Privacy Policy
Effective date: January 20, 2026At Expa (a service of Expanential Inc., also referred to as "we", "us" or "our"), we are committed to protecting the privacy and security of personal information. This Privacy Policy explains how we collect, use, disclose and safeguard the personal information of users of our website domain expahealth.com ("Site"), mobile application ("App"), and associated services (collectively, the "Services").
By using our Site, App or Services, you agree to the collection, use and disclosure of your personal information as described in this Privacy Policy. If you do not agree, please discontinue use of our Services.
Information We Collect
We collect personal information from you directly, automatically when you interact with our Services, and from third-party sources including government entities and public records databases.
Information Provided Directly
- Registration data like name, email, phone number, username, password when creating an account
- Profile data like resume, work experience, licenses, certifications for clinicians
- Contact details and communications when you contact us for support
- Payment information for purchases or premium services
- Content you post on community forums or submit for courses
Automatically Collected Data
- Usage data like browser type, IP address, pages visited, time spent
- Approximate location data derived from your IP address
- Cookie data and online identifiers
- Interaction data with our website, app, and digital channels
- Messaging data: When you communicate with us via third-party messaging platforms (such as WhatsApp), we collect your phone number, the content of your messages, and the timestamp of each interaction
Data From Third Parties
- Public records data about clinician licenses and certifications from government entities
- Data from references or employers identified by clinicians
- Social media profile data if you login via a social account
- Data from analytics partners that help us understand website and application engagement (these partners do not receive WhatsApp message content or metadata)
How We Use Information
We use the information we collect for the following purposes:
- Providing our Services and facilitating matching of clinicians with employers
- Processing transactions and customer support
- Personalizing content and experiences
- Marketing and advertising our offerings (we do not use WhatsApp message content to build advertising profiles or target ads; if we send marketing messages on WhatsApp, we do so only with required opt-in and honor opt-out requests)
- Research, product development and improvement
- Legal compliance and protecting rights and safety
- Identifying and evaluating potential job candidates for our customers through analysis of interactions with our owned channels (website, app, agents)
- Building profiles of users who engage with our Services to better match candidates with employment opportunities
- Sending you job alerts, interview confirmations, application updates, and support messages via SMS, email, or instant messaging platforms (such as WhatsApp), subject to your consent where required
- As otherwise disclosed at the time of collection
We may anonymize or aggregate data, which we may use and share for analytics, research, and service improvement purposes.
Candidate Identification and Matching
We use third-party services to analyze how users interact with our website, app, and other digital channels. This analysis helps us identify individuals who may be suitable job candidates for our customers. This process involves:
- Tracking user engagement across our owned digital channels
- Creating profiles based on interaction patterns and submitted information
- Using algorithms to match potential candidates with employment opportunities
- Sharing anonymized or aggregated candidate data with our customers
This candidate identification process uses interactions with our owned web and app channels only. It does not rely on WhatsApp message content for profiling or candidate matching purposes.
Sharing and Disclosure
We are committed to protecting your privacy and personal information. We share personal information in the following limited circumstances:
- With service providers that assist in operating our Services, including cloud hosting providers and communication platforms (such as Meta/WhatsApp) that facilitate message delivery on your behalf
- With third-party analytics and candidate identification services that help us match job candidates with employers (these services do not receive WhatsApp message content or metadata)
- In corporate transactions like mergers or acquisitions
- To comply with legal requirements and protect rights and safety
- With consent or as otherwise disclosed at the time of collection
We do not share our users' names, email addresses, or mobile numbers with third parties or affiliates for their own marketing purposes. Furthermore, text messaging originator opt-in data and consent will not be shared with any third parties. We may share mobile numbers with communication service providers (such as WhatsApp) solely for the purpose of delivering messages you have requested or consented to receive. We do not share contact information with employers on our platform or recruiters unless the user explicitly consents to such sharing.
We do not sell personal information. We may share anonymized or aggregated data that cannot be used to identify individual users.
Your Choices and Rights
You can update your account details by logging in. Under the California Consumer Privacy Act (CCPA), California residents have the right to:
- Opt-out of sales of their personal information by us
- Request access to the personal information we have collected about them
- Request deletion of their personal information, subject to exceptions
- Not be discriminated against for exercising these rights
California residents may submit requests related to their CCPA rights by filling out the form or emailing [email protected]. We will verify requests before processing.
Most browsers provide options to restrict tracking technologies like cookies. Note this may impact some functionality.
You may unsubscribe from marketing emails using the link provided.
