Privacy Policy

CBTBUDDY.COM PRIVACY POLICY
Last modified: May 4th 2021

Introduction

FRED NOT FREUD, LLC, owner of the CBTBuddy.com mobile app, (“FNF” “Company” or “We”) is committed to protecting your privacy through this privacy policy (“Policy”). We comply with all federal and state laws and regulations relating to the privacy of our users’ private health information (PHI). This Policy describes the kinds of data we may process when you use FNF and our overall program for safeguarding, storing, processing, and sharing said data. If you oppose any portion of this Policy, you may not use the App. By accessing or using this App, you agree to this Policy and our Terms and Conditions. We may modify the Policy from time to time, such changes will be posted here. Please check the App regularly, as continued use of the App following the changes, will be deemed as though you agree to such changes. 

Where We Collect:

  • This policy applies to personal information (“PI”) we collect:
    • When you enroll and with your consent; and
    • in electronic messages between you and this App; 
  • It does not apply to information collected: Offline or via any other means such as publicly available or social media data.

Minors:

Our App is not aimed at minors under 18 years of age. Minors may use the App but only with the express prior written consent of their legal guardian or if they have a signed agreement with their therapist. A therapist who works with a minor through the app is responsible for consent. Such consent will be required every six (6) months. Otherwise, minors should not provide any PI to the App. We never intentionally collect PI from minor otherwise. Minors do not use this App or provide us with any PI without consent. If we learn we have unauthorized PI from a child, we will delete it. If you believe we have PI belonging to minors, please contact us at support@cbtbuddy.com. 

If you are a minor based in California, and a user of this App, California Business Code Sec. 22581 gives you rights such as to access or remove your PI. 

PI We Collect:

 We collect types of PI from and about our users, directly and indirectly:

  • Categories of PI: In the preceding 12 months, with consent we have collected, the following categories of PI:  
    • Identifiers: this includes name, address, telephone number, email address, and your FNF username and password.
    • Sensitive personal data such as health data.
    • Contact information of an emergency contact. 
    • Data Collected Automatically: Whether on an individual or aggregated basis.

How We Collect:

  • We collect this information:
  • By submitting PI on the App, you agree to our data processing, such as by: 
    • completing forms, requesting further services or other correspondence on our App, 
    • subscribing to our service, 

How We Use Data:

 We use PI you provide in any way we may describe prior to your provision of PI or to:

  • Present our App to you.
  • Answer your requests or fulfill any purpose for which you provide PI with consent.
  • Perform our duties and enforce our rights from agreements between you and us.
  • In any other way we may describe when you provide PI.
  • Research and analytics in de-identified form.
  • IT management, monitoring and data security including fraud detection and auditing.
  • Protect our privacy, safety, rights or property (we may use without consent within a court process) or similar rights of others and allow us to pursue remedies to limit damages. 
  • We may disclose suchif required or permitted by law such as to safeguard your rights, freedoms, and legitimate interests.
  • To independent auditors or consultants in order to carry out institutional risk control;
  • To agencies, including self-regulatory organizations

Data Recipients:

 We may disclose PI we have about you, as described herein, to third parties such as auditors or professional advisors. 

Choices On Use and Disclosure:

  • Accessing and Correcting Your Information:
    • We respond to data rights requests within a reasonable time. You can review and change your PI by emailing support@cbtbuddy.com with ample verification that it is in fact you responding. 
    • We cannot not delete your PI except by also deleting your account. We will not change PI if we believe it would violate any law or legal requirement or cause the data to be incorrect. Any deletion request will be governed by our retention policy.
  • Your Data Rights: 
  • Right to be Informed. The right to be informed about the processing of your PI. This Policy is designed to inform of how your data is processed and describe your rights.
  • Right of Access. You have the right to access your PI and supplementary data to be aware of and verify the lawfulness of processing.
  • Right to Rectification. You may have PI rectified if it is inaccurate or incomplete.
  • Right to Erasure. You have the right to request deletion or removal of your PI where there is no compelling reason for its continued processing unless it is considered essential for other retention purposes such as:
    • Complete the transaction you requested, take actions anticipated within our ongoing business relationship, or otherwise perform our contract with you.
    • Detect security, fraudulent, deceptive, or illegal activity, or prosecute for such.
    • Debug and repair errors that impair existing intended functionality.
    • Exercise free speech or another right for us or others.
    • Comply with the Electronic Communications Privacy Act.
    • Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
  • Right to Restrict. You have the right to block or suppress processing of your PI. 
  • Right to Data Portability. You have the right to obtain and reuse PI that can be clearly linked to you, for your purposes. We will send you a copy in a commonly used and machine-readable format.
  • Right to Object. You have the right to object when processing is based on legitimate interests, for the public interest, direct marketing, and for scientific research. 
  • Automated individual decision-making . You have the right not to be opined upon based solely on automated processing, including profiling. which produces legal or similarly significant effects. 
  • Right to make a complaint with a supervisory authority or seek a judicial remedy.
  • Request Fulfillment. We typically fulfill any such request without delay and no later than one month after its receipt. If we are not required to fulfill such or there is a delay, we will provide the rationale via email. Responses are provided free of charge, unless requests are patently unfounded or excessive, especially due to redundancy. You will never be discriminated against due to exercise of these rights or any others.

Data Security:

  • Security Program: We implemented administrative, technical and physical measures to secure your PI from accidental loss and unauthorized access, use, and disclosure, including HIPAA compliant encryption.. 
  • Your Duties: Security of your data also depends on you. You must keep your login credentials secure. Any transmission of PI is at your own risk. 
  • Our Duty: We are not responsible for bypassing of any privacy or security measures, or settings contained on the App.

Therapists:

 Though our App will connect you to your therapist we have no control over his or her privacy practices. Accordingly, we assume no liability for their data practices. We suggest that you review their policies, if any, prior to providing such with any information.‍

Contact Information:

 For questions or comments about this Policy contact us at: support@cbtbuddy.com

DPO: dpo@cbtbuddy.com

Retention:

  • When the need to process your PI ceases, we will either delete, de-identify or anonymize it, or, if not possible (i.e. as your PI has been stored in archives), we will securely store your PI and isolate it from any further processing until deletion is possible. 
  • Duration of Retention Examples:
    • When You Interact with Business Expansion Functions: We may retain PI as long as necessary to provide you with your request for information or other responses. 
    • Opening an Account: We may retain your PI for as long as your account is active, or to comply with our legal duties, preserve and protect our rights as allowed by law, resolve disputes, maintain security, prevent fraud and enforce our agreements.
  • Personal Data Retention Periods
    • Except as otherwise permitted or required by applicable law or regulation, we only retain PI for as long as necessary to fulfill its purpose, as required to satisfy any duties, or as necessary to resolve disputes. To determine the appropriate retention period for PI, we consider the amount, nature, and sensitivity of PI, potential risk of harm from unauthorized use or disclosure, the purposes, and any legal requirements. 
    • We typically retain PI for 6 months, subject to any exceptional circumstances or to comply with laws or regulations that require a specific retention period: