SYNAP

Privacy Policy

Revision Version: 1.0

Last Updated: 01-17-2025

Important Notice: This Privacy Policy reflects our dedication to safeguarding your privacy and outlines our practices for collecting, using, protecting, and handling your personal and medical information in compliance with applicable laws and regulations, including the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We encourage you to read this document carefully to understand your rights and choices regarding your information and how we operate to protect your privacy.

1. Introduction

Welcome to SYNAP, LLC. We are committed to protecting your personal information and your right to privacy. This comprehensive privacy policy explains in detail how we handle your data, your rights, and our obligations as a data controller and processor. For questions or concerns, please contact us at support@synap.cloud.

1.1 Scope and Application

This policy applies to all services provided through:

2. Information Collection and Processing

2.1 Types of Information Collected

Personal Information:

Technical Information:

2.2 Processing Activities and Legal Basis

Processing Activity Legal Basis Retention Period
User Registration Contractual Necessity Duration of account + 1 year
Medical Recommendation Processing Explicit Consent Duration of validity + 2 years
Communication Legitimate Interest 2 years from last interaction
Security Logging (e.g., IP logs) Legal Obligation 3 years
JWT/Session Data Contractual Necessity Expires after 1 hour (JWT), plus session lifetime of 1 hour
Upload Counts Legitimate Interest Stored until no longer needed for analytics
Edit History Legitimate Interest Indefinite or until no longer required

3. International Data Transfers

3.1 Data Storage Locations

We utilize Google Cloud Platform services for data storage and processing. Your information may be processed and stored in various locations globally, including:

Additionally, user-generated files and images may be stored in Google Drive when you authorize our application to link with your Google account. We adhere to Google's security and compliance standards for such integrations.

3.2 Transfer Safeguards

We implement the following safeguards for international data transfers:

4. Third-Party Service Providers

4.1 Core Service Providers

Provider Service Data Accessed Security Measures
Google Cloud Platform Infrastructure & Authentication User data, Documents ISO 27001, SOC 2/3
SendGrid Email Communication Email, Name GDPR, CCPA Compliant
Google Vision API Document Processing Document Images Encrypted Processing
Google Drive User File Storage (Optional) Images, PDFs, documents Encrypted at rest and in transit
Redis Session & Token Management Session data, Blacklisted tokens In-memory storage, SOC 2 Type II environment

4.2 Service Provider Compliance

5. Data Security Measures

5.1 Technical Security Measures

5.2 Organizational Security Measures

6. Medical Information Handling

6.1 HIPAA Compliance

We are not a HIPAA-covered entity because we do not meet the definition of:

Nevertheless, we strive to implement HIPAA-grade security measures to protect sensitive information and maintain the trust of our clients and users. Our safeguards include:

6.2 Special Category Data Protection

6.3 State Medical Marijuana Program Compliance

We recognize and respect that different states in the United States have specific laws and regulations governing the possession, distribution, and use of medical marijuana. In order to remain compliant with these state programs, we:

6.4 Additional Details About Recommendation Processing and Storage

Our platform facilitates the submission and processing of medical marijuana recommendations from authorized healthcare providers. Here is how we manage these recommendations:

6.5 Scope of Medical Data

While we handle medical marijuana recommendations, we do not store or transmit detailed medical conditions or diagnoses. The information we process is limited to data necessary for verifying the validity of the recommendation itself (e.g., issuing provider details, expiration date, and patient ID). By design, we do not collect or maintain comprehensive patient health records or diagnostic information.

7. Cookie Policy and Tracking Technologies

7.1 Types of Cookies Used

Cookie Name Type Purpose Duration Necessary?
medi_plus_access_token Session Cookie User authentication token (Medi+) 1 hour (or session) Yes
medi_plus_refresh_token Session Cookie Token refresh authentication (Medi+) 1 hour (renewable) Yes
medi_plus_session Session Cookie Session state management (Medi+) 1 hour (or session) Yes
medi_pass_access_token Session Cookie User authentication token (Medi Pass) 1 hour (or session) Yes
medi_pass_session Session Cookie Session state management (Medi Pass) 1 hour (or session) Yes
admin_access_token Session Cookie Admin authentication token (single authorization) 1 hour (or session) Yes
register_access_token Session Cookie Registration authentication token (single authorization) 1 hour (or session) Yes
Security Cookies Security CSRF protection, JWT cookie checks Session Yes
Preference Cookies Preference User settings 1 year No
Analytics Cookies Analytics Usage statistics 2 years No

7.2 Cookie Control

We use cookies that are essential to the security and functionality of our services, including user authentication and session management. These cookies are strictly necessary, and the service cannot function without them.

If you do not wish to accept essential cookies, you will not be able to use our services. By continuing to use our platform, you acknowledge the use of these strictly necessary cookies. For other optional cookies (e.g., analytics or preferences), you may manage your browser settings or use our consent tool to opt out if desired.

7.3 Additional Cookie Clarifications

8. Data Protection Rights

8.1 Your Rights

8.2 Exercise Your Rights

8.3 Data Deletion Requests from Patients

9. Data Breach Notification

9.1 Notification Timeline

In the event of a data breach that compromises the security of personal or sensitive information, we are committed to taking swift and transparent action in compliance with applicable laws, including the California Consumer Privacy Act (CCPA) and California Civil Code Section 1798.82.

9.2 Notification Content

In the event of a data breach, affected individuals will be notified promptly with a clear and comprehensive explanation of the following:

By providing clear and actionable information, we aim to minimize potential harm and empower affected individuals to respond effectively to the breach.

10. Children's Privacy (COPPA Compliance)

10.1 Age Restrictions

Our services are designed for use by individuals who are at least 18 years old. We are committed to protecting the privacy of children in compliance with the Children's Online Privacy Protection Act (COPPA) and applicable laws. Specifically, we comply with the following guidelines:

10.2 Verification and Deletion

If we discover that we have inadvertently collected information from a minor, we will take swift and decisive action to protect their privacy and ensure compliance with COPPA and other applicable laws:

11. Rate Limiting

We enforce rate limits for API requests, currently set to 300 requests per day and 100 requests per hour per IP address. Additionally, certain endpoints may enforce stricter limits (e.g., 35 requests per minute) to protect sensitive actions such as logins or administrative tasks.

These rate limits help ensure overall service stability and protect against malicious activities, including brute-force attempts and denial-of-service attacks. Limits may be updated periodically based on performance requirements and evolving security needs.

12. Regulatory Compliance

12.1 CalOPPA Compliance

In accordance with the California Online Privacy Protection Act (CalOPPA), we are committed to maintaining transparency and user rights. To ensure compliance, we:

12.2 CCPA (CPRA) Compliance

In compliance with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), we ensure the following rights for California residents:

By upholding these rights, we empower California residents with greater control over their personal information while fostering trust and transparency in our services.

12.3 Additional Compliance Measures

To ensure robust adherence to privacy and data protection regulations, we implement the following measures:

These measures underscore our commitment to maintaining the highest standards of privacy and regulatory compliance across all aspects of our operations.

12.4 State-Specific Privacy Rights Regarding Medical Marijuana Information

In addition to federal and California-specific laws, we recognize that states may enact unique privacy protections for individuals who participate in medical marijuana programs. To address these requirements, we:

13. Changes to Privacy Policy

13.1 Update Process

To ensure our policies remain up-to-date and transparent, we adhere to the following update procedures:

13.2 Version Control

We maintain thorough records of all Privacy Policy updates to ensure transparency and accountability.

These version control measures ensure transparency in our practices and allow users to access historical records as needed.

14. Contact Information

Primary Contacts:

Response Times: