Where Veterans Are VIP Privacy Policy

Effective Date: May 25, 2026
Last Updated: May 25, 2026

1. Introduction

Welcome to Where Veterans are VIP and Veterans Care International (VCI) (“Company,” “we,” “our,” or “us”).

We are committed to protecting the privacy, confidentiality, integrity, and security of personal information entrusted to us by our customers, prospects, users, patients, partners, employees, contractors, and visitors.

This Privacy Policy explains how we collect, process, store, use, disclose, transfer, and safeguard personal information through our websites, applications, communication systems, customer relationship management platforms, cloud infrastructure, telecommunications services, support systems, and related services.

This Privacy Policy has been developed to align with applicable international privacy and data protection regulations, including but not limited to:

  • The General Data Protection Regulation (GDPR) of the European Union;
  • The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA);
  • The Health Insurance Portability and Accountability Act (HIPAA), where Protected Health Information (PHI) is processed;
  • Applicable telecommunications, cybersecurity, consumer protection, and data privacy laws.

This policy applies to all individuals whose information we process, including:

  • Customers;
  • Leads and prospects;
  • Website visitors;
  • Patients and healthcare-related contacts;
  • Vendors and business partners;
  • Employees and contractors;
  • Users of our communication platforms and services.

By accessing or using our services, websites, communication systems, forms, portals, applications, or interacting with us through phone, SMS, email, or other channels, you acknowledge and agree to the terms of this Privacy Policy.

2. Scope of This Policy

This Privacy Policy applies to all information collected through:

  • Websites and landing pages;
  • Customer portals and applications;
  • Zoho CRM;
  • JustCall;
  • VoIP systems;
  • SMS and MMS services;
  • Call center operations;
  • Email communications;
  • Support and ticketing systems;
  • Online forms;
  • Integrations with third-party systems;
  • Analytics and tracking technologies;
  • Marketing campaigns;
  • Social media interactions;
  • Customer support interactions.

This policy applies regardless of the country from which users access our services.

3. Definitions

3.1 Personal Information

“Personal Information” means any information that identifies, relates to, describes, or can reasonably be linked to an individual.

3.2 Sensitive Personal Information

Sensitive information includes:

  • Government-issued identifiers;
  • Financial information;
  • Authentication credentials;
  • Health-related information;
  • Biometric information;
  • Precise geolocation;
  • Account credentials;
  • Communication contents.

3.3 Protected Health Information (PHI)

Under HIPAA, Protected Health Information includes individually identifiable health information transmitted or maintained in any form or medium.

3.4 Processing

“Processing” means any operation performed on personal information, including collection, storage, use, disclosure, transmission, deletion, analysis, recording, or organization.

4. Information We Collect

We may collect the following categories of information.

4.1 Personal Identification Information

  • Full name;
  • Email address;
  • Phone number;
  • Mailing address;
  • Government-issued identifiers where legally required.

4.2 Communication Information

When you communicate with us through telephone systems, SMS, email, support systems, or messaging platforms, we may collect:

  • Call recordings;
  • Call metadata;
  • Call duration;
  • Call routing information;
  • SMS and MMS content;
  • Voicemail recordings;
  • Chat conversations;
  • Communication transcripts;
  • Customer support tickets;
  • Internal notes and annotations.
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
 

4.3 Technical Information

We may automatically collect:

  • IP address;
  • Browser type and version;
  • Operating system;
  • Device identifiers;
  • Session identifiers;
  • Cookies and tracking identifiers;
  • Referring URLs;
  • Usage logs;
  • Approximate geographic location;
  • Diagnostic and telemetry data.

4.4 Financial and Billing Information

Where applicable:

  • Billing address;
  • Payment method information;
  • Transaction history;
  • Invoices;
  • Tax-related information.

Payment processing may be handled by third-party payment processors.

4.5 Healthcare and Sensitive Information

Where applicable to healthcare-related services:

  • Protected Health Information (PHI);
  • Appointment information;
  • Clinical communication history;
  • Patient support records;
  • Medical service interactions.

We process PHI in accordance with HIPAA requirements when applicable.

4.6 Marketing and Preference Information

  • Marketing preferences;
  • Survey responses;
  • Campaign interactions;
  • Advertisement engagement;
  • Consent records.

5. How We Collect Information

We collect information through:

  • Direct user submissions;
  • Website forms;
  • CRM integrations;
  • Telephone systems;
  • SMS platforms;
  • Email communications;
  • Cookies and analytics technologies;
  • Third-party integrations;
  • API integrations;
  • Customer support interactions;
  • Service agreements and contracts;
  • Marketing and lead generation campaigns.

6. Legal Basis for Processing (GDPR)

For individuals located in the European Economic Area (EEA), United Kingdom, or jurisdictions applying similar standards, we process personal data under one or more lawful bases:

6.1 Consent

We may process information based on explicit consent.

6.2 Contractual Necessity

Processing necessary to perform contractual obligations.

6.3 Legal Obligations

Processing necessary to comply with applicable laws and regulations.

6.4 Legitimate Interests

Processing necessary for legitimate business interests including:

  • Service improvement;
  • Fraud prevention;
  • Security monitoring;
  • Customer support;
  • Marketing communications;
  • Operational efficiency.

6.5 Vital Interests

Processing necessary to protect the vital interests of individuals.

7. Use of Zoho CRM

We use Zoho CRM as our customer relationship management platform.

Zoho CRM may process and store:

  • Contact records;
  • Customer communications;
  • Sales opportunities;
  • Service requests;
  • Internal notes;
  • Call records;
  • Email interactions;
  • Marketing engagement data.

Zoho CRM is used to:

  • Manage customer relationships;
  • Track support activities;
  • Automate workflows;
  • Manage marketing campaigns;
  • Improve customer service;
  • Maintain operational records.

Information stored within Zoho CRM may be hosted in cloud environments managed by Zoho Corporation and its infrastructure providers.

8. Use of JustCall

We use JustCall for telecommunications, SMS messaging, call management, customer engagement, and communication tracking.

JustCall may process:

  • Incoming and outgoing calls;
  • SMS communications;
  • Call recordings;
  • Voicemail;
  • Call analytics;
  • Call transcriptions;
  • Communication metadata.

We may record or monitor calls for:

  • Quality assurance;
  • Compliance;
  • Security;
  • Staff training;
  • Customer support;
  • Operational documentation.

By communicating with us via phone or SMS, you acknowledge that calls or messages may be recorded, monitored, transcribed, analyzed, and stored.

9. Purpose of Processing

We process personal information for the following purposes:

  • Providing products and services;
  • Managing customer relationships;
  • Technical support;
  • Communication management;
  • Billing and payment processing;
  • Regulatory compliance;
  • Fraud prevention;
  • Security monitoring;
  • Data analytics;
  • Marketing campaigns;
  • Service optimization;
  • Internal administration;
  • Telecommunications management;
  • Customer authentication;
  • Performance measurement;
  • Incident response;
  • Legal and contractual enforcement.

We do not process personal information for purposes materially different from those described in this policy without appropriate notice or consent.

10. HIPAA Compliance

Where our services involve Protected Health Information (PHI), we implement safeguards designed to comply with HIPAA requirements.

10.1 Administrative Safeguards

  • Workforce training;
  • Access management;
  • Risk assessments;
  • Security policies;
  • Incident response procedures.

10.2 Technical Safeguards

  • Encryption;
  • Access controls;
  • Authentication mechanisms;
  • Audit logging;
  • Secure transmission protocols.

10.3 Physical Safeguards

  • Secure facilities;
  • Device management;
  • Infrastructure protection.

10.4 Business Associate Agreements (BAA)

Where required, we may execute Business Associate Agreements with applicable vendors and customers.

11. CCPA/CPRA Privacy Rights

California residents may have the following rights:

  • Right to know;
  • Right to access;
  • Right to correction;
  • Right to deletion;
  • Right to opt out of sale or sharing;
  • Right to limit use of sensitive personal information;
  • Right to non-discrimination.

We do not sell personal information as defined under the CCPA/CPRA.

California residents may submit requests using the contact information listed below.

12. GDPR Data Subject Rights

Individuals protected under GDPR may exercise:

  • Right of access;
  • Right to rectification;
  • Right to erasure;
  • Right to restrict processing;
  • Right to object;
  • Right to data portability;
  • Right to withdraw consent;
  • Right to lodge complaints with supervisory authorities.

Requests may be submitted using the contact information in this policy.

13. Data Sharing and Disclosure

We may disclose personal information to:

  • Cloud hosting providers;
  • CRM providers;
  • Telecommunications providers;
  • Analytics providers;
  • Payment processors;
  • Legal advisors;
  • Auditors;
  • Regulatory authorities;
  • Service providers;
  • Security and compliance vendors.

All third parties are expected to maintain appropriate security and confidentiality measures.

We do not sell personal information.

14. International Data Transfers

Personal information may be processed in countries outside your jurisdiction, including the United States.

Where required by GDPR or similar regulations, we implement safeguards such as:

  • Standard Contractual Clauses (SCCs);
  • Data Processing Agreements;
  • Encryption controls;
  • Security certifications;
  • Cross-border transfer assessments.