A New Era of Behavioral Health Support for Your Workforce. Learn about our New Digital Content

Privacy Notice

Introduction and Scope
This Privacy Notice (“Notice”) describes how the Rethink Benefits and RethinkCare divisions of Rethink Autism, Inc. (“Rethink,” “we,” “us,” or “our”) collect, use, disclose, secure, and eventually dispose of (collectively “process”) your personal information. Personal information is any information that does, or could, identify you.

Rethink values the privacy of individuals who use our websites, mobile apps, technology platforms, and related services. When you access these services, you trust us with your personal data, and we are committed to keeping that trust and being transparent about our privacy practices.  This includes This includes Consultants (“Consultants”), who are third-party Consultants, Coaches (“Coaches”), who are third-party Coaches, and Caregivers (“Caregiver”), who are third-party Caregivers, or applicants seeking to become a Consultant, Coach or Caregiver (“ Applicants”).

This Notice applies to personal information collected on:

  • our websites (including rethinkbenefits.com/eb/ and rethinkcare.com),
  • our mobile apps (Rethink Benefits and RethinkCare),
  • the associated technologies and communications media,
  • RethinkCare application, websites, and technology platform, and
  • any offline interactions with you

(collectively, the “services”).
Our websites include public and subscription-only sections, and our mobile apps and platform components are part of subscription-only services.

The Privacy Notice explains how we collect, use, and share information from individuals who use the services. Users covered by this Notice include, without limitation:

  • individuals accessing the services to learn about or use the offerings;
  • employees of corporate customers of Rethink or of corporate customers of Rethink channel partners;
  • parents using the services on behalf of or for the benefit of their children;
  • members of a child’s “support team” such as family members or teachers who are invited to participate;
  • visitors to public websites;
  • Consultants, coaches or caregivers who access relevant components of the services;
  • applicants seeking to become a consultant, coach or caregiver; and
  • anyone else who accesses the services.

For parents and legal guardians, the definition of “your personal information” includes your child’s personal information if you have entered it into the services. A “primary user account holder” is the employee of a corporate customer of Rethink, or a corporate customer of a Rethink channel partner, who enrolls in the services.

Rethink channel partners are intermediaries selected or approved by your organization through which you may access the services. This Notice does not cover the personal information processing of channel partners. If you are uncertain whether you access the services through a channel partner, please consult your organization.

RethinkCare currently provides access to digital tools, content, and related services across multiple subscription-based libraries and solution areas, including those focused on family support (formerly known as ‘Rethink Benefits at Home;’ ‘Parental Success’), professional and workplace development (formerly known as ‘Rethink Benefits at Work’; Professional Resilience), and personal wellbeing. These libraries and offerings may be renamed, expanded, consolidated, or otherwise modified over time.

Rethink is the data controller in relation to the services. Rethink Benefits and RethinkCare are part of the Rethink group of businesses. This Notice applies only to the Rethink Benefits and RethinkCare divisions and applies to uses of the RethinkCare platform as part of the services.

This Notice is an important part of the agreement between you and RethinkCare. Any capitalized terms not defined in this Notice have the meaning given to them in the agreement or in other referenced policies.

Changes to this Privacy Notice

We may update this Privacy Notice from time to time at our sole discretion. Any changes will be posted in the services, including on applicable platforms, indicating the date on which the Notice was last updated and posted on the footer. Material changes will be communicated to you through an appropriate channel (for example, via a notice in our services). Any changes will be effective upon the date of posting unless explicitly stated otherwise.

As long as you use the services, you are agreeing to this Privacy Notice and any updates made to it. If you disagree with an updated Privacy Notice, you may terminate this agreement with immediate effect by discontinuing your use of the services. Your continued use of the services following the effective date of any modified terms indicates your acceptance of the modified Notice.

Personal Information We Collect

We collect personal information from you and about you in several ways, including information you provide directly, information provided by your employer or channel partner, information provided by other users, information collected through your use of the services, information collected automatically through technologies such as cookies, and information collected from third parties or third-party services. This includes information collected directly from Users that sign up for an account, apply to become a Consultant, Coach, Caregiver, or contact us through the Platform. When we collect personal information directly from you, you will know the details of that information.

  1. Information You Provide Directly for All Subscription Environments

Personal information you may provide includes:

Login credentials (username and password).

Name, job role, e-mail address, telephone number; country, state, and city of location.

Sessions and courses you “like.”

Ratings and feedback about the services.

Information provided in surveys, assessments, or questionnaires.

Information you choose to provide in surveys, assessments, or questionnaires.

Any personal details you reveal through free-form use of the services (e.g., discussing activities during a consultation, responding to survey questions, Training module information, such as quiz scores or uploading photos/documents).

There is information you provide only if you register for specific areas:

For Coaching and Consultations and Navigator, the information collected includes: Your schedule of appointments with consultants.

