Privacy Policy

Privacy Policy
Updated June 18, 2019

At Wellness Holdings, LLC, we take online privacy seriously and we respect the concerns of our community of users. In this policy (the “Privacy Policy”) we describe our privacy practices about  information we collect through HPDrx.com (the “Site”) to help you make informed decisions about how you share information when you visit or use the site.

INFORMATION YOU MAY CHOOSE TO PROVIDE TO US

We may collect information, including personal data, directly from you if you choose to provide that information. For example, you may provide us with your name and contact information (such as an email address), date of birth, or other details of that nature, when you sign up for our newsletters or purchase items on the Site.


You also may choose to provide personal data about yourself when you leave comments on the Site. Please be aware that information you post in these forums may be viewed or captured by anyone who visits the Site, therefore you should avoid posting sensitive personal data that you would not want to be available to the public.


Additionally, when you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, including your name, billing address, shipping address, payment information (including credit card numbers), email address, and phone number. We refer to this information as “Order Information”.

INFORMATION THAT IS AUTOMATICALLY COLLECTED WHEN YOU VISIT HPDrx

When you access the Site, we and our third-party partners may automatically collect certain information about your visit using tools such as cookies, web beacons, and other similar technologies. The information collected automatically when you visit the Site may include your IP address, time zone, characteristics of your operating system, information about your browser and system settings, data about the computer or mobile device you use to access the Site, unique device identifiers, clickstream data (which shows the page-by-page path you take as you browse the Site). We or our third-party partners may combine information that each of us collects automatically with other information about you, including information you choose to provide.


When you visit the Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically collected information as “Device Information”.

We collect Device Information using the following technologies:

  • “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. This Site may use cookies (such as HTTP and HTML5 cookies and Flash cookies), as well as other types of local storage. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org.
  • “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
  • “Web beacons”, “tags”, and “pixels” are electronic files used to record information about how you browse the Site. To manage our automatic data collection, we may place tags (often referred to as “web beacons”) on pages on the Site or in emails we send to you. Web beacons are small files that link web pages to particular web servers and their cookies, and they may be used for a variety of purposes, such as counting the number of visitors to the Site, analyzing how users navigate around the Site, assessing how many emails that we send are actually opened and which articles or links are viewed by visitors.
  • We also use third-party web analytics services, such as Google Analytics, on the Site, to provide us with statistics and other information about visitors to the Site.
  • “Do Not Track” Signals. Your browser settings may allow you to automatically transmit a “do not track” signal to websites and online services you visit. At this time there is no consensus among industry participants as to the meaning of “do not track” in this context. Like many other websites, HPDrx.com is not configured to respond to “do not track” signals from browsers. Click here to learn more about “do not track” signals.
  • Companies that provide certain third-party apps, tools, widgets, and plug-ins that may appear on the Site (for example, Facebook “Like” buttons), also use automated means to collect information regarding your interactions with these features. This information collection is subject to the privacy policies or notices of those providers.

HOW WE MAY USE INFORMATION WE COLLECT

We may use the information gathered on HPDrx for various purposes, including the purposes listed below. For example, if you were to contact us with a question and provide your email address, we would use the email address you provided to respond to your inquiry. In addition, we use the information we collect from you and through the Site to:

  • Provide products and services you request (such as when you fulfill your order when you purchase an item from our store);
  • Respond to requests, questions, and comments, and provide other types of user support;
  • Offer you products and services via marketing communications, or direct you to portions of this Site or other websites, that we believe may interest you;
  • To serve advertising, content, and offers to you based on your interests and online activities, from us or third parties;
  • Communicate about, and administer your participation in, events, programs, contests, and other offers or promotions;
  • Carry out, evaluate, and improve our business (which may include developing new features for the Site; analyzing and enhancing the user experience on the Site; assessing the effectiveness of our marketing and advertising; and managing our communications);
  • Perform data analytics regarding usage of the Site (including market and customer research, trend analysis, financial analysis, and anonymization of personal data);
  • Guard against, identify, and prevent fraud and other criminal activity, claims, and other liabilities; and
  • Comply with applicable legal requirements, law enforcement requests, and our company policies.

HOW WE MAY SHARE INFORMATION

Our agents, vendors, consultants, and other service providers may have access to the information we collect through the Site to carry out work on our behalf. Those parties are subject to confidentiality obligations and are restricted from using personal data collected through the Site for purposes other than to provide the requested assistance. In addition, we may share information:

  • With our affiliates for internal business purposes;
  • If we are required to do so by law, regulation, or legal process (such as a court order or subpoena);
  • In response to requests from government agencies, such as law enforcement authorities;
  • If we believe disclosure is necessary or appropriate to prevent physical harm or financial loss, or in connection with an investigation of suspected or actual illegal activity;
  • With respect to analytics and statistical information, to inform advertisers about the nature of our user base;
  • In the event we sell or transfer all or a portion of our business or assets (including a reorganization, dissolution, or liquidation); and
  • With your consent or at your discretion.

