Privacy Policy
Current website scope. This policy applies to Inlumia's current public website and waitlist/interest-registration activities. The public Website is intended for general information and communications, not for medical intake or submission of health records or other clinical information. If Inlumia later offers secure patient intake or clinical services through the Website, additional privacy notices, terms, authorizations, or consents may apply.
Inlumia, LLC ("Inlumia," "we," "us," or "our") respects your privacy and is committed to protecting personal information collected through our website and other online services that link to this policy (collectively, the "Website"). This policy explains the information we collect, how we use and disclose it, how we retain and protect it, and choices that may be available to you.
Health information and HIPAA. Information collected in connection with providing health care may be protected health information ("PHI") under HIPAA and may also be protected by federal or state law. Inlumia's Notice of Privacy Practices describes how we use and disclose PHI. If this Website Privacy Policy conflicts with the Notice of Privacy Practices with respect to PHI, the Notice of Privacy Practices and applicable law control.
1. Summary of Our Website Data Practices
The table below summarizes the main categories of personal information that may be collected through the current Website.
2. Information We Collect
Information you provide
We may collect your name, email address, telephone number, mailing address, general location, waitlist status, appointment or consultation request information, communications, preferences, and other information you choose to provide. Information submitted in connection with requesting or receiving health care may constitute PHI or medical information protected by law.
Information collected automatically
Depending on the Website configuration and your choices, technical information may include IP address, browser and device information, operating system, pages viewed, referring or exit pages, dates and times of access, approximate geographic location derived from an IP address, general interaction data, cookie identifiers, pixels, local storage, and similar technology information. Health-related browsing activity, appointment requests, form entries, URLs, search terms, chat content, or other online activity may be sensitive and, depending on context, may constitute PHI or medical information.
3. Health and Medical Information
Do not submit medical records, diagnoses, symptoms, medications, genetic information, imaging results, insurance information, or other sensitive health information through the public Website, general inquiry forms, or ordinary email unless Inlumia specifically directs you to an approved secure channel for that purpose. Information you provide in connection with requesting or receiving health care will be handled in accordance with applicable law and our Notice of Privacy Practices.
4. How We Use Information
• Register and manage interest in Inlumia services, including a waitlist.
• Respond to inquiries and provide information about Inlumia services.
• Process appointment or consultation requests and communicate with prospective and existing patients.
• Provide requested services and administer patient relationships.
• Communicate about service availability, launches, events, or other updates, subject to applicable consent and opt-out requirements.
• Operate, secure, troubleshoot, maintain, and improve the Website.
• Understand Website use and evaluate the effectiveness of communications and marketing.
• Prevent fraud, misuse, security incidents, or unlawful activity.
• Maintain appropriate records and comply with legal and regulatory obligations.
• For other purposes disclosed when information is collected or with your consent.
5. Cookies, Analytics, Tracking, Session Replay, and Similar Technologies
The Website may use cookies, pixels, local storage, analytics tools, and similar technologies that are strictly necessary for functionality and security. Optional analytics or similar technologies may be used only in accordance with applicable law and Inlumia's privacy and security requirements.
Inlumia does not knowingly permit advertising, analytics, social-media, session-replay, chat, call-tracking, or similar third-party technologies to collect or receive PHI unless the collection or disclosure is permitted by applicable law and all required safeguards, agreements, consents, or authorizations are in place. A cookie banner, general privacy-policy disclosure, or continued use of the Website is not treated as a HIPAA authorization to disclose PHI.
Where applicable law requires prior consent for optional tracking, recording, or interception technologies, Inlumia intends to obtain the required consent before activating those technologies. Inlumia may provide controls such as Accept, Reject, or Manage Preferences. Browser settings may also allow cookie controls. Strictly necessary technologies may operate without optional-cookie consent where permitted by law. Because Website technologies may change, Inlumia periodically reviews cookies, analytics tools, and third-party integrations and updates this policy or related controls as appropriate.
