Privacy Policy

Effective Date: April 25, 2026
Governing Law: State of Wyoming & U.S. Federal Law (HIPAA, HITECH Act)

Service Area: All 50 United States

1. PURPOSE AND BINDING AGREEMENT

Calmora (“the Company,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal and health-related information. This document governs our data practices across our website, mobile applications, and associated APIs (the “Platform”). By using the Platform, you provide explicit consent to these practices.

2. NOTICE OF PRIVACY PRACTICES (NPP)

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Calmora operates as a Management Services Organization (MSO) providing administrative and technological services to independent medical practices and clinicians (the “Providers”). We maintain Protected Health Information (PHI) on behalf of these Providers in a HIPAA-compliant “Secure Platform.” We are required by law to maintain the privacy of your PHI and to abide by the terms of this Notice currently in effect.

3. USES AND DISCLOSURES OF YOUR HEALTH INFORMATION

We use your PHI strictly for Treatment, Payment, and Healthcare Operations (TPO). By using our services, you provide a single consent for all future uses and disclosures of your information for these purposes:

  • For Treatment: We facilitate the sharing of your health data between you and your paired physician via the Beluga Health and CarePortals platforms to ensure accurate diagnosis and treatment planning.
  • For Payment: We use your information to process subscriptions and verify billing through secure third-party processors.
  • For Healthcare Operations: We use data to review the quality of care provided on our platform and for internal business planning.
  • Business Associates: We share PHI with “Business Associates” (such as our telehealth infrastructure and pharmacy partners) who are contractually bound by Business Associate Agreements (BAAs) to protect your data. Including, but not limited to, Beluga Health (https://www.belugahealth.com)

4. DATA COLLECTION & “CLICKSTREAM” METRICS

We collect information to the minimum extent necessary for your treatment plan:

  • Account Information: Legal name, email, phone, address, and ID for verification.
  • Metabolic & Clinical Data: Medical history, weight-related health markers, laboratory results, and current medications provided for weight management.
  • Technical Data: IP addresses, browser type, and “clickstream” data to improve platform performance.

5. COMMERCIAL RESTRICTIONS

Calmora does not sell your PHI. We do not use your medical records or clinical data for targeted advertising, marketing, or third-party data mining without your explicit, written HIPAA Authorization.

6. YOUR LEGAL RIGHTS UNDER HIPAA

As a patient, you have the following rights regarding your PHI:

  • Right to Access: You may request a copy of your health records maintained on our platform.
  • Right to Amend: You may request a correction to inaccurate metabolic or personal data.
  • Right to an Accounting of Disclosures: You may request a list of certain disclosures we have made of your PHI for purposes other than treatment, payment, or operations.
  • Right to Request Restrictions: You may ask us not to use or share certain health information, though we are not always required to agree if it affects your care.
  • Right to Confidential Communications: You may request that we contact you in a specific way (e.g., home phone vs. office).

7. COOKIES AND TARGETED ADVERTISING

On public, non-secure portions of our website, we use pixels (Google, Meta, Microsoft) to show you relevant advertisements.

  • Separation: No clinical data from the Secure Platform is ever shared with these advertising pixels.
  • Opt-Out: You may restrict cookies via your browser or via NAI/DAA opt-out pages.

8. DATA RETENTION AND SECURITY

  • Retention: Under HIPAA and state laws, we maintain medical records for a mandatory period (typically 7–10 years), even if you delete your account.
  • Security: We utilize SSL/TLS encryption and multi-factor authentication (MFA). However, internet transmissions are never 100% secure; use is at your own risk.

9. BREACH NOTIFICATION

In the event of a security breach involving your unsecured PHI, Calmora will notify you without unreasonable delay (and no later than 60 days post-discovery) via email or first-class mail, as required by the HIPAA Breach Notification Rule.

10. CONTACT AND COMPLAINTS

If you believe your privacy rights have been violated, you may file a complaint with our Privacy Officer or with the Secretary of the U.S. Department of Health and Human Services (HHS). We will not retaliate against you for filing a complaint.

Privacy Officer Contact: support@calmora.com

(Subject: ATTN: Privacy Officer)
HHS Office for Civil Rights: 200 Independence Avenue, S.W., Washington, D.C. 20201