Legal Policy

OrthoRPM Privacy & Security Policy

Please read this Policy carefully. If you do not agree with any part of this Policy, you should refrain from using the Site or our Products.

Effective Date: 03/01/2026

1. Introduction

OrthoRPM Inc. ("OrthoRPM," "we," "us," or "our") respects your privacy and is committed to protecting the information you share with us. This Privacy and Security Policy explains how we collect, use, protect, and disclose information when you use our website, mobile applications, devices, and related services (collectively, the "Services").

OrthoRPM develops and provides medical technology solutions designed to support rehabilitation and therapy, including the Gr!p smart hand therapy device and related digital therapy platform.

This policy applies when you:

  • Visit the OrthoRPM website
  • Use the Gr!p device or mobile application
  • Interact with OrthoRPM services through a healthcare provider

Please read this policy carefully.

By using our Services, you acknowledge that you have read and understood this Privacy Policy.

2. Relationship With Your Healthcare Provider

If you are using OrthoRPM through your doctor, therapist, or clinic, your healthcare provider controls your medical information.

In these cases:

  • Your healthcare provider is considered the "Covered Entity" under the Health Insurance Portability and Accountability Act ("HIPAA").
  • OrthoRPM acts as a "Business Associate" that processes certain health information on behalf of your healthcare provider.

Your healthcare provider's Notice of Privacy Practices governs how your Protected Health Information (PHI) is used for medical care.

OrthoRPM processes PHI only as permitted by agreements with your healthcare provider and applicable law.

3. Information We Collect

We may collect several types of information depending on how you use our Services.

Personal Information

Information that may identify you directly, including:

  • Name
  • Email address
  • Phone number
  • Insurance information

Health and Therapy Data

Information related to your rehabilitation therapy, including:

  • Therapy session data (repetitions, duration, compliance)
  • Device usage and performance metrics
  • Progress and outcome measurements
  • Treatment protocols assigned by your healthcare provider

Device and Usage Information

  • Device type and serial number
  • App usage patterns
  • IP address and browser information

4. How We Use Your Information

We use the information we collect to:

  • Provide and operate the OrthoRPM platform and Services
  • Deliver therapy programs assigned by your healthcare provider
  • Track and report your rehabilitation progress
  • Communicate with you about your treatment and device usage
  • Support healthcare providers in managing patient care
  • Improve and develop our products and Services
  • Ensure device functionality and performance
  • Comply with legal and regulatory requirements

We may use de-identified or aggregated data for research, product development, and system improvement purposes.

5. How We Share Information

OrthoRPM does not sell personal or health information.

We may share information only in the following situations:

With Your Healthcare Provider

Your healthcare provider may access therapy data to monitor treatment progress.

With Service Providers

We may use trusted vendors to help operate the platform, such as:

  • secure cloud hosting providers
  • data storage providers
  • technical service providers

These vendors must protect your information and may only use it to provide services for OrthoRPM.

Legal Requirements

We may disclose information if required by law, court order, or regulatory authority.

Safety and Fraud Prevention

We may disclose information when necessary to: investigate fraud, protect system security, or prevent harm to individuals.

6. How We Protect Your Information

Your Data is Protected

OrthoRPM implements administrative, physical, and technical safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction.

Security measures include:

  • encrypted data transmission
  • secure servers and firewalls
  • restricted access controls
  • system monitoring
  • HIPAA-aligned security practices

Despite these safeguards, no system can guarantee absolute security.

7. Data Retention

We retain information for as long as necessary to:

  • provide the Services
  • comply with legal obligations
  • support healthcare providers using the platform
  • maintain system integrity and security

If your healthcare provider stops using the OrthoRPM platform, your healthcare provider may request that certain data be returned or removed in accordance with applicable laws and contractual obligations.

De-identified data may be retained for research, product development, and system improvement purposes.

8. Cookies and Website Technologies

Our website may use cookies and similar technologies to:

  • improve website performance
  • remember user preferences
  • analyze website traffic
  • improve user experience

Cookies do not typically identify you personally.

You may manage cookie preferences through your browser settings.

9. Children's Privacy

OrthoRPM services are not intended for children under the age of 13 without parental or guardian involvement.

If we learn that personal information has been collected from a child without appropriate consent, we will take steps to delete the information.

10. Changes to This Privacy Policy

OrthoRPM may update this Privacy Policy from time time.

If significant changes are made, we will post the updated policy on our website and update the effective date.

11. Contact Information

If you have questions about this Privacy Policy or how OrthoRPM handles information, please contact:

OrthoRPM Inc.

674 2nd Street
Encinitas, CA 92024

Important: OrthoRPM does not use identifiable health information for marketing or advertising purposes.