SYNAP

Privacy Policy

Revision Version: 1.0

Last Updated: April 9, 2025

Important Notice: This Privacy Policy reflects our dedication to safeguarding your privacy and outlines our practices for collecting, using, protecting, and handling your personal and medical information in compliance with applicable laws and regulations, including the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We encourage you to read this document carefully to understand your rights and choices regarding your information and how we operate to protect your privacy.

1. Introduction

Welcome to SYNAP, LLC. We are committed to protecting your personal information and your right to privacy. This comprehensive privacy policy explains in detail how we handle your data, your rights, and our obligations as a data controller and processor. For questions or concerns, please contact us at support@synap.cloud.

1.1 Scope and Application

This policy applies to all services provided through:

2. Information Collection and Processing

2.1 Types of Information Collected

We retain your data only as long as necessary for the purposes outlined in this policy, unless a longer retention period is required by law.

Personal Information:

For Medi Pass users, details such as Name, Date of Birth, Phone Number, Provider Name, Patient ID, and Expiration Date are stored encrypted within user-specific data files hosted on our secure servers (or optionally within your linked Google Drive folder).

Technical Information:

2.2 Processing Activities and Legal Basis

We process your data for the following purposes, based on these legal bases:

Processing Activity Legal Basis Retention Period
User Registration Contractual Necessity Duration of account + 1 year
Medical Recommendation Processing Explicit Consent Duration of validity + 2 years
Communication Legitimate Interest 2 years from last interaction
Security Logging (e.g., IP logs) Legal Obligation 3 years
JWT/Session Data Contractual Necessity 1 hour (standard JWT expiry), up to 365 days (Medi+ 'Stay Logged In' refresh/access cookies), or Redis session lifetime
Upload Counts Legitimate Interest Duration needed for analytics
Edit History Legitimate Interest / Legal Obligation Indefinite or as required by law/audit needs

3. International Data Transfers

3.1 Data Storage Locations

We utilize Google Cloud Platform services for data storage and processing. Your information may be processed and stored in various locations globally, including:

Additionally, user-generated files and images may be stored in Google Drive when you authorize our application to link with your Google account. We adhere to Google's security and compliance standards for such integrations. Users can view and manage the files uploaded to Google Drive by our application via the standard Google Drive interface. All files are stored in the dedicated application folder, accessible only by the app and the authenticated user.

3.2 Transfer Safeguards

We implement the following safeguards for international data transfers:

We rely on the robust data protection measures implemented by our infrastructure providers, such as Google Cloud Platform, which include Standard Contractual Clauses (SCCs) and Data Processing Agreements (DPAs), to safeguard data during international transfers.

4. Third-Party Service Providers

4.1 Core Service Providers

We partner with trusted third-party providers to deliver Medi+ services. These providers include:

Each provider is carefully selected and contractually bound to protect your data. For a full list of providers and their roles, see the table below.

Provider Service Data Accessed Security Measures
Google Cloud Platform Infrastructure & Authentication User data, Documents ISO 27001, SOC 2/3
SendGrid Email Communication Email, Name GDPR, CCPA Compliant
Google Vision API Document Processing Document Images Encrypted Processing
Google Drive Optional User File Storage Images, PDFs, documents Encrypted at rest and in transit
Redis Session & Token Management Session data, Blacklisted tokens, Device identifiers In-memory storage hosted within Google Cloud Platform's secure environment (SOC 2 Type II compliant).
Stripe Payment Processing & Subscriptions Payment method identifiers (via Stripe's secure methods, including bank account details handled by Stripe/Plaid), Subscription details (plan, status, dates), Customer email/name, Purchase history PCI DSS Compliant

4.2 Service Provider Compliance

4.3 Google API Services & Data Usage

When you use our Google integrations, we adhere to Google's API Services User Data Policy. Our use of Google API Services is strictly limited to:

When you connect your Google account to Medi+, we adhere to Google's API Services User Data Policy and use OAuth to securely access specific data with your permission. Here's how it works:

You can revoke our access to your Google data at any time by:

  1. Visiting your Google Account Permissions
  2. Selecting the appropriate app from the list
  3. Clicking "Remove Access"

For more information, please review the Google API Services User Data Policy.

4.4 Additional Data Sharing Scenarios

Beyond our core service providers, we may share your data in the following limited circumstances:

In all cases, we ensure that any data sharing is conducted under strict data protection standards and in compliance with applicable laws.

5. Data Security Measures

5.1 Technical Security Measures

5.2 Organizational Security Measures

6. Medical Information Handling

6.1 HIPAA Compliance

We are not a HIPAA-covered entity because we do not meet the definition of:

Nevertheless, we strive to implement HIPAA-grade security measures to protect sensitive information and maintain the trust of our clients and users. Our safeguards include:

6.2 Special Category Data Protection

6.3 State Medical Marijuana Program Compliance

We recognize and respect that different states in the United States have specific laws and regulations governing the possession, distribution, and use of medical marijuana. In order to remain compliant with these state programs, we:

6.4 Additional Details About Recommendation Processing and Storage

Our platform facilitates the submission and processing of medical marijuana recommendations from authorized healthcare providers. Here is how we manage these recommendations:

6.5 Scope of Medical Data

While we handle medical marijuana recommendations, we do not store or transmit detailed medical conditions or diagnoses. The information we process is limited to data necessary for verifying the validity of the recommendation itself (e.g., issuing provider details, expiration date, and patient ID). By design, we do not collect or maintain comprehensive patient health records or diagnostic information.

