Last Updated: January 28, 2026
Nox Medical LLC., and its affiliated parties (“Nox Medical,” “Nox,” ”we,” or “us”), are committed to protecting your privacy. We understand that health is a very private subject, and we want you to feel comfortable visiting our website and engaging with our applications and services. We provide this Website and Application Privacy Notice (“Notice”) to inform individuals about the personal data we collect, how we use, disclose, and protect that information as well as what choices you may make regarding your information.
This Privacy Notice applies to the Somryst websites and services provided through those sites, including the Somryst web-based and mobile applications (the “Somryst Application”). This Notice is incorporated into and is a part of the terms of use of the Somryst Application (the “Terms of Use”). We encourage you to review both this Notice and the Terms of Use.
When used in this Notice, “personal data” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an individual (“data subject”), and includes “personal data” or “personal information” as defined in applicable data protection laws. Data that cannot be associated with you, such as aggregated, de-identified, or anonymized information (“Anonymous Information”), is not personal data. Nox commits to keep Anonymous Information in its de-identified state, and will make no efforts to re-identify such data.
This Notice does not apply to Protected Health Information (“PHI”) as defined in the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended (“HIPAA”). For information regarding how we collect, use, and disclose PHI that we receive as a covered entity under HIPAA, please see our Notice of Privacy Practices. We may also maintain your PHI on behalf of other third parties subject to HIPAA, including, for example, Clinical Partners, Clinicians, Health Plan Sponsors, or Pharmacy Partners who are our business partners or customers. Where we maintain your PHI on behalf of any third party subject to HIPAA, we will maintain that information in accordance with the applicable Business Associate Agreement that Nox may enter into with each third party.
Clinical Partners are hospitals, clinics, practices or other medical groups or health care systems that have contracted with Nox to permit use of the Service by their respective Clinicians and Patients;
Clinicians are practitioners, patient advocates, coaches or other individuals who (as employees of or contractors to a Clinical Partner) provide health care or related services to Patients;
Health Plan Sponsors are organizations, including employers, that establish and maintain a health insurance plan for their members, employees, or participants;
Pharmacy Partners are pharmacies that have contracted with Nox to facilitate the use of the Service by their respective Clinicians and Patients; and
Patients are individual patients of the Clinical Partner who receive medical treatments or other health care services from one or more Clinicians, or individuals who are properly authorized representatives of any such patient.
By accessing and using the Somryst Application, or any part thereof, you agree that you have read and understand this Privacy Notice, and that in exchange for access to the Somryst Application, you accept and consent to the privacy practices described in this Notice.
You can navigate to particular topics by going to the desired heading below:
The table below provides you with details about the information we collect, how we obtain that information, how it is used, who it is shared with and how long we keep it. Please see the subsequent sections for further explanation about Nox’s data processing activities.
The following table provides examples of the types of information that we collect in various contexts and how we use that information.
|
Categories of Personal Data Collected |
Business and Commercial uses of Personal Data |
Categories of Third Parties to Whom We Disclose Personal Data | Retention of Personal Data |
| Identifiers: (such as name, email address, telephone number, and other contact information) | Account registration and servicing
To communicate with you To improve and develop new products and services To provide our Services and operate our business |
Our affiliates and subsidiaries
Clinicians Clinical Partners Pharmacy Partners Third parties that assist us, such as analytics providers, providers of technical services (e.g., providers of data storage, customer support), and other subcontractors Entities involved in dispute resolution (such as an arbitrator or an opposing party) Entities involved in potential or actual significant corporate transactions or events Governmental entities |
10 years
|
| Commercial information, including products and services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies | To improve and develop new products and services
To provide our Services and operate our business |
Same as above | The duration of the relationship + 3 years |
| Financial data: (such as payment information, account or credit card information) | To provide our Services and operate our business | Same as above | 7 years |
| Internet or other network or device activity: (such as IP addresses, device identifiers, cookie data, device attributes, device usage information, browsing information and metadata | Account registration and servicing
To communicate with you To improve and develop new products and services To provide our Services and operate our business |
Our affiliates and subsidiaries
Third parties that assist us, such as payment processors, analytics providers, providers of technical services (e.g., providers of data storage, customer support, and CRM systems), and other subcontractors |
1 year |
| Protected Classifications and Sensitive Personal information: Health information, such as medical conditions and prescription information
|
Business purposes | Clinicians
Clinical Partners Pharmacy Partners Professional services consultants Third parties that assist us, such as payment processors, analytics providers, providers of technical services (e.g., providers of data storage, customer support, and CRM systems), and other subcontractors |
10 years
|
In addition to collecting information from you directly, we may receive information about you from other sources, including third parties, business partners, our affiliates, or publicly available sources.
In addition to the purposes and uses described above, we use information in the following ways:
Although the sections above describe our primary purposes for collecting and using your information, in many situations, we have more than one purpose. For example, if you submit an application for a job posting, we may collect your information in anticipation of employing you, but we also collect your information as we have a legitimate interest in contacting you about the status of your application and evaluating your qualifications for the position. As a result, our collection and processing of your information is based on different contexts upon your consent, our need to perform a contract of employment, our obligations under law, and/or our legitimate interest in conducting our business.
To the extent necessary for purposes of communicating with you or fulfilling your requests for content, materials, and opportunities, we may share your information with the entities identified below and any of the entities that we elect to share such information with, subject to any legal or contractual limitations. In addition to the specific situations discussed elsewhere in this Privacy Notice, we disclose information to others in the following situations:
We, our affiliates, or our respective trusted business parties and third-party service providers may also produce reports on the Somryst Application’s traffic or usage patterns and share these reports with us, or our business partners and others. In addition to the uses described above, Nox Health may also use and disclose certain aggregated, anonymized information, such as usage data related to the Somryst Application, to our affiliates, subsidiaries, trusted business partners, or other trusted third parties. Such information may also be shared with other users or the general public for advertising, informational, or comparison purposes.
We use reasonable efforts to protect your personal data from unauthorized access, use, or disclosure. However, no method of transmission over the Internet, or method of electronic storage, is fully secure and impenetrable. Therefore, we cannot guarantee the security of your personal data. In the event that we are required by law to inform you of any unauthorized access to your personal data, we may notify you electronically, in writing, or by telephone, if permitted to do so by law. You agree to immediately notify us of any breach of security of the Somryst Application, any breach of this Privacy Notice, or any breach of the Terms of Use of which you become aware.
Some areas of our Somryst Application permit you to create an account. When you do, you will be prompted to create a password. You are responsible for maintaining the confidentiality of your user identification and your password, and you are responsible for any access to or use of your account by someone else that has obtained your user identification or your password, whether or not such access or use has been authorized by you. You should notify us of any unauthorized use of your password or account.
By placing a small file known as a “cookie” on your computer (or other device), Nox Health’s, and its third-party service providers’, servers may passively gather information about a visitor’s use of the Somryst Application for several reasons, including, but not limited to, the following: statistics collection and analysis, Somryst Application optimization, analytics (as described below), market research, and maintenance of user login information. The information that we and our third-party service providers track with cookies may include, but is not necessarily limited to, the type of browser (such as Google Chrome or Internet Explorer) and Internet-connected device being used to access the Somryst Application, your Internet Protocol (“IP”) address, your home domain or Internet service provider, your referrer URL (which is the URL for the website that you were viewing prior to visiting the Somryst Application), how you were directed to the Somryst Application, which specific pages you access, how long you view each page, the time and date you gain access and the total number of visitors to the Somryst Application and any portions thereof. We may also use your IP address to determine the general physical location of your computer or device and understand from what geographic locations visitors come.
Our Somryst Application allows you to define which cookies you will allow on your computer and will respect those settings. Certain cookies labeled “Strictly Necessary Cookies” are required for our applications to function.
