Last Updated: May 14, 2026

Vitra Health (“Vitra” or “we”) values its users’ privacy. This Privacy Policy (“Policy”) will help  you understand how we collect and use personal information from those who visit our  website or make use of our online facilities and services, and what we will and will not do  with the information we collect. Our Policy has been designed and created to ensure those  affiliated with Vitra of our commitment and realization of our obligation not only to meet, but  to exceed, most existing privacy standards.  

We reserve the right to make changes to this Policy at any given time. If you want to make  sure that you are up to date with the latest changes, we advise you to frequently visit this  page. If at any point in time Vitra decides to make use of any personally identifiable  information on file in a manner vastly different from that which was stated when this  information was initially collected, the user or users shall be promptly notified by email.  Users at that time shall have the option as to whether to permit the use of their information  in this separate manner.  

This Policy applies to Vitra, and it governs any and all data collection and usage by us.  Through the use of vitrahealth.com you are therefore consenting to the data collection  procedures expressed in this Policy.  

Please note that this Policy does not govern the collection and use of information by  companies that Vitra does not control, nor by individuals not employed or managed by us. If  you visit a website that we mention or link to, be sure to review its privacy policy before  providing the site with information. It is highly recommended and suggested that you review  the privacy policies and statements of any website you choose to use or frequent to better  understand the way in which websites garner, make use of and share the information  collected.  

Specifically, this Policy will inform you of the following: 

IMPORTANT NOTE: Vitra is a covered entity under the Health Insurance  Portability and Accountability Act (“HIPAA”). In the course of providing  services to you, we may process your protected health information (“PHI”),  including health information you provide in connection with your care or  services. This Privacy Policy does not apply to our processing of such PHI.  Your PHI is protected by applicable state and federal law and is handled in 

accordance with our HIPAA Notice of Privacy Practices. Please see our HIPAA  Notice of Privacy Practices for more information about how we collect, use, and  disclose your PHI under HIPAA.  

What Types of Information Do We Collect?  

It is always up to you whether to disclose personally identifiable information to us,  although if you elect not to do so, we reserve the right not to register you as a user or  provide you with any products or services. This website collects various types of  information, such as: 

In addition, Vitra may have the occasion to collect non-personal anonymous  demographic information, such as age, gender, household income, political affiliation,  race and religion, as well as the type of browser you are using, IP address, or type of  operating system, which will assist us in providing and maintaining superior quality  service.  

Vitra may also deem it necessary, from time to time, to follow websites that our users  may frequent to glean what types of services and products may be the most popular to  customers or the general public.  

Please rest assured that this site will only collect personal information that you  knowingly and willingly provide to us by way of surveys, completed membership forms,  and emails. It is the intent of this site to use personal information only for the purpose  for which it was requested, and any additional uses specifically provided for on this  Policy.  

Why We Collect Information and For How Long  

We are collecting your data for several reasons: 

The data we collect from you will be stored for no longer than necessary. The length of  time we retain said information will be determined based upon the following criteria: the  length of time your personal information remains relevant; the length of time it is  reasonable to keep records to demonstrate that we have fulfilled our duties and obligations;  any limitation periods within which claims might be made; any retention periods prescribed  by law or recommended by regulators, professional bodies or associations; the type of  contract we have with you, the existence of your consent, and our legitimate interest in  keeping such information as stated in this Policy.  

How We Use the Information  

Vitra does not now, nor will it in the future, sell, rent or lease any of its client lists and/or  names to any third parties.  

Vitra may collect and may make use of personal information to assist in the operation of our  website and to ensure delivery of the services you need and request. At times, we may find  it necessary to use personally identifiable information as a means to keep you informed of  other possible products and/or services that may be available to you from vitrahealth.com.  

Vitra may also be in contact with you with regards to completing surveys and/or research  questionnaires related to your opinion of current or potential future services that may be  offered.  

Vitra uses various third-party social media features including, but not limited to, Facebook,  Twitter, Instagram, LinkedIn, YouTube and other interactive programs. These may collect  your IP address and require cookies to work properly. These services are governed by the  privacy policies of the providers and are not within Vitra’s control.  

