Privacy Policy
PSYSOED DYNAMICS, LLC d/b/a Groundbreaker Therapy
Website: www.groundbreakertherapy.com
Date of Last Revision: 1 September 2026
Contents
- Introduction And Scope
- Definitions
- Categories Of Personal Information Collected
- New York Statutory Private Information
- Sources Of Personal Information
- Purposes And Legal Bases For Processing
- Cookies, Web Beacons, And Tracking Technologies
- Universal Opt-Out Preference Signals And Global Privacy Control
- Disclosure And Sharing Of Personal Information With Third Parties
- Algorithmic Recommendations And Feed Personalization Disclosures
- Data Safeguards And Information Security Program Under New York SHIELD Act
- Data Retention And Destruction Protocols
- Data Breach Notification Procedures
- Children’s And Minors’ Privacy Under Federal COPPA And New York Law
- State-Specific Consumer Privacy Rights And Choice Architecture
- Notice To California Residents And CCPA/CPRA Disclosures
- Third-Party Websites, Applications, And External Integrations
- Cross-Border Data Transfers And International Users
- Policy Modifications, Material Changes, And Retroactive Consents
- Dispute Resolution, Governing Law, And Venue
- Contact Information And Regulatory Inquiries
1. Introduction And Scope
1.1 Purpose and Applicability. This Privacy Policy governs the collection, use, retention, disclosure, and Processing of Personal Information and Private Information by PSYSOED DYNAMICS, LLC, d/b/a Groundbreaker Therapy, together with Matthew G. Mandelbaum, PhD (collectively, the “Company,” “Controller,” “we,” “us,” or “our”). This Privacy Policy applies to any individual or Consumer who accesses, registers with, browses, or otherwise uses our websites, applications, and associated services (collectively, the “Systems”). By accessing or using the Systems, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
1.2 Exclusions and Third Parties. This Privacy Policy does not apply to information collected through any third-party website, application, platform, or service that may link to, be linked from, or otherwise be accessible through the Systems. We are not responsible for the privacy practices, content, or security of any such third parties.
1.3 Role as Controller. Unless otherwise expressly indicated in a separate agreement or notice, the Company serves as the data controller or “business” regarding all Personal Information and Private Information collected through the Systems, determining the purposes and means of all such Processing in accordance with applicable federal law and the laws of the State of New York.
2. Definitions
2.1 Interpretation and Operative Effect. As used in this Privacy Policy, capitalized terms have the respective meanings assigned to them in this Section 2. Unless the context clearly requires otherwise, terms defined in the singular include the plural and vice versa, and references to any statute, regulation, or statutory provision include that provision as amended, consolidated, or reenacted from time to time, including all statutory instruments, rules, or orders issued thereunder.
2.2 “Breach of the Security of the System” or “Data Breach” means an unauthorized acquisition of or unauthorized access to computerized data that compromises the security, confidentiality, or integrity of Personal Information or Private Information maintained by the Company, as defined under New York General Business Law Section 899-aa.
2.3 “CCPA/CPRA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, codified at California Civil Code Section 1798.100 et seq., and all implementing regulations promulgated thereunder.
2.4 “Consent” means any freely given, specific, informed, and unambiguous indication of an individual’s wishes by which such individual, or the individual’s parent or legal guardian where required by applicable law, signifies agreement to the Processing of their Personal Information by a clear affirmative statement or action.
2.5 “Consumer” means any natural person, whether acting in an individual, household, or commercial capacity, who accesses, browses, interacts with, or utilizes the Systems.
2.6 “Controller” means the Company or any affiliate determining, alone or jointly with others, the purposes and means of the Processing of Personal Information.
2.7 “COPPA” means the federal Children’s Online Privacy Protection Act, 15 U.S.C. Section 6501 et seq., and its implementing regulations codified at 16 C.F.R. Part 312.
2.8 “Cross-Context Behavioral Advertising” or “Targeted Advertising” means the targeting of advertising to a Consumer based on the Consumer’s Personal Information obtained from the Consumer’s activity across businesses, distinctly-branded websites, applications, or services, other than the Systems.
2.9 “De-Identified Data” means information that cannot reasonably be used to infer information about, or otherwise be linked directly or indirectly to, a particular Consumer, household, or device.
2.10 “Global Privacy Control” or “Universal Opt-Out Preference Signal” means a standardized, machine-readable protocol transmitted by a browser, device, or application indicating a Consumer’s affirmative choice to opt out of the sale or sharing of Personal Information, or out of Targeted Advertising, recognized under applicable law.
2.11 “Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer, household, or electronic device. Personal Information does not include publicly available information lawfully obtained from government records, aggregated information, or De-Identified Data.
2.12 “Private Information” has the meaning ascribed to it in New York General Business Law Section 899-aa, including personal information consisting of any information in combination with any one or more of the following unencrypted (or encrypted with an acquired key) data elements: (a) Social Security number; (b) driver’s license number or non-driver state identification card number; (c) financial account number or credit or debit card number in combination with any required security code, access code, or password permitting account access; (d) a Biometric Identifier; or (e) a user name or email address in combination with a password or security question and answer that would permit access to an online account.
2.13 “Processor” means any natural or legal person that Processes Personal Information on behalf of the Controller pursuant to documented instructions.
