EFFECTIVE DATE: January 1, 2023
LAST UPDATED: December 30, 2022
Apexus, LLC including its affiliates (collectively, “Apexus,” “we,” “us,” or “our”) values your privacy. In this Privacy Policy (“Policy”), we describe how we collect, use, and disclose information that we obtain about visitors to our websites www.apexus.com and www.340bpvp.com (the “Site”) and corporate offices as well as through our products and services (collectively, the “Services”). We also provide legal Terms of Use for our Site, which are located below in Section 2.
1. Scope and Consent
By visiting the Site, you acknowledge that your personal information will be handled as described in this Policy. As used herein, “Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer.
2. Terms of Use
These Terms of Use (“Terms”) apply to your use of the Site and Services provided by Apexus. By accessing or using our services, you agree to these Terms. If you do not agree to these Terms, including the mandatory arbitration and class action waiver in Section 2(F), do not access or use our Services. We may make changes to our policies, content and all other aspects of the operation of the Site at any time without notice to you. We will post any changes to the Site from time to time, and therefore you should periodically review the Terms when accessing the Services.
A. Disclaimers
These web pages contain confidential and/or proprietary information and are provided “as is” and “as available.” APEXUS MAKES NO WARRANTY, EXPRESS OR IMPLIED, OF THE VALIDITY OF SERVICES OR ITS APPROPRIATENESS FOR USE IN ANY MANNER, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE OR NONINFRINGEMENT. BY ACCESSING THE SERVICES, YOU ASSUME THE ENTIRE RISK. APEXUS DOES NOT WARRANT OR MAKE ANY REPRESENTATIONS CONCERNING THE USE OF THESE DOCUMENTS OR THE ACCURACY, COMPLETENESS, RELIABILITY OR USEFULNESS OF ANY INFORMATION IN THEM. WHILE APEXUS ATTEMPTS TO MAKE YOUR ACCESS TO AND USE OF OUR SERVICES SAFE, WE CANNOT AND DO NOT REPRESENT OR WARRANT THAT OUR SERVICES OR SERVERS ARE FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS. Apexus neither warrants nor represents that your use of content on this Site will not infringe rights of third parties not affiliated with Apexus.
B. Information Not Legal Advice
This Site makes use of licensed stock photography that is intended for illustrative purposes only. The professional services depicted are not necessarily services provided by Apexus. The information contained in these web pages and in material referenced by these web pages, is intended for informational and educational purposes only, and does not constitute legal, financial, accounting, medical or other professional advice.
C. Limitation of Liability
The information herein should not be considered a substitute for your independent professional judgment or expert advice from a competent professional. Under no circumstances shall Apexus, its affiliates, or any copyright holder, be liable for any actual, incidental, indirect, special, punitive, or consequential damages arising from or related to this Site or the Services, even if Apexus, or its affiliates, have been advised of the possibility of such damages.
The Site and its content will be transmitted over a medium that may be beyond the control and jurisdiction of Apexus. Accordingly, Apexus assumes no liability for or relating to the delay, failure, interruption, or corruption of any information transmitted in connection with your use of the Site.
D. Limited License
All content on the Site (including, without limitation, text, design, graphics, logos, icons, images, audio clips, downloads, interfaces, code and software, as well as the selection and arrangement thereof, collectively “Apexus Content”), is the exclusive property of and owned by Apexus, its licensors or its content providers and is protected by copyright, trademark and other applicable laws. As a visitor to the Site, you are our guest. Apexus and its third-party content contributors grant you a limited, nonexclusive, nontransferable, non-sublicensable, revocable license to access the Apexus Content. You may copy, download and print the Apexus Content solely for your personal, non-commercial benefit, provided that you shall not modify or delete any copyright, trademark or other proprietary notice that appears on the Apexus Content. However, such license is subject to these Terms and does not include any right to modify, distribute, transmit, perform, broadcast, publish, upload, license, reverse engineer, transfer or sell the Apexus Content. Any use of our Apexus Content, other than as authorized herein, without our prior written permission, is strictly prohibited and will terminate the license granted herein. You agree to abide by all additional restrictions displayed on the Site as it may be updated from time to time.
Except as explicitly stated in these Terms, Apexus and our licensors reserve all rights, title, and interest in and to our Services and the Apexus Content. Apexus reserves the right to prohibit any person from using the Site for any reason, at its sole discretion.
E. Prohibited Uses
We reserve the right to deny access to you at any time if you engage in prohibited activity, such as posting copyright-protected content without approval from the author, unauthorized copying or use of information or functionality on the Site, attempting to obtain unauthorized access to restricted areas of the Site, using slanderous, profane or inappropriate language in communications involving or in the Website, or infecting the Website with computer viruses or other destructive functionality.
You may not use contact information provided on the Site for unauthorized purposes, including marketing. You may not use any hardware or software intended to damage or interfere with the proper working of the site or to surreptitiously intercept any system, data or personal information from the Site. You agree not to interrupt or attempt to interrupt the operation of the Site in any way. Apexus reserves the right, in its sole discretion, to limit or terminate Your access to or use of the site at any time without notice. Termination of your access or use will not waive or affect any other right or relief to which Apexus may be entitled at law or in equity. Any content found to be in violation of these Terms will be removed.
