Legal

Privacy Policy

Last updated: [pending real date from BC/legal]

1. Introduction

Centime, Inc. ("Centime") understands that individuals, businesses, and healthcare organizations care about how information—particularly Protected Health Information (PHI)—is used and protected. This Privacy Policy explains how we collect, maintain, use, and share information, including PHI, through our website (the "Site") and online services, and how you can manage the way information is handled.

As a HIPAA Business Associate, the Organization may receive PHI in connection with the business services it provides to healthcare organizations, and we are committed to handling all such information responsibly and in accordance with applicable privacy and security requirements.

2. What Personal Data is Collected and from What Sources?

We collect and process the following categories of information:

  • Contact Information: such as name, email address, phone number, and physical address of our customers, as well as their buyers and suppliers.
  • Financial Information: including bank account numbers and routing numbers necessary to facilitate transactions.
  • Other Financial Data: we may also collect certain financial information that does not constitute personally identifiable information (PII).

IP Addresses

Your Internet Protocol ("IP") address is usually associated with the place from which you access the internet, like your home Internet Service Provider or company office. We may collect and use your IP information to gather broad information about how users access our website.

Cookies

Most websites, including our Site, use a feature of your browser to set a small text file called a "cookie" on your computer. The site placing the cookie on your computer can then recognize the computer when you revisit the site to allow auto login and track how you are using the site.

When you visit our Site, our servers and/or those of our service providers automatically record certain information that your web browser sends, such as your web request, IP address, browser type, referring/exit pages and URLs, number of clicks, domain names, landing pages, pages viewed, time and date of use and other information.

The information we collect using cookies does not allow you to be personally identified; but we may link this information to information that you submit while on our Site, which does allow you to be personally identified.

You are free to decline cookies. You can configure your browser to accept all cookies, reject all cookies, erase cookies, or notify you when a cookie is set.

Third Party Cookies

The use of cookies by our partners, affiliates, tracking utility company, and service providers is not covered by our Privacy Policy. We do not have access or control over these cookies. Our partners, affiliates, tracking utility company, and service providers may use session ID cookies in order to:

  • Personalize your experience
  • Analyze which pages our visitors visit
  • Provide website features such as social sharing widgets
  • Measure advertising effectiveness
  • Track which areas of our Site you visit in order to market to you after you leave

Google Analytics

We use Google Analytics, a web analytics service provided by Google, Inc. Google Analytics uses cookies and/or other tracking technologies to help us analyze how users interact with and use the Site, compile reports on the Site's activity, and provide other services related to Site activity and usage. The technologies used by Google may collect information such as your IP address, time of visit, whether you are a return visitor, and any referring website.

The Site does not use Google Analytics to gather information that personally identifies you. The information generated by Google Analytics will be transmitted to and stored by Google and will be subject to Google's privacy policies.

Do Not Track Signals

Your browser or device may include "Do Not Track" functionality. Our information collection and disclosure practices, and the choices that we provide to visitors, will continue to operate as described in this Privacy Policy, whether or not a Do Not Track signal is received.

Web Beacons

Our web pages contain electronic images known as web beacons (sometimes called single-pixel gifs) and are used along with cookies to compile aggregated statistics to analyze how our Site is used.

3. How Does Centime Use Information?

The Company reserves the right to modify, suspend, or discontinue, temporarily or permanently, the Application or any service to which it connects, with or without notice and without liability to you.

Updates to the Application

Centime may aggregate collected information about our users in a form that does not allow users to be personally identified, for the purpose of understanding our customer base and enhancing the services that we and our strategic partners and customers can provide you. Centime will use Personal Information only in ways that are compatible with the purposes for which it was collected or subsequently authorized by the individual about whom the information pertains. Centime will take reasonable steps to ensure that Personal Information is relevant to its intended use, accurate, complete, and current.

Specifically, we may use Personal Information and platform use information for:

  • Allowing users easier and more efficient use of the platform
  • Understanding how users use the platform in order to improve our user interface and detect problems and bugs
  • Processing payments and agreed services
  • Communicating with you about our services
  • Providing customer support
  • Meeting legal requirements
  • Providing business services to healthcare clients

4. HIPAA Business Associate Notice (Healthcare Business Services)

Centime operates as a HIPAA Business Associate when providing business services to healthcare organizations. We do not provide healthcare services directly.

Protected Health Information (PHI) refers to any individually identifiable health information related to the provision of healthcare services, payment for such services, or healthcare operations.

Within the scope of our business services, PHI is limited to references contained in descriptions used in bills, invoices, and purchase orders. For more details, please refer to the HIPAA Business Associate section below.

4.1 How We Use PHI as a Business Associate

We use and disclose PHI ONLY for the specific business services we provide to our customers (healthcare organizations), including:

  • Processing invoices and payments related to our customers (healthcare organizations)
  • Communicating with relevant parties as necessary for business operations

4.2 What We Do NOT Do with PHI

We do NOT:

  • Provide direct healthcare services or treatment
  • Use PHI for our own marketing purposes
  • Sell PHI to third parties
  • Use PHI beyond what is necessary for contracted business services

4.3 Business Associate Agreements

We enter into Business Associate Agreements (BAAs) with healthcare customers that require us to:

  • Safeguard PHI according to HIPAA requirements
  • Use PHI only for permitted business functions
  • Report any security incidents or breaches
  • Return or destroy PHI as necessary

4.4 Individual Rights Regarding PHI

Because we are a Business Associate (not a Covered Entity), patients should contact the covered entity (customer organization) directly to:

  • Access their medical records
  • Request corrections to health information
  • File complaints about privacy practices
  • Exercise other HIPAA rights

We will assist healthcare organizations in responding to individual requests as required by our Business Associate Agreements.

5. Information Sharing

We may share your information with:

  • Third parties and service providers as necessary to provide contracted services
  • Legal authorities when required by law
  • Other parties with your consent

We do not sell your personal information or PHI to third parties.

6. Your Privacy Rights

You have the right to:

  • Access the personal information we have about you
  • Correct inaccurate information
  • Delete your information (with some legal exceptions)
  • File a complaint about our privacy practices

Important: for PHI-related rights, please contact your covered entity (customer organization) directly, as we are a Business Associate providing business services only. To exercise your rights regarding non-PHI information, contact us at privacy@centime.com.

7. Data Security

We use comprehensive security measures to protect your information, including PHI, in our business operations:

  • Encryption of data in transit and at rest
  • Access controls and multi-factor authentication
  • Regular security risk assessments
  • Staff training on data protection and HIPAA requirements
  • Business Associate Agreements with all vendors who may access PHI

8. Updates to this Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date and posting the revised policy on our website. Healthcare organizations with whom we have Business Associate Agreements will be notified of any changes that affect PHI handling.

9. Contact Information

If you have questions about this Privacy Policy or want to exercise your rights:

General Privacy and PHI/PII Questions: privacy@centime.com

For PHI-related individual rights, contact your healthcare provider (covered entity) directly.