Skip to main content

Privacy Policy

Hero background
General Informations

General Informations

Last Updated: April 2026.

This Privacy Notice (“notice”) applies to the processing of personal data by Sofwave Ltd. (“Sofwave”, “we,” “us,” or “our”) on our website available at sofwave.com (“Website”), our mobile application (“App”), and our other related online or offline offerings which link to, or are otherwise subject to, this Privacy Notice (collectively, the “Services”).

It describes how we handle personal data about you when using our services globally. We apply a baseline set of privacy standards for all users, regardless of where they use our services from. However, as privacy laws vary significantly by territory, to ensure alignment with local requirements this notice is divided into 2 parts:

  • Our Global Privacy Notice. Sections 1-10 to this notice apply to all recipients and users of our Services worldwide and covers our general privacy practices.

  • Processing Under Specific Laws. Section 11 contains territory-specific supplements that apply only if such territory’s regulatory framework applies to our processing of personal data about you.

In this notice, the term “personal data” refers to any information that relates to an identified or identifiable individual, consumer, or household, and includes equivalent terms under laws and regulations governing the protection of privacy and personal data such as ‘personal data’; and “processing” refers to any action we perform on personal data, including collecting, using, retaining, and deleting it.

SPECIAL NOTE TO USERS INTERACTING WITH A SOFWAVE-CONTRACTED PROVIDER

Our services are available only to providers with a contractual relationship with Sofwave. If you engage directly with a Sofwave-contracted provider, this Privacy Notice does not apply to the protected health information collected, created, used, or shared pursuant to the Health Insurance Portability and Accountability Act, as amended (“HIPAA”). Any questions, rights requests, and/or concerns about your protected health information should be directed to your provider.

Index & Summary of this Notice

The summary below will give you a quick and clear view of our practices. Please take the time to read our entire Notice. If you disagree with this Privacy Notice, please do not access or use our Services.

Our General Privacy Notice

PERSONAL DATA WE COLLECT
We collect personal data that you provide to us, personal data we collect automatically when you use the Services, and personal data from third-party sources, as described below.
Personal data You Provide to Us Directly
We collect personal data that you provide to us:

  • Your Communications with Us. We, and our service providers, collect information you communicate to us, such as through email, the contact form on the Website or App, or via our web chat tool. Such information includes your contact details (name, email address, and phone number). If you provide us with sensitive personal data as part of communicating with us, we will only use it for the specific purpose for which you provided it (such as to connect you with a local medical professional).

  • Loyalty Programs. If you participate in our loyalty programs (for example PulsePal), we collect personal data related to your enrollment and participation, including your contact details, account information, transaction history, points or rewards balance, and preferences related to the program. We use this information to administer the program, track your participation, provide you with program benefits, and communicate with you about program updates and offers.

  • Transactions. If you subscribe to a paid account of the Services, or if you make purchases via the Services (for example: when you purchase pulses) we will receive your payment transaction details (such as your name, the amount paid, the date of payment, and other billing details) from the payment service provider that processed your payment. We do not receive or process the details of your credit card or other payment method that you use to pay for the Services.

  • Surveys. When we contact you to participate in surveys, if you decide to participate, we will collect personal data from you in connection with the survey, including your contact details and any information you choose to provide us as part of the survey.

  • Interactive Features. We and others who use our Services may collect personal data that you submit or make available through our interactive features (e.g., our Marketing Templates feature, messaging features, commenting functionalities, forums, blogs, and social media pages). Such information includes any information you choose to provide using the public sharing features of the Services, note that such information will be considered “public.”

  • Conferences, Trade Shows, and Other Events. We will collect personal data from individuals when we attend or host conferences, trade shows, and other events. Such information includes your contact information and any additional information you choose to provide us.

  • Business Development and Strategic Partnerships. We will collect personal data from individuals and third parties to assess and pursue potential business opportunities, including contact details, company information, business interests, professional background, and information relevant to potential partnerships or collaborations.

  • Job Applications. If you apply for a job with us, we will collect any personal data you provide in connection with your application, such as your contact details, CV, employment history, educational background, professional qualifications, references, and any other information included in your application materials.

Personal Data Collected Automatically

We collect personal data automatically when you use the Site:

  • Device Information. We collect personal data about your device, such as your Internet protocol (IP) address, user settings, cookie identifiers, other unique identifiers, browser or device information, Internet service provider, and location information (including, as applicable, approximate location derived from IP address and precise geo-location information). Such information includes device type, operating system, browser type and version, screen resolution, and mobile network information.

  • Usage Information. We may collect personal data about your use of the Services, such as the pages that you visit, items that you search for, the types of content you interact with, information about the links you click, the frequency and duration of your activities, and other information about how you use the Services.