Nox Medical. is a multinational company and maintains offices around the world, including in the United States, Canada, Portugal, and in Iceland. As a result, your personal data may be processed in a foreign country where privacy laws may be less stringent than the laws in your country. Nonetheless, where possible, we take steps to treat personal data using the same privacy principles that apply pursuant to the law of the country in which we first received it. By submitting your personal data to us, you agree to the transfer, storage and processing of your personal data in a country other than your country of residence including, but not necessarily limited to, the United States. If you are visiting the Somryst site or Application or any part thereof from outside of the United States of America, please be aware that your information may be transferred to, stored or processed in the United States, where our servers are located and our central database is operated. The data protection and other laws of the United States and other countries might not be as comprehensive as those in your country,and have put in place the required legal data transfer mechanisms necessary to protect your data By using any portion of the Somryst Application, you understand and consent to the transfer of your information to our facilities in the United States and those third parties with whom we share it as described in this Privacy Notice. If you would like more information concerning our attempts to apply the privacy principles applicable in one jurisdiction to personal data when it goes to another jurisdiction, you can contact us using the contact information below.
You may have certain rights and choices regarding your personal data. Depending on your jurisdiction, and subject to applicable law, you may make the following choices:
For your convenience, some hyperlinks may be posted on the Somryst Application that link to other websites not under our control (the “Linked Websites”). We are not responsible for, and this Privacy Notice does not apply to, the privacy practices of any Linked Websites or of any companies that we do not own or control. We cannot be responsible for the privacy practices of any such Linked Websites, nor do we endorse any of these Linked Websites, the services or products described or offered on such Linked Websites, or any of the content contained on the Linked Websites. We encourage you to seek out and read the privacy policy of each website that you visit. In addition, should you happen to initiate a transaction on a Linked Website, even if you reached that site through Somryst Application, the information you submit to complete that transaction becomes subject to the privacy practices of the operator of the applicable Linked Website. You should read each Linked Website’s privacy policies to understand how Personal Information that is collected about you is used and protected.
We may change this Privacy Notice from time to time. The effective date of this Privacy Notice is specified by the version date located at the end of this Privacy Notice. All updates and amendments to this Privacy Notice are effective immediately when posted on the SleeCharge Application. We expressly reserve the right to make any changes to this Privacy Notice at any time, without prior notice to you. This Privacy Notice is not intended to and does not create any contractual or other legal right in or on behalf of any party other than Nox Health.
The Somryst Application is intended for a general audience and is not intended for use or viewing by children under sixteen (16) years of age, and we do not knowingly collect information about children or sell products to children.
Should you have any questions about this Privacy Notice or our privacy practices, please contact us at the appropriate address below.
Nox Medical, LLC.
Data Privacy and Security Officer
100 Kimball Place, Suite 100
Alpharetta, GA 30009
Tel.(844) 475-3376.
Fax. (678) 669-2274
You may also contact your local supervisory authority.
Nox has adopted a global approach on privacy with the intent of providing individuals with strong privacy protections regardless of where they reside. We recognize and implement high standards for privacy rights. If you have any questions or concerns regarding the privacy provisions relevant to you, or you wish to exercise any of these rights, please contact our Privacy Officer by using the contact information provided in Section 17 “Contact Information.”
Controlling Law: There are many US state-specific privacy laws with new ones coming into effect every year. Because California’s privacy protections are viewed by many to be the most comprehensive in the US, we refer US-based individuals to the California Consumer Privacy Act of 2018 (“CCPA”), and as of January 1, 2023 the California Privacy Rights Act of 2020 (“CPRA”), for personal data protection.
Our Processing of US Personal Data: We collect and have collected in the last 12 months all of the information described in Section 3 of our Privacy Statement from and about US residents. You should refer to that section for more detail, but this information generally falls into the categories listed in the chart in Section 3 to the extent it is personally identifiable. The chart also indicates the data subjects whose personal data we collect, the purposes of processing, and the categories of third parties to whom we recently disclosed the data leading up to the effective date of this Statement.
We have not sold or shared (as defined in the CCPA and other U.S. state comprehensive privacy laws) personal data covered by this Privacy Notice in the preceding 12 months. We also do not knowingly sell or share the personal data of individuals under 16 years of age.
