PYMED PRIVACY POLICY

Last Updated & Effective: July 01, 2026

Please read this Privacy Policy carefully before using any of our Services. By accessing or using the Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

SECTION 1. INTRODUCTION AND SCOPE.

Pymed Technologies, Inc. ("Pymed," "we," "us," or "our") is a provider of cloud-native electronic health record (EHR), practice management, patient engagement, and telehealth solutions, including the Pymed Cloud-Native EHR SaaS Solution and the Bookingo Platform (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect Personal Information in connection with our websites, applications, portals, and the Services we provide to healthcare organizations ("Customers" or "Providers") and their authorized users. This Privacy Policy applies to Personal Information that we collect from or about:

a)     visitors to our websites;

b)     Authorized Users of our Services (including employees, contractors, and agents of Providers whom the Customer has authorized to access the Services); and

c)     individuals who communicate with us. It is intended for use in the United States and, where applicable, for individuals in the European Economic Area (EEA), United Kingdom, and other jurisdictions. 

Important Distinction Regarding Protected Health Information (PHI): This Privacy Policy does not govern Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"). When we process PHI on behalf of our healthcare provider Customers, we do so solely as a Business Associate under HIPAA and pursuant to a Business Associate Agreement ("BAA") and our Pymed Master Cloud Subscription and Terms of Use Agreement (the "Pymed Master Agreement") and the applicable Business Associate Agreement ("BAA"). PHI is subject to the Customer’s Notice of Privacy Practices and the terms of the BAA, not this Privacy Policy. Patients seeking information about their PHI should contact their healthcare provider directly. 

This Privacy Policy is not itself a contract and does not create independent contractual rights or obligations. It forms part of the overall contractual relationship described in the Pymed Master Agreement but ranks lowest in the order of precedence set forth therein. Your use of the Services is governed by the Pmyned Master Agreement, any applicable Order Form, Statement of Work, Service Level Agreement, Acceptable Use Policy, and the BAA. In the event of any conflict with respect to Protected Health Information, the BAA controls. This Privacy Policy is the lowest document in the contractual order of precedence established by the Master Agreement. 

SECTION 2. KEY DIFINITIONS.

2.1. Personal Information (or "personal data").

means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an individual or household. For purposes of this Policy, Personal Information does not include PHI. 

2.2. Protected Health Information (PHI).

means individually identifiable health information that is protected by HIPAA. 

2.3. Services.

means the Pymed Cloud-Native EHR SaaS Solution, Bookingo Platform, related websites, mobile and web applications, portals, software, and any other products or services we offer. 

2.4. Customer/ Provider.

means a healthcare organization, practice, clinic, hospital, or individual practitioner that has contracted with Pymed to use the Services. 

2.5. Usage Data.

means information automatically collected about how the Services or websites are accessed and used, including IP addresses, browser type, device information, pages viewed, and timestamps. 

SECTION 3. PERSONAL INFORMATION WE COLLECT.

The categories of Personal Information we collect depend on how you interact with us. We may collect:

3.1. Information You Provide Directly.

        Identifiers and Contact Information: name, email address, telephone number, mailing address, job title, organization name, specialty, and number of providers in the organization.

        Account Credentials: username, password, and multi-factor authentication information.

        Professional and Licensing Information: NPI number, DEA registration number, medical license information, Tax ID, and related professional credentials.

        Payment and Billing Information: credit card number, security code, expiration date, billing address, and bank account information (processed through secure third-party payment processors).

        Communications: information you provide when contacting support, requesting demos, submitting forms, or interacting with us via email, chat, phone, or social media.

        Other Information: any other information you choose to provide.

3.2. Information Collected Automatically.

        Device and Internet Information: IP address, browser type and version, operating system, device identifiers, and internet service provider.

        Usage Data: pages or features accessed, time and date of access, referring URLs, clickstream data, and interaction with emails.

        Cookies and Similar Technologies: we and our service providers use cookies, web beacons, pixels, and similar technologies. See Section 8 for more details.

3.3. Information from Third Parties.

We may receive Personal Information from third parties, including business partners, analytics providers, public databases, or other sources you authorize. We handle such information in accordance with this Privacy Policy.

3.4. Sensitive Personal Information

In limited circumstances and only as necessary to provide the Services or as required by law, we may process certain sensitive personal information (such as government-issued identifiers or, with consent, biometric data for authentication). We do not use sensitive personal information for purposes beyond those necessary to provide the Services or as otherwise permitted by applicable law of the United States of America and the markets where Pymed is doing business. 

SECTION 4. HOW WE COLLECT PERSONAL INFORMATION.

