Last Updated: May 22, 2025
Nox Health Group, Inc., and its affiliated parties (“Nox Health,” “Nox,” ”we,” or “us”), are committed to protecting your privacy. We understand that health is a very private subject, and we want you to feel comfortable visiting our website and engaging with our applications and services. We provide this Website and Application Privacy Notice (“Notice”) to inform individuals about the personal data we collect, how we use, disclose, and protect that information as well as what choices you may make regarding your information.
This Privacy Notice applies to the SleepCharge websites and services provided through those sites, including the SleepCharge web-based and mobile applications (the “SleepCharge Application”). This Notice is incorporated into and is a part of the terms of use of the SleepCharge Application (the “Terms of Use”). We encourage you to review both this Notice and the Terms of Use.
When used in this Notice, “personal data” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an individual (“data subject”), and includes “personal data” or “personal information” as defined in applicable data protection laws. Data that cannot be associated with you, such as aggregated, de-identified, or anonymized information (“Anonymous Information”), is not personal data. Nox commits to keep Anonymous Information in its de-identified state, and will make no efforts to re-identify such data.
This Notice does not apply to Protected Health Information (“PHI”) as defined in the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended (“HIPAA”). For information regarding how we collect, use, and disclose PHI that we receive as a covered entity under HIPAA, please see our Notice of Privacy Practices. We may also maintain your PHI on behalf of other third parties subject to HIPAA, including, for example, health plans, physicians, or medical facilities who are our business partners or customers. Where we maintain your PHI on behalf of any third party subject to HIPAA, we will maintain that information in accordance with the applicable Business Associate Agreement that Nox Health may enter into with each third party.
By accessing and using the SleepCharge Application, or any part thereof, you agree that you have read and understand this Privacy Notice, and that in exchange for access to the SleepCharge Application, you accept and consent to the privacy practices described in this Notice.
The table below provides you with details about the information we collect, how we obtain that information, how it is used, who it is shared with and how long we keep it. Please see the subsequent sections for further explanation about Nox's data processing activities.
The following table provides examples of the types of information that we collect in various contexts and how we use that information.
| Categories of Personal Data Collected | Categories of Data Subjects (Individuals) | Business and Commercial uses of Personal Data | Categories of Third Parties to Whom We Disclose Personal Data | Retention of Personal Data |
| Identifiers (such as name, email address, telephone number, business affiliation, and other contact information) | SleepCharge users, partners, vendors, website visitors | Account registration and servicing To communicate with you To improve and develop new products and services To provide our Services and operate our business | Our affiliates and subsidiaries Third parties that assist us, such as analytics providers, providers of technical services (e.g., providers of data storage, customer support), and other subcontractors Entities involved in dispute resolution (such as an arbitrator or an opposing party) Entities involved in potential or actual significant corporate transactions or events Governmental entities | 10 years |
| Commercial information, including products and services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies | SleepCharge users, website visitors | To improve and develop new products and services To provide our Services and operate our business | Same as above | The duration of the relationship + 3 years |
| Financial data (such as payment information, account or credit card information) | SleepCharge users, partners, vendors | To provide our Services and operate our business | Same as above | 7 years |
| Internet or other network or device activity (such as IP addresses, device identifiers, cookie data, device attributes, device usage information, browsing information, metadata, and other information described in this section of our Privacy Notice) | SleepCharge users, partners, vendors, visitors | Account registration and servicing To communicate with you To improve and develop new products and services To provide our Services and operate our business | Our affiliates and subsidiaries Third parties that assist us, such as payment processors, marketing providers, analytics providers, providers of technical services (e.g., providers of data storage, customer support, and CRM systems), and other subcontractors | 1 year |
| Protected Classifications and Sensitive Personal Information health information, such as medical conditions | SleepCharge users | Business purposes | Professional services consultants Data analytics services Security vendors IT vendors | 10 years |
In addition to the purposes and uses described above, we use information in the following ways:
Although the sections above describe our primary purposes for collecting and using your information, in many situations, we have more than one purpose. For example, if you submit an application for a job posting, we may collect your information in anticipation of employing you, but we also collect your information as we have a legitimate interest in contacting you about the status of your application and evaluating your qualifications for the position. As a result, our collection and processing of your information is based on different contexts upon your consent, our need to perform a contract of employment, our obligations under law, and/or our legitimate interest in conducting our business.
To the extent necessary for purposes of communicating with you or fulfilling your requests for content, materials, and opportunities, we may share your information with the entities identified below and any of the entities that we elect to share such information with, subject to any legal or contractual limitations. In addition to the specific situations discussed elsewhere in this Privacy Notice, we disclose information to others in the following situations:
We, our affiliates, or our respective trusted business parties and third-party service providers may also produce reports on the SleepCharge Application's traffic or usage patterns and share these reports with us, or our business partners and others. In addition to the uses described above, Nox Health may also use and disclose certain aggregated, anonymized information, such as usage data related to the SleepCharge Application, to our affiliates, subsidiaries, trusted business partners, or other trusted third parties. Such information may also be shared with other users or the general public for advertising, informational, or comparison purposes.
We use reasonable efforts to protect your personal data from unauthorized access, use, or disclosure. However, no method of transmission over the Internet, or method of electronic storage, is fully secure and impenetrable. Therefore, we cannot guarantee the security of your personal data. In the event that we are required by law to inform you of any unauthorized access to your personal data, we may notify you electronically, in writing, or by telephone, if permitted to do so by law. You agree to immediately notify us of any breach of security of the SleepCharge Application, any breach of this Privacy Notice, or any breach of the Terms of Use of which you become aware.
Some areas of our SleepCharge Application permit you to create an account. When you do, you will be prompted to create a password. You are responsible for maintaining the confidentiality of your user identification and your password, and you are responsible for any access to or use of your account by someone else that has obtained your user identification or your password, whether or not such access or use has been authorized by you. You should notify us of any unauthorized use of your password or account.
By placing a small file known as a “cookie” on your computer (or other device), Nox Health's, and its third-party service providers', servers may passively gather information about a visitor's use of the SleepCharge Application for several reasons, including, but not limited to, the following: statistics collection and analysis, SleepCharge Application optimization, analytics (as described below), market research, and maintenance of user login information. The information that we and our third-party service providers track with cookies may include, but is not necessarily limited to, the type of browser (such as Google Chrome or Internet Explorer) and Internet-connected device being used to access the SleepCharge Application, your Internet Protocol (“IP”) address, your home domain or Internet service provider, your referrer URL (which is the URL for the website that you were viewing prior to visiting the SleepCharge Application), how you were directed to the SleepCharge Application, which specific pages you access, how long you view each page, the time and date you gain access and the total number of visitors to the SleepCharge Application and any portions thereof. We may also use your IP address to determine the general physical location of your computer or device and understand from what geographic locations visitors come.
Our SleepCharge Application allows you to define which cookies you will allow on your computer and will respect those settings. Certain cookies labeled “Strictly Necessary Cookies” are required for our applications to function.
Nox Health Group, Inc. is a multinational company and maintains offices around the world, including in the United States, Canada, Portugal, and in Iceland. As a result, your personal data may be processed in a foreign country where privacy laws may be less stringent than the laws in your country. Nonetheless, where possible, we take steps to treat personal data using the same privacy principles that apply pursuant to the law of the country in which we first received it. By submitting your personal data to us, you agree to the transfer, storage and processing of your personal data in a country other than your country of residence including, but not necessarily limited to, the United States. If you are visiting the SleepCharge site or Application or any part thereof from outside of the United States of America, please be aware that your information may be transferred to, stored or processed in the United States, where our servers are located and our central database is operated. The data protection and other laws of the United States and other countries might not be as comprehensive as those in your country,and have put in place the required legal data transfer mechanisms necessary to protect your data By using any portion of the SleepCharge Application, you understand and consent to the transfer of your information to our facilities in the United States and those third parties with whom we share it as described in this Privacy Notice. If you would like more information concerning our attempts to apply the privacy principles applicable in one jurisdiction to personal data when it goes to another jurisdiction, you can contact us using the contact information below.
You may have certain rights and choices regarding your personal data. Depending on your jurisdiction, and subject to applicable law, you may make the following choices:
For your convenience, some hyperlinks may be posted on the SleepCharge Application that link to other websites not under our control (the “Linked Websites”). We are not responsible for, and this Privacy Notice does not apply to, the privacy practices of any Linked Websites or of any companies that we do not own or control. We cannot be responsible for the privacy practices of any such Linked Websites, nor do we endorse any of these Linked Websites, the services or products described or offered on such Linked Websites, or any of the content contained on the Linked Websites. We encourage you to seek out and read the privacy policy of each website that you visit. In addition, should you happen to initiate a transaction on a Linked Website, even if you reached that site through SleepCharge Application, the information you submit to complete that transaction becomes subject to the privacy practices of the operator of the applicable Linked Website. You should read each Linked Website's privacy policies to understand how Personal Information that is collected about you is used and protected.
We may change this Privacy Notice from time to time. The effective date of this Privacy Notice is specified by the version date located at the end of this Privacy Notice. All updates and amendments to this Privacy Notice are effective immediately when posted on the SleepCharge Application. We expressly reserve the right to make any changes to this Privacy Notice at any time, without prior notice to you. This Privacy Notice is not intended to and does not create any contractual or other legal right in or on behalf of any party other than Nox Health.
The SleepCharge Application is intended for a general audience and is not intended for use or viewing by children under sixteen (16) years of age, and we do not knowingly collect information about children or sell products to children.
Should you have any questions about this Privacy Notice or our privacy practices, please contact us at the appropriate address below.
Nox Health Group, Inc.You may also contact your local supervisory authority.
Nox has adopted a global approach on privacy with the intent of providing individuals with strong privacy protections regardless of where they reside. We recognize and implement high standards for privacy rights compliance on a global scale. Listed below, you can find additional privacy provisions that may be relevant to your specific country or region.
If you have any questions or concerns regarding the privacy provisions relevant to you, or you wish to exercise any of these rights, please contact our Privacy Officer by using the contact information provided in Section 13 “Contact Information.”
Canada:
Controlling Law: Personal Information Protection and Electronic Documents Act (PIPEDA)
Canada Privacy Rights: You can exercise your rights of access and rectification by contacting us. Depending on your province, you may have additional rights, including the right to control the dissemination of your personal data, the right to data portability, the right to be informed of and submit observations regarding automated decision-making, and the right to request information about data processing.
You also have the right to file a complaint with the Office of the Privacy Commissioner of Canada or your local privacy commissioner.
To exercise your rights, use our online form.
Supervisory Authority:
Office of the Privacy Commissioner of Canada
Online: https://www.priv.gc.ca/en/report-a-concern/file-a-formal-privacy-complaint/file-a-complaint-about-a-business/European Union (EU), United Kingdom (UK), Switzerland (CH) and European Economic Area (EEA):
Controlling Laws: The General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR), UK The Data Protection Act 2018 (UK GDPR), Swiss Federal Act on Data Protection.
Legal Bases for Processing EU, UK CH, EEA personal data: Applicable law and policies require Nox to have a “legal basis” for the processing of your personal data. The applicable legal basis often depends on the types of data and the specific context in which it is processed. Where the GDPR and similar laws apply, we typically rely on performance of a contract, our legitimate business interests, or your consent as our primary legal bases to process your personal data.
EU, UK, CH, EEA Privacy Rights: If you are located in these regions listed, you have the following rights with respect to your personal data. You may contact us if you wish to exercise any of these rights:
To exercise your rights, use our online form.
Supervisory Authorities:
EU/ EEA Data Protection Authorities:
https://edpb.europa.eu/about-edpb/about-edpb/members_en
Switzerland: Federal Data Protection and Information Commissioner
Online: https://www.edoeb.admin.ch/edoeb/en/home/deredoeb/kontakt/anzeigeformular_betroffene.html
Phone: 058 462 43 95
United Kingdom: UK Information Commissioner’s Office:
Online: https://ico.org.uk/make-a-complaint/data-protection-complaints/what-to-expect/
Phone: 0303 123 1113
United States (US):
Controlling Law: There are many US state-specific privacy laws with new ones coming into effect every year. Because California's privacy protections are viewed by many to be the most comprehensive in the US, we refer US-based individuals to the California Consumer Privacy Act of 2018 (“CCPA”), and as of January 1, 2023 the California Privacy Rights Act of 2020 (“CPRA”), for personal data protection.
Our Processing of US Personal Data: We collect and have collected in the last 12 months all of the information described in Section 3 of our Privacy Notice from and about US residents. You should refer to that section for more detail, but this information generally falls into the categories listed in the chart in Section 3 to the extent it is personally identifiable. The chart also indicates the data subjects whose personal data we collect, the purposes of processing, and the categories of third parties to whom we recently disclosed the data leading up to the effective date of this Statement.
We have not sold or shared (as defined in the CCPA and other U.S. state comprehensive privacy laws) personal data covered by this Privacy Notice in the preceding 12 months. We also do not knowingly sell or share the personal data of individuals under 16 years of age.
US Privacy Rights: Under applicable US law, you have the right to:
To exercise your rights, use our online form.