Information you choose to provide when creating a profile for your child (optional), including:

name, date of birth, school grade, photo, developmental disabilities or concerns.

Information you choose to provide about your child in written, phone, or video consultations.

  1. Public Websites

You may provide personal information through:

“Contact Us” or similar forms,

Chat features,

“Email Us” or comparable features.

Rethink Platform User Information

When using the services, you may provide:

Registration and profile information (name, email address, password, phone number).

Profile photos.

User ratings and feedback (including ratings of consultants, coaches, caregivers, or service providers).

Testimonials, feedback, or other submissions.

Communications through audio, video, or chat tools.

Other information not specifically listed here but provided by you.

  1. Consultants, Coaches, Caregivers, and Applicants

In addition to the above, personal information may include:

Name, location, business contact information.

Professional certifications, experience, licensing details.

Date of birth, Social Security number or other government ID, government-issued ID, insurance information, and other documentation handled through third-party providers.

Profile photos.

Payment-related information (e.g., bank routing numbers, tax information) for those who receive payments.

User ratings, feedback, and survey responses.

User Comments submitted to areas viewable by users or personnel.

  1. Information We Receive from Employers or Channel Partners

This may include:

Your name and email address.

Additional information selected by your employer for service usage reporting (e.g., work location, department).

Your employee number or similar unique identifier.

Channel partner processing is not covered by this Notice. If unsure whether you access the services via a channel partner, consult your organization.

  1. Information Collected Through Your Use of the Services

Usage Tracking

We collect information about:

Time spent interacting with subscription-only content.

Which sessions and courses you complete.

Routine monitoring and recording of usage for security and user support.

Wearable or Connected Device Data

If you connect a device or product integrated with the services, we may receive:

Fitness data (e.g., steps),

Heart rate, blood oxygen level, sleep activity,

Device identifiers (serial number, Bluetooth address, UPC, etc.).

Data from Third-Party Services

If you choose to share information from third-party services (e.g., Apple HealthKit, Fitbit):

It is used to provide services such as recommending content.

Such recommendations are not medical advice and not for diagnostic purposes.

We do not use this data for marketing or advertising.

We do not share this data with third parties.

  1. Information Collected Automatically Through Technology

We use cookies and similar technologies to recognize your device and collect information such as:

Pages visited, features used, and duration of visits.

Navigation patterns and login facilitation.

Device information including IP address, browser type, operating system version, manufacturer, application installations, device identifiers.

Crash and error event data.

Communication metadata (e.g., date and time of calls, messages, content sent through the platform).

Cookies and Similar Technologies Include:

Cookies (browser cookies) — may be refused by adjusting browser settings; refusal may limit access to parts of the services.

Flash cookies — store preferences and navigation information; managed separately from browser cookies.

Web beacons / pixel tags / clear GIFs — used to count visitors, analyze popularity of content, verify system integrity, and track engagement.

Third-party providers may also use these technologies for the purposes described.

  1. Information Collected from Third Parties

We may collect personal information from:

Publicly available sources.

Social media platforms (e.g., SSO via Google or Apple ID) where you permit connection.

Third-party websites or applications you use to access or interact with the services (e.g., Zoom, Indeed, LinkedIn), including information collected or provided by third-party data providers.

Other users, including updates from calls, emails, or sessions.

We do not control third-party information collection. Their use of your personal information is governed by their own terms and privacy policies.

How We Use Your Personal Information

We will never sell your personal information.

We use the personal information we collect from you and from other sources to provide the services and for other purposes described in this Privacy Notice. These purposes include:

  1. To Provide, Operate, and Improve the Services

We use personal information:

to provide our services, including managing log-ins and maintaining security and confidentiality of data contained in the services;

to schedule and hold consultations with consultants, including behavioral, neurodiversity, caregiving, or coaching interactions as applicable;

to connect users with coaches, caregivers, consultants, or other users;

to make connection recommendations and enable communication between users through audio, video, or chat features;

to communicate essential service information;

to provide customer support;

to monitor, maintain, and improve the quality and integrity of the services and platform;

to monitor compliance with our Terms of Use;

to personalize the user experience;

to recommend content;

to respond to your requests or questions, including through forms and chat features.

  1. For Research, Development, and Service Improvement

We use personal information:

to analyze and improve the services and user experience, including identifying which components you find useful or difficult to use;

to develop and improve products and services;

to publish and share information and content to engage with users and potential users;

to build, onboard, and support a diverse community of service providers such as consultants, coaches, or caregivers.

Usually, the information used for these purposes does not directly identify you as an individual.

  1. For Marketing Purposes

Where permitted by applicable law, we may:

send marketing messages for products or services we believe may interest you;

communicate about our services with users and potential users;

measure the effectiveness of our marketing communications.

You may opt out at any time (see “Your Rights and Choices”).

  1. To Create Anonymous, Aggregated, or De-identified Data

We may create anonymous, aggregated, or de-identified data from personal information by removing information that makes the data personally identifiable. Such data may be used for any lawful purpose, including research and service improvement. De-identified information cannot reasonably be reconnected to an individual.

  1. For Compliance, Fraud Prevention, and Safety

We may use personal information:

to protect the rights, property, or safety of us, users, or the public;

to investigate misuse, enforce agreements, or ensure compliance with applicable policies.

  1. To Comply with Law

We may use personal information to comply with legal requirements, regulations, or processes, including civil or criminal subpoenas, court orders, or other compulsory disclosures.

  1. With Your Consent

We will use your personal information whenever you consent to such use. You may withdraw consent at any time (see “Your Rights and Choices”).

  1. Lawfulness of Processing (GDPR and Other Jurisdictions Requiring Legal Bases)

Where required by applicable law, such as the EU/EEA, UK, or China, the legal basis for processing your personal data depends on the purpose:

Purpose of processingLegal basis
To provide our servicesYour consent.
To respond to your requests or questions (on our public services)In order to take steps at your request prior to entering into a contract.
Market our services to youYour consent.
To help us improve our servicesOur legitimate interests in improving our services and online media.

 

Disclosure of Your Personal Information

Your personal information is only disclosed or shared where authorized by You or the law. Who we disclose your personal information to depends on the specific items of information and the purposes for which we use them. We may share or disclose personal information as needed to provide the services and as otherwise described in this Privacy Notice. Your personal information may be disclosed to the following categories of recipients:

  1. Employees and Contractors

We may disclose personal information to Rethink employees and contractors who have a role requiring access to your information (“need to know”) to provide the Services. These personnel are bound by employment or contractor terms requiring confidentiality and security and are trained in applicable laws governing confidentiality of personal health information.

  1. Service Providers (“Processors”)

We use third-party service providers to perform tasks on our behalf, such as hosting services, secure video calling, engineering, candidate recruitment, payment processing, research, marketing, and other support functions.

Service providers:

  • process your information only on our behalf and according to our instructions,
  • are contractually bound to protect your information, and
  • are prohibited from using it for their own purposes.
  1. Professional Advisors

We may disclose personal information to professional advisors such as lawyers, bankers, auditors, and insurers where necessary in the course of the professional services they provide to us.

  1. Other Third Parties (De-identified Information)

We may disclose de-identified information to third parties, including business partners and research organizations. De-identified information has been stripped of attributes that tie it to a particular individual and cannot reasonably be reconnected to that individual.

  1. Service Usage Reporting

Channel Partners

We may provide:

  • Aggregate, non-personal utilization data to channel partners.
  • Identifiable content usage information (e.g., courses started or completed, login frequency) for the purpose of administering employer programs.

For any educational tools, identifiable usage information is limited to confirmation that you completed a course—not the specific content you viewed. We do not disclose your or your child’s profile information or consultation interactions.

Employers

We may provide:

  • Aggregate, non-personal utilization data to your employer.
  • We may disclose identifiable information about the number of courses you completed (but not specific content) for employer incentive program administration.
  1. Disclosures
    1. Personal information collected in coaching/consultation sessions may be disclosed voluntarily by You to other authorized users of the services, as the primary user account holder determines who is authorized and their level of access.
    2. Employers providing RethinkCare as a benefit are not users of the services and do not receive your personal information except as described above under employer reporting.
  1. Information We Have Disclosed to Service Providers in the Last 12 Months

We have disclosed the following categories of personal information to service providers:

  • Identifiers such as name, email address, username, and IP address.
  • Personal information defined under certain US state laws, including address and telephone number.
  • Internet activity and usage information from websites and applications.
  • Protected classification characteristics and special categories of data (e.g., gender, health information).
  1. Corporate Transactions

Personal information may be disclosed or transferred to third parties as part of any:

  • merger,
  • acquisition,
  • financing,
  • sale of assets, or
  • similar corporate event.
  1. Legal and Compliance-Related Disclosures

We may disclose personal information to:

  • government agencies,
  • law enforcement,
  • courts,
  • other authorities, or
  • third parties (including sponsors),

when required to comply with applicable law, legal obligations, court orders, or other legal processes.

Information provided to consultants may not be protected by physician-patient privilege.

  1. Safety and Vital Interests

If we reasonably believe that the safety or vital interests of any individual are at risk, we will disclose personal information to relevant parties as necessary to assist the individual.

  1. Protection of Business Interests

Where permitted by applicable law, we may disclose personal information to our professional advisors or other qualified parties when reasonably necessary to protect our essential business interests.

 

How do Users share information with one another?

