Skip to content
← Return to GeoMedix
GeoMedix Digital
Legal · Privacy

Privacy Policy

Effective January 1, 2026

GeoMedix Digital ("GeoMedix," "we," "our," or "us") delivers conversion-engine websites, local SEO infrastructure, and AI front-desk automation to licensed medical spas and aesthetic clinics operating within the United States. This Privacy Policy explains what information we collect through our marketing properties, qualification funnels, and deployed software infrastructure, how we use it, the rights you hold under United States privacy law, and the strict boundary between our role as a technology service provider and the clinic's role as the regulated healthcare Covered Entity.

1. Scope & Data Controller

This Policy applies to (a) visitors to geomedixdigital.com and any subdomain we operate, (b) prospective clients submitting qualification or contact forms, (c) executed clients receiving deployed infrastructure, and (d) end-consumers interacting with AI-powered booking assistants deployed on behalf of clinic clients. With respect to our own marketing site and qualification funnel, GeoMedix Digital acts as the data controller. With respect to data flowing through clinic-deployed infrastructure, GeoMedix Digital acts strictly as a technology service provider; the contracting clinic remains the data controller and, where applicable, the HIPAA Covered Entity.

2. Information We Collect

Through Web3Forms-powered qualification and contact funnels, Instagram direct inquiries, and direct correspondence, we collect: full name, business email address, phone number, clinic or med spa name, clinic website URL, declared monthly revenue tier, declared margin profile, stated growth bottleneck, preferred asynchronous contact method, and any free-form notes voluntarily provided. We also collect technical metadata automatically generated by your browser, including IP address, user-agent string, referring URL, viewport dimensions, and timestamps. We do not knowingly collect Social Security numbers, financial account numbers, government-issued identifiers, biometric identifiers, or precise geolocation through our marketing properties.

3. Purposes of Processing

We process the information described above to (i) evaluate fit and respond to qualification inquiries, (ii) deliver contracted services and account management, (iii) operate, secure, and improve our marketing properties, (iv) measure marketing performance and optimize conversion architecture, (v) comply with our legal, tax, and audit obligations, and (vi) protect our legal rights and prevent fraud or abuse. We do not sell personal information, and we do not engage in cross-context behavioral advertising for monetary consideration.

4. Tracking Technologies

Our marketing properties deploy first-party and third-party tracking technologies, including:

  • Google Analytics 4 — aggregated traffic measurement, session attribution, conversion event reporting, and audience composition analytics. IP anonymization is enabled.
  • Meta Pixel (Facebook / Instagram) — conversion attribution, retargeting audiences, and campaign optimization for our paid social funnels.
  • Essential session cookies — preserve qualification funnel progress, ROI calculator state, and CSRF protection tokens.

You may disable non-essential tracking by configuring your browser to reject third-party cookies, by installing the Google Analytics Opt-Out Browser Add-on, or by exercising the rights described in Section 8 below. We honor Global Privacy Control (GPC) signals as a valid opt-out of sale and sharing for California residents.

5. Sharing & Sub-Processors

We engage the following categories of sub-processors, each bound by contractual confidentiality and data-protection obligations: hosting and edge compute (Vercel, Cloudflare), form intake and relay (Web3Forms), workspace and document storage (Notion, Google Workspace), payment processing (Stripe), email delivery (Resend, Postmark), and analytics (Google, Meta). We disclose personal information to law enforcement only when compelled by valid legal process and only to the minimum extent legally required.

6. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. Controls include TLS 1.3 in transit, AES-256 encryption at rest within our managed sub-processors, role-based access control, principle-of-least-privilege provisioning, mandatory two-factor authentication for all production access, quarterly access reviews, and segregated production environments. No internet-facing system is impervious to compromise, and we cannot warrant absolute security.

7. Data Retention

Prospect inquiry records are retained for thirty-six (36) months from last contact to support continuity of correspondence. Executed-client account, billing, and contract records are retained for the duration of the engagement plus seven (7) years to satisfy United States tax, accounting, and audit requirements. Operational application logs are rotated on a rolling ninety (90) day window. Backups are purged on a one hundred eighty (180) day cycle.

