Legal

Privacy Policy

Effective: September 8, 2026  ·  Last updated: September 8, 2026

This policy explains what personal information Vereen Injury Medical Group collects, why we collect it, who we share it with, how long we keep it, and the choices and legal rights you have over it. It covers our public website and our portal for member law firms.

1. Who we are and what this policy covers

Vereen Injury Medical Group is a trade name of GVR Equity, LLC, a Florida limited liability company (Florida document number L23000226481) whose principal office is at 705 SE 5th Ct, Fort Lauderdale, FL 33301. We operate a credentialed network of injury-care providers in Florida and a software portal through which member personal injury law firms search for providers, manage client records and submit appointment requests. In this policy, “Vereen”, “we”, “us” and “our” mean that entity.

This policy applies to:

  • our public website at www.vereeninjury.com, including the demo and access request forms;
  • the Vereen portal at portal.vereeninjury.com, used by approved member law firms and by Vereen staff;
  • email we send in connection with those services; and
  • other interactions with us in which we collect personal information, such as sales conversations and support requests.

We refer to all of the above together as the “Services”.

This policy does not apply to the independent medical providers in our network, who maintain their own privacy practices and their own Notices of Privacy Practices; to the member law firms, who are independently responsible for their own clients' information; or to third-party websites we link to.

2. Protected health information and HIPAA

The most important thing to understand about this policy

When Vereen receives, stores or transmits health information on behalf of a network provider that is a HIPAA covered entity, Vereen acts as that provider's business associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”).

Protected Health Information (“PHI”) is not governed by this policy. Our handling of PHI is governed by HIPAA and by the Business Associate Agreement (“BAA”) between Vereen and the relevant covered entity. Where this policy and an applicable BAA conflict with respect to PHI, the BAA controls.

In practice this means:

  • We use and disclose PHI only as permitted by the applicable BAA and by HIPAA — principally to carry out the treatment, payment and health care operations purposes for which the covered entity engaged us.
  • We do not use or disclose PHI for marketing, advertising or analytics purposes, and we do not sell PHI.
  • We require our subcontractors that handle PHI on our behalf to enter into written agreements imposing the same restrictions that apply to us.
  • We maintain administrative, physical and technical safeguards for electronic PHI as required by the HIPAA Security Rule, and we will report breaches of unsecured PHI as required by the HIPAA Breach Notification Rule.

For rights over PHI held by a provider — access, amendment, an accounting of disclosures, restrictions, or confidential communications — contact that provider directly and consult its Notice of Privacy Practices. We will support the provider in responding to such requests as required by our BAA.

Where information in our Services is not PHI — for example, information about the law firm users of the portal, and information submitted through our public website — this policy governs it.

3. Patient information submitted by law firms

The portal exists so that a member law firm can arrange medical care for its own client. To do that, an authorized user at the firm enters information about that client (whom we call a patient) into the portal, and we transmit the relevant parts of it to the provider chosen for the appointment.

The law firm, not Vereen, decides what patient information to submit and whether it has the authority to submit it. Under our Terms of Service, each member firm represents that it has obtained all consents and authorizations necessary — from its client and under applicable law and rules of professional conduct — before entering that client's information into the portal. Vereen processes that information on the firm's and the treating provider's behalf.

If you are a client of a member law firm and you have questions about why your information is in the Vereen portal, or you want it corrected or removed, please contact your law firm first. They are best placed to answer, and in most cases they instruct us. You may also contact us using the details in section 20 and we will route your request appropriately.

4. Personal information we collect

The table below lists the categories of personal information we collect, using the category names from the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”). We have collected these categories in the twelve months preceding the last-updated date of this policy.

