Legal
Privacy Policy (Draft Pending Counsel)
This draft explains how Nuraflow handles personal information through its public website, waitlist, demo funnel, chat and pre-launch software activities. It is written to be useful now, while keeping future product and advertising plans separate from technology that is actually in use.
- Effective date
- [COUNSEL INPUT REQUIRED: effective date]
- Last updated
- September 1, 2026 (draft)
Draft. This document is a comprehensive working version pending review by qualified counsel. Bracketed items remain unresolved legal or operational facts. This page must not be treated as final until those items are completed and counsel approves the document.
1. Draft Status and Who Is Responsible
This is a working legal draft, not a final or effective policy. It must be reviewed against Nuraflow's actual launch operations before publication.
Nuraflow is a company registered in Delaware and operating from Texas. Its mailing address is 550 S Watters Rd Ste 223, Allen, TX 75013. Nuraflow is the controller or business responsible for personal information covered by this policy, except where it processes information only on a customer's instructions.
Questions, privacy requests and grievances may be sent to privacy@nuraflow.cloud. Nuraflow has not named a data protection officer in this draft and does not represent that one is legally required. [COUNSEL INPUT REQUIRED: determine whether an EU, UK or Swiss representative must be appointed before offering services in those jurisdictions.]
Legal correspondence may be sent to legal@nuraflow.cloud or mailed to the Texas address above. Privacy requests should continue to use privacy@nuraflow.cloud. Email Nuraflow Legal
Before this policy becomes effective, Nuraflow must confirm the deployed website, form fields, consent controls, environment settings, contracts, vendor settings, retention schedule, legal entity information and the status of every analytics or advertising tool described below. The words 'may,' 'planned' and 'intended' identify processing that is conditional or not yet verified as active.
2. Scope and Our Different Roles
This policy covers the public Nuraflow experience. Customer-controlled records inside a future SaaS deployment will follow a different legal and contractual path.
This policy covers visits to the Nuraflow public website; waitlist, contact and demo submissions; demo scheduling; website chat; marketing communications; and information used to plan, secure, test and launch the pre-launch Nuraflow service. It also covers related communications by email or other channels when they concern these activities.
For this public website and funnel, Nuraflow generally decides why and how information is handled and therefore acts as the controller, business or equivalent responsible party under applicable privacy law.
When a future agency customer uses Nuraflow to handle information about its patients, clients, family members, workers or applicants, the customer will generally determine the purposes and means of that processing. In that setting, Nuraflow expects to act as the customer's processor, service provider or business associate under the customer agreement, data processing addendum and, where required, a Business Associate Agreement. The customer's privacy notice and instructions will govern requests about customer-controlled records.
This policy does not govern third-party websites or services reached through a link, even when Nuraflow links to them. Their own privacy terms apply to information they collect for their purposes.
3. Information We Collect
We collect what you provide, basic information produced when you use the site, and records created while we respond to you.
Contact and identity information may include your name, business email address, telephone number, organization, job title or role, and the state or region where your organization operates.
Waitlist and demo information may include agency name and website, care lines, approximate workforce size, current software, operational priorities, requested workflows, who expects to attend a demo, preferred meeting time, referral source, and any answers or comments you choose to submit.
Communications information may include messages sent through forms, surveys, chat or email; scheduling records; meeting status; support or privacy correspondence; consent and opt-out records; and notes needed to follow up on the request.
Device, network and usage information may include IP address, approximate location derived from IP address, browser and device type, operating system, language, referring page, pages viewed, timestamps, links or buttons selected, scrolling and pointer activity, technical errors, cookie or similar identifiers, and consent signals. Microsoft Clarity can reconstruct page interactions for session replay, but its documentation states that text entered into input fields is masked by default and third-party iframe contents are not captured by Clarity.
Derived information may include broad inferences about which Nuraflow topics or pages appear useful, whether a visitor is likely to be interested in the waitlist or a demo, and aggregated measures of campaign or site performance. Nuraflow does not intend to infer a visitor's health condition from public-site activity.
Nuraflow does not ask for government identification numbers, financial-account credentials, precise geolocation, biometric identifiers, patient records, medical diagnoses or treatment details through the public website, waitlist, demo survey, calendar or chat. Please do not submit those categories through these channels.
4. Where Information Comes From
Most information comes from you. Some comes automatically from your browser or from the services used to run the funnel.
We receive information directly from you when you browse, join the waitlist, request or schedule a demo, use chat, email us, respond to a survey, exercise a privacy right or otherwise communicate with Nuraflow.
We receive technical and interaction information automatically from browsers, devices, cookies, pixels, local storage, server logs and similar technologies, subject to the controls described in this policy.
We may receive records from service providers that operate our forms, surveys, calendar, chat, email delivery, hosting, security, analytics or advertising. For example, GoHighLevel or LeadConnector may return a submitted lead record, appointment status, conversation history and related technical information to Nuraflow.
If another person submits business contact information on your behalf, we may receive it from that person. We may also receive consent, suppression or preference information from advertising and consent-management partners if those tools are later activated.
5. Why We Use Information
We use information to run the website and funnel, respond to people, prepare the product, measure what works and protect the service.
We use information to operate and troubleshoot the website; receive and manage waitlist entries; qualify, schedule and conduct demos; respond to questions; provide requested information; maintain relationship history; and honor communication preferences.
We use information to understand demand, prioritize product planning, evaluate prospective founding-cohort participation, improve content and usability, measure campaigns, maintain records, forecast capacity and prepare for a SaaS launch. Joining the waitlist does not guarantee selection, product access, pricing or launch timing.
We use information to detect, investigate and prevent spam, fraud, misuse, security incidents and unlawful activity; enforce agreements; protect rights and safety; comply with legal process; establish or defend legal claims; and meet accounting, tax, regulatory and recordkeeping duties.
We may send service messages about a submission or appointment. We may send marketing or launch updates where permitted by law and consistent with the choice presented when information is collected. You can unsubscribe from marketing messages at any time; an unsubscribe does not stop transactional or legally required messages.
We may combine records from the same person or organization when reasonably necessary for these purposes. We may also aggregate or deidentify information so it no longer reasonably identifies an individual, and use that result for analytics, planning, security and research. We will not attempt to reidentify data we maintain as deidentified except to test whether deidentification works, where law permits.
6. Legal Bases for Processing
Where European, UK or similar law requires a legal basis, the basis depends on why the information is being used.
Consent: we rely on consent for optional analytics or advertising cookies where consent is required, for certain marketing communications, and for sensitive information only when the law requires explicit consent. Consent can be withdrawn at any time without affecting earlier lawful processing.
Steps at your request and contract: we may process information to answer a demo request, schedule a meeting, evaluate a requested commercial relationship, enter into an agreement or perform an agreement with you or your organization.
Legitimate interests: we may process information to operate and improve a business-to-business website, understand demand, respond to inquiries, develop the pre-launch service, maintain business relationships, prevent abuse, secure systems and establish legal claims. We consider the nature of the information, reasonable expectations and potential impact before relying on this basis.
Legal obligation and vital interests: we may process information to comply with law, valid legal process, regulatory duties or breach-notification requirements, or to protect someone's life or physical safety in an emergency. If another legal basis applies under local law, we will identify and use it as required.
7. Cookies, Pixels and Consent Choices
Different technologies do different jobs. Optional analytics and advertising should not be treated like tools that are necessary to deliver a form or protect the site.
Strictly necessary and security technologies support core functions such as delivering pages, balancing traffic, preventing abuse, remembering a privacy choice and completing a form or appointment request. Where the law allows, these operate without optional-cookie consent because the requested service would not work reliably without them.
