Official websites covered: www.northstaremergencycenter.com and www.nstartec.com.
1. Introduction
NorthStar Emergency Center ("NorthStar," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit www.northstaremergencycenter.com or another website where this policy is posted (collectively, the "Site"), contact us, or otherwise interact with us outside a patient-care relationship.
This Privacy Policy applies to general website and business information. Medical information that NorthStar creates, receives, or maintains as a healthcare provider may be protected health information ("PHI") governed by the Health Insurance Portability and Accountability Act ("HIPAA") and other health-privacy laws. Please review our separate HIPAA Notice of Privacy Practices for information about how we use and disclose PHI and the rights you may have regarding your medical records.
2. Medical Emergencies and Sensitive Information
The Site and its contact form are not monitored continuously and must not be used for medical emergencies, diagnosis, treatment requests, time-sensitive symptoms, prescription requests, or communications containing sensitive medical details.
If you are experiencing a medical emergency, call 911 or go to the nearest appropriate emergency facility. Do not wait for an email or website response.
Please do not submit medical-record information, Social Security numbers, payment-card data, insurance identification numbers, or other highly sensitive information through a general website form or ordinary email unless NorthStar specifically provides a secure method and asks you to use it.
3. Personal Information We Collect
Depending on how you interact with the Site, we may collect the following categories of information.
A. Information You Provide
When you submit a contact form, email us, call us, or otherwise communicate with us, we may collect:
- Name
- Telephone number
- Email address
- The contents of your message
- Communication preferences
- Records of our correspondence
- Any other information you choose to provide
If you submit information about another person, you represent that you are authorized to do so.
B. Information Collected Automatically
When you visit the Site, our web server or service providers may automatically receive limited technical information, such as:
- Internet Protocol (IP) address
- Browser and device type
- Operating system
- Referring and exit pages
- Pages viewed and links clicked
- Approximate location derived from an IP address
- Date, time, and duration of a visit
- Error, security, and performance logs
The current Site does not appear to contain advertising pixels or behavioral-analytics scripts. It loads web fonts from Google and provides links to Google Maps. [CONFIRM BEFORE PUBLICATION: identify all hosting, security, analytics, consent-management, chat, call-tracking, form, CRM, map, video, scheduling, advertising, and tag-management tools used in production.]
C. Cookies and Similar Technologies
Cookies are small files stored on a browser or device. We may use cookies or similar technologies that are necessary to operate the Site, maintain security, remember preferences, measure performance, or understand Site use.
At the time this draft was prepared, the Site code did not show nonessential advertising or analytics cookies. If NorthStar later adds analytics, advertising, chat, session replay, embedded maps, videos, or similar tools, this section and any required consent mechanism must be updated before those tools are activated.
You can adjust browser settings to block or delete cookies. Blocking necessary cookies may affect Site functionality. Browser "Do Not Track" signals are not subject to a uniform industry standard. Where required by applicable law, we will honor legally recognized opt-out preference signals.
D. Information From Other Sources
We may receive information from service providers, business partners, public sources, or other people—for example, when a person asks us to contact you or when a service provider helps protect the Site from fraud or abuse.
4. How We Use Personal Information
We may use personal information to:
- Respond to general questions and communications
- Provide requested information about our location, hours, or services
- Operate, maintain, secure, and improve the Site
- Diagnose technical problems and prevent fraud, misuse, or security incidents
- Understand general Site usage and performance
- Maintain business and compliance records
- Enforce our Terms of Use
- Protect the rights, safety, and property of NorthStar, our patients, users, workforce, and others
- Comply with law, legal process, audits, or regulatory obligations
- Carry out another purpose disclosed when information is collected or with your consent
We do not use a general website inquiry to establish a clinician-patient relationship, diagnose a condition, or guarantee an appointment or response time.
5. How We Disclose Personal Information
We may disclose personal information in the following circumstances.
A. Service Providers
We may provide information to vendors that perform services for us, such as website hosting, cybersecurity, form processing, email delivery, customer communications, data storage, analytics, and professional advice. We require service providers to handle information consistently with their contractual and legal obligations.
If a vendor creates, receives, maintains, or transmits PHI on our behalf, we will address HIPAA requirements, including a business associate agreement when required. A privacy policy or cookie banner alone does not authorize a disclosure of PHI.