Categories of personal information collected, and the business purposes for which they are used.
CategoryExamples of what we actually collectWhy
Identifiers Name; email address; telephone number; postal address; firm name and website; account identifier issued by our identity provider; IP address; device and browser identifiers set by cookies. Create and secure accounts; respond to demo and access requests; send service email; site security and analytics.
Customer records Contact and address details recorded for a firm, its primary attorney and its case manager; contact and address details recorded for a patient, including date of birth. Operate the portal; route appointment requests; identify a patient to the treating provider.
Protected classifications Date of birth (age); health and medical information relating to an injury. Collected only in the patient records described in section 3. Enable a provider to schedule and deliver appropriate care.
Commercial information Appointment requests, preferred dates, request status history, and records of services considered or arranged. Provide, track and support the core function of the Services.
Internet or network activity Pages viewed, referring URL, links clicked, approximate session information, and interactions with our public website collected through cookies and analytics tools. Understand and improve the website; measure marketing.
Geolocation data Approximate location inferred from IP address. Precise geographic coordinates derived from a street address that a firm enters for a patient, and from provider practice addresses, so the portal can sort providers by distance. Distance-ranked provider search; coarse website analytics.
Professional or employment information Job role at the firm (attorney, case manager, administrator); firm affiliation; the permission level assigned to an account. Access control; support; account administration.
Sensitive personal information Health information; precise geolocation derived from a patient address; account log-in credentials handled by our identity provider. See section 7. Only for the purposes described in section 7.
Audio, electronic or visual information Free-text notes and injury descriptions entered by firm users, and documents a firm may attach to a patient record. Give the provider the clinical and case context needed for the appointment.
Inferences Limited inferences drawn by our website analytics and advertising tools about visitor interests, for marketing measurement only. We draw no inferences from patient records. Marketing measurement and audience reporting.

What we do not collect

  • We do not collect government identification numbers, Social Security numbers, financial account numbers or payment card data through the Services. The portal is provided free of charge to member law firms and takes no payment.
  • We do not collect biometric information.
  • We do not ask for, and do not want, information about a person's racial or ethnic origin, religious or philosophical beliefs, union membership, sex life or sexual orientation, or citizenship or immigration status. Please do not enter such information into free-text fields.
  • Our public website form includes a hidden anti-spam field; a submission that fills it is discarded. That check involves no personal information.

5. Where we get it

Directly from you
When you fill in a demo or access request form, email or call us, create a portal account, or use the portal.
From your law firm
If you are a client of a member firm, your information reaches us because your firm entered it, as described in section 3.
From our network providers
Appointment confirmations, scheduled dates and status updates, including through our customer relationship management system.
Automatically, from your device
Through cookies and similar technologies on our public website, and through security and server logs across the Services. See section 8.
From service providers
Our identity provider supplies the account identifier and verified email for a portal user. Our geocoding provider returns coordinates for an address we submit. Our analytics and advertising providers return measurement data about website visitors.

6. How and why we use it

We use personal information to:

  • Provide the Services — create and authenticate accounts, run provider search, transmit appointment requests to providers, record and display request status, and maintain patient and firm records.
  • Communicate — send transactional email about account approval, submitted requests, booked, completed, cancelled and missed appointments, and firm activation; respond to enquiries; and provide support.
  • Review and approve accounts — verify that a firm requesting access is a bona fide personal injury law firm, and approve, decline, suspend or reinstate accounts.
  • Keep the Services secure — authenticate users, enforce firm-level access boundaries, detect and block automated abuse, maintain an append-only log of administrative actions, and investigate suspected misuse.
  • Improve the Services — diagnose errors, understand which features are used, and plan development. Where we analyse usage at scale we use aggregated or de-identified data.
  • Market our services to law firms — measure website performance, understand which campaigns bring firms to us, and reach similar audiences. This use never involves patient records or portal data. See section 8.
  • Comply with law and protect rights — meet legal, regulatory and professional obligations, respond to lawful requests, enforce our Terms of Service, and establish, exercise or defend legal claims.

We do not use personal information to make decisions producing legal or similarly significant effects about you through solely automated means, and we do not profile individuals for such purposes.

7. Sensitive personal information

Some of what we handle is sensitive personal information under the CCPA and comparable US state laws, and special category data under UK and EU data protection law. Specifically: health and injury information, precise geolocation derived from a patient's address, and account log-in credentials.

We use and disclose sensitive personal information only for the purposes permitted by CCPA regulations without a right to limit — performing the Services requested, ensuring security and integrity, short-term transient use, and services performed on our behalf such as storage and transmission. We do not use or disclose it to infer characteristics about a person, and we do not use it for advertising.

Because we confine our use to those permitted purposes, the CCPA right to limit the use of sensitive personal information does not apply. You may still exercise every other right described in section 14.