Functional technologies remember optional settings or enable features such as embedded forms, surveys, calendars and chat. Some embedded features come from a third-party domain and may store or read their own identifiers when loaded.
Analytics technologies measure visits, interactions, errors and usability. Advertising technologies can measure campaigns, create or use audiences, attribute conversions and support targeted or cross-context behavioral advertising. Where required, analytics and advertising storage will be disabled until the visitor makes the relevant choice.
The current site provides controls to reject all optional technologies, accept them, choose analytics, marketing and functional categories separately, and reopen Cookie Settings from the footer. The site stores the choice in local storage and in a first-party nuraflow_consent cookie for up to one year so it can remember the selection. Withdrawing a previously granted category reloads the page so the related tool is removed.
A recognized Global Privacy Control signal forces the site's marketing category off. You can also change browser settings and clear stored identifiers. Blocking an embedded-service technology may prevent a form, survey, calendar or chat from working; email remains an alternative contact path. [COUNSEL INPUT REQUIRED: confirm the final production cookie inventory, geographic rules and environment configuration before publication.]
8. Current and Planned Website Vendors
The site has consent-gated components for Microsoft Clarity, Google Analytics, the Meta Pixel and GoHighLevel chat, plus GoHighLevel forms, surveys and scheduling. Production activation still depends on deployment settings.
Microsoft Clarity. The current site loads Clarity only after a visitor grants analytics consent. It then sends Clarity's Consent V2 signal with analytics storage granted and advertising storage denied. Clarity can collect page views and interactions and provide heatmaps, session replay and machine-generated insights. Microsoft identifies Clarity cookies including _clck and _clsk and, depending on configuration, Microsoft-domain identifiers. Microsoft currently states that ordinary recordings are retained for 30 days and certain favorite or sampled recordings may be retained for up to nine months. Read Microsoft's Clarity Consent V2 documentation
GoHighLevel and LeadConnector. The current code embeds hosted forms, a demo survey and a scheduling calendar on the pages where a visitor requests those features. The GoHighLevel chat widget loads only after functional consent. These services receive information submitted through the embedded experience and may receive device, log, consent and cookie information needed to provide and secure it. The embeds carry GoHighLevel's automatic cookie-consent setting, and the site provides an email alternative. HighLevel generally processes customer-submitted data for Nuraflow under its data processing terms, while it may act for its own purposes for account administration, service security and other activities described in its notices. Read HighLevel's Privacy Policy
Google Analytics. The current site includes a Google Analytics component that can measure page and campaign performance only after analytics consent and only when a public Google Analytics measurement ID is configured in the deployed environment. The component requests IP anonymization. The repository does not establish whether a production measurement ID is currently configured, so active production collection must be confirmed. Google Analytics can process device and usage data and use analytics identifiers; advertising features, Google Signals or linked advertising services require separate review and consent controls. Read Google's Analytics privacy controls
Meta or Facebook Pixel. The current site includes a Meta Pixel component that can send a PageView event only after marketing consent and only when a public Meta Pixel ID is configured in the deployed environment. A Global Privacy Control signal keeps the marketing category off. The repository does not establish whether a production Pixel ID is currently configured, so active production collection must be confirmed. If active, the tool may send Meta event, page, device and cookie information for campaign measurement, conversion attribution, audience building or targeted advertising. Nuraflow will not send public-form free text or health information to Meta for advertising purposes. Read Meta's Privacy Policy
[COUNSEL INPUT REQUIRED: verify these activation statements and vendor configurations against the production deployment immediately before publication and after every tag-manager or funnel change.]
9. Sensitive and Health Information Boundaries
The public funnel is for business conversations, not patient care. Do not put patient information or personal medical details into public forms, calendars, chat or ordinary email.
Nuraflow's public website and demo funnel are not a clinical service, patient portal or emergency channel. They are not designed to receive protected health information, consumer health data, medical records, diagnoses, treatment details, insurance identifiers, disability details, genetic or biometric data, precise geolocation, government identifiers, financial credentials or other highly sensitive information.
