Privacy Policy
Harbour Direct Primary Care Inc. Website
Privacy is a fundamental right. This Privacy Notice explains how Harbour Direct Primary Care, Inc. (“we,” “our,” or “us”) collects, uses, stores, and protects the personal information of visitors (“you”) to this website (the “Site”). It also describes your privacy rights, including rights under Rhode Island law.
⸻
1. Consent
We only collect, use, or disclose your personal information as permitted by applicable law or with your consent. You may withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal. Withdrawal may limit our ability to provide you with certain services or consider you for opportunities.
⸻
2. What is Personal Information
“Personal Information” broadly means information that identifies or could reasonably be linked to an individual.
For Rhode Island residents, “Personal Information” also specifically includes (R.I. Gen. Laws § 11-49.3):
• First name or initial and last name combined with:
• Social Security number;
• Driver’s license number or Rhode Island ID number;
• Financial account, credit, or debit card number with any required code or password;
• Medical or health information;
• Email address with password or security Q&A.
⸻
3. Your Privacy Rights
No matter where you live, you have rights regarding your Personal Information:
• Right to be Informed – know what we collect and why.
• Right to Access – obtain a copy of your Personal Information.
• Right to Rectification – request corrections if inaccurate.
• Right to Deletion (“Right to be Forgotten”) – request erasure of information not required for legal/business purposes.
• Right to Restrict Processing – request that we limit use of your data.
• Right to Data Portability – receive information in a portable format.
• Right to Object – stop certain types of processing.
• Right to Non-Discrimination – no unfair treatment for exercising rights.
• Right to Appeal – appeal our response to a privacy request.
• Right to Opt-Out – decline sale of data or targeted advertising.
• Right to Lodge a Complaint – contact a regulator such as the Rhode Island Attorney General (if you are a RI resident).
To exercise these rights, contact us at drregan@wendyreganmd.com or 401-560-4156.
⸻
4. Why We Collect Personal Information
We collect only what is necessary to:
• Respond to your inquiries or job applications;
• Provide and improve our services;
• Advertise or promote services;
• Conduct analytics to understand Site usage.
⸻
5. How We Collect Personal Information
We collect information:
• When you visit or interact with our Site;
• Through communications, applications, or social media;
• Through cookies, device identifiers, and similar tracking tools.
See our Cookies Notice for details.
⸻
6. Who is the Data Controller?
Harbour Direct Primary Care, Inc. is the data controller responsible for your Personal Information.
⸻
7. Legal Basis for Processing
We process Personal Information for:
• Contract performance;
• Compliance with legal obligations;
• Our legitimate interests (business operations, fraud prevention, site security).
⸻
8. Categories of Information Collected
We may collect:
• Identifiers (name, address, email, phone);
• Device/Internet activity (IP, device ID, browsing behavior);
• Employment-related information (applications, work history).
⸻
9. Sharing Personal Information
We do not sell your data. We may share it:
• With trusted vendors who provide services (under contract);
• As required by law or legal proceedings;
• To protect our legal rights;
• In the event of a business transfer or bankruptcy.
⸻
10. How We Protect Your Information
Harbour Direct Primary Care, Inc. maintains a written information security program as required by Rhode Island law. This includes administrative, technical, and physical safeguards such as:
• Encryption of data in transit and at rest where feasible;
• Access controls and employee training;
• Regular review of risks and safeguards.
⸻
11. Your Rights to Access, Portability & Deletion
You may request access to, or deletion of, your information. We will verify your identity before fulfilling requests. We may deny requests where disclosure would violate another’s privacy, legal privilege, or law.
⸻
12. Data Retention & Secure Disposal
We retain data only as long as needed for business or legal purposes. When no longer required, Personal Information is securely destroyed, erased, or made unreadable in compliance with Rhode Island law.
⸻
13. Breach Notification (Rhode Island Residents)
If a security breach compromises your Personal Information, we will notify you as soon as practicable, and no later than 45 days after confirmation, unless law enforcement delays notice.
• If 500+ Rhode Island residents are affected, we will also notify the Rhode Island Attorney General and the major credit reporting agencies.
• Notices will describe the breach, the type of data involved, steps taken, and how you can protect yourself.
⸻
14. Changes to this Privacy Notice
We may update this Notice from time to time. Changes will be posted on this page with an updated effective date.
⸻
15. Contact Us
If you have questions or wish to exercise your rights, contact us:
Harbour Direct Primary Care, Inc.
Email: drregan@wendyreganmd.com
Phone: 401-560-4156
Address: 53 Narragansett Avenue, Jamestown, RI 02835
Attention: Data Protection Officer
⸻