Last updated April 25, 2022
We at EnduringWishes, Inc. (“EnduringWishes,” “we,” and “us”) believe you should always know what data we collect from you and how we use it. This privacy notice provides information on how we collect and process your personal data when you use our products or services (collectively the “Services”) or visit our website www.enduringwishes.com(the “Site”), contact us or have a relationship with us.
When you use our Services, we collect the following types of information (collectively “Personal Information”).
Some general and basic information is required to create an account with EnduringWishes and while signing up for our Services, such as your name, email address, phone number, password, and in some cases your date of birth and gender, language preferences, etc.
Your private, sensitive, personal information other than the basic information to form an account that you voluntarily submit through the Services, including your stored documents, other passwords, financial and legal information (“Secure Information”). Our systems will indicate whether you have submitted certain information if it is provided under certain functions of our Services but we do not access this information for the puspose of operating our Services other than storing the information until it is released and shared as per your instructions.
If the situation calls for it, you may voluntarily provide us with your health and medical information which may be considered “Protected Health Information” or “PHI,” as defined by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Our systems will indicate whether you have submitted certain information if it is provided under certain functions of our Services but we do not access this information for the puspose of operating our Services other than storing the information until it is released and shared as per your instructions.
To help improve your experience or enable certain features of the Services, you may choose to provide us with additional information such as a profile photo, biography, nationality, location, and profession.
If you choose to connect your account on our Services to your account on another third party services, such as financial advisors, legal advisors or other third party service providers, we may receive information from mentioned third parties as well.
We may also partner with third parties, such as funeral providers, employers, insurance companies, that offer EnduringWishes’ Services to their customers, employees, clients, and consumers. In such cases, those organizations may provide us with your name, email address, or similar information, including personal health information, so that we can provide the Services to these third parties.
For the Services to fully function, it may therefore be necessary for you to authorize one or more third party providers to provide us with the information needed for performing the Services. This will only be done with your express permission, which will be collected upon the creation of your account with the third party service providers that we have an agreement with and who you have given the permission to share the information with us.
Whenever you interact with our Services, we automatically receive and record information on our server logs from your browser or device, which may include your internet protocol (“IP”) address, geolocation data, device identification, “cookie” information, the type of browser and/or device you’re using to access our Services, and the page or feature you requested. “Cookies” are identifiers we transfer to your browser or device that allow us to recognize your browser or device and tell us how and when pages and features in our Services are visited and by how many people. You may be able to change the preferences on your browser or device to prevent or limit your device’s acceptance of cookies, but this may prevent you from taking advantage of some of our features.
We collect information about you when you send, receive, or engage with messages in connection with our Services.
We use the information we collect for the following purposes:
When you register for the Service, or when a third party registers you for the Service on your behalf, we collect your Personal Information as part of the registration process, including but not limited to your name, address, phone number, email address.
We collect information to provide you with our Services and to manage your relationship with us, including to send you technical notices, updates, offers, promotions, rewards, events, news, security alerts, support and administrative messages.
We use the information we collect to improve and personalize the Services and to develop new ones. For example, we use the information to troubleshoot and protect against errors; perform data analysis and testing; conduct research and surveys; and develop new features and Services.
We use the information we collect to promote the safety and security of the Services, our users, and other parties. For example, we may use the information to authenticate users, facilitate secure payments, protect against fraud and abuse, respond to a legal request or claim, conduct audits, and enforce our terms and policies.
We collect information to enforce or defend any legal obligation or rights or to comply with any legal obligation.
We use your data to produce and share aggregated insights that do not identify you for statistical purposes and to improve the Services. For example, we may use your data to generate statistics about our users, their profession or nationality, to publish cognitive demographic insights.
Subject to applicable state and federal law, including but not limited to our obligations under HIPAA and HITECH, we may share aggregated, de-identified or identified versions of your Personal Information with our subsidiaries, affiliates, partners, investors, and contractors for the purposes below.
EnduringWishes personnel may access Personal Information in order to provide Services and customer support to our users. We have developed internal processes to govern the way our personnel accesses user data. Internal access to this data is supervised to ensure user privacy.
We use third parties to process some of your Personal Information. When we allow them access to your data, we do not permit them to use it for their own purposes. We have in place with each processor, a contract that requires them only to process the data on our instructions and to take proper care in using it. They are not permitted to keep the data after our relationship with them has ended, unless required by law.
If you connect or communicate with us using social media, for example, Instagram, Twitter or Facebook, your personal information will be shared with us and the social media platform. We may be able to communicate with you using that platform but we are not otherwise responsible for the ways in which these platforms might use your personal information. Please look at the privacy notices and preference centers available on these platforms to understand how your personal information is used and what options you might have in respect of it.
