Privacy Policy & CCPA Notice
Review how privacy rights are handled and submit requests from one place.
Who We Are and How to Contact Us
MediWorld provides patient-management and healthcare-support services. This policy describes our online and offline handling of personal information and the rights available to California consumers.
- Privacy email: dev@kodeplus.com
- Phone: 0907193168
Notice at Collection
The following notice applies at or before collection. We do not collect additional categories or use information for materially incompatible purposes without providing a new notice and obtaining consent when required.
The categories below describe information collected during the preceding 12 months and information we expect to continue collecting.
For information collected by telephone or in person, this notice may be provided orally, on the relevant paper form, or through a conspicuous sign or direct link before collection.
| Category | Examples | Collection and use purposes | Sold/shared for cross-context advertising | Retention period or criteria |
|---|---|---|---|---|
| Identifiers and contact information | Name, account ID, email, telephone number, address, date of birth, guardian and referral information. | Create and secure accounts, identify patients, provide care, schedule services, communicate, and comply with law. | No | For the account relationship and afterward only as required for clinical, billing, security, dispute, or legal obligations. |
| Demographic and protected characteristics Sensitive information |
Age, sex or gender, language, marital or guardian status, and information relevant to care. | Provide appropriate care, accessibility, administration, and legally required reporting. | No | According to the retention period applicable to the related patient or administrative record. |
| Health, medical, dental, obstetric, therapy, and prescription information Sensitive information |
Diagnoses, symptoms, medicines, tests, treatment notes and plans, medical images, measurements, assessments, and insurance or medical identifiers. | Treatment, care coordination, patient-requested services, payment, safety, legal reporting, and continuity of care. | No | For the period required by applicable medical-record, prescription, insurance, and professional-practice obligations; unrelated optional data is deleted or deidentified when no longer needed. |
| Services, billing, and payment history Sensitive information |
Services received, invoices, charges, discounts, payment status, and transaction references; not full payment credentials. | Provide services, collect payment, manage accounts, prevent fraud, and meet tax and accounting duties. | No | For the account relationship and the period required by tax, accounting, payment-dispute, and legal obligations. |
| Communications and customer-service content Sensitive information |
Email and SMS delivery records, appointment messages, comments, chatbot conversations, reports, and support requests. | Respond to requests, deliver requested notices and reports, support care, and document service communications. | No | For as long as needed for the communication, related care or service record, delivery evidence, disputes, and legal obligations. |
| Images, video, audio, and documents Sensitive information |
Medical and dental images, before-and-after records, therapy videos, uploaded records, voice output, and statements. | Treatment, documentation, requested accessibility features, patient reports, and legal recordkeeping. | No | According to the related clinical, educational, billing, or legal record period; temporary generated artifacts are removed when no longer necessary. |
| Therapy and education records Sensitive information |
Student schedules, assessments, goals, lessons, progress reports, tuition statements, and related media. | Provide therapy and educational services, communicate progress, coordinate care, and bill for services. | No | According to the related care, education, payment, and legal retention requirements. |
| Device, network, and account activity | IP address, browser and device information, login activity, request metadata, security events, and cookie identifiers. | Authentication, fraud prevention, security monitoring, request auditing, troubleshooting, and service operation. | No | Security and PHI-access logs are generally retained for up to seven years; privacy-request records are retained for at least 24 months; cookies expire according to their stated lifetime. |
| Location information Sensitive information |
Address, coordinates supplied for access controls, and geocoded location descriptions. | Provide location-based service functions, protect accounts, and enforce authorized access locations. | No | For as long as the location restriction or related account/security record remains necessary. |
| Privacy choices and rights-request records | Opt-out and limit choices, GPC signals, request type and status, acknowledgements, deadlines, decisions, and action history. | Honor choices, fulfill rights requests, prevent preferences from being reversed, and demonstrate legal compliance. | No | At least 24 months, and longer only when reasonably necessary for legal claims or another documented obligation. |
Sources of Personal Information
- You, the patient, a parent, guardian, authorized representative, or person acting at your direction.
- Healthcare providers, clinics, therapists, laboratories, pharmacies, staff, and other care participants.
- Your browser, device, account activity, cookies, security systems, and information you upload or submit.
- Integrated processors and service providers, including clinical, imaging, prescription, communications, location, backup, and payment services.