6. Website Chat, Forms, and Electronic Interactions
Website chat, AI-enabled chat, appointment forms, keystroke or form-monitoring tools, session-replay technologies, and similar tools may capture the substance of communications. Inlumia will evaluate such tools before deployment and will use them only with appropriate privacy, security, contractual, and consent controls. Sensitive medical information should be submitted only through channels designated by Inlumia for that purpose.
7. How We Share Information and Vendor Safeguards
We may disclose personal information to service providers supporting website hosting, information technology, cybersecurity, communications, CRM, appointment scheduling, form processing, data storage, analytics, and professional or compliance services. Inlumia evaluates vendors, as applicable, for HIPAA obligations, state medical-information confidentiality, data-security requirements, and applicable interception or recording laws.
• Professional advisers. We may disclose information to lawyers, accountants, auditors, insurers, or other professional advisers where reasonably necessary.
• Legal and safety purposes. We may disclose information when reasonably necessary to comply with law, legal process, or governmental requests; protect rights, safety, or property; investigate misuse; or address security incidents.
7. How We Share Information and Vendor Safeguards (continued)
• Business transactions. Information may be disclosed in connection with a merger, financing, acquisition, reorganization, sale of assets, or similar corporate transaction, subject to applicable law.
• With your direction or consent. We may disclose information when you direct us to do so or provide consent.
When a vendor creates, receives, maintains, or transmits PHI on Inlumia's behalf and qualifies as a business associate, Inlumia will require an appropriate Business Associate Agreement when required by HIPAA. A Business Associate Agreement does not replace other consent, authorization, privacy, security, or state-law requirements that may apply.
8. Sale, Sharing, Advertising, and Marketing
Inlumia does not sell PHI. Inlumia does not sell personal information collected through the Website for monetary consideration. Some state privacy laws define “sale,” “sharing,” or “targeted advertising” more broadly and may treat certain disclosures involving advertising or analytics technologies as regulated activities even when no money changes hands.
If Inlumia uses technologies that trigger an opt-out right under applicable law, we will provide the required mechanism, such as a “Do Not Sell or Share My Personal Information” or similar privacy-choice link, and will honor legally recognized browser-based opt-out signals where required. Inlumia will not use or disclose PHI for marketing or other purposes requiring HIPAA authorization unless a valid authorization has been obtained, and will comply with applicable state restrictions on medical information.
9. Email, Text Messages, Telephone Calls, and Recording
If you provide an email address or telephone number, we may use it to respond to you and communicate as permitted by law. Standard email and SMS may not always be secure; avoid sending sensitive medical information through unsecured channels unless specifically instructed.
If Inlumia records or uses technology to intercept a telephone, audio, oral, or electronic communication, Inlumia will provide notice and obtain consent when required by applicable law. For communications subject to all-party-consent requirements, recording or interception should begin only after legally sufficient notice and consent have been provided.
Marketing or promotional emails will include applicable unsubscribe methods. If text messaging is used for promotional communications, Inlumia will obtain consent and provide opt-out instructions as required by law. Consent to receive marketing communications is not a condition of purchasing services unless expressly permitted by law.
10. Florida Privacy and Communications Protections
For Florida patients and communications subject to Florida law, Inlumia will maintain the confidentiality of patient medical records and information in accordance with applicable Florida law, including Florida Statutes section 456.057 and other applicable confidentiality requirements. Where Florida law provides greater privacy protection than HIPAA, Inlumia will follow the more protective requirement.
Florida law may require prior consent of all parties before certain wire, oral, or electronic communications are intercepted or recorded. Inlumia will use recording, session-replay, chat, call-tracking, and similar technologies in a manner designed to comply with applicable Florida consent requirements.
11. California Privacy and Medical-Information Protections
When California law applies, Inlumia will use and disclose medical information in accordance with the California Confidentiality of Medical Information Act (CMIA) and other applicable California confidentiality laws. Where California law provides greater privacy protection than HIPAA, Inlumia will follow the more protective requirement.
California law may impose consent requirements on certain interceptions or recordings of communications. Inlumia will use recording, session-replay, chat, call-tracking, and similar technologies in a manner designed to comply with applicable California consent requirements. Certain California privacy statutes contain exemptions or limitations for PHI, medical information, and certain information maintained by health care providers; those exemptions do not necessarily apply to every category of Website information.