The RethinkCare Platform offers opportunities for connection between Users.  By accessing Services you may share information with other Users, including: Expert Consultants, Coaches & Caregivers. The Platform makes Consultants, Coaches’ and Caregivers’ profile information – including name, photo, quotes, videos, ratings, and professional details – available to other Users. Users. When Users communicate using the audio, video, or chat features of the Platform, the User’s name and photo are displayed to the Consultant, Coach, or other User(s). The User may also choose to share additional personal information using the audio, video, or chat features of the Platform.  Additionally, when you participate in a program together with other participants, your personal information may be visible to other participants.

 

Information security

We employ technical, physical, and administrative security measures appropriate to the categories of personal information processed in our services. These measures include, for example: encryption at rest and in transit, roles-based access, firewalls, and anti-virus software. For more details of our practices, please consult our Information Security Standards statement.

We protect information about individual’s diagnoses, treatments, and outcomes with particular care. Rethink is HITRUST CSF certified. HITRUST CSF is a security and privacy framework that covers, among others, HIPAA and National Institute for Standards and Technology (NIST) standards.

No matter how carefully we safeguard your information, it is unfortunately not possible to guarantee that it will never be accidentally or illegally breached. We also cannot protect against any misuse, loss, or alteration of any user-editable content. You also have an important role in in protecting Personal Information. You should not share your username and password with anyone, and you should not re-use passwords across more than one site. If you have any reason to believe that your username or password has been compromised, please contact us [email protected].

 

Data retention

We will retain your personal information as long as necessary to fulfill the purposes for which it was collected, and to satisfy legal, accounting, and reporting obligations, or to resolve disputes or enforce our Terms of Use.

Your rights are described below to request deletion of your data outside of our normal data retention schedule and to withdraw your previously given consent to our processing of your data.

 

International transfer

Rethink is based in the United States. Your personal information is stored on our systems in the US.

If you live in the European Union, European Economic Area, or UK, note that the European Commission has not issued an unlimited adequacy decision for the US.

As set out in this Notice, Rethink strives to protect your data and your rights regardless of any international transfer.

We obtain your explicit consent to transfer your information to the US and cannot provide our services without that consent.

Should we disclose your personal information to a Rethink service provider (see the Section on Service Providers in this Notice) located outside the US, we will put in place appropriate legal safeguards (for example, standard contractual clauses) that are designed to protect your personal information in the new jurisdiction.

 

Your Rights and Choices

US and international laws give you various rights over your personal information and, where applicable, your child’s personal information. These may include the right to:

  • access personal information held about you;
  • correct inaccurate or out-of-date personal information;
  • request deletion of your personal information;
  • restrict processing of your personal information;
  • data portability: receive your personal information in a readily usable format;
  • object to processing when the legal basis is our legitimate interests.

Notice of withdrawal of consent and all requests to exercise privacy rights should be addressed using the contact information provided in Section below “Options for Limiting the Use of Your Information” of this Notice.

When a Consultant, Coach, or Caregiver terminates their account, we remove the Consultant’s or Coach’s profile from the Platform. However, Users will continue to have access to their communications with former Consultant, Coaches, and Caregivers.

If you believe your privacy rights have been infringed, please contact us so we may attempt to resolve the issue. If you are an EU/EEA/UK resident, you have the right to lodge a complaint with your EU/EEA supervisory authority or, in the UK, with the ICO.

 

Marketing Communications

  • You may opt out of our marketing communications at any time, including through “unsubscribe” links in emails or by replying “STOP” to text messages.
  • Where required by local law, we will obtain your prior consent before sending marketing communications. You may withdraw that consent at any time using opt-out mechanisms in marketing messages or by contacting us using the information below.
  • If you are a user of subscription-only services, you may continue to receive service-related communications even after opting out of marketing. These service communications contain important information about the services you use.

 

Options for Limiting the Use of Your Information

You may use the following options to change or limit how your information is used:

  • Profile Information: You may review, request an update, or request the deletion of certain information in your profile.
  • Communications Preferences:
    • You may opt out of receiving text messages by replying “STOP” or by contacting us.
    • You may opt out of marketing-related emails by using the unsubscribe instructions or by contacting us.

 

Do Not Track

We do not currently respond to “Do Not Track” signals from web browsers. To learn more about “Do Not Track,” please visit:
http://www.allaboutdnt.com

 

Account Deletion Requests

Consultants, Coaches and Caregivers 

When a Consultant, Coach or Caregiver terminates their account, we remove the profile from the platform. However, users will continue to have access to their communications with former Consultants, Coaches, or Caregivers.

Other Users

When a User who is not a Consultant, Coach or Caregiver terminates their account, we delete the User’s profile. For compliance purposes, we will retain any communications between the User and any Consultants, Coaches, or Caregivers.

All Users

We retain personal information after an account is canceled to the extent reasonably necessary to:

  • comply with legal obligations;
  • meet payment or financial requirements;
  • satisfy regulatory requirements;
  • respond to law-enforcement requests;
  • resolve disputes;
  • maintain security;
  • prevent fraud and abuse; and
  • enforce the Terms of Service.