F. Dispute Resolution; Binding Arbitration
Please read the following section carefully because it requires you to arbitrate certain disputes and claims, including all privacy related claims, with Apexus and limits the manner in which you can seek relief from us, unless you opt out of arbitration by following the instructions set forth below. No class or representative actions or arbitrations are allowed under this arbitration provision. In addition, arbitration precludes you from suing in court or having a jury trial.
(i) No Representative Actions. To the fullest extent permitted by applicable law, you and Apexus agree that any dispute arising out of related these Terms, including claims related to privacy and data security, is personal to you and Apexus and that any dispute will be resolved solely through individual action, and will not be brought as a class arbitration, class action or any other type of representative proceeding.
(ii) Arbitration Disputes. Except for small claims disputes in which you or Apexus seeks to bring an individual action in small claims court located in the county of your billing address or disputes in which you or Apexus seeks injunctive or other equitable relief for the alleged infringement or misappropriation of intellectual property, you and Apexus waive your rights to a jury trial and to have any other dispute arising out of or related to these Terms, including claims related to privacy and data security, (collectively, “Disputes”) resolved in court. Instead, for any Dispute that you have against Apexus you agree to first contact Apexus and attempt to resolve the claim informally by sending a written notice of your claim (“Notice”) to Apexus by email at legalprivacynotice@apexus.com or by certified mail addressed to 290 E. John Carpenter Fwy, Irving, TX 75062. The Notice must (a) include your name, residence address, email address, and telephone number; (b) describe the nature and basis of the Dispute; and (c) set forth the specific relief sought. Our notice to you will be similar in form to that described above. If you and Apexus cannot reach an agreement to resolve the Dispute within thirty (30) days after such Notice is received, then either party may submit the Dispute to binding arbitration administered by JAMS or, under the limited circumstances set forth above, in court. All Disputes submitted to JAMS will be resolved through confidential, binding arbitration before one arbitrator. Arbitration proceedings will be held in Dallas Texas unless you are a consumer, in which case you may elect to hold the arbitration in your county of residence. For purposes of this Section 2(F), a “consumer” means a person using the Services for personal, family or household purposes. You and Apexus agree that Disputes will be held in accordance with the JAMS Streamlined Arbitration Rules and Procedures (“JAMS Rules”). The most recent version of the JAMS Rules are available on the JAMS website and are hereby incorporated by reference. You either acknowledge and agree that you have read and understand the JAMS Rules or waive your opportunity to read the JAMS Rules and waive any claim that the JAMS Rules are unfair or should not apply for any reason.
(iii) You and Apexus agree that these Terms affect interstate commerce and that the enforceability of this Section 2(F) will be substantively and procedurally governed by the Federal Arbitration Act, 9 U.S.C. § 1, et seq. (the “FAA”), to the maximum extent permitted by applicable law. As limited by the FAA, these Terms and the JAMS Rules, the arbitrator will have exclusive authority to make all procedural and substantive decisions regarding any Dispute and to grant any remedy that would otherwise be available in court, including the power to determine the question of arbitrability. The arbitrator may conduct only an individual arbitration and may not consolidate more than one individual’s claims, preside over any type of class or representative proceeding or preside over any proceeding involving more than one individual.
(iv) The arbitration will allow for the discovery or exchange of non-privileged information relevant to the Dispute. The arbitrator, Apexus, and you will maintain the confidentiality of any arbitration proceedings, judgments and awards, including information gathered, prepared and presented for purposes of the arbitration or related to the Dispute(s) therein. The arbitrator will have the authority to make appropriate rulings to safeguard confidentiality, unless the law provides to the contrary. The duty of confidentiality does not apply to the extent that disclosure is necessary to prepare for or conduct the arbitration hearing on the merits, in connection with a court application for a preliminary remedy or in connection with a judicial challenge to an arbitration award or its enforcement, or to the extent that disclosure is otherwise required by law or judicial decision.
(v) You and Apexus agree that for any arbitration you initiate, you will pay the filing fee (up to a maximum of $250 if you are a consumer), and Apexus will pay the remaining JAMS fees and costs. For any arbitration initiated by Apexus, Apexus will pay all JAMS fees and costs. You and Apexus agree that the state or federal courts of the State of Texas and the United States sitting in Dallas, Texas have exclusive jurisdiction over any appeals and the enforcement of an arbitration award.
(vi) Any Dispute must be filed within one year after the relevant claim arose; otherwise, the Dispute is permanently barred, which means that you and Apexus will not have the right to assert the claim.
(vii) You have the right to opt out of binding arbitration within 30 days of the date you first accepted the terms of this Section 2(F) by contacting us at legalprivacynotice@apexus.com. In order to be effective, the opt-out notice must include your full name and address and clearly indicate your intent to opt out of binding arbitration. By opting out of binding arbitration, you are agreeing to resolve Disputes in accordance with Section 2(F).
