MEDIFINDER
Privacy Policy
Global Master Document covering web, mobile apps, and all related services
|
Legal Entity Yeshan Healthtech, LLC |
Brand / DBA MediFinder |
|
Registered Address 5205 Congress Ave APT 524, Boca Raton, Florida 33487-3905, United States |
Governing Law Florida, United States |
|
Version 1.0 |
Published 19 May 2026 |
|
Contact Email |
Website medifinder.com |
MediFinder is a healthcare discovery and community platform operated by Yeshan Healthtech, LLC. It is NOT a healthcare provider. It does NOT provide medical diagnosis, treatment, or prescriptions. No doctor-patient relationship is formed. Always consult a qualified healthcare professional. In an emergency, call 911 (US), 112 (EU and Turkey), or your local emergency number.
Introduction
This Privacy Policy (the "Policy") describes how Yeshan Healthtech, LLC, a Florida (United States) limited liability company doing business as "MediFinder", with registered offices at 5205 Congress Ave APT 524, Boca Raton, Florida 33487-3905, United States ("MediFinder", "we", "our", or "us"), collects, uses, shares, transfers, retains, and protects personal information when you access, register on, or use our website at medifinder.com, our iOS and Android mobile applications, and any related services (collectively, the "Services").
MediFinder operates a global, multilingual healthcare discovery and community platform connecting patients with verified healthcare providers across 16 languages, including doctors, clinics, hospitals, pharmacies, veterinary clinics, beauty centers, laboratories, and other health professionals. The Services include video and photo upload, community discussions, consultation requests, and provider profiles.
This Policy applies to all users worldwide. Region-specific rights and disclosures are included within this single document — please refer to Section 19 for the section applicable to your jurisdiction.
By using the Services, you acknowledge that you have read, understood, and agree to this Policy. If you do not agree, you must not use the Services.
1. Definitions
- "Personal Data" / "Personal Information": any information relating to an identified or identifiable natural person.
- "Health Data" / "Special Category Data": personal data revealing physical or mental health, including data inferred from consultation forms, treatment preferences, symptoms, conditions, or any health-related communications.
- "Sensitive Personal Information" (CCPA/CPRA): a subset including health information, precise geolocation, racial/ethnic origin, biometric data, and similar categories.
- "Consumer Health Data" (Washington MHMDA, Nevada SB 370, Connecticut CTDPA): personal information linked or reasonably linkable to a consumer and identifying past, present, or future physical or mental health status.
- "User Content": any content (including text, photos, videos, audio, reviews, posts, comments) that you submit, upload, transmit, or otherwise make available through the Services.
- "Processing": any operation performed on Personal Data.
- "User" / "Patient": any individual accessing the Services as a patient, family member, or information seeker.
- "Provider": any healthcare professional or facility listed on the platform.
- "Claimed Profile": a provider profile verified and actively managed by its rightful owner.
- "Unclaimed Profile": a provider profile created from publicly available sources.
- "De-Identified Data": data that has been irreversibly stripped of identifiers and cannot reasonably be linked back to an individual.
- "Aggregated Data": statistical data derived from multiple users with no individual identifiers.
2. Scope and Important Disclosures
2.1. We Are a Discovery Platform, Not a Healthcare Provider
- We do not provide medical advice, diagnosis, treatment, or prescriptions.
- We do not maintain medical records in a clinical sense.
- No doctor-patient relationship is formed by your use of the Services.
- We are not a licensed pharmacy, hospital, telemedicine provider, or insurance company.
2.2. HIPAA Position
- MediFinder is generally NOT a "Covered Entity" under HIPAA.
- Where MediFinder processes Protected Health Information (PHI) on behalf of a U.S. Covered Entity, MediFinder may operate as a "Business Associate" under a separately executed Business Associate Agreement (BAA), available upon request at [email protected] with subject "BAA Request".
- In all other contexts, health information you voluntarily share is protected under this Policy and applicable laws (state, federal, and international).
2.3. Voluntary Health Information
When you complete a Consultation Request, post in our Community, upload a video or photo, message a Provider, or use search features filtered by medical specialty or treatment, you may voluntarily share Health Data with us. This Policy explains how that data is handled and your rights regarding it.