How to Request Data Deletion
You have the right to request deletion of your personal data. To submit a data deletion request, you can:
- Use our online form: Submit a Data Deletion Request
- Email us directly: Send your request to [email protected] with the subject line "Data Deletion Request"
We will respond to your request within 30 days and complete the deletion within 45 days, unless an exception applies under applicable law.
What We Delete Upon Request
Upon a valid deletion request, we will delete:
- Your account profile and registration data
- WhatsApp and messaging conversation transcripts
- Contact identifiers (phone numbers, email addresses) from active systems
- Message metadata and timestamps
- Any attachments or media you shared via messaging platforms
What We May Retain
We may retain certain data as required by law or for legitimate business purposes:
- Audit logs and transaction records required for legal compliance
- Billing and payment records as required by tax and accounting regulations
- Data necessary to resolve disputes or enforce our agreements
- Anonymized or aggregated data that cannot identify you
Social Media Login (Facebook, Google)
If you choose to connect or log in to our Services using a social media account such as Facebook or Google, we may receive certain information from that platform, including:
- Your public profile information (name, profile picture)
- Email address associated with your social media account
- Any other information you have made publicly available on that platform
We use this information solely for authentication and to create your account on our Services. We do not post to your social media accounts or access your friends list. We do not share your social media data with third parties except as described in this Privacy Policy.
Cookie Consent and Tracking Technologies
Our website uses cookies and similar tracking technologies to collect information about your browsing activities. We use this information to improve our Services, personalize your experience, and identify potential job candidates. You can manage your cookie preferences through our Cookie Consent Manager on our website.
WhatsApp and Messaging Communications
We use WhatsApp and other messaging platforms to communicate with you about our Services. This section explains how we handle data related to these communications.
Data We Process
When you communicate with us via WhatsApp or similar messaging platforms, we process:
- Your phone number
- Messages you send to us and messages we send to you
- Message timestamps and delivery status
- Any information you include in your messages (such as documents or images)
How We Use Messaging Data
We use messaging data solely for the following purposes:
- Providing customer support and responding to your inquiries
- Sending account notifications and service updates
- Delivering job alerts, interview confirmations, and recruiting communications you have requested or consented to
- Facilitating communication between clinicians and potential employers when authorized
We do not use WhatsApp-derived data for advertising targeting or candidate profiling. WhatsApp data is used only for delivering messages, providing customer support, and facilitating communications you have requested—not for candidate matching or targeting decisions.
Consent and Opt-Out
You may opt in to receive WhatsApp messages from us by:
- Providing your phone number through our website or app registration where the intention to receive WhatsApp communications is clearly disclosed
- Initiating a conversation with us on WhatsApp (which provides consent for us to respond and continue that conversation thread)
- Explicitly agreeing to receive messages during the job application process
You can opt out of WhatsApp communications at any time by:
- Replying "STOP" to any WhatsApp message from us
- Contacting us at [email protected]
Messaging Data Retention
We retain WhatsApp conversation records for as long as necessary to provide our Services, comply with legal obligations, and resolve disputes. Typically, messaging data is retained for up to 2 years after your last interaction, unless a longer retention period is required by law for compliance purposes. You may request deletion of your messaging data by contacting us at [email protected].
Data Retention and Security
We retain personal information for as long as necessary for our business purposes, subject to legal requirements. We use technical, administrative and physical security measures to protect the information we collect, including:
- Encryption in transit (TLS/HTTPS) for all data transmissions
- Encryption at rest for stored personal data
- Role-based access control (RBAC) with least-privilege principles
- Secure authentication and session management
- Logging and monitoring of system access and security events
- Incident response procedures for security breaches
- Secure key management and secrets storage
- Vendor and subprocessor security assessments
- Regular security reviews and updates
International Data Transfers
Your personal data may be transferred to and processed in the United States by our service providers, including cloud infrastructure and communication platforms. We ensure appropriate safeguards are in place through contractual data protection obligations with our processors that provide protections consistent with applicable privacy laws.
Third-Party Sites and Services
Our Services may link to third-party websites and services that have their own policies. We are not responsible for their privacy practices.
Children's Privacy
Our Services are not directed at children under 13 and we do not knowingly collect personal information from children under 13.
Updates
We may update this Policy from time to time by posting the revised version on our Site. Your continued use constitutes acceptance of the updated Policy. For significant changes, we will provide reasonable notice, such as through a website notice or email.
Contact Us
If you have any questions or concerns about this Policy or our data practices, please contact us at [email protected].