Privacy Policy

Privacy Policy

Effective Date: January 8, 2025

Our Privacy Commitment: Novobeing is committed to protecting your privacy and the privacy of your clients. We have designed our platform with privacy-by-design principles, ensuring that we do not collect, store, or have access to your clients’ personal health information (PHI) or personally identifiable information (PII).

1. Introduction

This Privacy Policy explains how Novobeing Inc. ("Novobeing," "we," "us," or "our") collects, uses, protects, and shares information when you use our therapeutic VR platform. This policy applies to mental health professionals and organizations using our services.

2. Information We Collect

2.1 Information We DO NOT Collect

  • Personal Health Information (PHI)
  • Personally Identifiable Information (PII) of your clients
  • Therapy session content or recordings
  • Client names, contact info, demographics, or medical records
  • Financial or payment information of your clients

2.2 Information We Do Collect

  • Account Information: Your name, email, practice info, billing address
  • Device Information: Device ID, software version, hardware specs
  • Usage Analytics: Session duration, experiences used, performance data
  • Technical Data: IP address, browser type, operating system

3. How We Use Information

  • Service delivery and access
  • Technical support & troubleshooting
  • Platform improvement & research (anonymized)
  • Security & fraud prevention
  • Billing and account administration
  • Legal and regulatory compliance

4. Data Sharing and Disclosure

We share only minimal information with trusted providers:

  • Meta (device platform services)
  • Google Workspace (email/productivity)
  • Feeling Digital (software development)
  • Payment processors (billing)
  • Cloud hosting providers

We may also disclose information if required by law, or as part of a business transfer (e.g., merger, acquisition).

5. Data Security

We maintain enterprise-grade safeguards aligned with HIPAA, including:

  • Encryption in transit and at rest
  • Role-based access controls & MFA
  • Firewalls and intrusion detection
  • Security training and background checks
  • Incident response procedures

6. Data Retention

  • Account Information: Kept during active use + 7 years
  • Usage Analytics: Anonymized, may be retained indefinitely
  • Technical Logs: Retained for 90 days
  • Billing Records: Retained for 7 years

7. Your Rights and Choices

You may request access, correction, deletion, or a portable copy of your data. You can manage email preferences or opt out of non-essential analytics by contacting us.

8. International Transfers

Your data may be processed in the United States or other jurisdictions with appropriate safeguards (e.g., standard contractual clauses, adequacy decisions).

9. Children’s Privacy

Our services are for professionals only and not intended for direct use by individuals under 18.

10. Cookies and Tracking

We use minimal cookies and analytics tools to improve performance. You can manage cookies via your browser settings.

11. Changes to this Policy

We may update this Policy. Material changes will be notified via email or prominent notice on our platform. Continued use constitutes acceptance.

12. Contact

Privacy Officer
Novobeing Inc.
100 Burlington Woods Dr., Suite 1030
Burlington, MA, USA
Email: hello@novobeing.com

13. State & Regional Rights

California Residents (CCPA)

  • Right to know what personal information we collect
  • Right to delete personal information
  • Right to opt-out of sale (we do not sell data)
  • Right to non-discrimination

European Residents (GDPR)

  • Right to access, rectification, erasure, and portability
  • Right to restrict or object to processing
  • Right to lodge a complaint with supervisory authorities