        Directly from you when you register for an account, complete forms, communicate with us, or use the Services.

        Automatically through cookies, log files, and similar technologies when you visit our websites or use the Services.

        From third parties, including our service providers, business partners, and sources you authorize. 

SECTION 5. HOW WE USE PERSONAL INFORMATION.

We use Personal Information for the following business and commercial purposes:

        To provide, operate, maintain, and improve the Services.

        To create and manage user accounts, authenticate users, and provide customer support.

        To process transactions, send invoices, and manage billing.

        To communicate with you about the Services, including service-related notices, updates, and (where permitted) marketing communications.

        To personalize your experience and develop new products and features.

        To detect, prevent, and respond to security incidents, fraud, and other illegal or unauthorized activities.

        To comply with applicable laws, regulations, legal processes, and governmental requests.

        To enforce our agreements and protect our rights, property, and safety, and those of our Customers and others.

        To conduct research, analytics, and aggregate or de-identified data analysis (in a manner that does not identify individuals).

        For any other purpose with your consent or as otherwise permitted by law.

SECTION 6. HOW WE DISCLOSE PERSONAL INFORMATION

We do not sell Personal Information. We may disclose Personal Information in the following circumstances:

        Service Providers: to vendors and service providers who perform services on our behalf (e.g., cloud hosting, payment processing, analytics, customer support, email delivery), subject to contractual confidentiality and data protection obligations.

        Affiliates: to our corporate affiliates for purposes consistent with this Privacy Policy.

        Business Transfers: in connection with a merger, acquisition, reorganization, sale of assets, or similar transaction.

        Legal and Safety: when required by law, legal process, or governmental request, or to protect rights, safety, or property.

        With Your Direction: when you request or authorize disclosure to a third party.

        Aggregated or De-identified Data: we may share aggregated or de-identified information that cannot reasonably be used to identify you.

SECTION 7. PROTECTED HEALTH INFORMATION AND OUR ROLE AS BUSINESS ASSOCIATE.

When our Customers use the Services to create, receive, maintain, or transmit PHI, Pymed acts as a Business Associate under HIPAA. In that capacity:

        We process PHI only as permitted or required by the applicable BAA and the Customer’s instructions.

        We implement administrative, physical, and technical safeguards required by the HIPAA Security Rule.

        We do not use or disclose PHI for our own purposes except as permitted by the BAA or required by law.

        Patients’ rights regarding their PHI (access, amendment, accounting of disclosures, etc.) are exercised through their healthcare provider (our Customer), not directly through Pymed.

If you are a patient seeking access to or information about your health records, please contact your healthcare provider. If you are a Customer and have questions about our HIPAA compliance or BAAs, please contact us using the information in Section 18.

SECTION 8. COOKIES AND TRACKING TECHNOLOGIES.

We and certain third parties use cookies and similar technologies on our websites and, to a limited extent, within the Services for authentication, security, functionality, analytics, and (on public websites) marketing. Essential cookies are necessary for the Services to function. You may control non-essential cookies through your browser settings or, where available, our cookie preference tools. Disabling certain cookies may affect functionality. We do not deploy non-essential third-party tracking cookies within authenticated Provider portals except as necessary for security and service delivery.

We use Google Analytics and similar tools on our public websites. You may opt out of Google Analytics by installing the browser add-on available at https://tools.google.com/dlpage/gaoptout.

SECTION 9. DATA SECURITY.

We implement reasonable and appropriate administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, use, disclosure, alteration, or destruction. These measures include encryption of data in transit and at rest, role-based access controls, multi-factor authentication, audit logging, regular security assessments, and employee training. No method of transmission or storage is 100% secure; therefore, we cannot guarantee absolute security. If you believe your information has been compromised, please contact us immediately.

SECTION 10. DATA RETENTION.

We retain Personal Information for as long as necessary to fulfill the purposes described in this Privacy Policy, to provide the Services, to comply with legal obligations (including healthcare record retention requirements applicable to our Customers), to resolve disputes, and to enforce our agreements. Retention periods may vary based on the nature of the data, contractual requirements with Customers, and applicable law. When Personal Information is no longer needed, we will securely delete or de-identify it in accordance with our retention policies and legal requirements.

SECTION 11. BIOMETRIC DATA.

In certain configurations of the Services, and only with appropriate notice and consent where required, we may collect biometric identifiers (such as fingerprints or facial geometry) solely for authentication and identity verification purposes. We do not sell, lease, or trade biometric information. We retain biometric data only until the purpose for collection has been satisfied, a required deletion date is reached, or three (3) years have elapsed since the individual’s last interaction with the relevant feature, whichever occurs first (unless a different period is required by law or the applicable BAA for PHI). Biometric data that constitutes PHI is governed exclusively by the BAA and HIPAA.

