Your Privacy Matters
Effective Date: November 14, 2025
Last Updated: November 14, 2025
Opaida, Inc ("we," "us," or "our") is committed to protecting your privacy and ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) (EU) 2016/679, the Health Insurance Portability and Accountability Act (HIPAA) (45 C.F.R. Parts 160, 162, and 164), and the American Institute of CPAs (AICPA) Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (SOC 2). This Cookie Policy explains how we use cookies and similar tracking technologies on our website(s) and services (collectively, the "Services"). By using our Services, you consent to the practices described in this policy, subject to your rights under applicable laws.
If you are a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, or if our Services process protected health information (PHI) under HIPAA, additional protections apply as outlined below.
Cookies are small text files that are stored on your device (e.g., computer, tablet, or mobile phone) when you visit a website. They enable the website to recognize your device and remember certain information about your preferences or actions. We also use similar technologies, such as pixels, web beacons, and local storage (collectively, "Cookies").
We use Cookies to enhance your experience, improve our Services, and ensure compliance with legal obligations. Under GDPR, non-essential Cookies require your explicit, informed consent. For HIPAA-covered entities or business associates, Cookies will not be used to collect or transmit PHI without appropriate safeguards, including Business Associate Agreements (BAAs) where required.
We classify Cookies based on their purpose and duration. The table below summarizes the categories:
| Category | Description | Examples of Use Cases | Duration | Essential? |
|---|---|---|---|---|
| Strictly Necessary (Essential) | Required for the website to function and provide Services you request. These do not require consent. | Session management, security features (e.g., CSRF tokens), basic navigation. | Session or persistent (up to 2 years) | Yes |
| Performance/Analytics | Help us understand how users interact with our Services to improve functionality. Requires consent under GDPR. | Aggregated usage data, page load times (e.g., Google Analytics, anonymized). | Persistent (up to 2 years) | No |
| Functional | Remember choices to provide a personalized experience. Requires consent under GDPR. | Language preferences, login status. | Persistent (up to 1 year) | No |
| Targeting/Marketing | Deliver relevant ads or content based on your interests. Requires consent under GDPR. | Ad tracking (e.g., Google Ads, Facebook Pixel), retargeting. | Persistent (up to 13 months) | No |
| Health-Related (HIPAA-Specific) | If applicable to our Services, used only for PHI-related functions with encryption and access controls. | Secure session for patient portals (e.g., encrypted tokens). | Session only | Yes (if PHI-enabled) |
For a full list of Cookies, including names, providers, purposes, and durations, refer to our [Cookie Inventory] (available upon request or via our privacy dashboard).
We use Cookies for the following legitimate purposes, aligned with GDPR Article 6 and SOC 2 Privacy Criteria:
We do not use Cookies to profile sensitive data (e.g., health categories) without explicit consent or HIPAA authorization. All processing is limited to what is necessary (data minimization principle under GDPR).
To manage Cookies:
We share Cookie data only with:
No sale of Cookie data occurs. Transfers outside the EEA/UK use adequacy decisions or safeguards (e.g., EU-US Data Privacy Framework).
Under GDPR (Arts. 15-22), you have rights to access, rectify, erase, restrict, port, and object to Cookie data processing. For HIPAA individuals, you have rights to access, amend, and restrict PHI uses.
This policy applies globally but is tailored for cross-border compliance. Non-EEA users are protected under equivalent standards (e.g., CCPA opt-out notices where applicable).
We may update this policy to reflect legal changes or Service updates. Significant changes will be notified via email or site banner, with a 30-day grace period for consent renewal.
For questions, contact:
This policy is governed by [New Jersey law]. By using our Services, you acknowledge this policy.