Privacy Policy
Contents of this Privacy Policy
- Introduction and scope
- Information we collect to serve you
- How information reaches our systems
- Uses that keep the platform calm and useful
- Lawful reasons we hold your data
- Sharing with partners we trust
- Cookies and reading signals
- Health and wellness data care
- Movement across borders
- How long we keep what you give us
- Safeguards and monitoring
- Privacy for Child Users
- Your rights and choices
- Notice for California Users
- Notice for other regions
- Links to other systems
- Changes to this policy
- How to reach our privacy team
1. Introduction and scope
Welcome to the Privacy Policy that Vital Rhythms Wellness LLC, a company established in the United States and operating from 8776 S Sunridge Dr, Sandy - 84093-7000, United States (US), provides for everyone who visits our website or uses the wellness technology services we design. This document explains in plain language what personal information we may collect, the reasons we collect it, how we keep it safe, and the control you hold over that data from beginning to end.
We developed this policy with the care we bring to every project in the VitalRhythms line of work. Our founder built the studio around a simple belief: technology that monitors health should respect the person behind the numbers. That belief shapes the rules below, and it shapes the software we ship every day.
Wherever this text refers to we, us or our, those words describe Vital Rhythms Wellness LLC. Where it refers to you or your, those words describe the visitor, the client, the practitioner or the patient who interacts with our website or with any system we craft on behalf of a wellness practice. Reading this policy takes only a few quiet minutes, and it explains far more than a legal form normally does.
2. Information we collect to serve you
We gather only the information that genuinely helps a health technology company serve you well. Nothing here exists for its own sake. The categories of information we may hold include the following.
- Contact details such as your full name, an email address and a telephone number you choose to share through a form, a booking request or a direct message.
- Company and role details when you represent a practice, a studio or a provider organization, including a workplace name, a job title and a professional license if you supply it voluntarily.
- Written inquiry content, including the subject line and message body of any note you send to ask@vitalrhythms.buzz.
- Service delivery details needed to run a project, such as billing contact information, project goals, staff names on your team and technical contact points.
- Technical data gathered automatically as you browse, including device type, operating system, browser, approximate region, pages viewed, actions taken and the duration of a visit.
- Wellness signals that reach us only when your practice asks us to build or host a health platform, including heart-rate summaries, activity totals, sleep duration and similar readings that you or your provider choose to route through our systems.
We never buy contact lists to fill our outreach, never seed our accounts with stranger data and never assume consent from silence. Every item listed above arrives in our care through an explicit action or through a clear configuration a practice already controls.
3. How information reaches our systems
Information flows into our environment through a handful of well-marked doorways. You hand us data directly when you complete a contact form, compose a consultation request, register for a demonstration or write us a message. That is the clearest and most respectful path, and we prefer it.
Data also reaches us when a wellness practice engages us under a written agreement to design, host or maintain a platform. In that role we act as the processor for the practice, and the practice remains the controller with the final word over the data life cycle.
Finally, a modest amount of browsing data arrives passively. Our web servers and analytics helpers see requests for pages, the type of device making them and the general region. That flow keeps the site healthy and helps us spot slow pages before they frustrate a visitor.
No channel collects anything without a described purpose. If an unexpected piece of data ever enters our environment, our team reviews it, decides on its usefulness and deletes it promptly when it has no value to the requested service.
4. Uses that keep the platform calm and useful
Personal information earns its place only when it supports a clear service goal. We use the information described above for a limited and legitimate set of purposes.
- To answer questions, prepare proposals, schedule demonstrations and manage the early conversations that begin every engagement.
- To design, build, refine and support the wellness platforms we deliver, including configuration, testing and security review.
- To send essential service communications such as confirmations, invoices, release notes and security alerts that you reasonably expect to receive.
- To improve our website through honest analysis of how visitors move through pages and which content helps people most.
- To detect and prevent misuse, abuse, fraud or technical threats that would put a visitor or a client at risk.
- To satisfy the legal, accounting and reporting duties that every responsible company carries.
We do not sell personal information, and we do not license wellness data to advertisers. A quiet signal in our company tells the whole story: the people we serve are never the product, and their health is never currency.
