Privacy Policy

We at What's In It, LLC. doing business as "WINIT CLINIC" and "WINIT" are committed to safeguarding your privacy. This Notice outlines how we collect, use, maintain, protect, and disclose information from and about you ("you" or "your") when you interact with our websites, mobile applications, social media networks, interactive features, and other services (collectively, our "Platforms"). Like most other platforms, our Platforms utilize cookies and other technologies to enhance user experience and gather information.  

Our Platforms are designed for users within the United States. Individuals outside the United States should refrain from using our Platforms. By using our Platforms, you acknowledge and agree that your information may be processed, transferred, or maintained outside of your jurisdiction, subject to laws that may be less stringent than those in your location. Residents of California or Virginia possess certain rights as described in Section 4 of this Notice.

If you access our Platforms in connection with services governed by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) or similar state laws concerning health information privacy, such as California's Confidentiality of Medical Information Act or Virginia Code § 32.1-127.1:03, please review our HIPAA Notice of Privacy Practices for details on how we handle such health information.

Any terms defined in WINIT’s Terms of Use hold the same meaning herein. By using our Platforms linked to those terms, you consent to the collection and use of personal information in accordance with this Notice and the terms linked by the Platforms.

1. INFORMATION WE COLLECT ABOUT YOU AND HOW WE COLLECT IT

We gather information about you through various means when you use our Platforms, including both personal and non-personal data. "Personal Information" refers to any information that may directly or indirectly identify a particular individual or household.

Examples of Personal Information we may collect, its sources, purposes, and disclosures are outlined below:

Type of Information

Sources of Information

Purposes for Collection

Disclosures for Business Purpose

Parties Disclosed to for Business Purpose

Identifiers (e.g., legal name, email address, phone number)

Direct interactions via Platforms, phone, email, web forms, and social media

For provision of products/services and internal operations

Yes

Service providers, marketing partners, affiliates, and entities providing direct services

Financial information (e.g., credit card details)

Direct interactions via Platforms, phone, email, social media, subsidiaries, affiliates, and third parties

For transactions, scheduling, and internal use

Yes

Service providers, affiliates

Commercial information (e.g., purchase history)

Platforms, cookies, third parties, affiliates

For internal and marketing purposes

Yes

Service providers, analytics, marketing partners

Internet or electronic network activity information (e.g., browsing history)

Platforms (websites, apps, social media), cookies

For internal and marketing purposes

Yes

Service providers, analytics, marketing partners

Geolocation data

Platforms, for proximity services

For internal, marketing, and operational purposes

Yes

Service providers, marketing partners, operational third parties

Inferences from collected data (e.g., consumer preferences)

Direct interactions, cookies, third parties

For targeted marketing and internal reporting

Yes

Service providers, marketing partners, operational third parties

Professional/employment-related information

Direct interactions, service providers

For employment processing and internal use

Yes

Service providers, potential employers (with consent or where permitted)

Employee information

Direct interactions with employees

For employment-related purposes

Yes

Service providers, operational third parties

Sensitive personal information (e.g., health data)

Direct interactions with users and employees

For internal reporting and marketing

Yes

Service providers, analytics, marketing partners

We do not consider Personal Information to include data that cannot identify a specific individual, even when combined with other information (e.g., de-identified or aggregated data).

Children’s Privacy

Our Platforms do not knowingly collect Personal Information from individuals under 18 years old, unless under the account of a direct parent or guardian. By independently using our Platforms, you affirm that you are 18 or older. We cannot effectively verify your age so we depend on your accurate age verification.  

Securing Your Information

We employ measures to secure your Personal Information from unauthorized access, alteration, or disclosure. All data is stored on secure servers behind firewalls. Payment transactions are encrypted, and passwords are safeguarded. While we strive to protect your data, transmission via the Internet cannot be entirely secure. Use caution when sharing information in public areas of the Platforms.

Retention of Your Information

We retain Personal Information for legitimate business purposes and legal obligations. This includes data backup retention. These retention practices apply to all categories of Personal Information in use. Your protected health information is specifically handled in compliance with applicable laws that pertain to that data.

2. HOW WE USE YOUR INFORMATION FOR BUSINESS PURPOSES

We utilize your Personal Information as outlined in this Notice or as disclosed before processing. This includes:

  • Providing requested services or product

  • Administering Platform features

  • Sending notices about your account

  • Enforcing contractual obligations

  • Notifying you of Platform changes or offerings

  • Sending marketing emails

  • Responding to inquiries

  • Enabling interactive Platform features

  • Personalizing user experiences

  • Enhancing Platform functionality

  • Tracking Platform usage

  • Conducting research and reporting

  • Improving security measures

  • Ensuring legal compliance

  • Protecting against fraud or threats

  • Other disclosed purposes

We may also contact you about our or third parties' services/products of interest. To opt out of third-party communications, email us at [email protected].