12. Data Security
We maintain reasonable administrative, technical, physical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Measures may include access controls, encryption where appropriate, security monitoring, vendor controls, and safeguards appropriate to the nature of the information. When electronic PHI is involved, safeguards are designed to address applicable HIPAA Security Rule requirements. No website, network, transmission, storage system, or other electronic system can be guaranteed completely secure.
13. Data Retention
We retain personal information for as long as reasonably necessary for the purposes collected, including to manage waitlist and communications, maintain business and security records, satisfy legal, regulatory, contractual, accounting, reporting, dispute-resolution, and legitimate business requirements, and enforce agreements. Retention periods may vary based on the type of information and relationship. When personal information is no longer reasonably necessary, we may delete, de-identify, or securely dispose of it, subject to applicable legal and recordkeeping obligations. Medical records and PHI are retained in accordance with applicable requirements and Inlumia policies.
14. Third-Party Links
The Website may link to third-party websites or services. Inlumia is not responsible for the privacy, security, content, or practices of websites that it does not operate or control. Review third-party privacy notices before providing information.
15. Children and Minors
The public Website is not directed to children under 13, and Inlumia does not knowingly collect personal information online from children under 13. If you believe a child under 13 has provided personal information through the Website, contact us so we can review and, where appropriate, delete it. Health information involving minors will be handled in accordance with applicable federal and state law concerning minors, parents, guardians, and personal representatives.
16. International Visitors
Inlumia is based in the United States. If you access the Website from outside the United States, your personal information may be transferred to, stored in, or processed in the United States or other jurisdictions where service providers operate. Privacy laws in those jurisdictions may differ from those in your country of residence. Where applicable law provides additional rights or requires a legal basis, consent, contractual safeguards, or other measures for processing or transferring personal information, Inlumia will take appropriate steps based on the relevant circumstances.
17. Your Privacy Choices and Rights
Depending on where you live, the information involved, and applicable exceptions, you may have rights concerning your personal information, including rights to:
• Request access to or confirmation of personal information we maintain about you.
• Request correction of inaccurate personal information.
• Request deletion of certain personal information.
• Receive a copy of certain personal information in a portable format.
• Opt out of certain sales, sharing, targeted advertising, or profiling activities, where applicable.
• Limit certain uses or disclosures of sensitive personal information, where applicable.
• Withdraw consent where processing is based on consent, subject to applicable law.
• Appeal certain decisions regarding a privacy request, where applicable.
• Exercise privacy rights without unlawful discrimination.
To submit a Website privacy request, contact info@inlumia.com. We may need to verify your identity before completing certain requests. You may also use an authorized agent where permitted by law, subject to verification requirements.
Rights concerning PHI are described in Inlumia's Notice of Privacy Practices, including rights to access, request amendment, request restrictions or confidential communications, receive an accounting of certain disclosures, obtain a copy of the notice, and file a privacy complaint.
18. Changes to This Policy
We may update this policy to reflect changes in our practices, technology, services, or legal requirements. We will update the Last Updated date and provide additional notice or obtain consent when appropriate or required.
19. Contact Us
Inlumia, LLC
5041 W. Cypress St., Tampa, Florida 33609
Privacy Officer: Heather Oliveira
Email: info@inlumia.com | Phone: 813.540.7044
Important: This Website Privacy Policy does not replace Inlumia's HIPAA Notice of Privacy Practices, patient authorizations, consents, or other documents required by law. Compliance also depends on Inlumia's actual website configuration, vendor contracts, consent mechanisms, and operational practices.
Website Form Notice
For use directly beneath the current waitlist or general inquiry form:
Privacy Notice: Please do not submit medical information, symptoms, diagnoses, medications, genetic information, medical records, or other sensitive health information through this form. This form is intended only for general inquiries and waitlist registration. By submitting the form, you agree that Inlumia may use the information you provide to respond to you and provide requested updates about Inlumia services. Please review our Privacy Policy for additional information about how we collect, use, and protect personal information.