B. Legal, Safety, and Compliance Purposes
We may disclose information when we reasonably believe disclosure is necessary to:
- Comply with applicable law, regulation, court order, subpoena, or lawful government request
- Protect a person's health or safety
- Detect, investigate, or prevent fraud, misuse, or security incidents
- Protect or enforce our rights, agreements, and property
- Cooperate with regulators, law enforcement, or professional advisers
C. Business Transactions
Information may be disclosed as part of a proposed or completed merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, subject to applicable legal protections.
D. With Your Direction or Consent
We may disclose information when you ask or authorize us to do so.
6. No Sale or Targeted Advertising — Confirm Before Publication
Based on the Site code reviewed for this draft, NorthStar does not appear to sell personal information or use it for targeted advertising across unrelated websites. [CONFIRM WITH MANAGEMENT AND ALL VENDORS BEFORE PUBLICATION.]
NorthStar will not sell sensitive personal data, including health-related data, or process it for targeted advertising without providing any notice, consent, and opt-out rights required by applicable law.
7. Third-Party Services and Links
The Site may link to third-party websites or services, such as Google Maps, social networks, insurers, or government resources. Third parties operate under their own privacy policies and terms. NorthStar is not responsible for their privacy, security, content, or availability.
Loading third-party content may allow that provider to receive technical information such as an IP address. NorthStar should evaluate third-party tools before deployment, particularly where a tool may receive health-related or identifying information.
8. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including responding to inquiries, maintaining business records, resolving disputes, protecting security, and meeting legal obligations.
[INSERT VERIFIED RETENTION RULES: general contact-form submissions — ___ months/years; security logs — ___ days/months; consent records — ___ years.]
When information is no longer needed, we may delete, destroy, anonymize, or aggregate it, subject to legal and operational requirements. Medical-record retention is governed by separate healthcare laws and NorthStar record-retention policies.
9. Security
We use administrative, technical, and physical safeguards designed to protect personal information. However, no website, email, network, storage system, or Internet transmission can be guaranteed completely secure. You use ordinary email and the general contact form at your own risk and should not send sensitive medical or financial information through them.
If we identify a breach requiring notification, we will provide notice as required by applicable law.
10. Children's Privacy
The Site is intended for a general audience and is not designed for children under 13 to use independently. We do not knowingly collect personal information online directly from a child under 13 without authorization from a parent or legal guardian. If you believe a child has submitted personal information through the Site, contact us so we can review and address it.
This section does not limit NorthStar's ability to provide emergency medical care to children or to maintain pediatric medical records as permitted or required by law.
11. Your Privacy Choices and Requests
Depending on applicable law and the nature of the information, you may request that we:
- Confirm whether we process certain personal information about you
- Provide access to or a copy of certain personal information
- Correct inaccurate personal information
- Delete certain personal information
- Provide certain information in a portable format
- Stop particular processing, where a legal right applies
- Withdraw consent for future processing based on consent
- Review an appeal of a denied privacy request, where applicable
These rights may not apply to every person or every type of information. Exceptions may apply for legal compliance, security, record retention, exercising legal claims, and other lawful purposes. HIPAA rights concerning PHI and medical records are described in our HIPAA Notice of Privacy Practices and may follow a different process.
To make a website-privacy request, contact us using the information below. We may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, but we may require proof of authority and identity verification.
We will not unlawfully discriminate against you for exercising an applicable privacy right.
12. Texas Privacy Information
NorthStar is based in Texas. The Texas Data Privacy and Security Act and other state or federal laws may provide rights or impose obligations depending on the data, entity, and circumstances. Certain data regulated by HIPAA and certain healthcare entities or activities may be exempt from some state-law provisions.
Where a Texas consumer right applies, you may submit a request or appeal using the contact information below. You may also submit a consumer privacy complaint to the Texas Attorney General through its official website.
This policy does not create rights beyond those provided by applicable law.
13. International Visitors
NorthStar operates in Texas, United States, and the Site is directed primarily to people in the United States. If you access the Site from another country, your information may be processed in the United States, where privacy laws may differ from those in your location.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, vendors, or legal obligations. We will post the revised policy on this page and change the effective date. If required by law, we will provide additional notice or request consent.
15. Contact Us
For questions or requests concerning this website Privacy Policy, contact:
NorthStar Emergency Center Attn: [PRIVACY CONTACT NAME OR TITLE] 9920 Cypresswood Dr Houston, TX 77070 Phone: [PHONE] Email: [PRIVACY EMAIL]
Do not use this contact channel for an emergency or to send sensitive medical information.
Contact details pending: Phone and designated legal or privacy contact fields remain marked with brackets until NorthStar provides the approved information.