3. Personal Data We Collect
3.1. Information You Provide Directly
Account Information
- Name, email address, phone number (optional), date of birth (for age verification)
- Gender (optional; used only for relevant provider matching)
- Password (stored as a one-way cryptographic hash; never in plaintext)
- Profile photo (optional)
- Preferred language, country, and region
Location Information
- City, region, country (for nearby provider search)
- Precise GPS location (mobile app only, with your explicit permission, used at the moment of search and not retained for tracking)
Health Data
- Medical specialty or treatment you are searching for
- Symptoms, conditions, or medical history voluntarily described in Consultation Requests
- Treatment preferences (budget, timeframe, location, language)
- Content voluntarily posted in our Community related to health
- Messages exchanged with Providers through the platform
- Health-related photos or videos you choose to upload
User-Generated Content (Photos, Videos, Posts)
- Photos and videos you upload to your profile, posts, or messages
- Metadata of uploaded files (file size, type, upload timestamp, technical specifications)
- EXIF data is stripped from uploaded media by default to protect your privacy
- Audio or video content of consultation requests where the feature is enabled
- Comments, reviews, ratings, community posts, and replies
Communication and Interaction Data
- Messages sent to Providers or to our support team
- Community posts, comments, reviews
- Provider ratings and feedback
- Support tickets and feedback submissions
Payment Information (Providers Only, When Paid Services Are Active)
- Billing name, address, and tax identifier for subscription invoicing
- Payment card details — handled exclusively by PCI-DSS compliant payment processors; MediFinder does not store full card numbers
3.2. Information Collected Automatically
- IP address and approximate geolocation derived from it
- Device type, operating system, browser type and version, screen resolution
- Mobile advertising identifiers (IDFA on iOS, Android Advertising ID), where you have not opted out via your device settings
- Pages viewed, clicks, search queries on the platform
- Session duration and interaction events
- Cookies, local storage, SDKs, pixels, and similar tracking technologies (see Section 14 for full details)
- Crash reports and performance telemetry
- Push notification tokens (mobile app only, where you enable notifications)
3.3. Information Received From Third Parties
- Social sign-in: profile information you authorize Google, Apple, or Facebook to share
- Payment processors: payment confirmation and fraud risk scores (for providers)
- Analytics partners: aggregated/anonymized usage statistics
- Publicly available sources (for Provider profiles): name, professional credentials, practice address, contact details published by government registries, professional associations, and public business listings
4. Legal Bases and Purposes of Processing
4.1. Performance of a Contract
Legal basis: GDPR Art. 6(1)(b); equivalents under other laws.
- Creating and managing your account
- Displaying providers matching your search criteria
- Routing your Consultation Requests to selected providers
- Hosting your User Content
- Delivering core platform functionality
4.2. Legitimate Interests
Legal basis: GDPR Art. 6(1)(f).
- Platform security, fraud prevention, abuse detection, and content moderation
- Service quality improvement, debugging, and analytics
- Automated content scanning for compliance with our Acceptable Use Policy (CSAM detection, malware scanning, copyright protection)
- Maintaining Unclaimed Profiles based on publicly available professional information, in the public interest of healthcare transparency
- Internal audit, compliance monitoring, and regulatory reporting
- Defending and pursuing legal claims
4.3. Explicit Consent
Legal basis: GDPR Art. 6(1)(a) + Art. 9(2)(a); KVKK m.5/1 + m.6/2.
