Revised Privacy Policy for True North Clinical Services

Last Updated: June 21, 2025

1. Introduction

True North Clinical Services ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website truenorthnj.org (the "Site"), including any forms, media, or channels connected thereto. Please read this Privacy Policy carefully. If you do not agree with the terms of this policy, please do not access the site.

This policy has been prepared to comply with applicable US privacy laws, including the New Jersey Data Privacy Act (NJDPA).

2. Important Distinction: This Policy vs. Our HIPAA Notice of Privacy Practices

This Privacy Policy describes our practices for information we collect from visitors and users of our public-facing website. It does not describe how we use and disclose Protected Health Information (PHI) we collect from our established patients.

As a healthcare provider, we are subject to the Health Insurance Portability and Accountability Act (HIPAA). Our legal duties and privacy practices regarding PHI are described in our separate HIPAA Notice of Privacy Practices. A copy of this notice, which begins with the header "THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY," is provided to all patients at the initiation of care.

Information you provide to us for the purpose of inquiring about or seeking our services will be handled under this Privacy Policy until a formal provider-patient relationship is established. At that time, that information will be incorporated into your patient record and will thereafter be governed by our HIPAA Notice of Privacy Practices.

3. Information We Collect

We may collect personal data about you in a variety of ways. "Personal Data" is any information that is linked or reasonably linkable to an identified or identifiable person.

A. Personal Data You Provide to Us: We collect Personal Data that you voluntarily provide to us when you fill out a contact or inquiry form, such as your name, email address, and phone number.

B. Sensitive Personal Data and Required Consent: The NJDPA defines certain information as "sensitive data," including information about a mental or physical health condition, treatment, or diagnosis, and financial information. Our inquiry forms may allow you to voluntarily provide such information. We will not process this sensitive data without your explicit, opt-in consent. We will obtain this consent via a dedicated mechanism on the form before you submit your information.

C. Data Collected Automatically (Usage Data): When you access the Site, we may automatically collect certain information, such as your Internet Protocol (IP) address, browser type, operating system, device information, access times, and the pages you have viewed directly before and after accessing the Site. We may use cookies, web beacons, and other tracking technologies to collect this Usage Data.

D. Information from Job Applicants: If you apply for employment through our Site (e.g., via a link to a Google Form), we collect the information you provide, such as your name, contact information, resume, and cover letter. This information is considered "Employment-Related Information" and is used solely for the purpose of evaluating your candidacy for employment. Please note that the consumer rights described in Section 6 of this policy do not apply to Employment-Related Information, as per exemptions in the NJDPA.  

4. How and Why We Use Your Information (Purpose of Processing)

We have a legitimate interest in using the information we collect for the following specific purposes:

To Respond to Your Inquiries: We use the Personal Data you provide to respond to your questions and requests for information about our services.

To Operate and Improve the Site: We use Usage Data to monitor and analyze usage and trends, which helps us improve the Site's functionality, content, and user experience.

To Maintain Security: We use Usage Data, such as IP addresses, to maintain the security and integrity of our Site, protect against fraudulent or malicious activity, and troubleshoot technical issues.

To Process Job Applications: We use Employment-Related Information to assess applicant qualifications and manage our hiring process.

To Comply with Legal Obligations: We may use any of your information as necessary to comply with applicable legal and regulatory obligations, subpoenas, or court orders.

5. Disclosure of Your Information (Categories of Third Parties)

We do not sell your Personal Data as defined by the NJDPA. We may share information we have collected about you with the following categories of third parties for legitimate business purposes:

A. Website and IT Service Providers: We may share Usage Data and Personal Data with third-party vendors who perform services for us or on our behalf, such as website hosting (Squarespace) and data analytics (Google Analytics). These providers are contractually obligated to safeguard your data and use it only for the purposes we specify.

B. Compliant Form and Application Processors: We may use HIPAA-compliant third-party services to securely collect and process information submitted through our inquiry or application forms (e.g., a compliant version of Google Forms or another dedicated provider). We share the Personal Data and/or Employment-Related Information you submit with these processors.

C. By Law or to Protect Rights: We may disclose your information if we believe in good faith that disclosure is necessary to: (1) comply with a legal process; (2) respond to claims against us; (3) protect the rights, property, or personal safety of our company, our employees, our users, or the public; or (4) enforce our agreements, terms, and policies.

6. Your Data Rights Under the New Jersey Data Privacy Act (NJDPA)

As a resident of New Jersey, you have the following rights with respect to your Personal Data. These rights do not apply to Employment-Related Information.

Right to Access: You have the right to confirm whether we are processing your Personal Data and to access such data.

Right to Correct: You have the right to correct inaccuracies in your Personal Data.

Right to Delete: You have the right to delete Personal Data you have provided to us or that we have obtained about you.

Right to Data Portability: You have the right to obtain a copy of your Personal Data in a portable and, to the extent technically feasible, readily usable format.

Right to Opt-Out: You have the right to opt out of the processing of your Personal Data for the purposes of:

(a) targeted advertising;

(b) the sale of Personal Data; or

(c) profiling in furtherance of decisions that produce legal or otherwise similarly significant effects concerning you.

How to Exercise Your Rights: To exercise any of these rights, please contact us using the information in the "Contact Us" section below. We will respond to your verified request within 45 days of receipt. We may extend this period by an additional 45 days where reasonably necessary, in which case we will inform you of the extension.

How to Appeal a Decision: If we decline to take action on your request, we will inform you of the reason and provide instructions on how you can appeal our decision. You may appeal by contacting us through the same method you used for your initial request. We will respond to your appeal within 45 days. If your appeal is denied, we will provide you with a method to contact the New Jersey Division of Consumer Affairs to submit a complaint.

Universal Opt-Out Mechanism: By July 15, 2025, we will honor opt-out preference signals sent via a Universal Opt-Out Mechanism (UOOM), such as the Global Privacy Control (GPC), which will be processed as a request to opt out of targeted advertising and/or the sale of your Personal Data, as applicable.

7. Cookies and Tracking Technologies

We may use cookies, web beacons, and other tracking technologies on the Site to help customize the Site and improve your experience. When you access the Site, your personal information is not collected through the use of tracking technology. Most browsers are set to accept cookies by default. You can choose to set your browser to remove or reject cookies, but be aware that such action could affect the availability and functionality of the Site.  

8. Data Security

We use reasonable and appropriate administrative, technical, and physical security measures designed to protect the confidentiality, integrity, and accessibility of your Personal Data. Our security program includes safeguards such as access controls, data encryption, regular security assessments, and an incident response plan. While we have taken reasonable steps to secure the Personal Data you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse.

9. Policy for Children

This Site is not primarily directed to children under the age of 13. However, as a clinical services provider, we recognize that our Site may be considered a "mixed audience" service under the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 without first obtaining verifiable parental consent.

If you are under 13, you must not use this Site or submit any information through its forms without the verifiable consent of your parent or guardian. We will use an age-verification mechanism on our forms to prevent the collection of information from children under 13 without such consent. If we learn we have collected personal information from a child under 13 without the requisite parental consent, we will take steps to delete that information as quickly as possible.

Parents have the right to review the information we have collected from their child, direct us to delete it, and refuse to allow any further collection or use of the child's information. To exercise these rights, please contact us.

10. Changes to This Privacy Policy

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.  

11. Contact Us

For any questions or comments about this Privacy Policy, or to exercise your data rights, please contact our Privacy Officer at:

aaron@keenertechsolutions.com