(viii) If any portion of this Section 2(F) is found to be unenforceable or unlawful for any reason, (a) the unenforceable or unlawful provision shall be severed from these Terms; (b) severance of the unenforceable or unlawful provision shall have no impact whatsoever on the remainder of this Section 2(F) or the parties’ ability to compel arbitration of any remaining claims on an individual basis pursuant to this Section 2(F); and (c) to the extent that any claims must therefore proceed on a class, collective, consolidated, or representative basis, such claims must be litigated in a civil court of competent jurisdiction and not in arbitration, and the parties agree that litigation of those claims shall be stayed pending the outcome of any individual claims in arbitration. Further, if any part of this Section 2(F) is found to prohibit an individual claim seeking public injunctive relief, that provision will have no effect to the extent such relief is allowed to be sought out of arbitration, and the remainder of this Section 2(F) will be enforceable.
G. Guidelines for Linking
If you wish to link to Apexus's Website, you must request permission to do so in writing, either by contacting us at apexusanswers@apexus.com or by U.S. mail at Apexus, Inc., 290 E. John Carpenter Freeway, Irving, Texas 75062, listing the URL of your site. Anyone linking to Apexus's Website must comply with these guidelines for linking to Apexus's Site and all applicable laws. A site that links to Apexus's Site:
- May link to, but not replicate, Apexus content
- Should not create a browser, border or frame environment around Apexus content
- Should not imply that Apexus is endorsing it or its products
- Should not misrepresent its relationship with Apexus
- Should not present false information about Apexus products or services
- Should not use the Apexus logo without written permission from Apexus
- Should not contain content that could be construed as distasteful, offensive or controversial
- Should contain only content that is appropriate for all age groups.
H. Client Contributed Content
Within the client-only area of www.apexus.com and www.340bpvp.com are many documents and discussions contributed by individuals within our client organizations. This content is for information sharing purposes only and should not be construed as clinically proven, endorsed, or recommended by Apexus or contributors. Posting of copyrighted materials, in whole or in part, is EXPRESSLY PROHIBITED without the prior written permission of the copyright holder, and may subject the user and their employer to legal liability for copyright infringement, and a denial of further access to this Site. Users may post hypertext links to, or URLs for, copyrighted materials already on the Internet unless prohibited by the copyright holder or applicable law. Users may also refer to copyrighted materials by title and/or author or publisher, but may not actually post the materials without prior written permission of the copyright holder. Site visitors agree to not disclose information in this Site to any third party, other than Apexus, LLC, its regional offices, subsidiaries and health care clients. Site visitors agree to not submit information to this Site that is covered by the Health Insurance Portability and Accountability Act of 1996 as amended (“HIPAA”), such as patient identifiable information (i.e. “Protected Health Information”).
The appearance of any information or materials on this Site does not constitute an endorsement or recommendation by Apexus or its affiliates. This Site contains copyrighted materials and proprietary materials owned by either Apexus or third parties who have given their permission to post their materials to this Site. These materials are protected by the United States copyright laws and international treaty provisions, and may be downloaded and/or printed for personal use only. Any posting of information, or any other use of information or materials on this Site, including, but not limited to, reproducing, copying, transmitting, or distributing, in whole or in part, is EXPRESSLY PROHIBITED without the prior written consent of the copyright holder. Information, comments, discussions, and materials on this Site may be discoverable in response to a valid request by a court of competent jurisdiction or governmental agency.
3. Apexus Data Practices and Consumer Rights
A. Information Practices: How We Collect, Use, Retain, and Disclose Personal Information
The information we collect through the Site, including all of its web pages, is controlled by Apexus, including its subsidiaries and wholly owned affiliates, which is headquartered in the United States at 290 E. John Carpenter Fwy, Irving, TX 75062.
California Consumers should see Sections 3.J and 3.K. for a detailed description of the information we collect, the business purposes for collection, and the categories of third parties with whom we may disclose, sell, or share your information as well as a description of your rights with regard to your personal information including your rights to know, access, delete, correct inaccuracies, opt-out of the sale or sharing, limit the use of sensitive personal information, and non-discrimination.
B. The Information We Collect About You
We collect information about you directly from you and from third parties, as well as automatically through your use of our Services.
C. Information We Collect Directly from You through the Site. The information we collect from you depends on how you use our Site. To request more information from us, you must provide us with identifiers or employment-related information such as your name, your job title and the name of the customer company you work for, your contact information, such as your business email and phone number, and your reason for contacting us.
D. Information We Collect Through Our Corporate Customer Relationships. In order to manage our customer relationships with our corporate customers, we collect identifiers and employment-related information about and from our corporate customers' employees and workforce. This information may include names, titles, business email addresses and phone numbers, work location, and information about an employee or workforce client’s role at the corporate customer (such as the department they work in, products or issues worked on, and other similar information). We use this information to administer our corporate customer contracts and to market our Services to corporate customers. When you/your employer are subscribed to one of our Services, listservs or community portals, we may collect information such as your name, email address, profession, and customer affiliation.
E. Information Collected and Used in Apexus Services. Apexus collects medical information, called “protected health information” under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), in Apexus’s role as a business associate to health care providers; however, not all Apexus Services collect protected health information, including its 340B prime vendor program (“PVP”). The protected health information is used to support Apexus customers’ health care operations and is received by Apexus in its capacity as a business associate to its clients. The privacy of such data is governed by HIPAA rather than any state privacy law.