- Processing Health Data you voluntarily provide via Consultation Requests, messaging, video, photo, or community posts
- Sharing Health Data with selected Providers to fulfill your request
- International transfer of your data outside your country of residence (where required)
- Marketing communications via email, SMS, or push notification
- Use of non-essential cookies (analytics, marketing)
- Precise GPS location access
- Camera, microphone, and photo library access (mobile app)
You may withdraw any consent at any time via your account settings or by emailing [email protected]. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
4.4. Legal Obligation
- Tax, accounting, and corporate record-keeping under Florida and US federal law
- Response to valid legal process (subpoenas, court orders, regulatory requests)
- Mandatory breach notifications under HIPAA, GDPR, MHMDA, state laws
- Mandatory reporting of child sexual abuse material (CSAM) under U.S. law (18 U.S.C. § 2258A) to the National Center for Missing & Exploited Children (NCMEC)
4.5. Vital Interests
- Protection of life or physical safety in medical emergencies when the data subject cannot provide consent
5. Special Treatment of Health Data
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Strict role-based access controls — only personnel with documented need-to-know
- Separate audit logs for every access to Health Data
- Data Protection Impact Assessment (DPIA) reviewed annually
- Mandatory privacy and security training for all employees handling Health Data
- Health Data is never used for third-party advertising
- Health Data is never sold to data brokers
- Health Data is only shared with Providers you have explicitly chosen or that the platform matches to your Consultation Request, with your consent
6. Use of De-Identified and Aggregated Data for Service Improvement and Health AI
6.1. Our Right to Use De-Identified Data
MediFinder may use, copy, modify, and process de-identified and aggregated data derived from User information (including Health Data) for the following purposes:
- Improving and developing the Services
- Developing new health-related features, products, and services, including artificial intelligence and machine learning health features (such as symptom checkers, provider matching algorithms, treatment recommendation engines, health content summarization, and personalized health insights)
- Conducting research and statistical analysis of health trends, healthcare access, and treatment outcomes
- Training and improving our internal machine learning models and AI systems
- Generating insights about healthcare needs across regions and demographics
- Producing aggregated reports for healthcare stakeholders, public health initiatives, or research collaborations
6.2. De-Identification Standards
De-identification is performed using methods consistent with HIPAA Safe Harbor (45 CFR § 164.514(b)(2)) and Expert Determination methods, GDPR Recital 26 anonymization standards, and KVKK anonymization guidelines. De-identified data cannot reasonably be linked back to you.
6.3. Use of Identifiable Personal Data for AI Training
MediFinder will not use your identifiable Personal Data (including identifiable Health Data) to train AI or machine learning models without your specific, informed consent. By default, your identifiable Personal Data is excluded from AI training datasets.
6.4. Your Right to Object
You may object to the use of even your de-identified or aggregated data for AI/ML training by emailing [email protected] with subject "AI Training Opt-Out". Where technically feasible, we will exclude your data from future training runs. We cannot remove your data from previously trained models, but new versions will exclude it where opt-out has been registered.
6.5. No Sale of Health Data for AI Training to Third Parties
MediFinder does not sell, license, or share Health Data with third parties for AI training purposes. Any internal AI/ML development uses de-identified data and is conducted within Yeshan Healthtech, LLC and its authorized service providers under contractual confidentiality.
7. How We Share Personal Data
7.1. With Healthcare Providers
When you submit a Consultation Request or message a Provider, we share with the selected Provider(s) the personal information necessary to fulfill your request. After this transfer, the Provider becomes an independent data controller and applies its own privacy practices and applicable laws.
7.2. With Service Providers (Data Processors)
We engage third parties under written contracts ensuring confidentiality and security:
- Cloud hosting (AWS, Google Cloud, Microsoft Azure)
- Video and image storage and content delivery networks
- Analytics (aggregated/anonymized data where possible)
- Payment processors (for providers when paid services are active)
- Email, SMS, and push notification delivery services
- Customer support tools
- Crash reporting and security monitoring
- Automated content moderation services (CSAM detection, malware scanning)
All data processors are bound by GDPR Art. 28 / KVKK m.12 compliant Data Processing Agreements. An up-to-date list of subprocessors is available at medifinder.com/subprocessors.
7.3. With Other Users (Public Information)
- Your community posts, comments, photos, and videos may be publicly visible (anonymous option available for community posts)
- Your provider reviews and ratings may be publicly visible (anonymous option available)
- Public profile information of Providers is visible to all users
7.4. Legal and Safety Disclosures
- In response to valid legal process
- To comply with applicable law
- To protect the rights, safety, and security of MediFinder, our users, or the public
- To detect, prevent, or investigate fraud, abuse, or violations of our Terms
- CSAM and other illegal content reports to law enforcement and NCMEC as required by law
7.5. Business Transfers
If Yeshan Healthtech, LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred. We will notify you and provide choices where required by law.
