Privacy Policy

Privacy Policy

Ojai Recovery

Effective Date: January 1, 2024
Last Updated: June 1, 2025

Introduction

Ojai Recovery ("We," "us," or "our") is committed to protecting your privacy and maintaining the confidentiality of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with our advertisements on social media platforms including Meta (Facebook and Instagram).

This policy applies to all visitors, users, and others who access or use our services, whether you are a prospective patient, current patient, family member, or general website visitor.

Information We Collect

Personal Information You Provide

We may collect the following information when you voluntarily provide it:

  • Contact Information: Name, email address, phone number, mailing address
  • Demographic Information: Age, gender, location
  • Insurance Information: Insurance provider details for verification purposes
  • Communication Preferences: How you prefer to be contacted
  • Inquiry Details: Information about your treatment needs or questions
  • Feedback: Reviews, testimonials, or survey responses

Information Collected Automatically

When you visit our website or interact with our online content, we may automatically collect:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent on pages, click-through rates
  • Location Data: General geographic location based on IP address
  • Cookies and Tracking Technologies: As described in our Cookie Policy

Information from Third Parties

We may receive information from:

  • Social Media Platforms: When you interact with our ads or content on Meta platforms
  • Insurance Providers: For coverage verification purposes
  • Referral Sources: Healthcare providers or other treatment centers
  • Marketing Partners: Aggregated demographic and interest data

How We Use Your Information

Treatment and Care Coordination

  • Provide addiction treatment services and medical care
  • Coordinate with healthcare providers and insurance companies
  • Maintain medical records and treatment plans
  • Follow up on treatment progress and outcomes

Communication and Support

  • Respond to inquiries and provide customer support
  • Send appointment reminders and treatment updates
  • Provide educational resources about addiction and recovery
  • Communicate about our services and programs

Marketing and Advertising

  • Display targeted advertisements on Meta platforms (Facebook/Instagram)
  • Send newsletters and promotional materials (with consent)
  • Improve our marketing campaigns and measure effectiveness
  • Conduct market research and analyze user preferences

Legal and Operational Purposes

  • Comply with legal obligations and regulatory requirements
  • Protect our rights and prevent fraud or abuse
  • Improve our website functionality and user experience
  • Maintain security and prevent unauthorized access

Legal Basis for Processing (GDPR Compliance)

For users in the European Union, we process your personal data based on:

  • Consent: When you provide explicit consent for marketing communications or cookies
  • Contract: To provide treatment services you've requested
  • Legal Obligation: To comply with healthcare regulations and legal requirements
  • Legitimate Interest: To improve our services and conduct business operations

Information Sharing and Disclosure

Healthcare Providers and Insurance

We may share your information with:

  • Licensed healthcare professionals involved in your care
  • Insurance companies for coverage verification and billing
  • Laboratory services and medical testing facilities
  • Other treatment facilities for continuity of care

Service Providers

We work with trusted third-party service providers who assist with:

  • Website hosting and technical support
  • Payment processing and billing services
  • Marketing and advertising services (including Meta)
  • Customer relationship management
  • Data analytics and research

Legal Requirements

We may disclose information when required by law or to:

  • Comply with court orders, subpoenas, or legal processes
  • Protect the safety of individuals or prevent harm
  • Investigate fraud or other illegal activities
  • Enforce our terms of service or other agreements

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, subject to the same privacy protections.

Meta Advertising Compliance

Social Media Advertising

We advertise our services on Meta platforms (Facebook and Instagram). When you interact with our ads:

  • No Protected Health Information (PHI) is included in our advertisements
  • We use aggregated, non-identifying data for ad targeting
  • Tracking pixels may collect general website usage data (not PHI)
  • You can opt out of targeted advertising through Meta's ad preferences

Data Restrictions

To maintain HIPAA compliance:

  • We do not share PHI with Meta or other advertising platforms
  • Our tracking tools are configured to exclude sensitive health data
  • We use privacy-safe marketing techniques that don't compromise patient confidentiality

Your Privacy Rights

Access and Control

You have the right to:

  • Access your personal information we maintain
  • Correct inaccurate or incomplete information
  • Delete your personal information (subject to legal requirements)
  • Restrict processing of your information
  • Data portability - receive your data in a portable format

Communication Preferences

You can:

  • Opt out of marketing emails by clicking unsubscribe links
  • Update your communication preferences by contacting us
  • Limit targeted advertising through Meta's ad settings
  • Request to be removed from our marketing lists

California Privacy Rights (CCPA/CPRA)

California residents have additional rights:

  • Right to know what personal information is collected and how it's used
  • Right to delete personal information (with exceptions)
  • Right to opt out of the sale or sharing of personal information
  • Right to non-discrimination for exercising privacy rights

Do Not Sell or Share My Personal Information

Data Security and Protection

We implement comprehensive security measures including:

  • Encryption of data in transit and at rest
  • Access controls limiting who can view your information
  • Regular security audits and vulnerability assessments
  • Staff training on privacy and security best practices
  • Incident response procedures for potential data breaches

Data Retention

We retain your information for as long as necessary to:

  • Provide ongoing treatment and care
  • Comply with legal and regulatory requirements
  • Fulfill the purposes outlined in this policy
  • Resolve disputes and enforce agreements

Medical records are retained according to state and federal requirements, typically 7-10 years after treatment completion.

Cookies and Tracking Technologies

Our website uses cookies and similar technologies to:

  • Essential cookies: Enable basic website functionality
  • Analytics cookies: Understand how visitors use our site
  • Marketing cookies: Deliver relevant advertisements
  • Preference cookies: Remember your settings and preferences

You can manage cookie preferences through your browser settings or our cookie consent banner.

Cookie Policy

Children's Privacy (COPPA Compliance)

Our services are not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.

For minors aged 13-17, we require parental consent before providing treatment services and will involve parents/guardians in treatment decisions as appropriate.

International Data Transfers

If you are located outside the United States, please note that your information may be transferred to and processed in the United States, where our servers and service providers are located. We ensure appropriate safeguards are in place for international transfers.

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will:

  • Post updates on our website with the new effective date
  • Notify you of material changes via email or website notice
  • Maintain previous versions for your reference
  • Review and update this policy at least annually

Contact Information

Privacy Questions and Requests

For questions about this Privacy Policy or to exercise your privacy rights:

Ojai Recovery
Privacy Officer
Phone: 1-805-793-1702
Email: admissions@ojairecovery.com
Oakview, California

Complaints and Concerns

If you believe your privacy rights have been violated:

  • Contact us using the information above
  • File a complaint with the U.S. Department of Health and Human Services Office for Civil Rights
  • Report concerns to the Joint Commission: https://www.jointcommission.org/report_a_complaint.aspx

HIPAA Notice of Privacy Practices

As a healthcare provider, we are required to provide you with a Notice of Privacy Practices under HIPAA. This notice describes how medical information about you may be used and disclosed and how you can access this information.

Link to full HIPAA Notice of Privacy Practices

Your Rights Under HIPAA

Get an Electronic or Paper Copy of Your Medical Record

  • You can ask to see or get an electronic or paper copy of your medical record and other health information we have about you
  • We will provide a copy or a summary of your health information, usually within 30 days of your request
  • We may charge a reasonable, cost-based fee

Ask Us to Correct Your Medical Record

  • You can ask us to correct health

Privacy PolicyTerms & ConditionsMedical Disclaimer