Privacy Policy

Last updated: July 1, 2025

Scope

Tectonic Health, Inc. ("Tectonic Health", "we", "us", or "our") created this Privacy Policy to describe its data collection, use, and disclosure practices with respect to information that identifies or may reasonably identify you ("Personal Information" or "PI"). This Privacy Policy applies to our primary care healthcare service provided to employees and their household members (including spouses/partners and dependents) as a benefit from their employers, including our mental health support, physical therapy, and prescription services and any accompanying features or products that we may develop ("Service") and website, mobile applications, blog, or other areas where we collect or receive PI about you (collectively, the "Platforms"). This Privacy Policy supplements our Terms of Service and Notice of Privacy Practices, which describes our collection, use, and disclosure of your Protected Health Information pursuant to the Health Insurance Portability and Accountability Act (HIPAA).

Updates

We may update this Privacy Policy from time to time. Any changes to this Privacy Policy will become effective when we notify you of the changes and may apply to PI that we have already collected. Our means of notifying you may vary and may include a banner or notification on our Platforms, an email communication from us, or another form of reasonable notice. Unless otherwise stated in the notice, your use of the Platforms following these updates will constitute your acceptance of these updates.

Children

Our Platform is not targeted to children under the age of 13. If you know that we have received PI from a child under the age of 13 without parental consent, please contact us by referencing the information in Contacting Us, below, so that we may delete that PI from our system. If you are a parent or guardian of a child who is under the age of 18 and your child is covered under your employer-provided health benefit, you may contact us to review or manage your child's PI. Please contact us by referencing the information in Contacting Us, below.

What Personal Information do we collect?

We may collect the following PI about you:

Contact information. This includes your full name and preferred name, postal address, phone number, and email address. This also includes your username* and password* if you create an account with us.

Demographic information.* This includes your birthdate, gender, and race.

Employment information. This includes information about your employer who provides this health benefit.

Health Information.* This includes information that you may provide to us through our Platforms, such as if you are asked to fill out a form on our website and voluntarily provide health information to help you with your experience, as well as health information collected during the provision of healthcare services.

Commercial Information. This includes records of products or services that you have received or considered receiving, as well as other consumption histories or tendencies.

Internet and device information. This includes device and browser characteristics (including unique or online identifiers such as your device ID, IP address, or mobile operating system). This also includes information regarding your interactions with other applications, advertisements, or websites.

Geolocation information.* This includes information that you may provide to us through our Platforms, such as if you are asked to provide location information to support a home visit or other healthcare services.

Categories marked with an asterisk (*) may be considered "sensitive" categories of information according to some state laws. We intend to retain each of the above categories of PI for as long as necessary to comply with legal obligations, fulfill your requests or inquiries, and improve our Platforms.

How do we collect Personal Information?

We collect your PI from the following sources:

Directly from you. For example, when you fill out our forms or sign up to use the Platforms, you provide PI like your contact, demographic, and employment information.

Automatically. For example, when you visit our Platforms, we use tools such as cookies or pixel tags, to collect PI such as your geolocation or other internet or device information. For more information on this, see Cookies, pixels, and other tracking technologies.

From your employer. We may receive certain information from your employer who provides this health benefit, such as your eligibility status and basic contact information.

Third-party service providers. Like many companies with an online or virtual presence, we work with service providers in data analytics to reach our users in a smart, informed manner. This includes, for example, learning about your commercial information, like your interactions with our Platform, so that we can better tailor our content and services.

By combining information. For example, we may combine PI that we collect offline with PI collected through our Platforms or combine PI that we receive from third parties with the PI that we already have about you.

How do we use your Personal Information?

We may use your PI for various purposes, including to:

  • Provide and administer your healthcare services and allow you access and use of our Platforms
  • Process your requested services and facilitate your interaction with our healthcare providers and Platforms
  • Personalize your experience with our services or Platforms
  • Address your customer service requests or communicate with you in relation to other follow up items or correspondence
  • Develop and improve our services or Platforms for you and other users, for example, by developing additional features or tools to offer within our Platforms or seeking your responses to a survey or communication
  • Help maintain and enhance the security and integrity of our services or Platforms
  • Communicate with you about our Platforms, including this Privacy Policy
  • Coordinate with your employer regarding your benefit eligibility and utilization for administrative purposes

The information that we use to provide clinical services is Protected Health Information (PHI) and therefore subject to our HIPAA Notice of Privacy Practices. We do not use your PHI for the purposes of targeted advertising.

How do we share your Personal Information?

We may share your PI in the following ways:

Within Tectonic Health and its affiliates, in order to provide our healthcare services and Platforms to you.

