Privacy

Karuna Labs (“Company”, “us”, “our”) is committed to protecting your privacy.  We have prepared this Privacy Policy to describe to you our practices regarding the collection, storage and use of information we collect from: (a) visitors to our websites (located at www.karunalabs.com, “Visitors”)

Questions

If you have any questions, concerns or complaints about our Privacy Policy or our data collection or processing practices, or if you want to report any security violations to us, please contact us at the following address or email:

Karuna Labs 

Attn: Privacy Officer, Alison Tarwater

525 York St

San Francisco, CA 94110

privacy@karunalabs.com

Changes to This Privacy Policy  

As a visitor to our website, the collection, use, and sharing of your data are subject to this privacy policy. This policy is periodically reviewed and may be amended from time to time. Any amendments to our privacy policy will be posted as a notification on our privacy policy page.  Continued use of our Site or Service, following notice of such changes shall indicate your acknowledgement of such changes and agreement to be bound by the terms and conditions of such changes. 

Website Specific Privacy Policy

Information Collected via Technology: 

Karuna Labs uses Google Analytics and similar technologies such as cookies and pixels to improve our services. Google Analytics provides an approximate location derived from the IP address that visited our website. Other anonymous data such as browser information, device information, and language are collected. We do not collect information such as age, gender, sex, or monetary information. You can control cookies through your browser settings and other tools. 

  • Cookies: When someone visits a website, that site or analytics services used by that sight may store or retrieve information on your browser, mostly in the form of cookies. Cookies are small text files that are transferred to a computer’s hard disk by a website. This information might be about you, your preferences or your device and is typically used to make the site work as you expect it. The information does not usually directly identify you, but it can give you a more personalized web experience. Karuna’s website uses cookies for Google Analytics.
  • Information Collected by Our Servers. To make our Site and Services more useful to you, our servers (which may be hosted by a third party service provider) collection information from you, including your browser type, operating system, Internet Protocol (“IP”) address (a number that is automatically assigned to your computer when you use the Internet, which may vary from session to session), domain name, and/or a date/time stamp for your visit.
  • Log Files. AS is true of most websites, we gather certain information automatically and store it in log files. This information includes IP addresses, browser type, Internet Service Provider (“ISP”), referring/exit pages, operating system, date/time stamp, and clickstream data. We use this information to analyze trends, administer the Site, and track users’ movements around the Site.
  • Analytics Services. We use Google Analytics to help analyze how users use the Site. We may receive reports based on these parties’ use of these tools on an individual or aggregate basis. We use the information we get from Analytics Services only to improve our Site and Services. The Analytics Services use Analytics Information to compile reports on user activity. The Analytics Services may also transfer information to third parties where required to do so by law, or where such third parties process Analytics Information on their behalf. Google Analytics’ ability to use and share Analytics Information is restricted by its Terms of Use and Privacy Policy. By using our Site and Services, you consent to the processing of data about you by Google Analytics in the manner and for the purposes set out above. 

Information You Provide to Us: 

Clinics and others looking for more information about working with Karuna Labs have the option of submitting contact information to us through the website.  

  • If you tell us where you are (e.g., by allowing your mobile device to send us your location), we may store and use that information as part of our product development or quality control processes.
  • If you provide us feedback or contact us via e-mail, we will collect your name and e-mail address, as well as any other content included in the e-mail, in order to send you a reply.

Website Specific Use of Personal Data

We use Personal Data in the following ways:  

  • Improve the quality of your experience when you interact with our Site and Services;
  • Respond to your inquiries on our site for more information and
  • Periodically send you free newsletters and e-mails that directly promote the use of our Site or Services. When you receive newsletters or promotional communications from us, you may indicate a preference to stop receiving further communications from us and you will have the opportunity to “opt-out” by following the unsubscribe instructions provided in the e-mail you receive or by contacting us directly (please see contact information above). Despite your indicated e-mail preferences, we may send you service related communications, including notices of any updates to our Terms of Use or Privacy Policy.
  • Allow you to log in to our database to view your own data 

Third Party Websites

Our Site may contain links to third party websites.  When you click on a link to any other website or location, you will leave our Site and go to another site and another entity may collect Personal Data or Anonymous Data from you.  We have no control over, do not review, and cannot be responsible for, these outside websites or their content. Please be aware that the terms of this Privacy Policy do not apply to these outside websites or content or to any collection of your Personal Data after you click on links to such outside websites.  The links to third party websites or locations are for your convenience and do not signify our endorsement of such third parties or their products, content or websites.

How do we secure personal data?

The Company maintains reasonable security measures to safeguard Personal Data and PHI from loss, interference, misuse, unauthorized access, disclosure, alteration or destruction. The Company also maintains reasonable procedures to help ensure that such data is reliable for its intended use and is accurate, complete, and current.

How long do we keep your personal data and PHI for?

We only keep data for as long as the data is needed to perform the Services or for as long as required by law or regulation.

California Online Privacy Protection Act (CalOPPA)

CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require any person or company in the United States (and conceivably the world) that operates websites collecting Personally Identifiable Information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals or companies with whom it is being shared. See more by visiting the CalOPPA website.

