Privacy Policy
This Privacy Policy explains what personal data Bloch Quantum Imaging Solutions, Inc. d/b/a BeSound (“BeSound,” “we,” “us” or “our”) collects, how we collect and use that information, and to whom we disclose it. It applies to visitors of the BeSound website at besoundbreast.com, the BeSound web application at app.besoundbreast.com, and any related websites (the “Sites”), and users of any other platforms, technologies, products, web applications, and on- and off-line services we offer, including our advanced ultrasound imaging services (collectively with the Sites, the “Services”). This Privacy Policy does not apply to business-to-business or employment information, nor to third-party websites, apps, or services linked to or from our Services.
We may collect, store, and use personal data that is linked or reasonably linkable to you and that identifies your past, present, or future health status or mental health status, as may be applicable (“consumer health data”). If you are a resident of Connecticut, Nevada, or Washington, we provide information about consumer health data collected about you, as well as the rights you may have related to this data, in our Consumer Health Data Privacy Notice.
Please note that we are providing the following disclosures and rights in this Privacy Policy in the interest of transparency. Such disclosures and rights are not intended to waive any applicable exemptions under state and federal law.
1. Personal Data We Collect
Personal data is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identifiable individual. It does not include publicly available information; lawfully obtained, truthful information that is a matter of public concern; information that has been de-identified, or aggregate consumer information. “Publicly available information” includes information from federal, state, or local government records; information we reasonably believe is lawfully available to the general public through widely distributed media or by the individual; and information made available by a person to whom the individual has disclosed it without restricting it to a specific audience.
We may create aggregated, de-identified, or anonymous information from data by removing certain data components (e.g., name, email address, or linkable tracking identifier) or through aggregation, obfuscation, or other means. Subject to applicable law, our use and disclosure of such aggregated, de-identified, and anonymized information is not personal data or subject to this Privacy Policy.
We collect data in the following categories:
- Identifiers: Name, address, email address, phone number, certain social media account information including user ID, IP address, unique device identifiers, mobile app identifiers.
- Commercial information: Products or services purchased, purchase histories, information about your interests and preferences.
- Internet or other electronic network activity information: Content and information about your communications through the Services, information using cookies and tracking technologies, mobile operating system information, mobile internet browser type, diagnostic data.
- Geolocation data: Global Positioning System (“GPS”) data, location information based upon your IP address, cell network data, location data collected from various devices including your mobile device(s).
- Financial data: Credit card, debit card, or bank account data.
- Audio, electronic, visual, or similar information: User-generated content, including original textual content (e.g., reviews you leave about our Services), photos (e.g., profile image or photos you tag us in on social media), videos, and other media you may share on our Services, radiology scan images.
- Characteristics of protected classifications: Age or age range, date of birth, gender or gender identity, marital status, national origin, income level, military or veteran status.
- Sensitive data: Health data, biometric data, genetic data, social security number, precise geolocation, religious beliefs, union membership.
- Inferences: Profiles or trends derived from any of the above.
2. Purposes of data collection:
- To fulfill the purposes for which the information was provided (e.g., to provide a service or perform on a contract).
- To provide, operate, maintain, improve, personalize, and expand our Services.
- To perform research and development.
- To communicate with you, including to provide customer service and provide you with updates about our Services.
- To facilitate orders.
- To develop new features and functionalities.
- To perform internal analytics.
- For marketing and promotional purposes.
- To market the products and services of others.
- For targeted advertising.
- For internal business purposes, including general business administration.
- For systems and data security, including to prevent unauthorized, improper, or illegal activities on our Services.
- To comply with our legal obligations, including responding to subpoenas, court orders, or legal process; and to establish or exercise our legal rights or defenses against legal claims.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal data held by us about the users of our Services is among the assets transferred.
- For purposes disclosed at the time you provide your information or as otherwise set forth in this Privacy Policy or for any other legal purpose not inconsistent with this Privacy Policy.
- Any other purpose consistent with your consent and expressed preferences.
3. Third-party recipients (excluding service providers and affiliates):
- Third-party advertising platforms and analytics providers (for Identifiers, Commercial information, Internet activity, Geolocation data, Audio/visual information, Characteristics of protected classifications, Inferences).
- No third-party recipients (excluding service providers and affiliates) for Financial data and Sensitive data.
4. Use of Artificial Intelligence
We may use artificial intelligence (“AI”) technologies to assist in the performance and delivery of our Services, including our advanced ultrasound imaging services. We may use aggregated, anonymized user data to improve the AI technologies we use. However, none of your personal data will be used to train our AI technologies without your consent.
5. Sources of Personal Data
We collect data from:
- Directly from you.
- Automatically through cookies and other tracking technologies, as discussed in more detail in Section 4.
- From our affiliates.