Apexus also collects personal information about consumers that are health care practitioners (“practitioners”) directly from its corporate health care customers, or from third party providers of data, such as health care claims data aggregators, and governmental sources, in order to provide Services to the health care industry. Apexus’ customers in the health care industry can include health care providers and health systems, data aggregators working in the health care industry, pharmaceutical manufacturers and general medical supply vendors. If the practitioner data in question is not otherwise exempt under the CCPA, the transfer to such customers can be considered a sale of personal information under the CCPA. You may review the chart showing Apexus’s practices in the past 12 months with respect to such personal information in Sections K(i) and K(ii) below.
F. Information We Collect Automatically. We may automatically collect the following identifiers and internet or other electronic network activity information about your use of our Site through cookies, web beacons, and other technologies: your domain name; country of origin, your browser type and operating system; Apexus web pages you view; links you click on the Apexus website; your IP address; the length of time you visit our Site; and the referring URL or webpage that led you to our Site. We may combine this information with other information that we have collected about you, including, where applicable, your username, name, business email and other personal information. Please see the Our Use of Cookies and Other Tracking Mechanisms section below for more information.
G. How We Use Your Information
We use your information, including your personal information, for the following purposes:
- To provide our Services, to communicate with you about your use of our Site or Services, to respond to your inquiries, and for other customer service purposes.
- To tailor the content and information that we may send or display to you, to offer location customization, and personalized help and instructions, and to otherwise personalize your experiences while using the Site.
- For marketing and promotional purposes. For example, we may use your information, such as your email address, to send you a welcome email, news, and newsletters when your organization subscribes to our programs, special offers, and promotions, or to otherwise contact you about products or information we think may interest you.
- To better understand how users access and use our Site, both on an aggregated and individualized basis, in order to improve our Site and respond to user desires and preferences, and for other research and analytical purposes.
- To administer surveys and questionnaires.
- To administer our customer contracts. For example, we will use a customer's employee's contact information to send our invoices or to send service communications to.
- To comply with applicable legal or regulatory obligations, including as part of a judicial proceeding; to respond to a subpoena, warrant, court order, or other legal processes; or as part of an investigation or request, whether formal or informal, from law enforcement or a governmental authority.
- To protect the safety, rights, property, or security of Apexus, our services, any third party, or the general public; to detect, prevent, or otherwise address fraud, security, or technical issues; to prevent or stop activity that Apexus, in its sole discretion, may consider to be, or to pose a risk of being, an illegal, unethical, or legally actionable activity; to use as evidence in litigation; to conduct audits; and to enforce this Policy or our Terms of Use.
H. How We Share Your Information
We share your information, including personal information, as follows:
- Affiliates. We may disclose the information we collect on the Site to our affiliates for the purposes described in this Policy; however, if we do so, their use and disclosure of your personal information will be subject to this Policy.
- Other Providers. We may disclose the information we collect from you to third-party vendors, service providers, contractors or agents who perform functions on our behalf. We also may share information provided to us by our clients to third parties as described in the charts in Sections K(i) and K(ii) below.
I. We also may disclose information in the following circumstances.
- Business Transfers. If we are or may be acquired by or merged with another company, if any of our assets are transferred to another company, or as part of a bankruptcy proceeding, we may transfer the information we have collected from you to the other company.
- In Response to Legal Process. We also may disclose the information we collect from you in order to comply with the law, a judicial proceeding, court order, or other legal processes, such as in response to a court order or a subpoena.
- To Protect Us and Others. We also may disclose the information we collect from you where we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of our Terms of Service or this Policy, or as evidence in litigation in which Apexus is involved.
- Aggregate and De-Identified Information. We may share aggregate or de-identified information about users with third parties for marketing, advertising, research or similar purposes.
J. Children’s Privacy.
Our Site is not directed to children under the age of sixteen (16), nor do we market products or services to such children. We request that children (or a parent acting on a child’s behalf) do not provide personally identifiable information through our Site. We do not knowingly collect, share, or sell Personal Information from children under sixteen (16) without parental consent. Nor do we sell or share the personal information of consumers if we have actual knowledge that the consumer is less than sixteen (16) years of age, unless the consumer, in the case of consumers at least thirteen (13) years of age and less than sixteen (16) years of age, or the consumer’s parent or guardian, in the case of consumers who are less than thirteen (13) years of age, has affirmatively authorized the sale or sharing of the consumer’s personal information.
K. Notices to and Rights of California Consumers The following information is provided for the benefit of California Consumers, including Apexus job applicants, employees, directors, officers, and contractors who meet the definition of a Consumer under the CCPA/CPRA. Apexus collects, stores, processes, and retains the Personal Information of California Consumers in accordance with this Section L.
(i) Categories of Personal Information Apexus has Sold or Shared for a Business Purpose in the Last Twelve (12) Months
The following table summarizes (a) the categories of Personal Information/Sensitive Personal Information that Apexus collected, (b) the categories of sources from which Personal Information/Sensitive Personal Information was collected, (c) the business purpose for collection, (d) the categories of third parties with whom Apexus has shared or sold Personal Information/Sensitive Personal Information, and (e) the associated retention period for each category of Personal Information/Sensitive Personal Information for the preceding twelve (12) months. As reflected in this table, we may sell or share your Personal Information/Sensitive Personal Information with a variety of outside entities.
