Effective June 2, 2026
If you have any questions about our Privacy Policy, you can contact us at Privacy@everydayhealth.com and include 'Privacy Policy' in the subject line.
PRISM Implementation Science Mobilized, LLC, with its parents (including Everyday Health, Inc.), its affiliates and its subsidiaries, (collectively, "PRISM", "us", "our" or "we"), owns and operates the PRISM business and all its branded interactive websites, mobile and connected applications, and other online interactive features and services, including, but not limited to, emails, newsletters, chat areas, natural language processing services executed via artificial conversation entity or entities (“ACE”), forums, communities, career centers, sweepstakes and contests for professionals in the healthcare industry (collectively "Services"). This Privacy Policy applies to all information collected about you by PRISM, describes the types of information collected about you when you interact with the Services, how your information may be used, when your information may be disclosed, how you can control the use and disclosure of your information, and how your information is protected.
Except as otherwise noted in this Privacy Policy, PRISM is a data controller (as that term is used under applicable privacy regulations, or a Business in the case of California), which means that we decide how and why the information you provide to us is processed.
We may collect or obtain information about you when you sign up, use and interact with our services and when you make your personal information public. In some cases, we may also receive information about you from third parties.
Data you provide when you sign up: This is, for example, username, password, subscription information, self-assessment data that you have not provided anonymously, and location.
Data you provide when you create profiles, pages or contributions: This is user generated contributions, such as the contents of profiles, including your profile name, contact details and any demographic information you choose to provide; as well as any comments and posts made in forums. We seek to provide users with an opportunity to be a part of an online community and communicate and share with others. This can include personal information that users choose to share. We encourage all of our users to make conscious choices about what they share online. PRISM, including its affiliates, subsidiaries and parent company, is not responsible for the information you disclose to the public using our services.
Inferences: We may infer data about you based on other data we collect about you, such as where you live, what language(s) you speak, and other data we have access to.
Data we collect through your use of our services: We make and keep records when we provide you support or assistance for the use of our services. We may also collect information about how you interact with our services or third party content you see on our apps and sites. We also collect data on how you interact with the ads you see. Data we receive from third parties: In some cases, we may receive information about you from third parties, for example, social networking sites. Please note that this policy does not cover the practices of third parties, including those that may disclose information to us.
We aim to process your personal information to provide you the best experience of our services. We may also process your information where the processing is necessary for the establishment, exercise or defense of legal rights.
Below is a chart stating which categories of personal information we process for which purposes, specifically, and how long we retain that data. Our processing of your data is subject to your use of our service, your privacy preferences, and your account setting choices.
| Purpose of Processing | Data Elements* | Legal Basis | Retention Period |
|---|---|---|---|
| 1. To provide use of our services as agreed in the ToS | Self-Assessment Data (anonymous user responses to the self-assessment, reported as outcomes only); Anonymous Engagement Data (visits, assessment completion rates, general interaction patterns); Location Information (IP address for non-precise GeoIP Data); Cookies and similar technologies (for session tracking and aggregate metrics only, excluding tracking of individual users over time). | Performance of a Contract, Legitimate Interest | Life of the account + legally compliant period thereafter |
| 2. Comply with applicable laws | Consent Records (records of anonymous consent to ToS/Privacy Policy); Location Information (IP address for non-precise GeoIP Data, used for regulatory compliance checks only, including blocking high-risk countries); Anonymous Engagement Data (to support outcomes and compliance reporting). Cookies (tracking data through cookies) | Legal Requirement | Life of the account + legally compliant period thereafter |
| 3. Enable customer expression | Engagement Data : Self-assestment submissions | Legitimate Interest | Life of the account + legally compliant period thereafter |
| 4. Maintain and Improve quality of services | Anonymous Engagement Data (non-identifiable behavioral patterns: visits, assessment completion rates, general interaction patterns); Device Information (device type, OS, used for aggregate performance analysis only); Location Information (IP address for non-precise GeoIP Data) | Legitimate Interest | Life of the account + legally compliant period thereafter |
| 5. Marketing | No personal data is collected or processed for direct marketing or targeted advertising, consistent with the microsite’s anonymous design. | Consent | Life of the account + legally compliant period thereafter |
| 6. Provide users with the ability to communicate efficiently and effectively with our company / Customer Support | Customer Records (Only collected if you proactively contact support at support@prism.com, and is limited to information provided by the user in the communication, such as name, email address, or any other personal data the user chooses to submit. | Legitimate Interest | In accordance with applicable laws |
We do not collect or process other sensitive personal information about race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, physical or mental health, sexual life, any actual or alleged criminal offences or penalties in the ordinary course of our business. Our Services are not intended for use by children.If it is discovered that we have collected Personal Information from a Minor, we will delete that information immediately.
We may use the contact details you provided us to reach out to you with information regarding services that may be of interest to you, for example, upcoming promotions. You may unsubscribe or opt out of SMS messages at any time at no cost.
We may collect information about you through the use of cookies and similar technologies on our sites and apps, or your devices. In compliance with your privacy choices and settings, we also may permit our third-party service providers to perform various analytics functions and to provide you with more relevant or interest-based advertisements using cookies.Some third parties may choose to use their own cookies for the purposes of collecting information relating to the viewing of their advertising. To learn more about how we use cookies, and to manage your preferences, please see our Cookie Policy.
Ziff Davis Companies: PRISM is owned by Ziff Davis, Inc. We share your information with other business owned by Ziff Davis, Inc. (“Ziff Davis Companies”) to assist in the operation of our services, to improve them and further develop them. We also share information with other Ziff Davis Companies for the purposes of targeted advertising. If you would like to opt out of the sale or sharing of your data with other Ziff Davis companies, you can do so via our Privacy Portal.