8. Cookies, analytics and advertising

Analytics and advertising technologies run on our public website only

Google Analytics, Google Tag Manager, the Meta Pixel and any comparable technology we add in future are loaded on www.vereeninjury.com and nowhere else. They are not present on the Vereen portal, are not loaded on any authenticated page, and never receive patient records, appointment information, or protected health information.

What we use

Strictly necessary cookies and storage
Required to make the Services work: session and authentication tokens set by our identity provider, security tokens set by our bot-protection provider, and a record of your cookie preferences. These cannot be switched off through our banner because the Services will not function without them.
Analytics — Google Analytics 4, deployed through Google Tag Manager
Measures how visitors find and move through our public website. We enable IP anonymisation where available and do not send Google any information that identifies a person by name.
Advertising — Meta Pixel
Measures whether an advertisement led to a demo request, and allows us to reach comparable audiences of legal professionals. This involves disclosing online identifiers and browsing activity to Meta for cross-context behavioural advertising, which the CCPA treats as “sharing”. See section 10.

Your control over them

  • Consent banner. When you first visit our public website we present a cookie banner. Analytics and advertising technologies are not loaded until you accept them, and you can change or withdraw your choice at any time from the Your Privacy Choices link in the website footer. Withdrawing is one click and takes effect immediately: we clear the relevant cookies and reload the page. We ask again after 12 months, and whenever the tools in these categories change.
  • Global Privacy Control. We treat an opt-out preference signal, including Global Privacy Control, as a valid request to opt out of the sale and sharing of personal information from the browser that sends it.
  • Do Not Track. There is no common industry standard for responding to browser Do Not Track signals, and we do not respond to them. We do honour Global Privacy Control, as above.
  • Provider-level opt-outs. You can install the Google Analytics opt-out browser add-on, and adjust ad preferences in your Meta account settings. Industry opt-out tools are available from the Network Advertising Initiative and the Digital Advertising Alliance.
  • Browser controls. Most browsers let you block or delete cookies. Blocking strictly necessary cookies will prevent you from signing in to the portal.

9. When we disclose personal information

We do not disclose personal information except as described here.

To network providers

When a firm submits an appointment request, we disclose to the chosen provider the patient information that provider needs to schedule and deliver care — name, contact details, date of birth, address, and the injury information the firm supplied.

To the member law firm

Portal records are scoped to the firm that created them. Users at one member firm cannot see another firm's patients, requests or documents.

To service providers who work on our behalf

Each is contractually restricted to using the information only to provide services to us, and those that handle protected health information do so under a Business Associate Agreement. As at the last-updated date these are:

Service providers that process personal information for Vereen.
ProviderFunctionInformation involved
ClerkAccount identity and authenticationName, email, account identifier, credentials
RailwayApplication hosting and database (United States)All portal data at rest and in transit
AirtableCustomer relationship and case management used by Vereen staffFirm records, patient records, appointment records
AlgoliaProvider directory search indexProvider directory information only — no patient data
ResendTransactional email deliveryRecipient name and email address, message content
GeoapifyAddress geocoding for distance searchStreet addresses, converted to coordinates
CloudflareBot protection and network servicesIP address, device signals
GoogleWebsite analytics and tag management (public website only)Online identifiers, browsing activity
Meta PlatformsAdvertising measurement (public website only)Online identifiers, browsing activity
SentryApplication error monitoringTechnical diagnostic data; configured to scrub personal information

We may add or change service providers. We will update this list when we do, and we will not permit a new provider to handle protected health information without a Business Associate Agreement in place.

For legal and safety reasons

We may disclose personal information where we believe in good faith it is necessary to comply with law, a subpoena or other lawful request; to enforce our agreements; to investigate suspected fraud or a security incident; or to protect the rights, property or safety of any person. Where a request concerns protected health information, we will respond as HIPAA and our Business Associate Agreements require, and we will notify the covered entity or member firm unless prohibited from doing so.

In a business transfer

If Vereen is involved in a merger, acquisition, financing, reorganisation or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honour this policy, and any protected health information will transfer only as HIPAA permits.

10. Sale and sharing of personal information

We do not sell personal information for money, and we have not done so. We do not and will not sell, share or use for advertising any patient information, protected health information, or any information held in the portal.