  • Cookie Notice (and Other Technologies). We, as well as third parties, may use cookies, pixel tags, and other technologies (“Technologies”) to automatically collect personal data through your use of the Services. For more information about our use of such Technologies, please see our Cookie Notice.

Personal Data Collected From Third Parties

We process personal data about you that we receive from third parties, including our business partners, service providers, and publicly-available information. Depending on your interaction with our Services, such information includes: your full name, physical address, email address, place of employment, additional employment-related information and online identifiers. For example, if you access the Services using a third-party website, application, service, products, or technology (each, a “Third-Party Service”), we receive personal data about you from that Third-Party Service that you have made available via your privacy settings.

How We Use Personal Data

We use personal data for a variety of business purposes, including to provide the Services, to improve the Services, to improve our products and services, to develop new products and services, to operate our business, to provide you with marketing materials, and with your consent, as described below.

Provide the Site

We use personal data to fulfill our contract with you and provide the Services, such as:

  • Providing access to certain areas, functionalities, and features of the Services;

  • Answering requests for support;

  • Communicating with you;

  • Sharing personal data with third parties as needed to provide the Services; and

  • Processing your transaction details in connection with purchases you make on the Services.

Improve the Services, Improve our Products and Services, and Develop New Products and Services

We use personal data to improve the Services, to improve our products and services, and to develop new products and services.

Operate Our Business

  • Pursuing our legitimate business interests such as direct marketing, research and development (including marketing research), network and information security, and fraud prevention;

  • Carrying out analytics;

  • Creating de-identified and/or aggregated information;

  • Processing applications if you apply for a job we post on our Services;

  • Allowing you to register for events;

  • Enforcing our agreements and policies; and

  • Carrying out activities that are required to comply with our legal obligations.

Marketing

We disclose personal data to the categories of third parties described below.

  • Service Providers. We disclose personal data to third-party service providers that assist us with the provision of the Services. This includes service providers that provide us with hosting, customer service, analytics, marketing services, IT support, and related services. In addition, personal data and chat communications may be disclosed to service providers that help provide our chat features.

Such service providers include:

  • Google Analytics. For more information about how Google uses personal data about you, please visit Google Analytics’ Privacy Notice. To learn more about how to opt-out of Google Analytics’ use of personal data about you, please click here.

    • Hotjar. We use Hotjar’s session replay analytics services. This allows us to record and replay an individual’s interaction with the Services. For more information about how Hotjar uses personal data about you, please visit the “Personal Data collected from a visitor of a Hotjar Enabled Site” section of Hotjar’s Privacy Policy. To learn more about how to opt-out of Hotjar’s use of your information, please click here.

We make sure that our third-party service providers provide us with adequate confidentiality and security commitments, and we will take all steps reasonably necessary to ensure that personal data about you is treated securely and in accordance with this privacy notice.

  • Third-Party Services You Share or Interact With. Where the Services link to or allow you to interface, interact, share information with, direct us to share information with, access and/or use a Third-Party Service.

Any personal data shared with a Third-Party Service will be subject to the Third-Party Service’s privacy policy. We are not responsible for the processing of personal data by Third-Party Services.

  • Business Partners. We will share personal data about you with business partners to provide you with a product or service you have requested. We will also share personal data about you with business partners with whom we jointly offer products or services.

Once personal data is shared with our business partner, it’s processing will also be subject to our business partner’s privacy notice. We are not responsible for the processing of personal data by our business partners.

  • Affiliates. We will share personal data about you with our corporate affiliates.

  • Advertising Partners. We will share personal data about you with third-party advertising partners. These third-party advertising partners set Technologies and other tracking tools on our Services to collect information regarding your activities and your device (e.g., your IP address, cookie identifiers, page(s) visited, location, time of day). These advertising partners use this information (and similar information collected from other services) for purposes of delivering personalized advertisements to you when you visit digital properties within their networks. This practice is commonly referred to as “interest-based advertising”, “personalized advertising”, or “targeted advertising”.

Disclosures To Protect Us Or Others

We may access, preserve, and disclose any information we store associated with you to external parties if we, in good faith, believe doing so is required or appropriate to: comply with law enforcement or national security requests and legal process, such as a court order or subpoena; protect your, our, or others’ rights, property, or safety; enforce our policies or contracts; collect amounts owed to us; or assist with an investigation or prosecution of suspected or actual illegal activity.

Disclosure In The Event Of Merger, Sale, Or Other Asset Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, purchase or sale of assets, transition of service to another provider, or other similar corporate transaction, personal data about you may be disclosed, sold, or transferred as part of such a transaction.