We also retain de-identified information.

 

Other Sites and Services

The RethinkCare Mobile Apps, websites, other technologies and other communications may be accessible through or contain links to other websites or platforms (e.g., Zoom, YouTube) operated by third parties. We also may use third-party websites (e.g., LinkedIn, Indeed, Handshake, Stripe) to recruit Consultant or Coach candidates, process applications, pay Consultants and Coaches, process payments, or otherwise operate our services.  These links are not an endorsement of or representation of any third party that we are affiliated with. We do not control third-party websites and are not responsible for their actions. Other websites and services follow different rules regarding collecting, using, and sharing your personal information. Any exchange of data or other interaction between a User and any third-party provider is solely between the User and that third-party provider and is governed by their terms and conditions.  We encourage Users to read the privacy policies of the other websites and online services they use.

To access, correct, update, or delete certain of your personal information, click on the edit button (pen symbol) in the app. Alternatively, you may email us [email protected] to request access to, correct, or delete certain personal information you provided us. If you close your RethinkCare account, we will remove your name, contact, and identifiable information from our publicly viewable database.

Artificial Intelligence

At RethinkCare, we are committed to ensuring that our AI-driven tools and technology are developed and deployed responsibly, with a focus on transparency and security. Transcription services are being used during consultations and coaching sessions and leveraged to generate session notes for Consultants and Coaches to review and approve/edit. RethinkCare also leverages AI to support “Guided Journey’s” within the platform to quickly connect members to the right content, resources, or tools. See our AI Code of Ethics.

 

Children’s Privacy

RethinkCare is not intended for anyone under thirteen (13) years of age, and the 13-18 years old must use the product under direct parental supervision.  We do not request any information regarding our users’ age, and we do not knowingly collect personal information from children under thirteen (13) years of age. If we learn we have collected or received personal information from a child under thirteen (13) years of age without verification of parental consent, we will delete that information. If you are a parent or guardian of a child from whom you believe we have collected personal information in a manner prohibited by law, please contact us at [email protected].

 

Servers Located in the United States

We are headquartered in the United States, and the servers and other technology supporting RethinkCare operations are located in the United States.  If you submit any personal information to RethinkCare (for example, if you provide your email to sign up for an email newsletter), you understand that you are voluntarily consenting to the transmission of such information to an organization in the United States and your information will be stored and processed in the United States.   

 

Your California Privacy Rights

California residents have the rights listed below under the CCPA. However, these rights are not absolute, and in some instances, we may decline your request as permitted by law.

Information. You can request information about how we have collected, used, and shared your Personal Information during the past 12 months. We have made this information available to California residents without having to request it by including it in this notice in the above chart.

Access. You can request a copy of the Personal Information we collected about you during the past 12 months.

Deletion. You can ask us to delete the Personal Information we collected from you.

Opt-out of sales. You can opt out of any sale of your Personal Information.

Nondiscrimination. You are entitled to exercise the rights described above free from discrimination as prohibited by the CCPA. Please note that the CCPA limits these rights by, for example, prohibiting us from providing certain sensitive information in response to an access request and limiting the circumstances in which we must comply with a deletion request. If we deny your request, we will communicate our decision to you. You are entitled to exercise the rights described above free from discrimination.

 

How to Submit a Request

To request access to or deletion of personal information, email [email protected].

 

Identity Verification

The CCPA requires us to verify the identity of the individual submitting a request to access or delete personal information before providing a substantive response to the request.

 

Authorized Agents

California residents can empower an “authorized agent” to submit requests on their behalf. We will require the authorized agent to have a written authorization confirming that authority.

 

Contact us

Data Protection Officer: Click to send an email [email protected] or (800) 708-2154

Rethink Autism, Inc.

49 West 27th Street, 8th Floor

New York, NY 10001

USA

EU Representative:

MyEDPO Ltd,

Unit 3d North Point House,

North Point Business Park,

New Mallow Road,

Cork, Ireland

Click to send an email [email protected] or +44 203 870 3376.

1. Introduction

This Privacy Notice (“Notice”) describes how the Rethink Benefits and RethinkCare divisions of Rethink Autism, Inc. (“Rethink”, “we”, “us”, “our”) collects, uses, discloses, secures, and eventually disposes of (collectively “processes”) your personal information. Personal information is any information that does, or could, identify you.

This Notice applies to personal information collected on our websites (rethinkbenefits.com/eb/ and rethinkcare.com), mobile apps (Rethink Benefits and RethinkCare), their associated technologies and communications media, and in the course of any offline contact with you (collectively the “services”). Our websites have public and subscription-only sections. Our mobile apps are part of our subscription-only services.

Our services may contain links to external websites. This Notice does not cover those sites.