2.14 “Processing” (and its cognates “Process” and “Processed”) means any operation or set of operations performed upon Personal Information or sets of Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
2.15 “Sale” (and its cognates “Sell” and “Sold”) means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer’s Personal Information to a third party for monetary or other valuable consideration.
2.16 “SAFE for Kids Act” means the New York Stop Addictive Feeds Exploitation (SAFE) for Kids Act, New York General Business Law Section 1500 et seq., and its implementing regulations.
2.17 “Sensitive Personal Information” means Personal Information that reveals an individual’s government-issued identification numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, genetic data, Biometric Information, health or medical data, or sex life or sexual orientation, as defined under applicable state and federal statutory frameworks.
2.18 “Sharing” (and its cognates “Share” and “Shared”) means sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer’s Personal Information to a third party for Cross-Context Behavioral Advertising or Targeted Advertising, whether or not for monetary or other valuable consideration.
2.19 “SHIELD Act” means the New York Stop Hacks and Improve Electronic Data Security Act, codified at New York General Business Law Section 899-aa and Section 899-bb.
2.20 “Systems” means the Company’s proprietary digital platforms, websites, portals, software applications, mobile applications, APIs, online interfaces, and technical infrastructure.
2.21 “Third-Party Service Provider” means any external vendor, contractor, platform provider, consultant, or outsourced agent engaged by the Company to perform services on the Company’s behalf.
3. Categories Of Personal Information Collected
3.1 Scope of Collection. The Controller collects and Processes the following categories of Personal Information from or concerning Consumers through their access to and interaction with the Systems, subject to the purpose limitations set forth in this Policy.
3.2 Identifiers and Contact Information. Identifiers including legal name, postal address, electronic mail address, telephone number, Internet Protocol (IP) address, unique personal or online identifiers, and account credentials such as usernames and encrypted passwords.
3.3 Commercial, Financial, and Transaction Records. Transaction records including records of goods or services purchased, obtained, or considered, billing addresses, tokenized payment identifiers or masked payment card data, and related payment confirmation records.
3.4 Internet and Electronic Network Activity. Electronic activity metrics including browsing history, search queries within the Systems, operating system, browser type and version, access timestamps, referring URLs, clickstream data, and technical diagnostic telemetry.
3.5 Geolocation Data. Non-precise, coarse geographic location derived strictly from IP addresses or general network routing data, excluding precise geolocation data.
3.6 Professional and Inbound Communications Data. Professional and employment-related information, including employer or organizational affiliation, job title, and the full contents of inquiries, feedback, or records submitted directly by Consumers through support channels, digital forms, or correspondence.
3.7 Inferences and Derived Attributes. Inferences drawn from any of the foregoing categories to establish a summary profile reflecting a Consumer’s operational preferences, usage characteristics, or service-related patterns.
4. New York Statutory Private Information
4.1 Statutory Scope and Characterization. In accordance with the SHIELD Act, the Controller distinguishes Personal Information from statutory Private Information. The Systems are not intended or configured to systematically collect or Process Social Security numbers, driver’s license numbers, non-driver identification card numbers, or biometric information.
4.2 Scope of Processed Credentials and Financial Information. To the extent the Controller Processes Private Information through the Systems, such Processing is limited to: (a) an individual’s user name or email address in combination with a password, security question and answer, or other access credential that would permit access to an online account; and (b) financial account numbers or credit or debit card numbers in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
4.3 Heightened Safeguards. All Private Information Processed by the Controller is maintained under reasonable administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of such information pursuant to N.Y. Gen. Bus. Law § 899-bb, segregated from routine network telemetry, and retained only as long as necessary to fulfill the authorized business purposes for which it was obtained.
5. Sources Of Personal Information
5.1 Direct Collection from Consumers. The Controller collects Personal Information directly from Consumers when they create or access an account, authenticate credentials, complete transactions, submit digital forms, or otherwise communicate with the Controller through the Systems.
5.2 Automated Collection Technologies. The Controller automatically collects technical and device data, including Internet Protocol (IP) addresses, device identifiers, and electronic network activity, when Consumers access or interact with the Systems, utilizing cookies, server logs, web beacons, and related tracking technologies.
5.3 Third-Party Partners and Service Providers. The Controller receives Personal Information from third parties, including service providers that perform payment processing, identity verification, fraud prevention, analytics, advertising, and technical support services for or in collaboration with the Controller.
5.4 Public and Commercial Sources. To the extent permitted by applicable law, the Controller collects or supplements Personal Information using commercially available databases, credit reporting agencies, business registries, and publicly available government records.
6. Purposes And Legal Bases For Processing
6.1 Operational and Service Delivery Purposes. The Controller Processes Personal Information to administer, deliver, and maintain the Systems, facilitate account authentication, process and fulfill commercial transactions, communicate administrative notices, provide customer assistance, and ensure the ongoing stability, security, and technical availability of our operations.
6.2 Fraud Detection, System Integrity, and Legal Compliance. The Controller Processes Personal Information and Private Information to detect, investigate, and prevent fraudulent, deceptive, or unauthorized activities; verify user identities; preserve the physical and digital security of the Systems in accordance with statutory safeguard requirements under New York law; and satisfy applicable federal and New York state statutory obligations, judicial orders, and binding regulatory demands.
6.3 System Diagnostics, Internal Analytics, and Optimization. The Controller Processes Personal Information to monitor performance telemetry, evaluate aggregate usage patterns, diagnose technical defects, conduct internal operational reporting, and optimize user navigation and feature functionality across the Systems.
6.4 Lawful Grounds and Consent. Processing of Personal Information is conducted pursuant to the following lawful grounds: (a) performance of contracts or transactions to which the Consumer is a party; (b) compliance with statutory, regulatory, and legal obligations under applicable federal and New York law; (c) legitimate business and commercial operations, including securing our Systems, defending legal claims, and improving services; and (d) affirmative Consent, where required by applicable law. Where Processing is based on Consent, the Consumer may withdraw Consent at any time via the mechanisms detailed herein, without affecting the lawfulness of Processing conducted prior to revocation.
6.5 Purpose Limitation and Compatible Uses. The Controller will not Process Personal Information or Private Information for purposes that are materially incompatible with the operational and commercial purposes disclosed in this Section 6 without providing prior notice or obtaining affirmative Consent where required by applicable law.
7. Cookies, Web Beacons, And Tracking Technologies
7.1 Deployment and Technical Scope. The Controller and authorized third parties deploy first- and third-party cookies, clear GIFs, web beacons, embedded scripts, session-replay tools, pixels, and related tracking technologies across the Systems. When a Consumer accesses or interacts with the Systems, these technologies automatically log device identifiers, IP addresses, network activity, navigational sequences, timestamps, and real-time user interactions (including mouse movements, scrolling, and keystrokes).
7.2 Functional Classifications. Tracking mechanisms deployed on the Systems are categorized as: (a) strictly necessary cookies, essential to deliver core functionality, maintain session security, balance network traffic, and facilitate electronic transmissions; (b) functional cookies, utilized to preserve user configurations, language preferences, and authenticated state; (c) analytics and performance technologies, utilized to capture aggregate diagnostic data, audit system performance, and measure visitor traffic; and (d) targeting and marketing technologies, utilized—subject to applicable Consent requirements—to measure campaign efficacy and deliver Cross-Context Behavioral Advertising.
7.3 Service Providers and Independent Third Parties. Where Third-Party Service Providers deploy tracking instrumentation on the Systems on behalf of the Controller, such entities are contractually restricted from Processing captured Personal Information for any purpose other than providing the designated services. Independent third parties deploying advertising or social media technologies operate subject to their respective privacy disclosures and governed by applicable opt-out frameworks.
7.4 Consumer Controls and Opt-Out Mechanisms. Consumers may manage, restrict, or disable non-essential cookies via the Systems’ cookie preference center or by modifying their internet browser and operating system settings. The Controller honors Universal Opt-Out Preference Signals, including the Global Privacy Control, in accordance with applicable law and the procedures set forth in Section 8. Restricting or rejecting technical tracking mechanisms may impair the availability, functionality, or performance of specific features across the Systems.
8. Universal Opt-Out Preference Signals And Global Privacy Control
8.1 Recognition and Scope. The Controller configures the Systems to detect and honor standardized, machine-readable universal opt-out signals, including the Global Privacy Control. The Controller treats a validly transmitted signal as a binding request to opt out of the Sale, Sharing, or Processing of Personal Information for Targeted Advertising across applicable state and federal legal frameworks.
8.2 Operational Implementation. Recognition of a Universal Opt-Out Preference Signal applies automatically to the specific browser, operating system, or device transmitting the signal, including all associated pseudonymous identifiers and cookies. Where a Consumer transmits the signal while authenticated into an account, or where the Controller can reasonably link the browser or device to an account or offline profile, the Controller applies the opt-out preference across all linked Personal Information.
8.3 Conflict Resolution and Precedence. If a valid Universal Opt-Out Preference Signal conflicts with a prior affirmative consent or privacy setting, the Universal Opt-Out Preference Signal controls as the prevailing instruction. The Controller suppresses targeted advertising and sharing practices until the Consumer subsequently provides explicit, affirmative consent to override the preference signal.
8.4 Frictionless Processing. The Controller processes all valid Universal Opt-Out Preference Signals without imposing any fee, charge, service degradation, differential pricing, or unreasonable navigational burden upon the Consumer.
9. Disclosure And Sharing Of Personal Information With Third Parties
9.1 Disclosures to Processors and Third-Party Service Providers. The Controller discloses Personal Information and Private Information to Processors and Third-Party Service Providers strictly to perform operational functions on behalf of the Controller, including cloud infrastructure hosting, data storage, payment processing, fraud prevention, technical diagnostics, and customer support. All such Third-Party Service Providers are bound by written agreements requiring them to implement reasonable administrative, technical, and physical safeguards consistent with the SHIELD Act, to maintain strict confidentiality, to bind authorized subcontractors to substantially equivalent terms, and prohibiting them from retaining, using, disclosing, or otherwise Processing Personal Information for any purpose other than providing the operational services specified by the Controller.
