Privacy Policy
At Navera Health & Wellness, we are committed to protecting your privacy and maintaining the confidentiality of your personal health information. This policy explains how we collect, use, and safeguard your data.
Last updated: January 2025
Information We Collect
Personal Information
When you become a member of Navera, we collect:
- Contact information (name, email address, phone number)
- Demographic information provided during registration
- Emergency contact information
- Billing and payment information
Health Information
In the course of providing our services, we may collect:
- Session notes and progress documentation
- Assessment results and treatment plans
- Communication records between you and your providers
- Appointment history and scheduling preferences
Technical Information
When you use our portal, we automatically collect:
- Login timestamps and session duration
- Device type and browser information
- IP address (for security purposes)
How We Use Your Information
We use your information to:
- Provide and coordinate your health and wellness services
- Schedule appointments and send reminders
- Process payments and manage your account
- Communicate with you about your care
- Improve our services and member experience
- Comply with legal and regulatory requirements
How We Protect Your Information
Enterprise-Grade Security
Your data is protected by Google Cloud's enterprise security infrastructure, including:
- Identity-Aware Proxy (IAP): Only authenticated, authorized users can access the portal
- Encryption in transit: All data is encrypted using TLS 1.3
- Encryption at rest: Your data is encrypted on Google Cloud servers
- Access controls: Staff access is limited to what's necessary for their role
HIPAA Compliance
Navera operates in accordance with the Health Insurance Portability and Accountability Act (HIPAA). We maintain appropriate administrative, physical, and technical safeguards to protect your health information.
Information Sharing
We do not sell your personal information. We may share your information only:
- With your consent: When you authorize us to share information with other providers
- For treatment: With providers involved in your care
- For payment: With payment processors to complete transactions
- As required by law: When legally obligated or to protect safety
Third-Party Services
We use the following third-party services to operate our platform:
- Google Cloud Platform: Hosting and security infrastructure
- Stripe: Payment processing
- Spruce Health: Appointment reminders, text messaging, and care-related notifications
Each of these providers maintains their own privacy policies and security certifications.
SMS / Text Messaging
When you provide your mobile phone number, Navera may send you text messages related to your care, including:
- Appointment confirmations, reminders, and scheduling updates
- Account verification and security notifications
- Important updates about your services
Mobile Information Sharing
Mobile phone numbers and SMS opt-in information are not shared with third parties or affiliates for marketing or promotional purposes. Mobile data is disclosed only to our SMS delivery provider (Spruce Health) as necessary to deliver messages on our behalf.
Frequency
Message frequency varies based on your care activity and account events.
Standard Rates
Message and data rates may apply per your mobile carrier plan.
Opt-Out
You may opt out of non-essential text messages at any time by replying STOP to any message. Reply HELP for help. Opting out of essential transactional messages may affect your ability to receive timely care information.
Consent
Providing your mobile phone number constitutes consent to receive text messages related to your care from Navera. Consent is not a condition of receiving services and may be withdrawn at any time.
Your Rights
You have the right to:
- Access: Request a copy of your personal information
- Correction: Request corrections to inaccurate information
- Deletion: Request deletion of your information (subject to legal retention requirements)
- Portability: Receive your data in a standard format
- Restriction: Request limitations on how we use your data
To exercise any of these rights, please contact us at privacy@naverahealthandwellness.com.
Data Retention
We retain your information for as long as necessary to provide services and comply with legal requirements. Health records are typically retained for the period required by applicable law (usually 7-10 years after your last visit).
Children's Privacy
Navera provides services to adolescents with parental consent. We collect only the information necessary to provide services and maintain appropriate safeguards for minor clients.
Changes to This Policy
We may update this privacy policy periodically. Significant changes will be communicated to you via email or through a notice on our portal. The "Last updated" date indicates when the policy was most recently revised.
Contact Us
If you have questions about this privacy policy or our data practices, please contact:
Navera Health & Wellness
Privacy Officer
Email: privacy@naverahealthandwellness.com