In this Notice, “you” refers to anyone about whom we process personal information. You will usually be an employee of a corporate customer of Rethink or of a corporate customer of a channel partner of Rethink; a parent of a child in whose interests the services are used; a member of a child’s “support team” (for example, a family member or teacher) who is invited to participate in the services; or a visitor to our public websites. For parents and legal guardians, “your personal information” includes your child’s personal information. In this Notice, “primary user account holder” means the employee of a corporate customer of Rethink, or of a corporate customer of a channel partner of Rethink, who enrolls for the services.

Rethink channel partners are intermediaries, selected and/or approved by your organization, through which you may access our services. This Notice does not cover the personal information processing of our channel partners. If you are uncertain whether you access our services through a channel partner, please consult your organization.

Rethink provides online tools, content, and related services in three distinct subscription-only environments: (1) “Parental Success” (formerly known as “Rethink Benefits At Home”) supports families of children with learning, social, or behavioral challenges; (2) “Professional Resilience” (formerly known as “Rethink Benefits At Work”) helps employers increase neurodiversity inclusion in the workforce, and (3) “Personal Wellbeing” assists employees to increase their mental wellbeing and work performance.

Rethink is the data controller in relation to the services.

Rethink Benefits and RethinkCare are part of the Rethink group of businesses. This Privacy Notice applies only to the Rethink Benefits and RethinkCare divisions.

2. Changes to this Notice

We will update this Notice from time to time and will communicate material changes to you through an appropriate channel (for example, via a notice in our services). The Notice was last updated on Feb 14, 2024.

3. Personal information we collect

3.1 Categories collected

We collect the following categories of personal information:

  • Identifiers such as your name, e-mail address, username, and IP address.
  • Additional personal information defined by certain applicable US state laws: address, telephone number.
  • Protected classification characteristics and EU “special categories of personal data”, such as gender and health information.
  • Biometric information (e.g., sleep and heart rate collected from a wearable device).
  • Commercial information, such as your purchases from us.
  • Internet activity/usage on our websites and applications.
  • Employment-related information, such as your job role or title.

3.2 Categories of sources

We collect the categories of personal information listed above from the following categories of sources:

  • Directly from you, for example when you complete an online form or provide information about you or your child during a Rethink consultation video call or a Parent Discussion Group.
  • From other users of the subscription-only parts of the services, for example if an invited caregiver mentions your child’s progress in acquiring a skill during a consultation.
  • We may receive information about you from your employer or our channel partner, for example your work e-mail address or other identifiers so that we can give you access to the service.
  • From observing your activity on our services, for example via cookies, other standard online technologies, and our routine monitoring and recording of your service usage.
  • When you use a device that is connected to the Internet, such as heart rate monitors, activity trackers, and other devices or wearables that integrate with our services.

3.3 Items of personal information collected

When we collect personal information directly from you, you will know the details of that information.

For Parental Success, it may include:

  • Login credentials (username and password).
  • Name, job role, e-mail address, telephone number; country, state, and city of location.
  • Your schedule of appointments with Rethink behavioral consultants or when you have participated in a Parent Discussion Group.
  • Information you choose to provide if you create a profile for your child, for example your child’s: name, date of birth, school grade, photo, and developmental disabilities and concerns. Providing such information is completely optional and is not essential for you to use the services.
  • Information you choose to provide about your child to Rethink behavioral consultants in the course of a written, phone, or video consultation.
  • Information you choose to provide about your child when participating in a Parent Discussion Group.
  • Information you choose to provide in response to a Rethink survey, assessment or questionnaire.
  • Any details about yourself that you reveal as you use free-form features of the services, for example you might mention your favorite activity with your child during a consultation video call with a Rethink behavioral consultant or include your family in a photograph you upload to the My Files area of the services.

For Professional Resilience, it may include:

  • Login credentials (username and password).
  • Name, job role, e-mail address, telephone number; country, state, and city of location.
  • Your schedule of consultations with Rethink neurodiversity consultants.
  • Any details about yourself that you might reveal during a neurodiversity consultation with a Rethink consultant, for example you could refer to your strengths and challenges as an employee or manager.
  • Information from training modules you take, for example your quiz score after taking a neurodiversity inclusion training module.
  • Information you choose to provide in response to a Rethink survey, assessment or questionnaire.

For Personal Wellbeing, it may include:

  • Login credentials (e-mail and password).
  • Name and country of residence.
  • The sessions and courses that you “like”.
  • Ratings and feedback that you give us about the service.
  • Information you choose to provide in response to a Rethink survey, assessment or questionnaire.

On our public websites, you may provide personal information in “Contact Us” or other forms and via our Chat, “Email Us” or similar features.

We collect personal information from other users of the subscription-only parts of the services only in Parental Success. For example, a support team member may, during a consultation with a Rethink consultant, volunteer information about how you interact with your child. Note that which support team members (for example, a spouse or therapist) are invited to access the services is entirely under the control of the primary user account holder. The primary user account holder also determines their level of access to the services (for example, whether or not they can view consultation session notes).