Your Privacy Choices

We will give you choices about the ways we use and share personal data about you, and we will respect the choices you make.

  • Email Communications. If you receive an unwanted email from us, you can use the unsubscribe functionality found at the bottom of the email to opt out of receiving future emails. Note that you will continue to receive transaction-related emails. We may also send you certain non-promotional communications regarding us and the Services, and you will not be able to opt out of those communications (e.g., communications regarding the Services or updates to this Privacy Notice).

  • Text Messages. If you receive an unwanted text message from us, you may opt out of receiving future text messages from us by following the instructions in the text message you have received from us or by otherwise contacting us as set forth in “Contact Us” below.

  • Mobile Devices. When using our App, you may opt-out to receive push notifications by using the settings interface in the App and by allowing the App to send you notifications via your mobile device’s settings. You may opt out of receiving these push notifications at any time by changing the settings on your mobile device. With your consent, we will also collect precise location-based information via App. You may opt out of this collection by changing the settings on your mobile device.

  • Deletion of Account. At any time you can delete your account by using our standard deletion functionality available via the Services, or by contacting us using the information set forth in “Contact Us” below and requesting that we delete it.

  • Do Not Track. Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.

  • Cookies. You may stop or restrict the placement of Technologies on your device or remove them by adjusting your preferences as your browser or device permits. On our Website, you can use our Cookie Tool for this purpose. However, if you adjust your preferences, the Services may not work properly. Please note that cookie-based opt-outs are not effective on mobile applications. However, you may opt-out of certain tracking on some mobile applications by following the instructions for Android, iOS, and others. You can also chose what permissions you choose to grant our App on you mobile device’s settings.

The online advertising industry also provides mechanisms that may allow you to opt out of receiving targeted ads from organizations that participate in self-regulatory programs. To learn more, visit the Network Advertising Initiative and the Digital Advertising Alliance.

Please note you must separately opt out in each browser and on each device.

For further details please see our Cookie Notice.

Accessing & Correcting Personal Data

If you find that the information on your account is inaccurate, incomplete or not up-to-date, please contact us at: privacy.policy@sofwave.com and provide us with the necessary information to correct it.

At any time, you can contact us at: privacy.policy@sofwave.com and request to access the Personal data that we keep about you. We will ask you to provide us certain credentials to make sure that you are who you claim to be and to as required under applicable law, we will make good-faith efforts to locate the Personal data that you request to access and provide you with a copy.

Following your review of the Personal data you can request to correct, amend or delete Personal data, if it is inaccurate, incomplete or not up-to-date, or if you believe that our processing of the Personal data is in violation of applicable law.

We will use discretion and due care to redact personal data related to others from the information we will make available to you. Where you believe that content containing Personal data was uploaded to our Services by a third-party user, please contact such user who uploaded that content with a request to remove Personal data.

Note that depending on the laws and regulations that apply to our Processing of Personal data about you, you may be entitled to additional rights with respect to our Processing of Personal data about you. Please see the chapter entitled Processing Under Specific Laws.

International Transfers of Personal Data

We store and process personal data, including personal data, either directly or using third parties such as data hosting service providers, in the European Economic Area, the United States, and in other regions to support the Services. The laws of the territories where personal data will be stored and processed can differ from the laws of the jurisdiction in which you live.

Retention of Personal Data

We store the personal data we collect as described in this Privacy Notice for as long as you use the Services, or as long as necessary to fulfill the purpose(s) for which it was collected, or as long as necessary to pursue our business purposes.

To determine the appropriate retention period for personal data, we may consider applicable legal requirements; the amount, nature, and sensitivity of the personal data; certain risk factors; the purposes for which we process personal data about you; and whether we can achieve those purposes through other means.

Children’s Personal Data

The Services is not directed to children under 18 (or other age as required by local law outside the United States), and we do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has uploaded personal data to the Services in violation of applicable law, you may contact us as described in “Contact Us” below.

Updates to this Privacy Notice

We may update this Privacy Notice from time to time in our sole discretion. If we do, we’ll let you know by posting the updated Privacy Notice on our website, and/or we may also send other communications.

Contact Us

Sofwave Medical Ltd., a company incorporated under the laws of the state of Israel, is the controller of the personal data we process under this Privacy Notice.

If you have any questions about our privacy practices or this Privacy Notice or to exercise your choices and rights as detailed in this Privacy Notice, please contact us at: privacy.policy@sofwave.com.

Processing Under Specific Laws

Processing Personal Data Under EEA Privacy Laws

If EU data protection laws apply to the processing of Personal data about you by us, then the following terms apply in addition to the general terms of the policy.