With general service providers that facilitate our healthcare services or Platforms or otherwise process your information on our behalf, including, for example, attorneys, accountants, technology providers, companies that send emails on our behalf, or other operating systems or platforms that help us with regular business operations.

With your employer for administrative purposes related to your health benefit, such as confirming eligibility, utilization reporting (in aggregate form), and billing purposes. We will not share detailed health information without your authorization.

With any successors to all or part of our business in the event that we assess or actually merge with, acquire or are acquired by, or sell a brand or part of our business to another entity as part of an asset sale, corporate reorganization, or other change of control, including bankruptcy.

With certain parties in order to comply with the law, or otherwise assess or defend our legal rights and obligations. This includes government agencies, investigatory bodies, law enforcement, and certain advisers such as our attorneys or other auditors. This may also include other third parties in response to a court order or subpoena. We may also release PI when its release is appropriate to enforce our site policies, or protect others' rights, property, or safety.

We do not enable users of the Website to make PI supplied to us publicly available.

How do we protect your Personal Information?

We take security seriously and have implemented reasonable technical, organizational, and physical safeguards to protect your PI. However, please keep in mind that no system, including our Platforms, are 100% secure. Please take reasonable steps to maintain your own security. We recommend that you select complex passwords for your accounts and not reuse login credentials for multiple accounts.

Cookies, pixels, and other tracking technologies

Cookies, and other technologies like web beacons or pixels, optimize your experience with our Platforms by remembering your browsing preferences. These technologies also help us improve our services. You may modify your cookie preferences by accessing your browser's help menu. Please note that if you turn cookies off, some features on our Platforms will be disabled. This may make your experience with our Platforms less efficient and our Platforms may not function at their best.

Third-party links

Occasionally, at our discretion, we may include or offer third-party products or services on our website. We do not own or control these third-party sites. Your use of these third-party sites is subject to the third parties' privacy policies and/or other applicable terms, and we are not responsible for the content or activities of these linked sites.

Your Privacy Choices

Depending on your state of residence (including California, Virginia, Colorado, Utah, Connecticut, and potentially other states), you may have certain rights with respect to your PI. We will strive to honor these rights no matter your country or state of residence, but we reserve our ability to fulfill your requests as legally required.

To exercise any of the following rights, you or your authorized agent may contact us via the instructions in Contacting Us, below.

We may request additional information to verify the authenticity of your request, including confirming PI or other information that you have already provided to us, or potentially requesting additional PI.

Right to Know and Access. You may request that we confirm whether we are processing your PI. Furthermore, you may request that we provide you with a copy of your PI. You may also request that we disclose the categories of third parties with whom we share PI, including identifying the categories of disclosed PI.

Right to Correct. You may request that we correct your PI.

Right to Delete. You may request that we delete the PI that you have provided to us.

Right to Restrict Certain Processing. You have the right to limit or opt out of other processing activities, such as those involving automated decision-making or "sensitive" PI, as defined by applicable state law.

Right to Nondiscrimination. We will not discriminate against you for exercising these rights. However, where permitted by law, we may charge a reasonable fee in fulfilling certain requests.

In addition to these rights, you can always manage your communication preferences. If at any time you would like to unsubscribe from receiving future emails, you can follow the unsubscribe or opt-out instructions included in the email communication.

Notice to Pennsylvania Residents

We comply with all applicable Pennsylvania state privacy and healthcare laws. If you have specific questions about your rights under Pennsylvania law, please contact us using the information in Contacting Us below.

Notice to California Residents

The following statements are made in compliance with the California Consumer Privacy Act (CCPA), as amended.

In the past 12 months, we have collected PI described above, under What Personal Information do we collect? from the sources listed in How do we collect Personal Information?. This PI falls into the following categories of PI under the CCPA:

  • Identifiers
  • Categories listed in California Civil Code 1798.80(e)
  • Characteristics of protected classifications under California or federal law
  • Commercial information
  • Health information
  • Internet or electronic network activity information
  • Professional or employment-related information

The Personal Information that we have disclosed to or shared with third parties in the past 12 months is described above, under How do we share your Personal Information?, and includes PI from the following categories of PI under the CCPA:

  • Identifiers
  • Categories listed in California Civil Code 1798.80(e)
  • Characteristics of protected classifications under California or federal law
  • Commercial information
  • Health information
  • Internet or electronic network activity information
  • Professional or employment-related information

Contacting Us

If you have any questions regarding this Privacy Policy, or would like to submit individual requests in accordance with this Privacy Policy, including those listed in Your Privacy Choices, you may contact us by:

Tectonic Health, Inc.
526 South Main Street, Suite 512
Akron, OH 44311
Email: privacy@tectonic.health
Phone: (412) 206-6562

© 2025 Tectonic Health. All rights reserved.