This Privacy Policy (“Policy”) supplements Hemma Wellness Group LLC’s (“Hemma Wellness,”
“we,” “us,” or “our”) Terms and Conditions. It describes how we and our affiliated medical provider
partners collect, use, maintain, protect, and disclose your personal information when you use our
website, digital platforms, and telehealth services (the “Services”).
By “Personal Data,” we mean information that identifies you or can reasonably be used to identify
you. Please read this Policy carefully. If you do not agree, you should not use our Services. By
accessing or using our Services, you agree to this Policy. We may update this Policy periodically, and
continued use of the Services indicates acceptance of those changes.
1. Platform and Provider Portals
Hemma Wellness does not presently provide medical advice or operate a patient portal. Our role is
to help you engage with independent medical groups and licensed clinicians who deliver care. If you
qualify through initial questions on our site, you will be invited to schedule with a provider and
complete intake on that provider’s own patient portal and related systems operated by the provider
or its service providers. Those systems may display Hemma branding, but are operated by the
provider or its service providers. Payment for clinical services, diagnosis or treatment, telehealth
encounters, lab work, and prescription fulfillment take place through those provider operated
systems and third party labs or pharmacies, not on Hemma’s website. Your relationship with the
provider and your use of the provider’s systems are governed by the provider’s privacy notices and
the provider’s service providers, not this policy.
2. Protected Health Information (PHI) and HIPAA
Some of the information you provide may be considered Protected Health Information (PHI) under
the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Hemma Wellness itself
does not practice medicine or dispense medication. Instead, clinical services are provided by licensed
U.S. telehealth providers.
PHI is protected under HIPAA and our providers’ Notice of Privacy Practices (NPP).
If there is any conflict between this Policy and our HIPAA obligations, HIPAA and the NPP
will govern.
Information that is not PHI may still be used and disclosed as described in this Policy.
Medical groups and their service providers may share limited personal information with Hemma
Wellness to support your experience, such as appointment status, non clinical account data,
fulfillment updates, and payment confirmations, and where permitted by law, limited clinical context
necessary for operations. Any PHI handled by a provider or its business associates is subject to
HIPAA and the provider’s Notice of Privacy Practices. To the extent there is any conflict between
this policy and HIPAA obligations, HIPAA and the provider’s Notice of Privacy Practices control.
3. Children Under 18
Our Services are intended for adults aged 18 and older. We do not knowingly collect Personal Data
from children under 18. If we learn that we have collected Personal Data from a child under 18, we
will delete it.
If you are under 18, do not use or provide any information on our Services. If you believe we may
have collected data from a minor, please contact us immediately at info@hemma-wellness.com.
4. Personal Data We Collect
We may collect the following categories of Personal Data:
Identifiers: Name, postal/billing address, email address, phone number, date of birth.
Payment Information: Credit or debit card numbers, HSA/FSA information, billing details
(processed by secure third parties).
Demographic Data: Gender, date of birth, and, where applicable, sensitive information such
as race or ethnicity if voluntarily provided for care.
Health Data (Sensitive Personal Data): Medical history, symptoms, diagnoses, medications,
interests related to health, and data from your intake or telehealth use.
Account Information: Usernames, login credentials, and communications with us.
Device/Usage Data: IP address, browser type, operating system, device identifiers, cookies,
pixels, and analytics data.
User Contributions: Content you post, upload, or submit via the Services.
Inferences: Information we generate about you, such as potential interests or preferences.5. How We Collect Personal Data Directly from You: When you fill out forms, create an account, subscribe to a service, use telehealth intake, or contact us.
Automatically: Through cookies, pixels, web beacons, and analytics when you interact with
our website or platform.
From Partners: From telehealth providers, labs, pharmacies, or business partners that help us
deliver services.
From Transactions: Payment and order records when you purchase subscriptions or products.
6. Automatic Data Collection Technologies
We and third parties use cookies, pixels, local storage, JavaScript and similar technologies to operate
and improve the site, remember preferences, measure performance, personalize content, and deliver
or measure advertising. Categories include necessary, performance, functionality, and targeting or
advertising technologies. Third party tools may set their own cookies or identifiers and process data
under their privacy policies. You can control cookies in your browser settings and learn more at
www.allaboutcookies.org. Blocking all cookies may impact site functionality. At this time, we do not
respond to browser do not track signals.
We use cookies, pixels, and similar tools to enhance your experience. This may include:
Traffic data, location data, error logs, and usage patterns.
Information about your device (IP address, operating system, browser).
Tracking technologies such as:
o Cookies: Small files stored on your browser.
o Pixels: Transparent images embedded in emails or ads (e.g., Meta, Google).
o Analytics Tools: Google Analytics, Mixpanel, or similar services.
7. How We Use Personal Data
We may use your data to:
Deliver the Services (telehealth, subscriptions, products).
Process payments and manage accounts.
Communicate with you about your care, account, or promotional offers (with opt-out
rights). Enforce our contractual rights and comply with laws.
Personalize your experience, track outcomes, and improve our Services.
