Privacy Policy, Data Retention and Account Deletion
This Privacy Policy explains how ECAPLUS HEALTHCARE INNOVATIONS LLC collects, uses, stores, protects, retains, and deletes personal information and health-related data processed through the ECAPLUS website, mobile application, and digital services.
Document Information
| Version | 2.1 |
| Effective Date | June 2025 |
| Company | ECAPLUS HEALTHCARE INNOVATIONS LLC |
| Website | ecaplus.io |
| Contact | privacy@ecaplus.io |
1. Introduction
ECAPLUS HEALTHCARE INNOVATIONS LLC respects user privacy and is committed to protecting personal information, account information, and health-related data. This policy describes what information we collect, why we collect it, how long we retain it, and how users may request access, correction, account deletion, or data deletion.
ECAPLUS may process information in accordance with applicable privacy and healthcare data protection principles, including Dominican Republic Law 172-13, HIPAA where applicable, GDPR as an international best-practice reference, and applicable healthcare, tax, accounting, contractual, and security obligations.
2. Information We Collect
ECAPLUS may collect and process the following categories of information:
Personal Identification Data
- Full name.
- Date of birth.
- Identification document, where required for verification.
- Profile photo, if uploaded by the user.
- Postal address.
Contact and Account Data
- Email address.
- Phone number.
- Username or account identifier.
- Login activity and session activity.
- Device identifiers and IP address.
Health-Related Data
- Medical history.
- Diagnoses and symptoms reported by the user.
- Medical prescriptions.
- Laboratory results.
- Diagnostic imaging and uploaded medical files.
- Telemedicine and patient-follow-up records.
Operational and Payment Data
- Subscription status and billing history.
- Transaction references.
- Support tickets and customer service records.
- User preferences and notification settings.
- Security logs and audit records.
3. How We Use Information
ECAPLUS uses collected information for the following purposes:
- To create, manage, and secure user accounts.
- To provide telemedicine, patient-follow-up, and healthcare coordination services.
- To allow users and authorized healthcare providers to access relevant health records.
- To process subscriptions, payments, and billing records.
- To provide customer support and respond to user requests.
- To send service notifications, appointment reminders, and important account communications.
- To improve platform functionality, security, reliability, and user experience.
- To comply with legal, regulatory, medical, accounting, contractual, and security obligations.
4. Data Retention Policy
ECAPLUS retains personal information only for as long as necessary to provide services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support healthcare recordkeeping requirements.
| Data Category | Retention Period |
|---|---|
| Account profile data | While the account remains active and up to 24 months after account closure, unless earlier deletion is legally permitted and requested. |
| Contact information | While the account remains active and up to 24 months after account closure. |
| Support requests and service communications | Up to 3 years from the last interaction. |
| Security logs, access logs, and audit logs | Up to 12 months, unless a longer period is required for security, fraud prevention, or legal investigation. |
| Billing, subscription, and transaction records | Up to 7 years or as required by applicable tax, accounting, and financial regulations. |
| Medical records and health-related information | Retained as required by applicable healthcare laws, medical recordkeeping obligations, patient safety requirements, or provider obligations. |
| Uploaded documents and medical files | While needed to provide the service or as required by healthcare, legal, or operational obligations. |
| Backup copies | Up to 90 calendar days, after which backup copies are overwritten or purged according to the backup retention cycle. |
| Anonymized or aggregated data | May be retained without time limit when it cannot reasonably identify the user. |
5. Account Deletion
Users may request permanent deletion of their ECAPLUS account at any time. Account deletion removes or disables access to the user account and starts the deletion or anonymization process for eligible personal information.
How to Delete Your Account
- Open the ECAPLUS mobile application.
- Go to Settings.
- Select Privacy.
- Select Delete Account.
- Confirm the account deletion request.
After identity verification, ECAPLUS will deactivate the account and delete or anonymize eligible personal data from active systems within 15 business days, unless a legal, healthcare, tax, accounting, contractual, fraud prevention, security, or regulatory retention obligation applies.