However, the CCPA and several other US state privacy laws define “sale” and “sharing” broadly enough to cover the disclosure of online identifiers to advertising technology providers. On that reading, our use of the Meta Pixel on our public website constitutes sharing for cross-context behavioural advertising, and may constitute a “sale”. We disclose it on that basis.

Categories disclosed for cross-context behavioural advertising in the preceding twelve months.
Category sharedRecipient categoryWhere it happens
Identifiers (cookie and device identifiers, IP address)Advertising networks and analytics providerswww.vereeninjury.com only
Internet or network activityAdvertising networks and analytics providerswww.vereeninjury.com only
Inferences drawn from the aboveAdvertising networkswww.vereeninjury.com only

We have not sold or shared sensitive personal information, protected classification information, customer records, geolocation derived from patient addresses, or commercial information from the portal — and we have no plans to.

We do not knowingly sell or share the personal information of consumers under 16 years of age.

How to opt out

Decline analytics and advertising cookies in our cookie banner, or open Your Privacy Choices in the website footer and withdraw a previous acceptance. Enabling Global Privacy Control in your browser also opts that browser out. You can additionally email us at hello@vereeninjury.com with the subject line “Do Not Sell or Share My Personal Information”. We do not require an account or verification to honour an opt-out, and we will never treat you differently for exercising it.

11. How long we keep information

We keep personal information only for as long as we need it for the purpose we collected it, and then delete it or de-identify it. Because records arranged through the portal may be evidence in active litigation, retention is deliberately conservative.

Retention periods by record type.
RecordKept for
Firm and user account recordsThe life of the account, then [24 months] after closure, unless a longer period is required by law or a live legal claim.
Patient records and appointment requestsAs directed by the member law firm and the treating provider. Where we hold them as a business associate, retention follows the Business Associate Agreement and applicable medical-record retention law — in Florida, generally at least [5 years] from the last patient contact.
Documents attached to a patient recordThe same period as the patient record they belong to.
Demo and access request submissions[24 months] from the last contact, unless the firm becomes a customer.
Transactional email records[12 months].
Administrative audit log[6 years]. This log is append-only by design and records which staff member took which action; it is what makes an access review possible, so entries are not edited or removed.
Your cookie choice12 months, stored in your own browser rather than on our servers, then we ask again.
Security and server logs[90 days], longer where an investigation requires it.
Website analytics and advertising dataAs set by the relevant provider's retention controls, currently [14 months] for Google Analytics.
BackupsEncrypted backups are taken daily and cycle out on a rolling [30-day] schedule. Deleted records may persist in a backup until it expires.

When you delete your own portal account, we delete your identity record with our identity provider and your account record in our database. Records that other parties are entitled to retain — the audit log, and patient records belonging to your firm and its providers — are not deleted with your account.

12. How we protect information

  • Encryption. All traffic to the Services is encrypted with TLS. Data is encrypted at rest by our hosting and database providers.
  • Authentication. Sign-in is handled by a dedicated identity provider. We never store or see your password. Multi-factor authentication is available and we recommend it.
  • Access boundaries. Every portal record is scoped to the firm that owns it, and the check fails closed — a record with no firm is visible to no firm. Staff access is role-based and limited to those who need it.
  • Approval gate. A newly registered firm has no access until Vereen staff approve it.
  • Directory protection. Provider identity and address are withheld from search results until an appointment is booked, so the network directory cannot be extracted through the search interface.
  • Audit logging. Administrative actions are written to an append-only log recording who acted, on what, and when.
  • Bot protection and content security. Automated abuse is filtered before it reaches the application, and the portal enforces a strict Content Security Policy.
  • Backups. The production database is backed up daily.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by HIPAA, the Florida Information Protection Act, and any other applicable law.

If you believe you have found a security vulnerability in the Services, please report it to hello@vereeninjury.com. We will not pursue legal action against researchers who report in good faith and do not access, alter or exfiltrate other people's data.

13. Your choices

  • Account information. Signed-in portal users can view and update their own profile, and can delete their account from within the portal.
  • Marketing email. Every marketing email carries an unsubscribe link. Transactional email about your account and your appointment requests is part of the Services and cannot be unsubscribed from while your account is open.
  • Cookies and tracking. See section 8.
  • Legal rights. See sections 14 to 16.