BEHAVIORAL ADVERTISING

As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

You can opt out of targeted advertising by using the links below:

  • Facebook: https://www.facebook.com/settings/?tab=ads
  • Google: https://www.google.com/settings/ads/anonymous
  • Bing: https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads

Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.

DATA RETENTION AND ACCESS

We will retain your personal data only for as long as necessary for the purposes it was retained, such as to enable you to use the Website and your products or to provide services to you. In some instances, we may retain data for longer periods  to comply with applicable laws (including those regarding document retention), resolve disputes with any parties, and otherwise as necessary to allow us to conduct our business. When you place an order through the Site, we will maintain your Order Information for our records unless and until you ask us to delete this information.

All personal data we retain will be subject to this Privacy Policy and our internal retention guidelines. We respect your control over your information and, upon request, we will seek to confirm your identity and whether we hold or are processing information that we have collected from you. You also have the right to amend or update inaccurate or incomplete personal information, request deletion of your personal information, or request that we no longer use it. Under certain circumstances we will not be able to fulfill your request, such as if it interferes with our regulatory obligations, affects legal matters, we cannot verify your identity, or involves disproportionate cost or effort, but in any event, we will respond to your request within a reasonable timeframe and provide you an explanation. In order to make such a request of us, please email us at info@hpdrx.com.

HOW WE PROTECT PERSONAL INFORMATION

We maintain appropriate administrative, technical, and physical safeguards designed to protect the personal data you provide against accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. That said, it is not possible to guarantee the security of information transmitted online, and you assume some risk about the security of information you provide through any website, including this Site. If you have a data security inquiry, you may contact us by emailing info@hpdrx.com. To request an invite to our bug bounty program to submit reports on vulnerabilities found on HPDrx.com, you may contact us by emailing info@hpdrx.com.

LINKS FROM HPDrx TO OTHER WEBSITES

On this Site, we may provide links to other websites that are controlled by third parties. Linked websites may have their own privacy notices or policies, which we strongly suggest you review. We are not responsible for the content, usage terms, or privacy policies of websites that we do not own or control.

SURVEYS AND QUIZZES

While you are visiting HPDrx, you may have the opportunity to participate in surveys, quizzes, or other interactive features that request information about you and your opinions and preferences. Your participation in these features is entirely voluntary. If you do choose to participate, please be aware that these features may be operated by a third party that is not controlled by HPDrx, and therefore the information you provide may be collected by the third party and subject to its privacy policy.

CHILDREN'S PRIVACY

This Site is not designed or intended for use by children, and we do not knowingly collect personal data from children under the age of 16. If we become aware that we have collected personal data from a child under the age of 16, we will delete any such information.

INFORMATION FOR USERS OUTSIDE THE UNITED STATES

Your personal data may be stored, transferred, and processed in and to the United States and in other countries by our affiliates and/or service providers. The data protection laws in these countries may provide a lower standard of protection for your personal data than your country of residence. We take great care in protecting your personal data and have put in place adequate mechanisms to protect it when it is transferred internationally. We will transfer your personal data in compliance with applicable data protection laws and will implement suitable safeguards to ensure that your personal data is adequately secured by any third party that will access your information (for instance, by using the Model Clauses as approved by the European Commission).

By using our Site and providing personal data to us, you consent to the terms of this Privacy Policy and the collection, use, maintenance, transfer to and processing of your personal data in the United States or other countries or territories, and, unless otherwise stated in this Privacy Policy, we use this consent as the legal basis for that data transfer.

If you have questions or wish to obtain more information about the international transfer of your personal data or the implemented safeguards, please send us an email to info@hpdrx.com.

HOW WE'LL INFORM YOU ABOUT CHANGES TO THIS PRIVACY POLICY

We may update this online privacy policy periodically to reflect changes to our privacy practices, such as how we collect or use personal data. If we propose to make any material changes, we will post a prominent notice on the HPDrx.com home page to notify you of significant changes to this policy, and we indicate at the top of the policy the date when it was most recently updated. We encourage you to periodically review this page for the latest information on our privacy practices.

HOW TO CONTACT US

If you have questions about this policy or about our privacy practices, you may contact us by emailing info@hpdrx.com.

  • If you are a California resident inquiring about your California privacy rights, please include “California privacy rights request” in the subject line of your email.
  • If you are a resident of the European Economic Area inquiring about your rights under the General Data Protection Regulation (“GDPR”), please include “GDPR privacy rights request” in the subject line of your email.

You may also write to:
Wellness Holdings, LLC
2633 Lincoln Blvd. #850
Santa Monica, CA 90405

JURISDICTION SPECIFIC PROVISIONS

Our Notice to California ResidentsSubject to certain limits, under California law California residents may ask us to provide them with a list of the categories of personal data that we have disclosed to third parties for those third parties’ direct marketing purposes during the preceding calendar year, as well as the identity of those third parties. California residents may contact us at info@hpdrx.com to request this information.

If you are located in the European Economic Area (EEA):

1. Controller of your Personal Data

The controller of your personal data under this policy is Wellness Holdings, LLC, with an address of 127 Broadway, Suite 208, Santa Monica, CA 90401. Our local representative with respect to the GDPR can be contacted at info@hpdrx.com.

