Nevada consumer health data privacy policy
About this document
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective date | 1 August 2026 |
| Publication date | 1 August 2026 |
| Last reviewed | 18 July 2026 |
| Status | Approved public document |
Version history
| Version | Effective date | Change summary | How this version applies |
|---|---|---|---|
1.0 | 1 August 2026 | Initial public version | Available separately; consent is requested where required |
1. Scope
This policy describes Alessia's practices under Nevada's consumer health data law, NRS 603A.400 to 603A.550.
Alessia is a professional portfolio service, not a patient health service or electronic health record. Information that identifies or could reasonably identify a patient is prohibited. Alessia also prohibits users from intentionally entering information about their own physical or mental health, disability, wellbeing, diagnosis, treatment or other consumer health data. Nevada's consumer health data law may nevertheless apply if such information is submitted contrary to these rules or if the Service otherwise derives consumer health data.
Whether a portfolio record is consumer health data depends on its contents and Nevada law. If you believe this policy applies to information about you, you may make a request under section 8.
2. Categories of consumer health data
Alessia does not intentionally collect consumer health data as part of the standard Service. Prohibited or incidentally received categories could include:
- the user's own physical or mental health, disability, symptoms, diagnosis, treatment or medication mentioned in a reflection, recording, document or support request;
- reproductive or sexual-health information about the user;
- biometric or precise-location information that identifies or reveals the user's health status;
- professional activity or leave information that reveals or permits an inference about the user's health; and
- account, device or identifier information linked or reasonably linkable to one of those categories.
A conspicuous link to this policy is made available from the alessiahq.com website, as Nevada law requires.
Alessia does not currently provide a personal health or wellbeing assessment feature or intentionally derive health, wellbeing or burnout inferences about users.
Information that identifies or could reasonably identify a patient must not be entered. If prohibited patient information is submitted, Alessia handles it as an incident rather than an authorised product purpose.
3. Sources
Prohibited or incidental consumer health data could come from:
- the user, through optional text, reflection, recording, attachment or support request;
- an Institution-controlled assessment or document;
- a supervisor or assessor named in the portfolio; or
- content the user selects for an AI-assisted or transcription feature.
Alessia does not acquire consumer health data from data brokers or advertising networks.
4. Purposes and processing
Where prohibited consumer health data is received, Alessia processes only what is necessary to contain and resolve the incident, respond to the person, secure the Service and comply with law. Alessia may restrict access to the information, investigate how it was received, delete it, retain a minimised incident record and provide legally required notifications.
The standard Service does not use consumer health data to provide personal health tracking, target advertising, determine insurance or clinical status, geofence a health facility, or make an automated education, employment, credentialling or progression decision.
Alessia will not intentionally collect consumer health data for an additional purpose without first updating this policy and obtaining any affirmative, voluntary consent required by Nevada law. Consent to sharing will be separate from consent to collection where required.
5. Sharing
The categories of consumer health data described in section 2 could have been sent to an optional feature provider before Alessia identified the content as prohibited. After identification, Alessia shares such data only where strictly necessary to contain or resolve the incident, secure the Service, delete the data or comply with law:
| Recipient category | Purpose and potential data |
|---|---|
| Hosting, storage, security and backup processors | Storage and protection of incidentally received content |
| AI-assisted processing provider | Content sent for a requested feature before it was identified as prohibited; afterwards, only the minimum information strictly necessary for incident containment or provider-side deletion |
| Transcription provider | Audio sent for transcription before it was identified as prohibited; afterwards, only the minimum information strictly necessary for incident containment or provider-side deletion |
| Alessia support or security personnel | Minimum access needed for an authenticated request, incident, security or legal purpose |
| Institution | Institution-controlled account content and administration |
| Professional advisers, courts or authorities | Minimum information required for legal rights, safety, security or law |
Alessia does not permit product analytics, identity services, notification payloads, ordinary email delivery or subscription records to contain consumer health content or portfolio evidence. Current providers and their roles are identified in the Subprocessor List.
Alessia does not permit a third party to collect consumer health data over time and across different websites or online services when a consumer uses Alessia's website or Service.
6. No sale
Alessia does not sell consumer health data or exchange it for money or other valuable consideration.
7. No health-location geofencing
Alessia does not use a geofence around a health-care facility or other in-person health-care provider to identify or track consumers seeking care, collect consumer health data or send health-related messages or advertisements.
8. Rights and requests
Subject to Nevada law, a consumer may ask Alessia to:
- confirm whether it is collecting, sharing or selling consumer health data about them;
- provide a list of the third parties with which it has shared that data or to which it has sold the data;
- cease collecting, sharing or selling the data; and
- delete the data.
While an account remains editable, a user can review and change their own portfolio entries using the Service's controls. To request review or amendment of other consumer health data, email privacy@alessiahq.com with the subject “Nevada Consumer Health Data Request”. Because consumer health data is prohibited in the standard Service, Alessia may delete it instead of retaining a corrected version where permitted by law.
Do not include patient information or unnecessary portfolio evidence in the request. Alessia will use commercially reasonable measures to authenticate it.
Alessia will respond without undue delay and generally within 45 days after authenticating the request. Where reasonably necessary because of the complexity and number of the consumer's requests, Alessia may extend this period by up to 45 additional days and will explain the extension within the initial period.
For an authenticated deletion request, Alessia will delete the requested consumer health data from its records and network within 30 days and notify each affiliate, processor, contractor or other third party with which the data was shared. Deletion from archived or backup systems may be delayed only as necessary to restore those systems and for no longer than two years after authentication of the request.
If Alessia refuses to act, the consumer may appeal by emailing legal@alessiahq.com with the subject “Nevada Consumer Health Data Appeal”. Alessia will provide a written appeal response within 45 days. If the appeal is denied, the response will include contact information for the Nevada Attorney General.
Where an Institution decides why and how the information is handled, its consumer health data policy and request process apply. Contact the Institution first; Alessia will assist it as a processor. This does not limit any right to contact Alessia where Nevada law requires Alessia to respond directly.
9. Security
Alessia limits access to consumer health data to personnel and processors for which access is necessary to provide a requested service or fulfil the purposes described in this policy. Alessia uses administrative, technical and physical safeguards designed to protect the confidentiality, integrity and availability of consumer health data, taking account of its volume and nature.
10. Changes and contact
Alessia will notify affected consumers of a material change to this policy by account email or in-app notice. Alessia will obtain any new consent required by Nevada law before collecting, using or sharing consumer health data in a way that is materially inconsistent with this policy.
- Alessia International Ltd
- 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom
- Privacy: privacy@alessiahq.com
- Legal and appeals: legal@alessiahq.com