8. California Consumer Privacy Act (CCPA / CPRA) Rights

If you are a California resident, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA"), grants you the following rights with respect to your personal information:

  • Right to Know — request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it.
  • Right to Delete — request deletion of personal information we have collected from you, subject to statutory exceptions (e.g., active contracts, legal compliance, fraud prevention).
  • Right to Correct — request correction of inaccurate personal information we maintain about you.
  • Right to Opt Out of Sale or Sharing — direct us not to "sell" or "share" your personal information as those terms are defined under the CCPA/CPRA. GeoMedix does not sell personal information for monetary consideration; we treat the use of advertising pixels as "sharing" and honor opt-outs accordingly.
  • Right to Limit Use of Sensitive Personal Information — direct us to limit our use of any sensitive personal information to that which is necessary to perform the requested services.
  • Right to Non-Discrimination — exercise any of the above rights without receiving discriminatory treatment in service or pricing.
  • Right to an Authorized Agent — designate an authorized agent to submit requests on your behalf, subject to verification.

To exercise any of these rights, email privacy@geomedixdigital.com with the subject line "CCPA Request." We will verify your identity before fulfilling the request and respond within forty-five (45) days, extendable once by an additional forty-five (45) days where reasonably necessary.

9. HIPAA & Protected Health Information (PHI) Disclaimer

GeoMedix Digital is an enterprise technology vendor. We design, build, and operate software and automation infrastructure — including conversion-engine websites, AI receptionist agents, voice and SMS routing layers, and CRM workflow scaffolds — for clients in the aesthetic and medical-spa sector. GeoMedix Digital is not a healthcare provider, is not a "Covered Entity" under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), and does not independently render medical services.

The contracting clinic is, and at all times remains, the Covered Entity under HIPAA and any applicable state health-privacy statute. The clinic alone determines what categories of Protected Health Information ("PHI") may be transmitted, stored, or processed through any system we deploy on its behalf. The clinic is solely and exclusively responsible for: (a) configuring its CRM, scheduling platform, and electronic medical record system to comply with HIPAA's Privacy, Security, and Breach Notification Rules; (b) obtaining patient authorizations and consents required by 45 C.F.R. § 164.508 and applicable state law; (c) executing Business Associate Agreements with any downstream sub-processor that will create, receive, maintain, or transmit PHI on the clinic's behalf; and (d) restricting the categories of patient information surfaced to our infrastructure to the minimum necessary for the intended booking, intake, or marketing workflow.

Where the parties mutually determine that our infrastructure will create, receive, maintain, or transmit PHI on the clinic's behalf, GeoMedix Digital will execute a separately negotiated Business Associate Agreement ("BAA") prior to such processing. Absent an executed BAA, the clinic warrants and represents that no PHI will be transmitted into systems we operate, and the clinic accepts full and exclusive responsibility for any inadvertent disclosure originating from its operational use of our infrastructure. Our standard workflows are engineered to support — but do not by themselves guarantee — HIPAA-compliant operation; compliance is the operational responsibility of the clinic.

10. International Data Transfers

GeoMedix Digital is operated from the European Union. Personal information collected through our marketing properties is processed on infrastructure located in the United States and the European Economic Area. By submitting personal information through our properties, you consent to the cross-border transfer and processing of that information in jurisdictions outside your country of residence, including in countries whose data-protection laws may differ from those of your home jurisdiction. We rely on Standard Contractual Clauses and equivalent transfer mechanisms where required by law.

11. Children's Privacy

Our services are directed exclusively to business operators and licensed medical professionals. We do not knowingly collect personal information from individuals under sixteen (16) years of age. If we become aware that we have inadvertently collected such information, we will delete it without undue delay.

12. Changes to this Policy

We may amend this Policy from time to time to reflect changes in our practices, sub-processor relationships, or applicable law. The "Effective" date at the top of this page reflects the most recent revision. Material changes will be announced via prominent notice on our marketing site and, where appropriate, via direct email to active-engagement clients.

13. Contact

General inquiries: info@geomedixdigital.com.