YOUR CALIFORNIA PRIVACY RIGHTS
Effective Date: September 15, 2026
Last Updated: September 15, 2026
Version: 1.1 (supersedes v1.0 dated 2026-05-18)
This California Privacy Rights Notice supplements, and forms part of, the emotilink Privacy Policy available at www.emotilink.com. It applies only to California residents and describes your rights under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (together, “CCPA/CPRA”), and how emotilink, LLC (“emotilink,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes your personal information.
Capitalized terms not defined in this Notice have the meaning given in the CCPA/CPRA or the Privacy Policy.
1. Notice at Collection
The following table lists the categories of personal information emotilink has collected about California residents in the preceding twelve (12) months, the purposes for which we collect and use such personal information, and the categories of third parties to whom we disclose it for a business purpose.
| Category (CCPA/CPRA) | Examples | Collected? | Business Purpose | Disclosed To |
|---|---|---|---|---|
| Identifiers | Name, email address, telephone number, account username, IP address, device identifier | Yes | Account creation, authentication, appointment scheduling, billing, communications, security | Service providers (Microsoft Azure for hosting, Finix for payments, Twilio for real-time communication); Providers (display name only); legal authorities as required |
| Personal information categories listed in Cal. Civ. Code § 1798.80(e) (Customer Records) | Name, address, telephone number, payment card information | Yes | Account creation, billing, communications, emergency response | Service providers; Providers (limited to display name and state unless emergency); legal authorities as required |
| Protected classification characteristics under California or federal law | Age (only that User is over 18) | Yes (limited) | Age verification | Service providers only |
| Commercial information | Records of Provider sessions purchased, scheduling history, payment history | Yes | Service delivery, billing, record retention per HIPAA and state law | Service providers; Providers (limited); legal authorities as required |
| Biometric information | None collected | No | N/A | N/A |
| Internet or other electronic network activity information | Server log files (date, time, originating IP, in-app activity) | Yes | Security, debugging, performance monitoring | Service providers only |
| Geolocation data | Precise GPS location (accessed only in emergency situations as described in the Privacy Policy) | Yes (emergency only) | Emergency response | Provider initiating emergency report; emergency services as appropriate |
| Sensory data | Audio and video transmitted during a telecounseling session (not recorded or stored by emotilink; flows peer-to-peer between User and Provider devices) | Transmitted, not collected/stored | Real-time session delivery | Provider only; not retained by emotilink |
| Professional or employment-related information | None collected from Users | No | N/A | N/A |
| Education information | None collected | No | N/A | N/A |
| Inferences drawn from the above | None | No | N/A | N/A |
| Sensitive Personal Information (defined below) | Account login credentials; precise geolocation (emergency only); health information (including the fact that a User has sought or received telemental health services) | Yes | Account access, emergency response, service delivery | Service providers; Providers (limited); legal authorities as required |
“Sensitive Personal Information” under CCPA/CPRA includes account credentials, precise geolocation, and information concerning a consumer’s health. emotilink uses Sensitive Personal Information only for the purposes permitted under California Civil Code § 1798.121(a) — that is, for purposes necessary to perform the services we provide, to ensure security and integrity, to detect security incidents, to prevent fraud, and as otherwise permitted by regulations adopted by the California Privacy Protection Agency. We do not use Sensitive Personal Information for purposes that would trigger your right to limit its use and disclosure.
2. Sources of Personal Information
We collect personal information from the following sources:
(a) Directly from you — when you create an account, schedule appointments, make payments, or communicate with us;
(b) Automatically from your device — through your interaction with the App and our website (including server logs);
(c) From Providers — limited information conveyed in connection with appointments or emergency reports;
(d) From service providers — payment confirmation and processing status from Finix; connection-routing metadata from Twilio; infrastructure logs from Microsoft Azure.
3. Sale and Sharing of Personal Information
emotilink does not “sell” your personal information, as that term is defined under CCPA/CPRA.
emotilink does not “share” your personal information for cross-context behavioral advertising, as that term is defined under CCPA/CPRA.
emotilink does not have actual knowledge that it sells or shares the personal information of consumers under the age of sixteen (16).
Because we do not sell or share personal information, you do not need to submit a request to opt-out of sale or sharing. We have nevertheless provided a “Do Not Sell or Share My Personal Information” link on our website footer to reflect our practice and to comply with the CCPA/CPRA’s notice requirements.
4. Retention of Personal Information
We retain each category of personal information for the period reasonably necessary to provide our services and to comply with applicable legal, accounting, or reporting requirements. The specific retention periods are:
| Category | Retention Period | Basis |
|---|---|---|
| Account credentials and contact information | While account is active; minimum 10 years from last Provider interaction if any appointment was requested | HIPAA and state mental-health record retention requirements; emotilink Business Associate Agreements with Providers |
| Scheduling and session history | Minimum 10 years from last Provider interaction | Same |
| Payment records | 7 years | Tax recordkeeping and dispute resolution |
| Server logs containing personal identifiers | 13 months | Security, debugging, performance; de-identified logs retained indefinitely |
| Communications with emotilink | 10 years | Customer service, legal, and regulatory recordkeeping |
| Emergency information | Retained only as part of provider-initiated emergency report; retention thereafter governed by HIPAA and applicable state law | Emergency response; legal recordkeeping |
| De-identified information | Indefinitely | De-identified information is not subject to the CCPA/CPRA |
After the applicable retention period, personal information is securely deleted or de-identified.