Lawful Grounds for Processing

Where we process Personal data about you as a data controller, the processing is based on the following lawful grounds:

  • We process your account and payment details to perform the contract with you.

  • We will process Personal data to comply with a legal obligation and to protect your and others’ vital interests.

  • We will further rely on our legitimate interests, which we believe are not overridden by your fundamental rights and freedoms, for the following purposes:Communications with you, including direct marketing where you are our client or a user of our client, or where you make contact with us through our Services or otherwise.Cyber security.Support, customer relations, service operations.Enhancements and improvements to yours and other users’ experience with the website and Services.

    • Fraud detection and misuse of the Services.

  • All processing of Personal data which are not based on the lawful grounds indicated below, are based on your consent.

Special Categories of Personal Data

We only process special categories of personal data if you choose to provide it when communicating with us, and will only use it for the specific purpose for which you provided it (such as to connect you with a local medical professional).

Accordingly, when processing such data we rely on the Contract Performance legal basis for processing such personal data, and your Explicit Consent for processing special categories of data.

International Transfers

As detailed under Our General Privacy Notice, we store and process information, including personal data in the European Economic Area, the United States, and in other regions to support the Services.

If you are located in the European Economic Area (EEA), note that some of there territories have not been deemed to provide an adequate level of data protection equivalent to the EU. In such case, we will use appropriate safeguards, in particular, by way of entering into the European Union Standard Contractual Clauses as amended from time to time with the relevant recipients, or by adhering to equivalent data transfer regulations to protect the security and confidentiality of such personal data. You can obtain a copy of the suitable safeguards that we use when transferring personal data as described above or receive further information about relevant data transfers by submitting your request to privacy.policy@sofwave.com.

Your rights under EU Privacy Laws

In addition to your rights under other sections in this policy, you have the following rights:

  • At any time, contact us if you want to withdraw your consent to the processing of personal data. Exercising this right will not affect the lawfulness of processing based on consent before its withdrawal.

  • Request to delete or restrict access to Personal data. We will review your request and use our discretion, pursuant to the provisions of the applicable law, to reach a decision about your request and respond to it.

  • If you exercise one (or more) of the above-mentioned rights, in accordance with the provisions of applicable law, you may request to be informed that third parties that hold Personal data, in accordance with this policy, will act accordingly.

  • You may ask to transfer Personal data in accordance with your right to data portability.

  • You may object to the processing of Personal data for direct marketing purposes. Additional information about this right is available under the Your Privacy Choices chapter in this notice.

  • You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affecting you.

  • You have a right to lodge a complaint with a data protection supervisory authority of your habitual residence, place of work or of an alleged infringement of the GDPR.

A summary and further details about your rights under EU data protection laws, is available on the EU Commission’s website at the following link: https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens_en.

Exercising your rights

Note that when you send us a request to exercise your rights, we will need to reasonably authenticate your identity and location. We will ask you to provide us credentials to make sure that you are who you claim to be and will further ask you questions to understand the nature and scope of your request.

If we need to delete Personal data following your request, it will take some time until we completely delete residual copies of Personal data from our active servers and from our backup systems. If you have any concerns about the way we process Personal data, you are welcome to contact our privacy team and our EU and UK representatives at: privacy.policy@sofwave.com. We will look into your inquiry and make good-faith efforts to respond

Representative

In accordance with applicable privacy laws of the EEA, we have appointed the following representatives:

Processing Personal data Under US Privacy Laws

If US consumer privacy laws apply to the processing of personal data about you by us, then the following terms apply in addition to the terms of Our General Privacy Notice.

CCPA Notice at Collection

This CCPA Notice at Collection applies to California residents and describes the categories of personal information we collect through our website at sofwave.com, mobile application, and related Services.

  • Categories of Personal Information Collected. We collect identifiers (name, email, phone, IP address, device identifiers), California Customer Records information (contact details, payment transaction details), protected classification characteristics (from job applications or surveys), commercial information (pulse purchases, subscription details, transaction history), internet or electronic network activity (browsing history, pages visited, device information, cookies), geolocation data (approximate location from IP address and precise location via App with consent), professional or employment-related information (contact details, company information, employment history), and inferences drawn from other personal information to create consumer profiles.

  • Purposes for Collecting Personal Information. We collect personal information to provide and operate the Services, fulfill requests, process transactions, and communicate with you. We also use it to improve our Services, develop new products, pursue legitimate business interests (direct marketing, research and development, network security, fraud prevention, analytics), comply with legal obligations, enforce agreements, and process job applications.