14. US state privacy rights

Depending on where you live, you may have some or all of the rights below. We honour these rights for residents of every US state that grants them, and as a matter of practice we will consider a request from any US resident.

Rights

Right to know or access
Confirm whether we process your personal information, and obtain the categories collected, the sources, the purposes, the categories of recipients, and the specific pieces of personal information we hold.
Right to delete
Request deletion of personal information we collected from you, subject to the exceptions in the applicable statute.
Right to correct
Request correction of inaccurate personal information.
Right to portability
Receive a copy in a portable and, where technically feasible, readily usable format.
Right to opt out of sale, sharing and targeted advertising
Direct us to stop selling or sharing your personal information for cross-context behavioural or targeted advertising. See section 10.
Right to limit the use of sensitive personal information
Because we use sensitive personal information only for purposes permitted without a limitation right, this right does not apply to us. See section 7.
Right to opt out of profiling
We do not profile individuals in furtherance of decisions producing legal or similarly significant effects.
Right to non-discrimination
We will not deny you services, charge you a different price, or provide a different level of quality because you exercised a privacy right. We offer no financial incentives for personal information.
Right to appeal
If we decline your request, you may appeal by replying to our decision or writing to hello@vereeninjury.com with “Privacy Appeal” in the subject line. We will respond within 45 days with our decision and reasons. If we deny the appeal, we will tell you how to complain to your state Attorney General.

How to exercise them

Email hello@vereeninjury.com or call (844) VEREEN-1, and tell us which right you are exercising and which state you reside in.

We will verify your identity before acting on a request to know, delete or correct — typically by matching the information in your request against what we already hold, and by sending a confirmation to the email address on file. For a request seeking specific pieces of personal information we apply a higher degree of certainty. We do not require verification to honour an opt-out.

We will acknowledge a request within 10 business days and respond substantively within 45 calendar days. If we need more time we will tell you within that period, and take no more than a further 45 days.

Authorized agents. You may use an authorized agent. We will ask the agent for written permission signed by you, and we may ask you to verify your identity with us directly. An agent acting under a valid power of attorney need not provide separate written permission.

An important limit. These rights apply to information we hold as a business or controller. They do not reach protected health information we hold as a business associate, or patient records we process on a member firm's instructions — for those, see sections 2 and 3, and contact the provider or the law firm. This is a limitation the statutes themselves impose; HIPAA-regulated information is expressly exempt from the CCPA and from every comparable state law.

State-specific notes

California

This entire policy is our CCPA notice at collection and our privacy policy for California residents. Section 4 lists the categories collected, section 6 the purposes, section 9 the recipients, section 10 our sale and sharing disclosure, section 11 our retention periods, and section 7 our treatment of sensitive personal information. California residents may also request, once a year and free of charge, information about disclosures to third parties for their direct marketing purposes under California's “Shine the Light” law; we make no such disclosures.

Colorado, Connecticut, Delaware, Iowa, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia

Residents of these states have the rights listed above, subject to each statute's own scope and exceptions, together with the right to appeal a refusal. Where a state requires consent before processing sensitive data, we obtain it or rely on an applicable exemption. Minnesota and Oregon residents may additionally request a list of the specific third parties to which we have disclosed personal data; email us and we will provide it.

Florida

The Florida Digital Bill of Rights applies to businesses above a very high revenue threshold that Vereen does not meet, so it does not currently apply to us. We nevertheless extend the rights above to Florida residents.

Nevada

Nevada residents may direct us not to sell certain covered information. We do not sell covered information as Nevada defines it, but you may submit a verified request to hello@vereeninjury.com.

15. Consumer health data (Washington, Nevada and Connecticut)

Washington's My Health My Data Act, Nevada Senate Bill 370 and Connecticut's amended privacy act regulate consumer health data and require a dedicated notice. This section is that notice, and it applies to residents of those states.

Most health information we handle is exempt. Protected health information governed by HIPAA, and information handled by a business associate under a Business Associate Agreement, is expressly excluded from all three statutes. Sections 2 and 3 explain why nearly all health information in the Services falls into that category. The disclosures below cover any consumer health data that does not.

