Welcome to Greenlight Health Data Solutions, portions of which are available on iOS, Android, and the web (the “Service”). Your use of the Service is governed by these Terms of Service and the Privacy Policy (the “Terms”). By creating an account or using the Service, you agree to these Terms.
Portions of the Service are also known under the Pattern Health brand, which is owned by Greenlight.
This Privacy Policy explains what information Greenlight Health Data Solutions (“Greenlight,” “we,” “our,” or “us”) collects, how we use it, and the choices you have — whether you’re visiting our website or using our Service.
Jump to:
If you access your health records through the TEFCA network, additional terms apply — see our TEFCA IAS Privacy and Security Notice.
Section 1 — Who We Are
Greenlight Health Data Solutions’ mission is to make healthcare more efficient through connected care and research. Our Service allows you to track, retrieve, share, and manage your health information, often in connection with your healthcare provider or research study team. Portions of the Service are also offered under the Pattern Health brand, which is owned by Greenlight.
General privacy questions:
- Email: privacy@greenlighthealth.com
- Mail: Privacy Officer,
- Greenlight Health Data Solutions, 801 Corporate Center Drive, Suite 320, Raleigh, NC 27607
All privacy inquiries are reviewed by Greenlight’s Security/Privacy/Data Protection Officers.
Section 2 — Scope of This Policy
This Privacy Policy applies to:
- The Greenlight website (GreenlightHealth.com)
- The Service (mobile and web applications), including the Records Retrieval Platform and the Pattern Health Engagement platform and Application
- Communications with us regarding the Service
This Policy does not cover third-party sites, apps, or services that connect to the Service (for example, Apple Health or other Health Data Sources). We encourage you to read the privacy policies of any third-party service you connect to Greenlight.
If you use Greenlight to access your health records through the TEFCA network, this Policy applies to you, but the TEFCA IAS Privacy and Security Notice controls wherever the two documents conflict with respect to the individually identifiable information accessed through the TEFCA network.
Section 3 – Website Visitors
This section applies to anyone visiting GreenlightHealth.com, whether or not you use the Service.
3.1 What We Collect
- Contact information you submit through web forms — name, email address, phone number
- Automatically collected information — browser and device type, app version, usage patterns, error logs, and non-precise location (e.g., zip code)
- Cookies and similar tracking technologies — see Cookies below
- Publicly available social media information (e.g., LinkedIn) used to support our marketing activities
3.2 How We Use It
- Respond to inquiries and requests for information
- Send marketing and general business communications
- Understand and improve how our website is used
- Deliver targeted advertising, where permitted by applicable law and consistent with your preferences
We use Pardot and Salesforce (privacy policy) to process and store this data in order to communicate with you about our Services. To engage in marketing activities, we also collect information from your publicly available social media profiles, interests and preferences including LinkedIn (privacy policy). We process such information to better understand you, to maintain and improve the accuracy of the information we store about you, and to better promote or optimize our Services. In addition, we may also use this information to deliver targeted advertising and marketing to you, where permitted by applicable law and in accordance with your marketing preferences.
3.3 Cookies
Greenlight uses cookies to make our website work as expected, and — if you permit — optional cookies that help us understand how the website is used. Our Cookie Policy explains our use of such technology.
3.4 Job Applicants
If you apply for a job with Greenlight, we collect your resume and related application information solely to process your application and contact you about the opportunity. This information is not used for marketing or Service delivery purposes.
Section 4 – Service Users
This section applies to anyone who has created a Greenlight account or otherwise uses the Service, including the Pattern Health platform.
4.1 What We Collect
- Information you provide: health information, photos, notes, health goals, your name, email address, date of birth, gender, and other information you choose to enter
- Information retrieved from Health Data Sources at your request (health systems, hospitals, medical practices, device companies, etc.)
- Information retrieved from Health Data Sources at your healthcare provider’s request, where your provider is authorized to use our platform
- Access Credentials: if you provide credentials to a Health Data Source, you authorize Greenlight to use them to retrieve your data and to store your data securely
- Support requests and feedback you submit to us
4.2 How We Use It
- Provide and improve the Service
- Support authorized healthcare providers and research programs using our platform
- Share your data with your healthcare provider, research team, or other recipients you authorize
- Send you important communications about the Service (email, in-app messages, or text; standard messaging rates may apply)
- Conduct research and analytics — using aggregated, non-personal information — to improve our products
- Protect system security, prevent fraud, and comply with applicable law
4.3 How We Share It
We do not sell your personal data. We may share it:
- With your healthcare provider, research team, or other parties you authorize
- With service providers and sub-processors who help us deliver the Service — see our current sub-processors list
- As required by law or legal process
- In connection with a business transaction (e.g., a merger or acquisition) — you will be notified of any change in ownership or use of your information
- As de-identified or aggregated data that cannot reasonably identify you
4.4 Third-Party Integrations
Portions of the Service may connect with third-party applications or services, such as Apple Health. Greenlight is not responsible for the content, privacy practices, or policies of these third parties. We encourage you to review their terms directly. You can manage or disconnect integrations in your device or app settings.