  • Sale or Sharing of Personal Information. We do not “sell” personal information as most consumers define the term. However, we share identifiers, California Customer Records information, commercial information, internet activity, geolocation data, professional information, and inferences with advertising partners for personalized advertising, which may constitute a “sale” or “sharing” under CCPA.

  • Retention Period. We retain personal information for as long as you use the Services or as necessary to fulfill collection purposes and pursue our business purposes. Retention periods vary based on legal requirements, the amount and sensitivity of data, risk factors, and whether we can achieve our purposes through other means.

  • Notice of Right to Opt-Out of Sale/Sharing. You can opt out of the collection of personal information by third-party advertising and analytics tools by visiting our “Your Privacy Rights” webpage or contacting us at privacy.policy@sofwave.com.

  • Privacy Policy. For more information on our privacy practices, please review our General Privacy Notice at sofwave.com.

Privacy Notice for all US Residents

This section applies solely to all recipients of the Services users, users and others who reside within the United States of America. We have adopted this section to comply with U.S. state privacy laws, and any terms defined under U.S. state privacy laws will have the same meaning when used in this section. This section supersedes any contradicting provisions under the other sections of this privacy notice.‍

  • Overview of Personal Data Collected, Disclosed, Sold, and Shared

U.S. consumers residing in a state with an effective consumer privacy law are provided with the right to know what categories of personal data Sofwave has collected about them, whether Sofwave disclosed that personal data for a business purpose (e.g., to a service provider), whether Sofwave “sold” that personal data, and whether Sofwave “shared” that personal data for “cross-context behavioral advertising” in the preceding twelve months.
U.S. consumers residing in a state with a comprehensive privacy law can find this information below:

Category of Personal data CollectedCategory of Third Parties to Whom Personal data is Disclosed to for a Business Purpose
[please see our Our General Privacy Notice for additional details about such third parties]
Third Parties To Whom Personal data is Sold or Shared for Cross-Context Behavioural Advertising
[please see Our General Privacy Notice for additional details about such third parties]
IdentifiersService ProvidersBusiness PartnersThird-Party Services You Share or Interact WithAdvertising Partners, for provision of ads to users.
Personal data categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))Service ProvidersBusiness PartnersThird-Party Services You Share or Interact WithAdvertising Partners, for provision of ads to users.
Protected classification characteristics under California or federal lawService ProvidersN/A
Commercial informationService ProvidersThird-Party Services You Share or Interact WithAdvertising Partners, for provision of ads to users.
Internet or other electronic network activityService ProvidersThird-Party Services You Share or Interact WithAdvertising Partners, for provision of ads to users.
Geolocation dataService ProvidersAdvertising Partners, for provision of ads to users.
Professional or employment-related informationService ProvidersAdvertising Partners, for provision of ads to users.
Inferences drawn from other personal data to create a profile about a consumerService ProvidersAdvertising Partners, for provision of ads to users.
Personal data that reveals a consumer’s account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an accountN/AN/A
Personal data that reveals a consumer’s precise geolocationService ProvidersBusiness PartnersN/A
Personal data collected and analyzed concerning a consumer’s healthService ProvidersBusiness PartnersN/A
  • Sources of Personal Data. We collect the above categories of personal data from the following sources, as further detailed under Our General Privacy Notice:

    • We collect personal data that you provide us directly, when you communicate with us, make transactions, participate in Surveys, apply for a job, and when we meet in conferences, trade shows, and other events,

    • We automatically collect personal data from your device and browser when you use our Services, including by using Cookie and similar tracking technologies.

    • We receive personal data from third parties, including our business partners, service providers, and publicly-available information, depending on your interaction with our Services.

  • Purposes of Processing. As further detailed under Our General Privacy Notice, we use and disclose the personal data that we collect for the business and commercial purposes detailed under the How We Use Personal Data chapter in Our General Privacy Notice.

  • Consumer under the age of 16. Sofwave does not have actual knowledge of any “sale” or “sharing” for “cross-context behavioral advertising” of personal information of minors under 16 years of age.

  • Sensitive Personal Data. We only receive sensitive personal data (including special category data, data of special sensitivity, and any equivalent term under applicable privacy laws) when you provide us with such as part of communicating with us, and only use it for the specific purpose for which you provided it (such as to connect you with a local medical professional), which is reasonably expected by consumers providing such data for this purpose.