When discussing workflows in a demo, use synthetic or properly deidentified examples. Do not identify a patient, client, family member, employee or applicant. If you accidentally send sensitive information, contact privacy@nuraflow.cloud so we can assess, restrict and, where appropriate, delete it.
If Nuraflow receives sensitive information unexpectedly, we will use it only as reasonably necessary to respond, protect the person, secure the service, comply with law or delete it. We do not intend to use health information or other sensitive information from the public funnel for targeted advertising, audience building or inferences about a person's health.
Some U.S. state laws protect consumer health data even when HIPAA does not apply. Where one of those laws applies, Nuraflow will obtain any required consent or authorization, provide applicable access, withdrawal and deletion rights, and avoid collecting or sharing consumer health data beyond what is necessary and disclosed. This policy is not a Washington Consumer Health Data Privacy Policy or another separate state notice unless counsel confirms that one is required.
10. HIPAA and Business Associate Agreements
HIPAA status depends on the relationship and the data flow. A healthcare-focused product is not automatically covered by HIPAA, and there is no government HIPAA certification.
Information submitted by a business representative through this public website is not automatically protected health information under HIPAA. HIPAA generally applies to covered entities and business associates in defined circumstances; other privacy and security laws may still protect the same information.
If Nuraflow launches functionality that creates, receives, maintains or transmits protected health information on behalf of a covered entity or another business associate, Nuraflow expects to process that information only under the applicable customer agreement and a Business Associate Agreement where required. The agreement will define permitted uses, safeguards, subcontractor duties, incident reporting, return or deletion and assistance with individual rights. Read HHS guidance on Business Associate Agreements
Nuraflow is pre-launch. This draft does not claim that Nuraflow has a government-issued HIPAA certification or has completed an independent HIPAA assurance review. Any statement that a system is built for HIPAA or uses HIPAA-eligible services describes an intended design boundary, not a certification or a substitute for customer configuration, risk analysis, policies and operating practice.
Requests concerning protected health information held for a customer should ordinarily be directed to that customer. Nuraflow will assist the customer as required by the governing agreement and law rather than independently changing a customer-controlled clinical record.
11. Automated Processing and Artificial Intelligence
Automation may help organize site activity and requests, but the public funnel is not intended to make high-impact decisions about people without human review.
Website analytics may use automated methods or machine learning to group interactions, identify usability patterns, flag unusual activity or produce aggregate insights. Funnel tools may automatically route a submission, send a confirmation, score completeness, assign a follow-up task or offer calendar times.
Nuraflow does not intend to use the public website, waitlist or demo funnel to make a decision based solely on automated processing that produces legal or similarly significant effects concerning a person. A person should review founding-cohort selection and other material commercial decisions. If that practice changes, Nuraflow will provide any notice, explanation, opt-out, appeal or human-review rights required by law before using the new process.
The current website implementation reviewed for this draft does not send waitlist, survey, calendar or chat submissions to Amazon Bedrock. Product references to AWS and Amazon Bedrock describe intended pre-launch architecture, not verified active processing of public-funnel information.
If Amazon Bedrock is later used for product AI, Nuraflow will define permitted data, access controls, logging, retention, human review and customer instructions before processing production information. AWS states that Bedrock model providers do not receive customer prompts or completions and that AWS does not use them to train underlying models unless the customer consents; those provider features do not remove Nuraflow's own responsibilities. Read Amazon Bedrock data-protection documentation
12. When We Disclose Information
We disclose information to operate the service, follow your instructions, protect people and systems, and complete legitimate business transactions.
Service providers may receive information to provide hosting, content delivery, security, analytics, forms, surveys, customer relationship management, chat, email, calendar, communications, support, professional advice, auditing and data-management services. They are expected to use information under contract and only for the services or legally permitted purposes.
