Skip to content

ENAVVI, INC.

eNavvi Consumer Health Data Privacy Policy

For Washington and Nevada Residents and Others Whose Data Is Collected in Washington or Nevada

This Consumer Health Data Privacy Policy (“Policy”) describes eNavvi, Inc.’s (“eNavvi,” “we,” or “us”) practices for collecting, using, and sharing the consumer health data of Washington and Nevada residents and of other individuals whose consumer health data is collected while they are in Washington or Nevada, as those terms are defined in the Washington My Health My Data Act and Nevada Senate Bill 370 (Nevada Revised Statutes Chapter 603A), in connection with the eNavvi Patient Wallet (the “Wallet”).

This Policy applies only to the consumer health data described below. It does not apply to your prescription history or your prescriber’s visit notes, which are protected health information handled under the Health Insurance Portability and Accountability Act as part of eNavvi’s business associate relationship with your prescriber’s practice. Other aspects of your use of the Wallet are described in the eNavvi Patient Wallet Privacy Notice, available at enavvi.com/wallet-privacy.

Consumer Health Data We Collect

We collect the following categories of consumer health data:

  • Your Self-Entered Medication List, if you choose to create one within the Wallet.
  • Biometric data collected as part of identity verification, including a government-issued identification document image and a selfie, and the facial geometry data derived from them.
  • Device and network information collected by our identity verification provider during the verification session, including your IP address, an approximate location derived from your IP address, your device type, operating system, and browser, device or browser identifiers, and network security indicators. This information is collected to verify that the verification session is genuine. It is not biometric data and is listed separately for that reason.
  • The ZIP code or address you type within the Wallet so that pharmacies can be shown to you sorted by distance. The Wallet does not access your device’s location and does not request location permission.
  • Your selection of a pharmacy and your designation of a Preferred Pharmacy, to the extent that information is not protected health information that we handle on behalf of your prescriber’s practice.

Sources of Consumer Health Data

We collect this consumer health data directly from you: when you choose to create a Self-Entered Medication List, when you complete identity verification to register for the Wallet, and when you enter a location or select a pharmacy within the Wallet.

How We Use Consumer Health Data

We use this consumer health data only to:

  • Operate the Wallet and provide the services you have requested.
  • Verify your identity and maintain the security of your account.
  • Comply with our legal obligations.

We do not use this consumer health data for advertising. We do not use a geofence to identify or track consumers, to collect consumer health data, or to send notifications, messages, or advertisements to consumers, near any location that provides in-person health care services.

How We Share Consumer Health Data

We do not sell your consumer health data. We will not sell your consumer health data without first obtaining your valid authorization, separate from your consent to our collection and sharing of that data, in the form Washington or Nevada law requires.

We share your consumer health data only with processors who help us provide the Wallet, under contracts that limit their use of it to that purpose. This currently includes Persona Identities, Inc., for identity verification. If you create a Self-Entered Medication List and give your separate consent to share it, we share it with your prescriber and your prescriber’s practice so that it appears, marked as entered by you, in their view of your medication history; we will not share it with your prescriber without that consent. We do not share your consumer health data with any affiliate of eNavvi. We do not otherwise disclose your consumer health data to third parties, except to prevent or respond to security incidents, fraud, or other illegal activity, or as required by law.

Your Rights

If you are a Washington or Nevada resident, or your consumer health data was collected while you were in Washington or Nevada, you have the right to:

  • Confirm whether we collect, share, or sell your consumer health data.
  • Access the consumer health data we have collected about you, including a list of any third parties and affiliates with which we have shared it and, for each, an email address or other online mechanism you can use to contact them.
  • Withdraw your consent to our collection or sharing of your consumer health data.
  • Request that we delete your consumer health data, including from our archived and backup systems, and that we notify our processors and any affiliate or third party to which we have provided it of your deletion request.

To exercise any of these rights, contact us at help@enavvi.com or eNavvi, Inc., 21 Esfahan Dr, San Jose, CA 95111. You do not need to create a new account to submit a request. We will respond within 45 days, which we may extend once by an additional 45 days if reasonably necessary, in which case we will notify you of the extension and the reason for it.

If we decline to act on your request, you may appeal by contacting us at the same address. We will inform you in writing of our decision within 45 days of receiving your appeal. If your appeal is denied, we will provide you with information on how to contact the Washington Attorney General or, for Nevada residents, the Nevada Attorney General.

Contact Us

If you have questions about this Policy, contact us at help@enavvi.com or eNavvi, Inc., 21 Esfahan Dr, San Jose, CA 95111.

5,000+

verified prescribers already on eNavvi — every one identity-proofed and license-checked.

Drummond EPCS Certified
Certified for electronic controlled-substance prescribing.
Surescripts Network Alliance Certified
On the same network the U.S. pharmacy system already runs on.
SOC 2 Type 2
Patient data handled under independently audited security controls.
Native NCPDP SCRIPT v2023011
Built native on the standard others must migrate to by 2028.