7.6. We Do Not Sell Personal Data
MediFinder does NOT sell Personal Data to third parties for monetary consideration. Sharing with Providers to fulfill your Consultation Request is not a "sale" — it is the core purpose of the Service. We do not engage in cross-context behavioral advertising using Health Data.
8. International Data Transfers
Yeshan Healthtech, LLC is a Florida (USA) entity operating a global platform. Your data may be transferred to and processed in the United States and other countries with different data protection standards than your country of residence.
- Primary processing and storage in the United States
- Cloud infrastructure distributed across multiple regions for performance and resilience
- Provider matches may involve cross-border data sharing
8.1. Safeguards
- EU/EEA and UK transfers: Standard Contractual Clauses (SCCs) approved by the European Commission, plus supplementary measures (encryption, access controls); UK International Data Transfer Agreement (IDTA) or UK Addendum where applicable
- EU-US Data Privacy Framework certification where applicable
- Turkey transfers: explicit consent, KVKK Board-approved standard contracts, or other lawful mechanisms under KVKK m.9
- Other jurisdictions: equivalent contractual safeguards consistent with local laws
9. Data Retention
- Active account data: retained while your account is active
- Closed account data: retained for up to 12 months after closure for legal and dispute-resolution purposes
- Consultation Requests and Health Data: retained for up to 24 months (you may request earlier deletion)
- User Content (photos, videos, posts): retained until you delete them or close your account; cached references and search engine archives may persist for a commercially reasonable period (typically up to 12 months) after deletion
- Server backup copies of deleted User Content may be retained in inaccessible storage for up to 90 days, after which they are permanently deleted
- Support and communication records: retained for 3 years
- Payment and tax records: retained for 7 years (Florida and US federal law)
- Security logs: retained for 12-24 months
- Content moderation records: retained for 24 months
- Provider profile data from public sources: retained as long as the provider remains in active practice
10. Profile Lifecycle (Provider-Specific)
10.1. Unclaimed Profiles
- Created from publicly available information (government registries, professional associations, public business listings)
- Display a clear banner indicating the profile has not yet been claimed or verified
- Limited content: name, specialty, credentials, public contact information, address
- No patient reviews or interactive features until claimed
- Legal basis: legitimate interest in healthcare transparency; data manifestly made public
10.2. Claimed Profiles
- Profile becomes "Claimed" once the rightful professional verifies identity and credentials
- Full feature set unlocks
- The provider becomes an independent data controller for the content they add
10.3. Account Closure
- When a Claimed Profile owner closes their account, the profile reverts to Unclaimed status
- Provider-added content (custom photos, marketing copy, custom hours) is removed
- Public-source professional information remains, consistent with our legitimate interest basis
- A new claim request may be initiated by the same or a different rightful owner at any time
10.4. Complete Profile Removal
Granted upon valid request when one of the following applies:
- Demonstrated identity error or duplicate profile
- Loss of professional license, retirement, or cessation of practice
- Death of the professional (request by authorized representative)
- Court order or regulatory directive
- Other valid GDPR Art. 17 / KVKK m.7 grounds where MediFinder's legitimate interests do not override
11. Data Security
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Password hashing using bcrypt or Argon2
- Optional two-factor authentication (2FA)
- Role-based access control with need-to-know enforcement
- Regular security audits, vulnerability scans, and penetration tests
- Mandatory privacy/security training for all personnel
- Incident detection, response, and notification procedures
- Encrypted backups and disaster recovery protocols
- Automated content scanning for malware, CSAM, and policy violations
11.1. Breach Notification
- Supervisory authority within 72 hours where required (GDPR, KVKK)
- Affected individuals where the breach is likely to result in high risk to their rights
- FTC Health Breach Notification Rule (60 days for non-HIPAA health information breaches affecting 500+ individuals in the US)
- US state breach notification laws (including Washington 30-day rule)
12. Your Privacy Rights (All Users)
- Right to Access — to know what Personal Data we hold about you
- Right to Rectification — to correct inaccurate or incomplete data
- Right to Erasure ("Right to Be Forgotten") — subject to legal grounds and balancing tests
- Right to Restriction of Processing
- Right to Data Portability — receive your data in structured, machine-readable format
- Right to Object to certain types of processing based on legitimate interests
- Right to Withdraw Consent at any time
- Right Not to Be Subject to Automated Decision-Making with significant effects
- Right to Object to AI/ML training using your data (see Section 6.4)
- Right to Lodge a Complaint with a supervisory authority
12.1. How to Exercise Your Rights
Email us at [email protected] using the appropriate subject line:
- "GDPR Data Subject Request" — for EU/EEA residents
- "KVKK Veri Sahibi Talebi" — for Turkey residents
- "CCPA Privacy Request" — for California residents
- "Consumer Health Data Request" — for Washington residents (Consumer Health Data)
- "LGPD Solicitacao" — for Brazil residents
- "PIPEDA Privacy Request" — for Canada residents
- "AI Training Opt-Out" — to opt out of AI/ML training use
- "Privacy Inquiry" — for all other privacy inquiries
Alternatively, you can submit requests by postal mail to: Yeshan Healthtech, LLC, 5205 Congress Ave APT 524, Boca Raton, Florida 33487-3905, United States.
Many privacy controls (data download, account deletion, consent management) are available directly within your account settings on the web and mobile app.
We respond within applicable legal timeframes (30 days under GDPR/KVKK, 45 days under CCPA/MHMDA). We may need to verify your identity to protect against fraudulent requests. There is no fee unless requests are manifestly unfounded or excessive.
13. Children's Privacy
- MediFinder is not intended for individuals under 16 (or the applicable digital-consent age in your country)
- United States: We comply with COPPA — we do not knowingly collect Personal Data from children under 13
- European Union: GDPR Art. 8 digital-consent age is 16 unless your Member State sets a lower age (13-16)
- Turkey: parental/legal-guardian consent required for minors under 18
13.1. Minors in User Content
If you upload photos or videos that include minors, you must obtain written consent from the minor's parent or legal guardian. MediFinder may remove any content depicting minors that lacks documented consent. Content involving the sexual exploitation of minors is strictly prohibited, will be removed immediately, and will be reported to NCMEC and relevant law enforcement authorities as required by 18 U.S.C. § 2258A and equivalent international laws.
If you believe a child has provided us Personal Data without proper consent, please contact [email protected] with subject "Privacy Inquiry" and we will promptly investigate and delete such data.
14. Cookies and Tracking Technologies
14.1. What Are Cookies
Cookies are small text files placed on your device. Similar technologies include pixel tags, web beacons, local storage, session storage, mobile SDKs, and device identifiers (IDFA, Android Advertising ID).
14.2. Why We Use Cookies and Trackers
- Enable core functionality (e.g., keeping you logged in)
- Remember your preferences (language, country, region, accessibility)
- Measure and improve performance of the Services
- Detect and prevent fraud, abuse, and security threats
- Understand how users interact with our platform (aggregated analytics)
- Deliver and measure marketing communications (only with your consent)
14.3. Categories of Cookies
Strictly Necessary (always active)
- Authentication, security, session, load-balancing, consent-state cookies
Performance and Analytics (requires consent in EU/UK/TR/BR)
- Google Analytics with IP anonymization, Sentry/Crashlytics, internal performance metrics
Functional (requires consent in some regions)
- Language and region preferences, recently viewed providers, saved search filters, accessibility settings
Marketing (requires consent)
- Facebook Pixel, Google Ads conversion, LinkedIn Insight Tag
We do NOT use marketing cookies to track Health Data or profile users based on their health interests.