- From our service providers, including those providing hosting services, analytics services, cloud services, customer and technical support, email services, healthcare services, and other services. For example, we may collect personal data if you use a chatbot on our Services, which is provided by our third-party service provider.
- From third-party business and marketing partners, joint marketing campaign partners, ad network providers, and advertisers.
- From social media and other content platforms, such as Meta and TikTok, if you interact with us on these platforms.
6. Disclosure of Personal Data
We may share data with:
- Affiliates: Our affiliates, licensees, and joint venture partners.
- Service providers: For order fulfillment, payment processing, analytics, advertising, hosting, marketing, customer and technical support, and other services. For example, if you use a chatbot or live chat on our Services, the information provided may be recorded and stored by our third-party provider, on our behalf.
- Medical providers: Radiologists and treating professionals for further consultation and treatment.
- Advertising partners: Third-party platform providers, including advertising, social media, and analytics companies, who assist us in serving advertising regarding the Services to others who may be interested. We also partner with third parties who use cookies to serve interest-based advertising and content on their respective third-party platforms that may be based on your preferences, location, and/or interests.
- Other third parties: Business partners and joint marketing campaign partners.
- Business transferees: In mergers, acquisitions, asset sales, or other corporate combinations, your personal data may be transferred to the acquiring or surviving entity.
- Professional advisors: Lawyers, auditors, bankers, insurers, where necessary in the course of their professional services.
- Authorities for compliance and harm prevention: Under certain circumstances, if required by law or in response to valid requests by public authorities, and/or in response to a threat of harm involving an individual’s health and/or safety.
- Other parties: With your consent.
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies (e.g., beacons, tags, scripts) to track activity on the Sites and hold certain information. Cookies are files with a small amount of data, which may include a unique identifier, sent to your browser from a website and stored on your device.
- Essential cookies: Necessary for the Sites to function, set in response to actions like setting privacy preferences, logging in, or filling in forms. These cannot be switched off.
- Functional cookies: Enable enhanced functionality and personalization, set by us or third-party providers. These are session cookies, erased when you close your browser. If not allowed, some services may not function properly.
- Performance cookies: Allow us to count visits and traffic sources to measure and improve Site performance. They collect aggregated, anonymous data to identify popular pages and user navigation patterns. If not allowed, we cannot track your visits or include your experience in performance monitoring.
- Analytics cookies: Track visits to improve content and suggest activities, collecting data on how users use the Sites, referral sources, visit frequency, and duration.
- Advertising/Targeting cookies: Placed by third-party advertising platforms to deliver ads and track ad performance, enabling relevant ads based on your activities (targeted advertising).
Opting out:
- Modify browser settings to decline cookies (note: some Site features may not function).
- Analytics opt-out: Use the Google Analytics Opt-out Browser Add-on.
- Targeted ad opt-out:
Opting out of targeted ads does not stop non-targeted ads. Opt-outs may not work if cookies are rejected, erased, or if using different devices/browsers. Mobile app opt-outs are separate. We are not responsible for the effectiveness of third-party opt-out options or their statements.
8. Children’s Data
Our Services are not for children under 18. We do not knowingly collect their data. If you think your child provided personal data, contact us immediately at people@besoundbreast.com, and we will make best efforts to remove it promptly.
9. Data Security and Retention
We use technical, administrative, and physical safeguards to protect data against unauthorized access, destruction, loss, alteration, disclosure, or misuse, but no method is 100% secure.
Data is retained only as necessary for:
- Legal compliance, dispute resolution, or enforcing legal agreements.
- Internal analytics (shorter retention unless needed for security or functionality).
Retention periods depend on:
- The length of time we have an ongoing relationship with you (e.g., whether you are a current employee or contractor).
- Legal obligations.
- Legal position (e.g., statutes of limitations, litigation, regulatory investigations).
10. Transfers of Personal Data
Data may be transferred outside your jurisdiction, including to the U.S., where data protection laws may differ. We take necessary measures to ensure adequate protection for such transfers.
11. Opting Out of Promotional Communications
- Email: Click the unsubscribe link in emails or email people@besoundbreast.com. We will comply as soon as reasonably practicable. Administrative messages may still be sent.
- SMS: With your consent, we may send SMS for promotional purposes, internal business, user research, or customer service. Text “STOP” to any message or email people@besoundbreast.com to cancel. You’ll receive a confirmation message, then no further SMS. For issues, text “HELP” or email us.
12. California Privacy Notice
This section complies with the California Consumer Privacy Act (CCPA). “Personal data” means information linked to a California resident or household, excluding publicly available, de-identified, or aggregated data, or data subject to certain regulations.
If you are visually impaired, have another disability, or seek support in another language, email people@besoundbreast.com to access this notice.
Disclosures and rights are provided for transparency and do not waive applicable exemptions under state or federal law.
a. Personal data we collect
In the last 12 months, we collected:
- Identifiers
- Commercial information
- Internet or other electronic network activity information
- Geolocation data
- Financial data
- Audio, electronic, visual, or similar information
- Characteristics of protected classifications
- Sensitive data (e.g., health, biometric, genetic, social security, precise geolocation, religious beliefs, union membership)
- Inferences
Certain personal information may constitute “sensitive personal information” as defined by California law.
b. Use of personal data
Same purposes as listed in Section 1.
c. Disclosure of personal data
We limit disclosures to service providers for business Ascertainable business purposes (e.g., operations, services, or purposes compatible with the context of data collection).
We may “sell” or “share” the following data with third-party advertising networks/platforms for targeted behavioral advertising:
- Identifiers
- Commercial information
- Internet or other electronic network activity information
- Geolocation data
- Audio, electronic, visual, or similar information
- Characteristics of protected classifications
- Inferences
d. Retention of personal data
Same as Section 6
e. Your privacy rights
California residents have the following rights, subject to exceptions:
- Right to know and access: Request what personal data we collect, use, disclose, or sell/share (up to 2 times in 12 months, portable copy).
- Right to delete and erase: Request deletion of personal data we collect.
- Right to correct: Request correction of inaccurate personal data.
- Right to non-discrimination: No discriminatory treatment for exercising these rights.
- Right to opt out of sale/sharing: Opt out of data sale/sharing for targeted advertising.
- Right to limit use and disclosure: Limit use of sensitive personal data to uses necessary for providing goods/services. We do not collect sensitive data without consent.
- Shine the Light law: Request information about third-party disclosures for direct marketing or opt out under Cal. Civ. Code §1798.83.
f. How to exercise your rights
Email people@besoundbreast.com or use our webform. Requests require sufficient information to verify identity (at minimum, first and last name, email address) and describe the request with sufficient detail. You may use an authorized agent (with proof of authorization and/or agent identity verification).
We cannot respond if we cannot verify/authenticate your identity or authority and confirm the data relates to you. We use data provided in requests only for verification.
We confirm receipt within 10 business days and respond within 45 days (extendable by 45 days with notice). No fees unless requests are excessive, repetitive, or manifestly unfounded, in which case we provide a cost estimate. You may be limited to a certain number of requests in 12 months. If we collected data on your minor child, you may exercise these rights on their behalf.
For visually impaired, disabled, or non-English speakers, email people@besoundbreast.com for access.
g. Notice of right to opt out of sale/sharing
Opt out by emailing people@besoundbreast.com or using our webform. We do not knowingly sell/share data of minors under 16 without legally required affirmative authorization. If you believe your child provided data without consent, contact us at people@besoundbreast.com.
h. Nevada Privacy Notice
We do not “sell” personal data under Nevada law (SB 220). Nevada residents may opt out of future sales by emailing people@besoundbreast.com with full name, email, and postal address for verification. We will make reasonable efforts to comply with such requests.
13. Nebraska and Texas Privacy Notice
This section provides additional information for Nebraska and Texas residents under the Nebraska Data Privacy Act and Texas Data Privacy and Security Act. See Sections 1–4 for details on data collection, use, sources, and disclosure.
We may “sell” or “share” personal data with third-party advertising networks/platforms through targeting and analytics cookies for targeted advertising.
a. Your privacy rights
Nebraska and Texas residents have the following rights, subject to exceptions:
- Right to know and access: Request what data we collect, use, disclose, or sell/share (up to 2 times in 12 months, portable copy).
- Right to delete and erase: Request deletion of personal data we collect.
- Right to correct: Request correction of inaccurate personal data.
- Right to opt out: Opt out of targeted advertising, data sales, or profiling with significant legal or similar effects.
- Rights concerning sensitive personal data: We cannot collect/use sensitive data or inferences without consent.
- Right to non-discrimination: No discriminatory treatment for exercising these rights.
Exercise rights by emailing people@besoundbreast.com or using our webform. Requests require verification. Response within 45 days (extendable by 45 days with notice). No fees unless excessive/repetitive, with a cost estimate provided. We use data in requests only for verification. Authorized agents may submit requests with proof. For visually impaired, disabled, or non-English speakers, email us for access.
b. Appeals:
- Nebraska: Appeal by contacting us. Response within 60 days with action taken or not taken and reasons. If denied, contact Nebraska’s Attorney General at (402) 471-2683 or here.
- Texas: Appeal by contacting us. Response within 60 days with action taken or not taken and reasons. If denied, contact Texas’ Attorney General at (800) 621-0508 or here.
14. Updates to this Privacy Policy
Changes take effect when posted. We’ll notify you via email or a prominent notice on our Services and update the effective date. Review periodically.
15. Contact Us
Email: people@besoundbreast.com