Privacy Policy
Effective Date: February 1, 2026
Sunrise Medical (US) LLC ("Sunrise," "we," "us," or "our") respects your privacy and is committed to protective personal information. This Privacy Notice explains how we collect, use, disclose, and protect personal information in connection with our business-to-business operations, websites, products, and services.
This Notice applies to customers, business partners, website vendors, dealers, distributors, healthcare professionals, and other individuals whose information we process.
For the purpose of federal and state laws of the United States, the Controller is Sunrise Medical (US) LLC. We have business locations at:
- 1855 South 57th Court, Suite 200, Boulder, CO 80301
- 12002 Volunteer Boulevard, Mt. Juliet, TN 37122
- 2842 N Business Park Avenue, Fresno, CA 93727
Scope and Applicability
This Privacy Notice is designed to comply with applicable U.S. federal and state privacy laws, including but not limited to:
- California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
- Tennessee Information Protection Act (TIPA)
- Colorado Privacy Act (CPA)
- Virginia Consumer Data Protection Act (VCDPA)
- Connecticut Data Privacy Act (CTDPA)
- Utah Consumer Privacy Act (UCPA)
- Texas Data Privacy and Security Act (TDPSA)
- Oregon Consumer Privacy Act (OCPA)
- Nevada Privacy Law
- New York SHIELD Act
- Massachusetts 201 CMR 17.00
- Federal Trade Commission Act
- Children's Online Privacy Protection Act (COPPA)
- FTC Health Breach Notification Rule
- Illinois Biometric Information Privacy Act (BIPA)
- Washington My Health My Data Act
This Notice applies to both consumer and business-to-business (B2B) personal information.
Information We Collect
Personal Information
We may collect the following categories of personal information:
- Identifiers: name, company name, job title, postal address, email address, telephone number, IP address
- Commercial Information: transaction records, products purchased, service history
- Financial Information: payment details, credit references
- Professional Information: employer, business role, licensing information
- Technical Information: browser type, device data, cookies, log data
- Communication: emails, call recordings, inquiries, feedback
Sensitive Personal Information
We may collect limited sensitive personal information, including:
- Health and disability-related information
- Medical device usage information
- Biometric identifiers or biometric information (if voluntarily provided)
- Accessibility-related data
- Precise geolocation (if enabled)
Sensitive personal information is processed only with explicit consent when required, or as otherwise permitted by law. Individuals may withdraw consent at any time.
Minors' Information
Our services are not directed to children under 13. We do not knowingly collect personal information from children without verified parental consent in accordance with COPPA. Parents or legal guardians may contact us to review, correct, or delete a child's information.
Sources of Information
We collect personal information from:
- Individuals directly
- Authorized representatives
- Dealers and distributors
- Business partners
- Service providers
- Public sources
- Automated technologies
How We Use Personal Information
We use personal information for the following purposes:
- Providing products and services
- Managing accounts and contracts
- Processing payments
- Customer support
- Training and education
- Product registration
- Warranty management
- Regulatory compliance
- Quality assurance
- Research and development
- Marketing and advertising (subject to opt-out)
- Security and fraud prevention
- Business operations and analytics
- Risk assessments and compliance auditing
We limit processing to what is necessary, proportionate, and relevant for legitmate business purposes.
Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Website functionality
- Performance analytics
- Security
- Advertising
- Preference management
You may manage cookie preferences through browser settings and our cookie management tool.
We honor Global Privacy Center (GPC) and other universal opt-out signals where required by law.
Targeted Advertising and Data Sharing
We may use third-party partners for advertising and analytics. These activities may constitue "sharing" under certain state laws.
You may opt out of targeting advertising and data sharing by:
We do not sell personal information for monetary consideration.
Disclosure of Personal Information
We may disclose information to:
- Affiliates and subsidiaries
- Service providers and vendors
- Logistics and payment partners
- Analytics providers
- Advertising partners
- Professional advisors
- Government authorities and regulators
- Successor entities in corporate transactions
All disclosures are governed by contractual and legal safeguards.
Health and Medical Information
Certain information we collect may constitue health-related or consumer health data.
We process such data only for:
- Product support, customization, and safety
- Clinical, regulatory, and quality compliance
- Warranty and service management
- Lawful business operations
Where required, we obtain explicit consent before processing health data.
If Sunrise acts as a business associate under the Health Insurance Portability and Accountability Act (HIPAA), we comply with all applicable HIPAA requirements and maintain appropriate Business Associate Agreements.
Individuals may request access to, correction of, or deletion of health-related information, subject to legal limitations.
Biometric Information
Where permitted by law, we may collect biometric identifiers or biometric information for accessibility or security purposes.
We will:
- Obtain written consent before collection where required
- Use biometric data only for disclosed purposes
- Store biometric data securely
- Permanently destroy biometric data when the original purpose has been satisfied or within three (3) years of last interaction, whichever comes first
We do not sell, lease, or profit from biometric information.
Data Retention
We retain personal information according to the following schedule, unless longer retention is required by law:
| Category |
Retention Period |
| Account Records |
Contract Term + 7 Years |
| Transation Data |
6 Years |
| Marketing Records |
Until Opt-Out + 3 Years |
| Technical Logs |
2 Years |
| Health-Related Data |
Service Term + 7 Years |
| Legal Records |
As Required |
Data is securely deleted or anonymized when no longer required.
Information Security
We maintain a comprehensive written information security program that includes:
- Administrative safeguards
- Technical safeguards
- Physical safeguards
- Regular risk assessments
- Employee training
- Vendor due diligence and audits
- Incident response planning
- Encryption and access controls
Our program is aligned with recognized industry standards such as NIST and ISO frameworks. Despite our best efforts, no system is completely secure.
Data Breach Notification
In the event of a security incident involving personal information, we will:
- Investigate promptly
- Mitigate harm
- Notify affected individuals
- Notify regulators where required
- Provide legally required remediation services
Notifications will be made in accordance with applicable federal and state laws.
Your Privacy Rights
Depending on your state of residence, you may have the right to:
- Access personal information
- Correct inaccurate information
- Delete personal information
- Obtain a portable copy
- Opt out of targeting advertising
- Limit use of sensitive data
- Opt out of profiling in furtherance of significant decisions
- Withdraw consent
- Appeal denied requests
- Use authorized agents
We will not discriminate against you for exercising your rights.
How to Exercise Your Rights
You may submit requests by:
We will verify your identity and respond within forty-five (45) days, with extensions as permitted by law.
Appeals may be submitted using the same contact methods.
California Privacy Notice
California residents have additional rights, including:
- Right to Know
- Right to Delete
- Right to Correct
- Right to Opt Out of Sharing
- Right to Limit Sensitive Information
We honor GPC signals as opt-out requests.
Do Not Sell or Share: https://www.sunrisemedical.com/policies/privacy-policy
Limit Use of Sensitive Data: https://www.sunrisemedical.com/policies/privacy-policy
Children's Privacy (COPPA)
We comply with COPPA when collective personal information from children under 13.
Parental rights include:
- Reviewing collected information
- Revoking consent
- Requesting deletion
- Prohibiting further collection
Parents may exercise these rights by contacting us using the information below.
Third-Party Websites
Our websites may link to third-party sites. We are not responsible for their privacy practices.
Changes to This Notice
We may update this Notice periodically. Material changes will be communicated as required by law.
Contact Information
Sunrise Medical (US) LLC, 1855 South 57th Court, Suite 200, Boulder, CO 80301
12002 Volunteer Boulevard, Mt. Juliet, TN 37122
2842 N Business Park Avenue, Fresno, CA 93727
Email: ChiefPrivacyOfficer@sunmed.com
Phone: 1-800-333-4000