Please note, Apexus’s ongoing collection, purposes for collection or use, sharing, selling, and retention of Personal Information/Sensitive Personal Information are performed in accordance with the disclosures in the table below.
Category of Personal Information Collected | Categories of Sources | Commercial/Business Purpose for Collection | Is the Personal Information Sold or Shared? | Categories of Third Parties with Whom Apexus Sold or Shared PI |
---|---|---|---|---|
Identifiers Examples: Full name, email address, phone number, account login, IP address |
You; service providers; and other tracking technologies on our website | Processing or fulfilling transactions; debugging to identify and repair errors that impair existing intended functionality; providing internal analytic services; providing Customer services; protecting against malicious, deceptive, fraudulent or illegal activity | Yes | Service providers; payment processors; third parties that assume control over all or part of the business in connection with a merger, acquisition, bankruptcy, or similar event; affiliates, professional advisors; law enforcement authorities; those involved in legal proceedings, with consent. |
Internet and other network activity Example:Browsing activity |
You, Your mobile devices and computers used to access our Site | Marketing, customer, or analytic services; enabling or effecting, directly or indirectly, a commercial transaction | Yes | Vendors such as medical services providers, third-party marketers, cloud providers, and service providers in the online advertising industry. |
Commercial Activity Examples: Information about goods or services purchased, obtained, or considered |
You, Your mobile device and computers used to access our site | Processing or fulfilling orders and transactions; marketing, customer or analytic services | Yes | Vendors such as health care providers and systems, health care service providers, data aggregators, third-party marketers, cloud providers, service providers in the online advertising industry and other suppliers to the health care industry. |
Professional or Employment-related Information Examples: Job history, educational history |
Applicants; corporate customers; and outside sources, such as credit bureaus. (e.g. National Practitioner Identifiers (NPIs), Drug Enforcement Administration (DEA) Numbers, office locations and addresses collected from our customers, governmental sources and health care claims aggregators | Process and evaluate applications for positions with Apexus; facilitate administrative purposes, such as payments to contractors, marketing, customer or analytic services; provide services for customers’ health care operations | Yes | Service providers, such as HR vendors or cloud providers; Personal information including professional and employment related information of practitioners is provided to customers in the health care industry, including health care providers and systems, data aggregators in the health care industry, pharmaceutical manufacturers and other suppliers to the health care industry. These third party transfers may be considered sales of data under the CCPA. |
Social Security, Drivers License, State Identification Card, or Passport Number | Employment applications, resumes, HR documents, email, phone correspondence, documentation completed throughout the application and employment terms | Performing services on behalf of the business | No | N/A |
Account Login, in combination with the required security or access code, password, or credentials allowing access to an account | Apexus HR, Apexus IT Security | Performing services on behalf of the business, ensuring the security and integrity, undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Apexus, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Apexus | No | N/A |
Geolocation Data | Apexus IT Security | Performing services on behalf of the business, ensuring the security and integrity, undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Apexus, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Apexus | No | N/A |
Medical Information or Health Insurance Information | Apexus’s employee health insurance plan documentation and associated forms, employee health applications | Performing services on behalf of the Apexus, or service provider, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, providing storage, or providing similar services. Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business. | No | N/A |
Personal information collected and analyzed concerning a consumer’s sex life or sexual orientation | Apexus’s employee health insurance plan and associated forms, employee health applications | Performing services on behalf of the Apexus, or service provider, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, providing storage, or providing similar services. Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business. | No | N/A |
Biometric Information Examples: Image and video recording |
Security systems, HR Documentation, IT Security | Helping to ensure security and integrity to the extent the use of the consumer’s personal information is reasonably necessary and proportionate for these purposes. Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business. | No | N/A |
(ii) (ii) Categories of Personal Information Apexus has Disclosed for a Business Purpose in the Last Twelve (12) Months
The following table summarizes (a) the categories of Personal Information that Apexus collected, (b) the categories of sources from which Personal Information was collected, (c) the business purpose for collection, (d) the categories of third parties with whom Apexus has disclosed Personal Information, (e) the categories of third parties with whom Apexus discloses Personal Information, and (f) the associated retention period for each category of Personal Information over the preceding twelve (12) months. As reflected in this table, we may disclose your personal information to a variety of outside entities.
Please note, Apexus’s ongoing collection, use, disclosure, and retention of Personal Information are performed in accordance with the disclosures in the table below.
