Privacy policy

We at Cohero Health, Inc. (“Cohero Health,” “we,” “us,” or “our”) have created this privacy policy (this “Privacy Policy”) because we know that you care about how information you provide to us is used and shared. This Privacy Policy relates to the information collection and use practices of Cohero Health in connection with our Services, which are made available to you through a variety of platforms, including, but not limited to, www.coherohealth.com and https://store.coherohealth.com (the “Sites”) and our BreathSmart mobile app, which is accessible through tablets, smart phones, connected televisions, and other devices (the “App”) and operates in conjunction with paired Bluetooth-enabled HeroTracker medicine inhaler sensors and mSpirometer sensors (the “Devices”), as well as BreathSmart personal web dashboards (“Dashboards”) . The Sites, App and Dashboards are collectively referred to as the “Platform.”

Description of Users and Acceptance of Terms

This Privacy Policy applies to visitors to the Sites, who view only publicly-available content (“Visitors”), individuals who have signed up to use our Services (“Users”), clinicians and health care providers who have signed up to use our Services (“Providers”) and caregivers of Users who are granted access to the Services through Dashboards (“Caregivers”).

By visiting our Site(s), Visitors are agreeing to the terms of this Privacy Policy and the accompanying Terms of Use.

By signing up, accessing, and/or using the Platform, each Visitor, User, Provider and Caregiver is agreeing to the terms of this Privacy Policy and the accompanying Terms of Use.

Capitalized terms not defined in this Privacy Policy shall have the meaning set forth in our Terms of Use.

The Information We Collect and/or Receive

1. Personal Information

When you sign up to use the Services as a User, Provider or a Caregiver you will be required to provide us with certain personal information about yourself, such as, your first and last name, and e-mail address.

If you would like to use the App as a User, you may be required to purchase a subscription from one of our Sites and you will need to download the App from the Apple, Android or any other app store through which the App is made available to you. You will also need to create an account on our ecommerce Site prior to purchasing your App subscription and a separate BreathSmart account in order to download, set up and use our App. During the subscription purchase, account registration and App setup process, you will be asked to create a login ID and password and provide personal information about yourself, such as your first name, last name, e-mail address, postal address, height, weight, and date of birth. If you are purchasing a subscription to the App for your child User, you or your child will be required to enter the same types of information for the intended User. If you use our ecommerce Site to purchase Devices and subscriptions to our App, you will also need to provide credit card or other payment account information, as well as a billing and shipping address and telephone number.

Users may be able to link their Facebook or other social media account with the App. If you link your Facebook or any other social media account with the App, you are authorizing Cohero Health to collect, store, and use, in accordance with this Privacy Policy, any and all information that you agreed that Facebook, Inc., or such other social media company could provide to Cohero Health through its Application Programming Interface (“API”). Such information may include, without limitation, your first and last name, username, profile picture, unique social media identifier and access token, and e-mail address.

If you would like to know more about our company or are interested in trying our products, you will need to provide your name, e-mail address, and age.

All information we collect and/or receive under this section is collectively called “Personal Information.”

We do not collect any Personal Information from you when you use the Platform unless you provide us with the Personal Information voluntarily.

2. Health Information

When you sign up to use the App as a User, you will also be asked to provide us with background health information that relates to your past, present, or future physical or mental health or condition, including but not limited to, medications, medication schedule, medication usage history, and spirometry data. When you use the App paired with one or more HeroTracker Bluetooth-enabled medication inhaler sensors, the App will collect and log information regarding the dates and times when you use your inhaler and related medications as well as any information you log regarding your symptoms, lung function, environmental conditions, or other triggers for attacks. If you use our App with a paired mSpirometer lung function sensor, the App will also collect and record spirometry data to help you monitor your lung function over time. This data will include measurements of peak flow, FEV1, FVC and other clinical metrics. All of the foregoing information described in this paragraph is referred to collectively as “Health Information”). Your Health Information is shared with Providers and Caregivers. You may add and remove Providers and Caregivers by the following steps: 1. Scroll to the More Section in the App, 2. Click on Caregiver, 3. Select Caregiver, 4. Click Delete, 5. Are you sure you want to delete caregiver? 6. Delete or Cancel

3. Geolocational Information

In order to provide certain features and functionality of the App, we may, with your consent, automatically collect geolocational information from your mobile device, your wireless carrier, or certain third-party service providers (“Geolocational Information”). Collection of such Geolocational Information occurs only when the App is running on your mobile device. You may decline to allow us to collect such Geolocational Information, in which case Cohero Health will not be able to provide certain features of the App to you.

