California Privacy Supplement
- Effective Date:
- July 30, 2026
- Last Updated:
- July 30, 2026
This California Privacy Supplement ("Supplement") applies to California residents and supplements Rivendell's Privacy Policy. It is provided by Elrond Health Inc., doing business in California as Rivendell Insurance & Administration Services ("Rivendell," "we," "us," or "our").
This Supplement addresses:
- the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA")
- the California Online Privacy Protection Act ("CalOPPA")
- the California Confidentiality of Medical Information Act ("CMIA")
- the California Insurance Information and Privacy Protection Act ("IIPPA")
- other California privacy rights identified below
Different laws can apply to different information. A right or exception under one law does not automatically apply to all information Rivendell maintains.
1. California insurance identity
California insurance services are offered under the filed name Rivendell Insurance & Administration Services.
- legal entity: Elrond Health Inc.
- California filed name: Rivendell Insurance & Administration Services
- principal place of business: 156 2nd St, Unit 310, San Francisco, CA 94105
- California insurance license number: 6018541
- California Department of Insurance entity number: B20260025795
- National Producer Number: 22113786
Insurance availability and services vary by state. A license does not imply endorsement by the California Department of Insurance.
2. Notice at collection and prior 12-month practices
The table describes categories Rivendell may collect, the sources, purposes, recipients, and retention criteria. We do not collect every example from every person.
| California category | Examples | Sources | Business purposes and recipient categories | Retention criterion |
|---|---|---|---|---|
| Identifiers | name, postal and email address, phone, date of birth, account, IP and device identifiers, signature, Social Security number where required | you; guardian or representative; employer; plan; broker; device; identity provider | account, identity, enrollment, plan administration, support, security, legal compliance; disclosed to plans, authorized representatives, processors, financial and government recipients as needed | active service plus the applicable plan, insurance, financial, security, or legal period |
| Customer records under Civil Code §1798.80(e) | contact, insurance, education, employment, bank and financial information | you; employer; plan; broker; financial partners | quote, enrollment, administration, payment, support, compliance; disclosed to the parties needed for those functions | active service or transaction plus the applicable record period |
| Protected classifications | age, sex or gender where required, marital or family status, disability or accessibility information, and other enrollment classifications | you; representative; employer; plan | eligibility, enrollment, accessibility, plan administration, and legal compliance; disclosed to authorized plan and service parties | applicable enrollment, plan, reimbursement, and legal period |
| Commercial information | requested services, plan selection, premium and transaction history | you; employer; plan; broker; financial partners | provide, bill, reconcile, support, and improve Services; disclosed to plan, financial, accounting, and processing parties | active relationship plus transaction, tax, accounting, and legal period |
| Internet or network activity | pages, features, searches, clicks, browser, app activity, cookies, logs, crash and performance data | browser; device; app; analytics and security providers | operate, secure, debug, measure, and improve Services; disclosed to hosting, analytics, diagnostics, and security providers | while needed to operate, measure, and secure the Services, or for an incident or legal hold |
| Geolocation | IP-derived region and device location when permission is enabled | device; browser; location provider | security, location-dependent plan support, and nearby care search; disclosed to location, hosting, security, and care-search providers | only while needed for the request, security record, or approved product period |
| Sensory information | uploaded images or scans and related metadata | you; device; communication provider | document processing, support, security, and legal compliance; disclosed to authorized document, AI, communications, and plan recipients | according to the underlying document or support-record period |
| Professional or employment | employer, job title, work location, hire and termination, broker role and license | you; employer; plan; broker; licensing source | quote, eligibility, enrollment, administration, brokerage, access control, and compliance; disclosed to authorized plan, broker, regulator, and processor recipients | active relationship plus the applicable insurance, plan, and legal period |
| Education | student status or related eligibility information where a plan requires it | you; representative; employer; plan | dependent eligibility and plan administration; disclosed to the plan and authorized administrator | eligibility period plus the plan's record period |
| Inferences | extracted document fields, assistant output, service recommendations, risk and security signals | derived from categories above | operate, secure, support, and improve the requested Service; disclosed to authorized users and contracted processors | no longer than the source information or approved feature period |
| Sensitive personal information | government identifiers; account credentials; precise location if enabled; conditions, medications, major care, accessibility, lab, and invoice service or CPT information; communications content; financial account and card information | you; representative; employer; plan; provider; lab; broker; financial partner; device | requested plan, health, financial, security, accessibility, and legal functions; disclosed only to authorized recipients and processors for those functions | minimum period needed for the requested function and applicable plan, insurance, financial, security, or legal obligation |
The Privacy Policy gives more detail about each category and contains the record-specific retention criteria.
