Privacy Policy

1. Introduction

Welcome to Hive Health Philippines, Inc., (“us”, “we”, or “our”), the parent company of Health Plan Philippines, Inc. We value your privacy and are committed to protecting your personal data in accordance with applicable laws and regulations.

This Privacy Policy explains how we collect, use, disclose, store, protect, and otherwise process your personal data when you visit our website at https://ourhivehealth.com, use our web application, communicate with us, or otherwise interact with our products and services (collectively, the “Services”).

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.
2. Scope of this Privacy Policy

This Privacy Policy applies to personal data that we collect from:
  • visitors to our website and web application;users of our Services;
  • individuals who contact us or submit inquiries;
  • members, dependents, and other individuals whose information is submitted to us in connection with healthcare-related products or services;
  • representatives of corporate clients, partners, providers, and vendors; and
  • applicants or individuals who otherwise engage with us.
3. Personal Data We Collect

Depending on the nature of your interaction with us, we may collect and process the following categories of personal data:
  • Personal and Contact Information

    Such as your full name, email address, mobile number, date of birth, gender, address, and other contact details.
  • Health and medical information

    Such as medical history, medical records, diagnoses, procedures, treatment information, clinical abstracts, operation records, letters of authorization, details of providers consulted or visited, and medical and dental utilization information.
  • Account, transaction, and service-related information

    Such as information relating to your use of our Services, account activity, healthcare coverage purchased, requests, inquiries, availments, claims, reimbursements, and payments.
  • Technical and usage information

    Such as your Internet Protocol (IP) address, browser type and version, device identifiers, mobile device information, pages visited, dates and times of access, time spent on pages, and other diagnostic or analytics data.
  • Location information

    If you permit location access on your device, we may collect and use location data to support certain service features and improve your experience.
  • Cookies and similar tracking technologies

    We may collect information through cookies, web beacons, tags, scripts, and similar technologies as described in this Privacy Policy.
  • Other information you voluntarily provide

    Including information submitted through forms, communications, support requests, surveys, or other interactions with us.
Where applicable, some of the personal data we process may constitute sensitive personal information under applicable law, including health-related information.
4. How We Collect Personal Data

We may collect personal data through the following means:
  • directly from you when you fill out forms, create or use an account, submit inquiries, or communicate with us;
  • when you use our website, web application, and other digital platforms;
  • from your employer, principal member, dependent, or authorized representative in connection with healthcare benefits or coverage;
  • from healthcare providers, clinics, hospitals, laboratories, or other service partners involved in your care or in the delivery of our Services;
  • from third-party service providers and business partners who support our operations; and
  • through cookies, analytics tools, and other similar technologies when you browse our website or use our digital platforms.
If you provide us with the personal data of another individual, you represent that you are authorized to do so and that the relevant individual has been informed of the disclosure and processing of such personal data in accordance with applicable law.
5. Purposes of Processing

We collect and process personal data for legitimate and lawful business purposes, including the following

Primary Purposes
We may use your personal data to:
  • provide, operate, maintain, and improve our Services;
  • verify your identity and manage your relationship with us;
  • process registrations, applications, enrollments, and requests;
  • facilitate healthcare-related services, including care coordination, service availment, utilization review, and customer support;
  • process claims, reimbursements, payments, and other transactions;
  • communicate with you regarding your account, benefits, coverage, requests, or service-related concerns;
  • fulfill obligations arising from contracts entered into between you and us, or between us and your employer or other authorized party;
  • support your medical needs and healthcare coverage purchased through or administered using our Services; and
  • comply with legal, regulatory, contractual, and internal governance requirements.
Secondary and Related Purposes
We may also use your personal data to:
  • monitor and analyze usage of our Services;
  • improve user experience, service quality, and operational efficiency;
  • conduct internal reporting, analytics, research, planning, and statistical analysis;
  • detect, prevent, and investigate fraud, abuse, security incidents, and technical issues;
  • protect the rights, property, and safety of Hive Health, our users, our partners, and the public;
  • enforce our terms, policies, and contractual rights;
  • provide service notices, renewal reminders, support updates, and other administrative communications;
  • send news, special offers, and information about products, services, and events similar to those you have purchased or inquired about, where permitted by law and subject to your preferences; and
  • process your information for any other purpose disclosed to you at the point of collection or with your consent, where required.
6. Legal Basis for Processing

We process personal data on one or more lawful bases, as applicable, including:
  • your consent, where required;
  • the performance of a contract or to take steps at your request prior to entering into a contract;
  • compliance with legal and regulatory obligations;
  • the protection of lawful rights and interests; and
  • other lawful bases recognized under applicable data protection laws.
7. Cookies and Similar Technologies

We use cookies and similar tracking technologies to support and improve our Services. These technologies help us:
  • keep the website and application functioning properly;
  • remember your preferences and settings;
  • understand user activity and traffic patterns;
  • improve platform performance and security; and
  • analyze how our Services are used.
Examples of cookies we may use include:
  • Session Cookies for operating our Services;
  • Preference Cookies for remembering settings and preferences; and
  • Security Cookies for protecting user sessions and system integrity.
You may configure your browser to refuse cookies or alert you when cookies are being sent. However, disabling cookies may affect certain functionalities of the Services.
8. Analytics and Third-Party Tools

We may use third-party analytics and related service providers to monitor and analyze usage of our Services.

For example, we may use Google Analytics to help us understand website traffic, user behavior, and Service performance. These providers may process technical and usage information in accordance with their own privacy policies.
9. Payments

We may provide paid products and/or services within Service. In that case, we use third-party services for payment processing (e.g. payment processors).

We will not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.

The payment processors we work with are:
10. Disclosure and Sharing of Personal Data

We may disclose or share your personal data, to the extent necessary and subject to applicable law, with the following:
  • our parent company, affiliates, and related entities;
  • healthcare providers, clinics, hospitals, laboratories, and other medical or dental service partners involved in the delivery of healthcare-related services;
  • contractors, consultants, professional advisers, and service providers who support our business operations, including hosting, technology, support, analytics, communications, payments, and security;
  • your employer, plan sponsor, or authorized representative, where relevant to the administration of benefits or services and as permitted by law;
  • banks and other financial institutions involved in payment processing;
  • regulators, courts, law enforcement agencies, and government authorities, where required or permitted by law; and
  • other parties where disclosure is necessary to protect rights, investigate violations, respond to lawful requests, or complete corporate transactions such as mergers, acquisitions, or asset sales.
All disclosures are made only for legitimate purposes and, where applicable, subject to contractual, organizational, and technical safeguards.
11. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for business, legal, regulatory, contractual, accounting, audit, dispute resolution, and enforcement purposes.

Usage data may be retained for a shorter period, except where it is needed to improve system security or functionality, or where longer retention is required or permitted by law.

When retention is no longer necessary, we will securely dispose of, delete, anonymize, or otherwise render the data inaccessible, in accordance with applicable law and internal policies.
12. Data Protection and Security Measures

We maintain appropriate organizational, physical, and technical security measures designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.

These measures may include:
  • access controls and role-based restrictions;
  • secure servers, encryption, firewalls, and anti-malware tools;
  • logging, monitoring, and security review processes;
  • confidentiality obligations for personnel and service providers; and
  • incident response and breach management procedures
While we strive to use commercially reasonable means to protect personal data, no method of transmission over the internet or method of storage is completely secure. Accordingly, we cannot guarantee absolute security.

In the event of a personal data breach that is subject to notification requirements under applicable law, we will provide the required notifications and take appropriate remedial measures.
13. Your Rights as a Data Subject

Subject to applicable law and reasonable verification of your identity, you may have the right to:
  • be informed about the processing of your personal data;
  • access your personal data;
  • correct or update inaccurate or incomplete personal data;
  • object to processing in certain circumstances;
  • withdraw consent, where processing is based on consent;
  • request erasure, blocking, or restriction of processing where legally applicable;
  • request data portability, where applicable; and
  • lodge a complaint with the relevant data protection authority.
Please note that some rights are subject to legal limitations and exceptions.
14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, Services, or legal and regulatory requirements.

Any updated version will be posted on this page, and where required or appropriate, we may provide additional notice through email, website prompts, or other appropriate means. The revised version becomes effective on the date indicated at the top of this Privacy Policy.
15. Contact Us

If you have questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data, you may contact the Data Protection Officer of Hive Health Philippines at: privacy@ourhivehealth.com