personal and interactive experience on our Services. This type of information is collected to make the Services more useful to you and to tailor the experience with us to meet your special interests and needs.
      • Pixel Tags. In addition, we use “Pixel Tags” (also referred to as clear Gifs, Web beacons, or Web bugs). Pixel Tags are tiny graphic images with a unique identifier, similar in function to Cookies that are used to track online movements of Web users. In contrast to Cookies, which are stored on a user’s computer hard drive, Pixel Tags are embedded invisibly in Web pages and emails. Pixel Tags also allow us to send e-mail messages in a format users can read, and they tell us whether e-mails have been opened to ensure that we are sending only messages that are of interest to our users. We may use this information to reduce or eliminate messages sent to a user.
      • Traffic Analytics. We use a number of third party service provides, such as Google Analytics, to help analyze how users use the Services (“Analytics Companies”). These Analytics Companies uses Cookies to collect information such as how often users visit the Services, and what features they use on our Applications. We use the information we get from these Analytics Companies to improve our Applications and Services. These Analytics Companies collect the IP address assigned to you on the date you visit the Services, rather than your name or other personally identifying information. We do not combine the information generated through the use of our Analytics Companies with your personal information. Although these Analytics Companies may place a persistent Cookie on your web browser or mobile device to identify you as a unique user the next time you visit the Services, the Cookie cannot be used by anyone but the Analytics Company that placed the applicable Cookie. This Policy does not apply to and we are not responsible for the Cookies used by these Analytics Companies.
    3. Information Provided by Third Parties.

      If you are an Employee, we may receive information about you from third parties who administer or provide the insurance benefits made available to you by your Employer. For example, we may receive medical information from insurance medical providers, such as your name, diagnoses, the procedure(s) you received and amounts billed to you, in order to provide you the Services. The Company’s use and disclosure of any personal health information (as defined under HIPAA) will be subject to the terms of the Company’s business associate agreement between the Company, your Employer and/or your insurance medical provider(s). Location Information. We may collection location information, such as your zip code, in order to provide you with recommended doctors, physicians and other medical providers in your network near you.

    4. Location Information.

      We may collection location information, such as your zip code, in order to provide you with recommended doctors, physicians and other medical providers in your network near you.

  4. Use of Your Personal information.

    1. General Use.

      In general, personal information you submit to us is used either to respond to requests that you make, or to aid us in serving you better. We use your personal information in the following ways:

      • facilitate the creation of and secure your Account on our network;
      • identify you as a user in our system;
      • provide improved administration of our Services;
      • provide the Services you request;
      • improve the quality of experience when you interact with our Applications and Services;
      • send you a welcome e-mail to verify ownership of the e-mail address provided when your Account was created;
      • send you administrative e-mail notifications, such as security or support and maintenance advisories;
      • respond to your inquiries related to employment opportunities or other requests;
      • send newsletters, surveys, offers, and other promotional materials related to our Services and for other marketing purposes of Company.
    2. Creation of Anonymous Data.

      We may create anonymous data records from personal information by excluding information (such as your name) that makes the data personally identifiable to you. We use this anonymous data to analyze request and usage patterns so that we may enhance the content of our Services and improve Application navigation. We reserve the right to use anonymous data for any purpose and disclose anonymous data to third parties in our sole discretion.

  5. Disclosure of Your Personal information.

    We disclose your personal information as described below and as described elsewhere in this Privacy Policy.

    1. Profile Information.

      If you are a Member, the information in your Profile will be accessible by your Employer as well as any network partner, case management partner and/or payment vendor with whom your Employer has approved to take part in your insurance plan.

    2. Third Party Service Providers.

      We may share your personal information with third party service providers to: provide you with the Services that we offer you; to fulfill your order or subscription for any products, services or other goods; to conduct quality assurance testing; to facilitate creation of accounts; to provide technical support; and/or to provide other services to the Company.

    3. Affiliates.

      We may share some or all of your personal information with our parent company, subsidiaries, joint ventures, or other companies under a common control (“Affiliates”), in which case we will require our Affiliates to honor this Privacy Policy.

    4. Corporate Restructuring.

      We may share some or all of your personal information in connection with or during negotiation of any merger, financing, acquisition or dissolution, transaction or proceeding involving sale, transfer, divestiture, or disclosure of all or any portion of our business or assets. In the event of an insolvency, bankruptcy, or receivership, personal information may also be transferred as a business asset. If another company acquires our company, business, or any of our assets, that company will possess the personal information collected by us and will assume the rights and obligations regarding your personal information as described in this Privacy Policy.

    5. Other Disclosures.

      Regardless of any choices you make regarding your personal information (as described below), Company may disclose personal information if it believes in good faith that such disclosure is necessary (a) in connection with any legal investigation; (b) to comply with relevant laws or to respond to subpoenas or warrants served on Company; (c) to protect or defend the rights or property of Company or users of the Applications or Services; and/or (d) to investigate or assist in preventing any violation or potential violation of the law, this Privacy Policy, or our Terms of Use.

  6. Your Choices Regarding Your Information.

    You have several choices regarding use of information on our Services:

    1. Email Communications.

      We will periodically send you free newsletters and e-mails that directly promote the use of our Services. When you receive promotional communications from us, you may indicate a preference to stop receiving further promotional communications from us and you will have the opportunity to “opt-out” by following the unsubscribe instructions provided in the e-mail you receive or by contacting us directly (please see contact information below). Despite your indicated e-mail preferences, we may send you service related communications, including notices of any updates to our Terms of Use or Privacy Policy.

    2. Changing or Deleting Your Personal Information.

      You may change any of your personal information in your Account by editing your settings within your Account or by sending an email to us at the address listed above. You may request deletion of your personal information by us, and we will use commercially reasonable efforts to honor your request, but please note that we may be required to keep such information and not delete it (or to keep this information for a certain time, in which case we will comply with your deletion request only after we have fulfilled such requirements). When we delete any information, it will be deleted from the active database, but may remain in our archives or backups. We may also retain your information for fraud prevention or similar purposes.

    3. Do Not Track Signals.

      Some web browsers may transmit “do not track” signals to the websites and other online services with which your web browser communicates. There is no standard that governs what, if anything, websites should do when they receive these signals. We currently do not take action in response to these signals. If and when a standard is established, we may revise our policy on responding to these signals.

  7. Changes to This Privacy Policy.

    This Privacy Policy is subject to occasional revision, and if we make any material changes in the way we use your personal information, we will notify you by sending you an e-mail to the last e-mail address you provided to us and/or by prominently posting notice of the changes within our Applications. Continued use of our Applications or Services, following notice of such changes shall indicate your acknowledgement of such changes and agreement to be bound by the terms and conditions of such changes.