PRIVACY POLICY
Last Updated: February 28, 2025
Policy Statement
By selecting CoventBridge (USA) Inc. (“CoventBridge”) as a vendor, our clients demonstrate their confidence in our reputation as a leading provider of quality medical information, risk management and investigation services to the insurance, legal, clinical and business communities. In return, CoventBridge values this trust and is committed to maintaining the privacy and security of the information entrusted to us. CoventBridge has established the following privacy policy to demonstrate our dedication to safeguarding this information and maintaining transparency in how it is handled. CoventBridge understands that protecting client information is critical, and we are committed to ensuring confidentiality and data security at all stages of service delivery.
Types of Information Collected
CoventBridge is authorized by clients to act as their representatives in obtaining information on individuals regarding the following:
- Personal Identifiable Information, which could be any information that can be used to identify an individual, including but not limited to name, email address, phone number, address, and social security number.
- Protected Health Information, which could be any health information that can be linked to an individual, including but not limited to their medical history, health insurance information, prescription information, test results, and healthcare provider information.
- Family History
- Lifestyle Habits including information regarding the individual’s lifestyle choices, such as diet, exercise, smoking, and use of alcohol and drugs
- General Reputation including publicly known information about the individual’s character or reputation in the community
- Driving Records
- Marital Status
- Death Records
- Civil and Criminal Court Records
- Employment History
- Financial Information
- Other Insurance Coverage
- Participation in Hazardous Activities
Sources of such information may include governmental agencies, medical facilities, independent consumer reporting agencies, and personal and business references provided by the subject.
Server Data
CoventBridge Web Servers automatically collect Internet Protocol (IP) addresses which are used solely for reporting demographic information, number of visits, and troubleshooting communications. Authentication credentials are also logged to comply with auditing requirements and assist in investigating customer-initiated service requests. As CoventBridge upgrades and maintains its systems and services, this policy may be modified to reflect any changes or improvements.
Use of Information
CoventBridge respects the privacy of individuals while obtaining information for legitimate business purposes and uses the information only for those purposes. CoventBridge collects, processes, and shares personal information in order to provide a wide range of investigative and service offerings to its clients.
CoventBridge processes personal information based on several grounds including where we have a contractual relationship with an individual or entity. This includes providing agreed-upon services and processing personal information to fulfill the terms of the contract. Additionally, the information is used in our, or a third party’s, legitimate business interests which may include disclosing such information pursuant to appropriate written authorizations to clients for the purposes of their underwriting and servicing of insurance policies, and other legitimate purposes authorized by law. CoventBridge handles such information in accordance with its clients’ directions, written authorizations, contracts with clients, and applicable law. CoventBridge may also process personal information to comply with legal obligations, such as responding to regulatory requirements, subpoenas, or legal inquiries, and defending against legal claims. CoventBridge does not share personal information it obtains from or for clients with others, except for the purpose of delivering contracted services.
Protecting Information
CoventBridge maintains security policies and practices in its facilities and systems to protect client information from unauthorized access and inappropriate disclosure, alteration or destruction. These security measures include encryption, physical access controls, and other appropriate technologies. CoventBridge continually reviews and enhances security systems as necessary. Personnel who fail to uphold the confidentiality of private information are subject to disciplinary process. All personnel are required to acknowledge receipt and understanding of CoventBridge’s policies and procedures regarding confidentiality obligations. CoventBridge does not provide private information to the general public or compile mailing lists or consumer marketing data from information received from clients. Additionally, CoventBridge does not alter or modify information obtained from third parties, as such information is provided as-is from external sources.
Cookies
CoventBridge makes use of both session and persistent cookies on websites it owns and operates directly as well as through third party partners. Cookies are small pieces of data that are stored by the user’s web browser on their device. These cookies enhance the user’s experience by remembering login credentials and viewing preferences. On some websites under CoventBridge’s control, user browsing and purchasing behavior may also be. However, CoventBridge ensures that no medical or health-related information is ever stored in cookie data.
Data Retention
CoventBridge retains information for as long as necessary to fulfill the purposes outlined in the relevant contracts with its clients and for the duration of the contractual obligations. Information may also be retained for longer periods when necessary to comply with legal and lawful obligations. This includes retaining data for audit purposes, legal compliance, and operational needs.
Opting Out
CoventBridge does not use the information it obtains on behalf of its clients outside of what is stated within this policy. If a subject desires to opt out of having their information used for any purpose, they should address this with CoventBridge’s client when providing authorization to release information to CoventBridge. If CoventBridge directly inquires with a subject, they will have the option to opt-out by simply declining to provide the requested information. In all other instances, CoventBridge only collects and discloses information as directed by the subject’s written authorization obtained by CoventBridge or our client.
Notice to all Users
The systems are restricted solely to authorized CoventBridge users and may be monitored for administrative and security reasons. All users expressly consent to such monitoring. Any use of the system must be in compliance with all CoventBridge policies and applicable laws. Unauthorized users or any unauthorized use will subject the user to criminal and civil penalties under applicable law.
Direct any questions related to the Privacy Policy to Privacy@coventbridge.com