Meadow Biosciences – Detailed Privacy Policy

Last Updated: 00/00/0000

1. Introduction

This Privacy Policy explains how Meadow Biosciences collects, uses, shares, and safeguards your personal information and Protected Health Information (“PHI”). Meadow complies with HIPAA, CCPA/CPRA, and applicable federal/state privacy regulations.

2. Information We Collect

We collect identifiers (name, DOB, contact info), medical history, biomarker data, clinician notes, diagnostic orders/results, payment information, device identifiers, IP address, cookies, and caregiver‑provided information for minors.

3. How We Collect Information

Information is collected directly from users, during telehealth visits, via diagnostic labs, from pharmacy partners, through device/browser technologies, and from optional research participation.

4. How We Use Information

Information is used to deliver care, coordinate with clinicians and labs, fulfill prescriptions, provide customer support, ensure regulatory compliance, and improve clinical systems and analytics. PHI is never sold.

5. How We Share Information

Information may be shared with clinicians, diagnostic labs, compounding pharmacies, service providers, analytics vendors, legal authorities when required, and corporate successors under confidentiality protections.

6. HIPAA Notice of Privacy Practices

Your HIPAA rights include: accessing your PHI, requesting corrections, restricting certain uses, receiving disclosures accounting, requesting confidential communication channels, and filing complaints without retaliation.

7. Your Privacy Rights (Including CCPA/CPRA)

Users may request access, deletion, correction, portability, opt‑out of data uses, or exercise nondiscrimination rights where applicable under state law.

8. Cookies & Tracking

Cookies enable authentication, session management, analytics, and user experience optimization. Users may disable cookies via browser settings, though some features may not function properly.

9. Data Retention

Medical data is retained according to state medical record retention laws and CLIA requirements. Research data may be retained in de‑identified form indefinitely.

10. Data Security

Meadow employs encryption, role‑based access, audit trails, secure hosting, and breach‑response protocols. In the event of a PHI breach, Meadow will notify affected individuals as required by HIPAA.

11. Children's Privacy

Parents or guardians must authorize care for minors. Meadow complies with COPPA and additional pediatric privacy protections.

12. International Users

Data may be transferred to and stored in the United States. GDPR‑style protections apply to international users where required.

13. Third-Party Integrations

External sites linked within the platform are not controlled by Meadow. Meadow is not responsible for external privacy practices.

14. Changes to This Privacy Policy

Policy revisions will be posted with a new “Last Updated” date. Continued use constitutes acceptance.

15. Contact Information

Meadow Biosciences Privacy Office | Email: privacy@meadowbiosciences.com | Address: 100 Alfred Drowne Rd. Barrington, RI 02806