Supplemental policy. This Consumer Health Data Privacy Policy supplements the DoseAdvisor Privacy Policy. It describes how GlucoWorks LLC handles Consumer Health Data as defined under the Washington My Health My Data Act (MHMDA), the Nevada Consumer Health Data Privacy Law, and similar state consumer health data privacy laws.
Contents
  1. 1. Introduction and Scope
  2. 2. Definitions
  3. 3. Categories of Consumer Health Data We Collect
  4. 4. How We Collect Consumer Health Data
  5. 5. How We Use Consumer Health Data
  6. 6. How We Share Consumer Health Data
  7. 7. Your Rights
  8. 8. Data Security
  9. 9. Data Retention
  10. 10. Changes to This Policy
  11. 11. Contact Us

01 Introduction and Scope

GlucoWorks LLC (“GlucoWorks,” “we,” “us,” or “our”) is a Wyoming limited liability company that develops diabetes management software. This Consumer Health Data Privacy Policy (“Policy”) supplements our Privacy Policy and describes how we collect, use, share, and protect Consumer Health Data as defined under the Washington My Health My Data Act (MHMDA), the Nevada Consumer Health Data Privacy Law, and similar state consumer health data privacy laws (collectively, “Consumer Health Data Laws”).

This Policy applies when Consumer Health Data Laws are applicable to the data we process. To the extent that health data we process is subject to the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, that data is exempt from Consumer Health Data Laws and is governed by our HIPAA Notice of Privacy Practices and applicable Business Associate Agreements.

DoseAdvisor — Dual Coverage: When DoseAdvisor is used by a patient under the care of a licensed healthcare provider who has established the patient’s account, data processing is governed by HIPAA and the applicable Business Associate Agreement. However, when DoseAdvisor is used outside a HIPAA-covered relationship — for example, by an individual who downloads the app directly from an app store for personal wellness use without a prescribing clinician — the health data collected constitutes Consumer Health Data subject to this Policy. GlucoWorks applies the protections described in this Policy to all DoseAdvisor users regardless of HIPAA coverage status.

02 Definitions

“Consumer Health Data” means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer’s past, present, or future physical or mental health status. This includes, but is not limited to:

03 Categories of Consumer Health Data We Collect

3.1 Website-Related Health Data

CategoryExamplesSource
Health-Related Browsing DataPages visited on gluco-works.com relating to diabetes management products, search queries on our siteWebsite analytics, cookies
Inquiry DataHealth-related information voluntarily included in contact form submissions or emailsDirect from consumer

3.2 DoseAdvisor Health Data

CategoryExamplesSource
Blood Glucose DataFingerstick BG readings, fasting glucose values, pre-meal and post-meal glucose readings, glucose targets and rangesDoseAdvisor patient app (manual entry), CGM integration (Dexcom, FreeStyle Libre)
Insulin Dosing DataCalculated insulin doses, insulin-to-carb ratios, insulin sensitivity factors, correction factors, basal insulin doses, dose historyDoseAdvisor patient app, clinician-prescribed parameters
Meal and Nutrition DataCarbohydrate counts, meal timing, meal type classificationsDoseAdvisor patient app (manual entry)
Continuous Glucose Monitor (CGM) DataReal-time and historical glucose readings, glucose trends, time-in-range statistics, CGM sensor session dataDexcom V3 API, LibreLinkUp integration
Insulin-on-Board (IOB) DataActive insulin calculations, insulin activity curves, stacking risk assessmentsDoseAdvisor dose calculation engine

04 How We Collect Consumer Health Data

05 How We Use Consumer Health Data

We use Consumer Health Data for the following purposes:

We do not sell Consumer Health Data. We do not use Consumer Health Data for advertising or marketing purposes unrelated to our diabetes management products.

06 How We Share Consumer Health Data

6.1 Service Providers (Website)

We share Consumer Health Data only with service providers who are contractually obligated to protect it and use it only for the purposes we specify:

ProviderPurposeData Shared
Google Cloud PlatformWebsite hostingServer logs that may contain browsing data
Google AnalyticsWebsite analyticsBrowsing patterns (with anonymized IP)

6.2 Service Providers (DoseAdvisor)

For DoseAdvisor, our service providers additionally include:

ProviderPurposeData Involved
Google Cloud Platform (Cloud Run, Cloud SQL, Cloud Storage)Application hosting, database, document storageAll DoseAdvisor application data, under GCP BAA
Expo (Expo Application Services)Push notification delivery for dose reminders and safety alertsDevice tokens, notification content (no glucose data in notification payloads)
Dexcom, Inc.CGM data integration via Dexcom V3 APIGlucose readings, CGM session data (user-authorized OAuth connection)
Abbott / LibreLinkUpCGM data integration for FreeStyle Libre usersGlucose readings (user-authorized connection)

6.3 Legal Requirements

We may disclose Consumer Health Data when required by law, in response to valid legal process, or to protect our rights, privacy, safety, or property.

6.4 With Your Consent

We may share Consumer Health Data with other parties when you provide affirmative consent.

07 Your Rights

Under applicable Consumer Health Data Laws, you have the following rights:

7.1 Right to Know / Access

You have the right to confirm whether we are collecting or sharing your Consumer Health Data and to request access to such data.

7.2 Right to Deletion

You have the right to request that we delete your Consumer Health Data. Upon verified request, we will delete your Consumer Health Data and direct our processors to do the same, subject to applicable legal exceptions.

7.3 Right to Withdraw Consent

Where we process Consumer Health Data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing before the withdrawal.

7.4 Right to Non-Discrimination

We will not discriminate against you for exercising any of your rights under Consumer Health Data Laws.

7.5 DoseAdvisor-Specific Data Rights

In addition to the rights described above, DoseAdvisor users have the following data rights:

7.6 How to Exercise Your Rights

To exercise any of the rights described above, you may:

We will respond to verified requests within the timeframes required by applicable law (typically 45 days for Washington MHMDA and 60 days for Nevada). We may request additional information to verify your identity before processing your request.

08 Data Security

We implement appropriate technical and organizational measures to protect Consumer Health Data, including:

09 Data Retention

We retain Consumer Health Data only for as long as necessary to provide our services and fulfill the purposes described in this Policy, or as required by law. Website browsing data that constitutes Consumer Health Data is retained for no longer than twenty-four (24) months. DoseAdvisor application data is retained in accordance with the DoseAdvisor Privacy Policy and applicable data retention schedules.

10 Changes to This Policy

We may update this Policy from time to time. We will post the revised Policy on this page with an updated effective date. Material changes will be communicated through a notice on our Website. Your continued use of our services after changes are posted constitutes your acceptance of the revised Policy.

11 Contact Us

If you have questions about this Consumer Health Data Privacy Policy or wish to exercise your rights, please contact us:

GlucoWorks LLC — Privacy Office
For consumer health data requests, MHMDA inquiries, and data subject rights.

privacy@gluco-works.com

For legal inquiries: legal@gluco-works.com
Mail: GlucoWorks LLC, Attn: Privacy, Wyoming, USA


DoseAdvisor is a trademark of GlucoWorks LLC. This Consumer Health Data Privacy Policy applies to consumer health data processed by GlucoWorks LLC through the DoseAdvisor platform and the gluco-works.com website. It supplements the DoseAdvisor Privacy Policy.

This document does not constitute legal advice.