4. Other Information

In addition to information noted above, we may collect additional information (the “Other Information”). Such Other Information may include:

(a) From Your Activity.

Information that we automatically collect when you use the Platform, including, without limitation:

IP addresses, browser type and language, referring and exit pages and URLs, date and time, amount of time spent on particular pages, what sections of the Platform you visit, etc.;

Information about a mobile device, including universally unique ID (“UUID”), App type and version (e.g., iOS or Android), carrier and country location, hardware and processor information (storage, chip speed, camera resolution, NFC enabled, and network type (Wi-Fi, 2G, 3G, 4G);

Activity and usage information occurring via the Platform, including tagging data, favorites, preferences, session lengths; and similar data

(b) From Cookies.

We collect information using “cookie” technology. Cookies are small packets of data that a website stores on your computer’s or mobile device’s hard drive so that your computer will “remember” information about your visit. We may use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your computer until you delete them) to help us collect Other Information and to enhance your experience using the Platform. If you do not want us to place a cookie on your hard drive, you may be able to turn that feature off on your computer or mobile device. Please consult your Internet browser’s documentation for information on how to do this and how to delete persistent cookies. However, if you decide not to accept cookies from us, the Platform may not function properly.

(c) Third Party Analytics.

We use third-party analytics services (such as Crashlytics and Google Analytics) to evaluate your use of the Platform, compile reports on activity, collect demographic data, analyze performance metrics, and collect and evaluate other information relating to the Platform and mobile and Internet usage. These third parties use cookies and other technologies to help analyze and provide us the data. By accessing and using the Platform, you consent to the processing of data about you by these analytics providers in the manner and for the purposes set out in this Privacy Policy.

For more information on our third-party analytics providers, including how to opt out from certain data collection, please visit the following links:

For Google Analytics, please visit: https://www.google.com/analytics. You may opt-out of data collection and use by Google Analytics by visiting https://tools.google.com/dlpage/gaoptout/.

For Crashlytics, please visit: https://get.fabric.io

Please be advised that if you opt out of any service, you may not be able to use the full functionality of the Platform.

Information Collected by or Through Third-Party Companies

We may share Other Information about you with third parties for ad distribution and ad optimization (defined as the tailoring, targeting (i.e., behavioral, contextual, and retargeting), analyzing, managing, reporting, and optimizing of ads). These third parties, including services such as Google Analytics and DoubleClick, may use cookies, pixel tags (also called web beacons or clear gifs), and/or other technologies to collect such Other Information for such purposes. Pixel tags enable us, and these third-parties, to recognize a browser’s cookie when a browser visits the site on which the pixel tag is located in order to learn which advertisement brings a user to a given site. For instance, we may use first-party cookies (such as Google Analytics cookies) and third-party cookies (such as the DoubleClick cookie) together (i) to inform, optimize, and serve ads based on your past visits to our Platform and (ii) report how your ad impressions, uses of ad services, and interactions with the foregoing are related to your visits to the Platform. You may opt-out of the tailoring of advertising based on information we collect. To learn more about the use of this information, or to choose not to have this information used by our providers or third party advertising partners by opting out, please visit the Network Advertising Initiative by clicking http://www.networkadvertising.org/managing/opt_out.asp. To learn more about how Google uses data, visit www.google.com/policies/privacy/partners. You may opt-out of data collection and use by Google Analytics by visiting https://tools.google.com/dlpage/gaoptout/.

Treatment and Use of Health Information and Personal Information; Sharing Authorization

The App provides Users with the ability to provide information to their Providers and Caregivers. Users’ provision of information to their Providers and Caregivers through the App may include Health Information and Personal Information. You (and not Cohero Health) are solely responsible for reviewing and approving any Providers and Caregivers before deciding whether to share your Health Information and Personal Information with such Providers or Caregivers.

As a User of the App, you hereby authorize Cohero Health to make the following disclosures and uses of your Health Information and Personal Information, in addition to the specific uses set forth in the “How We Use and Share the Information” section below:

Cohero Health may disclose Health Information and Personal Information to those Providers and Caregivers to whom you have granted access to view your Health Information.

