Legal
Consumer Health Data Privacy Policy
This is a separate policy required by state consumer health data laws. It describes how LumenUs handles consumer health data. It must be linked distinctly on our homepage and kept separate from our general Privacy Policy.
On this page
- 1. Who this applies to
- 2. Categories of consumer health data we collect
- 3. Categories of sources of consumer health data
- 4. How we use consumer health data (purposes)
- 5. Categories of consumer health data we share, and with whom
- 6. How we obtain consent and authorization
- 7. Your rights, and what happens when you ask us to delete
- 8. No geofencing
- 9. Contact
1. Who this applies to
This policy applies to consumers who are residents of Washington, Nevada, and Connecticut, and to consumer health data we collect about them. Because LumenUs supports people through grief, much of the information we collect can relate to mental or physical health and is treated as consumer health data.
"Consumer health data" means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. For LumenUs, consumer health data includes, but is not limited to, the following categories:
- Mental or physical health status, conditions, or symptoms you share or that can be inferred from what you share.
- The cause of a death, where you provide it, including a death by suicide, overdose, or pregnancy or infant loss, which may reveal health information about you or about the person who died.
- Your emotional or mental state, including self-reported state and reflections.
- Your responses to any grief-reflection prompt, including a reflection based on the PG-13-R instrument, and any reflection we derive from them.
- Inferences we draw from any of the above to personalize your grief support.
2. Categories of consumer health data we collect
- Information about a loss and its nature, including cause of death where you provide it (which may indicate health conditions, suicide, overdose, or pregnancy or infant loss).
- Information you provide about your emotional or mental state, including self-reported state and reflections.
- Your responses to any grief reflection based on the PG-13-R instrument, and any reflection we derive from them. This reflection is a self-reflection aid. It is not a diagnostic tool and does not diagnose any condition.
- Health-related context you provide during onboarding or in your use of grief-support practices.
- Information generated by the automated safety feature, such as indicators it evaluates and crisis-resource events.
- Inferences we draw from the above to personalize your grief support.
3. Categories of sources of consumer health data
- Directly from you, when you provide it through the Service.
- Generated automatically as you use the Service.
- From a partner or referrer, where you have asked to use our Service through them.
- Where lawful and applicable, and only for an approved partner program, from publicly available sources such as published obituaries. We do not conduct automated outreach to non-users.
4. How we use consumer health data (purposes)
- To provide and personalize grief support to you.
- To operate the automated safety feature that surfaces crisis resources.
- To improve the Service using de-identified data.
- To comply with law and protect safety.
We do not use consumer health data for advertising, and we do not sell it.
5. Categories of consumer health data we share, and with whom
We share consumer health data only with the categories of recipients below, and only as described:
- Service providers (processors) who operate the Service for us under contract and may use the data only to provide their service to us. The categories of service providers are: hosting and storage; artificial-intelligence processing of your support conversations; transactional email delivery; audio generation for certain practices; product analytics on a de-identified basis; and payment processing. The current, named list is published at lumenus.life/subprocessors.
- People and providers you direct, such as a Supporter you invite or a professional you choose to connect with, limited to what you authorize.
- Legal and safety recipients, where required by law or necessary to protect any person's safety.
- A successor entity, in connection with a merger, acquisition, or sale of assets.
Affiliates. LumenUs does not currently have corporate affiliates, and we do not share consumer health data with affiliates. If we acquire affiliates in the future, we will update this policy and will not share consumer health data with an affiliate for the affiliate's own purposes without your consent.
We do not sell consumer health data, and we do not share it for targeted advertising.
6. How we obtain consent and authorization
State consumer health data law treats collecting beyond necessity, sharing beyond necessity, and selling as three different things that need three different permissions. Here is how we handle each.
We treat consent to collect, consent to share, and authorization to sell as three distinct mechanisms:
(a) Consent to collect beyond what is necessary. We collect and process consumer health data that is necessary to provide a service you have requested without separate consent, as the law allows. Before we collect any consumer health data that is beyond what is necessary to provide a service you have requested, we obtain your separate, affirmative, opt-in consent, presented clearly and separately from other terms, describing the categories of data and the purposes.
(b) Consent to share beyond what is necessary. We share consumer health data with the service providers who operate the Service for us, and with the recipients you direct, as needed to provide the service you have requested. Before we share consumer health data in any manner that is beyond what is necessary to provide a service you have requested, we obtain your separate, affirmative, opt-in consent, distinct from the consent to collect.
(c) Authorization to sell. We do not sell consumer health data, and we currently seek no authorization to sell, so this mechanism is not applicable at this time. We will not sell consumer health data unless we first obtain your valid, written authorization that separately meets each element the law requires, which are:
- the specific consumer health data concerning the sale;
- the name and contact information of the buyer (the person purchasing the data);
- a description of the purpose of the sale, including how the data will be gathered and used by the buyer;
- a statement that the provision of goods or services may not be conditioned on the consumer signing the authorization;
- a statement that the consumer has a right to revoke the authorization at any time and a description of how to do so;
- a statement that the data sold may be subject to redisclosure by the buyer and may no longer be protected by this policy or the applicable law;
- an expiration date for the authorization that is no later than one year from the date the consumer signs it; and
- the signature of the consumer and the date.
The authorization will be separate and distinct from any consent obtained under (a) or (b), and both LumenUs and the buyer will retain a copy.
Withdrawal. You may withdraw any consent or revoke any authorization at any time. When you do, we will stop the corresponding collection, processing, sharing, or (if it ever occurs) sale. Withdrawal does not affect processing that already took place while consent was in effect.
7. Your rights, and what happens when you ask us to delete
If you are a resident of a state covered by this policy, you have the right to:
- Confirm whether we are collecting, sharing, or selling your consumer health data, and access that data.
- Withdraw consent to our collection and sharing of your consumer health data.
- Have your consumer health data deleted.
- Appeal a denial of a rights request.
Downstream deletion. When you ask us to delete your consumer health data, we will delete it from our records, and we will notify every service provider, processor, and third party with which we have shared that data and instruct each of them to delete it as well.
Non-discrimination. We will not discriminate or retaliate against you for exercising any right under this policy. We will not deny you goods or services, charge you a different price, or provide you a different level or quality of service because you exercised a right, and we do not condition the provision of the Service on your agreement to collection, sharing, or sale that is beyond what is necessary to provide the Service.
To exercise these rights, contact us at hello@lumenus.life. We will verify your request and respond within the time the law requires. If we deny a request, you may appeal by replying to our response. We will respond to an appeal within forty-five days, extendable once by an additional sixty days where reasonably necessary, with notice to you. If you have concerns about the outcome, you may contact your state Attorney General to submit a complaint.
Retention and security. We retain and secure consumer health data as described in Section 11 of our general Privacy Policy, which is the single source of truth for retention and security across all of our policies.
8. No geofencing
We do not use geofencing to identify, track, collect data from, or send notifications to consumers based on proximity to any health care facility.
9. Contact
LumenUs Platform, Inc., a Delaware corporation with its principal operations in California. Consumer health data inquiries and rights requests: hello@lumenus.life Data protection inquiries: hello@lumenus.life General: hello@lumenus.life