NowRPM Privacy Policy & Terms of Use

Last Updated: 12/04/2025

NowRPM (“NowRPM”, “we”, “our”, or “us”), which may be contacted at info@nowrpm.com, provides this Privacy Policy to explain how we collect, use, disclose, and otherwise process personal information through the NowRPM mobile and web applications (“Software”) and the NowRPM Clinical Portal (together, “NowRPM”). This policy applies solely to the NowRPM applications and clinical portal and does not apply to the NowRPM website located at www.nowrpm.com.

By accessing or using the NowRPM mobile or web applications, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy and the Terms of Use contained herein. If you do not agree, do not install or use the Software.

References to “you” or “your” include both the individual user and any person or entity on whose behalf you act.


1. What This Privacy Policy Covers

This Privacy Policy explains how NowRPM collects, receives, uses, stores, and discloses Personally Identifiable Information (PII) and Personal Health Information (PHI) belonging to users of the NowRPM application and clinical portal.

NowRPM operates as the data controller for data collected through the NowRPM applications and clinical portal.

NowRPM may be used by adults and children. If the User is a minor, a parent or legal guardian must register on their behalf. If the child is under 16 years old, verifiable parental consent is required for the collection and processing of personal data.


2. Information We Collect

A. Information Provided During Registration

NowRPM collects the following information directly from Users or their authorized caregivers:

  • Full name
  • Date of birth
  • Medical history and clinical treatment history
  • Drug abuse history
  • Medication and dosing
  • Drug testing schedules
  • Check-ins and registered locations
  • Geographical location when check-ins or events occur
  • Sleep metrics
  • Drug use history
  • Primary care provider information
  • Billing information
  • Clinical responses, surveys, and questionnaires
  • Designated caregiver or treatment provider information

Users who provide caregiver or provider information warrant that they have obtained a signed HIPAA release and necessary consents before sharing such data with NowRPM.


B. Device and Technical Information

NowRPM automatically collects and stores information through the Software Development Kit (SDK) of supported devices, including:

1. Physiological Information

Collected in real time through wearable sensors:

  • Biometric and physiological data
  • Sensor and algorithm-driven metrics
  • Automatically transmitted via Bluetooth® from the device to the App and then to the clinical portal

2. Technical Information

  • IP address
  • Device identifier
  • Device type, operating system, and version
  • Bluetooth® and WiFi status
  • Geolocation (only during physiological events or manual check-ins)
  • Survey responses or lack thereof
  • Contact attempts to assigned support contacts
  • Breathing exercise usage
  • Dates and times of App access

3. Clinical Information

  • DBT and clinical question responses
  • Journaling entries
  • User engagement metrics
  • General in-app and portal usage data

4. Geographical Information

  • Location when an event is detected
  • Check-in location data

All PHI is transmitted and stored in compliance with HIPAA, HITECH, and industry-standard encryption protocols.


3. How We Use Personal Data

NowRPM processes PHI and PII to provide services to the User and their healthcare providers.

A. Healthcare Delivery

  • Access by Covered Healthcare Entities, Practitioners, Clinicians, and Clinical Partners
  • Support for treatment, monitoring, and clinical decision-making

B. Application & Service Operations

  • Providing application functionality
  • Billing and payment processing
  • Customer support and technical assistance
  • Measuring service performance
  • Handling complaints and disputes
  • Performing credit recovery or assignments

C. Data Processing for Improvement (Legitimate Interest)

NowRPM may also use data for:

  1. Application testing, updates, and development
  2. Product research and enhancement, including use of AI/ML
  3. De-identifying and aggregating data for internal research
    • You own your identifiable data
    • NowRPM owns the de-identified version
  4. Merger, acquisition, or due diligence activities (de-identified data only)

Users may object at any time (see Section 9).


4. Legal Basis for Data Processing

A. Contractual Necessity

Processing is required to deliver the Services, referencing Sections 2 and 3.

B. User Consent

Certain PHI categories require explicit consent. If consent is withdrawn, NowRPM may be unable to provide services.

C. Legitimate Interest

Used for research, improvement, AI development, and due diligence.


5. Data Security

  • Secure Socket Layer (SSL)
  • HIPAA-compliant encryption
  • Firewalls and secure authentication
  • HIPAA/HITECH-approved secure storage

No system can guarantee absolute security.


6. Who We Share Data With

For Contractual Purposes:

  • Covered Healthcare Entities
  • Covered Healthcare Practitioners
  • Authorized Clinicians and Partners
  • Softbir group companies
  • Government authorities

For Legitimate Interest:

  • Third-party service providers
  • Potential acquiring entities
  • Authorized healthcare providers

7. Data Retention

  • For the duration of service provision
  • For 10 years after contract termination, unless:
    • Legal claims require longer retention
    • Applicable laws require additional storage

8. User Rights

Users may contact info@nowrpm.com to:

  • Request access
  • Request updates/corrections
  • Request deletion (where lawful)
  • Withdraw consent
  • Object to processing

9. Data Protection Officer

The DPO may be contacted at info@nowrpm.com.


10. Updates

This policy may be updated periodically and will be available at www.nowrpm.com.


11. License Terms & Conditions

NowRPM provides a limited, non-exclusive, non-transferable license to use the Application.

  • No copying or modifying
  • No reverse engineering
  • No selling or leasing
  • No redistribution

12. Restrictions & Disclaimer of Warranty

The Application is for general informational use only.

It is provided “as is,” without warranties including merchantability, accuracy, completeness, reliability, fitness for purpose, or non-infringement.


13. Limitation of Liability

  • NowRPM is not liable for direct, indirect, incidental, special, or consequential damages.
  • Total liability shall not exceed $1.00.

14. Export Control

Users agree not to export the Application in violation of applicable laws.


15. Indemnification

Users agree to indemnify NowRPM against claims, losses, damages, and attorney fees resulting from use of the Application.