Category of Personal Information Collected | Categories of Sources | Commercial/Business Purpose for Collection | Is the Personal Information Disclosed to third parties? | Categories of Third Parties with Whom Apexus Disclosed PI | Categories of Third Parties with Whom Apexus Discloses PI |
---|---|---|---|---|---|
Identifiers Examples: Full name, email address, phone number, account login, IP address |
You; service providers; and other tracking technologies on our website | Processing or fulfilling transactions; debugging to identify and repair errors that impair existing intended functionality; providing internal analytic services; providing Customer services; protecting against malicious, deceptive, fraudulent or illegal activity | Yes | Service providers; payment processors; third parties that assume control over all or part of the business in connection with a merger, acquisition, bankruptcy, or similar event; affiliates, professional advisors; law enforcement authorities; those involved in legal proceedings, with consent. | Service providers; payment processors; third parties that assume control over all or part of the business in connection with a merger, acquisition, bankruptcy, or similar event; affiliates, professional advisors; law enforcement authorities; those involved in legal proceedings, with consent. |
Internet and other network activity Example: Browsing activity |
You, Your mobile devices and computers used to access our Site | Marketing, customer, or analytic services; enabling or effecting, directly or indirectly, a commercial transaction | Yes | Vendors such as third-party marketers, cloud providers, and service providers in the online advertising industry. | Vendors such as medical services providers, third-party marketers, cloud providers, and service providers in the online advertising industry. |
Commercial Activity Examples: Information about goods or services purchased, obtained, or considered |
You, Your mobile device and computers used to access our site | Processing or fulfilling orders and transactions; marketing, customer or analytic services | Yes | Vendors such as health care providers and systems, health care service providers, data aggregators, third-party marketers, cloud providers, service providers in the online advertising industry and other suppliers to the health care industry. | Vendors such as health care providers and systems, health care service providers, data aggregators, third-party marketers, cloud providers, service providers in the online advertising industry and other suppliers to the health care industry. |
Professional or Employment-related Information Examples: Job history, educational history |
Applicants; corporate customers; and outside sources, such as credit bureaus. (e.g. National Practitioner Identifiers (NPIs), Drug Enforcement Administration (DEA) Numbers, office locations and addresses collected from our customers, governmental sources and health care claims aggregators | Process and evaluate applications for positions with Apexus; facilitate administrative purposes, such as payments to contractors, marketing, customer or analytic services; provide services for customers’ health care operations | Yes | Service providers, such as HR vendors or cloud providers. As part of its Services, Personal information including professional and employment related information of practitioners is provided to customers in the health care industry, including health care providers and systems, data aggregators in the health care industry, pharmaceutical manufacturers and other suppliers to the health care industry. These third party transfers may be considered disclosures of data under the CCPA. | Service providers, such as HR vendors or cloud providers. As part of its Services, Personal information including professional and employment related information of practitioners is provided to customers in the health care industry, including health care providers and systems, data aggregators in the health care industry, pharmaceutical manufacturers and other suppliers to the health care industry. These third party transfers may be considered disclosures of data under the CCPA. |
Social Security, Drivers License, State Identification Card, or Passport Number | Employment applications, resumes, HR documents, email, phone correspondence, documentation completed throughout the application and employment terms | Performing services on behalf of the business | Yes | Service providers, such as HR vendors or cloud providers | N/A |
Account Login, in combination with the required security or access code, password, or credentials allowing access to an account | Apexus HR, Apexus IT Security | Performing services on behalf of the business, ensuring the security and integrity, undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Apexus, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Apexus | No | N/A | N/A |
Geolocation Data | Apexus IT Security | Performing services on behalf of the business, ensuring the security and integrity, undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Apexus, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Apexus | No | Service providers such as cloud providers, security auditors, or IT consultants | N/A |
Medical Information or Health Insurance Information | Apexus’s employee health insurance plan documentation and associated forms, employee health applications | Performing services on behalf of the Apexus, or service provider, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, providing storage, or providing similar services. Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business. | Yes | Service providers such as medical providers, medical services providers, payment processors | Service providers such as medical providers, medical services providers, payment processors |
Personal information collected and analyzed concerning a consumer’s sex life or sexual orientation | Apexus’s employee health insurance plan and associated forms, employee health applications | Performing services on behalf of the Apexus, or service provider, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, providing storage, or providing similar services. Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business. | Yes | Service providers such as medical providers, medical services providers, payment processors | Service providers such as medical providers, medical services providers, payment processors |
Biometric Information Examples: Image and video recording |
Security Systems, HR Documentation, IT Security | Helping to ensure security and integrity to the extent the use of the consumer’s personal information is reasonably necessary and proportionate for these purposes. Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business. | Yes | Service providers, such as HR vendors or cloud providers | Service providers, such as HR vendors, security auditors, or cloud providers |
(iii) Data Retention
Apexus retains each category of Personal Information for the time period required to fulfill the business purpose for which it was collected and to conduct the activities contemplated in this Privacy Policy, unless a different retention period is required by applicable law, or to otherwise fulfill a legal obligation or protect our legal rights. Our data retention policy is designed to retain data for as long as needed for us to comply with our contractual obligations, employment obligations, and other business purposes, including legal obligations to retain data. We may retain some information from closed accounts so that we can comply with law, prevent fraud, assist with investigations, resolve disputes, analyze or troubleshoot programs, enforce our Terms of Use, or take other actions permitted by law.
(iv) Sale of Personal Information.