SECTION 12. CHILDREN’S PRIVACY.

Our Services are directed to healthcare organizations and adult professionals. We do not knowingly collect Personal Information from children under the age of 18 (or the applicable age of majority). If we learn that we have collected Personal Information from a child under 18 without appropriate consent, we will take steps to delete such information. If you believe a child has provided us with Personal Information, please contact us at [email protected].

SECTION 13. THIRD-PARTY LINKS AND SERVICES.

Our websites and Services may contain links to third-party websites or integrate third-party services. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party sites or services you access.

SECTION 14. INTERNATIONAL DATA TRANSFERS AND LOCAL GOVERNANCE.

Pymed is based in the United States, and the Services are primarily intended for Customers located in the United States. Personal Information may be transferred to, stored, and processed in the United States or other countries where we or our service providers operate. By using the Services, you acknowledge that your information may be transferred to the United States. When we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) or other lawful transfer mechanism.

SECTION 15. GENERAL TERM OF YOUR PRIVACY RIGHTS.

Depending on your location and applicable law, you may have the right to:

        Access the Personal Information we hold about you.

        Request correction of inaccurate or incomplete Personal Information.

        Request deletion of your Personal Information, subject to legal and contractual retention obligations.

        Object to or restrict certain processing.

        Withdraw consent where processing is based on consent.

        Receive a portable copy of certain Personal Information.

To exercise these rights, please contact us at [email protected]. We will respond in accordance with applicable law. We may need to verify your identity before processing your request. Certain rights may be limited where we act as a service provider/processor on behalf of a Customer; in those cases, we will direct you to the relevant Customer.

SECTION 16. SUPLEMENTAL PRIVACY NOTICE FOR CALIFORNIA RESIDENTS.

This Section 16 supplements the Privacy Policy and applies solely to residents of California ("Consumers") as required by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"). Terms defined in the CCPA/CPRA have the same meaning when used in this Section.

16.1. Categories of Personal Information Collected.

In the preceding 12 months, we have collected the following categories of Personal Information (as defined by the CCPA/CPRA):

        Identifiers: name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.

        Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)): name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or other financial information, medical information, or health insurance information.

        Protected classification characteristics under California or federal law: age, race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex, sexual orientation, veteran or military status (collected only when voluntarily provided or required).

        Commercial information: records of products or services purchased, obtained, or considered.

        Biometric information: fingerprints or facial geometry (only if used for authentication and with appropriate notice/consent).

        Internet or other electronic network activity: browsing history, search history, information regarding interaction with our websites, applications, or advertisements.

        Geolocation data: physical location or movements (only as permitted and with consent where required).

        Professional or employment-related information: current or past job history, professional licenses, NPI, DEA numbers.

        Inferences: drawn from other Personal Information to create a profile reflecting preferences or characteristics.

We do not collect sensory data or education information beyond what is voluntarily provided in a professional context. PHI is excluded from the scope of this Notice as explained in Section 1.

16.2. Sources of Personal Information.

We collect Personal Information from the sources described in Section 4 (directly from you, automatically, and from third parties).

16.3. Business or Commercial Purposes for Collection and Use.

We use the categories of Personal Information listed above for the purposes described in Section 5.

16.4. Disclosure of Personal Information.

We may disclose each of the categories of Personal Information listed above to the categories of third parties described in Section 6 (service providers, affiliates, in connection with business transfers, for legal reasons, and at your direction). We do not sell Personal Information and have not sold Personal Information in the preceding 12 months. We do not share Personal Information for cross-context behavioral advertising.

16.5. Your California Privacy Rights.

As a California resident, you have the following rights (subject to certain exceptions and limitations):

        Right to Know/ Access: to request that we disclose the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business or commercial purpose for collecting, and the categories of third parties with whom we share it.

        Right to Delete: to request deletion of Personal Information we have collected from you, subject to exceptions.

        Right to Correct: to request correction of inaccurate Personal Information.

        Right to Opt-Out of Sale/Sharing: we do not sell or share Personal Information for cross-context behavioral advertising; therefore, this right is not applicable in the ordinary course.

        Right to Limit Use of Sensitive Personal Information: to limit our use of sensitive personal information to that which is necessary to perform the Services or as otherwise permitted.

        Right to Non-Discrimination: we will not discriminate against you for exercising your CCPA/CPRA rights.