  • Your Rights. In addition to other rights detailed under Our General Privacy Notice, you have the following rights as a U.S. resident:

    • Access to specific personal data and data portability rights. You have the right to request that we disclose certain information to you about our collection and use of personal data about you over the past 12 months preceding your request. Upon verification of your request, we will disclose the following information to you: (A) The categories of personal data we collected about you; (B) The categories of sources for the personal data we collected about you; (C) Our business or commercial purpose for collecting that personal data; (D) The categories of personal data that we disclosed for a business purpose, and the categories of third parties with whom we disclosed that particular category of personal data; (E) The specific pieces of personal data that we collected about you; and, (F) If we disclose personal data about you for a business purpose, we will provide you with a list which will identify the personal data categories that each category of recipient obtained.

    • Deletion rights. You have the right to request that we delete any personal data about you. Upon confirmation of your request, we will delete personal data about you from our records, unless an exception applies.

    • Opt-out of Selling or Sharing. We don’t “sell” personal information as most consumers typically define the term “sell” or “sold” or otherwise share it with third parties for monetary or disclose it for monetary or other consideration. However, our Services use advertising and analytics tools provided by third parties that may constitute a “sale” of personal information under certain U.S. state laws. At any time, you can opt out of the collection of personal data by such service providers by contacting us or by visiting our “Your Privacy Rights”

    • Non-discrimination. You also have a right not to be discriminated against for exercising your rights under applicable United States privacy laws.

    • Limit the Use of Sensitive Personal Data. We do not provide you with an option to limit our use of such sensitive personal data, because (as detailed above) we already use it solely for permitted purposes under applicable U.S. Privacy Laws. If you have further questions about our use of sensitive personal data about you, please contact us at privacy.policy@sofwave.com.

  • Retention. Please see Retention of Personal Data under Our General Privacy Notice.

Supplemental Consumer Health Data Privacy Notice

This Supplemental Consumer Health Data Privacy Notice (“Consumer Health Data Privacy Notice”) supplements the Sofwave Privacy Notice.

This Consumer Health Data Privacy Notice only applies to personal data that we process that is “consumer health data” subject to the Connecticut Data Privacy Act, as amended (“CTDPA”), Washington My Health My Data Act (“MHMDA”), Nevada’s Consumer Health Data Privacy Law (“NVCHDPL”), or other states with consumer health data privacy laws (as applicable).

Terms used in this Consumer Health Data Privacy Notice that are defined in CTDPA, MHMDA, or NVCHDPL will have the meanings set forth in those laws, to the extent such laws are applicable.

  • Consumer Health Data We Collect

Under CTDPA, “consumer health data” is defined as “any personal data that a controller uses to identify a consumer's physical or mental health condition or diagnosis, and includes, but is not limited to, gender-affirming health data and reproductive or sexual health data.

Under the MHMDA, “consumer health data” is defined as “personal data that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status.

Under NVCHDPL, “consumer health data” is defined as “personally identifiable information that is linked or reasonably capable of being linked to a consumer and that a regulated entity uses to identify the past, present or future health status of the consumer.

Because consumer health data is defined very broadly, many of the categories of personal data that we collect under our Privacy Notice may also be considered consumer health data.

Examples of consumer health data that you may provide to us, or that we may otherwise collect, may include:

Examples of consumer health data that you may provide to us, or that we may otherwise collect, may include:

  • Information that could identify your attempt to seek health care services or information, including services that allow you to assess, measure, improve, or learn about your or another person’s health. For example, we collect information you submit to the Services, which may include information concerning your health and wellbeing, mental health, medical conditions, or other health-related topics.

    • Information about your health-related conditions, symptoms, status, diagnoses, disease, testing, or treatments.

    • Information about social, psychological, behavioral, and medical interventions.

    • Information about use or purchase of prescribed medication.

    • Information about measurements of bodily functions, vital signs, symptoms, or characteristics.

    • Information about diagnoses or diagnostic testing, treatment, or medication.

    • Information about surgeries or other health-related procedures.

    • Reproductive or sexual health information.

    • Biometric information.

    • Genetic data.

    • Information related to the precise (geo)location information of a consumer used to indicate an attempt by a consumer to receive health care services or products.

    • Other information that may be used to infer or derive data related to the above or other consumer health data.

We collect consumer health data that you provide to us, consumer health data we collect automatically when you use the Services, and consumer health data from third-party sources, as described in our Privacy Notice and below.

  • Why We Collect and Use Consumer Health Data

We collect consumer health data that you provide to us, consumer health data we collect automatically when you use the Services, and consumer health data from third-party sources, as described in our Privacy Notice and below.

  • Why We Collect and Use Consumer Health Data

We collect and use consumer health data for the purposes and in the manner described in the “How We Use Personal data” section of the Privacy Notice.