Except as specified in this Section 3.K., for each of the Categories of Personal Information Collected above, we do not sell your Personal Information for money, but we and our business partners use tracking technologies to help us understand our customers and visitors use of the Services, enhance your online experience, and customize our offerings in ways that may be deemed a “sharing” or "sale" of personal information under the CCPA. This includes working with third parties, such as ad networks, which collect personal information via tracking technologies to serve personalized advertisements on and off our Services, provide us with data collection, reporting, and ad response measurement. To the extent we or our partners use such technologies on the Services, we offer an opt-out as discussed below.
(v) Consumer Rights.
If you are a California Consumer as defined by the CCPA and CPRA, you have the certain rights with regard to your personal information, including (a) the right to know what personal information we collect about you and access such information, (b) the right to know what personal information is sold or shared, and to whom, (c) the right to correct inaccurate personal information, (d) the right to delete your personal information, (e) the right to opt-out of the sale or sharing of your personal information, (f) the right to limit the use and disclosure of sensitive personal information, and (g) the right to no retaliation following opt-out or exercise of other rights.
To exercise these rights and choices, please follow the instructions below:
- How to request the right to know: You may request to know the (i) categories of personal information we have collected about you; (ii) categories of sources from which your personal information is collected; (iii) business or commercial purpose for collecting, selling, or sharing personal information; (iv) the categories of third parties to whom we disclose personal information; (v) the specific pieces of personal information we have collected about you. Please note, this information is available in Sections 3.K.(i)-(ii) of this Privacy Policy. You may exercise your right to know twice in a 12-month period. To do so, please complete the online form by clicking here or calling 1-800-842-5146. The Right to Know Report will be delivered by mail or electronically at your request. Note, we may not always be able to fully address your request; for example, if it would impact the duty of confidentiality we owe to others, or if we are legally entitled to deal with the request in a different way.
- How to request access to your personal information: You may request access to your personal information twice in a 12-month period. You may request (i) the categories of personal information Apexus has collected about you; (ii) the categories of sources from which the personal information is collected; (iii) the business or commercial purpose for collecting, selling, or sharing personal information; (iv) the categories of third parties to whom the business discloses personal information; (v) the specific pieces of personal information Apexus has collected about you. To do so, please complete the online form by clicking here or calling 1-800-842-5146. The Access Report will be delivered by mail or electronically at your request. Note, we may not always be able to fully address your request; for example, if it would impact the duty of confidentiality we owe to others, or if we are legally entitled to deal with the request in a different way.
- How to request the right to know what personal information is sold or shared and to whom: You may request to know the (i) the categories of personal information we have collected about you, (ii) the categories of personal information about you that we have sold or shared and the categories of third parties to whom your personal information was sold or shared, by category or categories of personal information for each category of third parties to whom the personal information was sold or shared, (iii) the categories of your personal information we have disclosed for a business purpose and the categories of persons to whom it was disclosed. To do so, please complete the online form by clicking here or calling 1-800-842-5146.
- How to correct inaccurate Personal Information: You may request that Apexus correct inaccurate Personal Information we’ve collected about you. Apexus will use commercially reasonable efforts to correct the inaccurate Personal Information as directed by you, taking into account the nature of the personal information and the purposes of the processing of the personal information. To do so, please complete the online form by clicking here or calling 1-800-842-5146.
- How to request deletion of your personal information: You may request that Apexus delete the personal information it has collected and/or maintained about you. To do so, please complete the online form by clicking here or calling 1-800-842-5146. Upon receipt of a verifiable consumer request to delete your personal information, except as otherwise permitted by law, we will delete your personal information from our records, notify any service providers or contractors to delete your personal information, and notify all third parties to whom we have sold or shared your personal information to delete your personal information unless it proves impossible or involves disproportionate effort. Note, we may retain certain personal information as permitted by law, such as to complete the transaction for which the personal information was collected, provide a requested good or service, detect security incidents, protect against malicious, deceptive, fraudulent or illegal activities, comply with legal obligations or to enable solely internal uses that are reasonably aligned with your expectations or lawful within the context in which you provided the information.
- How to opt-out of the sale or sharing of personal information: You, or a person authorized by you, have the right to opt-out of the sale or sharing of your personal information. At any time, you may direct Apexus not to sell or share your Personal Information. We also offer an opt-out from the use of cookies and other tracking technologies in connection with our Services, which may in some cases constitute the sale of your personal information under the CCPA/CPRA or other privacy laws. To do so, please complete the online form by clicking our Do Not Sell or Share My Personal Information link or calling 1-800-842-5146. For cookies, this will cause information to cease to be added to any cookies or other tracking technologies that have been set on our Services or block them entirely; for our other programs, Apexus will cease providing your personal information to third parties. Please note that, as to cookies, you will need to opt out again if you visit one of our Services from a different device or browser of if you clear your cookies.
- Right to Limit Use and Disclosure of Sensitive Personal Information: You have the right, at any time, to direct Apexus to limit the use of your sensitive personal information to those uses that (i) are necessary to perform the services or provide the goods as reasonably expected by an average consumer who requests those goods or services; (ii) help ensure security and integrity to the extent the use of your personal information is reasonably necessary and proportionate to that purpose; (iii) are short term, transient use, including, but not limited to, non-personalized advertising as a part of your current transaction with Apexus, provided that your personal information is not disclosed to another third party and is not used to build a profile about you or otherwise alter your experience outside your then current interaction with Apexus; (iv) are necessary to perform services on behalf of Apexus, including maintaining or servicing accounts, providing customer service, processing and fulfilling orders and transactions, verify customer information, process payment, provide financing, provide analytic services, provide storage, or provide similar services on behalf of Apexus; or (v) are undertaken to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Apexus, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Apexus.