9.2 Disclosures for Legal Compliance, Protective Mandates, and System Integrity. The Controller discloses Personal Information and Private Information to law enforcement bodies, regulatory authorities, courts, or other authorized government entities when required by applicable federal, state, or local law, including responding to a valid subpoena, warrant, judicial order, or regulatory inquiry. Unless prohibited by law or court order, the Controller reserves the right to notify affected Consumers of such requests. The Controller may also disclose Personal Information where reasonably necessary to investigate, prevent, or take action regarding potential fraud, unlawful activity, security incidents, Breaches of the Security of the System, or to enforce the Controller’s legal rights, terms of service, and the safety and security of Consumers and the public.
9.3 Corporate Transactions and Restructuring. In connection with the evaluation, negotiation, or completion of a proposed or consummated merger, acquisition, consolidation, corporate reorganization, asset sale, financing, bankruptcy, or transfer of all or a substantial portion of the Controller’s business or Systems, Personal Information and Private Information may be shared with prospective or actual counterparties under customary non-disclosure obligations. Any acquiring or successor entity remains obligated to Process such information in a manner consistent with this Privacy Policy and applicable statutory notice and Consent requirements under federal and New York law.
9.4 Targeted Advertising, Sales, and Sharing Prohibitions. The Controller does not sell Personal Information or Private Information to third parties in exchange for monetary or other valuable consideration. Except where a Consumer has provided explicit affirmative Consent, or subject to statutory opt-out preference mechanisms as set forth in Section 8, the Controller does not disclose, disseminate, or otherwise make available Personal Information to independent third parties for Cross-Context Behavioral Advertising or Targeted Advertising.
10. Algorithmic Recommendations And Feed Personalization Disclosures
10.1 Algorithmic Processing and Content Personalization. The Controller deploys automated algorithms, ranking models, and computational mechanisms across the Systems to organize, prioritize, sequence, and curate third-party and native content, commercial displays, recommendations, and search outputs. These algorithmic systems process operational inputs, including technical telemetry, user-directed interactions, account profile attributes, search queries, and historical engagement within the Systems, to dynamically adjust the display and order of content based on inferred relevance.
10.2 New York Youth Protections and Addictive Feed Restrictions. Pursuant to the SAFE for Kids Act and the New York Child Data Protection Act, the Controller does not deploy an “addictive feed” (as defined by New York law) to any Consumer known to be, or reasonably determined to be, a minor under eighteen (18) years of age, absent verifiable parental consent. For covered minor Consumers, the Systems automatically default to non-addictive, chronological, or general popularity-based content feeds, and disable engagement-maximizing automated push notifications during protected statutory hours.
10.3 Consumer Customization and Opt-Out Mechanisms. Adult Consumers may adjust, restrict, or opt out of algorithmic feed personalization via account preference settings accessible on the Systems. Electing to opt out shifts the content delivery interface to non-algorithmic sorting, such as chronological or topical sequencing. Exercising personalization controls or clearing historical interaction data does not restrict essential system functions, core administrative routing, or non-personalized operational sorting required to deliver the underlying services.
11. Data Safeguards And Information Security Program Under New York SHIELD Act
11.1 Reasonable Safeguards Framework. In compliance with the SHIELD Act, the Controller shall implement and maintain a comprehensive, written information security program containing reasonable administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Private Information and Personal Information. To the extent the Controller is subject to and complies with the data security regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Gramm-Leach-Bliley Act (GLBA), or 23 NYCRR 500, such compliance shall satisfy the requirements of this Section 11 pursuant to N.Y. Gen. Bus. Law § 899-bb(2)(b)(i).
11.2 Administrative Safeguards. The Controller’s administrative controls shall include: (a) designating one or more qualified employees to coordinate the information security program; (b) identifying reasonably foreseeable internal and external security risks through periodic risk assessments; (c) assessing the sufficiency of existing safeguards to control identified risks; (d) training and managing employees in security program practices and procedures; (e) selecting Processors and Third-Party Service Providers capable of maintaining appropriate safeguards, and contractually requiring them to implement and maintain such safeguards; and (f) periodically adjusting the information security program in response to operational changes or new risk circumstances.
11.3 Technical Safeguards. The Controller’s technical controls shall include: (a) assessing risks in network and software design; (b) assessing risks in information Processing, transmission, and storage; (c) deploying technological mechanisms to detect, prevent, and respond to system attacks or failures; (d) regularly testing and monitoring the key controls, systems, and operational procedures of the Systems; and (e) utilizing industry-standard encryption protocols for Private Information and sensitive network transmissions both at rest and in transit.
11.4 Physical Safeguards. The Controller’s physical controls shall include: (a) assessing risks of information storage and disposal; (b) detecting, preventing, and responding to physical intrusions into electronic or physical records; (c) protecting against unauthorized access to or use of Private Information and Personal Information during or after collection, transportation, and destruction; and (d) disposing of Private Information within a reasonable time after it is no longer needed for business purposes by erasing or destroying electronic media and physical records so that information cannot be read or reconstructed, in accordance with applicable retention schedules and the data disposal terms of this Privacy Policy.
11.5 Standard of Care and Disclaimer. The Controller shall maintain the safeguards described herein to meet the statutory standard of reasonable care under N.Y. Gen. Bus. Law § 899-bb. The parties acknowledge that no computing, storage, or transmission environment is infallible, and the Controller does not guarantee absolute or impenetrable security, disclaiming any implied warranties not expressly stated in this Privacy Policy.
12. Data Retention And Destruction Protocols
12.1 Retention Criteria and Period. The Controller retains Personal Information and Private Information only for as long as reasonably necessary to fulfill the specific operational purposes for which it was collected, as set forth in Section 6, or as required to satisfy applicable statutory, regulatory, tax, accounting, or reporting obligations under New York state and federal law. In establishing definitive retention schedules, the Controller evaluates the volume, nature, and sensitivity of the data, the risk of potential harm from unauthorized access or disclosure, the feasibility of achieving the underlying purposes through alternative means, and mandatory statutory limitation periods.
12.2 Disposal of Private Information under the SHIELD Act. Pursuant to the safeguard mandates of the SHIELD Act, the Controller audits stored records and disposes of Private Information within a reasonable time after such information is no longer needed for verified business operations or legal compliance. Disposal is executed through technical and operational procedures that prevent recovery, interception, or unauthorized access.
12.3 Secure Destruction and Irreversible Sanitization Methods. Except as provided in Section 12.5, when Personal Information or Private Information reaches the expiration of its operational or statutory retention period, or upon a validated consumer erasure request, the Controller irreversibly destroys, erases, or de-identifies the data. Electronic data is sanitized in accordance with recognized industry standards (such as NIST SP 800-88 Rev. 1) to ensure records cannot be read, recovered, or reconstructed. Physical records containing Personal Information or Private Information are destroyed through cross-cut shredding, pulping, or incineration.
12.4 Retention of De-Identified Data and Archival Backups. Data retained following expiration of the operative retention schedule is converted into De-Identified Data maintained under technical and administrative controls prohibiting re-identification. Personal Information residing in encrypted, automated disaster recovery or backup archives is logically separated from active Processing environments and systematically overwritten, purged, or deleted in accordance with the Controller’s standard archival lifecycle protocols, and will not be restored to active systems.
12.5 Legal Hold and Preservation Exceptions. The Controller’s automated deletion and destruction protocols are immediately suspended with respect to relevant Personal Information and Private Information in the event of an active or reasonably anticipated legal hold, litigation, regulatory inquiry, subpoena, or statutory preservation requirement, and such data will be retained until the hold is formally released.
13. Data Breach Notification Procedures
13.1 Incident Detection and Investigation. Upon discovering or receiving notification of any actual or reasonably suspected security incident, the Controller shall promptly initiate a forensic investigation to determine whether a Breach of the Security of the System has occurred. If the Controller confirms unauthorized access to or acquisition of computerized data that compromises the security, confidentiality, or integrity of Private Information, the Controller shall take immediate remedial action to contain, mitigate, and resolve the security exposure across the Systems.
13.2 Mandatory Consumer Notification. In accordance with the SHIELD Act, the Controller shall notify any affected resident of New York whose Private Information was, or is reasonably believed to have been, accessed or acquired by an unauthorized person without valid authorization. Such notice shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the integrity of the Systems. Notice is not required if the exposure was an inadvertent disclosure by persons authorized to access Private Information, and the Controller reasonably determines such exposure will not likely result in misuse of such information or financial or emotional harm to affected individuals, provided such determination is documented in writing and maintained pursuant to N.Y. Gen. Bus. Law § 899-aa(2)(a).
13.3 Content and Methods of Consumer Notice. Breach notifications delivered to affected individuals shall be written in plain language and specify: (a) the contact information for the Controller; (b) the telephone numbers and websites of relevant state and federal agencies that provide information regarding security breach response and identity theft prevention; (c) the categories of Private Information accessed or acquired; (d) a general description of the incident; and (e) the approximate date or date range of the incident. Notice shall be provided by direct written notice, electronic notice consistent with 15 U.S.C. § 7001, or substitute notice where permitted under N.Y. Gen. Bus. Law § 899-aa(5)(d). If the breach involves online account credentials, notice may be delivered electronically directing the individual to promptly change credentials, provided that notice for compromised email credentials shall not be directed to the compromised email address.
13.4 Regulatory and Agency Coordination. Prior to or concurrent with notification to affected individuals, the Controller shall notify the New York State Attorney General, the New York State Department of State, and the New York State Division of State Police as to the timing, content, and distribution of the notices and approximate number of affected individuals, submitting a template copy of the notice in accordance with N.Y. Gen. Bus. Law § 899-aa(8)(a). If more than five thousand (5,000) New York residents are required to be notified at one time, the Controller shall also notify nationwide consumer reporting agencies without unreasonable delay.
13.5 Processor and Vendor Obligations. Any Processor or Third-Party Service Provider that maintains, hosts, or processes Private Information or Personal Information on behalf of the Controller shall notify the Controller immediately upon discovery of any actual or suspected unauthorized access to, acquisition of, or Breach of the Security of the System regarding such data or Systems. The Processor or Third-Party Service Provider shall cooperate fully in the forensic investigation, and the Controller shall maintain exclusive authority over all statutory determinations and notifications required under applicable law.
14. Children’s And Minors’ Privacy Under Federal COPPA And New York Law
14.1 General Audience and Prohibition on Underage Collection. The Systems are designed and intended exclusively for general audience use by adults. The Controller does not direct the Systems to, nor knowingly collect, solicit, or Process Personal Information from, children under thirteen (13) years of age in violation of COPPA, or minors under eighteen (18) years of age residing in the State of New York in violation of the New York Child Data Protection Act and related statutes. No individual under the age of eighteen (18) is authorized to create an account, register credentials, or transmit Personal Information through the Systems without verified legal authorization.
14.2 Inadvertent Processing and Parental Rights under COPPA. If the Controller obtains actual knowledge, or has reasonable cause to believe, that Personal Information of a child under thirteen (13) years of age has been collected through the Systems without verified prior parental Consent conforming to COPPA standards, the Controller will immediately take reasonable measures to delete such Personal Information from its active databases and archival systems. A parent or legal guardian who believes their child under thirteen (13) has provided Personal Information may review the collected information, request its permanent deletion, and refuse further collection or Processing by contacting the Controller using the contact channels specified in this Privacy Policy.
14.3 Restrictions on Minors’ Data under New York Law. In compliance with the New York Child Data Protection Act and the SAFE for Kids Act, the Controller strictly restricts the Processing of Personal Information relating to covered minors under eighteen (18) years of age. Personal Information belonging to known minor Consumers shall not be Processed unless strictly necessary to perform the core transaction or functionality of the Systems requested by the user, or unless informed affirmative Consent is obtained (directly from the minor if aged thirteen (13) through seventeen (17), or from a parent or legal guardian if under thirteen (13)). The Controller shall not sell, share, or disclose Personal Information of any minor for Cross-Context Behavioral Advertising or Targeted Advertising, nor Process such data for commercial profiling or behavioral monetization.
14.4 Verification and Remediation Inquiries. Parents, legal guardians, or minor Consumers wishing to exercise statutory rights of access, correction, restriction, or deletion regarding minor Personal Information may submit a verified request to the Controller. Upon receipt of such request, the Controller will authenticate the requester’s identity and authority in accordance with statutory standards and execute the requested erasure or restriction without unreasonable delay.
15. State-Specific Consumer Privacy Rights And Choice Architecture
15.1 Scope and Multi-State Applicability. Depending on the Consumer’s state of residence, applicable state privacy enactments provide qualifying Consumers with specific statutory rights concerning their Personal Information. Without limiting any statutory protections afforded under applicable law (including New York General Business Law § 899-aa and § 899-bb), this Section 15 establishes the choice architecture, operational protocols, and procedural framework through which eligible Consumers may exercise applicable statutory entitlements. Specific rights applicable to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), are governed by Section 16.
15.2 Enumerated Consumer Rights. Subject to identity authentication and statutory exemptions under applicable state law, qualifying Consumers may exercise the following rights regarding Personal Information maintained by the Controller: (a) Right of Confirmation and Access: to confirm whether the Controller Processes their Personal Information and to access such data; (b) Right to Data Portability: to obtain a copy of their Personal Information in a portable, readily usable, and machine-readable format; (c) Right to Correction: to correct inaccuracies in their Personal Information, taking into account the nature and purposes of the Processing; (d) Right to Deletion: to request the deletion of Personal Information provided by or obtained concerning them, subject to statutory retention exceptions and Section 12; (e) Right to Opt-Out: to opt out of the Processing of Personal Information for Targeted Advertising, the Sale of Personal Information, or automated profiling in furtherance of decisions producing legal or similarly significant effects; and (f) Sensitive Data Protections: to revoke consent or exercise opt-out mechanisms regarding the Processing of sensitive data categories, as mandated by the Consumer’s state of residence.
15.3 Choice Architecture and Opt-Out Mechanisms. The Controller designs and maintains user interfaces, preference dashboards, and opt-out mechanisms in accordance with transparent design standards. The Controller does not deploy deceptive design patterns, asymmetrical consent workflows, or interfaces (“dark patterns”) designed to subvert or impair Consumer autonomy or choice. Where required by applicable state law, the Controller processes opt-out preference signals, including the Global Privacy Control, as a valid, automated request to opt out of the sale of Personal Information or Targeted Advertising for the designated browser or device.
15.4 Request Submission, Verification, and Authorized Agents. Consumers may submit statutory rights requests via the designated electronic portal on the Systems or by contacting the Controller at the email address designated in Section 21. The Controller authenticates requests by matching identifying data points provided by the Consumer against verified Personal Information maintained in the Systems. A Consumer may designate an authorized agent to act on their behalf; provided, that the Controller may require proof of written authorization and direct identity verification from the Consumer, unless the authorized agent acts pursuant to a valid power of attorney executed under applicable law (including New York General Obligations Law Article 5, Title 15).
15.5 Response Timelines and Statutory Appeals Architecture. The Controller shall respond to authenticated Consumer requests within forty-five (45) days of receipt. Where reasonably necessary due to the complexity or volume of requests, the Controller may extend the response period by an additional forty-five (45) days upon delivering written notice within the initial response window specifying the reason for the extension. If the Controller denies or declines action on a request, it shall state the factual and legal basis for the determination and provide instructions on how to appeal. Consumers may appeal an adverse determination within thirty (30) days of receipt of the denial. The Controller shall resolve the appeal within forty-five (45) days (or sixty (60) days where permitted by applicable law), providing a written explanation of the determination and instructions for submitting complaints to the relevant state Attorney General.
15.6 Non-Discrimination Mandate. The Controller shall not discriminate or retaliate against any Consumer for exercising statutory privacy rights. Except where differential pricing, service levels, or rates are reasonably related to the value provided to the Controller by the Consumer’s Personal Information or are otherwise permitted by law, the Controller shall not deny goods or services, charge differential rates, or alter the quality of services based upon the exercise of rights under this Section 15.
16. Notice To California Residents And CCPA/CPRA Disclosures
16.1 Applicability and Scope. This Section 16 supplements the Privacy Policy and applies exclusively to individual residents of the State of California who qualify as Consumers under the California Consumer Privacy Act of 2018, (CCPA/CPRA). Consistent with the expiration of statutory exemptions as of January 1, 2023, this Section 16 encompasses California Consumers acting in an individual, employment-related, or commercial business-to-business capacity.
16.2 Statutory California Consumer Rights. Subject to identity verification and statutory exceptions, California Consumers possess specific legal rights under the CCPA/CPRA, including: (a) the right to know and access the specific pieces and categories of Personal Information collected, the categories of sources, the business or commercial purposes for collection and processing, and the categories of third parties to whom Personal Information is disclosed; (b) the right to delete Personal Information collected from the Consumer, subject to statutory retention exceptions under Civil Code Section 1798.105; (c) the right to correct inaccurate Personal Information; (d) the right to opt out of the Sale of Personal Information or the Sharing of Personal Information for Cross-Context Behavioral Advertising; (e) the right to limit the use and disclosure of Sensitive Personal Information; and (f) the right to freedom from retaliatory or discriminatory treatment for exercising statutory privacy rights.
16.3 Sales, Sharing, and Profiling Disclosures. The Controller does not engage in the Sale of Personal Information or the Sharing of Personal Information for Cross-Context Behavioral Advertising under the CCPA/CPRA. Consequently, the Controller does not deploy a “Do Not Sell or Share My Personal Info” link. The Controller processes opt-out preference signals (including Global Privacy Control) where required by applicable law, does not utilize automated decision-making or profiling producing legal or similarly significant effects concerning Consumers, and has no actual knowledge of selling or sharing Personal Information of minors under sixteen (16) years of age.
16.4 Sensitive Personal Information and Retention Criteria. The Controller does not collect or process Sensitive Personal Information for the purpose of inferring characteristics about Consumers, nor for any purpose beyond the authorized service and operational functions enumerated in California Civil Code Section 1798.121 and 16 CCR Section 7027. Accordingly, the right to limit Sensitive Personal Information does not apply. Personal Information collected is retained strictly for the duration necessary to satisfy the operational business purposes set forth in this Privacy Policy, comply with statutory recordkeeping obligations, resolve disputes, and enforce legal agreements, determined pursuant to the objective retention criteria set forth in Section 12.
16.5 Submission, Verification, and Processing of Requests. California Consumers or their legally authorized agents may exercise CCPA/CPRA rights in accordance with the intake, verification, agent authorization, and response framework established in Section 15. The Controller will confirm receipt of an authenticated request within ten (10) business days, detailing the verification process and fulfillment timeline, and will deliver a substantive response within forty-five (45) calendar days, subject to lawful extensions. Compliance with verified requests will be provided free of charge, up to two (2) times within any twelve (12) month period.
16.6 California “Shine the Light” Disclosures. Under California Civil Code Section 1798.83, California residents who provide Personal Information in obtaining products or services for personal, family, or household use are entitled to request and obtain from the Controller, once per calendar year, information regarding customer data disclosed to third parties for direct marketing purposes during the preceding calendar year. The Controller does not disclose Personal Information to unaffiliated third parties for their own direct marketing purposes.
17. Third-Party Websites, Applications, And External Integrations
17.1 External Links and Platforms. The Systems may contain hyperlinks to third-party websites, applications, and digital services not owned or operated by the Controller. The inclusion of any link does not imply endorsement, authorization, or affiliation. Once a Consumer departs the Systems, this Privacy Policy ceases to apply, and any collection, use, or disclosure of data is governed solely by the privacy policies and terms of the applicable third party.
17.2 Embedded Features and Technical Integrations. The Systems may incorporate third-party components, including software development kits (SDKs), application programming interfaces (APIs), pixels, and social media plugins. These integrations may allow third-party providers to collect Consumer data, technical identifiers, and usage metrics directly through the Systems. To the maximum extent permitted by applicable law, the Controller is not responsible for the independent data collection, processing, or security controls of such third-party providers.
17.3 Assumption of Risk and Disclaimer of Liability. Accessing third-party platforms, interacting with external integrations, and transmitting Personal Information through third-party services is conducted solely at the Consumer’s own risk. The Controller disclaims all liability arising from the acts, omissions, data practices, security compromises, or regulatory non-compliance of any independent third party.
18. Cross-Border Data Transfers And International Users
18.1 Operational Jurisdiction and Location of Processing. The Systems are hosted, operated, and administered by the Controller from facilities located within the United States, including the State of New York. Personal Information and Private Information collected through the Systems will be transferred to, stored, and Processed in the United States, where data protection and privacy laws may offer different levels of protection than those in the Consumer’s home jurisdiction.
18.2 International Access and Data Transfer. A Consumer accessing the Systems from outside the United States, including the European Economic Area, the United Kingdom, Switzerland, or Canada, acknowledges that their Personal Information will be transferred to and Processed in the United States by the Controller, its affiliates, Processors, and Third-Party Service Providers as necessary to provide the Systems and perform requested services, or pursuant to the Consumer’s explicit consent where required by applicable law.
18.3 Cross-Border Safeguards and Transfer Mechanisms. Where applicable law requires valid transfer mechanisms to transmit Personal Information to jurisdictions lacking an adequacy decision, the Controller relies on recognized safeguards, including the EU-U.S. Data Privacy Framework, the UK Extension, the Swiss-U.S. Data Privacy Framework, approved standard contractual clauses, or binding corporate rules. All cross-border transfers remain subject to reasonable administrative, technical, and physical safeguards in compliance with applicable law, including the New York SHIELD Act.
19. Policy Modifications, Material Changes, And Retroactive Consents
19.1 Right to Modify and Non-Material Updates. The Controller reserves the right to amend this Privacy Policy at its discretion. For non-material revisions, the Controller will publish the updated policy on the Systems and update the effective date. To the extent permitted by applicable law, continued use of the Systems following the posting of non-material revisions constitutes acceptance of the modified Privacy Policy.
19.2 Advance Notice for Material Alterations. If the Controller implements any material change to this Privacy Policy—including expansions of the categories of Personal Information collected, additions to Processing purposes, or modifications that materially reduce Consumer privacy protections—the Controller shall provide Consumers with prominent advance notice at least thirty (30) days prior to the effective date. Notice shall be provided via direct electronic communication to registered account holders, a conspicuous banner or pop-up notification on the Systems, or other commercially reasonable means calculated to provide actual notice.
19.3 Prohibition Against Retroactive Material Changes Without Consent. The Controller will not retroactively apply material modifications to Personal Information collected prior to the effective date of the change in a manner that expands Processing, sharing, or disclosure practices without obtaining the Consumer’s prior, affirmative, and express Consent. If a Consumer does not grant affirmative Consent for such retroactive Processing, the Controller shall continue to Process previously collected Personal Information in accordance with the Privacy Policy terms in effect at the time of collection, subject to the Consumer’s right to terminate the account and request data erasure pursuant to Section 12 and Section 15.
20. Dispute Resolution, Governing Law, And Venue
20.1 Governing Law. This Privacy Policy, and any claim, controversy, cause of action, or dispute arising out of or relating to this Privacy Policy, the Processing of Personal Information or Private Information, or the use of the Systems, shall be governed by, construed, and enforced in accordance with the laws of the State of New York and applicable federal laws of the United States, without giving effect to any principles of conflicts of law or choice of law rules that would result in the application of the substantive laws of any other jurisdiction.
20.2 Exclusive Venue and Jurisdiction. To the maximum extent permitted by applicable law, any legal suit, action, or proceeding arising out of or relating to this Privacy Policy, the Processing of Personal Information or Private Information, or the use of the Systems shall be instituted exclusively in the state or federal courts located in the State of New York, County of New York (including the United States District Court for the Southern District of New York). The Controller and each Consumer irrevocably and unconditionally submit to the personal and exclusive jurisdiction of such courts and waive any defense or objection based on inconvenient forum, improper venue, or lack of personal jurisdiction.
20.3 Pre-Dispute Informal Resolution. Prior to initiating any formal legal proceeding, the asserting party must deliver written notice setting forth the specific factual details, asserted statutory or contractual grounds, and requested relief to the other party. The parties shall engage in good-faith negotiations to resolve the dispute informally for a period of thirty (30) days from receipt of such notice before initiating judicial proceedings, except where emergency equitable relief is necessary.
20.4 Equitable Remedies and Jury Trial Waiver. Nothing in this Section 20 shall preclude either party from seeking preliminary injunctive relief, temporary restraining orders, or other emergency equitable remedies in a court of competent jurisdiction to protect against imminent security threats, unauthorized access to the Systems, or unlawful disclosure of information. TO THE EXTENT PERMITTED BY APPLICABLE LAW, EACH PARTY HEREBY IRREVOCABLY WAIVES ALL RIGHT TO TRIAL BY JURY IN ANY ACTION, PROCEEDING, OR COUNTERCLAIM ARISING OUT OF OR RELATING TO THIS PRIVACY POLICY.
21. Contact Information And Regulatory Inquiries
21.1 Designated Privacy Office. Any Consumer, parent, legal guardian, or regulatory authority seeking to submit inquiries, exercise applicable privacy rights, or lodge complaints concerning this Privacy Policy or the Processing of Personal Information may contact the privacy office using the following designated channels:
PSYSOED DYNAMICS, LLC / Groundbreaker Therapy
Attn: Matthew G. Mandelbaum, PhD
Online Portal: https://groundbreakertherapy.com/contact/
Electronic Mail: drm@groundbreakertherapy.com
Scope and Service of Process. The contact details set forth in Section 21.1 are designated exclusively for privacy-related inquiries and requests under applicable data protection laws. They do not constitute an agreement or designated channel for the acceptance of service of legal process, which must be served upon our registered agent in accordance with applicable law. Consumers with disabilities who require access to this Privacy Policy in an alternative format may contact us using any of the methods listed above.
