We collect account information (name, work email, phone), company and site details, device and location data needed for dispatch and live tracking, and payment method tokens. Technicians additionally provide credential, license, vehicle, and insurance documentation used for vetting.
Delivering our service requires processing injury-related information: triage answers, injury descriptions and photos, treatment records, drug test results where ordered, and signatures on aftercare reports. This information is sensitive health data. It is encrypted at rest, access is scoped by role, and it is used only to deliver care, produce required documentation, and support your compliance obligations.
We use data to dispatch and track consultations, generate aftercare reports, process payments and payouts, verify technician credentials, respond to support requests, and improve platform safety and reliability. We do not sell personal information, and we do not use injury data for advertising.
Injury and treatment records are shared with the employer that requested care, as required for workplace recordkeeping. We share limited data with service providers under contract — payment processing, hosting, and communications — and with authorities when the law requires it. Technicians see only the case details needed to respond.
Consultation and aftercare records are retained for as long as needed to support employer recordkeeping obligations, which for workplace injury logs can extend to five years or more, and thereafter deleted or de-identified. Account data is retained while your account is active and for a limited period after closure.
We maintain administrative, technical, and physical safeguards including encryption in transit and at rest, role-based access controls, and audit logging on access to health information. No system is perfectly secure, and we notify affected parties of incidents as required by law.
Depending on your state, you may have rights to access, correct, delete, or receive a copy of your personal information, and to limit certain uses of sensitive data. Submit requests to privacy@wits.example; we verify identity before acting and respond within the timelines the law requires.
Questions about this policy or our data practices can be sent to privacy@wits.example or by mail to WITs, Inc., San Diego, CA. If we update this policy, we will post the revised version here with a new effective date.