5. Lawful reasons we hold your data
Data protection law in many regions asks a company to name the reason it may lawfully process personal information. We rely on a short list of reasons chosen for honesty and fit.
Contract performance covers the requests and engagements you start with us. Legitimate interest covers website operation, issue prevention, communication related to an existing relationship and the modest analytics that keep our services dependable. Your consent, given freely and withdrawn freely, covers optional newsletter contact and any processing where no other basis applies. Legal obligation covers the retention and reporting duties that regulators set.
We weigh every new purpose against these bases before we start. If a planned activity does not fit a listed reason, we either reshape it or do not pursue it at all. That discipline is written into the design review process of the whole VitalRhythms team.
When you give consent, we record the fact of that consent together with the context around it. You may withdraw consent at any moment using one of the contact routes at the end of this policy, and withdrawal will not unravel an agreement already in progress.
8. Health and wellness data care
Some projects we build touch data that deserves extra tenderness, such as heart-rate history, sleep patterns or stress indicators. We treat that material as protected information even when the law does not force us to.
When we act for a practice, the practice defines the purposes and we support them faithfully. Our engineers encrypt wellness data while it rests and while it travels, restrict administrative access to named staff, and log the rare moments any record is touched. Retention windows are set to the minimum a clinical or billing need requires.
When a platform stores an especially sensitive field, it never appears in plain log files, never flows into support tickets and never surfaces in training data for any model. Personnel see real signals only when fixing an issue the practice has raised.
We publish honest statements about wellness data because we believe a patient deserves to know exactly where a reading travels and why. That transparency forms the backbone of every health integration contract we sign.
9. Movement across borders
Vital Rhythms Wellness LLC operates from the United States, and the servers that support our platforms may sit in data centers outside the country where you read this page. Moving data across borders is normal for modern technology, but it merits plain explanation.
Where a transfer reaches a region with its own data law, we put safeguards in place that keep protection at a consistent level. That may mean standard contractual terms, an adequacy finding by the relevant regulator or another mechanism the law recognizes.
We tell a practice where its data region sits before a project begins, and we do not quietly change the parking place of wellness data once it has a home. If a practice needs a data location policy, we document it in the service contract so there is never a surprise.
Your right to know and control your data travels with you across any border. A transfer never strips away the promises made in the first half of this document.
10. How long we keep what you give us
Retention is a promise measured, not hoarded. We keep personal information only as long as the purpose that justified collecting it still stands, plus the statutory window a record-keeping duty demands.
Contact and inquiry details are reviewed periodically and are archived or erased when a conversation concludes and no agreement follows. Project-related records remain available for the useful life of a client relationship and the retention periods set in the contract, after which deletion runs on a timetable.
Logs and technical monitoring data are scrubbed on rolling cycles so that access evidence does not pile up without reason. Cookies and analytics stores follow voluntary expiration schedules.
At the end of any retention window our staff delete the data or transform it into an anonymous form that can no longer identify a person. We make that endpoint visible in contracts, because knowing a record will eventually rest is part of feeling safe.
11. Safeguards and monitoring
Protection begins with the character of our studio and continues through concrete technical measures. Our security program aligns with industry practice for companies that touch wellness signals.
We encrypt data in motion with modern transport security and encrypt resting data on the volumes that hold it. Access to production systems follows a least privilege rule, which means each person can reach only the parts their job needs. Every login to an internal system is recorded, and suspicious activity sounds an alert.
Our staff complete responsible handling training, and our vendors meet reviewable standards. We run routine checks for outdated components and known weaknesses in the projects we maintain.
No system is impenetrable, and we do not pretend otherwise. If a breach ever touches personal information, we will assess the harm, act to contain it and inform affected parties and authorities as the law requires, without delay designed to soften the message.
12. Privacy for Child Users
Our website and the standard services we offer are directed at adults, practitioners and business users. They are not built for young children, and they do not collect personal information from children with knowledge of their age.
Where the law sets an age of consent, we expect supervisory adults to decide which tools a young person may use. A wellness platform that a practice runs is governed by that practices own rules and by the consent framework it maintains with families.
