Privacy Policy & CCPA Notice

Review how privacy rights are handled and submit requests from one place.

Last updated: 2026-08-11 Policy version: 2026-08-11.1
Who We Are and How to Contact Us

MediWorld provides patient-management and healthcare-support services. This policy describes our online and offline handling of personal information and the rights available to California consumers.

Notice at Collection

The following notice applies at or before collection. We do not collect additional categories or use information for materially incompatible purposes without providing a new notice and obtaining consent when required.

The categories below describe information collected during the preceding 12 months and information we expect to continue collecting.

For information collected by telephone or in person, this notice may be provided orally, on the relevant paper form, or through a conspicuous sign or direct link before collection.

CategoryExamplesCollection and use purposesSold/shared for cross-context advertisingRetention period or criteria
Identifiers and contact information Name, account ID, email, telephone number, address, date of birth, guardian and referral information. Create and secure accounts, identify patients, provide care, schedule services, communicate, and comply with law. No For the account relationship and afterward only as required for clinical, billing, security, dispute, or legal obligations.
Demographic and protected characteristics
Sensitive information
Age, sex or gender, language, marital or guardian status, and information relevant to care. Provide appropriate care, accessibility, administration, and legally required reporting. No According to the retention period applicable to the related patient or administrative record.
Health, medical, dental, obstetric, therapy, and prescription information
Sensitive information
Diagnoses, symptoms, medicines, tests, treatment notes and plans, medical images, measurements, assessments, and insurance or medical identifiers. Treatment, care coordination, patient-requested services, payment, safety, legal reporting, and continuity of care. No For the period required by applicable medical-record, prescription, insurance, and professional-practice obligations; unrelated optional data is deleted or deidentified when no longer needed.
Services, billing, and payment history
Sensitive information
Services received, invoices, charges, discounts, payment status, and transaction references; not full payment credentials. Provide services, collect payment, manage accounts, prevent fraud, and meet tax and accounting duties. No For the account relationship and the period required by tax, accounting, payment-dispute, and legal obligations.
Communications and customer-service content
Sensitive information
Email and SMS delivery records, appointment messages, comments, chatbot conversations, reports, and support requests. Respond to requests, deliver requested notices and reports, support care, and document service communications. No For as long as needed for the communication, related care or service record, delivery evidence, disputes, and legal obligations.
Images, video, audio, and documents
Sensitive information
Medical and dental images, before-and-after records, therapy videos, uploaded records, voice output, and statements. Treatment, documentation, requested accessibility features, patient reports, and legal recordkeeping. No According to the related clinical, educational, billing, or legal record period; temporary generated artifacts are removed when no longer necessary.
Therapy and education records
Sensitive information
Student schedules, assessments, goals, lessons, progress reports, tuition statements, and related media. Provide therapy and educational services, communicate progress, coordinate care, and bill for services. No According to the related care, education, payment, and legal retention requirements.
Device, network, and account activity IP address, browser and device information, login activity, request metadata, security events, and cookie identifiers. Authentication, fraud prevention, security monitoring, request auditing, troubleshooting, and service operation. No Security and PHI-access logs are generally retained for up to seven years; privacy-request records are retained for at least 24 months; cookies expire according to their stated lifetime.
Location information
Sensitive information
Address, coordinates supplied for access controls, and geocoded location descriptions. Provide location-based service functions, protect accounts, and enforce authorized access locations. No For as long as the location restriction or related account/security record remains necessary.
Privacy choices and rights-request records Opt-out and limit choices, GPC signals, request type and status, acknowledgements, deadlines, decisions, and action history. Honor choices, fulfill rights requests, prevent preferences from being reversed, and demonstrate legal compliance. No At least 24 months, and longer only when reasonably necessary for legal claims or another documented obligation.

Manage Privacy Preferences

Sources of Personal Information
  • You, the patient, a parent, guardian, authorized representative, or person acting at your direction.
  • Healthcare providers, clinics, therapists, laboratories, pharmacies, staff, and other care participants.
  • Your browser, device, account activity, cookies, security systems, and information you upload or submit.
  • Integrated processors and service providers, including clinical, imaging, prescription, communications, location, backup, and payment services.
Disclosures and Recipient Categories

During the preceding 12 months, we may have disclosed the listed categories to the following recipients for the stated operational purposes. A service-provider classification depends on an applicable contract restricting use of the information.

Recipient categoryPurposeData categoriesRelationship
OpenEMR treatment identifiers, medical information Service provider or contractor
Orthanc treatment identifiers, medical imaging Service provider or contractor
Configured mail provider appointment notification identifiers, communications Service provider or contractor
Configured SMS provider appointment notification identifiers, communications Service provider or contractor
Configured backup storage backup all application data Service provider or contractor
Consumer consumer export consumer personal information Consumer or other directed recipient
Google Translate TTS service provider processing name or spoken text Service provider or contractor
Configured geocoding provider service provider processing address Service provider or contractor
Configured mail provider marketing identifiers, contact information Service provider or contractor

We do not sell personal information for money and do not share personal information for cross-context behavioral advertising. We honor Global Privacy Control and recorded opt-out choices in case a practice or integration changes.

We use sensitive personal information for necessary treatment, requested services, payment, security, legal retention, backups, and other permitted purposes. A recorded limitation blocks optional profiling, personalization, marketing uses, and unrelated sensitive-data disclosures.

Your Privacy Rights
Right to Know

You have the right to request what personal information we collect, use, and disclose.

Right to Correct

You have the right to request correction of inaccurate personal information that we maintain about you.

Right to Delete

You have the right to request the deletion of your personal information collected by us, subject to certain exceptions (like medical record retention laws).

Right to Limit

You have the right to limit our use and disclosure of sensitive personal information.

Right to Opt-Out

You have the right to direct us to not sell or share your personal information.

Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights.

Exercise Your Rights

To exercise your rights under CCPA, please use the links below or contact us at dev@kodeplus.com.

We confirm receipt within 10 business days and respond to requests to know, delete, or correct within 45 calendar days. When reasonably necessary, we may extend the response period once by 45 calendar days and will explain the reason.

Please log in to exercise your Right to Know and Right to Delete. Manage Privacy Preferences
Submitting and Verifying Privacy Requests

Submit a request through the website tools above, email dev@kodeplus.com, or call 0907193168. We do not charge for verification or require an account for sale/share or sensitive-information limitation choices.

For requests to know, delete, or correct, we use the information already associated with the account, authenticated access, two-factor authentication, recent password confirmation, and proportionate follow-up questions where needed. We use newly collected verification information only for verification, security, fraud prevention, and required request records, then delete it when no longer needed.

An authorized agent may email dev@kodeplus.com with the request, the consumer’s signed permission, the consumer’s contact information, and proof of the agent’s identity. We may ask the consumer to verify their identity or directly confirm permission. A valid power of attorney is accepted without requiring separate signed permission.

Healthcare Information and Other Laws

Some medical information governed by HIPAA, CMIA, or another healthcare law may be exempt from particular CCPA provisions. These exemptions apply to qualifying information and processing, not automatically to every account, website, device, marketing, or administrative record. Separate medical-record access rights continue to apply.

Children and Financial Incentives

We do not knowingly sell or share the personal information of consumers under 16. Patient services for a minor may be managed by a parent, guardian, or other legally authorized representative.

We do not currently offer a financial incentive or price or service difference in exchange for collecting, retaining, selling, or sharing personal information. If this changes, we will provide a separate Notice of Financial Incentive before enrollment.

Security, Cookies, and Policy Changes

We use administrative, technical, and physical safeguards designed for the sensitivity of healthcare and account information. No system can guarantee absolute security; suspected incidents are investigated and handled under applicable notification duties.

We use strictly necessary first-party cookies for sessions, security, language, and privacy choices. The privacy-choice cookie is necessary to remember browser-specific opt-outs. We do not currently use the cookie banner to authorize analytics or advertising trackers.

AI-assisted features may process information supplied by authorized users to interpret instructions, draft structured records, or provide chatbot responses. They are not represented as the sole basis for a legally or similarly significant decision about a consumer. If covered automated decisionmaking is introduced, we will provide the required pre-use notice and applicable access and opt-out methods.

We review this policy at least annually and update the date above when practices change. If we intend to collect a new category or use information for a materially incompatible purpose, we will provide a new notice before that collection or use.