16.6. How to Exercise Your California Rights

You (or your authorized agent) may submit a request by:

        Email: [email protected]

        Online form: available on our website

We will verify your identity before processing requests. For requests submitted by an authorized agent, we may require proof of authorization. We will respond within the timeframes required by law (generally 45 days, with a possible 45-day extension).

SECTION 17. ADDITIONAL STATE PRIVACY RIGHTS—Nevada, Texas, and Other States.

17.1. Nevada Residents.

Under Nevada Revised Statutes Chapter 603A, Nevada residents may submit a verified request directing us not to sell certain covered information that we have collected or will collect about them. Pymed does not sell covered information as defined under Nevada law. Nevertheless, if you are a Nevada resident and wish to submit a formal "Do Not Sell" request, please email: [email protected] with the subject line “Nevada Do Not Sell Request.” We will respond in accordance with Nevada law.

17.2. Texas Residents.

The Texas Data Privacy and Security Act (TDPSA) provides Texas residents with certain rights regarding their personal data, including the rights to access, correct, delete, and obtain a copy of personal data, and to opt out of certain processing (targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects). We do not sell personal data or engage in targeted advertising or profiling of the type regulated by the TDPSA in a manner that would trigger opt-out rights for the ordinary use of our Services. Texas residents may exercise applicable rights by contacting us at [email protected]. We will respond in accordance with the TDPSA.

17.3 Other U.S. State Privacy Laws.

Residents of states that have enacted comprehensive consumer privacy laws (including, without limitation, Colorado, Connecticut, Virginia, Utah, Oregon, Montana, Iowa, Delaware, New Jersey, and others as they become effective) may have rights similar to those described above. We will honor applicable rights under those laws. Please contact [email protected] to exercise your rights. We will process requests in accordance with the applicable state law.

SECTION 18. Supplemental Notice for Individuals in the European Economic Area, United Kingdom, and Switzerland (GDPR).

This Section applies to the processing of personal data of individuals located in the EEA, UK, or Switzerland when GDPR or equivalent law applies. Pymed Technologies, Inc. is the data controller for personal data we process about our direct customers, website visitors, and our own personnel. When we process personal data (including health data) on behalf of our healthcare provider Customers, we act as a data processor and process such data only in accordance with the Customer’s documented instructions and the applicable Data Processing Agreement.

 18.1. Legal Bases for Processing.

We process personal data on the following legal bases:

        Contractual necessity: to perform our contract with you or the Customer.

        Legitimate interests: for security, fraud prevention, service improvement, and business operations, provided these do not override your rights and freedoms.

        Legal obligation: to comply with applicable laws.

        Consent: where we have obtained your consent (e.g., for certain marketing or optional features). You may withdraw consent at any time.

18.2. Your GDPR Rights.

Under the GDPR you have the following rights (subject to conditions and exceptions):

        Right of access – to obtain confirmation of whether we process your personal data and a copy of that data.

        Right to rectification – to have inaccurate personal data corrected.

        Right to erasure ("right to be forgotten") – to request deletion of personal data in certain circumstances.

        Right to restriction of processing – to request that we restrict processing in certain circumstances.

        Right to data portability – to receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

        Right to object – to object to processing based on legitimate interests or for direct marketing.

        Rights related to automated decision-making – including the right not to be subject to solely automated decisions with legal or similarly significant effects.

To exercise these rights, contact us at [email protected]. We will respond within one month (extendable in complex cases). You also have the right to lodge a complaint with your local supervisory authority.

18.3. International Transfers.

When personal data is transferred outside the EEA/UK/Switzerland, we ensure appropriate safeguards are in place, including the use of Standard Contractual Clauses approved by the European Commission or UK authorities, and other measures as required by applicable law.

18.4. Data Protection Officer / Representative.

For GDPR-related inquiries, you may contact us at [email protected]. If we appoint a Data Protection Officer or EU/UK Representative, contact details will be published on our website.

19. Changes to This Privacy Policy.

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last Updated" date at the top of this Policy and, where appropriate, provide additional notice (such as a notice on our website or direct notification). We encourage you to review this Privacy Policy periodically. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should discontinue use of the Services.

20. Contact Us.

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:

Pymed Technologies, Inc.

9355 John W. Elliott Drive, Suite 25

Frisco, Texas 75033, USA

Email: [email protected]

 21. ACKNOWLEDGMENT.

BY ACCESSING OR USING THE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR PERSONAL INFORMATION AS DESCRIBED HEREIN. IF YOU DO NOT AGREE, PLEASE DO NOT USE THE SERVICES.

###END###