The HIPAA boundary
NUYU's public website is deliberately not a clinical system. Anything you submit through this site, whether contact form messages, newsletter signups, or quiz answers, is treated as a general business inquiry. We don't ask for, and you should not provide, any medical information here.
All Protected Health Information (PHI), including medical history, allergies, current medications, symptoms, treatment notes, and consent forms, lives inside JaneApp, our HIPAA-compliant scheduling and clinical platform. JaneApp has its own privacy notice; once you book, that notice governs your clinical record.
This policy covers what happens on this website only. If you have a question about your clinical record, contact us and we'll point you to the right place.
What we collect
We collect a small amount of information, only when you give it to us:
- Contact form submissions: the name, email, phone (optional), topic, and message you choose to provide.
- Newsletter signups: the email address you provide.
- Cookies: a small number of cookies that keep the site running and let us measure aggregated traffic. Details in the cookies section below.
- Server logs: automatic technical data such as IP address, browser type, and pages visited, used to keep the site running and secure.
We don't run advertising trackers, third-party social pixels, or fingerprinting scripts on this site.
How we use it
We use the information you provide to:
- Respond to your inquiry or message
- Send you the newsletter you signed up for. You can unsubscribe at any time
- Operate, secure, and improve this website
- Comply with applicable law
We never sell, rent, or share your information with third parties for marketing.
Service providers we rely on
We use a small number of standard service providers to keep the site running. Each operates under its own privacy practices and a data-processing agreement with us:
- A web hosting provider for the website and serverless functions.
- A database provider for storing contact-form submissions (encrypted at rest).
- A transactional email provider for auto-replies and newsletters.
- A HIPAA-compliant clinical scheduling platform that handles all booking, intake, and PHI, entirely separate from this website.
- Standard web-font providers for the typefaces this site uses.
We do not use advertising networks, marketing trackers, or data brokers. For the specific names of our current providers, email hello@nuyuiv.com and we'll share them.
How long we keep it
Contact form submissions and newsletter signups are kept as long as we have an active business relationship with you, or until you ask us to delete them. Server logs are kept for up to 30 days. Cookies are kept as set by your browser (sessional cookies disappear when you close the tab; persistent cookies last up to 12 months unless you clear them sooner).
Your rights
Depending on where you live, you may have the right to:
- Request a copy of the information we have about you
- Ask us to correct or delete it
- Opt out of any marketing communications
- Withdraw consent for analytics cookies
To exercise any of these, email us at hello@nuyuiv.com and we'll respond within 30 days.
Children
NUYU's services are for adults. This website is not directed to children under 18, and we don't knowingly collect information from anyone under 18.
Changes to this policy
We may update this policy as our practices evolve. We'll change the "last updated" date at the top of the page, and for any meaningful change we'll post a notice on the home page.
Contact
Questions about this policy? Email hello@nuyuiv.com or write to NUYU Wellness LLC, Lancaster, PA. We answer every message ourselves.