2. Legal Basis for Using Personal Data

We process your personal data only if we have a legal basis to do so, including:

  • to comply with our legal and regulatory obligations;
  • for the performance of our contract with you or to take steps at your request before entering into a contract;
  • for our legitimate interests or those of a third party;
  • where you have given consent to our specific use.

The purpose for which we use and process your information and the legal basis on which we carry out each type of processing is further explained below.

  • To provide products and services you request: we must process your data in order to deliver the services and process transactions according to the applicable contract between us.
  • To respond to requests, questions, and comments, and provide other types of user support: we must respond to requests, questions, and comments, and provide other types of user support in order to take steps at your request or according to the applicable contract between us.
  • To offer you products and services in marketing communications, or direct you to portions of this Site or other websites, that we believe may interest you: We may send electronic marketing communications to you if you have consented to these communications. It is in our legitimate interest to market our products and services to you by other means and to direct you to portions of this Site or other websites that we believe may interest you. We consider this use to be proportionate and will not be prejudicial or detrimental to you.
  • To communicate about, and administer your participation in, events, programs, contests, and other offers or promotions: We will send electronic communications to you if you have consented to these communications. With respect to other communications, it is in our legitimate interest to communicate with you and administer your participation in, our events, programs, contests, and other offers or promotions. We consider this use to be proportionate and will not be prejudicial or detrimental to you.
  • To carry out, evaluate, and improve our business (which may include developing new features for the Site; analyzing and enhancing the user experience on the Site; assessing the effectiveness of our marketing and advertising; and managing our communications: It is in our legitimate interests to process your personal data to carry out these activities. We consider this use to be proportionate and will not be prejudicial or detrimental to you.
  • To perform data analytics regarding usage of the Site (including market and customer research, trend analysis, financial analysis, and anonymization of personal data): It is in our legitimate interests to process your personal data to carry out these activities. We consider this use to be proportionate and will not be prejudicial or detrimental to you.
  • To serve advertising, content, and offers to you based on your interests and online activities, from us or third parties: We will serve you advertising, content, and offers to you based on your interests and online activities if you have consented to this processing.
  • To enable our affiliates or service providers to perform certain activities on our behalf: We must process your data in this manner in order to deliver the services and process transactions according to the applicable contract between us. It is also in our legitimate interest to enable our service providers and affiliates to perform certain activities on our behalf. We consider this use to be proportionate and will not be prejudicial or detrimental to you.
  • To notify you of any changes to the Website that may affect you: We must process your data to deliver the services and process transactions according to the applicable contract between us.
  • If we are required to do so by law, regulation, or legal process (such as a court order or subpoena); In response to requests from government agencies, such as law enforcement authorities; If we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation of suspected or actual illegal activity; and In the event we sell or transfer all or a portion of our business or assets (including a reorganization, dissolution, or liquidation): We conduct this processing to comply with our legal obligations and to protect the public interest.
  • Guard against, identify, and prevent fraud and other criminal activity, claims, and other liabilities; and Comply with applicable legal requirements, law enforcement requests, and our company policies: We conduct this processing to comply with our legal obligations and to protect the public interest.

3. International Transfers

Some of our processing of your data will involve transferring your data outside the European Economic Area (“EEA”). Some of our external third-party service providers are also based outside of the EEA, and their processing of your personal data will involve a transfer of data outside the EEA. This includes the United States. Where personal data is transferred to and stored in a country not determined by the European Commission as providing adequate levels of protection for personal data, we take steps to provide appropriate safeguards to protect your personal data, including when appropriate entering into standard contractual clauses approved by the European Commission, obliging recipients to protect your personal data.

4. Retention of Personal Data

We will retain your data only for as long as necessary for the purposes it was retained, such as to enable you to use the Site and your products or to provide services to you. In some instances, we may retain data for longer periods to comply with applicable laws (including those regarding document retention), resolve disputes with any parties, and otherwise as necessary to allow us to conduct our business. All personal data we retain will be subject to this Privacy Policy and our internal retention guidelines.

5. Data Subject Access Rights

You have the following rights:

  • Right of access to your personal data: You have the right to ask us for confirmation on whether we are processing your personal data, and access to the personal data and related information.
  • Right to correction: You have the right to have your personal data corrected, as permitted by law.
  • Right to erasure: You have the right to ask us to delete your personal data, as permitted by law.
  • Right to withdraw consent: You have the right to withdraw consent that you have provided.
  • Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a supervisory authority in the member state of your habitual residence.
  • Right to restriction of processing: You have the right to request the limiting of our processing under limited circumstances.
  • Right to data portability: You have the right to receive the personal data that you have provided to us, in a structured, commonly used and machine-readable format, and you have the right to transmit that information to another controller, including to have it transmitted directly, where technically feasible.
  • Right to object: You have the right to object to our processing of your personal data, as permitted by law, under limited circumstances.

In order to exercise any of these rights, please contact us according to the How to Contact Us section. Please note that the above rights are not absolute and we may be entitled to refuse requests, wholly or partly, where exceptions under the applicable law apply.