Primarily, we collect and use consumer health data as reasonably necessary to provide you with the Services, fulfill your requests submitted via the Services, or as otherwise authorized by you. This may include delivering and operating the Services and its features, personalization of certain Services features, ensuring the secure and reliable operation of the Services and the systems that support the Services, troubleshooting and improving the Services, and other essential business operations that support the provision of the Services (such as analyzing our performance and meeting our legal obligations).

We may also use consumer health data for other purposes for which we give you choices and/or obtain your consent as required by law.

  • Sharing of Consumer Health Data

We may share each of the categories of consumer health data described above for the purposes described above and in the “How We Use Personal data” section of the Privacy Notice.

We only share or disclose your consumer health data as needed to provide you with the Services, or with your explicit consent. We may share or disclose any or all the above categories of consumer health data to the following entities, who shall use the data only as permitted for the purposes set forth above, and within the bounds of our contracts with them:

These general categories of third parties:

  • Business CollaboratorsLife Sciences CompaniesProduct co-promotion partnersProduct co-development partnersMarketing and Advertising AgenciesSocial Media Companies and PlatformsService Providers (including those hosting or analyzing data on our behalf, those assisting with fraud prevention, those assisting in program administration, those assisting in incident management and reporting, those administering our call center and websites, and those who assist with our information technology and security programs)Emergency PersonnelAuthorized/legal representatives, family members, and caregiversThird parties (including those with whom Sofwave has joint marketing and similar arrangements, those who provide marketing and data analytics services, those who provide program enrollment or product fulfillment, payment, and authorization, other third parties as necessary to complete transactions and provide products or Services, or where required by law)Sofwave lawyers, auditors, and consultantsLegal and regulatory bodies

    • In addition, we may share or disclose consumer health data as permitted or required by law, such as (i) to an acquiring organization if we are involved in a sale or a transfer of our business, (ii) as needed to prevent, detect, protect against, or respond to security incidents, identity theft, fraud, harassment, malicious or deceptive activities, (iii) in situations that may involve violations of our terms of use or other rules, (iv) to protect our rights and the rights and safety of others, (v) as needed to support external auditing, compliance and corporate governance functions, (vi) as needed to preserve the integrity or security of our systems, or (vii) to investigate, report, or prosecute those responsible for any action that is illegal under applicable state or federal law.

  • How to Exercise Your Rights

The CTDPA, MHMDA and NVCHDPL provide consumers with certain rights with respect to consumer health data.

Under CTDPA, Sofwave is required to obtain consumer consent prior to selling or offering to sell, consumer health data. Consumers have the right to: (i) confirm whether Sofwave is collecting or sharing consumer health data; (ii) have Sofwave provide the categories of consumer health data that it shares with third parties and the categories of third parties with which it shares consumer health data; and (iii) withdraw consent from Sofwave’s selling of consumer health data.

Under MHMDA, consumers have the right to: (i) confirm whether Sofwave is collecting, sharing, or selling consumer health data and to access such data; (ii) withdraw consent from Sofwave’s collection and sharing of consumer health data; and (iii) request that Sofwave delete consumer health data.

Under NVCHDPL, consumers have the right to: (i) confirm whether Sofwave is collecting, sharing or selling consumer health data; (ii) have Sofwave provide the consumer with a list of all third parties with whom Sofwave has shared consumer health data relating to the consumer or to whom Sofwave has sold such consumer health data; (iii) request that Sofwave cease collecting, sharing, or selling consumer health data relating to the consumer; and (iv) request that Sofwave delete consumer health data.

The rights afforded to consumers under CTDPA, MHMDA and NVCHDPL are subject to certain exceptions.

Subject to certain legal limitations and exceptions, you have the following rights with respect to any consumer health data we may collect about you:

  • The right to confirm whether we are collecting, sharing, or selling your consumer health data and to access such data, including to receive a list of affiliates or specific third parties with whom we have shared or sold your information, along with contact information such as an active email address for each third party;The right to review and request corrections to your consumer health data;The right to withdraw consent from our collection or sharing of your consumer health data; and

    • The right to request that we delete your consumer health data.

You can request to exercise such rights by contacting us at:  privacy.policy@sofwave.com.

Sofwave will not discriminate against you for exercising any of your rights. We will make reasonable efforts to respond promptly to your requests in accordance with applicable laws. Please allow 45 days for a response.  We may, after receiving your request, require additional information from you to authenticate your request and verify your identity. Please be aware that we may be unable to afford these rights to you under certain circumstances, such as if we are legally prevented from doing so. If your request to exercise a right is denied, you may appeal that decision by contacting us at: privacy.policy@sofwave.com. We will process and respond to your appeal within the time permitted by applicable law.