7. Cookie Policy and Tracking Technologies

7.1 Types of Cookies Used

Cookie Name Type Purpose Duration Necessary?
medi_plus_access_token Session Cookie User authentication token (Medi+) 1 hour (standard) or up to 365 days (if 'Stay Logged In') Yes
medi_plus_refresh_token Session Cookie Used to securely refresh Medi+ authentication tokens Up to 365 days (if 'Stay Logged In' is selected) Yes
medi_plus_session Session Cookie Session state management (Medi+) 1 hour (or session) Yes
medi_pass_access_token Session Cookie User authentication token (Medi Pass) 1 hour (or session) Yes
medi_pass_refresh_token Session Cookie Used to securely refresh Medi Pass authentication tokens Configured session duration Yes
medi_pass_session Session Cookie Session state management (Medi Pass) 1 hour (or session) Yes
admin_access_token Session Cookie Admin authentication token (single authorization) 1 hour (or session) Yes
admin_refresh_token Session Cookie Used to securely refresh Admin authentication tokens Configured session duration Yes
Security Cookies Security CSRF protection, JWT cookie checks Session Yes

7.2 Cookie Control

We use cookies that are essential to the security and functionality of our services, including user authentication and session management. These cookies are strictly necessary, and the service cannot function without them.

If you do not wish to accept essential cookies, you will not be able to use our services. By continuing to use our platform, you acknowledge the use of these strictly necessary cookies. For other optional cookies (e.g., analytics or preferences), you may manage your browser settings or use our consent tool to opt out if desired.

7.3 Additional Cookie Clarifications

7.4 Local Storage

In addition to cookies, we may utilize your browser's local storage mechanism. This allows us to store certain data directly on your device, which can persist even after you close your browser. We use local storage for:

Data stored in local storage is generally not sent to our servers unless required for specific features and is subject to the same security principles as other data we handle. You can typically clear local storage through your browser's settings.

8. Data Protection Rights

8.1 Your Rights

8.2 Exercise Your Rights

8.3 Data Deletion Requests from Patients

9. Data Breach Notification

9.1 Notification Timeline

In the event of a data breach that compromises the security of personal or sensitive information, we are committed to taking swift and transparent action in compliance with applicable laws, including the California Consumer Privacy Act (CCPA) and California Civil Code Section 1798.82.

9.2 Notification Content

In the event of a data breach, affected individuals will be notified promptly with a clear and comprehensive explanation of the following:

By providing clear and actionable information, we aim to minimize potential harm and empower affected individuals to respond effectively to the breach.

10. Children's Privacy (COPPA Compliance)

10.1 Age Restrictions

Our services are designed for use by individuals who are at least 18 years old. We are committed to protecting the privacy of children in compliance with the Children's Online Privacy Protection Act (COPPA) and applicable laws. Specifically, we comply with the following guidelines:

10.2 Verification and Deletion

If we discover that we have inadvertently collected information from a minor, we will take swift and decisive action to protect their privacy and ensure compliance with COPPA and other applicable laws:

11. Rate Limiting

We enforce rate limits for API requests, currently set by default to 10000 requests per day and 1000 requests per hour per IP address. Additionally, certain endpoints may enforce stricter limits (e.g., 3 to 5 requests per minute) to protect sensitive actions such as logins or administrative tasks.

These rate limits help ensure overall service stability and protect against malicious activities, including brute-force attempts and denial-of-service attacks. Limits may be updated periodically based on performance requirements and evolving security needs.

12. Regulatory Compliance

12.1 CalOPPA Compliance

In accordance with the California Online Privacy Protection Act (CalOPPA), we are committed to maintaining transparency and user rights. To ensure compliance, we:

12.2 CCPA (CPRA) Compliance

In compliance with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), we ensure the following rights for California residents:

By upholding these rights, we empower California residents with greater control over their personal information while fostering trust and transparency in our services.

12.3 Additional Compliance Measures

To ensure robust adherence to privacy and data protection regulations, we implement the following measures:

These measures underscore our commitment to maintaining the highest standards of privacy and regulatory compliance across all aspects of our operations.

12.4 State-Specific Privacy Rights Regarding Medical Marijuana Information

In addition to federal and California-specific laws, we recognize that states may enact unique privacy protections for individuals who participate in medical marijuana programs. To address these requirements, we:

13. Changes to Privacy Policy

13.1 Update Process

To ensure our policies remain up-to-date and transparent, we adhere to the following update procedures:

We also ensure that our OAuth consent screen reflects the contents of this Privacy Policy, including:

These measures help users make informed choices when authorizing our services.

13.2 Version Control

We maintain thorough records of all Privacy Policy updates to ensure transparency and accountability.

These version control measures ensure transparency in our practices and allow users to access historical records as needed.

14. Contact Information

Primary Contacts:

Response Times: