| Who holds it | Northwell, 71 Mill Street, Unit B, Austin, Texas 43086, United States. Details |
|---|---|
| What we take | What you type into the form or the chat, your IP address and browser, and ad click IDs. No card data, no accounts. Full list |
| Where it sits | With our hosting provider in the United States. Ad platforms may process it elsewhere. Transfers |
| How long | Inquiries 18 months, chat 12 months, logs 90 days, your cookie choice 12 months. Retention |
| Who else sees it | Google, Microsoft and Meta for advertising, only after you allow storage; our host and our mail provider. Named list |
| Advertising | We run Google Ads and Microsoft Advertising, and Meta Ads on some campaigns. Consent Mode v2 keeps ad signals denied until you say yes. How it works |
| Getting it out | Email or write to us. We answer within 7 days. Data request |
| Who to write to | [email protected] or +1 (779) 555-3858. Contact |
When this notice applies
This notice takes effect on September 27, 2026 and was last updated on that date. It covers northwell.us.com, the inquiry form, the support chat and the cookie banner. It does not cover the hospitals or practices a guide may help you reach. They keep their own records under their own notices, and we never see what your clinician writes.
One practical note before anything else. The desk does not need symptoms, diagnoses or medication lists to plan a visit or seat you in a class. Please leave them out of the form and the chat. If they arrive anyway, the guide deletes that part of the message.
Who is responsible for your data
The controller is Northwell, trading at northwell.us.com, with its office at 71 Mill Street, Unit B, Austin, Texas 43086, United States. That is the family-services desk: patient guides, class instructors and the careers team. Decisions about what this site collects are made there, and questions about it are answered there.
What we collect
From the inquiry form
When you send the form, hire4c4.php stores your name, phone, email, the street and city if you add them, the kind of inquiry, your message, the program you picked, and whether you ticked the consent box. Alongside it the server records your IP address, your browser's user-agent string, the page that referred you, the moment the form was rendered and the moment it was sent. The two timestamps are there to filter out automated spam.
From the support chat
The chat keeps the conversation you have with the desk, plus a name, phone, email and consent tick if you give them. A token is stored in your browser so that you can close the window and come back to the same conversation.
Cookie and storage identifiers
Your consent choice is kept in your browser under site_consent_v2. Nothing else on this site persists a choice. If you allow storage, the advertising tags set their own identifiers; the cookie statement lists each one.
Advertising click identifiers
If you arrive from an ad, the address you land on carries a click identifier: gclid from Google, msclkid from Microsoft or fbclid from Meta. It is recorded in the server log as part of the URL and, with your consent, read by the matching ad tag.
We hold no account, no password, no payment and no card data. Nothing is sold on this site and no payment is taken here.
What each piece is used for
- Form and chat contents: a guide calls or writes back, plans the visit, or holds a class seat. A careers inquiry goes to the careers team.
- IP address, user-agent and timestamps: blocking spam and abuse, and working out what went wrong when a message fails.
- Referring URL and click identifiers: telling which ad or page a visitor came from, so we can stop paying for ads that bring nobody useful.
- The consent record: remembering your answer so the banner does not ask on every page.
We do not use any of it to build profiles for sale, and we never pass it to an insurer or an employer.
Legal bases
Where a law such as the GDPR asks us to name the basis for each purpose, these are the ones we rely on.
| Purpose | Data | Legal basis |
|---|---|---|
| Answering your inquiry, booking a class seat | Form fields, chat | Steps taken at your request before a contract, and the contract itself once booked |
| Contacting you by phone or email | Name, phone, email | Consent, given by the tick box |
| Spam filtering and site security | IP, user-agent, timestamps, logs | Legitimate interest in keeping the desk usable |
| Ad measurement and remarketing | Click IDs, ad cookies | Consent, via the cookie banner |
| Remembering your cookie choice | site_consent_v2 | Legitimate interest, and a legal obligation to record consent |
The advertising platforms that send visitors here
This site receives paid clicks. We run campaigns on Google Ads and Microsoft Advertising, and Meta Ads sends traffic here when a campaign runs there. Each platform adds its own identifier to the link you click:
- Google Ads attaches
gclid. - Microsoft Advertising attaches
msclkid. - Meta Ads attaches
fbclid.
With your consent, the tag for that platform reads the identifier so the platform can count a sent form as a conversion against the ad. Without consent, the identifier sits only in our server log for 90 days and is not sent back to the platform. None of these platforms has any say over what the desk tells you, and nothing on this page should be read as a platform's endorsement of Northwell.
Consent Mode v2
Before the banner has an answer, Google Consent Mode v2 sets four signals to denied: ad_storage, ad_user_data, ad_personalization and analytics_storage. In that state the tags write no advertising or analytics cookies and send no personal data for ads. They may send cookieless pings that carry no identifier.
When you press Allow, the four signals switch to granted. When you press Decline, or later withdraw through Cookie settings in the footer, all four are set back to denied the same moment. Microsoft's UET tag and Meta's pixel follow the same answer. Your choice is stored under site_consent_v2 for 12 months, after which the banner asks again.
Who else receives data
- Google Ireland Ltd and Google LLC, for Google Ads. It attaches
gclidto a click and receives the Consent Mode signals. - Microsoft Ireland Operations Ltd, for Microsoft Advertising. It attaches
msclkid. Its own handling is covered by the Microsoft privacy statement at privacy.microsoft.com. - Meta Platforms Ireland Ltd, for Meta Ads. It attaches
fbclid, where a campaign runs there. - Our hosting provider, which serves this site and stores the inquiry database and the server logs.
- Our mail provider, which carries the notification of each new inquiry to the desk's inbox.
The host and the mail provider act on our instructions only. We do not sell personal data to anyone, and we do not share it for cross-context behavioral advertising unless you have allowed ad storage.
Transfers outside the country
Northwell is in the United States and the inquiry database is hosted there. If you write from Europe, your data travels to the United States when you press send. Google, Microsoft and Meta process data in the United States and elsewhere. Those transfers rely on the EU-U.S. Data Privacy Framework where the recipient is certified, and on the European Commission's standard contractual clauses where it is not.
How long we keep it
| Category | Kept for | Then |
|---|---|---|
| Inquiries and their email copies | 18 months | Deleted from the database and the inbox |
| Chat transcripts | 12 months | Deleted |
| Server and access logs | 90 days | Overwritten |
| Record of a consent choice | 12 months | Expires, and the banner asks again |
Eighteen months is long enough to cover a scheduled admission booked a year out and the class that follows it. We have not found a reason to keep anything longer.
How it is protected
Every page and form is served over HTTPS. The inquiry database is not reachable from the public web, and access to it needs a named login held by desk staff only. Guides see inquiries assigned to them. Hidden honeypot fields and the render timestamp stop most automated submissions before they are stored. No system is perfect; if we learn of a breach that affects you, we tell you directly and without delay.
Your rights under the GDPR
If you reach this site from the European Economic Area or the United Kingdom, the GDPR gives you these rights over the data we hold about you:
- access: a copy of it;
- rectification: correcting anything wrong;
- erasure: deleting it;
- restriction: pausing our use of it while a dispute is settled;
- portability: receiving it in a machine-readable file;
- objection: stopping use based on legitimate interest;
- withdrawing consent at any time, without affecting what was done before.
Withdrawing cookie consent takes one click on Cookie settings in the footer.
Your rights under US state law
US state privacy law applies to this site. California residents have rights under the CCPA as amended by the CPRA: to know what we collect and why, to access it, to delete it, to correct it, to limit use of sensitive information, and to opt out of the sale or sharing of personal information. Residents of other states with privacy laws in force, including Texas, Colorado, Connecticut, Virginia and Oregon, have similar rights. We do not sell personal information. The only sharing that could count as sharing for advertising is the ad tags described above, and declining in the banner opts you out of it. Using any of these rights changes nothing about the service you get: the same class seats, fees and callbacks.
Global Privacy Control
If your browser sends a Global Privacy Control signal (the Sec-GPC header), the site records it as an opt-out of sale and sharing and does not ask again. The four Consent Mode signals stay denied and the ad tags do not set cookies, whatever the banner last recorded for that browser.
Children
This site is for adults. We do not knowingly take data from anyone under 16, and the form and chat are not meant for them. Parents booking the new parents class or an infant CPR place give their own details, not a child's. If you think a child has written to us, email us and we delete it.
Complaints
Write to us first; most problems are fixed in one reply. You also have the right to complain to your state Attorney General, and in California to the California Privacy Protection Agency. Visitors from Europe may complain to the data protection authority where they live or work.
Making a data request
Email [email protected] with "Data request" in the subject, or write to Northwell, 71 Mill Street, Unit B, Austin, Texas 43086, United States. Say which right you are using and give the name, email or phone you used with us so we can find the records. We may ask one question to confirm it is you, usually by calling the number on file.
We answer within 7 days. An authorized agent may write on your behalf with your signed permission. There is no fee.
Accessibility
We aim for this site to meet WCAG 2.2 at level AA. Every page works with a keyboard alone, has a skip link, keeps text readable at 200% zoom and at 320px wide, and holds motion still when your system asks for reduced motion. The pinned class-morning section on the home page becomes a plain list in that case. Form errors are written out in words and announced to screen readers.
Known gaps: the chat widget's new-message notice depends on a live region that some older screen readers skip. If anything on the site gets in your way, call +1 (779) 555-3858 and a guide will do by phone whatever the page would have done, including taking a class booking.
Changes to this notice
When this notice changes, the new version goes up on this page with a new "last updated" date at the top. If the change adds a new recipient or a new use of your data, the cookie banner asks you again, and anyone with an open inquiry gets an email saying what changed.
Contact
Privacy questions reach a person at the desk, not a form processor. Email [email protected], call +1 (779) 555-3858 on a weekday, or write to 71 Mill Street, Unit B, Austin, Texas 43086, United States. The terms cover bookings and the cookie statement covers storage in detail. For anything else, the contact page has the hours.