Privacy Notice

Consolidated Research, Inc. d/b/a General Sleep Corporation

Last updated and effective: August 28, 2026

In short. General Sleep makes sleep monitoring devices and software for healthcare providers and researchers. We sell to them, not to patients or the general public — your provider orders your sleep study. Where a provider orders our HomeDirect service, we do deal with you directly to deliver, rent, and recover the test kit. We do not sell your personal information, we do not share it for targeted advertising, and we do not use it to build advertising profiles. Health information we handle for a healthcare provider is protected health information under HIPAA and is governed by that provider's privacy practices, not by this notice.

Contents

1. Who we are 2. Who this notice covers 3. Health information and HIPAA 4. Part A — Website visitors 5. Part B — Provider users of our web application 6. Part C — Patients 7. How we disclose information 8. We do not sell or share your personal information 9. How we protect information 10. How long we keep information 11. Your choices and rights 12. Children 13. Additional information for residents of certain states 14. Visitors from outside the United States 15. Changes to this notice 16. How to contact us

1. Who we are

Consolidated Research, Inc., doing business as General Sleep Corporation ("General Sleep," "we," "us," or "our"), designs and manufactures sleep monitoring devices and the software used to record, review, and report on sleep studies. Our products include the Zmachine® Insight+ and the Zmachine® Synergy home sleep test.

We provide our products and services to licensed medical, dental, and research professionals and their organizations. Patients are not our customers. A provider decides a sleep study is needed, orders it from us, and remains responsible for the patient's care; we do not diagnose, treat, or advise patients, and we do not offer our products to the public.

One part of what we do involves dealing with patients directly, and its name invites confusion, so it is worth stating plainly. Where a provider orders a home sleep test through HomeDirect, we ship the kit directly to the patient's home, the patient agrees to certain terms and conditions in connection with its usage of the kit, and we correspond with the patient about delivery, return of the kit, and payment where the patient is the one responsible for it. "Direct" describes how the equipment reaches the patient's door rather than a retail relationship: the provider still orders the test, still directs the care, and is the reason we hold the patient's information at all. Section 6.2 describes that rental in detail.

If you are a patient and have questions about your sleep study or your health information, please contact your healthcare provider.

This notice explains what personal information we collect, why we collect it, who we share it with, and what choices you have.

2. Who this notice covers

People interact with General Sleep in very different ways, and the information we hold about them differs accordingly. Rather than describe everything at once, this notice is divided into parts. Find yourself in the table below and read the part that applies to you, along with the sections that apply to everyone.

If you are…ReadWhat we typically hold about you
A website visitor. You are browsing generalsleep.com, perhaps submitting our contact form to ask about a product. Part A What you type into the contact form, plus basic technical details of your visit.
A provider user. You are a physician, dentist, researcher, technologist, or administrator with an account in our web application. Part B Your account and contact details, your organization, and records of what you did in the application.
A patient. Your healthcare provider ordered a sleep study using our equipment or software. Part C Your sleep study data and demographics, held on behalf of your provider. If your provider used our HomeDirect service, also your shipping and rental details.

Sections 7 through 16 apply to everyone.

This notice does not cover websites, applications, or services operated by anyone else, including your healthcare provider, even if you reach them through a link from us. Their own privacy practices apply.

3. Health information and HIPAA

This is the most important thing to understand about how we handle health information, so we want to be direct about it.

General Sleep is not a healthcare provider and is not a HIPAA covered entity. We do not diagnose, treat, or advise patients. When a healthcare provider uses our software to record and review a patient's sleep study, we act as that provider's business associate under HIPAA. We handle the patient's protected health information only to deliver the services the provider has engaged us to perform, and only as permitted by our written business associate agreement with that provider and by law.

What this means in practice:

The HomeDirect device rental

Some providers order a home sleep test through our HomeDirect service, which ships a Zmachine® Synergy kit directly to the patient's home. When that happens, the patient enters into a device rental agreement with General Sleep, covering delivery, care of the equipment, its return, and financial responsibility for loss, damage, or late return. That rental is a commercial transaction between you and us. It is not the delivery of healthcare, and General Sleep is not providing you with medical care of any kind.

The personal information involved in that rental — your address, your phone number, the fact that your provider ordered a sleep test for you — is nonetheless health-related and originates from your provider. We therefore safeguard it as protected health information under our business associate agreement with the ordering provider, applying the same protections described above, even though the rental contract itself is commercial. We do this deliberately: it is the more protective treatment.

4. Part A — Website visitors

This part applies to generalsleep.com.

What we collect from you directly

The contact form is the only place our website currently asks you for information. It collects:

You may also give us information through other channels, and we collect whatever you choose to provide when you do. That includes emailing or telephoning us, requesting a quote, a demonstration, or product literature, subscribing to a newsletter or mailing list, registering for or attending a webinar, trade show, or training session, responding to a survey or a request for feedback, taking part in a product evaluation, or interacting with us on a social media platform. If we ever record or monitor a call for quality or training purposes, we will tell you at the start of that call.

The form also records which page you submitted it from, and a token from our bot protection service confirming you are not an automated script.

Nothing else is added to the form on your behalf. We no longer read, store, or submit any advertising identifier with your inquiry.

We ask that you use this form only if you represent a medical practice, hospital, sleep center, research institution, or related business. Please do not send us health information about yourself or anyone else through this form. It is not a secure channel for that purpose, and we have no way to act on it.

What we collect automatically

SourceInformationWhy
Cloudflare IP address, request details, and bot-detection signals To deliver the site reliably and to stop automated abuse of the contact form
Server and network logs IP address, browser user agent, timestamps, and pages requested Security, troubleshooting, and preventing abuse
Your device and connection Device type, operating system, browser and version, screen size, language setting, and approximate time zone To render pages correctly, to fix display problems, and to distinguish genuine visitors from automated traffic

We do not currently operate any third-party analytics product on this website. We have no measurement tool that profiles visitors across pages or across visits.

We may add or change analytics, hosting, security, and performance-monitoring providers over time, and may use other technologies that serve the same measurement, reliability, and security purposes described here. Where we do, the categories of information and the purposes remain those set out in this section.

No analytics or advertising tool on our website reads what you type into the contact form. Your name, email address, and message are sent only to us.

Embedded videos

Some product and patient-instruction pages offer videos that are hosted on YouTube. These do not load automatically. Each one appears as a still image stored on our own website, and nothing is requested from YouTube or Google until you click it. If you do click a video, YouTube then loads and may set its own cookies and receive your IP address, in accordance with Google's privacy policy. If you never click, no request to Google is made.

Cookies and storage

A cookie is a small file a website stores in your browser. We use a small number of them. Everything is listed here.

NameTypeSet byPurposeExpires
refsCookieUs Counts visits associated with a referral code, so we can tell which brochures, partner links, and printed materials bring people to the site 90 days
__cf_bm, cf_clearanceCookie Cloudflare Bot detection and form protection 30 minutes to a few days

That is the complete list. We do not use advertising cookies, retargeting pixels, conversion or click identifiers, session recording, heatmap tools, or social media tracking pixels on our website.

You can block or delete cookies through your browser settings. Doing so will not prevent you from using the site, though the contact form's bot protection may not work correctly.

How we use website information

5. Part B — Provider users of our web application

This part applies to clinicians, technologists, researchers, and administrative staff who hold accounts in the General Sleep web application.

What we collect

CategoryDetails
Account details Name, username, email address, and a securely hashed password. If your organization uses single sign-on, we receive an identifier from your identity provider instead of a password.
Contact details Street address, city, state or province, postal code, country, telephone number and extension, and mobile number.
Organization The organization you belong to, your role and permissions within it, and which studies you may access.
Security information Two-factor authentication enrollment details, sign-in attempts, and account lockout events.
Activity records Records of actions taken in the application — who created, viewed, changed, scored, or interpreted a study, and when. These records exist so that access to patient information is auditable, which HIPAA requires.
Technical information IP address, browser and device details, and application logs. If you use our Windows desktop uploader, it records the workstation's operating system user name and computer name alongside the upload, so uploads can be traced to a machine.
Preferences Display and notification settings you choose, and your marketing preferences, including any opt-out you have exercised.
Billing information Billing contact details for your organization, invoices, purchase and payment records, and any dispute or collection history. Organization billing is handled through our invoicing provider.
Communications with us Support tickets, emails, chat messages, and notes of telephone conversations, together with any attachments, screenshots, or diagnostic files you send us. If we ever record a call for quality or training purposes, we will tell you at the start of that call.
Feedback and research Responses to surveys, feature requests, bug reports, beta or evaluation participation, and anything you tell us about how you use the product or how it could be better.
Training and credentials Records of training or onboarding you have completed with us, and where relevant to a permission we grant you, your professional role or credential as your organization reports it. We do not independently verify licences.