  • What we collect: injury type, injury date, free-text injury descriptions, appointment and treatment scheduling information, and precise location derived from a home address — all as described in section 4.
  • Where it comes from: the member law firm that represents the individual, and the treating provider. We do not collect consumer health data from website visitors, and our analytics and advertising tools never receive it.
  • Why we collect it: solely to arrange and coordinate medical care at the direction of the law firm and the provider, as described in section 6.
  • Who we share it with: the treating provider, and the service providers listed in section 9 that are contractually restricted to processing it on our behalf. Our staff, our hosting and database provider, and our case management system are the categories of personnel and affiliates with access.
  • We do not sell consumer health data. We will not sell it, and we do not use it for advertising. Selling consumer health data requires your written authorization; we will not seek one.
  • Geofencing. We do not operate a geofence around any health care facility.

Your rights. You may confirm whether we collect, share or sell your consumer health data; obtain a list of the third parties and affiliates with which we have shared it; withdraw consent to its collection and sharing; and request its deletion, including from our archives and backups, which we will action within 30 days. Email hello@vereeninjury.com with “Consumer Health Data Request” in the subject line. If we deny a request you may appeal as described in section 14, and Washington residents may complain to the Washington State Attorney General.

16. EEA, UK and Switzerland

The Services are designed for personal injury law firms practising in Florida and are not targeted at individuals in the European Economic Area, the United Kingdom or Switzerland. Where the UK GDPR, the EU General Data Protection Regulation or Swiss data protection law nonetheless applies to our processing of your personal data, this section applies and Vereen is the controller of that data.

Lawful bases

Performance of a contract
Providing the Services to a member firm and to its authorized users, and administering accounts.
Legitimate interests
Securing the Services, preventing fraud and abuse, improving and developing the Services, and marketing to law firms — balanced in each case against your interests and rights.
Consent
Analytics and advertising cookies, and any marketing email where consent is required. You may withdraw consent at any time, without affecting processing already carried out.
Legal obligation
Meeting our record-keeping, regulatory and lawful-request obligations.
Establishment, exercise or defence of legal claims
Our Article 9 condition for processing health data, alongside your explicit consent or that of the law firm acting on your instructions, where applicable. Records arranged through the Services exist to support personal injury claims.

Your rights

You have the right to access your personal data; to have inaccurate data rectified; to erasure; to restrict processing; to data portability; to object to processing carried out on the basis of legitimate interests, including profiling, and to object at any time to direct marketing; to withdraw consent; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — which we do not carry out.

To exercise any of these, email hello@vereeninjury.com. We will respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.

You have the right to complain to your local supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.

International transfers

Vereen operates in the United States and all of our infrastructure and service providers process data there. If you are in the EEA, the UK or Switzerland, your personal data will be transferred to and stored in the United States, which has not received an adequacy decision of general application. Where we make such a transfer we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary technical measures including encryption in transit and at rest. You may request a copy of the relevant safeguards by emailing us.

Our representative

[If Vereen is genuinely in scope of the EU or UK GDPR, an Article 27 representative must be appointed and named here. If the Services are not offered to individuals in the EEA or UK — the current position — delete this subsection rather than naming a representative we have not appointed.]

17. Children's privacy

The Services are business tools for law firms. They are not directed at children, and we do not knowingly collect personal information directly from anyone under 18 through our website or portal accounts.

A patient record created by a member law firm may relate to a minor, because minors are injured in accidents and are represented by counsel. Such a record is created by the firm on the authority of the minor's parent, guardian or legal representative, and is handled as described in sections 2 and 3. If you believe a child's information has reached us without proper authority, contact us at hello@vereeninjury.com and we will investigate and, where appropriate, delete it.

We do not sell or share the personal information of anyone under 16.

18. Other sites and services

Our website links to sites we do not control, including provider websites, professional bodies and the opt-out tools named in section 8. This policy does not apply to them. Read their privacy policies before providing personal information.

19. Changes to this policy

We may update this policy to reflect changes in our practices, our service providers, or the law. When we do we will change the “Last updated” date at the top. If a change materially affects how we handle personal information already collected, we will give notice by email to portal account holders, or by a prominent notice on the website, at least 30 days before it takes effect, unless the law requires sooner. Continuing to use the Services after a change takes effect means you accept the updated policy.

We keep prior versions and will provide one on request.

20. How to contact us

For any privacy question, request or complaint:

If you need this policy in an alternative accessible format, tell us and we will provide one at no charge.