14.4. Mobile Application Tracking
- Device identifiers (IDFA on iOS, Android Advertising ID) — only with App Tracking Transparency permission on iOS 14.5+
- In-app analytics SDKs
- Crash reporting and performance monitoring SDKs
- Push notification tokens (if enabled by you)
14.5. Managing Your Preferences
- In-platform Cookie Settings panel: accept all, reject all non-essential, or customize
- Browser controls (Chrome, Firefox, Safari, Edge)
- Mobile device settings (iOS Tracking, Android Ad ID reset)
- Global Privacy Control (GPC) signal honored as a valid opt-out under CCPA/CPRA, Colorado, and Connecticut privacy laws
- Industry opt-out tools: NAI (optout.networkadvertising.org), DAA (optout.aboutads.info), EDAA (youronlinechoices.com)
14.6. Detailed Cookie Inventory
A complete, real-time list of cookies in use is available within the in-platform Cookie Settings panel. The list includes cookie name, purpose, category, duration, and provider.
15. Automated Decision-Making and Profiling
- No decisions producing legal effects or similarly significant effects on you are made solely by automated means
- You may request human review of automated matching outputs
- Profiling is limited to platform-internal recommendation features and is not used to make decisions about insurance, employment, or other significant outcomes
- Automated content moderation (CSAM detection, malware scanning, spam detection) operates on uploaded content; you may appeal automated moderation decisions via [email protected] with subject "Appeal Request"
16. User-Generated Content and Your Responsibilities
You are solely and fully responsible for all content you post, share, transmit, upload, or otherwise make available through the Services (including text, photos, videos, audio, community posts, comments, reviews, messages to Providers, and information shared in Consultation Requests).
- You must own or have all necessary rights, licenses, and permissions to share the content
- Content must not violate the rights of any third party
- You must not share Personal Data or Health Data of any other person without their valid, documented consent
- Content involving minors requires documented parental/guardian consent
- Content must be accurate, lawful, and not misleading
- You acknowledge that MediFinder may scan uploaded content automatically for compliance with our policies and applicable law
MediFinder acts as a host platform and benefits from intermediary-liability protections under Section 230 of the U.S. Communications Decency Act, the EU Digital Services Act (Articles 4-6), KVKK, and Turkish Law No. 5651. Detailed rules for user content are set out in our Acceptable Use Policy and Content & Copyright Policy.
17. Indemnification
You agree to indemnify, defend, and hold harmless Yeshan Healthtech, LLC, its affiliates, officers, directors, employees, and agents from any claims arising out of:
- Your use of the Services
- Your User Content
- Your violation of this Policy, our Terms of Service, or any applicable law
- Your violation of any third-party rights
18. Third-Party Links and Services
The Services may contain links to third-party websites, apps, or services not operated by MediFinder. We are not responsible for their content or privacy practices.
19. Regional Rights and Disclosures
19.1. European Union / EEA — GDPR
If you are in the EU/EEA, your processing is subject to Regulation (EU) 2016/679 (GDPR). In addition to the rights in Section 12, you have the right to:
- Lodge a complaint with your national supervisory authority
- Request information about international data transfers and applicable safeguards
- Receive copies of Standard Contractual Clauses upon request to [email protected]
Health Data is processed as Special Category Data under Article 9. Our legal bases are: your explicit consent (Art. 9(2)(a)); data manifestly made public by the data subject for Unclaimed Provider Profiles (Art. 9(2)(e)); vital interests in emergencies (Art. 9(2)(c)); and the establishment, exercise, or defense of legal claims (Art. 9(2)(f)).
Until an EU Representative under Article 27 is designated, all data-subject requests are handled directly by our team at [email protected] with subject "GDPR Data Subject Request", which acts as your single point of contact for EU GDPR matters.
19.2. United Kingdom — UK GDPR
If you are in the UK, your processing is subject to the UK GDPR and the Data Protection Act 2018. Your rights mirror those described under EU GDPR in Section 19.1.