Conduct research, development, and product improvement.
Protect against fraud, security threats, and misuse.
8. Disclosure of Personal Data
We may share your Personal Data as follows:
Clinical Partners: Licensed U.S. telehealth providers delivering care through Hemma’s intake
system.
Vendors & Service Providers: IT, hosting, payment processing, analytics, and marketing
partners under confidentiality agreements.
Affiliates & Subsidiaries: For operational or administrative purposes.
Corporate Transactions: If Hemma is acquired, merged, or restructured.
Legal & Regulatory: To comply with law, respond to government requests, or protect rights,
property, or safety.
With Consent: For purposes you authorize.
We do not sell your Personal Data. However, some data sharing with advertisers or analytics
providers may be considered a “sale” or “sharing” under certain state laws.
9. Choices About Data Use
Emails: You may unsubscribe from promotional emails at any time by clicking the
“unsubscribe” link or contacting us.
Cookies/Tracking: Adjust browser settings or use opt-out tools at www.aboutads.info or
www.networkadvertising.org.
Targeted Ads: You can opt out of interest-based advertising, but you may still see non-
targeted ads.
Do Not Track: At this time, we do not honor browser “Do Not Track” signals.
10. Your Rights
Depending on where you live, you may have rights under U.S. state laws (including California
CCPA/CPRA, Colorado, Connecticut, Texas, Utah, Virginia, Washington, and Nevada):
Access and request a copy of your data.
Request correction of inaccurate data.
Request deletion of data (subject to legal/medical retention rules).
Opt out of sales/sharing of Personal Data.
Limit use of sensitive Personal Data.
Appeal a denied request.
To exercise these rights, contact us at info@hemma-wellness.com. We may need to verify your
identity before processing a request.
11. Data Retention
We retain personal information for as long as needed to provide the services you request, meet legal
and regulatory retention periods, resolve disputes, and enforce agreements. When no longer needed,
we delete or de identify the information.
12. Marketing, direct mail, and advertising choices
With your consent where required, we may send marketing emails or deliver ads we think are
relevant. We may work with partners that use cookies and other identifiers to match to postal
addresses and send direct mail on our behalf. Hemma does not receive the underlying matched
personal data and our partners are contractually restricted from selling that information. You can opt
out of marketing emails using the unsubscribe link, request removal from direct mail programs by
contacting us at info@hemma-wellness.com, and manage ad preferences at the Digital Advertising
Alliance and the Network Advertising Initiative.
13. SMS communications and cart reminders
If you provide a mobile number and opt in, we may send SMS messages including appointment
updates, account alerts, and marketing messages. Message frequency varies. Message and data rates
may apply. You can opt out at any time by replying STOP. We may use cookies or pixels to detect
when a cart or sign up flow was started but not completed and, with your consent where required,
send reminder SMS or emails. We store phone numbers and related data as long as needed for the
purposes described or as required by law and we share them only with service providers that support
our messaging programs.
14. Security
We use physical, technical, and administrative safeguards to protect your Personal Data, including
encryption of data in transit and at rest where appropriate. However, no system is 100% secure, and
transmission of information via the internet is at your own risk.
15. Supplement for Washington and Nevada
This Consumer Health Data Privacy Notice supplements our Privacy Policy and applies to personal
data defined as consumer health data under Washington’s My Health My Data Act and Nevada’s
Consumer Health Data Privacy Law. Depending on how you interact with Hemma, examples may
include information about conditions, symptoms, treatment interests, medications, reproductive or
sexual health information, and data that identifies your attempt to seek health services.
Sources include information you provide, information collected automatically, limited information
from medical groups as described above, and other third party sources. Purposes include delivering
and improving our services, advertising and marketing with your consent where required, and
addressing legal obligations. We may share consumer health data with the categories described in our
Privacy Policy, including medical groups, vendors, affiliates, legal authorities when required, and in
connection with corporate transactions. Subject to exceptions, you may have rights to confirm,
access, delete, and withdraw consent for collection or sharing of consumer health data. To exercise
these rights or appeal a denial, contact us at legal@hemma-wellness.com. Washington residents can
also contact the Washington Attorney General and Nevada residents can contact the Nevada
Attorney General.
16. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted on our website with a
revised “Last Updated” date. We encourage you to review this Policy periodically.
17. Contact Us
For questions or requests related to this Policy, please contact:
Hemma Wellness Group LLC
16220 N Scottsdale Rd
Scottsdale, AZ 85254
info@hemma-wellness.com
Disclaimer
Hemma Wellness Group provides educational resources, digital tools, and access to licensed healthcare professionals through affiliated U.S. platforms. We do not provide medical care, and the information on this website is not a substitute for professional medical advice, diagnosis, or treatment. Always consult your physician or a qualified healthcare provider regarding any medical concerns. If you are experiencing a medical emergency, call 911 or seek emergency care immediately. Use of this website and related services does not establish a doctor-patient relationship with Hemma Wellness Group or its team. All clinical services are delivered by licensed U.S. providers through secure, HIPAA-compliant platforms.