Other Third Parties: We may also share your personal information with the following:
We may transfer your information to recipients in other countries. Ziff Davis, Inc., participates in the E.U.-U.S. Data Privacy Framework, the UK extension to the EU-U.S. DPF, the Swiss-U.S. Privacy Framework and the APEC Cross Border Privacy Rules System. Where we transfer information from the European Economic Area (“EEA”) to a recipient outside the EEA that is not in an adequate jurisdiction, we do so on the basis of standard contractual clauses.
Because of the international nature of our business, we may need to transfer your information within the Ziff Davis group of companies, and to third parties as noted above, in connection with the purposes set out in this Policy. For this reason, we may transfer your information to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which you are located. We remain liable under the DPF Principles if any third parties that we transfer your personal information to process it in a manner inconsistent with the DPF Principles, unless we prove that we are not responsible for the event giving rise to the damage.
Ziff Davis, Inc. and its associated affiliates and subsidiaries complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Ziff Davis, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF.Ziff Davis, Inc. has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov.
We are committed to staying current with developments related to the Data Privacy Framework and may update our transfer mechanisms and safeguards as necessary to remain compliant. Any updates will be reflected in this Privacy Policy.
If you are a European individual with a privacy related complaint, concern or question about Ziff Davis, Inc.’s privacy practices, please contact us through our privacy portal. Under certain conditions, more fully described on the Data Privacy Framework website, European individuals may invoke binding arbitration when other dispute resolution procedures have been exhausted.
Where we transfer your personal information from the EEA to recipients located outside the EEA who are not in a jurisdiction that has been formally designated by the European Commission as providing an adequate level of protection for information, we do so on the basis of standard contractual clauses. You may request a copy of the relevant standard contractual clauses using our privacy portal. Please note that when you transfer any personal information directly to an entity established outside the EEA, we are not responsible for that transfer of your information. We will nevertheless process your information, from the point at which we receive the data, in accordance with the provisions of this policy.
The Federal Trade Commission has jurisdiction over our compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Ziff Davis, Inc. commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Ziff Davis, Inc. at privacy@everydayhealth.com.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Ziff Davis, Inc. commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to TrustArc, an alternative dispute resolution provider. The services of Trustarc are provided at no cost to you. For further information please visit https://trustarc.com/dispute-resolution/.
Under certain conditions, a binding arbitration option may be available to you in order to address complaints not resolved by any other means. For further information, please see Annex I of the EU-U.S. Data Privacy Framework Principles at: https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Ziff Davis, Inc. commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of human resources data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF in the context of the employment relationship.
For a list of our subsidiaries and affiliates who also adhere to the DPF Principles, please click here.
Our privacy practices described in this Policy comply with the Asia-Pacific Economic Cooperation (“ APEC ”) Cross Border Privacy Rules System. To learn more about this program, please click here.
We implement appropriate technical and organizational security measures to protect your personal information against unlawful destruction, loss alteration, misuse, or unauthorized access while in our possession. In compliance with applicable laws and regulations, all parties we contract with must agree to provide reasonable data security measures for the customer information we share with them.
If you have any reason to believe that your data with us has been compromised (for example, there has been unauthorized access to your account), please contact us at privacy@everydayhealth.com
We will retain your personal information for no longer than is necessary to fulfill each of the purposes set out in this policy, and in accordance with applicable laws. For more details on how long data is retained see the table in Section 3.
Many privacy regulations afford consumers a number of specific rights. The EEA, Brazil, California, and several other U.S. states and countries grant specific rights to people living under their jurisdiction. You can exercise the rights below by visiting our privacy portal or emailing us at privacy@everydayhealth.com .
Your rights:
How to Exercise Your Request: You, or an agent authorized to act on your behalf, may exercise these choices through the mechanisms described above, by emailing us at privacy@everydayhealth.com, or through our interactive webform available through the Privacy Portal.
How We Process Your Request: For security purposes and in order to complete your request appropriately, we may need to ask specific information from you to help us confirm your identity and/or clarify your request.
How to Appeal a Decision Concerning Your Request: If we notify you that we will not take action on your request, you may appeal such refusal within a reasonable period after receipt of the notice by following the instructions provided in the notice or by submitting an appeal through the Privacy Portal.
You can change your preferences at any time. Below is a list of some of the actions you can take.
You can submit privacy related inquiries to our Privacy Portal. For any additional questions, you can contact us by emailing support@prism.com, or privacy@everydayhealth.com. You can send postal mail to the following address.
Ziff Davis
Attention: Legal Department
360 Park Ave. S., 17th Floor
New York, NY 10010
We have registered our DPO with the Irish Data Protection Commission. If you have any questions or concerns about our privacy practices, we encourage you to contact our DPO at the following email address dpo@ziffdavis.com or at the following address:
Ziff Davis
Attention: Legal Department
Unit. 3.1, Woodford Business Park
Santry, Dublin 17 Ireland
These services are not intended for use by children under 18. We reserve the right to remove an account at any time, when necessary, if we discover that an account holder is under 18. If you have reason to believe we have collected personal information from someone under 18, please report it to us so we can take appropriate steps to rectify it.
Pursuant to the California privacy regulations, our consumer rights metrics can be found on our Regulatory Information Site.
We are committed to ensuring this policy is accessible to individuals with disabilities. If you wish to access this policy in an alternative format, please contact us .
This policy may be amended or updated from time to time at our discretion. Any updates will be effective at the time of publication, unless specified otherwise. Your continued use of our Services after the publication of a policy update constitutes your consent to the changes. We will notify you prior to making policy updates that materially change the way we treat your personal data, and will not use your data in a materially different manner without notice to you or without your consent, depending on applicable legal requirements.