Cohero Health may use Health Information and Personal Information as necessary in connection with the purposes described in the section below entitled “How We Use and Share Your Information.”

If you choose to share any of your Health Information through the App with any Provider or Caregiver, you acknowledge and agree that such information is made available to such Provider or Caregiver and their use of your information is not subject to the terms of this Privacy Policy. Further, if the Providers and Caregivers that you authorize to receive your Health Information from Cohero Health are not subject to federal or state health information privacy laws, subsequent disclosure by such persons and entities may not be prohibited and/or protected by those laws. You may revoke all or part of the authorization granted to Cohero Health above in writing at any time by sending a signed and dated statement to Cohero Health as set forth in the “How to Contact Us” section below.

How We Use and Share the Information

We use Personal Information, Geolocational Information, and Other Information (collectively, the “Information”) to process, confirm and fulfill orders for our Devices and App subscriptions; to enable Users to track their medication use and lung function over time, log their symptoms, triggers and environmental conditions and share related reports and information with authorized Providers and Caregivers; to facilitate communications among Users, Cohero, Providers and Caregivers; to provide medication and other reminders, environmental alerts and insights; to provide, analyze and improve our Platform and our Services; to solicit your feedback; and to inform you about our company, products and services and those of our third-party marketing partners. We may also use any information we collect for any other purpose disclosed at the time of collection or to which you consent.

You also authorize us to use and/or share your Information as described below.

Agents, Providers and Related Third Parties. We may engage other companies and individuals to perform certain business-related functions on our behalf. Examples may include providing technical assistance, order fulfillment, payment processing, analytics, customer service, and marketing assistance. These other companies will have access to the Information only as necessary to perform their functions and to the extent permitted by law. We may also share your Information with any of our parent companies, subsidiaries, or other companies under common control with us.

Payment Processing. For online payments, we use the payment services of Authorize.Net. We do not process, record or maintain your credit card or other payment account information. For more information on how payments are handled, or to understand the data security and privacy afforded such information, please refer to https://www.authorize.net/company/privacy/.

Aggregated Information. In an ongoing effort to better understand our users and our Platform, we might analyze and otherwise use your Information in aggregate form in order to operate, maintain, manage, and improve the Platform and our Services. This aggregate information does not identify you personally. We may share this aggregate data with our affiliates, agents, and service providers. We may also disclose aggregated user statistics in order to describe our Platform and Services to current and prospective business partners and disclose aggregated data to other third parties for other lawful purposes.

De-identified Information. We may analyze and otherwise use your Information in de-identified form and we may share this de-identified data with our affiliates, agents, and service providers. We may also disclose this de-identified data to current and prospective business partners and to other third parties for other lawful purposes.

Business Transfers. As we develop our businesses, we might sell or buy businesses or assets. In the event of a corporate sale, merger, reorganization, sale of assets, dissolution, bankruptcy or similar event, your Information may be part of the transferred assets.

Legal Requirements. To the extent permitted by law, we may also disclose your Information: (i) when required by law, court order, or other government or law enforcement authority or regulatory agency; or (ii) whenever we believe that disclosing such information is necessary or advisable, for example, to protect the rights, property, or safety of Cohero Health or others.

Private Messaging

Providers and Caregivers may be able to communicate with their Users and with each other via direct messages sent through the Services. If you choose to send a direct message through the Services, you acknowledge and agree that none of the information contained in that message (including, without limitation, Personal Information and/or Health Information) is covered by this Privacy Policy and we are not responsible or liable in any way for how the recipient uses that information.

Accessing and Modifying Information and Communication Preferences

If you have provided us any Personal Information, you may access, remove, review, and/or make changes to the same by contacting us at privacy@coherohealth.com. In addition, you may manage your receipt of marketing and non-transactional communications by clicking on the “unsubscribe” link located on the bottom of any Cohero Health marketing e-mail. We will use commercially reasonable efforts to process such requests in a timely manner. You should be aware, however, that it is not always possible to completely remove or modify information in our subscription databases.

How We Protect the Information

We take commercially reasonable steps to protect your Information from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. Please understand, however, that no security system is impenetrable. We cannot guarantee the security of our databases or the databases of the third parties with which we may share such information, nor can we guarantee that the information you supply will not be intercepted while being transmitted over the Internet. In particular, e-mail sent to us may not be secure, and you should therefore take special care in deciding what information you send to us via e-mail.