6. How Users Can Request Data Deletion
Users may request deletion of their personal information and eligible health-related data through any of the following channels:
| Request Channel | Instructions |
|---|---|
| Mobile App | Open ECAPLUS → Settings → Privacy → Request Data Deletion or Delete Account. |
| Send a request to privacy@ecaplus.io with the subject: DATA DELETION REQUEST. | |
| Support Portal | Submit a support request under the category: Privacy and Data. |
| Written Request | 8538 NW 66th St, CE #7586, Miami, Florida 33166, USA. |
Required Information
- Full name registered on the platform.
- Email address associated with the account.
- Phone number associated with the account, if applicable.
- Type of request: full account deletion, partial data deletion, or anonymization.
- Copy of a valid government-issued identification document, when required to verify identity.
7. Data Deletion Process and Timelines
Once ECAPLUS receives a valid deletion request, the request is reviewed, the user’s identity is verified, and eligible data is deleted, restricted, or anonymized according to the following timelines:
| Process Stage | Maximum Timeline |
|---|---|
| Acknowledgment of receipt | Within 24 business hours. |
| Identity verification | Up to 3 business days. |
| Resolution notification | Up to 5 business days after verification. |
| Deletion from active systems | Within 15 business days after approval. |
| Deletion from backup systems | Up to 90 calendar days according to the backup retention cycle. |
| Final confirmation | Provided after the request has been completed or restricted due to legal retention obligations. |
8. Data That May Be Retained After a Deletion Request
Some information may not be immediately deleted if ECAPLUS is required to retain it for legal, regulatory, healthcare, accounting, contractual, fraud prevention, security, or dispute resolution purposes.
| Data Category | Reason for Retention |
|---|---|
| Medical records | Healthcare continuity, patient safety, and applicable medical recordkeeping requirements. |
| Prescription records | Healthcare, pharmacy, legal, and regulatory compliance. |
| Billing and transaction records | Tax, accounting, financial reporting, and dispute resolution obligations. |
| Security and audit logs | Fraud prevention, system integrity, security investigations, and legal compliance. |
| Records related to active disputes or investigations | Retained until the matter is resolved or as legally required. |
| Anonymized or aggregated data | May be retained because it cannot reasonably identify the user. |
9. User Privacy Rights
Depending on applicable law, users may have the following rights:
- Request access to personal information held by ECAPLUS.
- Request correction of inaccurate or incomplete information.
- Request deletion of eligible personal information.
- Request account deletion.
- Request restriction of processing where applicable.
- Object to processing for marketing or non-essential purposes.
- Request a copy of available account information in a standard format where applicable.
10. Sharing of Information
ECAPLUS does not sell personal information. ECAPLUS may share information only when necessary to provide services, comply with legal obligations, protect users, maintain platform security, or work with authorized service providers.
- Healthcare providers authorized to participate in the user’s care.
- Cloud hosting, infrastructure, security, and technical service providers.
- Payment processors and billing service providers.
- Laboratories, pharmacies, insurers, or healthcare partners where applicable.
- Regulatory, legal, or government authorities when required by law.
11. Security Measures
ECAPLUS uses administrative, technical, and organizational safeguards designed to protect personal information and health-related data against unauthorized access, loss, misuse, alteration, or disclosure.
- Access controls and role-based permissions.
- Authentication and session security controls.
- Encryption where appropriate.
- Audit logs and monitoring.
- Secure backup and recovery procedures.
- Internal privacy and security policies.
12. Children and Minors
ECAPLUS services involving minors must be used by or with the authorization of a parent, guardian, healthcare provider, or authorized representative where required. Health-related records of minors may be retained according to applicable healthcare and legal recordkeeping requirements.
Contact and Data Protection Requests
To exercise privacy rights, request account deletion, request data deletion, or ask questions about this Privacy Policy, users may contact ECAPLUS using the information provided here.
Miami, Florida 33166,
USA
For data deletion requests, use the subject: DATA DELETION REQUEST — [Full Name] — [Date].
ECAPLUS HEALTHCARE INNOVATIONS LLC
Privacy, Legal and Compliance Department
ECAPLUS HEALTHCARE INNOVATIONS LLC | ecaplus.io
8538 NW 66th St, CE #7586, Miami, Florida 33166, USA — June 2025