Which of these exist for any individual depends on how you and your organization use the product. We collect what is needed for the purposes below and no more.

How we use it

We may send you information about product updates and offerings. You can opt out of those messages at any time using the unsubscribe link or by contacting us. We will still send you service messages about your account, because they are necessary to provide the service.

6. Part C — Patients

Patients do not have accounts with General Sleep, and we have no direct relationship with patients other than the HomeDirect rental described below. Please read Section 3 first — it explains why most of this information is governed by your healthcare provider's privacy practices rather than by this notice.

6.1 Sleep study information

When your provider records a sleep study using our system, the following may be stored on your provider's behalf. Exactly what is present depends on what your provider chooses to enter.

CategoryDetails
Who you are First, middle, and last name; date of birth; sex; telephone number; email address; and your referring physician.
Physical characteristics Height, weight, and neck circumference, which affect how a sleep study is interpreted.
Recordings from the device The physiological signals the Zmachine® records during your sleep study, including brain activity (EEG) and the other channels the device captures, along with the times the recording started and stopped for each night.
Results and analysis Sleep staging, scoring annotations, calculated statistics summarizing your sleep and breathing, and the report your provider produces.
Notes Free-text notes your provider or our support staff add to the study record.
Identifiers your provider chooses Organizations can define their own fields, such as a medical record number or personal health number. What is collected depends on your provider's configuration.
Equipment and handling The serial number of the device used, and records of who accessed or changed the study and when.

We do not collect biometric identifiers such as fingerprints, voiceprints, or facial geometry. We do not make audio or video recordings of you. We do not collect precise location data, genetic information, or information about your race, ethnicity, religion, sexual orientation, or immigration status.

How we use sleep study information

This information is protected health information, and what we may do with it is set by HIPAA and by our business associate agreement with your healthcare provider — not by our own preference. Within those limits, we use it to:

What we will not do with it. We do not use or disclose protected health information for our own marketing or advertising, sell it, monetize it, use it to build profiles, or use it for any purpose beyond those above and those our business associate agreement permits. If we ever needed it for a genuinely new purpose, that would require your provider's agreement, and in many cases your authorization, before anything changed.

6.2 HomeDirect — using our home sleep test kit

If your provider ordered your test through HomeDirect, we ship the kit to your home and you deal with us directly for delivery and return. You reach the ordering page through a private link sent to you by email or text message. There is no account and no password; the link itself is the key, and it expires after 30 days.

What your provider tells us

Your name, email address, telephone number, preferred language, and the name of your referring physician.

What you tell us

About your card. Your card details go straight from your browser to Stripe, Inc., our payment processor. They never pass through or rest on General Sleep systems, and we never store your card number. We keep only the tokens Stripe gives us, which let us process an authorized charge without seeing the card itself. You may see a temporary authorization hold that is not a charge and disappears on its own.

What we generate while fulfilling the order

Shipping and return tracking numbers and labels, ship and delivery dates, the date the kit is returned, your rental period, the price, a record of how far you progressed through the ordering steps, notes about the order, and the paperwork we print and pack in the box, such as your instructions, the patient guide, and return documentation.

Paperwork you send back with the kit

Your provider may ask you to complete forms that travel in the kit — a sleep questionnaire, a symptom or medication list, a consent form, or something similar — and you may add notes of your own. When the kit comes back, we scan whatever paperwork is inside and attach it to your study record so that your provider can read it.

What you write on those forms is health information. We handle it as protected health information on your provider's behalf, on the terms in Section 6.1 rather than the rental terms here: it becomes part of the study record your provider controls. Your provider decides which forms to send and what to ask, and your provider, not General Sleep, reads and acts on the answers. We scan, attach, and store it, and we do not use it for any purpose of our own.

How we use it

You agree to be contacted by phone, email, and text message when you accept the Patient Terms and Conditions. Message and data rates may apply. If you would prefer not to receive text messages, contact us and we will switch you to email or telephone, though we do need some way to reach you about your kit.

7. How we disclose information

We disclose personal information only in the circumstances described here.

Service providers

We use other companies to run parts of our business. They may only use the information we give them to perform services for us, under written contracts that require them to protect it. Where they handle protected health information, we have business associate agreements with them.

