Data Protection

alt
0 Comments

Scope and Applicability

This Data Protection Notice explains how KidsForce Rx (kidsforce.org) collects, uses, shares, and safeguards personal data in connection with our pediatric-focused information services. It is intended to meet requirements of the General Data Protection Regulation (GDPR) for individuals in the European Economic Area and United Kingdom, while also aligning with applicable United States privacy laws, including the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the Children’s Online Privacy Protection Act (COPPA), and other state privacy statutes. This Notice applies to personal data processed via our website, communications, tools, and related services.

Our content is informational and does not replace advice from a licensed clinician. Do not submit protected health information or emergency medical details through our website.

Identity of the Controller

Controller: KidsForce Rx, owned by Nerissa Halbrook

Postal Address: 1300 W Sunset Rd, Henderson, NV 89014, United States

Email: [email protected]

KidsForce Rx has not appointed a Data Protection Officer. Please direct all privacy inquiries to the contact above. If required by law, we will designate an EU/UK representative and update this Notice.

Categories of Personal Data We Process

Data You Provide Directly

  • Contact details (e.g., name, email address).
  • Account or preference information (e.g., saved settings, content preferences).
  • Communications content (e.g., inquiries, feedback, support requests).
  • Child-related context you choose to provide for educational tools (e.g., age range, weight range for dosing calculators), avoiding identifiable health details.

Data Collected Automatically

  • Usage and device data (e.g., IP address, browser type, operating system, pages viewed, time and date of visits, referring URLs).
  • Cookies and similar technologies (e.g., session identifiers, analytics tags) for functionality, analytics, security, and performance.

Data from Third Parties

  • Service providers (e.g., analytics, hosting, email delivery) furnishing aggregated or pseudonymous usage information.
  • If you interact with our content on third-party platforms, we may receive limited engagement metrics subject to your settings on those platforms.

Special Categories of Data

We do not seek to collect special categories of personal data (e.g., health, genetic, biometric data). Please do not submit protected health information. Any incidental health-related information that you voluntarily provide is processed only as necessary to respond to your request, with heightened care and minimal retention.

Purposes of Processing and Legal Bases

  • Provide and maintain services: to operate the website, enable features, and respond to requests (GDPR Art. 6(1)(b) contract or 6(1)(f) legitimate interests).
  • Safety, security, and integrity: to prevent fraud, abuse, and unauthorized access (GDPR Art. 6(1)(f) legitimate interests; 6(1)(c) legal obligation where applicable).
  • Communications: to send service messages and respond to inquiries (GDPR Art. 6(1)(b) contract; 6(1)(f) legitimate interests).
  • Consent-based activities: placing non-essential cookies or sending certain marketing communications (GDPR Art. 6(1)(a) consent).
  • Analytics and improvement: to understand usage and enhance content quality (GDPR Art. 6(1)(f) legitimate interests).
  • Legal compliance and protection: to comply with laws, resolve disputes, and enforce terms (GDPR Art. 6(1)(c) legal obligation; 6(1)(f) legitimate interests).

Where we rely on consent, you may withdraw it at any time without affecting lawfulness of prior processing.

Children’s Privacy and Parental Consent

Our resources are designed for caregivers and clinicians. We do not knowingly collect personal information from children under 13 years of age without verifiable parental consent, in accordance with COPPA. If you believe a child provided personal data to us without consent, please contact us at [email protected] so we can delete it.

Cookies and Similar Technologies

We use cookies and similar technologies for site functionality, security, audience measurement, and service improvement.

  • Strictly necessary cookies: essential for core features and security.
  • Analytics/performance cookies: help us understand usage and improve content.
  • Preference cookies: remember your settings.

Where required, we obtain consent before setting non-essential cookies. You can manage cookies via your browser settings and any on-site controls that may be provided. Disabling cookies may affect certain features.

International Data Transfers

If you are located in the EEA or UK, your personal data may be transferred to, and processed in, the United States. We implement appropriate safeguards for such transfers, including Standard Contractual Clauses or other lawful transfer mechanisms, and apply supplementary measures as needed. You may contact us for information about these safeguards.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described, including compliance with legal, accounting, or reporting obligations. Criteria for retention include the nature of the data, potential risk from unauthorized use or disclosure, the purposes of processing, and applicable legal requirements. When data are no longer needed, we delete or de-identify them in a secure manner.

Security Measures

We employ administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit where appropriate, access controls, least-privilege practices, and vendor due diligence. No method of transmission or storage is completely secure; we continuously improve our protections commensurate with risk.

Sharing and Disclosure

  • Service providers: hosting, security, analytics, communications, and customer support vendors acting under instructions and subject to confidentiality obligations.
  • Legal and compliance: disclosures required by law, regulation, legal process, or to protect rights, safety, and security.
  • Business transfers: in connection with a merger, acquisition, reorganization, or asset sale, subject to continued protections consistent with this Notice.

We do not sell or share personal information for cross-context behavioral advertising as defined by the CCPA/CPRA. If this policy changes, we will provide required notices and a method to opt out.

Your Privacy Rights

Rights under the GDPR (EEA/UK)

  • Access: obtain confirmation and a copy of your personal data.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion in specified circumstances.
  • Restriction: limit processing in certain cases.
  • Portability: receive data in a structured, commonly used format and transmit it to another controller where technically feasible.
  • Objection: object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent: at any time where processing is based on consent.
  • Complaint: lodge a complaint with a supervisory authority in your EEA member state or the UK.

U.S. State Privacy Rights

Depending on your state of residence (e.g., California, Colorado, Connecticut, Virginia, Utah), you may have rights to access, correct, delete, and obtain a copy of your personal information, and to opt out of certain processing, including targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects. We currently do not sell or share personal information for cross-context behavioral advertising.

Exercising Your Rights

To exercise your rights or submit an appeal of a decision, contact us at [email protected]. We may request information to verify your identity and residency. Authorized agents may submit requests where permitted by law, subject to verification. We will respond within the timelines required by applicable law.

Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects about you.

Do Not Track and Global Privacy Control

Our services do not currently respond to browser-initiated Do Not Track signals. Where required by law, we will treat a valid Global Privacy Control signal as a request to opt out of selling or sharing personal information, to the extent applicable.

HIPAA Clarification

KidsForce Rx is not a covered entity or business associate as defined by HIPAA in the ordinary course of offering this website. Do not submit protected health information via our site. If we incidentally receive such information, we will handle it securely and delete it as appropriate.

California Notice at Collection

We collect identifiers (e.g., IP address, email), internet activity (e.g., browsing on our site), and inferences from usage for the purposes described above. We retain data for the periods outlined in the Data Retention section. We do not sell or share personal information as defined by the CCPA/CPRA and do not collect sensitive personal information for the purpose of inferring characteristics.

Changes to This Notice

We may update this Notice to reflect changes in our practices or legal requirements. Material changes will be indicated by updating the effective date and, where appropriate, by providing additional notice. Your continued use of our services after changes become effective constitutes acknowledgment of the updated Notice.

Contact Information

For any questions, requests, or complaints regarding this Data Protection Notice or our privacy practices, please contact:

KidsForce Rx
Attn: Privacy Contact (Nerissa Halbrook)
1300 W Sunset Rd
Henderson, NV 89014
United States
Email: [email protected]

Effective date: 2025-09-15

0 Comments

Write a comment