Privacy Policy
The Force for Health Network ("FFH," "we," "us," "our") operates a community activation platform that brings together healthcare, education, workforce, and community partners around prevention and human thriving. This Privacy Policy explains what we collect, why we collect it, how we protect it, and what rights you have over it.
1. Information We Collect
1.1 Information You Provide
When you create an account, participate in a program, or contact us, you may provide information such as your name, email address, role (participant, educator, clinician, chamber partner), organizational affiliation, and demographic information that helps us deliver programs appropriate to your community. If you voluntarily participate in Live It Trackers or health-related programs, you may provide health information such as pain levels, weight, treatment logs, medication reactions, nutrition entries, physical activity, and screen-time tracking.
1.2 Information Collected Automatically
We collect information that your device provides automatically, including IP address, browser type, operating system, referring URL, page interactions, and timestamps. We use this information to operate, secure, and improve the platform.
1.3 Information from Third Parties
With your consent, we may receive information from integrated platforms such as your school's learning management system, your employer's wellness program, your Chamber of Commerce, or a CMS Blue Button 2.0 data request that you personally authorize.
2. How We Use Information
- To deliver the programs, games, tools, and educational content you request.
- To personalize your experience and track your progress, coins, and achievements.
- To generate aggregated, de-identified insights for research, policy, and community improvement.
- To communicate with you about platform updates, program opportunities, and service announcements.
- To maintain the security, integrity, and compliance of the platform.
- To comply with legal obligations.
3. Categories of Data
3.1 Protected Health Information (PHI)
Health information you enter into Live It Trackers or any HIPAA-covered FFH tool is treated as PHI and is subject to our HIPAA Policy and to Business Associate Agreements with vendors that process it. PHI is encrypted at rest (AES-256) and in transit (TLS 1.2+), is never cached in browser local storage when you are authenticated, and generates an audit log entry on every access.
3.2 Educational Records (FERPA)
Student records โ including IDEAS Challenge projects, progress, and assessments โ are treated as FERPA-protected educational records. We do not disclose these records without written consent from the eligible student or, where applicable, the parent or guardian.
3.3 Children's Information (COPPA)
For users under the age of 13, we require verifiable parental consent before collecting personal information, or verified school consent where the child is using FFH as part of a school-authorized program.
4. How We Share Information
We do not sell personal information. We share information only in the following ways:
- With service providers bound by contract and, where applicable, Business Associate Agreements.
- With educational or healthcare institutions that you or your guardian have authorized.
- To comply with legal process or protect rights, safety, and security.
- In aggregated, de-identified form for research and public health purposes.
5. Your Rights
You have the right to access, correct, delete, export, or restrict processing of your personal information, subject to applicable legal limits. California residents have specific rights under the California Consumer Privacy Act (CCPA/CPRA). European Economic Area residents have rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with a supervisory authority. To exercise any right, contact privacy@forceforhealth.com.
6. Security
We implement administrative, technical, and physical safeguards designed to protect your information, including encryption at rest and in transit, JWT-authenticated sessions, row-level database security, audit logging on sensitive data access, 30-minute inactivity session timeouts on PHI tools, and vendor Business Associate Agreements in place or being executed.
7. Retention
We retain personal information only as long as necessary for the purposes described in this Policy or as required by law. You may request deletion of your account and associated personal information at any time.
8. International Transfers
FFH operates primarily in the United States. If you access the platform from outside the United States, your information may be transferred to and processed in the United States under appropriate safeguards.
9. Children's Privacy
We do not knowingly collect personal information from children under 13 without verifiable parental consent or school authorization. See our FERPA & COPPA Policy for details.
10. Changes to This Policy
We will post material changes to this Policy on this page and update the effective date. Continued use of the platform after changes become effective constitutes acceptance of the revised Policy.
11. Contact Us
Questions or concerns about this Policy, or to exercise your rights, contact privacy@forceforhealth.com.