J & R Health Insurance LLC (“we” or “us”) operates this website jrhealthins.org (the “Site”) and provides services that may collect your personal information. This Privacy Policy explains what information we collect, how we use it, and your rights under applicable laws (GDPR, CCPA/CPRA, CalOPPA). Please read it carefully.
1. Information We Collect. We collect personal information you voluntarily provide when using our Site or services. For example, when you submit a contact or intake form, you may give us your name, email address, phone number, and any message content. We also automatically collect certain data through website analytics. We may choose in the future to integrate Google Analytics or Meta (Facebook) Pixel, which set cookies and process usage data. Such tools may transfer data outside the EU (see Section 6). We will obtain consent before enabling these.*) Our Site also may embed videos from YouTube. We use YouTube’s “privacy-enhanced” (nocookie) embed mode, but note: playing an embedded video may still store functional cookies on your device (per YouTube/Google policy).
2. How We Use Your Information. We process collected data for specified purposes, including:
- Responding to inquiries: To handle contact form requests and communicate with you. Lawful basis: contractual necessity or your consent if you opted in.
- Marketing: We may email newsletters or offers only with your consent. You can unsubscribe at any time.
- Analytics and site improvement: To analyze trends, administer the Site, and enhance user experience. Lawful basis: legitimate interest (improving our service) or consent (for non-necessary cookies).
- Legal compliance and fraud prevention: To comply with laws (e.g. tax, anti-fraud) and protect rights. Lawful basis: legal obligation or legitimate interest.
We will not sell your personal information. We do not engage in “data brokering” or advertising sales. (California residents: if your data were “sold” or “shared,” you have a right to opt out via our “Do Not Sell or Share My Personal Information” link.)
3. Data Sharing and Third Parties. We may share information with third parties only as described here:
- Service Providers: We use trusted vendors to operate our Site (e.g., hosting providers, email services, CRM). We share only necessary data under Data Processing Agreements (DPAs) that require them to protect your data.
- Analytics/Advertising Partners: Plausible Analytics processes data in the EU (no personal data). If we use Google Analytics/Meta Pixel, these share data with Google/Meta in the US. We rely on EU Commission Standard Contractual Clauses (SCCs) and Google’s Data Processing Amendment to safeguard transfers.
- Legal Disclosures: We may disclose information if required by law or to protect rights (e.g. responding to a subpoena).
4. International Data Transfers. Our systems are hosted in the EU/US with our service providers. Personal data (e.g. form submissions) transferred out of the EU/UK or California will rely on appropriate safeguards: for example, Standard Contractual Clauses approved by the European Commission or UK Information Commissioner. Data from California and beyond may likewise be transferred to the US under CCPA/CPRA as a service provider transfer, subject to Cal. Business & Professions Code § 1798.140 (businesses must do so under contract).
5. Data Retention. We retain personal data only as long as necessary for each purpose. For example, contact form submissions are kept for up to [X months/years] (or until you request deletion). Analytics data in Plausible is automatically aggregated and deleted after a short period (per Plausible’s policy).
6. Your Legal Rights.
- Access & Portability: You have the right to request access to the personal data we hold about you, and to receive it in a portable format.
- Rectification/Correction: You may request correction of inaccurate or incomplete data.
- Erasure (“Right to be Forgotten”): You may request deletion of your data (subject to legal retention requirements).
- Restriction of Processing: You may request that we limit processing of your data.
- Objection: You have the right to object to processing based on legitimate interests or marketing. We will stop such processing unless we demonstrate compelling legitimate grounds.
- Withdraw Consent: If we rely on your consent (e.g., for marketing emails or analytics cookies), you can withdraw it at any time. Withdrawal is as easy as granting it.
- Complaint: You may lodge a complaint with a supervisory authority (e.g. ICO in the UK, or appropriate EU/US/CA data protection authority) if you believe we violated your rights.
(California-specific rights – CCPA/CPRA): If you are a California resident, you have additional rights: to know, delete, and correct your personal information, to limit use of sensitive info, and to opt out of sale/sharing. We do not sell your data; however, we provide a “Do Not Sell or Share My Personal Information” link on our Site so you can assert your right to opt-out of any sale or sharing as required. We do not discriminate for exercising any privacy rights. Our privacy policy includes information on how to submit requests (email us at info@jrhealthins.org). We will respond as required by law.
7. Cookies and Tracking. We use cookies and similar technologies (e.g. local storage) to distinguish you from other users. We use:
- Essential cookies: necessary for site security and functionality (no consent needed).
- Analytics cookies: We may enable Google Analytics or Plausible Analytics.
- Advertising cookies: We may enable Google Tag Manager or Facebook Pixel, these are “marketing cookies” requiring consent under GDPR/ePrivacy. Before using such cookies, we will obtain explicit opt-in consent via a cookie banner that lets you accept or reject categories of cookies. We will document and store all cookie consents, allow site access even if you refuse cookies, and make it easy to withdraw consent.
8. Security. We implement appropriate technical and organizational measures (encryption, access controls, regular security reviews) to protect data. However, no internet system is completely secure, so we cannot guarantee absolute security. In the event of a breach involving your data, we will follow applicable notification laws.
9. Minors. Our Site and services are for users over 16. We do not knowingly collect personal information from children under 13. Parents/guardians concerned about information from a child should contact us immediately; we will delete any such data per COPPA (Children’s Online Privacy Protection Act) requirements.
10. Changes & Contact. We may update this Privacy Policy (e.g. after new laws or changes to our services). The “Effective Date” above shows when it was last revised. We will notify users of material changes (e.g. via email or site banner). For questions or privacy concerns, contact us by email, info@jrhealthins.org, or phone, (253) 528-8805. You may also review the Office of the Attorney General of CA FAQs or ICO resources for more information on your rights.
CalOPPA Notice (California): As required by CalOPPA, our Privacy Policy link is labeled “Privacy” in the website footer. It clearly discloses the categories of information we collect, with whom it is shared, and our effective date. We respect “Do Not Track” signals: currently, we do not track users across websites.
DMCA (Copyright Infringement): If you believe content on our Site infringes your copyright, contact our Copyright Agent (see Terms of Service below) with a notice as specified in 17 U.S.C. §512(c)(3).
Sources: This policy aligns with GDPR Article 13 (transparency requirements), ICO guidance on rights, CPRA/CCPA FAQs, CalOPPA rules, and resources like the Plausible data policy.