Current website-related providers identified in the code reviewed for this draft include Microsoft for Clarity and HighLevel or LeadConnector for forms, surveys, calendar and chat. Google and Meta are planned possibilities described in Section 8, not verified active recipients. AWS and Amazon Bedrock are intended infrastructure or product references and are not identified here as current recipients of public-funnel submissions.
We may disclose information to professional advisers, auditors, insurers, financing sources and transaction counterparties subject to appropriate confidentiality; to a successor or prospective successor in a merger, financing, reorganization, sale of assets or similar transaction; and to regulators, courts, law enforcement or others when reasonably necessary to comply with law, valid process, protect rights and safety, investigate wrongdoing or defend claims.
We may disclose information at your direction, with your consent, or to people you ask us to include in a demo or business conversation. We may disclose aggregated or deidentified information that does not reasonably identify an individual.
We do not give an agency prospect access to another prospect's submission, and we do not disclose public-funnel information to future SaaS customers as though it were part of their customer-controlled records.
13. Sale, Sharing, Targeted Advertising and GPC
Some privacy laws define 'sale' or 'sharing' broadly enough to include certain advertising or analytics disclosures even when no money changes hands.
[COUNSEL INPUT REQUIRED: confirm and state whether Nuraflow has sold personal information, shared it for cross-context behavioral advertising, or processed it for targeted advertising during the required lookback period. Do not replace this sentence with a 'we do not sell' claim without reviewing vendor contracts, tags, audiences, match features and consideration received.]
Nuraflow does not intend to activate Google advertising features, the Meta Pixel, custom audiences or another targeted-advertising tool without first providing the notice, consent and opt-out mechanisms required for the visitor's location. If a disclosure through one of those tools is treated as a sale, sharing or targeted advertising under applicable law, an eligible person may opt out by using the site's privacy controls or emailing privacy@nuraflow.cloud with the subject 'Do Not Sell or Share.'
Global Privacy Control and other recognized universal opt-out mechanisms communicate a browser- or device-level request to opt out of covered sale, sharing or targeted advertising. The current site detects the browser's Global Privacy Control signal and forces its marketing category off for that browser, including preventing the Meta Pixel component from loading. [COUNSEL INPUT REQUIRED: determine whether any analytics disclosure also falls within an applicable sale, sharing or targeted-advertising definition and, if so, extend the signal's effect and downstream signaling before publication.] Learn about Global Privacy Control from the California Attorney General
Browser 'Do Not Track' signals are not the same as GPC and do not yet have one uniform legal meaning. We respond to GPC and other universal opt-out signals where applicable law recognizes them; otherwise, use the privacy controls or contact method described above.
14. Retention
We keep information only for as long as it remains reasonably necessary for the purpose collected, legal duties and a limited set of operational needs.
Waitlist, demo and business-contact records are retained while Nuraflow evaluates and prepares the launch, responds to the relationship and has a reasonable need to remember the request. Scheduling and communication records may be kept while the relationship is active and for a reasonable period afterward to maintain context, resolve disputes and meet legal obligations.
We set or review retention by considering the amount, nature and sensitivity of the information; the purpose and whether it has been completed; the person's choices; the risk of harm; applicable limitation periods; tax, accounting, contractual and regulatory duties; security and fraud-prevention needs; vendor capabilities; and whether aggregation or deidentification can meet the purpose instead.
Cookie and analytics records follow the relevant consent choice and provider settings. Microsoft currently publishes the Clarity recording periods described in Section 8. HighLevel's data processing terms generally tie customer-data processing to the period in which a customer uses its service, subject to deletion and legal-retention terms. Nuraflow must still apply its own retention decisions to records in its account.
Opt-out and suppression records may be retained as necessary to respect the choice. Privacy-request and verification records may be retained as required to show compliance. Security logs, legal holds and backup copies may remain for a limited additional period and are then deleted or overwritten under the applicable process.
[COUNSEL INPUT REQUIRED: approve a written retention schedule with concrete periods for lead records, communications, consent logs, analytics, security logs, rights requests and backups before this policy becomes effective.]
15. Security
We use safeguards proportionate to a pre-launch business and the information involved, while recognizing that no system is risk-free.
Nuraflow uses or plans administrative, technical and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration and disclosure. Depending on the system and launch stage, these may include access restrictions, authentication, encryption in transit, secure configuration, vendor review, logging, backups, incident response, workforce confidentiality and data minimization.
The production SaaS security program and any handling of protected health information remain pre-launch work. References to planned encryption at rest, least-privilege access, audit trails, recovery controls, HIPAA-eligible AWS services or governed AI describe intended architecture unless separately confirmed in a customer agreement or current trust documentation.
AWS identifies Amazon Bedrock and many other services as HIPAA eligible when used under an AWS Business Associate Agreement and configured consistently with HIPAA. Eligibility is a property of the provider service, not proof that Nuraflow's application or operations comply with HIPAA. Read the AWS HIPAA Eligible Services Reference
No safeguard can guarantee absolute security. Please use the designated forms for ordinary business information, avoid sending sensitive or patient data through public channels, and tell privacy@nuraflow.cloud if you believe information was submitted improperly or the site has been compromised.
16. International Processing and Transfers
Website and funnel providers may process information in the United States and other countries whose privacy rules differ from those where a visitor lives.
Nuraflow and its providers may access, store or process personal information in the United States and in other countries where they or their subprocessors operate. Courts, regulators or law enforcement in those places may have lawful access under local rules.
Where the EEA GDPR, UK GDPR or Swiss Federal Act on Data Protection restricts a transfer, Nuraflow will use an available lawful mechanism as applicable, such as an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, Swiss adaptations, or another approved safeguard. We will conduct any required transfer assessment and apply supplementary measures appropriate to the risk.
Some providers may participate in an official data-transfer framework. We will rely on a framework only for a recipient and data flow actually covered by that recipient's current certification, and will use another valid mechanism where needed.
You may ask privacy@nuraflow.cloud for information about the transfer mechanism relevant to your information. We may provide a summary or a redacted copy where contracts must remain confidential. Read the European Commission's transfer overview
17. EEA, UK and Swiss Rights
Depending on where you live and which law applies, you may have rights over access, correction, deletion, restriction, objection and portability.
You may have the right to know whether we process your personal information; receive a copy and information about its use; correct inaccurate or incomplete information; delete information; restrict processing; object to processing based on legitimate interests or to direct marketing; and receive information you provided in a structured, commonly used, machine-readable format or transmit it to another organization where portability applies.
Where processing is based on consent, you may withdraw consent at any time. Where applicable, you may object to profiling related to direct marketing and may have rights concerning a decision based solely on automated processing that has legal or similarly significant effects, including human intervention, an explanation, the opportunity to express your view and the ability to contest the decision.
These rights are not absolute. We may limit or deny a request when an exemption applies, such as to protect another person's rights, preserve legal claims, comply with law, keep a suppression record or complete a transaction you requested. We will explain a denial where the law requires.
You may lodge a complaint with the data-protection authority where you live, work or believe a violation occurred. UK residents may contact the Information Commissioner's Office, and Swiss residents may contact the Federal Data Protection and Information Commissioner. We ask that you contact privacy@nuraflow.cloud first so we have a chance to address the concern, but doing so does not limit your right to complain to an authority. Contact the UK Information Commissioner's Office
18. California Notice at Collection and Rights
California law requires a clear account of the categories collected, why they are used, how long they are kept and the rights available to eligible residents.
Categories collected. Depending on how you interact with Nuraflow, the categories described in Section 3 map to California identifiers; customer-record information; commercial information; internet or other electronic-network activity; approximate geolocation; professional or employment-related information; audio, electronic or visual information contained in communications; and inferences. Nuraflow does not intend to collect California sensitive personal information through the public funnel, but may receive it if a person includes it unexpectedly in free text.
