As described below, we collect personal information about individual consumers in connection with the provision of our software and services we offer them, and on behalf of our customers who provide our software and services to their customers and consumers. We implement reasonable physical, administrative, and technical safeguards designed to protect your information from unauthorized access, use, or disclosure. When we receive and collect data on behalf of our customers, our customers generally need to tell us when, with who, whether, and how we may disclose personal information.
For more information about the specific pieces of personal information we have collected about you in connection with an HRA, FSA, HSA or similar accounts, or to request disclosure of that information, please contact your health plan, administrator, or the bank at which you opened your HSA. If you are a direct consumer of one of our products or services such as WealthCare HSA, please contact us directly using the contact information included at the end of this document.
What We Do
Alegeus provides software and services to support the administration of health-related consumer-directed accounts, such as health savings accounts and flexible spending accounts. In addition, we are an HSA custodian and provide the WealthCare Saver solution directly to consumers. We also provide software and services to support the administration of COBRA health benefit continuation and health insurance premium billing. Our customers are health plans, insurance companies, third party administrators, banks, financial institutions, and similar organizations that work directly with employers and, in some instances, consumers, to offer health reimbursement accounts (HRAs), flexible spending accounts (FSAs), health savings accounts (HSAs), and similar consumer-directed healthcare accounts, as well as COBRA health benefit continuation and insurance premium billing. You can find out more about Alegeus at https://www.alegeus.com/ or https://wealthcare.com/.
Regarding the Protection of the Confidentiality and Security of Your Personal Information
We maintain physical, electronic and procedural safeguards to protect your Personal Information from unauthorized access or intrusion. We limit access to your Personal Information only to those employees, contractors and agents who need such access in connection with providing products or services to you or for other legitimate business purposes. We will comply with all laws and regulations to which we are subject regarding the collection, use and disclosure of individually identifiable Information.
Categories of Sources
We collect and use information about you if you are enrolled in a benefit plan administered by one of our customers, if you sign up for or open a health-related financial account with one of our customers, or if you are a direct consumer of one of our products, such as WealthCare Saver. We may collect Personal Information about you from the following sources:
- From applications or other forms we receive from you or your authorized representative
- From your transactions with, or from the services performed by, us, our affiliates, or others
- From our internet web sites
- From the public records maintained by governmental entities that we either obtain directly from those entities, or from our affiliates or others
- From consumer or other reporting agencies
Categories of Information
When you use our services, we collect and use personal information which is necessary for the performance of those services. The majority of the personal information we collect and use to provide our services is supplied voluntarily by you, your employer, and/or our customers, and most of that personal information is available for you to review by accessing our software and services. This information falls into the following categories:
- Basic information such as your name, the company you work for, and your relationship to a person;
- Contact information such as postal address, email address and telephone number(s);
- Identifiers such as unique personal identifier, online identifier, or user id. We collect social security numbers if your employer or health plan uses your social security number as your unique personal identifier. In some circumstances, such as when you use our services to open a bank account, we are required to collect images of documents from you reflecting your social security number, driver’s license number, or passport number to verify your identity.
- Insurance information such as insurance policy number and other health insurance information when we provide COBRA continuation and similar services. We may also receive insurance information in the course of administering your HRA, FSA, or HSA account.
- Financial information (such as bank account information, credit and debit card numbers, tax registration information, billing details) in order to manage and process any payments that you make to us, we make to you, or you make to others using accounts that we administer for you.
- Medical information associated with medical bills if you use your HRA, FSA or HSA to pay medical bills.
- Demographic information such as gender and health insurance coverage levels (such as individual or family coverage) if your health plan or health insurer requires it.
- Information such as your Internet Protocol address and geolocation data, which we use when we receive a request to log into our software using your credentials to help us decide whether to allow access.
- Information about your interactions with our software and services.
How We Use Information
We may use or disclose the personal information listed above for the following purposes, as permitted by applicable law:
- To provide you with information about our products and services
- To administer the products and services that we offer, including to determine eligibility or to review and pay claims
- To engage service providers to assist us in administering and providing our products and services
- To provide data analytics to allow us to assess product performance or enhance our products or website
- To comply with administrative or legal requests, subpoenas, or otherwise required by law
- For any purpose permitted under HIPAA or Gramm-Leach-Bliley
We may share your personal information in the following ways with the following categories of third parties:
- Employers to administer their benefits programs
- Agents, brokers or representatives to provide you with services you have requested
- Banks to process payments and administer accounts or benefits programs
- Health insurance companies to administer accounts or benefits programs and receive accurate claims information
- With service providers, authorized third-party agents, or contractors to provide a requested service or transaction
- In response to a request for information by a competent authority if we believe disclosure is in accordance with, or is otherwise required by, any applicable law, regulation or legal process
- With law enforcement officials, government authorities, or other third parties as necessary to comply with legal process or meet national security requirements; protect our rights, property, or safety and the rights, property or safety of our business partners, you, or others; or as otherwise required by applicable law
- In aggregated, anonymized, and/or de-identified form, which cannot reasonably be used to identify you
- If we otherwise notify you and you consent to the sharing
In addition, we will disclose your Personal Information when you direct or give us permission, when we are required by law to do so, or when we suspect fraudulent or criminal activities. We also may disclose your Personal Information when otherwise permitted by applicable privacy laws such as, for example, when disclosure is needed to enforce our rights arising out of any agreement, transaction or relationship with you.
Certain states afford you the right to access your Personal Information and, under certain circumstances, to find out to whom your Personal Information has been disclosed. Also, certain states and the Safe Harbor principles afford you the right to request correction, amendment or deletion of your Personal Information. We reserve the right, where permitted by law, to charge a reasonable fee to cover the costs incurred in responding to such requests.
Selling your Personal Information
We do not sell your Personal information.
We may amend this policy from time to time to keep it up to date with legal requirements and the way we operate our business. Please regularly check for the latest version of this policy. If we make significant changes to this policy, we will seek to inform you by notice on our website or by email.
Retention of Personal Information
We will store your personal information for as long as is reasonably necessary for the purposes for which it was collected and to comply with applicable law, such as HIPAA and GLBA.
Requesting this Policy in Alternative Format
You are able to request this policy in an alternative format if you have a disability. Please see our contact information below to request an alternative format.
Postal Address: Alegeus Technologies
Attn: Privacy Officer
1601 Trapelo Road
Main Building, Suite 301
Waltham, MA 02451
CALIFORNIA CONSUMER PRIVACY ACT SUPPLEMENT
The CCPA defines “Personal information” as information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a consumer or device.
Right to know what information is collected about you
Right to know if your information is sold, by whom to whom, and the right to opt out of that sale
We do not sell your Personal information.
Right to access the information that is collected about you
You can access all Personal Information that we have collected about you by logging into your account.
Right to have a business delete your information
We are required by federal regulation and law, such as HIPAA and GLBA, to keep records of all personal information we collect, and therefore, we are not permitted to honor requests to delete.
Right to not be discriminated against for enforcing your rights under the CCPA
We will not discriminate against you for exercising your CCPA rights.