5. Your California Privacy Rights
If you are a California resident, you have the following rights under CCPA/CPRA:
5.1 Right to Know
You have the right to request that we disclose to you (a) the categories of personal information we have collected about you; (b) the categories of sources from which the personal information was collected; (c) the business or commercial purposes for collecting, selling, or sharing the personal information; (d) the categories of third parties to whom we disclose the personal information; and (e) the specific pieces of personal information we have collected about you.
We will provide this information for the twelve (12) months preceding your request, or for a longer period if you request and we are able to do so without unreasonable burden.
5.2 Right to Delete
You have the right to request that we delete personal information we have collected from you. There are exceptions to this right — for example, we may not delete information necessary to complete a transaction, comply with a legal obligation (including HIPAA, mental-health record retention laws, and tax laws), detect security incidents, or that is otherwise exempt under the CCPA/CPRA.
Important: Information that constitutes Protected Health Information (“PHI”) under HIPAA is excluded from the CCPA/CPRA’s deletion right. Most of the information collected about Users who have requested or attended appointments with Providers will constitute PHI and is subject to HIPAA’s separate access, amendment, and accounting rules, which we honor under the HIPAA Notice of Privacy Practices provided by your Provider.
5.3 Right to Correct
You have the right to request that we correct inaccurate personal information we maintain about you. We may, in our discretion, ask you to provide documentation supporting the requested correction.
5.4 Right to Opt-Out of Sale or Sharing
As stated above, we do not sell or share personal information. You may nevertheless submit a request through the “Do Not Sell or Share My Personal Information” link, and we will confirm that no sale or sharing occurs with respect to your information.
5.5 Right to Limit Use and Disclosure of Sensitive Personal Information
We use Sensitive Personal Information only for purposes permitted under California Civil Code § 1798.121(a) — namely, to perform our services, ensure security and integrity, prevent fraud, and as otherwise permitted by regulation. Because we do not use Sensitive Personal Information beyond these permitted purposes, this right is not triggered by our processing. You may nevertheless submit a request to limit, and we will confirm that no extended use occurs.
5.6 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you services, charge you different prices, provide you a different level or quality of services, or suggest that you will receive any of the foregoing for exercising your rights.
5.7 Right to Appeal
If we decline to take action on a request you submit, you may appeal our decision by emailing info@emotilink.com with the subject line “Privacy Appeal.” We will respond to your appeal within sixty (60) days.
6. How to Exercise Your Rights
To submit a request to exercise any of the rights described above, you may:
(a) Submit a request through the App: Tap Settings → Privacy → Submit Privacy Request.
(b) Email us: info@emotilink.com with the subject line “California Privacy Request.”
(c) Call us: 312-554-5812.
(d) Mail us: emotilink, LLC, Attn: Privacy Officer, 222 W Merchandise Mart Plaza, Suite 1230, Chicago, IL 60654.
7. Verification of Requests
For your protection, we must verify your identity before responding to a request. Verification requirements depend on the nature of the request and the sensitivity of the information involved:
- For requests to know categories or to delete non-sensitive information: We will match at least two pieces of personal information you provide against information we already have (for example, your account email and a recent appointment date).
- For requests to know specific pieces of personal information or to delete sensitive information: We will require a signed declaration under penalty of perjury and may request additional information to verify identity.
If we cannot verify your identity, we will deny the request and explain why.
8. Authorized Agents
You may designate an authorized agent to submit a request on your behalf. The agent must provide written authorization signed by you, and we may require you to verify your identity directly with us before we respond to the agent. We will not require verification through an agent if you have provided the agent with a power of attorney pursuant to California Probate Code §§ 4000 to 4465.
9. Response Timeline
We will acknowledge your request within ten (10) business days and respond substantively within forty-five (45) calendar days. We may extend the response period by an additional forty-five (45) calendar days when reasonably necessary, in which case we will inform you of the extension and the reason for it.
10. Categories of Personal Information Disclosed for a Business Purpose
In the preceding twelve (12) months, we have disclosed the following categories of personal information for a business purpose:
- To Microsoft Azure (cloud hosting): Identifiers; customer-records data; commercial information; internet activity; sensitive personal information (account credentials). Microsoft is a business associate of emotilink under the Microsoft HIPAA BAA.
- To Finix Payments, Inc. (payment processing): Identifiers; customer-records data (name, billing address); payment card information.
- To Twilio, Inc. (real-time video and audio communication): Connection-routing metadata only. Real-time session content (audio and video) flows peer-to-peer between User and Provider devices and is not transmitted through Twilio’s media infrastructure.
- To Providers (limited): User display name and state of residence; in emergencies only, identifying and location information necessary to facilitate emergency response.
- To legal and regulatory authorities as required by law.
We do not disclose personal information for any business purpose not described above.
11. Shine the Light (California Civil Code § 1798.83)
California residents who have an established business relationship with emotilink may request information once per calendar year about the personal information we share, if any, with third parties for their own direct marketing purposes. emotilink does not share personal information with third parties for their direct marketing purposes. You may nevertheless submit a request to info@emotilink.com.
12. Children
emotilink does not knowingly collect personal information from California residents under the age of sixteen (16) without parental or guardian consent. If you believe we may have collected personal information from a person under sixteen (16), please contact us at info@emotilink.com and we will promptly delete the information.
13. Changes to This Notice
We may update this Notice from time to time. Material changes will be communicated through the App or by other reasonable means, and the “Effective Date” and “Last Updated” dates above will be revised.
14. Contact
If you have questions about this Notice or our privacy practices, please contact:
emotilink Privacy Officer
emotilink, LLC
222 W Merchandise Mart Plaza, Suite 1230
Chicago, IL 60654
info@emotilink.com
312-554-5812