Purposes, sources and recipients. We collect these categories from the sources in Section 4 for the business and commercial purposes in Section 5. We may disclose them to the categories of recipients in Section 12. Retention follows the criteria in Section 14. Sections 8 and 13 explain analytics, advertising, sale and sharing status, including the counsel confirmations still required for the statutory lookback period.
Subject to coverage, exceptions and verification, California residents may request the categories and specific pieces of personal information collected; sources, purposes and recipient categories; correction; deletion; and portability. They may opt out of sale or sharing and may limit certain uses or disclosures of sensitive personal information when those rights apply. Nuraflow will not discriminate against a person for exercising a CCPA right, including by denying service, charging a different price or providing a different quality solely because of the request, except where the law permits a reasonably related difference.
Nuraflow does not offer a financial incentive or price or service difference in exchange for personal information through the public waitlist or demo funnel in this draft. [COUNSEL INPUT REQUIRED: confirm this before publication and add a Notice of Financial Incentive before offering any such program.]
An eligible request can be made using the workflow in Section 20. The right to opt out does not require identity verification beyond what is reasonably needed to associate and honor the preference. A parent or guardian may make an applicable request for a minor, and an authorized agent may act as described below. Read the California Attorney General's CCPA guidance
19. Other U.S. State Rights
State privacy laws vary. We provide the rights that apply to an eligible resident without pretending every state uses the same definitions or rules.
Residents of states with comprehensive privacy laws may have rights to confirm processing; access, correct or delete personal data; obtain a portable copy; obtain information about certain recipients; and opt out of targeted advertising, sale and profiling used for decisions with legal or similarly significant effects. Some states also provide rights involving sensitive data, consumer health data, universal opt-out signals or explanations of automated profiling.
The exact right, coverage threshold, exception, response period and appeal process depend on the state and context. A law may exclude business-to-business contacts, employees, HIPAA-regulated data, nonprofit entities, small businesses or processing below a threshold. We will evaluate a request under the law that applies rather than promise a right the law does not provide.
If we deny a request and your state provides an appeal right, you may reply to the denial or email privacy@nuraflow.cloud with the subject 'Privacy Appeal' and explain why the decision should be reconsidered. We will review the appeal, respond within the period required by applicable law and provide the relevant regulator or attorney-general complaint path if the appeal is denied and the law requires it.
Nevada residents may submit a verified request through privacy@nuraflow.cloud directing Nuraflow not to make a sale of covered information as Nevada defines that term. Nevada's definition is narrower than the definitions used in some other states, and this Nevada right does not depend on whether Nuraflow currently makes such a sale. Read Nevada Revised Statutes Chapter 603A
Colorado and certain other states recognize universal opt-out mechanisms for sale or targeted advertising. Connecticut and several other states provide a formal appeal from some request denials. State consumer-health laws may impose separate consent, authorization, deletion or geofencing requirements even when HIPAA does not apply. Read the Colorado Attorney General's universal opt-out guidance
20. How to Exercise a Privacy Right
Email us, tell us what you want, and give us enough information to find the right record without sending sensitive identity documents unless we ask for them.
Send a request to privacy@nuraflow.cloud with a subject such as 'Access Request,' 'Deletion Request,' 'Correction Request,' 'Privacy Appeal' or 'Do Not Sell or Share.' State the right you want to exercise, your jurisdiction, the email address or telephone number used with Nuraflow, and enough context to locate the relevant waitlist, demo, calendar or chat record.
We will acknowledge and respond within the period required by applicable law. We may ask you to confirm control of an email address or telephone number, describe a recent interaction, or provide other information already associated with the record. We will match the verification method to the sensitivity of the request and information. Do not send a passport, driver's license, Social Security number, medical record or other sensitive document unless we specifically explain why it is necessary and provide an appropriate method.