You may also call our phone number: 855-617-6691
You may designate an authorized agent to request any of the above rights on your behalf. You may make such a designation by providing the agent with a signed written document permission stating that the agent is authorized to make the request on your behalf. Your agent may contact us via the information provided above to make a request on your behalf. If you are submitting a request through an authorized agent, we may, as permitted by law, require:
Subject to applicable law, we may not discriminate against you for exercising any of the above-listed rights or any other rights under the CCPA or similar U.S. state comprehensive privacy laws, including by:
We may, however, charge different prices or rates, or provide a different level or quality of goods or services, if that difference is reasonably related to the value provided to Nox by your personal data, subject to the requirements of applicable law.
California law requires that Nox indicate whether it honors “Do Not Track” settings in your browser concerning targeted advertising. “Do Not Track” is a standard that is not currently in use by Nox. As it is not currently in use, Nox adheres to the standards set out in this Privacy Notice and does not monitor or follow any Do Not Track browser requests.
Cookies and online tracker opt-out: If you would like to opt-out of CPRA “sales or sharing” that happen through Cookies and related technologies, follow the steps below on each Nox site you use:
Click the cookie icon in the bottom left corner of the Site and select the “Reject All” option.
Please note, you must repeat this process for each device and browser that you use to access Nox Sites.
Contact: Please contact us as described in Section 13 for more information or to exercise a request regarding your US privacy rights.
Supervisory Authority:
If you are concerned about Nox's compliance with US laws relating to the privacy of your personal data, you may contact your Attorney General's Office.
List of Attorneys General: https://www.naag.org/find-my-ag/
Washington Consumer Health Data Privacy Notice
This Washington Consumer Health Data Privacy Notice applies to “consumer health data” collected from Washington state residents and those whose consumer health data is collected through SleepCharge by Nox Health Group Inc.(“SleepCharge,” “we,” “us,” or “our”) or affiliated website on which it is posted, as well as those whose consumer health data is collected in the State of Washington. This notice applies to Washington residents and those whose consumer health data is collected in Washington. Consumer health data means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status, under the Washington State My Health My Data Act (MHMDA). See also our other privacy notices that provide disclosures about personal information that is not consumer health data subject to MHMDA.
This notice does not apply where an exception or exemption applies such as with respect to protected health information under the Health Insurance Portability and Accountability Act (“HIPAA”) and data that is subject to the Gramm-Leach-Bliley Act (“GLBA”). When we are a covered entity, we provide separate HIPAA and GLBA privacy notices to certain customers and consumers as required under applicable laws and regulations. Most consumer health data we process is regulated under HIPAA or GLBA or is processed for a necessary function.
Consumer Health Data Collected
The personal information, including consumer health data, we collect varies based on your relationship with us. For example, if you visit our website we may collect personal information through tracking technologies essential to running our website.
We may collect the following categories of consumer health data:
The categories of consumer health data above may include the following personal information, when collected in connection with your past, present, or future physical or mental health status:
We process any deidentified consumer health data only in a deidentified fashion and will not attempt to reidentify such data.
Why We Collect and Use Consumer Health Data
To the extent we collect your Consumer Health Data as described above, we may use it for the following purposes:
Categories of Sources
We generally collect personal information, including consumer health data, from the following categories of sources:
Our Sharing of Consumer Health Data
The categories of third parties and other recipients with whom we may share consumer health data as necessary to provide our products and services requested by consumers are:
How to Exercise Your Rights
MHMDA grants certain rights including a right of access and deletion, subject to certain exceptions.
Upon request, Nox will provide you with a copy of personal data we hold about you, correct your personal data, or delete your personal data. You may also object to processing of your personal data or opt-out of automated decision making processes.
Please note, pursuant to the law, certain personal data is exempt from the above requests. To exercise any of these rights, please use our online form, email privacy@noxhealth.com, or call (855-617-6691).
We may request additional information from you, if necessary, to verify your identity or find your unique records in our systems. If you are the authorized representative making an access, correction or deletion request, we must take steps to verify your authority. This will require you to provide written proof of your authority.
We respect your right to privacy, and will not take any negative actions against you for asserting your rights.
If your request to exercise a right under the MHMDA is denied, you may appeal the denial. A method for submitting an appeal will be contained in our response. If your appeal is unsuccessful, you can raise a concern or lodge a complaint with the Washington State Attorney General at www.atg.wa.gov/file-complaint.
Contact
If you have any questions on the processing of your personal data, please contact us using the details below.
Nox Health Group Inc.
Address:
100 Kimball Place, Suite 100
Alpharetta, GA 30009
USA
Tel: 855-617-6691
Fax: 678 669 2274
Email: privacy@noxhealth.com