ProviderWhat it doesWhat it receives
Amazon Web Services Hosting, storage, databases, automated email delivery, and text messaging All information stored in or sent through our systems
MicrosoftOur business email accounts Anything contained in email you send to or receive from us, including support requests, and the messages we retain in our mailboxes
Stripe, Inc.Payment processing Card details entered directly by the patient, plus name, contact details, and amount
ShippoAddress validation and shipping labels Patient name and shipping address
FedExShipping, delivery, and tracking Patient name, shipping address, and delivery details
InvoicedOrganization invoicing and billing Organization and billing contact details
TaxJarSales tax calculation Organization address and order amounts
CloudflareWebsite delivery and bot protection IP address and request details

This table names the providers we use today. We also use, and may in future engage, other providers performing the same kinds of function — hosting and storage, email and messaging, payments, shipping and logistics, address validation, tax calculation, customer support and ticketing, analytics, security and fraud prevention, error monitoring, backup and disaster recovery, invoicing and collections, and professional advisers such as accountants, auditors, insurers, and lawyers. Any replacement or addition is held to the same standard: a written contract limiting them to performing services for us, and a business associate agreement wherever protected health information is involved. You may ask us for the current list at any time using Section 16.

Your healthcare provider and their organization

Sleep study information is made available to the ordering provider, to authorized users within their organization, and to anyone they choose to share a study with, such as a scoring or interpreting physician. Your provider controls who that is.

Systems your provider connects

An organization can connect our application to its own systems, so that events such as a completed report are delivered automatically to a destination it specifies. Where an organization sets this up, information about its own studies is sent to that destination. The organization is responsible for the systems it connects and for what happens to the information there. These transmissions are cryptographically signed and are only sent over encrypted connections.

Legal reasons

We may disclose information when we believe in good faith it is necessary to comply with a law, regulation, subpoena, court order, or other legal process; to respond to a lawful government request; to enforce our agreements; to investigate suspected fraud or security incidents; or to protect the rights, property, or safety of General Sleep, our customers, patients, or the public. Where the information is protected health information, we apply the additional standards HIPAA requires before making any such disclosure.

This includes what we may need to do to recover our equipment or amounts owed to us under a rental agreement — for example instructing legal counsel or a collection agency, filing or defending a claim in court, or reporting unreturned equipment to law enforcement. Where a patient's information is involved we disclose only what is reasonably necessary for that purpose, we continue to treat it as protected health information, and any collection agency or other provider acting for us is bound by a written contract and, where it handles protected health information, by a business associate agreement.

Business transfers

If General Sleep is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, and may be disclosed to prospective parties and their advisers in the course of it. Any recipient would take the information subject to this notice as it then stands. Protected health information would remain governed by HIPAA and by the business associate agreements covering it, which bind a successor. If our practices changed as a result, Section 15 governs how and when we would tell you.

Aggregated and de-identified information

We may create information that has been aggregated or de-identified so that it no longer identifies anyone and cannot reasonably be used to identify anyone. Health information is de-identified in accordance with the standards HIPAA sets before it is used this way.

Once information is properly de-identified it is no longer personal information or protected health information, and we may use and disclose it for any lawful purpose, including:

We do not attempt to re-identify de-identified information, and we require anyone we give it to not to attempt re-identification either. Where we disclose it, we do so under terms that carry that restriction.

8. We do not sell or share your personal information

The purposes described in Parts A, B, and C are deliberately broad, because they cover running a business, supporting customers, and developing medical devices over time. This section sets the outer boundary. These are commitments about what we will not do, and they apply to everything in this notice.

We use the specific meanings these terms have under state privacy laws.

Because we do not sell or share personal information, there is nothing for you to opt out of in that respect. We honor browser-based opt-out preference signals, including the Global Privacy Control, as a matter of course; since we do not sell or share, such a signal requires no change to our behavior.

9. How we protect information

We maintain administrative, technical, and physical safeguards designed to protect personal information against loss, misuse, and unauthorized access, disclosure, alteration, and destruction. These include:

No system can be guaranteed completely secure, and we cannot promise that information will never be accessed improperly. If you hold an account, you play a part too: keep your password confidential, do not share your account, enable two-factor authentication, and tell us promptly if you suspect unauthorized access.

10. How long we keep information

We keep personal information for as long as it serves the purposes described in this notice, and longer where law, a contract, or a professional obligation requires it. We do not delete information simply because time has passed. Sleep study information in particular is clinical record material that a provider or a patient may need years after the study, so our practice is to retain it rather than to dispose of it on a schedule.

We delete or dispose of information when the law or an agreement requires us to, when a provider organization instructs us to for records in its account, when you make a request we are required to honor, or when we decide on our own that we no longer need it. Absent one of those reasons, our default is to keep it.

The table below therefore describes our general practice rather than a guaranteed disposal schedule. Any of these periods may run longer where circumstances require, for example a legal hold, litigation or an anticipated claim, a government or accreditation audit, an open billing or warranty dispute, a safety investigation, or a specific regulatory obligation.

InformationHow long
Sleep study data and reports Retained for at least as long as the provider's organization maintains its account, in accordance with our agreement with that organization. Providers control the records in their account and may direct us to dispose of them. On termination we return or dispose of the information as our agreement requires; where return or disposal is not feasible, we retain it and continue to apply the protections of that agreement to it, as HIPAA permits.
HomeDirect order records For the life of the order and afterward for billing, warranty, equipment tracking, dispute resolution, and legal recordkeeping. We generally retain order history rather than disposing of it on a fixed schedule.
Provider account records For as long as the account is active and afterward for as long as we have a business, contractual, or legal reason to keep them
HIPAA compliance documentation Six years, as HIPAA requires
Detailed application request logs Typically about a week in the live system, then moved to restricted archive storage
Audit records of changes Typically up to about ninety days in the live system, then archived. Records evidencing access to patient information are kept for at least the six years HIPAA requires.
Contact form submissions and support correspondence For as long as needed to handle your inquiry and to maintain a support and correspondence history. We generally retain correspondence rather than deleting it on a schedule.
Referral code cookie (refs) Ninety days in your browser, unless you clear it sooner
Private ordering links The link stops working thirty days after we issue it. The order record it pointed to is kept as described above.

Backups, archives, and residual copies. We maintain backups and archival copies so that we can restore the service after a failure, and we retain the records our legal and contractual obligations require us to preserve. Backup media are written on their own cycles and are not selectively editable, so when information is deleted from our live systems, copies can remain in backups, archives, or preserved records until those age out or are overwritten in the ordinary course. The same is true of information contained in email and in logs. We apply the same security controls and confidentiality obligations to those copies as to live data, and we do not restore them in order to work around a deletion we have made or been asked to make. We cannot, however, represent that every copy of a given item has ceased to exist.

11. Your choices and rights

Choices available to everyone

What you want to doHow
Stop receiving marketing email Use the unsubscribe link in any marketing message, or contact us. Service and transactional messages will continue where they are necessary.
Change how we contact you about a HomeDirect order Contact us and we will use a different channel where we can. We do need some way to reach you about your kit.
Update your account details Edit them in the application, or ask your organization administrator.
Control cookies Use your browser settings. Our website sets only the two cookies listed in Part A.
Ask a question about privacy Contact us using Section 16.

Health information

If you are a patient and want to see, copy, correct, or restrict your sleep study or health information, contact the healthcare provider who ordered your study. They hold your medical record and can act on those requests. We support providers in responding, but we cannot release health information directly to a patient. See Section 3.

State privacy rights

Depending on where you live, you may have additional rights over personal information that is not covered by HIPAA. Those rights, and how to use them, are described in Section 13.

12. Children

Our website and web application are intended for healthcare and research professionals and are not directed to children. We do not knowingly collect personal information from children through them. If you believe a child has provided us information through our website, contact us and we will delete it.

Sleep studies are sometimes performed on children at a provider's direction. Where that happens, the child's information is protected health information handled on behalf of the provider, and it is the provider who obtains any consent required from a parent or guardian. A parent or guardian who wants access to a child's study information should contact the provider.

13. Additional information for residents of certain states

Several states give residents specific rights over their personal information. This section explains those rights and how to use them.

Two things determine whether these rights apply to your information.
First, these laws exclude protected health information and information handled by a business associate under HIPAA. Most patient information we hold falls into that category, so these rights generally do not reach it — the HIPAA protections in Section 3 apply instead, and requests go through your healthcare provider. Second, several of these laws apply only to businesses above certain size thresholds. Where a law does not apply to us, we may not be obliged to honor a request, but we will tell you if that is the reason we cannot act.

