Privacy Notice framework.
This reference page identifies the sections required for production. It is not a substitute for counsel-approved language aligned to actual data flows and vendors.
1. Scope and responsible entity
Identify the exact OneHolo legal entity, address and contact responsible for the website and each service.
2. Information collected
Describe contact, business, account, configuration, billing, investor-request, device, usage, support and communications data. General website forms should prohibit sensitive patient or protected health information.
3. Sources and purposes
Explain how information is collected and used for account creation, service delivery, support, security, analytics, communications, legal compliance and investor-access administration.
4. Vendors and disclosures
Identify categories of processors such as hosting, CRM, email, analytics, authentication, payment and electronic-signature providers. Do not claim data is never shared where processors receive it.
5. Cookies and analytics
Disclose actual cookies, pixels, attribution tools and consent choices. Implement consent controls where legally required.
6. Security and retention
Describe reasonable controls without guaranteeing perfect security. State retention criteria and deletion processes.
7. Individual rights
Address applicable access, correction, deletion, opt-out and appeal rights, including state-law requirements.
8. Communications
Explain email, telephone and SMS consent, opt-out mechanisms and message-frequency/cost disclosures where applicable.
9. Healthcare and sensitive information
State that public marketing forms are not intended for clinical, emergency or patient information. Separate customer deployments require contract-specific data and compliance review.
10. Contact and updates
Provide a monitored privacy contact and effective date. Material changes should use version control.