How Do We Assure Privacy and Confidentiality?  

Vitra may not use or disclose the information provided by you except under the following  circumstances: 

Non-Marketing Purposes  

Vitra greatly respects your privacy. We do maintain and reserve the right to contact you if  needed for non-marketing purposes (such as bug alerts, security breaches, account  issues, and/or changes in Vitra products and services). In certain circumstances, we may  use our website, newspapers, or other public means to post a notice.  

Children under the age of 13  

Vitra’s website is not directed to, and does not knowingly collect personal identifiable  information from, children under the age of thirteen (13). If it is determined that such  information has been inadvertently collected on anyone under the age of thirteen (13), we  shall immediately take the necessary steps to ensure that such information is deleted from  our system’s database, or in the alternative, that verifiable parental consent is obtained for  the use and storage of such information. Anyone under the age of thirteen (13) must seek  and obtain parent or guardian permission to use this website.  

Unsubscribe or Opt-Out  

All users and visitors to our website have the option to discontinue receiving  communications from us by way of email or newsletters. To discontinue or unsubscribe  from our website please send an email that you wish to unsubscribe to  marketing@vitrahealth.com. If you wish to unsubscribe or opt-out from any third-party  websites, you must go to that specific website to unsubscribe or opt-out. Vitra will continue  to adhere to this Policy with respect to any personal information previously collected.  

Text Messaging (SMS) Communications  

Vitra may send you text message (SMS) communications in connection with your care and  our services. The following applies to all SMS communications from us. 

Types of Messages. We may send two categories of SMS messages: 

Consent – Healthcare and Operational Messages. By providing your mobile telephone  number in connection with your care or services and consenting to receive text  communications, you agree to receive healthcare and operational SMS messages from  us as described above. Consent is voluntary and is not a condition of receiving care or  services.  

Consent – Marketing and Promotional Messages. By expressly and affirmatively opting  in to receive marketing SMS communications from Vitra, including through a signed  consent form, a website opt-in checkbox, or other written mechanism, you provide your  prior express written consent to receive promotional text messages from us. This  consent is separate from any consent provided for healthcare or operational messages  and is not required as a condition of care or services.  

Opt-Out. You may withdraw consent to receive SMS messages at any time by replying  STOP to any message. A STOP reply will apply only to the category of messages from  which that message was sent. For example, replying STOP to a healthcare or  operational message will not affect your enrollment in marketing communications, and  vice versa. You will receive a single confirmation of your opt-out for that category and  will receive no further messages in that category. To re-enroll in any category, contact  us at marketing@vitrahealth.com.  

Reply HELP to any message for assistance.  

Message and Data Rates. Standard message and data rates may apply. Messaging  frequency may vary.  

Sharing of SMS Opt-In Data. Your mobile opt-in information and SMS consent will not  be sold, rented, or otherwise shared with third parties or affiliates. We may disclose  opt-in information to service providers who deliver SMS communications on our behalf,  including our VOIP and communications vendors. Such providers are authorized to use  this information solely to facilitate our communications with you, are subject to  confidentiality obligations, and where applicable operate under a Business Associate  Agreement consistent with HIPAA requirements.  

External Links  

Our website may contain links to affiliate and other websites. Vitra does not claim nor  accept responsibility for any privacy policies, practices and/or procedures of other such  websites. Therefore, we encourage all users and visitors to be aware when they leave our 

website and to read the privacy statements of every website that collects personally  identifiable information. This Online Privacy Policy Agreement applies only and solely to the  information collected by our website.  

Notice to European Union Users  

Vitra’s operations are located primarily in the United States. If you provide information to  Vitra, your information will be transferred from the European Union (EU) to the United  States and processed here. By providing personal information to us, you are consenting to  its storage and use as described in this Policy. Please note that data protection laws in the  United States may differ from those in your country of residence.  