4.5 Data Accuracy
Greenlight is not responsible for the accuracy of information originally provided by a Health Data Source. Greenlight, your healthcare provider, or your research team may modify or correct the copy of data you enter or share, as well as the copy of data retrieved from a Health Data Source.
4.6 Children
Greenlight does not knowingly collect information from children under 18 except under parental or guardian supervision. If we learn we have collected such information without appropriate consent, we will delete it. For programs operated by healthcare providers on our platform, those providers — not Greenlight — are responsible for obtaining any required parental consent.
4.7 Data Retention
We retain your information while you use the Service and for a reasonable period afterward, unless a longer period is required by law or contract. To request deletion, contact support@greenlighthealth.com.
4.8 Your Choices
- Opt out of marketing emails (unsubscribe link) or texts (reply STOP)
- Disconnect third-party integrations in your device or app settings
- Update your profile within the Service or by contacting support@greenlighthealth.com
- Request deletion of your account by contacting support@greenlighthealth.com
- Your choices are honored even after you stop using the Service
4.9 Security
Greenlight uses technical, administrative, and physical safeguards to protect your data, including encryption, access controls, and staff training in privacy and security best practices. Access to your information is limited to those who need it.
Greenlight is not a HIPAA-covered entity. Where we provide services to HIPAA-regulated organizations, such as healthcare providers and health plans, our handling of protected health information is governed by our agreements with those organizations. Greenlight also aligns its practices with HIPAA’s security and privacy standards as a matter of policy.
No system is completely secure. We recommend using antivirus and firewall tools and setting a PIN or passcode on your personal devices. You can learn more about personal device security at the FTC’s OnGuard Online site.
4.10 TEFCA IAS Participants
If you use Greenlight to access your health records through the TEFCA network, additional privacy and security protections apply. Greenlight participates as a Request-Only IAS Provider — meaning you can request access to your health information via TEFCA, but you cannot use Greenlight to share your information with other TEFCA participants.
For full details on how Greenlight handles individually identifiable information accessed through TEFCA, your rights, and how to give or revoke consent, see the TEFCA IAS Privacy and Security Notice. Where this Policy and the TEFCA Notice conflict, the TEFCA Notice controls with respect to information accessed through the TEFCA network.
Section 5 — International Use
Your data is processed and stored in the United States. If you access the Service from outside the U.S., you consent to this transfer by using the Service.
Health records retrieval through the Records Retrieval Platform is intended for U.S. residents only and complies with U.S. law.
Section 6 — California Residents (CCPA)
This section supplements the rest of this Policy and applies specifically to California residents under the California Consumer Privacy Act (CCPA).
6.1 Categories of Personal Information We Collect
- Identifiers (name, address, ID numbers, email address)
- Customer record details (medical information, contact data)
- Protected classifications (age, gender, race, health data)
- Biometric data (BP, weight, health data)
- Internet or network activity (usage data, cookies)
6.2 Sources of Data
- Directly from you
- From your healthcare provider, research team, or other authorized users of the Service
- From third-party health platforms, when you grant access
6.3 How We Use and Share It
- Fulfill requests and provide the Service
- Maintain, improve, and secure the Service
- Communicate with you and provide support
- Comply with legal obligations
- Conduct research and improve our products
- Support business transactions
We do not sell your personal information. We may share de-identified data using HIPAA’s safe harbor de-identification method.
6.4 Your Rights Under the CCPA
- Right to know what personal information we collect
- Right to request access to, or deletion of, your data
- Right to opt out of data sharing
- Right to non-discrimination for exercising your privacy rights
6.5 How to Submit a Request
- Email: privacy@greenlighthealth.com
- Website: GreenlightHealth.com
- Mail: Privacy Officer, 801 Corporate Center Drive, Suite 320, Raleigh, NC 27607
We may need to verify your identity before fulfilling a request. We aim to respond within 45 days; if more time is needed (up to 90 days total), we will notify you. We do not charge a fee for CCPA requests unless a request is excessive or repetitive, in which case we will provide a cost estimate first.
Section 7 — Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you by posting the updated Policy within the Service and/or on our website, and updating the effective date above. Changes take effect 14 days after posting, unless required by law or related to new features, in which case they may take effect immediately. Continued use of the Service after changes take effect means you accept the updated Policy.
Section 8 — Contact Us
If you have questions about this Privacy Policy:
- Email: privacy@greenlighthealth.com
- Mail: Privacy Officer, Greenlight Health Data Solutions, 801 Corporate Center Drive, Suite 320, Raleigh, NC 27607
Your inquiry will be reviewed by Greenlight’s Security/Privacy/Data Protection Officers.