When we receive information about you from your employer or our channel partner, it may include:

  • Your name and e-mail address.
  • Other information items selected by your employer to assist in the segmentation of service usage reports, for example your work location and department.
  • Your employee number or similar unique identifier.

We collect personal information from observing your activity on our services:

  • We track how you use our subscription-only content, for example how much time you spend interacting with it and which sessions and courses you complete.
  • We routinely monitor and record your usage of our subscription-only services for the purpose of providing service security and effective user support.
  • We use cookies and other standard online technologies in our public and subscription-only services. Cookies allow us to recognize your device. We use them to collect information about your device and how you use our services; for example, which pages you visit and how long you stay on them. Cookies also facilitate, for example, logging into and navigating our services.

When you use a wearable or connected device or product that is integrated with our services, we may receive certain data related to your fitness activity (e.g., number of steps), heart rate, blood oxygen levels, sleep activity (e.g., number of hours of sleep) and similar types of data relating to physiological condition and activity. We may also receive certain information about the wearable or connected device or product such as serial number, Bluetooth address, UPC, or other device- or purchase-related information.

Data from Third Party Services

In connection with your use of the RethinkCare app, you can choose to share with Rethink information from third party services such as Apple HealthKit and Fitbit. The information you choose to send from such third party services is used by Rethink to provide our services such as recommending content to you. However, the content that we recommend should not be considered medical advice and is not intended to be used for diagnostic purposes. In addition, Rethink will not use any of the information that you choose to send us from such third party services for marketing or advertising purposes and will not share the information with any third parties.

4. How we use your personal information

Rethink will never sell your personal information.

Rethink may use your personal information for the following purposes:

  • To provide our services, for example to manage log-ins and maintain the security and confidentiality of data contained in the services; to schedule and hold consultations with our consultants; to communicate essential service information to you; to recommend content to you; to provide customer support; and to monitor compliance with our Terms of Use.
  • Where permitted by applicable law, we may send you marketing messages for Rethink products that we think may interest you (see Section 9 for information about opting out of such messages).
  • To help us improve our services and user experience, for example by identifying which parts of our services you find useful or difficult to use. Usually, the information used for this purpose does not directly identify you as an individual.
  • To respond to your requests or questions, including through forms and chat features.

Lawfulness of processing:

The EU General Data Protection Regulation (GDPR) requires that we provide EU individuals with our legal bases for processing their personal data. A similar requirement applies in some other jurisdictions, for example China and the United Kingdom. Our legal basis depends on the purpose of processing:

Purpose of processingLegal basis
To provide our servicesYour consent.
To respond to your requests or questions (on our public services)In order to take steps at your request prior to entering into a contract.
Market our services to youYour consent.
To help us improve our servicesOur legitimate interests in improving our services and online media.

5. Disclosure of your personal information

Who we disclose your personal information to depends on the specific items of information and the purposes we use them for. Your personal information may be disclosed to the following categories of recipients:

  • Employees and contractors of Rethink: These personnel have roles that require access to your information (a “need to know”). They are bound by employment terms that cover their obligation to keep personal information confidential and secure and have been trained in US law governing confidentiality of personal health information.
  • Service providers (“processors”): We use service providers to perform certain tasks for us, for example hosting our services on a Cloud computing platform or providing secure video calling functionality. Service providers process your data on our behalf and according to our instructions. They are contractually bound to protect your data and are prohibited from using it for their own purposes.
  • Other third parties: We may disclose de-identified information to third parties, for example business partners or research organizations. “De-identified” information is stripped of attributes that tie it to a particular individual and which cannot reasonably be reconnected to that individual.
  • Services usage reports:
    • Our channel partners: We may provide aggregate data on utilization of our services to our channel partners. Such data is non-personal and does not identify you. We may also disclose content usage information in an identifiable form (for example, courses you begin or complete, and how often you log in to the services) to our channel partners so that they can provide services to your employer (for example, administer use-based incentive programs). In the event we disclose any content usage information for Parental Success or Professional Resilience, such information will only disclose that you have completed a Parental Success or Professional Resilience course (as applicable) and will not specify the particular content that you interacted with. Further, to be clear, we do not disclose to our channel partners your or your child’s profile or information related to your interactions with our behavioral or neurodiversity consultants.
    •  
    • Your employer: We may provide aggregate data on utilization of our services to your employer. Such data is non-personal and does not identify you. For Professional Resilience and Personal Wellbeing, we may also disclose to your employer in an identifiable form the number of courses that you have completed (but not the particular content that you interacted with) for the purposes of your employer administering use-based incentive programs.
  • Disclosure information applicable only to specific services:
    • Parental Success: (1) Personal information collected in our Parental Success environment may be disclosed to other authorized users of the services. Authorized users and their level of access to the services are determined by the primary user account holder. (2) Note that the employer who provides Parental Success to you as a benefit is not a user of the services and your personal information is not disclosed to them except as described in the immediately preceding section. (3) Note that for Parent Discussion Groups we encourage participants to keep any information disclosed by other participants private and confidential. However, there can be no guarantee of full confidentiality and you should think carefully before disclosing any personal information when participating in the groups.
    • Professional Resilience: Note that Professional Resilience is not designed for the disclosure to Rethink consultants of identifying information about individuals who are the subject of a consultation, and primary user account holders are actively discouraged from making such disclosures.