We may preserve or disclose information about you to comply with a law, regulation, legal process, or governmental request; to assert legal rights or defend against legal claims; or to prevent, detect, or investigate illegal activity, fraud, abuse, violations of our terms, or threats to the security of the Services or the physical safety of any person.
We may share non-personal information that is aggregated or de-identified so that it cannot reasonably be used to identify an individual. We may disclose such information publicly and to third parties, for example, in public reports, to partners under agreement with us, or as part of the community benchmarking information we provide to users of our subscription services.
We may share de-identified versions of your Personal Information and other data in aggregated or non-aggregated forms with partners, investors, contractors or prospective advertisers and research partners for any purposes related to our business practices.
We may share your Personal Information during a corporate transaction like a merger, or sale of our assets, or as part of the due diligence for such contemplated transactions. If a corporate transaction occurs, we will provide notification of any changes to control of your personal information, as well as choices you may have at that time.
As part of your use of the Services, you may designate specific persons who may access your information given certain conditions met. We may share your Personal Information with your designated specific persons and only pursuant to and in accordance with your explicit instruction, including the permissions you set that give any particular Deputy access to designated portions of the Services.
We may share your Personal Information with third party service providers for the case where you signed up for the Services using an invitations received from external advisors and third party service providers such as financial advisors, funeral providers or any other third party provider.
We give you account settings and tools to access and control your Personal Information. If you live in certain jurisdictions, you may have legal rights with respect to your information, which your account settings and tools may allow you to exercise.
By logging into your account, you can access much of your personal information, including your account settings. You can also download information in a commonly used file format, including data about your activities and results.
By logging into your account and using your account settings, you can change and delete your personal information.
If you choose to delete your account, please note that all data, scores, and information will be permanently deleted, except as noted below.
We retain your Personal Information even after you have closed your account if reasonably necessary to comply with our legal obligations (including law enforcement requests), meet regulatory requirements, resolve disputes, maintain security, prevent fraud and abuse, enforce our Terms and Conditions, or fulfill your request to “unsubscribe” from further messages from us. We will retain de-personalized information after your account has been closed.
Information you have shared with others may remain visible after you closed your account or deleted the information from your own profile or mailbox, and we do not control data that other users copied out of our Services.
Note that while most of your information will be deleted within 30 days, it may take up to 90 days to delete all of your information, like data stored in our backup systems.
We maintain information about you for as long as we provide services to you, and as long it is required for us to perform any related business activities. After your information is no longer necessary for our business purposes, we will destroy the information unless we have agreed with you that we should keep the information, or a court or administrative order is made to preserve the information, or if it is otherwise stipulated by law.
The Services are not directed to children under 18 years of age. Unless otherwise disclosed during collection and with parent or guardian consent, EnduringWishes does not knowingly collect Personal Information from children under 18 years of age. Should it come to our knowledge that we have collected Personal Information of a person under 18 years of age without verified consent from a parent or guardian, we will take action to remove the information from our systems.
We have put in place appropriate security measures to prevent your Personal Information from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your Personal Information to those employees, agents, contractors and other service providers who have a business need to know and they are contractually obliged to keep this information confidential.
We also endeavor to take reasonable steps to protect Personal Information from external threats, for example hacking or malicious software. Please be aware that there are always risks in sending Personal Information over public networks and that we cannot guarantee the security of data sent to us using these networks.
We have procedures to deal with any suspected Personal Information breach and will notify you and any applicable regulator when it is appropriate for us to do so.
If you have a security-related concern, please contact customer support at email@example.com.
If you are a California resident, please review the following additional privacy disclosures under the California Consumer Privacy Act of 2018 (“CCPA”).
You have the right to understand how we collect, use, and disclose your PHI, to access your information, to request that we delete certain information, and to not be discriminated against for exercising your privacy rights.
You may exercise these rights using your account settings and tools as described in the Your Rights to Access and Control Your PHI section, for example:
By logging into your account and using your account settings, you may exercise your right to access your PHI and to understand how we collect, use, and disclose it.
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
We collect the categories of Personal Information listed below. We receive this information from you, your device, your use of the Services, third parties and as otherwise described in this policy. We use and disclose these categories of information for the business purposes described above. The categories are:
Identifiers, like your name or username, email address, mailing address, phone number, IP address, account ID, cookie ID, and other similar identifiers.
If you have questions about this policy or need help exercising your privacy rights, please contact us at firstname.lastname@example.org EnduringWishes, Inc., 44 Portland Street, Fourth Floor, Worcester MA 01605, USA