13.1 Rights that may be available to you

RightWhat it meansOur position
Know and access Confirm whether we process your personal information and get a copy, along with the categories collected, the sources, our purposes, and who we disclose it to Available
CorrectHave inaccurate personal information corrected Available
DeleteHave your personal information deleted Available, subject to the exceptions below
Portability Receive a copy in a portable, machine-readable format where technically feasible Available
Opt out of saleDirect us not to sell your personal information Not applicable — we do not sell personal information
Opt out of targeted advertising Direct us not to share your information for targeted advertising Not applicable — we do not do this
Opt out of profiling Direct us not to profile you in ways producing significant effects Not applicable — we do not do this
Limit use of sensitive information Restrict our use of sensitive personal information We use it only to provide the service and as permitted by law, never to infer characteristics
Withdraw consent Withdraw consent you previously gaveAvailable
Appeal Appeal if we decline your requestAvailable to everyone, see 13.4
Non-discrimination Not be treated worse for exercising a privacy right We do not discriminate. We will not deny service, charge a different price, or provide a lower quality of service because you exercised a right.

We may decline all or part of a request where the law allows — for example where the information is protected health information governed by HIPAA, where we must keep it to comply with a legal obligation, complete a transaction you asked for, maintain security, detect fraud, or establish or defend legal claims, or where we cannot verify who you are. We will always tell you why.

Where we act on a deletion request, we delete or de-identify the information in our active systems and instruct our service providers to do the same. Copies may remain in backups and preserved records for a period afterward, as described in Section 10.

13.2 How to submit a request

Use any of these. We do not currently operate a web form for privacy requests.

Tell us what you want us to do and enough about yourself for us to find your information.

13.3 Verifying who you are

Before we act, we must be reasonably sure you are who you say you are, so that we do not give your information to someone else. We will usually ask you to confirm details we already hold, such as the name, email address, or telephone number associated with your information, and we may contact you at an address or number already on file. For requests about sensitive information we may ask for more. If we cannot verify you, we will tell you.

Authorized agents. You may use an agent. We will ask for written, signed permission from you, and we may still ask you to confirm your identity with us directly and to confirm you gave the agent authority. An agent acting under a valid power of attorney need not provide separate written permission.

13.4 Our response, and appeals

We will acknowledge your request promptly and respond within the time the applicable law allows, generally forty-five days, which we may extend once where the law permits and where we tell you why. Requests are free, though we may charge a reasonable fee or decline a request that is manifestly unfounded, excessive, or repetitive.

Appeals. If we decline your request, you may appeal by replying to our response or contacting us through any channel in 13.2 with "Privacy Appeal" in the subject line. We will review the decision and respond in writing, within sixty days, explaining our reasoning. We offer this to everyone, not only to residents of states that require it. If your appeal is denied, you may contact your state Attorney General.

13.5 California

California residents have the rights in 13.1 under the California Consumer Privacy Act as amended by the California Privacy Rights Act.

Categories of personal information. In the past twelve months we have collected the following categories, as defined by California law. For each, the sources, purposes, and recipients are those described in Parts A, B, and C and in Section 7.

CategoryCollectedExamples
IdentifiersYes Name, postal address, email address, telephone number, IP address, and account name
Customer records informationYes Contact details, and payment information processed by our payment provider
Protected classification characteristicsYes, limited Age or date of birth and sex, where a provider enters them for a sleep study
Commercial informationYes Products ordered, rentals, invoices, and support history
Internet or network activityYes Pages viewed, links clicked, referring site, application activity records
Geolocation dataCoarse only Approximate region inferred from IP address. We do not collect precise geolocation.
Professional or employment informationYes, limited Specialty, job role, and the organization a provider user works for
Sensory informationNo We make no audio, video, or photographic recordings and use no thermal or olfactory sensors
Biometric informationNo We do not collect fingerprints, voiceprints, iris or facial geometry, or any biometric identifier used to identify a person
Education informationNo
InferencesNo We do not build profiles reflecting preferences, characteristics, or behavior
Sensitive personal informationYes Health information, and account credentials. Used only to provide the service and as permitted by law, never to infer characteristics.

We disclose personal information for business purposes to the categories of recipients listed in Section 7. We have not sold or shared personal information for cross-context behavioral advertising in the past twelve months, and we do not sell or share the personal information of anyone under sixteen.

California Shine the Light. Under California Civil Code section 1798.83, California residents may request information about disclosures of personal information to third parties for those parties' own direct marketing. We do not make such disclosures. You may confirm this by writing to us.

Notice of financial incentive. We offer none.