According to CalOPPA we agree to the following: users can visit our website anonymously, once our privacy policy is created, it will be available as a link on our homepage, our privacy policy link includes the word ‘privacy’ and can be easily found when entering our website, users of our website or application will be notified of any changes to our privacy policy on our privacy policy page and/or via email, amd users of our website or application are able to change their personal information by emailing us.

Software Specific Privacy Policy: 

What information do we collect?

“Personal Data” means information that alone or when in combination with other information may be used to readily identify, contact, and locate you, such as: name, address, email address, or phone number.

“Anonymous Data” means data that is not associated with, or linked to, your Personal Data or PHI. Anonymous Data does not, by itself, permit the identification of individual persons. We collect Personal Data, PHI and Anonymous Data, as described below.

“Protected Health Information (PHI)” means information that is created or received by Karuna Labs and relates to the past, present, or future physical or mental health or condition of the Patient; the provision of health care to a Patient; or the past, present, or future Payment for the provision of health care; and that identifies the Patient or for which there is a reasonable basis to believe the information can be used to identify the Patient. Protected health information includes information about persons living or deceased whether in electronic, printed, or spoken form. PHI may include many common identifiers, such as name, address, and birth date. Identifying information about Patients obtained by or created by Karuna Labs is treated as PHI for purposes of this Policy unless it has been de-identified consistent with applicable law.

We collect the following types of data:

  • Name
  • Date of Birth
  • Address
  • Email Address
  • Telephone Number
  • Gender
  • Height
  • Health Data
  • Biometric Data from sessions
  • Location treatment is provided
  • Name of Physician
  • Date(s) of Treatment(s)

Information you provide to us

  • Certain Services, such as two-factor authorization, may require our collection of your phone number. We may associate that phone number to your mobile device identification information.
  • We retain information on your behalf, such as files and messages that you store using your Account.
  • We use quality complaint information (including images) to provide customer support assistance to you
  • We use information provided by you, your provider, and data collected during your Karuna sessions to provide progress reporting to physicians, all of which may be shared with your insurer
  • We may send you email notifications about messages in our customer feedback portal if you have filed a ticket with us

Collection of Personal Health Information

Customers or Healthcare Providers using our Customer’s products may load PHI onto our servers as part of the Services. Customers and Healthcare providers may only provide PHI to us with authorization from the individual Patient who is the subject of the PHI. If you do not have such an authorization, you may not load any PHI onto our servers or use our Services in any way for those Patients. It is the responsibility of the Customer and Healthcare Provider to ensure that they have received appropriate authorization from the Patient.

General Use of Personal Data

We use Personal Data in the following ways:  

  • facilitate the creation of, and secure, your Account on our network;
  • identify you as a user in our system;
  • identify you as a recipient of our Services;
  • Identify you as part of a clinical network to provide you access to that clinic’s services;
  • provide the Services you request;
  • send you a welcome e-email to verify ownership of the e-mail address provided when your Account was created; 
  • send you administrative and security notifications, software updates or password reset notifications via e-mail and other communication means
  • Provide customer support to respond to any issues you have using our services

Use of PHI

We only use PHI for the purposes that have been authorized by the subject of the PHI for provision of the Services. Customers are responsible for obtaining the authorization from the Patient and must transmit any withdrawal of consent for use of PHI to Karuna Labs. Karuna does not currently have a direct relationship with Patients and relies on Customers and Healthcare Providers to obtain and appropriately document the consent and withdrawal of the consent.

Creation of Anonymous Data

We may create Anonymous Data records from Personal Data and/or PHI by excluding information that makes the data personally identifiable. We use this Anonymous Data to analyze request and usage patterns so that we may enhance the content of our Services and improve Site navigation. We may also use this Anonymous Data to perform outcome studies, market research, improve manufacturing processes, or assess patient engagement. We may share this Anonymous Data with third parties for similar use by such third parties. We reserve the right to use Anonymous Data and aggregated and other de-identified information for any purpose and disclose Anonymous Data to third parties in our sole discretion.

Disclosure of Personal Data and PHI  

Limited members of the Engineering, Product and Customer Support departments of Karuna may access and otherwise process Personal Data and PHI in connection with their job responsibilities or contractual obligations. 

How do we secure personal data?

The Company maintains reasonable security measures to safeguard Personal Data and PHI from loss, interference, misuse, unauthorized access, disclosure, alteration or destruction. The Company also maintains reasonable procedures to help ensure that such data is reliable for its intended use and is accurate, complete, and current.

How long do we keep your personal data and PHI for?

Karuna Labs only keeps data for as long as the data is needed to perform the Services or for as long as required by law or regulation. 

Your Rights to your Personal Data and PHI

If you would like to view, request changes to, or ask for deletion of any of your Personal Data please contact customer service at privacy@karunalabs.com. You can stop new collection of information by ceasing usage of the web application or terminating your account. 

If you are a Patient and you want to withdraw your sense for use of your PHI, please contact the clinic where you used or were prescribed Karuna products. Karuna Labs relies on the consent obtained by our Customers and therefore you must directly contact the Customer to withdraw your consent.

Karuna Labs is required by law and regulation to keep some PHI for safety monitoring and chain of identity. If you withdraw your consent, Karuna Labs will only keep the information that is required by law or regulation.