Effective Date: 1st April, 2026
This Privacy Policy (“Policy”) sets forth the manner in which LaCharme LLC, a Florida limited liability company doing business as Health & Group (“H& Group,” “Company,” “we,” “us,” or “our”), collects, processes, stores, uses, discloses, and protects personal information obtained through the website located at https://healthandgroup.com (the “Website”).
This Policy applies to all users (“User,” “you,” or “your”) who access or interact with the Website.
1. ROLE OF THE COMPANY
1.1 For the purposes of applicable data protection laws, the Company acts as a data controller with respect to personal data collected through the Website.
1.2 The Company operates as an umbrella organizational entity overseeing multiple divisions and may process data in connection with:
- Business inquiries
- Workforce-related interactions
- Operational and consulting engagements
- General communications
1.3 Where services are provided through separate entities or divisions, such entities may act as independent controllers or processors pursuant to separate agreements.
2. CATEGORIES OF PERSONAL DATA COLLECTED
The Company may collect and process the following categories of personal data:
2.1 Information Provided Directly by Users
- (a) Full name
- (b) Email address
- (c) Telephone number
- (d) Company or organization details
- (e) Job role, qualifications, or professional information
- (f) Any information voluntarily submitted through forms or communications
2.2 Automatically Collected Information
- (a) IP address
- (b) Device type and browser information
- (c) Usage data and interaction logs
- (d) Cookies and tracking identifiers
2.3 Sensitive or Healthcare-Related Information
The Website is not intended to collect Protected Health Information (“PHI”). However, if Users voluntarily submit health-related or sensitive information:
- Such data shall be treated with heightened safeguards
- Processing shall be limited to the purpose for which it was provided
3. PURPOSES OF PROCESSING
The Company processes personal data for the following lawful purposes:
- (a) Responding to inquiries and communications
- (b) Evaluating potential business relationships or service engagements
- (c) Recruitment, screening, and workforce evaluation
- (d) Internal analytics, operational improvement, and system optimization
- (e) Compliance with legal and regulatory obligations
- (f) Protection of Company rights, systems, and security
Under applicable laws, personal data must be collected and used only for specific, legitimate purposes and not in a manner incompatible with those purposes.
4. LEGAL BASIS FOR PROCESSING (GDPR)
Where the General Data Protection Regulation (“GDPR”) applies, the Company processes personal data on the following bases:
- (a) Consent — where you have explicitly provided consent
- (b) Legitimate Interests — including business development, operational management, and service improvement
- (c) Contractual Necessity — where processing is required prior to entering into a contractual relationship
- (d) Legal Obligations — where processing is required to comply with applicable laws
GDPR requires organizations to clearly identify the controller and disclose processing practices to ensure transparency.
5. DISCLOSURE AND SHARING OF INFORMATION
5.1 The Company may disclose personal data to:
- (a) Affiliates, subsidiaries, and divisions within the H& ecosystem
- (b) Service providers, contractors, and vendors
- (c) Legal, regulatory, or governmental authorities where required
- (d) Professional advisors (legal, financial, compliance)
5.2 The Company does not sell personal data.
5.3 All disclosures are limited to what is reasonably necessary for legitimate business or legal purposes.
5.4 Inter-Entity Data Sharing Within Organizational Ecosystem
5.4.1 The Company operates as part of an integrated organizational ecosystem comprising affiliated entities, divisions, and operational units under Health & Group.
5.4.2 Personal data may be shared, transferred, or made accessible between such affiliated entities where necessary for legitimate business purposes, including but not limited to:
- (a) service coordination across divisions;
- (b) workforce, operational, or administrative alignment;
- (c) internal analytics, system integration, and process optimization; and
- (d) compliance, risk management, and security functions.
5.4.3 Such data sharing shall be limited to what is reasonably necessary and shall remain subject to appropriate safeguards and applicable data protection laws.
6. INTERNATIONAL DATA TRANSFERS
6.1 The Company operates internationally and may transfer personal data across jurisdictions, including outside the European Economic Area (EEA).