3. Information governed by health and insurance privacy laws
The CCPA contains data-specific exemptions, including for protected health information governed by HIPAA and certain information governed by IIPPA. Those exemptions do not mean that every record held by a health-plan service provider or insurance licensee is exempt.
Protected health information held for a group health plan is governed by the plan's Notice of Privacy Practices. Insurance-transaction information may be governed by IIPPA and the rights in Section 8 below. Rivendell also grants the CCPA rights in Section 7 for other Rivendell-controlled personal information, whether or not a statutory business threshold would independently require it.
California medical information
CMIA applies to medical information maintained through Rivendell's consumer health application. We:
- maintain the confidentiality of medical information
- disclose it to contracted service providers as permitted by Civil Code section 56.10(c)(3), under a valid authorization when one is required, or as otherwise required or permitted by law
- give the signer a copy of any required authorization and honor its stated limits
- limit redisclosure as law requires
- provide access to a medical profile or medical information at no charge
- apply special legal review to requests involving abortion, contraception, gender-affirming care, and related sensitive services
- do not disclose medical information for immigration enforcement except with express authorization or as otherwise required or permitted by California law
California law also restricts some subpoenas, investigations, and out-of-state access involving abortion and gender-affirming care that is lawful in California. We review those requests under California and federal law before disclosure and document a refusal when California law prohibits compliance.
An app permission, AI feature permission, or acceptance of a general privacy policy does not replace a separate CMIA authorization when one is required. A valid CMIA authorization identifies the information, disclosing and receiving parties, permitted use, expiration, and required rights, and is signed separately. We provide a copy to the signer. Contracted processing needed to provide the requested service ordinarily relies on the service-provider permission in Civil Code section 56.10(c)(3), not a section 56.11 authorization.
4. Purposes and sensitive personal information
We use personal information for the purposes in the table and Privacy Policy, including to:
- provide quotes, licensed producer services, enrollment, eligibility, administration, reimbursements, and support
- operate member plan, card, HSA, payment, bank-linking, document, assistant, and care-navigation features
- communicate and deliver requested notices
- secure, debug, measure, and improve the Services
- prevent fraud and harm
- comply with insurance, plan, health, financial, tax, accounting, litigation, and other law
We do not use sensitive personal information to infer characteristics for an unrelated purpose. We use and disclose it only to perform requested services, maintain security and integrity, prevent fraud, verify information, meet legal obligations, or for another purpose permitted without a right to limit under the CCPA.
If this changes, we will update this Supplement and provide a "Limit the Use of My Sensitive Personal Information" method when required.
5. Sale, sharing, advertising, and preference signals
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising. We have not knowingly sold or shared personal information of a person under 16.
We process a valid Global Privacy Control signal as an opt-out request where the CCPA applies and the signal relates to covered sale or sharing. Because there is no uniform Do Not Track standard, we do not otherwise respond to browser DNT signals.
We do not offer a financial incentive or price difference in exchange for personal information. If we introduce one, we will provide the required notice and obtain opt-in consent.
6. Artificial intelligence and automated decisionmaking
The Privacy Policy identifies third-party AI and document-processing providers, the features they support, and information that may be sent. A mobile feature will request explicit permission before sharing personal information with a third-party AI when required.
Rivendell does not use automated decisionmaking technology as the sole basis for a final adverse eligibility, coverage, reimbursement, or other significant plan decision when law requires human review.
7. CCPA rights
Rivendell grants each California resident the right to:
- know the categories and specific pieces of personal information collected
- know categories of sources, business purposes, and third-party recipients
- delete personal information, subject to exceptions
- correct inaccurate personal information
- opt out of sale or sharing
- limit certain uses and disclosures of sensitive personal information
- receive equal service and pricing without retaliation for exercising a right
These rights do not apply to every record. For example, Rivendell may need to retain plan, reimbursement, insurance, transaction, security, or legal records, and another law may govern a health or insurance record.
How to submit a CCPA request
You or an authorized agent may:
- use the privacy-request control in the app
- email privacy@rivendell.health
- call (646) 600-8840
- write to the California address in Section 12
We will confirm receipt within 10 business days and generally respond within 45 calendar days. If reasonably necessary, we may extend the response by up to 45 additional calendar days and will explain the extension.
We verify identity in proportion to the request and sensitivity. We may require an authorized agent to provide signed permission and may confirm identity or authority directly with you. A valid power of attorney will be handled as law requires.
If we deny a request in whole or part, we will explain the basis and any available complaint or appeal process.
8. California insurance privacy notice
This section is Rivendell's notice under IIPPA for personal information collected or received in connection with an insurance transaction.
Sources
We may collect insurance-transaction information from:
- applications, census, enrollment, health, reimbursement, and other information that you or an authorized representative provides
- employers, plans, brokers, producers, administrators, insurers, stop-loss carriers, providers, laboratories, and financial partners
- government, licensing, sanctions, public-record, and identity sources
- interactions with the Services and support
Disclosures
We may disclose insurance-transaction information without a separate authorization only as IIPPA or another law permits, including to:
- the person, employer, plan, broker, producer, administrator, insurer, stop-loss partner, provider, or financial party involved in the authorized transaction
- service providers that perform insurance, administrative, technology, document, communication, security, professional, or payment functions under required contractual controls
- regulators, law enforcement, courts, auditors, guaranty or rating organizations, and other legally authorized recipients
- a successor in a permitted business transaction
We will obtain a written authorization before disclosing medical-record information when California law requires one. An authorization will identify the information, purpose, recipient, expiration, and revocation method required by law. We do not disclose medical-record information to an affiliate or nonaffiliate for marketing without the required authorization.
Access and correction
You may make a written request to access recorded personal information that Rivendell can reasonably locate and retrieve. After verifying identity, we will respond within 30 business days as IIPPA requires. We will describe the information, identify recipients recorded during the prior two years where required, and explain how to obtain a copy. A lawful fee, if any, will be disclosed before copies are provided.
You may request correction, amendment, or deletion of recorded personal information. Within 30 business days, we will correct the record or explain the refusal and your right to file a concise statement of dispute. Where required, we will send a correction or dispute statement to specified prior recipients.
Access can be limited where IIPPA permits, including for information compiled for an investigation, litigation, or certain confidential sources. We will identify the legal basis for a denial.
Initial and annual notice
Rivendell will provide the required insurance privacy notice when an insurance relationship is established and at least annually while the customer relationship continues, subject to statutory exceptions. Delivery records will identify the recipient, version, date, and method. Electronic delivery will use the consent, access, and acknowledgment process required by California law.
Posting this Supplement online does not replace required delivery.
9. CalOPPA
The Privacy Policy and this Supplement identify:
- categories of personally identifiable information collected online
- categories of third parties that may receive it
- ways to review or request changes
- effective dates and update practices
- Rivendell's DNT and GPC response
We do not permit an independent third party to collect personally identifiable information about a member's authenticated activity over time and across unaffiliated websites for the third party's own advertising.
10. Other California rights
Shine the Light
California Civil Code §1798.83 permits certain residents to request information about disclosures of customer information to third parties for their direct-marketing purposes during the prior calendar year. Rivendell does not disclose customer personal information to third parties for their own direct marketing without consent. You may submit a request using "California Shine the Light" in the subject line.
Users under 18
If a California resident under 18 has a registered account and posted content publicly, the resident may request removal under Business and Professions Code §22581. Removal does not ensure complete erasure where retention is required or another user independently posted the information.
Rivendell's Services are not directed to minors for independent account creation. We do process minor dependent information submitted by a parent, guardian, employer, or plan as explained in the Privacy Policy.
11. Complaints
You may contact:
- the California Privacy Protection Agency or California Attorney General for a CCPA concern
- the California Department of Insurance at (800) 927-4357 for an insurance privacy concern
- the U.S. Department of Health and Human Services Office for Civil Rights for a HIPAA concern involving a covered plan
We will not retaliate against you for a good-faith request or complaint.
12. Contact
Privacy Officer, Rivendell Insurance & Administration Services, 156 2nd St, Unit 310, San Francisco, CA 94105, privacy@rivendell.health, (646) 600-8840
For a request, include your name, relationship to Rivendell, preferred contact method, the right you wish to exercise, and enough detail to identify the relevant records. Do not email a Social Security number, full financial account number, or detailed medical record.
We may update this Supplement. We will post a new effective date and provide any separate initial, annual, or material-change notice required by law.