← Back to ilumeniq.com
Legal

Privacy Policy

Last updated: September 17, 2026

ilumenIQ LLC

1. Introduction and Scope

1.1 Who We Are. ilumenIQ LLC (“ilumenIQ,” “we,” “us,” or “our”) is a North Carolina limited liability company located at 1235 East Blvd, Suite E519, Charlotte, North Carolina 28203. We provide a software platform that helps group mental health and wellness practices understand the operational and financial performance of their practices.

1.2 What This Policy Covers. This Privacy Policy describes how we handle information in connection with (a) our marketing website at ilumeniq.com (the “Site”) and (b) our software platform (the “Platform,” and together with the Site, the “Services”). It applies to visitors to the Site, to individuals who request a demonstration or join our early access list, to the administrators and authorized users of our customers, and to the client and patient data we process on behalf of our customers.

1.3 Our Two Different Roles. We handle information in two distinct capacities, and different rules apply to each. As to information about Site visitors and about the individual administrators and users of the Platform, we act on our own behalf and this Privacy Policy governs. As to the client and patient data we receive from or on behalf of a customer practice, we act solely as a HIPAA business associate of that practice, and the Business Associate Agreement at Article 14 of our Master Subscription and License Agreement governs and controls over this Privacy Policy in the event of any conflict.

1.4 What This Policy Does Not Cover. This Privacy Policy does not govern the privacy practices of our customer practices with respect to their own clients and patients, the electronic health record, accounting, payroll, or other systems our customers use, or any third-party website linked from the Site. Clients and patients of a practice that uses ilumenIQ should direct privacy questions to that practice, which is the covered entity under HIPAA and which maintains its own Notice of Privacy Practices.

2. Information About Site Visitors and Platform Users

2.1 Information You Give Us. We collect information you provide when you contact us through the Site, request a demonstration, join our early access list, create an account, communicate with us by electronic mail or telephone, enter into an agreement with us, or respond to a survey or product research request. This may include your name, job title, practice or organization name, electronic mail address, telephone number, billing and payment information, and anything else you choose to tell us.

2.2 Information Collected Automatically on the Site. When you visit the Site, we and our analytics provider automatically collect your internet protocol address and approximate geographic location, browser type and version, operating system and device type, the pages you visit and the time you spend on them, referring addresses, the date and time of your visit, and standard web log data.

2.3 Information Collected Automatically on the Platform. When an authorized user accesses the Platform, we collect authentication and session data including timestamps and internet protocol addresses, feature usage and interaction logs, error and diagnostic data, configuration and preference settings, and an audit log of activity conducted under that user’s credentials, including access to and viewing of records containing protected health information. We maintain this audit logging in furtherance of 45 C.F.R. § 164.312(b). Authorized users have no expectation of privacy in their use of the Platform, and we may disclose these logs to the customer practice that authorized their access.

2.4 Payment Information. Payment card information is collected and processed by our third-party payment processor. We do not store full payment card numbers.

3. Client and Patient Data We Process for Our Customers

3.1 Source. Our customers connect the Platform to their electronic health record, practice management, accounting, and payroll systems. Data is transferred to the Platform by an application programming interface published by the operator of the source system, by a file the customer uploads, or by an automated process in which we authenticate to the source system using credentials the customer supplies and acting as the customer’s agent, and retrieve the reports the customer has configured.

3.2 Data Minimization at Ingestion. We reduce each client record before storing it. Client names exist only transiently in memory during a synchronization and are then discarded; the durable match key is the record identifier assigned by the source system. For each client record we retain: initials; birth year, without month or day; the first three digits of the postal ZIP code; gender identity; race and ethnicity; preferred language; relationship status; employment status; an indicator of whether the individual is a minor; intake date; last attended date; billing type, meaning self-pay or insurance; the name of the insurance company, without any member or subscriber identifier; treating clinician; outstanding account balance; referral source; and the individual’s appointment history, including the date and time of each appointment, the applicable service or procedure code, the duration, and whether the appointment was in-office or by telehealth.

3.3 What We Do Not Retain. We do not retain: name; full date of birth; full postal ZIP code; street address; telephone number; electronic mail address; insurance member or subscriber number; Social Security number; medical record number; clinical notes or any other clinical documentation; or diagnosis codes.

3.4 This Data Is Protected Health Information.

The reduced client record described in Section 3.2 is protected health information under HIPAA. We store it, we maintain it as protected health information, and we protect it as protected health information. The reduction described in Section 3.2 is a data minimization measure. It is not de-identification, and we do not represent that the data we hold is de-identified within the meaning of 45 C.F.R. § 164.514.

3.5 How We Use It. We use client and patient data only to provide the Services to the customer practice from which we received it, and only as permitted by our Business Associate Agreement with that practice and by HIPAA. We do not use it for our own commercial purposes, we do not sell it, we do not use it for advertising, and we do not use it to train any artificial intelligence or machine learning model other than one used solely to provide the Services to that same practice.

3.6 De-Identified and Aggregated Data. We may create de-identified data from customer data and may use it and comparative benchmarks derived from it to improve and develop the Services and to publish industry benchmarks. Before we do so, the data must be de-identified in accordance with 45 C.F.R. § 164.514(b), either by removal of the enumerated identifiers or by the documented determination of a qualified expert, and we must not have actual knowledge that the residual information could be used to identify an individual. We do not attempt to re-identify de-identified data, we contractually prohibit recipients from doing so, and we do not publish any benchmark from which a customer practice, a clinician, or an individual client is reasonably identifiable.

3.7 Requests From Clients and Patients. If you are a client or patient of a practice that uses ilumenIQ and you wish to exercise a right of access, amendment, accounting of disclosures, or restriction with respect to your health information, please contact that practice. It is the covered entity and it holds those obligations. If you contact us directly, we will refer your request to the practice and will not respond substantively.

4. How We Use Information About Visitors and Users

4.1 Purposes. We use the information described in Article 2 to provide, operate, secure, and improve the Services; to create and administer accounts and process payments; to respond to inquiries and provide support; to send service and security notifications; to send marketing communications, subject to Section 6.1; to detect, investigate, and prevent fraud, unauthorized access, and misuse; to enforce our agreements; and to comply with legal obligations.

4.2 What We Do Not Do. We do not sell personal information. We do not share personal information for cross-context behavioral advertising or targeted advertising. We do not use advertising or targeting cookies. We do not engage in profiling that produces legal or similarly significant effects.

5. How We Share Information

5.1 Service Providers. We share information with vendors that perform services for us, including cloud infrastructure hosting, payment processing, electronic mail delivery, customer support, and website analytics. Each is authorized to use the information only to perform services for us and is bound by confidentiality and data protection obligations. Every vendor that creates, receives, maintains, or transmits protected health information on our behalf has executed a business associate agreement with us. We maintain a current list of those vendors and will furnish it to a customer on written request.

5.2 Customer Practices. If you access the Platform as an authorized user of a customer practice, your account information and your activity and audit logs are accessible to that practice’s administrators.

5.3 Legal Process. We may disclose information when required by law, regulation, subpoena, court order, or lawful governmental request, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of ilumenIQ, our customers, or others. Where legally permitted, we will notify the affected customer before disclosing customer data in response to legal process, and will disclose only what is legally required.

5.4 Corporate Transactions. If ilumenIQ is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to the acquiring party’s assumption of the obligations in this Privacy Policy and in the applicable Business Associate Agreement. We will give notice of any such transfer.

5.5 With Consent. We may share information for any other purpose with your consent or at your direction.

5.6 Location of Processing. We store and process information in the United States. We do not transmit or store protected health information outside the United States.

6. Your Choices

6.1 Marketing Communications. You may opt out of marketing electronic mail at any time by using the unsubscribe link in any marketing message or by writing to legal@ilumeniq.com. Opting out does not affect service, security, billing, or legal notices.

6.2 Account Information. Authorized users may review and update their account information within the Platform. A customer practice may request correction or deletion of account data by writing to legal@ilumeniq.com.

6.3 Cookies. The Site uses strictly necessary cookies required for the Site to function and analytics cookies used to understand how visitors use the Site. We use Google Analytics for this purpose; information collected by it is transmitted to and held by Google in accordance with Google’s own privacy policy, and you may opt out by installing the Google Analytics Opt-out Browser Add-on. You may also control cookies through your browser settings, though disabling some cookies may impair Site functionality.

6.4 Do Not Track and Global Privacy Control. The Site does not currently respond to browser “Do Not Track” signals. Because we do not sell personal information or share it for targeted advertising, a Global Privacy Control signal does not change how we handle your information.

7. Privacy Rights

7.1 North Carolina and South Carolina. North Carolina and South Carolina have not enacted comprehensive consumer data privacy statutes conferring individual rights of access, correction, deletion, or portability. Residents of those states nevertheless have the rights described in Section 7.2, which we extend as a matter of practice.

7.2 Rights We Extend. Subject to verification of your identity and to applicable legal exceptions, you may request that we (a) confirm whether we process personal information about you and provide access to it, (b) correct inaccurate personal information, (c) delete personal information, and (d) provide a portable copy of personal information you provided to us. Submit requests to legal@ilumeniq.com. We will respond within forty-five (45) days, subject to one extension where reasonably necessary, and we will tell you if we decline a request and why. We will not discriminate against you for exercising these rights.