13.6 Texas

Texas residents have the rights in 13.1 under the Texas Data Privacy and Security Act, including the right to appeal in 13.4.

Texas law requires consent before processing sensitive personal data. Health information a provider enters about a patient is protected health information handled under HIPAA and our business associate agreement, which is how consent is obtained and governed. We do not otherwise collect sensitive personal data from Texas residents, and we do not sell sensitive or biometric personal data.

13.7 Maryland

Maryland residents have the rights in 13.1 under the Maryland Online Data Privacy Act, including the right to appeal in 13.4.

Maryland law restricts the collection of personal data to what is reasonably necessary for the requested product or service, and prohibits the sale of sensitive data. We collect only what is necessary for the purposes described in this notice, and we do not sell personal data of any kind, sensitive or otherwise.

13.8 Colorado, Connecticut, Delaware, Indiana, Kentucky, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, and Virginia

Residents of these states have the rights in 13.1 under their respective state privacy laws, including the right to appeal in 13.4.

These laws require opt-in consent before processing sensitive data, which includes health information. Health information we hold about patients is protected health information handled under HIPAA and our business associate agreement, which governs how it may be used and is generally excluded from these laws. We do not process sensitive data of residents of these states for any other purpose.

Minnesota residents additionally have the right to question the result of profiling and to review the personal data used in it. We do not profile anyone, so this right has nothing to operate on. Minnesota and Oregon residents may additionally request a list of the specific third parties to which we have disclosed personal data; contact us and we will provide it. Minnesota residents may also opt out of the processing of personal data for targeted advertising or sale through a universal opt-out mechanism; we honor opt-out preference signals, including Global Privacy Control, as described in Section 8.

Connecticut residents: Connecticut law prohibits the sale of consumer health data without consent and prohibits the use of geofences within 1,750 feet of a mental health facility or reproductive or sexual health facility to identify, track, or collect data from consumers. We do not sell consumer health data, and we do not operate geofences around any healthcare facilities.

13.9 Florida

Florida residents may exercise the rights in 13.1 under the Florida Digital Bill of Rights to the extent it applies to us. Florida law requires consent before processing sensitive personal data, addressed the same way as described for Texas in 13.6.

13.10 Iowa and Utah

Residents of Iowa and Utah have the rights in 13.1 under the Iowa Consumer Data Protection Act and the Utah Consumer Privacy Act, other than the right to correct, which those laws do not provide. We will nonetheless correct inaccurate information on request as a matter of practice. Both states require notice and the ability to opt out before sensitive data is processed; as above, patient health information is handled under HIPAA.

13.11 Nevada and Washington

Nevada residents may direct a business not to sell certain personal information. We do not sell personal information, so there is nothing to opt out of, but you may confirm this by contacting us.

Washington's My Health My Data Act and Nevada's consumer health data law both exclude protected health information and information handled by a business associate under HIPAA. The health information we hold falls within that exclusion. We do not collect consumer health data outside that relationship, we do not sell consumer health data, and we do not operate geofences around healthcare facilities.

14. Visitors from outside the United States

General Sleep is based in the United States and our systems are located here. Our products and services are intended for use in the United States. If you access our website or services from elsewhere, your information will be transferred to and processed in the United States, where privacy laws may differ from those where you live and where governmental authorities may be able to access information under United States law. By using our website or services, you understand that your information will be processed in the United States as described in this notice.

15. Changes to this notice

We may update this notice as our practices, our technology, or the law changes. When we do, we will revise the "last updated and effective" date at the top and post the new version here.

If we make a material change — particularly one that would allow us to use information we already hold for a genuinely new purpose — we will provide notice before that new use begins, prominently on our website and, where we hold your email address and it is appropriate, by email. Please review this notice periodically.

16. How to contact us

For any question, request, concern, or complaint about privacy, or to reach our Privacy Official, contact us:

General Sleep Corporation
Attn: Privacy Official
26250 Euclid Avenue, Suite 709
Cleveland, Ohio 44132
United States

Telephone: (888) 330-4424 (toll-free)
Email: support@generalsleep.com

We take privacy complaints seriously and will not retaliate against anyone for making one. If you are a patient with a concern about your health information, you may also raise it with the healthcare provider who ordered your study, or with the U.S. Department of Health and Human Services Office for Civil Rights. If you are a resident of a state with a privacy law described in Section 13, you may also contact your state Attorney General.