Security  

Vitra takes precautions to protect your information. When you submit sensitive information  via the website, your information is protected both online and offline. Wherever we collect  sensitive information (e.g. credit card information), that information is encrypted and  transmitted to us in a secure way. You can verify this by looking for a lock icon in the  address bar and looking for “https” at the beginning of the address of the webpage.  

While we use encryption to protect sensitive information transmitted online, we also protect  your information offline. Only employees who need the information to perform a specific job  (for example, billing or customer service) are granted access to personally identifiable  information. The computers and servers in which we store personally identifiable  information are kept in a secure environment. This is all done to prevent any loss, misuse,  unauthorized access, disclosure or modification of the user’s personal information under  our control.  

Vitra also uses Secure Socket Layer (SSL) for authentication and private communications  to build users’ trust and confidence in the internet and website use by providing simple and  secure access and communication of credit card and personal information. 

Acceptance of Terms  

By using Vitra’s website, you are hereby accepting the terms and conditions stipulated  within this Policy. If you are not in agreement with our terms and conditions, then you  should refrain from further use of our sites. In addition, your continued use of our  website following the posting of any updates or changes to our terms and conditions  shall mean that you agree and accept such changes.  

How to Contact Vitra  

If you have any questions or concerns regarding the Policy related to our website,  please feel free to contact us at the following email, telephone number or mailing  address.  

Email:  

Telephone Number: (508) 978-1841  

Mailing Address:  

Vitra Health  

150 Wood Rd., Ste. 201 Braintree, Massachusetts 02184  

DISCLAIMER OF WARRANTY  

Although we work very hard to provide the user with the most current and accurate  information, we cannot and do not warrant that everything you see on the website is  up-to-date, error free, or complete. While we may periodically add, modify, or delete  any of the content, we do not make any commitment or assume any obligation or duty  to do so. The user should assume that the information is current and up-to-date only as  of the date it is posted to the website. Any item with a fee or cost associated may be  subject to change at any time and without prior notification.  

GDPR Disclosure:  

If you answered “yes” to the question Does your website comply with the General Data  Protection Regulation  

(“GDPR”), then the Privacy Policy above includes language that is meant to account for  such compliance. Nevertheless, in order to be fully compliant with GDPR regulations  your company must fulfill other requirements such as: (i) doing an assessment of data  processing activities to improve security; (ii) have a data processing agreement with any  third party vendors; (iii) appoint a data protection officer for the company to monitor  GDPR compliance; (iv) designate a representative based in the EU under certain  circumstances; and (v) have a protocol in place to handle a potential data breach. For 

more details on how to make sure your company is fully compliant with GDPR,  please visit the official website at https://gdpr.eu. Vitra and its affiliates are in no  way responsible for determining whether or not your company is in fact compliant  with GDPR and takes no responsibility for the use you make of this Privacy Policy  or for any potential liability your company may face in relation to any GDPR  compliance issues.  

COPPA Compliance Disclosure:  

This Privacy Policy presumes that your website is not directed at children under the  age of 13 and does not knowingly collect personal identifiable information from them  or allow others to do the same through your site. If this is not true for your website  or online service and you do collect such information (or allow others to do so),  please be aware that you must be compliant with all COPPA regulations and  guidelines in order to avoid violations which could lead to law enforcement actions,  including civil penalties.  

In order to be fully compliant with COPPA your website or online service must fulfill  other requirements such as: (i) posting a privacy policy which describes not  only your practices, but also the practices of any others collecting personal  information on your site or service — for example, plug-ins or ad networks; (ii)  include a prominent link to your privacy policy anywhere you collect personal  information from children; (iii) include a description of parental rights (e.g. that you  won’t require a child to disclose more information than is reasonably necessary, that  they can review their child’s personal information, direct you to delete it, and refuse  to allow any further collection or use of the child’s information, and the procedures to  exercise their rights); (iv) give parents “direct notice” of your information practices  before collecting information from their children; and (v) obtain the parents’  “verifiable consent” before collecting, using or disclosing personal information from a  child. For more information on the definition of these terms and how to make sure  your website or online service is fully compliant with COPPA please visit  www.ftc.gov/tips-advice/business-center/gu.