If we learn that we hold personal information from a child below the age of consent without proper permission, we will delete it promptly and review the channel that allowed it in. Parents or guardians who believe their child is involved with our site may contact us using the details at the end of this policy, and we will act quickly.
We apply the same restraint to family wellness data that we apply to our own home life: signals about a child are handled only under clear adult authority and only for the benefit of that child care.
13. Your rights and choices
Data protection is not a courtesy; it is a structure of rights you may exercise at any time. Depending on where you live, you may hold some or all of the following abilities.
- The right to know which of your personal information we hold and how we use it.
- The right to receive a portable copy of that information in a common format.
- The right to ask us to correct a detail that has become inaccurate.
- The right to ask us to erase data when the reason for keeping it has faded.
- The right to limit certain processing or to object to legitimate interest analysis.
- The right to withdraw consent given earlier for optional contact.
- The right to lodge a complaint with a data protection authority in your region.
To use any of these rights, write to ask@vitalrhythms.buzz. We verify your identity with reasonable checks before acting, and we respond within the window your law allows. We will not punish you for exercising a right, and we will keep the process simple.
14. Notice for California Users
Californians enjoy specific protections under state law, and we honor them for every visitor who requests them, wherever that person lives. The rules below summarize our posture.
Over the past year we have not sold personal information to any party, and we treat requests to be forgotten with full effect. California users may ask for a record of the categories of personal information we have collected about them, the categories of sources, the business reasons for collection and the categories of recipients with whom the data was shared.
You may also request deletion of personal information we hold about you, subject to the narrow exceptions the law describes. We will not discriminate against you for choosing to stay private, and the quality of our service will not change if you decline a marketing contact.
Authorized agents may submit requests on behalf of a California consumer when they provide proof of authority. We handle each request without confusion and provide a status update within the legal window.
15. Notice for other regions
Privacy expectations differ gently across the world, and we honor the higher standard where one applies. For people in the European Economic Area, the United Kingdom or Switzerland, the sections on consent, legitimate interest, erasure and complaints answer to those laws, and you may address a concern to our privacy team before approaching a supervisor.
Visitors in Australia, Canada, Japan, Brazil and other regions may rely on the general rights earlier in this document. We aim to exceed expectations rather than merely meet a jurisdiction and provide both a personal response and a practical fix whenever a concern is genuine.
Regional law changes quickly, so our staff review emerging rules and fold reasonable duties into our templates. That review keeps the overseas client experience steady and readable no matter which country hosts the practice.
16. Links to other systems
Our site and the platforms we ship sometimes link to outside systems, including payment services, mapping tools, wearable maker portals or external reference content. When you leave our environment, that destination sets its own rules.
We pick outside services with care and check the language of their privacy pages before we recommend them to a practice. Still, we do not control how a third party manages its corners, and this policy stops at the boundary of our own software.
We encourage you to glance at a destination privacy statement before you hand it sensitive data. A short pause to read costs little, and it keeps surprise to a minimum in the connected world where health tools live.
17. Changes to this policy
Policy language ages like any other craft, so we revisit this document whenever our practices, the law or the shape of our services change. When an update is meaningful, we mark a new effective date near the top and describe the shift in plain words where practical.
Material changes that touch how personal or wellness data is handled carry a visible notice on this site and, where we hold a working address, a direct note to the practices we serve. You have a chance to review before the new text governs activity.
Continuing to use this site after an effective date means you accept the version then in force. If you would rather not, you may end use at any time and ask us about ongoing records by writing to our privacy email.
18. How to reach our privacy team
Questions, requests and quiet concerns are welcome. The fastest route to a human answer is a message to ask@vitalrhythms.buzz, and our studio also answers the telephone at +15709735697 during the business hours listed on our contact page.
Postal correspondence may be directed to Privacy Team, Vital Rhythms Wellness LLC, 8776 S Sunridge Dr, Sandy - 84093-7000, United States (US). When you write, a short note about the topic helps us route your matter to the person who can act on it fastest.
We reply to every genuine request without charge and without delay. If you feel an issue is not resolved, a regulator in your region may accept the concern, and we will cooperate fully with any review. Thank you for trusting your health rhythm to our studio.