External Sites

The Platform may contain links to External Sites. Cohero Health has no control over the privacy practices or the content of these External Sites. As such, we are not responsible for the content or the privacy policies of those External Sites. You should check the applicable third-party privacy policy and terms of use when visiting any External Sites.

Children’s Privacy

We do not knowingly collect Personal Information from children under the age of 13 without parental consent. If you are under 13, please do not give us any Personal Information through the Sites or use any aspect of the Platform without your parents’ permission. We encourage parents and legal guardians to monitor their children’s Internet usage and to help enforce our Privacy Policy by instructing their children never to provide Personal Information through the Platform without their permission. If you have reason to believe that a child under the age of 13 has provided Personal Information to us without parental consent, please contact us, and we will endeavor to delete that information from our databases.

If you purchase one or more of our Devices and pair them with our App for your child’s use, you agree that we may collect from your child User all of the Personal Information, Health Information, Geolocational Information and Other Information described above and use and share all such information in accordance with this Privacy Policy. Without limiting the generality of the foregoing sentence, by purchasing a subscription to our App for use by your child, you agree that: (1) Cohero may share your child’s Personal Information and Health Information with any Providers and Caregivers that you or your Child authorize to receive such information through our Services; (2) Cohero may communicate directly with your child through the App and by using his or her Personal information, including to send emails regarding our company and our products and services as well as products and services offered by our third-party marketing partners.

We will not require a child User to disclose more Personal Information or Health Information than is reasonably necessary to enable your child to participate in any activities offered through our Services. If you are designated as your child’s Caregiver through your child’s App settings, you will be able to access and review much of the Personal Information and Health Information that we collect from your child through the Services via your Dashboard. You can also can request to review all of your child’s Personal Information and Health Information and direct us to delete or refuse to allow any further collection, use or sharing of such information by contacting us at support@coherohealth.com. You can also use the same email address to direct us to disable the sharing of your Child’s Personal and Health Information with particular Providers or Caregivers, while continuing to agree to the collection and use of your child’s information to provide the Services to you and your Child. We reserve the right to condition your access to and ability to manage your child’s information on the completion of steps reasonably calculated to verify your identity and relationship to the applicable child User.

The operator of our App is Cohero Health, Inc., 12 East 49th Street, New York, NY 10017, telephone, 1- 833-426-4376, email address: privacy@coherohealth.com

Important Notice to Non-U.S. Residents

The Platform, the Services and their servers are operated in the United States. Please be aware that your Information, including your Personal Information, may be transferred to, processed, maintained, and used on computers, servers, and systems located outside of your state, province, country, or other governmental jurisdiction where the privacy laws may not be as protective as those in your jurisdiction. If you are located outside the United States and choose to use the Platform and/or the Services, you hereby irrevocably and unconditionally consent to such transfer, processing, and use in the United States.

California Residents

Under California Civil Code Section 1798.83, California residents who have an established business relationship with Cohero Health may choose to opt out of our sharing their personal information with third parties for direct marketing purposes. If you are a California resident and (1) you wish to opt out; or (2) you wish to request certain information regarding our disclosure of your personal information to third parties for the direct marketing purposes, please send an e-mail to privacy@coherohealth.com with “Privacy Policy” in the subject line or write to us at:

Cohero Health, Inc. 12 East 49th Street, New York, NY 10017, NY 10017

In addition, Cohero Health does not monitor, recognize, or honor any opt-out or do not track mechanisms, including general web browser “Do Not Track” settings and/or signals.

Changes to This Privacy Policy

This Privacy Policy is effective as of the date stated at the top of this Privacy Policy. We may change this Privacy Policy from time to time with or without notice to you. Any such changes will be posted on the Platform. By accessing the Platform and/or using the Services after we make any such changes to this Privacy Policy, you are deemed to have accepted such changes. Please be aware that, to the extent permitted by applicable law, our use of your information is governed by the Privacy Policy in effect at the time we collect the Information. Please refer back to this Privacy Policy on a regular basis.

How to Contact Us

If you have questions about this Privacy Policy, please contact us via e-mail at privacy@coherohealth.com with “Privacy Policy” in the subject line.

POL-IT-000197 1.2019