If we cannot verify identity or authority, cannot locate a record, or an exception applies, we may ask for clarification or deny part or all of the request. We will explain the reason and any appeal or complaint option required by law. We may retain a minimal record of the request and response to demonstrate compliance and prevent repeated or fraudulent requests.
Authorized agents may submit a request where local law allows. We may ask for signed permission, proof of the agent's registration where applicable, direct confirmation from the person, or other evidence of authority. A valid power of attorney may satisfy different requirements. We will not require direct confirmation when doing so would conflict with applicable law.
There is no charge for a reasonable request, but applicable law may allow a fee or refusal for requests that are manifestly unfounded, excessive, repetitive or technically disproportionate. Exercising a right will not result in unlawful retaliation or discrimination.
21. Children and Minors
Nuraflow is a business service for adult representatives of care organizations, not a service directed to children or teenagers.
The public waitlist, demo funnel and pre-launch SaaS are intended for business representatives who are at least 18 years old. We do not knowingly collect personal information online from a child under 13 and do not intend to sell or share a minor's personal information or use it for targeted advertising.
If you are under 18, do not submit a waitlist entry, demo request, calendar booking or chat message. If we learn that we collected personal information from a child in a manner that requires parental consent or otherwise violates applicable law, we will take reasonable steps to delete or restrict it. A parent or guardian may contact privacy@nuraflow.cloud.
A future customer's use of Nuraflow for records concerning a minor will be customer-controlled product processing, not permission for the minor to use this public business funnel. The customer agreement, applicable healthcare and child-privacy law, and the customer's own notice will govern that processing. Read the FTC's COPPA Rule overview
22. Security Incidents and Breach Notices
We assess suspected incidents and notify affected people, customers and authorities when the law or a governing contract requires it.
If we discover unauthorized access, acquisition, use or disclosure, we will investigate, contain and remediate the incident; assess the information and people affected; preserve appropriate records; and make notices within the time, form and content required by applicable law.
Where Nuraflow acts as a processor, service provider or business associate, it will notify and assist the responsible customer as required by contract and law. The customer may be responsible for notifying individuals or regulators. For a breach of unsecured protected health information at or by a business associate, HIPAA generally requires notice to the covered entity without unreasonable delay and no later than the applicable legal deadline. Read the HHS Breach Notification Rule overview
A notice may describe what happened, the information involved, steps a person can take, Nuraflow's response and how to ask questions. Not every security event is a legally reportable breach, and notification duties vary by jurisdiction and the type of information involved.
23. Changes to This Policy
The policy will change as Nuraflow moves from a pre-launch funnel to an operating service, but material changes should not arrive silently.
We may update this policy when the website, funnel, product, vendors, legal requirements or processing practices change. The effective date will show when the current version applies.
For a material change, we will provide additional notice appropriate to the impact, such as a prominent website message, consent prompt or direct communication when we have contact information and the law requires it. We will obtain consent before applying a materially different use when consent is legally required.
Earlier versions may be retained for legal and accountability purposes. This draft is not an earlier effective version; it is expressly pending counsel and operational confirmation.
24. Contact, Appeals and Grievances
Use one address for questions, requests, appeals, sensitive-data concerns and privacy complaints.
Email privacy@nuraflow.cloud for any question about this policy; to exercise a right; to appeal a decision; to report information submitted in error; or to raise a grievance about collection, use, disclosure, retention, security, advertising, automation or international transfer. Email the Nuraflow privacy contact
Please include a concise description and the email address or telephone number associated with the interaction. Do not include patient information, medical records, government identifiers or financial credentials in the initial message.
Privacy correspondence may also be mailed to Nuraflow, 550 S Watters Rd Ste 223, Allen, TX 75013. Legal notices should be sent to legal@nuraflow.cloud. [COUNSEL INPUT REQUIRED: determine whether any regulator-required toll-free or web-form request method must be added before publication. Do not add a DPO or representative title unless that role has actually been appointed.] Email Nuraflow Legal