- Right to Non-Discrimination: You have the right to be free from discrimination in product quality, goods or services if you choose to exercise your privacy rights under the CCPA or CPRA. Apexus will not deny you goods or services, charge different prices or rates for goods or services, or retaliate against an employee, applicant, or independent contractor as a result of exercising any rights described in this Privacy Policy. Notwithstanding the above, Apexus may charge you a different price or rate, may provide a different level of quality or goods, or may not be able to provide certain goods or services if your personal information is required for such goods or services and you elect not to provide such personal information.
(vi) Responses to Requests from California Consumers.
We reserve the right to charge a fee where permitted by law, for instance, if your request is manifestly unfounded or excessive. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Verification: Please note, we will take steps to verify your identity before fulfilling any of the above requests. We will request a copy of your identification with your California residency as well as request you to verify through an authentication e-mail. We may also require other authentication that is reasonable in light of the nature of the personal information requested.
Authorized Agents: Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your or your minor child's personal information. In order to designate an authorized agent to make a request on your behalf, you or your authorized agent must provide written proof that you have consented to this designation unless the agent has power of attorney pursuant to California Probate Code sections 4000-4465. If you are submitting a request via an authorized agent, please direct your authorized agent to submit its attestation/power of attorney to Apexus using the email CCPACompliance@vizientinc.com. You must also verify your identity directly with us by providing a copy of your government issued identification.
Response Timing and Format: We will respond to a verified consumer request for personal information within 45 days of receipt. If we require more time (up to 90 days), we will notify you of the reason and extension period in writing. Disclosure of required information will be made in writing and delivered to you through your account with Apexus, if you maintain an account with Apexus, or by mail or electronically at your election, in a readily usable format that allows you to transmit the information from one entity to another without hindrance. The disclosure of the required information will cover the twelve (12) month period preceding Apexus’s receipt of your verified request provided that, you may request that Apexus disclose the required information beyond the twelve (12) month period and Apexus will provide that information unless doing so proves impossible or would involve disproportionate effort. Your right to request information beyond the twelve (12) month period shall only apply to personal information collected on or after January 1, 2022.
Do Not Track: Your browser may deliver a "Do-Not-Track ('DNT') signal" to this Site. We will honor a "Do-Not-Track" signal as a valid opt-out request.
L. Our Use of Cookies and Other Tracking Mechanisms
We and our third-party service providers may use cookies and other tracking mechanisms to track information about your use of our Site.
Disabling Cookies. Most web browsers automatically accept cookies, but if you prefer, you can edit your browser options to block them in the future. The Help portion of the toolbar on most browsers will tell you how to prevent your computer from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether.
Service Provider Analytics. We use automated devices and applications, such as Google Analytics, to evaluate usage of our Site. We also may use other analytic means to evaluate our Site. We use these tools to help us improve our Site, performance, and user experiences. These entities may use cookies and other tracking technologies to perform their services. To learn more about Google's privacy practices, please review the Google Privacy Policy. You can also download the Google Analytics Opt-out Browser Add-on to prevent their data from being used by Google Analytics.
4. Third-Party Links
Our Site may contain links to third-party websites. Any access to and use of such linked websites is not governed by this Policy but instead is governed by the privacy policies of those third-party websites. We are not responsible for the information practices of such third-party websites.
5. Security of My Personal Information
We have implemented reasonable security measures to protect the information we collect from unauthorized access, exfiltration, theft, loss, misuse, disclosure, alteration, or destruction. Please be aware that despite our best efforts, no data security measures can guarantee security.
You should take steps to protect against unauthorized access to your password, phone, and computer by, among other things, signing off after using a shared computer, choosing a robust password that nobody else knows or can easily guess, and keeping your log-in and password private. We are not responsible for any lost, stolen, or compromised passwords or for any activity on your account via unauthorized password activity.
6. Additional Choices
Promotional Emails
We may send periodic promotional emails to you. You may opt-out of such promotional emails by following the opt-out instructions contained in the email. Please note that it may take up to 15 business days for us to process such opt-out requests. If you opt-out of receiving promotional emails, we may still send you emails about your account or any services you have requested or received from us.
7. Contact Us
If you have questions, comments, or concerns about the privacy aspects of our Site or if you have a disability and need access to this privacy/legal policy, please email us at legalprivacynotice@apexus.com, or call us at 1.800.842.5146. If you are a California consumer exercising one of your rights under CCPA, you may call us at 1.800.842.5146 or contact us at CCPACompliance@apexus.com.
8. Changes to this Policy and Terms of Use
This Policy and Terms of Use is current as of the Effective Date set forth above. We may change this Policy from time to time, so please be sure to check back periodically. We will post any changes to this Policy or our Terms of Use on our Site.