If you are a Washington resident and your appeal is unsuccessful, you can raise a concern or lodge a complaint with the Washington State Attorney General at www.atg.wa.gov/file-complaint.

Consumer Health Data Authorization

This Consumer Health Data Privacy Authorization (“Authorization”) supplements the Sofwave (“Sofwave”, “we,” “us,” or “our”) Privacy Notice, Supplemental Consumer Health Data Privacy Notice, and the https://sofwave.com/ cookie banner and applies only to “consumer health data” subject to the Connecticut Data Privacy Act, as amended (“CTDPA”), Washington My Health My Data Act (“MHMDA”), Nevada Consumer Health Data Privacy Law (“NVCHDPL”), or other states with consumer health data privacy laws (as applicable).

Terms used in this Authorization defined in CTDPA, MHMDA, NVCHDPL, or other applicable state consumer health data privacy laws will have the meaning set forth in those laws to the extent such laws are applicable.

If you opt-in to “personalized marketing” through the https://sofwave.com/ cookie banner, you allow us to “sell” your consumer health data as described below:

  • Specific consumer health data intended for “sale”:  Consumer health data collected via cookies and similar technologies including but not limited to browsing activity on our website.

  • Purpose of the “sale” of consumer health data:  To tailor and deliver personalized advertisements to you.

  • How consumer health data purchasers gather and use the data: Consumer health data purchasers will gather the data via cookies and other tracking technologies when you visit https://sofwave.com/. These purchasers may use the data to assist us to deliver personalized advertisements to you and in accordance with their privacy policies linked below.

  • Consumer health data purchasers’ contact information:

Please note:

  • The provision of goods or services may not be conditioned upon you accepting the terms of this Authorization.

  • Purchasers may redisclose the consumer health data sold under this authorization and such data may no longer be protected by the CTDPA, MHMDA, NVCHDPL, and/or applicable state consumer health data privacy laws.

  • You may revoke this authorization at any time through the https://sofwave.com/ cookie banner To do so, please be sure the box next to “Personalize marketing” is unchecked and click “Save my choices.” you may also click “Decline all” to decline our use of all cookies not required to operate our website.

  • A revocation will not impact previously sold consumer health data. In addition, if you use different browsers or devices, you must indicate your choices on each browser/device used to access https://sofwave.com/.

  • If you have any questions about how to revoke your authorization, please contact: privacy.policy@sofwave.com.

  • This authorization will expire one (1) year after accepting it.

Processing Personal Data Under Israeli Privacy Laws

If Israeli data protection laws apply to the processing of personal data about you by us, then the following terms apply in addition to Our General Privacy Notice.

Lawful Grounds for Processing

Where we are not required under law to collect and process personal data about you (for example when we process certain personal data in connection with transactions you make) – all our processing of personal data about you is subject to your consent, and you are under no legal obligation to provide us with personal data about you.

In some cases, if you do not provide the required personal data, you will not be able to use some of our Services, for example, to register to our newsletter.

If after reading this notice you find that it does not align with your views or wishes, please refrain from using our Services. We will be sorry for that, but it is your full right.

International Transfers

As detailed in Our General Privacy Notice, we store and process personal data in the European Economic Area, the United States, and other regions to support the Services. If you are located in Israel, note that some of these territories may not provide an equivalent level of data protection. In such cases, we use appropriate safeguards, including Standard Contractual Clauses or equivalent data transfer mechanisms, to protect the security and confidentiality of personal data.

You can obtain a copy of the suitable safeguards that we use when transferring personal data by submitting your request to privacy.policy@sofwave.com.

Your Rights Under Israeli Privacy Laws

In addition to your rights under other sections of this notice, you have the following rights:

  • Right to Unsubscribe: At any time, you may notify us of your refusal to receive the newsletter material by using the unsubscribe link in the messages that we send you.

  • Right to Review Personal Data: You have a right to review personal data about you which is held in our databases, subject to certain applicable legal limitations.

  • Right to Correct Personal Data: If you find that any of the personal data about you is inaccurate, incomplete, unclear, or outdated, you may request that this personal data be corrected or deleted. If we decide to refuse your request, we will notify you of our refusal in accordance with applicable law, and you may appeal our decision.

  • Right to Delete Personal Data Transferred From the EEA: If personal data about you is transferred to us from the European Economic Area (EEA) by a source other than yourself, you have the right to request its deletion. Such deletion request is subject to limitations under applicable laws.

  • Please contact us at privacy.policy@sofwave.com  to exercise your rights. We will ask you to provide certain details or credentials to verify your identity, before attending to your request.

Retention of Personal Data

For information about the durations for which we retain personal data, please see the Retention of Personal Data under Our General Privacy Notice.