We have in the preceding 12 months disclosed the following categories of personal information to “service providers” (defined above):

  • Identifiers such as your name, email address, username, and IP address.
  • Additional personal information defined by certain applicable US state laws: address, telephone number.
  • Internet activity/usage on our websites and applications.
  • Protected classification characteristics and EU “special categories of personal data”, such as gender and health information.

We will also disclose your personal information in the following exceptional circumstances:

  • Corporate event: Your data may be transferred to third parties as a result of a merger, acquisition, or similar corporate event involving Rethink.
  • Legal necessity: We will disclose your information to government agencies, law enforcement, courts, and other authorities and parties if required to by applicable law. Note that information you provide to Rethink, including to our behavioral consultants in the course of a consultation, may not be protected by physician-patient privilege.
  • Individual’s vital interests: If we reasonably believe based on information posted on or provided in relation to our services that the safety or vital interests of an individual are at risk, we will disclose personal information to relevant parties as necessary to assist the individual.
  • Protection of Rethink’s interests: Where permitted by applicable law, we may disclose personal information to our professional advisors and other qualified parties when we reasonably believe it to be necessary to protect our essential business interests.

6. Information security

We employ technical, physical, and administrative security measures appropriate to the categories of personal information processed in our services. These measures include, for example: encryption at rest and in transit, roles-based access, firewalls, and anti-virus software. For more details of our practices, please consult our Information Security Standards statement.

We protect information about individual’s diagnoses, treatments, and outcomes with particular care. Rethink is HITRUST CSF certified. HITRUST CSF is a security and privacy framework that covers, among others, HIPAA and National Institute for Standards and Technology (NIST) standards.

No matter how carefully we safeguard your information, it is unfortunately not possible to guarantee that it will never be accidentally or illegally breached.

7. Data retention

We will retain your personal information as long as necessary to fulfill the purposes for which it was collected, and to satisfy legal, accounting, and reporting obligations, or to resolve disputes or enforce our Terms of Use.

Section 9 of this Notice below describes your rights to request deletion of your data outside of our normal data retention schedule and to withdraw your previously given consent to our processing of your data.

8. International transfer

Rethink is based in the United States. Your personal information is stored on our systems in the US.

If you live in the European Union, European Economic Area, or UK, note that the European Commission has not issued an unlimited adequacy decision for the US.

As set out in this Notice, Rethink strives to protect your data and your rights regardless of any international transfer.

We obtain your explicit consent to transfer your information to the US, and cannot provide our services without that consent.

Should we disclose your personal information to a Rethink service provider (see Section 5 of this Notice) located outside the US, we will put in place appropriate legal safeguards (for example, standard contractual clauses) that are designed to protect your personal information in the new jurisdiction.

9. Your rights

US and international laws give you various rights over your personal information and that of your child. These may include the right to:

  • Access personal information held about you
  • Correct inaccurate or out-of-date personal information
  • Request deletion of your personal information
  • Restrict processing of your personal information
  • Data portability: Receive your personal information in a readily useable format
  • Object to processing for which the legal basis is our legitimate interests

Notice of withdrawal of consent and other requests to exercise privacy rights should be addressed to us using the contact information in Section 10 below.

If you believe that we have infringed your privacy rights, please contact us so that we can try to resolve the issue. However, if you are an EU/EEA/UK resident, you have the right to lodge a complaint with your EU/ EEA local supervisory authority or, in the UK, with the ICO.

9.1 Marketing

You can opt out of our marketing communications at any time using, for example, the “unsubscribe” in an e-mail message or “STOP” reply in a text message.

When required by local law, we will obtain your prior consent for marketing communications. You may withdraw that consent at any time using the “unsubscribe” or similar functionality in a marketing message. Alternatively, please contact us using the contact information in Section 10 below.

Please note that, if you are a user of our subscription-only services, you may continue to receive service communications even after you have opted out of marketing communications. “Service” communications contain important information about the service for which you are a current user.

10. Contact us

Data Protection Officer: Click to send an email [email protected] or (800) 708-2154

Rethink Autism, Inc.
49 West 27th Street, 8th Floor
New York, NY 10001
USA

EU Representative:

MyEDPO Ltd,
Unit 3d North Point House,
North Point Business Park,
New Mallow Road,
Cork, Ireland
Click to send an email [email protected] or +44 203 870 3376.