Definitive Healthcare Virginia privacy policy (VCDPA Policy)

This Privacy Policy for Virginia residents supplements the information in Definitive Healthcare’s Privacy Policy. This policy defines the rights of Consumers who reside in the state of Virginia for Personal Data that is subject to the Virginia Consumer Data Protection Act (“VCDPA”). These rights include the Right to Know, Right to Opt-Out of Targeted Advertising, Right to Opt-Out of Sale of Your Personal Data, Right to Delete, Right to Correct, and Right to Non-Discrimination. This supplement of the Privacy Policy uses the terms “Consumer”, “Personal Data”, “Sale” and “Business Purpose” as they are defined in the VCDPA.

Right to know

Under the VCDPA, Consumers have the right to know the categories of Personal Data that are collected.

In the past 12 months, depending on your use of the Service, we may have collected the following Personal Data about you:

   
Category   
   
Examples of data collected   
   
Collect   
   
Disclose   
   
Sell   
   
Identifiers such as a real   name, alias, postal address, unique personal identifier, online identifier,  Internet Protocol address, email address, account name, social security   number, driver’s license number, passport number, or other similar   identifiers.   
   
  • Name (First, middle and last)
  • Business E-mail
  • Business Phone
  • Business Address   
  • Internet Protocol Address
  • National Provider Identification Number
  • Personal E-mail
  • Mobile phone number 
   
Yes   
   
Yes   
   
Yes   
   
Personal Data as defined in the VCDPA, such as name, contact information, education, employment,  employment history and financial information.   
   
  • Name
  • Business Address
  • Place of Employment
  • Business E-mail 
  • Business Phone
  • Personal E-mail
  • Mobile phone number
   
Yes   
   
Yes   
   
Yes   
   
Internet or other electronic   network activity information, including, but not limited to, browsing   history, search history, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement.   
   
  • Internet Protocol Address
  • Information about how consumers interact with our website or other online materials
   
Yes   
   
No   
   
No   
   
Professional or  employment-related information.   
   
  • Place of Employment
  • Job History
  • Job Title
  • Professional position
  • Leadership or executive role
  • Name of employer
  • Practice address (if HCP)
  • LinkedIn profile  
   
Yes   
   
Yes   
   
Yes   
   
Inferences drawn from any of   the information identified in this subdivision to create a profile about a   consumer reflecting the consumer’s preferences, characteristics,   psychological trends, predispositions, behavior, attitudes, intelligence,   abilities, and aptitudes   
   
   
   
Yes   
   
Yes   
   
Yes   

 

Categories of sources from which we collect consumers’ Personal Data include:

  • Publicly available information from federal, state, and local government agencies, and web research through use of technology and by our in-house research team
  • Proprietary research by our in-house research team through publicly accessible websites and electronic and phone surveys
  • Licensed data from third parties including data like clinical practice history of healthcare providers (HCPs) based upon HIPAA-certified de-identified patient data
  • Directly from consumers
  • Directly and indirectly from consumers by their activities on our website or their devices
  • Directly and indirectly from our customers
  • Through communications with prospective customers

Categories of third parties with whom Personal Data has been shared in the past 12 months include:

  • Definitive Healthcare customers
  • Service providers
  • Third parties integrated into our services
  • Third parties as required by law
  • Third parties in relation to a merger, sales, or asset transfer
  • Other third parties with consumers’ consent

Business purposes for which the categories of Personal Data above are collected include:

  • To fulfill the purpose for which the information was provided
  • To include in Definitive Healthcare’s platform licensed to customers, which is used for business-to-business sales and marketing efforts.
  • To provide consumers with information about Definitive Healthcare and its products, services, events, or other information, and to enhance their experience on our website and with our product, services, and marketing materials.
  • To research, develop, test, evaluate future product features and enhancements and improve the services
  • To provide product customer service
  • As necessary to comply with applicable federal, state, and local laws.
  • To protect against security threats and protect against illegal, fraudulent, or malicious activity, and any subsequent investigation of that activity.

Personal Data subject to this VCDPA Privacy Policy does not include the information covered by certain federal and state laws, such as the Health Insurance Portability and Accountability Act of 1996 (HIPAA), clinical trials, or other information described in the exceptions for VCDPA.

Under the VCDPA, consumers have the right to request that we disclose what Personal Data we collect, use, disclose, or sell. To exercise your right to know, please contact us:

Mail:
Definitive Healthcare
Attn: Data Privacy Officer
492 Old Connecticut Path
Suite 401
Framingham, MA 01701

Right to opt-out

In the last 12 months, Definitive Healthcare has sold Personal Data related to healthcare providers and other individuals affiliated with healthcare organizations, including name, place of employment, professional title, business e-mail address and phone number, office address, social media links, and work or educational history. Business Personal Data is sold to Definitive Healthcare’s customers, including for commercial strategy, analytics, and business-to-business sales and marketing.

Under the VCDPA, Consumers have the right to opt-out of the sale of any Personal Data that was collected and retained by Definitive Healthcare. We will also inform our customers and service providers of your decision to opt-out. To exercise your right to opt-out, please contact us via:

Right to Delete

Under the VCDPA, Consumers have the right to request the deletion of any Personal Data that was collected and retained by Definitive Healthcare for certain purposes.

To exercise your right to delete, please contact us:

Right to Correct

Under the VCDPA, Consumers have the right to request that we correct any Personal Data that was collected and retained by Definitive Healthcare for certain purposes.

To exercise your right to delete, please contact us:

Right to non-discrimination

Definitive Healthcare will not discriminate in pricing and services against a consumer for exercising their VCDPA rights.

Verifiable requests

Your rights under the VCDPA are not absolute. For example, any such request must provide sufficient information that allows Definitive Healthcare to verify that you are the consumer whose Personal Data we have collected. You may be entitled, in accordance with applicable law, to submit a request through an authorized agent through the same mechanisms that you can use to submit a request directly. The request must also include sufficient detail that allows us to properly understand, evaluate, and respond to the request. If we need more information to process your request, we will contact you via e-mail or in writing.

Children’s information

Definitive Healthcare’s products and services are directed at business professionals. Definitive Healthcare’s products and services are not targeted to children under the age of 16. We do not knowingly collect or maintain any Personal Data for children under the age of 16. If we discover we have collected any information for persons under the age of 16, we will delete their Personal Data.

Questions?

Definitive Healthcare is committed to protecting the privacy of Consumers’ Personal Data and being transparent about our privacy practices. We welcome questions, comments, or feedback on this supplemental policy or our Privacy Policy. To obtain more information, submit feedback or questions, or to exercise your rights, please contact us:

Mail:
Definitive Healthcare
Attn: Data Privacy Officer
492 Old Connecticut Path
Suite 401
Framingham, MA 01701