Last Updated: October 10, 2018
WHO WE ARE
We are Lyra Health, Inc., a company focused on helping people feel emotionally healthy at work and at home.As an employer-sponsored benefit that connects employees and their dependents with effective and convenient care for their mental and emotional well-being, we combine technology, research-backed therapeutic methods, and top providers to offer personalized care.
WHAT WE COLLECT
We get information about you in a range of ways.
Information You Give to Us or Lyra affiliated entities. We may collect your name, postal address, email address, phone number, username, password, demographic information (such as your gender and birth date) as well as other information you directly give us on our Site and/or through our Services.By providing us with an email address, you consent to receiving information from us by email to that address, including protected health information which is private to you and protected by HIPAA.
Information We Get From Your Lyra Benefit Sponsor. We may receive information from your Lyra benefit sponsor (typically your employer) to enable us to confirm you or your household member(s)’ eligibility for Lyra benefits, to contact you in order to inform you of the availability of the Lyra benefit, and to help us measure the effectiveness of the Lyra benefit.
Information Automatically Collected. We automatically log information about you and your computer, phone, tablet, or other devices you use to access the Site and/or Services. For example, when visiting our Site or when using the Company’s mobile applications, we log your computer or device identification, operating system type, browser type, browser language, the website you visited before browsing to our Site, pages you viewed, how long you spent on a page, access times and information about your use of and actions on our Site or in the Company’s mobile applications.How much of this information we collect depends on the type and settings of the device you use to access the Site and/or Services.
Cookies. We may log information using “cookies.” Cookies are small data files stored on your hard drive by a website. We may use both session Cookies (which expire once you close your web browser) and persistent Cookies (which stay on your computer until you delete them) to provide you with a more personal and interactive experience on our Site. Other similar tools we may use to collect information by automated means include web server logs, web beacons and pixels. This type of information is collected to make the Site and/or Services more useful to you and to tailor the experience with us to meet your special interests and needs.
California Do Not Track Disclosure. We currently do not support the Do Not Track browser setting or respond to Do Not Track signals. Do Not Track (or DNT) is a preference you can set in your browser to let the websites you visit know that you do not want them collecting certain information about you. For more details about Do Not Track, including how to enable or disable this preference, visit https://termsfeed.com/do-not-track.
If you choose to interact on the Site and/or through the Services (such as by registering; using our Services; completing questionnaires, surveys, service contacts, or requests for information) the Company will collect the personal information that you provide.We may collect personal information about you that you provide through telephone, email or other communications.If you provide us with personal information regarding another individual, we will assume that you have that person’s consent to give us his or her personal information.
USE OF PERSONAL INFORMATION
How we use the information we collect depends in part on which Services you use, how you use them, and any preferences you have communicated to us.Below are the specific purposes for which we use the information we collect about you.We use your personal information as follows:
We may combine all of the information that we collect with data obtained from third parties or through our products and Services.We may also collect and store information locally on your device using mechanisms such as browser web storage (including HTML 5) and application data caches.
Lyra will take reasonable precautions to protect your information from loss, misuse or alteration.Please be aware, however, that any text, email or other transmission you send unencrypted through the Internet cannot be completely protected against unauthorized interception.In particular, we want to make you aware that personal email may be unsecure, and Lyra cannot be responsible for any unauthorized access to information when information is sent to your personal email. You are not required to authorize the use of email for this purpose, a decision not to consent or to opt out of receiving these emails will not restrict your ability to access care from your provider, and you can continue to receive other emails from Lyra, using oursecure electronic communication system instead of your personal email. Our secure electronic communication system will require you to log into a separate portal to access the email that is being sent.