7.3 Limits. These rights apply to information we hold in our own capacity. They do not apply to protected health information we hold as a business associate; requests concerning health information must be directed to the customer practice, as described in Section 3.7. We may decline a request where fulfilling it would require us to violate HIPAA, would compromise the security of the Services, or where an exception under applicable law applies.

7.4 Residents of Other States. If you reside in a state that has enacted a comprehensive consumer data privacy statute, you may have additional rights under that statute, including the right to appeal a denial and to lodge a complaint with your state attorney general. We will honor rights conferred by any such statute that applies to us.

8. Retention

8.1 Retention Periods. We retain client and patient data for the duration of the customer practice’s subscription and for a thirty (30) day wind-down period following termination, after which it is deleted or destroyed. We retain audit and security logs for six (6) years in accordance with 45 C.F.R. § 164.316(b)(2)(i). Backup media containing customer data are purged on a rolling cycle not exceeding thirty-five (35) days. We retain information about Site visitors and prospective customers for as long as necessary for the purpose for which it was collected, and account, billing, and contract records for as long as necessary to comply with law and to enforce our agreements.

8.2 Written Policy. We maintain a written retention and destruction policy consistent with this Article and will furnish it to a customer on written request.

9. Security

9.1 Safeguards. We maintain a written information security program that includes encryption of protected health information at rest and in transit, database-enforced isolation of each customer’s data, multi-factor authentication for administrative access, role-based access control, designated Security and Privacy Officers, audit logging as described in Section 2.3, written policies covering incident response, risk analysis, vendor management, workforce training, and asset inventory, and an annual documented risk analysis under 45 C.F.R. § 164.308(a)(1)(ii)(A). With respect to electronic protected health information we comply with the HIPAA Security Rule as it applies to business associates.

9.2 Certifications. We do not hold SOC 2 attestation, HITRUST certification, certification under the ONC Health IT Certification Program, or any other third-party audit, attestation, or certification, and we have not undergone third-party penetration testing. We say so here so that no one relies on an assumption to the contrary.

9.3 No Absolute Security. No method of electronic transmission or storage is completely secure. We cannot and do not guarantee the absolute security of information transmitted to or held within the Services.

9.4 Breach Notification. In the event of a breach of unsecured protected health information, we will notify the affected customer practice in accordance with the Business Associate Agreement and applicable law. That practice, as the covered entity, is responsible for notifying affected individuals. In the event of a breach affecting other personal information, we will notify affected individuals and regulators as required by applicable law, including N.C. Gen. Stat. § 75-65 and S.C. Code Ann. § 39-1-90.

10. Children

10.1 The Site and Platform Are Not for Children. The Site and the Platform are directed to healthcare businesses and their workforce. They are not directed to children, and we do not knowingly collect personal information directly from any individual under the age of eighteen. If we learn that we have received such information directly from a child, we will delete it.

10.2 Health Records Relating to Minors. Client records processed on behalf of a customer practice may relate to individuals under the age of eighteen. Those records are protected health information governed by HIPAA, by our Business Associate Agreement with the practice, and by applicable state law. Under N.C. Gen. Stat. § 90-21.5 and comparable law in other states, a minor may consent on the minor’s own behalf to certain mental health and related services, and in those circumstances a parent or guardian may not be the minor’s personal representative. We do not determine who a minor’s personal representative is and we do not disclose records to a parent, guardian, or family member. All such requests are referred to the customer practice.

11. Changes, Governing Law, and Contact

11.1 Changes. We may update this Privacy Policy. If we make a material change, we will notify customers by electronic mail or through the Platform before the change takes effect, and we will update the effective date at the top of this page. Material changes affecting the handling of protected health information will also be made in accordance with the Business Associate Agreement.

11.2 Governing Law. This Privacy Policy is governed by the laws of the State of North Carolina, without regard to its conflict of laws principles, except to the extent the law of another jurisdiction applies of its own force to a resident of that jurisdiction.

11.3 Relationship to Our Agreements. This Privacy Policy is incorporated into the Master Subscription and License Agreement and is subordinate to it and to the Business Associate Agreement at Article 14 of that agreement, in the order of precedence stated in Section 1.5 of that agreement.

11.4 Contact. Questions, requests, and complaints may be directed to ilumenIQ LLC, Attn: Privacy Officer, 1235 East Blvd, Suite E519, Charlotte, North Carolina 28203, or legal@ilumeniq.com.