We may use collected data to facilitate targeted advertising, with your consent.

3. PERSONAL INFORMATION SHARING AND DISCLOSURE

We do not sell Personal Information. However, we may share or disclose Personal Information as follows:

  • Laboratory testing, clinician, telehealth, or pharmacy services

  • Within our corporate entities

  • In corporate transactions

  • When required by law

  • With service providers

  • For website tracking

  • Integration with third-party platforms

  • With third-party advertisers

  • For targeted advertising

You may opt in or out of targeted advertising via our Platforms.

We do not currently respond to "do not track" signals.

4. NOTICE TO RESIDENTS OF CERTAIN STATES

A. Rights for California Residents (under Civil Code Section 1798.83 and CCPA) and Residents of Colorado, Connecticut, Utah, and Virginia

Residents of California, Colorado, Connecticut, Utah, or Virginia have rights outlined in this Notice. To exercise these rights, contact us at [email protected].

B. Right to Know about Personal Information

Applicable Residents have the right to request disclosure of collected, shared, or sold Personal Information. To request, email [email protected]. We'll verify your identity and respond within statutory timelines.

For further details, consult the specific state's regulations.

C. Other Rights

Applicable Residents have additional rights under respective state laws concerning Personal Information. Contact us for information on exercising these rights.

We are committed to transparency and compliance with applicable privacy regulations.

D. The Right to Access and Receive your Specific Personal Information

Applicable Residents have the right to request that we provide a portable copy of the Personal Information we collect, use, disclose, and sell. You can request a listing of the types of Personal Information we have collected about you, the sources of that information, how we use the information (e.g., our business or commercial purposes for collecting or selling Personal Information), other individuals and business with whom we share Personal Information, and the specific pieces of Personal Information that we have collected about you. When you make a request for a portable copy of your information, you can expect the following:

  • We will verify your identity based upon information that you previously have provided. Where possible, we will use information we already hold about you in order to confirm that you are who you say you are.

  • We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at the webpage or phone number listed above.

  • We will respond to your request within 45 days of receipt of the request, if possible. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why.

In certain cases, a request for access may be denied, for example, if we cannot verify your identity. If we deny your request, we will explain why we denied it.

E. You have a Right to Request Deletion of Personal Information about You

Applicable Residents have a right to request the deletion of their Personal Information collected or maintained by us. If you would like information about you to be deleted, you may request deletion through [email protected]. When you make a request for deletion, you can expect the following:

  • After you submit a request deletion, you will need to confirm that you want your information deleted. We will verify your identity based upon information that you previously have provided. Where possible, we will use information we already hold about you in order to confirm that you are who you say you are.

  • We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at the webpage or phone number listed above.

  • We will respond to your request within 45 days of receipt of the request, if possible. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why.

In certain cases, a request for deletion may be denied, for example, if we cannot verify your identity, the law requires that we maintain the information (e.g., in case of certain tests) or if we need the information for internal purposes such as ongoing research. If we deny your request, we will explain why we denied it, treat your request as an "opt-out" of the sale of information (as described in our Notice of Right to Opt-Out), and delete any other information that is not protected from deletion.

F. Right to be Forgotten:

You have the right to request the erasure of your personal data held by us without undue or unreasonable delay. We will fulfill this request where one of the following grounds applies:

  • Your personal data is no longer necessary for the purposes for which it was collected or used.

  • You object or withdraw your consent for use of your Personal Information, and there is no other legal ground for its use. 

  • Your personal data has been unlawfully used.

  • Your personal data must be erased to comply with a legal obligation.

If we have made your personal data public and are obliged to erase it, we will take reasonable steps to inform other parties using your data to erase any links to, or copies or replications of that data.

G. You may have a Right to Request the Correction of Inaccurate Personal Information about You

Applicable Residents may also have the right to request the correction of inaccurate Personal Information collected or maintained by us. If you would like information about you to be corrected, you may request correction through the contact information at [email protected]. When you make a request for correction, you can expect the following:

  • After you submit a request for correction, you will need to confirm what information is incorrect and requires correction. We will verify your identity based upon information that you previously have provided. Where possible, we will use information we already hold about you in order to confirm that you are who you say you are.

  • We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at the webpage or phone number listed above.

  • We will respond to your request within 45 days of receipt of the request, if possible. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why.

In certain cases, a request for correction may be denied, for example, if we cannot verify your identity. If we deny your request, we will explain why we denied it.

H. Residents of California, Colorado, Connecticut, Utah and Virginia have a Right to Opt-Out of the Sale of Personal Information or Sharing of Personal Information for Cross-Context 

Behavioral Advertising and other Specified Purposes; Residents of Nevada also have the Right to Opt-Out of the Sale of Personal Information

This Section also serves as a Notice to residents of the States of California, Colorado, Connecticut, and Utah and the Commonwealth of Virginia of their right to opt-out of the sale of Personal Information and of the use and/or disclosure of Personal Information for certain types of targeted advertising and consumer or household profiling.

Residents of California have a right to direct businesses not to sell or share their Personal Information for cross-context behavioral advertising. Colorado, Connecticut, Utah, and Virginia residents have the right to direct businesses not to process their personal data for purposes of (i) targeted advertising, (ii) selling or otherwise transferring personal data in exchange for monetary or other valuable consideration, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. Under Applicable State Data Protection Law, this is known as the “right to opt out”. In general, we will only use your Personal Information to perform services or provide the goods reasonably expected by you, internal reporting and analytics purposes, for other purposes in the ordinary course of business, and to facilitate more targeted marketing and analytics. We do not sell your Personal Information for monetary consideration.

However, when you visit our websites, we may share information about your use of our websites, including the specific health conditions, health care services and products you view, search for, or purchase, with certain advertising and/or analytics partners who retain the right to utilize that data for their own business purposes, which may include targeted advertising and/or profiling that produce legal or similarly significant effects concerning consumers. You can opt into, or out of, such sharing at any time by interacting with the cookie banner that may appear at the bottom of our websites the first time you come to the website or the Sharing Settings or Your Privacy Choices link that may appear in the footer of our websites.

Nevada law also gives Nevada consumers the right to request that a company not sell their Personal Information for monetary consideration to certain other parties.  This right applies even if their Personal Information is not currently being sold in that manner.  If you are a Nevada consumer and wish to exercise this right, please send an email with the subject line “Nevada Resident Do Not Sell Request” to [email protected].

I. Rights Regarding Use and Disclosure of Sensitive Personal Information

Sensitive personal information includes the “sensitive personal information” described in Section 1 of this Notice, such as your driver’s license number, national or state identification number, citizenship status, immigration status, race, national origin, religious or philosophical beliefs, sexual orientation, sex life, precise geolocation, information concerning your health, and genetic information.

In general, we will only use your sensitive personal information to perform services or provide the goods reasonably expected by you, for internal reporting and analytics purposes, for other internal purposes in the ordinary course of business, and to facilitate more targeted marketing and analytics.

However, when you visit our websites, we may share information about your use of our websites, including the specific health conditions, health care services and products you view, search for, or purchase, with certain advertising and/or analytics partners who retain the right to utilize that data for their own business purposes. Depending on where you live, Applicable Residents can either opt into, or out of, such sharing at any time by interacting with the cookie banner that may appear at the bottom of our websites the first time you come to the website or the Sharing Settings or Your Privacy Choices links that may appear in the footer of our websites.

J. You have a Right to Non-Discrimination/No Retaliation for the Exercise of a Consumer's Privacy Rights

You have a right not to receive discriminatory treatment by us for exercising any of your state’s consumer privacy laws. We will not discriminate against any consumer because such person exercised any of the consumer's rights under these privacy laws, including, but not limited to:

  • Denying goods or services.

  • Charging different prices or rates for goods and services, including through the use of discounts or other benefits or imposing penalties.

  • Providing a different level or quality of goods or services.

  • Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.


K. Your Right to Appeal

If we refuse to take action on any of the above rights, consumers who are residents of the states of Colorado, Connecticut and Virginia can appeal this decision by emailing us at [email protected]. Within 60 days of receipt of an appeal, we shall inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.

L. Authorized Agents

If you are a California resident and would like, you may designate an authorized agent to make a request under the CCPA on your behalf. If you are a Colorado or Connecticut resident, you may have a right to designate an authorized agent to make a request to opt out on your behalf. We will deny requests from agents that do not submit proof of authorization from you. To verify that an authorized agent has authority to act for you, we may require a copy of a power of attorney or require that you provide the authorized agent with written permission and verify your own identity with us.

M. Contact Information

To request additional information, or make any of the requests described above, you may contact us at [email protected] or via phone number at (323) 401-1535.

5. GEOGRAPHIC RESTRICTION

Our Platforms are intended for individuals who reside in the United States of America. We make no representations that our Platforms are appropriate or available for use outside of the United States. If you are a resident of another country, or are accessing the website from outside of the United States, please note that you are transferring data to the United States of America, which does not have the same data protection laws as the European Union and other regions.

6. CHANGES TO OUR PRIVACY NOTICE

From time to time, we may update this Notice. If we make changes, we will revise the “Last Updated” date at the bottom of this Notice. We encourage you to review this Notice periodically to be sure you are aware of those changes. Changes will become effective as of the “Last Updated” date.

7. CONTACT INFORMATION

To exercise your rights or ask questions regarding this Notice, you may contact us at any of the following:

Mail: Attn: WINIT Privacy Support, 4951 Indiana Ave., Ste. 400, Lisle, IL 60532

Email: [email protected]

Phone Number: (323) 401-1535

Last Updated: February 13, 2024