SHARING OF PERSONAL INFORMATION
Personally Identifiable Information: We will not rent or sell your personally identifiable information to others without your consent, although we may share it with partners for the purposes described above under “Use of Personal Information”, such as the provision and personalization of Services.For example, we may share your personal information with our contracted partners, such as Lyra Clinical Associates P.C., to provide you with Services, with third parties who help us with our business functions, such as payment processing or data storage, and with business partners.Such third parties are not authorized to use or disclose your information except as necessary to perform Services or comply with legal requirements, and are subject to agreements requiring them to maintain the confidentiality of any such information. If you seek treatment or other services from a clinical provider, such as Lyra Clinical Associates P.C. in its capacity as a health care provider, the use and disclosure of your health information in connection with such services will be governed by its separate HIPAA Notice of Privacy Practices, available at https://www.lyrahealth.com/hipaa-notice/. We also reserve the right to disclose personal data or other information that we believe, in good faith, is appropriate or necessary to (i) take precautions against liability, (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity, (iii) investigate and defend ourselves against any third-party claims or allegations, (iv) protect the security or integrity of the Service and any facilities or equipment used to make the Service available, or (v) protect our property or other legal rights, enforce our contracts, or protect the rights, property, or safety of others.
We may store personal information in North American locations outside our direct control (for instance, on servers or databases co-located with hosting providers). In the event that personal information is compromised as a breach of security, Lyra will promptly notify our customers, users, and clients in compliance with applicable law.We will retain personal data we process for as long as needed to provide our Services, and as recommended to comply with our legal obligations (including those under HIPAA), resolve potential or actual disputes, conduct research and development for our Services, or enforce our agreements.
Any personally identifiable information you elect to make publicly available on our Sites or through the Services, such as posting comments on our blog page, will be available to others. If you remove information that you have made public on our Sites or through the Services, copies may remain viewable in cached and archived pages of our Sites or through the Services, or if other users have copied or saved that information.
Non-Personally Identifiable Information: We may share non-personally identifiable information (such as anonymous usage data, referring/exit pages and URLs, platform types, number of clicks, etc.) with interested third parties to help us understand the usage patterns for certain Services and those of our partners. Lyra may also share with your Lyra benefit sponsor the outcomes and impact of our Services, which would consist solely of non-personally identifiable information, e.g., aggregated and anonymized data.Non-personally identifiable information may be stored indefinitely.
HOW INFORMATION IS STORED AND PROCESSED
Your information is stored in databases maintained by the Company or third parties that are located within North America, where privacy rules differ and may be less stringent than those of the country in which you reside.For E.U. residents, please note that we are not located in the E.U., nor do we collect or process the personal data of EU residents.As such, Lyra is neither a controller nor a processor under the EU’s General Data Protection Regulation (GDPR).
You should be aware that when you are on the Site and/or using our Services, you can be directed to other websites that are beyond our control, and we are not responsible for the privacy practices of third parties or the content of linked websites.
HOW INFORMATION IS PROTECTED
We are committed to protecting your privacy and data. We encrypt sensitive information (e.g. your login credentials, PII) during transmission and storage. We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected personal data breach and will notify you, other involved parties, and any applicable regulator(s) of a breach where we are legally required to do so.
However, no method of transmission over the Internet or method of electronic storage, is 100% secure. Therefore, we cannot guarantee its absolute security. If you have any questions about the security of our Services, you can contact us at firstname.lastname@example.org.
INFORMATION CHOICES AND CHANGES
Our marketing emails tell you how to “opt-out.” After doing so, you will not receive future promotional emails unless you open a new account, or sign up to receive newsletters or emails. If you opt out, we may still send you non-marketing emails. Non-marketing emails include emails about your accounts and our business dealings with you.
You may send requests about personal information to our Contact Information below or to email@example.com. You can request to change contact choices, opt out of our sharing with others, and update your personal information.
You can typically remove and reject cookies from our Site with your browser settings. Many browsers are set to accept cookies until you change your settings. If you remove or reject our cookies, it could affect how our Site works for you.
If you are a California resident, you have the right to request information from Lyra regarding the manner in which Lyra shares certain categories of your personal information with third parties, for the third parties’ direct marketing purposes. We do not share your personal information with third parties for third party marketing purposes.
Lyra Health, Inc.
205 Park Road
Burlingame, California 94010