PRIVACY POLICY
Revised: February 19, 2025
This Privacy Policy explains how genus and our authorized care partners collect, use, disclose, and protect information when you visit our website, interact with our Communities of Care, use our applications (including genusConnect, theWall.AI, Mingle, and related tools), or participate in programs such as 211-411 Care Code/SMS journeys. Continued use of the Services indicates your acceptance of this Policy.
- We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided information, we will take steps to delete it.
- Accessibility and language support are available by emailing support@genusconnect.org.
- Our Services may link to third-party sites or apps; their privacy practices are governed by their own policies.
- We will communicate material changes to this Policy through our website, app notices, or email when appropriate.
- Contact: genus Inc., Attn: Privacy & Data Protection, 440 Burroughs St, Suite 169, Detroit, MI 48202, USA | support@genusconnect.org.
- "Personal Information": Data that can identify you.
- "Authorized Care Partners": Organizations or individuals you allow to coordinate care.
- "CCPA/CPRA": California privacy laws granting rights such as access, deletion, correction, and the right to limit certain uses of personal information.
- "GDPR/UK GDPR": Data-protection laws in the European Economic Area and the United Kingdom granting rights such as access, rectification, erasure, restriction, portability, and objection.
- genusConnect acts as a Business Associate under HIPAA for the covered entities and partners it serves, signs Business Associate Agreements with them, and provides a separate privacy notice where a program requires one.
- The Services do not constitute medical advice; always consult licensed clinicians.
- Contact and profile information you provide (such as name, email address, phone number, organization, role, and preferences) so we can create and manage your account, respond to inquiries, and personalize experiences.
- Program and Community information, including details you or your care team choose to share about a Person of Care, care plans, goals, and support activities (subject to separate HIPAA notices where applicable).
- User Content such as messages, notes, survey responses, uploaded documents, photos, or videos shared within Communities of Care or through our tools.
- Website and app usage data, including IP address, browser type, device identifiers, pages viewed, referring pages, timestamps, and interactions with features, collected via logs, cookies, pixels, and similar technologies.
- Analytics data from service providers (for example, to understand which pages are visited most often, measure campaign performance, or improve usability); you may be able to control some of this collection via browser or device settings.
- SMS program data, including the mobile number you use for 211-411 or other Care Codes, the keywords you text (e.g., DISCHARGE, STOP, HELP), message delivery metadata, and program enrollment status.
- Approximate location information when derived from IP or when you enable location services in an app, used to tailor content or connect you to nearby resources.
- genusAI analyzes de-identified data to deliver relevant recommendations and stores cached, human-reviewed answers.
- Where feasible, we remove direct identifiers (such as names and contact details) before using data with language models or other AI components.
- We keep personal information only as long as needed to provide services, meet legal and regulatory obligations (including HIPAA retention rules), resolve disputes, and maintain security and reliability.
- You can request deletion or de-identification of certain personal information via support@genusconnect.org; we will honor these requests where required by law and inform you when retention is still necessary.
- Backups and logs may retain information for a limited period even after deletion to support security, disaster recovery, and legal compliance.
- Service providers operate under confidentiality agreements and, where applicable, Business Associate Agreements.
- Authorized Care Partners receive relevant data with your consent.
- We may disclose information to comply with laws, defend rights, or complete corporate transactions.
- Aggregate or de-identified data (which does not reasonably identify you) may be shared for analytics, quality improvement, and research.
- We do not sell your personal information. Where required by laws such as CCPA/CPRA, you have the right to know whether your information is "sold" or "shared" and to opt out of such practices.
- We share SMS and telephony information with SMS providers and carriers solely to deliver messages and comply with applicable telecom and anti-abuse requirements.
- Encryption is used for data in transit and, where appropriate, at rest.
- Access controls limit data exposure to authorized personnel.
- Incident response plans guide breach notification and mitigation.
- Employees receive privacy and HIPAA training; contingency plans protect availability.
- Under GDPR and UK GDPR you may have rights to access, correct, erase, restrict, or object to processing of your personal data, and to receive a copy of certain information in a portable format. You also have the right to lodge a complaint with your local supervisory authority.
- Under CCPA/CPRA, California residents may have rights to know, delete, correct, and limit certain uses of their personal information, and to be free from discrimination for exercising those rights.
- When we transfer personal data from the European Economic Area, the United Kingdom, or other regions with data-protection laws, we use appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) where required.