US Privacy Rights: Under applicable US law, you have the right to:
You may designate an authorized agent to request any of the above rights on your behalf. You may make such a designation by providing the agent with a signed written document permission stating that the agent is authorized to make the request on your behalf. Your agent may contact us via the information provided above to make a request on your behalf. If you are submitting a request through an authorized agent, we may, as permitted by law, require:
Subject to applicable law, we may not discriminate against you for exercising any of the above-listed rights or any other rights under the CCPA or similar U.S. state comprehensive privacy laws, including by:
California law requires that Nox indicate whether it honors “Do Not Track” settings in your browser concerning targeted advertising. “Do Not Track” is a standard that is not currently in use by Nox. As it is not currently in use, Nox adheres to the standards set out in this Privacy Notice and does not monitor or follow any Do Not Track browser requests.
Marketing opt-out: You may opt out of marketing communications by contacting us using our online form or you may email us at privacy@noxmedical.com or call (844) 475-3376 to submit an inquiry.
Contact: Please contact us as described in Section 17 for more information or to exercise a request regarding your US privacy rights.
Supervisory Authority:
If you are concerned about Nox’s compliance with US laws relating to the privacy of your personal data, you may contact your Attorney General’s Office.
List of Attorneys General: https://www.naag.org/find-my-ag/
This Washington Consumer Health Data Privacy Notice applies to “consumer health data” collected from Washington state residents and those whose consumer health data is collected through Somryst by Nox Medical LLC (“Somryst,” “Nox,” “Nox Medical,” “we,” “us,” or “our”) or affiliated website on which it is posted, as well as those whose consumer health data is collected in the State of Washington. This notice applies to Washington residents and those whose consumer health data is collected in Washington. Consumer health data means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer’s past, present, or future physical or mental health status, under the Washington State My Health My Data Act (MHMDA). See also our other privacy notices that provide disclosures about personal information that is not consumer health data subject to MHMDA.
This notice does not apply where an exception or exemption applies such as with respect to protected health information under the Health Insurance Portability and Accountability Act (“HIPAA”) and data that is subject to the Gramm-Leach-Bliley Act (“GLBA”). When we are a covered entity, we provide separate HIPAA and GLBA privacy notices to certain customers and consumers as required under applicable laws and regulations. Most consumer health data we process is regulated under HIPAA or GLBA or is processed for a necessary function.
Consumer Health Data Collected
The personal information, including consumer health data, we collect varies based on your relationship with us. For example, if you visit our website we may collect personal information through tracking technologies essential to running our website.
We may collect the following categories of consumer health data:
The categories of consumer health data above may include the following personal information, when collected in connection with your past, present, or future physical or mental health status:
We process any deidentified consumer health data only in a deidentified fashion and will not attempt to reidentify such data.
Why We Collect and Use Consumer Health Data
To the extent we collect your Consumer Health Data as described above, we may use it for the following purposes:
Categories of Sources
We generally collect personal information, including consumer health data, from the following categories of sources:
Our Sharing of Consumer Health Data
The categories of third parties and other recipients with whom we may share consumer health data as necessary to provide our products and services requested by consumers are:
How to Exercise Your Rights
MHMDA grants certain rights including a right of access and deletion, subject to certain exceptions.
Upon request, Nox will provide you with a copy of personal data we hold about you, correct your personal data, or delete your personal data. You may also object to processing of your personal data or opt-out of automated decision making processes.
Please note, pursuant to the law, certain personal data is exempt from the above requests. To exercise any of these rights, please use our online form, email privacy@noxmedical.com, or call (855-617-6691).
We may request additional information from you, if necessary, to verify your identity or find your unique records in our systems. If you are the authorized representative making an access, correction or deletion request, we must take steps to verify your authority. This will require you to provide written proof of your authority.
We respect your right to privacy, and will not take any negative actions against you for asserting your rights.
If your request to exercise a right under the MHMDA is denied, you may appeal the denial. A method for submitting an appeal will be contained in our response. If your appeal is unsuccessful, you can raise a concern or lodge a complaint with the Washington State Attorney General at www.atg.wa.gov/file-complaint.
Contact
If you have any questions on the processing of your personal data, please contact us using the details below.
Nox Medical, LLC.
Data Privacy and Security Officer
100 Kimball Place, Suite 100
Alpharetta, GA 30009
Tel.(844) 475-3376.
Fax. (678) 669-2274
You may also contact your local supervisory authority.