6.2 Where required, such transfers shall be subject to appropriate safeguards, including:
- (a) Standard contractual clauses;
- (b) Adequacy decisions; or
- (c) Equivalent lawful mechanisms
GDPR applies to U.S. companies where EU personal data is processed, regardless of company location.
7. DATA RETENTION
7.1 Personal data shall be retained only for as long as necessary to:
- (a) Fulfill the purposes outlined in this Policy;
- (b) Comply with legal obligations;
- (c) Resolve disputes and enforce agreements
7.2 The Company reserves the right to retain anonymized or aggregated data indefinitely.
8. DATA SECURITY
8.1 The Company implements commercially reasonable administrative, technical, and organizational safeguards designed to protect personal data.
8.2 Such measures may include:
- (a) Access controls
- (b) Encryption and secure storage
- (c) System monitoring and audit protocols
8.3 Notwithstanding the foregoing, no system can be guaranteed to be completely secure.
9. HIPAA-ADJACENT POSITIONING
9.1 The Company is not a healthcare provider and is not, by default, a “covered entity” under the Health Insurance Portability and Accountability Act (“HIPAA”).
9.2 However, to the extent that any data processed may constitute health-related information:
- (a) The Company applies safeguards aligned with industry standards for protecting sensitive information;
- (b) Access to such data is restricted;
- (c) Use and disclosure are limited to defined operational purposes
9.3 HIPAA establishes national standards governing the use and disclosure of protected health information and requires transparency regarding such practices.
9.4 Any HIPAA-regulated activities, where applicable, are conducted exclusively through separate legal entities or contractual frameworks.
10. USER RIGHTS
10.1 GDPR Rights (EU Users)
Where applicable, you have the right to:
- (a) Access your personal data
- (b) Rectify inaccurate or incomplete data
- (c) Request erasure (“right to be forgotten”)
- (d) Restrict processing
- (e) Object to processing
- (f) Data portability
- (g) Withdraw consent at any time
10.2 U.S. Privacy Rights
Depending on jurisdiction, you may have the right to:
- (a) Know what personal data is collected
- (b) Access such data
- (c) Request deletion
- (d) Opt out of certain processing activities
U.S. privacy frameworks increasingly require transparency regarding data collection and sharing practices.
11. COOKIES AND TRACKING TECHNOLOGIES
11.1 The Website may use cookies and similar tracking technologies to:
- (a) Enhance user experience
- (b) Analyze Website performance
- (c) Maintain session functionality
11.2 Where required by law, Users shall be provided with the option to accept or reject non-essential cookies.
11.3 Cross-Domain and Cross-Platform Tracking
11.3.1 The Company may operate multiple websites, subdomains, or digital platforms within its ecosystem.
11.3.2 Where Users interact with more than one such platform, the Company may associate, correlate, or combine usage data, identifiers, or interaction patterns across domains for purposes including:
- (a) maintaining continuity of user experience;
- (b) improving system functionality and integration;
- (c) analytics and performance optimization; and
- (d) security and fraud prevention.
11.3.3 Any such cross-platform data processing shall be conducted in accordance with this Policy and applicable laws.
12. THIRD-PARTY SERVICES
12.1 The Website may utilize third-party services, including analytics, communication tools, or hosting providers.
12.2 The Company is not responsible for the privacy practices of such third parties.
12.3 Users are encouraged to review applicable third-party privacy policies.
13. CHILDREN’S PRIVACY
The Website is not directed toward individuals under the age of eighteen (18), and the Company does not knowingly collect personal data from minors.
14. POLICY MODIFICATIONS
14.1 The Company reserves the right to modify this Policy at any time.
14.2 Any changes shall become effective upon posting.
14.3 Continued use of the Website constitutes acceptance of the revised Policy.
15. CONTACT AND DATA REQUESTS
For privacy-related inquiries or to exercise your rights:
Email: legal@healthandgroup.com
Phone: +1 (833) 377-2526
16. GOVERNING LAW
This Policy shall be governed by the laws of the State of Florida, United States, without regard to conflict of law principles.
17. INTERPRETATION
This Policy shall be interpreted in a manner consistent with applicable data protection laws, including GDPR, U.S. privacy laws, and relevant regulatory frameworks.

