Privacy Policy
Ayureon, Inc. ("Ayureon, Inc.," "we," "us," or "our") is committed to protecting the privacy and security of your personal information and health information. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our services.
1. Who We Are
Ayureon, Inc. operates the Ayuva® healthcare interoperability platform and its associated websites, applications, and services accessed through ayureon.com. This includes online appointment scheduling pages that pharmacies and clinics offer to their patients under their own name, powered by Ayuva®.
Our role with your health information. When you book an appointment through an Ayuva®-powered scheduling page, the pharmacy or clinic named on that page is the healthcare provider (the HIPAA "covered entity"), and Ayureon, Inc. processes your information on its behalf as a HIPAA business associate under a written Business Associate Agreement. The provider's own Notice of Privacy Practices describes how it uses and discloses your health information; this Privacy Policy describes Ayureon, Inc.'s practices.
2. Information We Collect
2.1 Information You Provide
- Booking and demographic information: name, date of birth, sex, contact details (email, phone), and address, when you book an appointment.
- Health screening information: your answers to pre-appointment screening questions (for example, allergy and vaccination-history questions) and related notes you choose to provide.
- Consent records: the consent you sign during booking, including an integrity record (a cryptographic fingerprint of the exact consent text you signed and its version).
- Insurance information: where you choose to provide it during booking, your coverage details (such as plan and member ID, and Medicaid or Medicare identifiers where applicable).
- Guardian information: if you book for a minor, the guardian's identity, relationship, and consent.
- Communications: messages you send to our support channels.
2.2 Information Collected Automatically
- Device and usage data: IP address, browser type, device identifiers, and pages visited.
- Cookies and similar technologies: strictly necessary cookies for sessions, security (including bot protection), and authentication. See Section 8.
2.3 Information Processed for Healthcare Organizations
As an interoperability platform, we process clinical records (such as FHIR resources and clinical documents) on behalf of our healthcare organization customers and connected health information networks. This processing is governed by our agreements with those organizations, including Business Associate Agreements.
3. How We Use Your Information
- To provide scheduling services on behalf of your provider: booking, managing, and canceling appointments; presenting screening and consent steps; supporting check-in and administration workflows at the provider.
- Appointment communications: where enabled, sending booking confirmations and appointment reminders. We do not send marketing messages without your separate opt-in consent.
- Health information exchange: transmitting records to healthcare providers and public-health registries as directed by your provider and as described in the consent you sign.
- Platform safety and operations: security monitoring, audit logging, fraud and abuse prevention, and service improvement using de-identified or aggregate data.
- As required or permitted by law: responding to lawful requests, court orders, and regulatory obligations.
4. How We Share Your Information
Ayureon, Inc. does not sell your personal information or health information, and does not share it for cross-context behavioral advertising.
4.1 Your Healthcare Provider
Information you provide during booking is shared with the pharmacy or clinic you are booking with — that is the purpose of the service.
4.2 Service Providers (Subprocessors)
We use vetted service providers (such as cloud infrastructure) to deliver the platform. Service providers that process health information are bound by written agreements, including Business Associate Agreements, restricting their use of your information.
4.3 Health Information Networks and Registries
Where your provider participates and as reflected in the consent you sign, we transmit immunization and clinical records to providers involved in your care and to public-health registries, via networks such as eHealth Exchange.
4.4 Legal and Regulatory
We disclose information as required by federal or state law, including to regulators such as the U.S. Department of Health and Human Services.
5. Your Rights
5.1 Health Information (HIPAA)
Your HIPAA rights over records held by your healthcare provider — including access, amendment, an accounting of certain disclosures, restrictions, and confidential communications — are exercised with the provider, as described in its Notice of Privacy Practices. Ayureon, Inc. supports providers in fulfilling these requests. If you contact us directly, we will route your request to your provider and assist.
5.2 California Residents (CCPA/CPRA)
California residents have the right to know, delete, correct, and opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. Ayureon, Inc. does not sell or share personal information as defined by the CCPA/CPRA. Note that health information governed by HIPAA is exempt from the CCPA/CPRA and is handled under Section 5.1.
5.3 Other State Privacy Laws
Residents of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Texas, and Utah) have similar rights over personal information we hold as a business. Contact us at privacy@ayureon.com to exercise them.
6. Data Retention
We retain information as long as needed to provide services and meet legal obligations:
- Booking, screening, and consent records are retained on behalf of your healthcare provider for as long as our agreement with the provider and applicable law require — generally at least six years, and longer where state pharmacy record rules apply.
- HIPAA compliance documentation is retained for at least six years.
- Security and audit logs are retained for at least six years.
- On termination of our agreement with a provider, we return or destroy the provider's patient information in accordance with the Business Associate Agreement, except where law requires retention.
7. Data Security
- Encryption at rest (AES-256) and in transit (TLS 1.2+).
- Role-based access controls with minimum-necessary enforcement.
- Audit logging of access to health information.
- Documented incident response and breach notification procedures.
- Data is processed and stored in the United States.
No system is perfectly secure; we cannot guarantee absolute security, but we work to protect your information and to notify affected parties as required by law if a breach occurs.
8. Cookies and Tracking Technologies
- Strictly necessary cookies (session, security, authentication) are always active.
- We do not use advertising pixels or third-party marketing trackers on pages where health information is entered or displayed.
- We honor Global Privacy Control (GPC) signals.
9. Children's Privacy
Our services are not directed to children, and we do not knowingly collect information directly from anyone under 18. Appointments for minors may be booked by a parent or legal guardian where the healthcare provider's policies permit; in that case the guardian provides the minor's information and consent, subject to the eligibility rules shown during booking.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be posted prominently on our website with an updated effective date, and communicated by email where we have an appropriate address on file. Continued use of our services after the effective date constitutes acceptance.
11. Contact Us
Ayureon, Inc. 12117 FM 2244, Suite 180 Austin, TX 78738
Privacy inquiries: privacy@ayureon.com
Complaints: You may also file a complaint with the Office for Civil Rights, U.S. Department of Health and Human Services, 200 Independence Avenue SW, Washington, DC 20201 — hhs.gov/ocr/privacy/hipaa/complaints.