Disclosures and Recipient Categories
During the preceding 12 months, we may have disclosed the listed categories to the following recipients for the stated operational purposes. A service-provider classification depends on an applicable contract restricting use of the information.
| Recipient category | Purpose | Data categories | Relationship |
|---|---|---|---|
| OpenEMR | treatment | identifiers, medical information | Service provider or contractor |
| Orthanc | treatment | identifiers, medical imaging | Service provider or contractor |
| Configured mail provider | appointment notification | identifiers, communications | Service provider or contractor |
| Configured SMS provider | appointment notification | identifiers, communications | Service provider or contractor |
| Configured backup storage | backup | all application data | Service provider or contractor |
| Consumer | consumer export | consumer personal information | Consumer or other directed recipient |
| Google Translate TTS | service provider processing | name or spoken text | Service provider or contractor |
| Configured geocoding provider | service provider processing | address | Service provider or contractor |
| Configured mail provider | marketing | identifiers, contact information | Service provider or contractor |
We do not sell personal information for money and do not share personal information for cross-context behavioral advertising. We honor Global Privacy Control and recorded opt-out choices in case a practice or integration changes.
We use sensitive personal information for necessary treatment, requested services, payment, security, legal retention, backups, and other permitted purposes. A recorded limitation blocks optional profiling, personalization, marketing uses, and unrelated sensitive-data disclosures.
Your Privacy Rights
You have the right to request what personal information we collect, use, and disclose.
You have the right to request correction of inaccurate personal information that we maintain about you.
You have the right to request the deletion of your personal information collected by us, subject to certain exceptions (like medical record retention laws).
You have the right to limit our use and disclosure of sensitive personal information.
You have the right to direct us to not sell or share your personal information.
We will not discriminate against you for exercising any of your CCPA rights.
Exercise Your Rights
To exercise your rights under CCPA, please use the links below or contact us at dev@kodeplus.com.
We confirm receipt within 10 business days and respond to requests to know, delete, or correct within 45 calendar days. When reasonably necessary, we may extend the response period once by 45 calendar days and will explain the reason.
Submitting and Verifying Privacy Requests
Submit a request through the website tools above, email dev@kodeplus.com, or call 0907193168. We do not charge for verification or require an account for sale/share or sensitive-information limitation choices.
For requests to know, delete, or correct, we use the information already associated with the account, authenticated access, two-factor authentication, recent password confirmation, and proportionate follow-up questions where needed. We use newly collected verification information only for verification, security, fraud prevention, and required request records, then delete it when no longer needed.
An authorized agent may email dev@kodeplus.com with the request, the consumer’s signed permission, the consumer’s contact information, and proof of the agent’s identity. We may ask the consumer to verify their identity or directly confirm permission. A valid power of attorney is accepted without requiring separate signed permission.
Healthcare Information and Other Laws
Some medical information governed by HIPAA, CMIA, or another healthcare law may be exempt from particular CCPA provisions. These exemptions apply to qualifying information and processing, not automatically to every account, website, device, marketing, or administrative record. Separate medical-record access rights continue to apply.
Children and Financial Incentives
We do not knowingly sell or share the personal information of consumers under 16. Patient services for a minor may be managed by a parent, guardian, or other legally authorized representative.
We do not currently offer a financial incentive or price or service difference in exchange for collecting, retaining, selling, or sharing personal information. If this changes, we will provide a separate Notice of Financial Incentive before enrollment.
Security, Cookies, and Policy Changes
We use administrative, technical, and physical safeguards designed for the sensitivity of healthcare and account information. No system can guarantee absolute security; suspected incidents are investigated and handled under applicable notification duties.
We use strictly necessary first-party cookies for sessions, security, language, and privacy choices. The privacy-choice cookie is necessary to remember browser-specific opt-outs. We do not currently use the cookie banner to authorize analytics or advertising trackers.
AI-assisted features may process information supplied by authorized users to interpret instructions, draft structured records, or provide chatbot responses. They are not represented as the sole basis for a legally or similarly significant decision about a consumer. If covered automated decisionmaking is introduced, we will provide the required pre-use notice and applicable access and opt-out methods.
We review this policy at least annually and update the date above when practices change. If we intend to collect a new category or use information for a materially incompatible purpose, we will provide a new notice before that collection or use.