- Supervisory authority: Information Commissioner's Office (ICO) at ico.org.uk
- Until a UK Representative under Article 27 is designated, contact [email protected] with subject "GDPR Data Subject Request"
- International transfers from the UK rely on the UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs
19.3. Turkey — KVKK
Türkiye'de ikamet eden kullanıcılar için ayrıntılı KVKK Aydınlatma Metni ayrı bir belgede yayımlanmıştır ve medifinder.com/kvkk adresinde erişilebilirdir. KVKK kapsamında veri sorumlusu Yeshan Healthtech, LLC'dir. Kanun'un 11. maddesi uyarınca hak taleplerinizi [email protected] adresine "KVKK Veri Sahibi Talebi" konu satırı ile iletebilirsiniz. VERBİS kaydı ve KVKK Temsilcisi atama süreçleri Türkiye'deki operasyonel ölçeğimizin Kanun'da belirtilen eşikleri aştığı tarihten itibaren tamamlanacaktır.
19.4. California — CCPA / CPRA
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following rights:
- Right to know what Personal Information we collect, use, disclose, and sell/share
- Right to delete Personal Information
- Right to correct inaccurate Personal Information
- Right to opt out of the sale or sharing of Personal Information (we do not sell or share)
- Right to limit use and disclosure of Sensitive Personal Information
- Right to non-discrimination for exercising your rights
Categories of Personal Information collected in the past 12 months: identifiers, customer records, commercial information, internet activity, geolocation, sensory data (photos, video, audio), professional information, inferences, and sensitive personal information (health data, precise geolocation).
To exercise your rights: email [email protected] with subject "CCPA Privacy Request", use the in-platform Privacy Choices panel, or rely on the Global Privacy Control (GPC) signal which we honor. Authorized agents may submit requests with proof of authorization. We respond within 45 days (extendable by 45 days where reasonably necessary).
19.5. Washington State — MHMDA
Washington State residents are protected under the My Health My Data Act (MHMDA), RCW 19.373. A separate Consumer Health Data Privacy Notice has been published and is available at medifinder.com/consumer-health-privacy. Exercise your MHMDA rights by emailing [email protected] with subject "Consumer Health Data Request".
Key MHMDA points: We do not sell Consumer Health Data. We do not engage in geofencing of healthcare facilities. You have rights to confirm, access, withdraw consent, delete, and appeal. The private right of action allows damages including up to USD 25,000 per violation under the Washington Consumer Protection Act.
19.6. Brazil — LGPD
Para usuários no Brasil, a Lei Geral de Proteção de Dados (LGPD), Lei nº 13.709/2018, aplica-se ao tratamento de dados pessoais. Você possui os direitos previstos no Art. 18. Dados de saúde são tratados como dados pessoais sensíveis (Art. 5, II). Exercício de direitos: [email protected] com o assunto "LGPD Solicitacao".
19.7. Canada — PIPEDA and Quebec Law 25
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws apply. Quebec residents are additionally protected by Quebec's Law 25.
- Right to access, correction, and withdrawal of consent
- Right to data portability (Quebec Law 25)
- Right to be informed of automated decision-making (Quebec Law 25)
- Right to file a complaint with the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec
Exercise your rights at [email protected] with subject "PIPEDA Privacy Request".
20. Changes to This Policy
- Material changes will be communicated via email and in-platform notifications at least 30 days before taking effect
- Updated versions will be published at medifinder.com/privacy with a clear version indicator
- For significant changes affecting your rights, we may require renewed acceptance
- Continued use after the effective date constitutes acceptance
21. Governing Law and Disputes
This Policy is governed by the laws of the State of Florida, USA, without regard to its conflict-of-laws principles. Disputes shall be resolved as set forth in our Terms of Service, except where mandatory consumer protection laws of your country of residence grant non-waivable rights to local courts.
Nothing in this Section limits your right to lodge complaints with your local data protection authority.
22. Language
This Policy is published in English as the master version. Translations are provided for convenience and accessibility. Where local law requires a translation to be legally binding, the local-language version shall govern for the affected jurisdiction (the Turkish KVKK Aydınlatma Metni governs for Turkish residents). In all other cases, the English version prevails in case of inconsistency.
23. Contact
- All inquiries: [email protected]
- Use the appropriate subject line per Section 12.1
- Postal mail: Yeshan Healthtech, LLC, 5205 Congress Ave APT 524, Boca Raton, Florida 33487-3905, United States
Yeshan Healthtech, LLC (MediFinder) — Privacy Policy
medifinder.com · [email protected] · Published 19 May 2026