Effective Date: October 2025
PLEASE READ THIS POLICY BEFORE USING VAYLEN’S SERVICES.
IMPORTANT NOTICE: At Vaylen, protecting your health and personal information is our top priority. This Privacy Policy explains how we manage your data. For details on how we use and disclose your Protected Health Information (“PHI”) under the Health Insurance Portability and Accountability Act (“HIPAA”), please refer to our Notice of Privacy Practices.
1. Introduction
This Privacy Policy (the “Privacy Policy”) describes how Vaylen Health, Inc. (“Vaylen,” “we,” “us,” or “our”) collects, uses, stores, and discloses personal and health information about you through your use of our website, online platform, mobile communication tools, and other electronic interactions between you and Vaylen.
Vaylen is a U.S.-based telehealth company, providing personalized medical weight-loss solutions, including GLP-1 medications such as Semaglutide, Tirzepatide, Ozempic, Zepbound, Wegovy, and compounded oral and injectable formulations.
Through our secure telehealth platform, we connect patients with licensed clinicians and healthcare providers via our trusted partners, including Openloop, which supports the delivery of medical consultations, and Telescope, which manages our communication and scheduling systems. We also collaborate with certified compounding pharmacies to fulfill prescriptions safely and efficiently.
Vaylen respects your privacy and is committed to protecting it through our compliance with this Privacy Policy and all applicable federal and state laws governing data privacy and health information, including HIPAA, the California Consumer Privacy Act (CCPA), and other U.S. state privacy regulations.
This Privacy Policy outlines the types of information that Vaylen and its affiliates (collectively, “Vaylen,” “we,” “our,” or “us”) may collect from you, or that you may provide when using our website, mobile services, or telehealth platform (collectively, the “Platform”). It also describes our practices for collecting, using, maintaining, protecting, and disclosing that information.
Your use of the Platform is governed by this Privacy Policy and our Terms of Service. This Privacy Policy is incorporated by reference into our Terms of Service. All capitalized terms not otherwise defined in this document have the meanings assigned to them in the Terms of Service.
By accessing or using the Platform, you acknowledge that you have read, understood, and agree to be legally bound by and comply with this Privacy Policy and our Terms of Service. If you are not in agreement with the terms of this Privacy Policy, please do not use the Platform or provide any personal or health information to us.
Please note that this Privacy Policy does not apply to information collected by any third party, including applications, websites, or content (such as advertisements) that may link to or be accessible from our Platform. You may also be subject to different privacy policies or terms of service when interacting with third-party platforms or services integrated with our system (for example, payment processors, partner pharmacies, or communication tools).
At Vaylen, we are committed to protecting your privacy and maintaining the confidentiality of your personal and medical information. We provide this Privacy Policy to help you understand the types of data we collect, how we use it, and the measures we take to safeguard it.
2. Information We Collect About You and How It’s Collected
We collect information necessary to provide and improve our services, ensure proper communication, and maintain compliance with applicable laws. The information we collect generally falls into three main categories:
1. Personal and Contact Information:
Includes details that identify you, such as your name, email address, phone number, mailing address, date of birth, and account details. This also covers payment or billing information when applicable.
2. Health and Service-Related Information:
Covers information related to your care, health history, prescriptions, treatment preferences, and communications with our healthcare providers or support staff. This may include notes, recommendations, or records necessary to deliver our services in compliance with HIPAA.
3. Technical and Usage Information:
We automatically collect data about how you interact with our website and platform, including your IP address, browser type, device information, location data, and browsing activity. This helps us improve our system performance and user experience.
We collect this information:
● Directly from you, when you fill out forms, create an account, or communicate with us.
● Automatically, through cookies, analytics tools, and similar technologies, when you use our website or platform.
● From third parties, such as affiliated providers, payment processors, or pharmacies assisting in your care or transactions.
This information helps us ensure secure access, personalized services, and effective communication throughout your experience with Vaylen Health.
3. How We Use Your Information
Vaylen collects and uses your information to provide safe, effective, and compliant telehealth and weight management services. We handle Personal Information, Protected Health Information (PHI), and other related data in accordance with HIPAA, federal, and state privacy regulations. The following outlines how we may use the information we collect:
1. To Provide and Manage Our Services:
We use your information to create and manage your account, verify your identity, connect you with licensed healthcare professionals through our partner Openloop, deliver consultations and treatment plans, process prescriptions, and coordinate with our compounding pharmacies for medication dispensing, refills, and delivery. This also includes maintaining your medical records, lab results, and progress updates to ensure high-quality care.
2. To Communicate with You:
We use your information to send appointment reminders, treatment updates, and notifications about your health plan. We may also respond to your inquiries, provide educational content, and deliver secure messages through the platform, email, SMS, or other channels based on your consent and communication preferences.
3. For Billing, Payments, and Administrative Functions:
Your information may be used to process payments securely, verify your eligibility for specific services or promotions, manage billing records, and maintain financial documentation for compliance and auditing purposes. All transactions are handled through PCI-DSS–compliant third-party processors to ensure data security.
4. To Improve and Optimize Our Platform:
We analyze how you interact with our website and services to enhance performance, user experience, and service quality. This includes troubleshooting technical issues, developing new features, and using aggregated or de-identified data to improve our telehealth programs and wellness offerings.
5. To Comply with Legal and Regulatory Obligations:
We retain and process certain information to comply with HIPAA requirements, medical licensing laws, and pharmacy regulations. This may include maintaining audit logs, consent forms, and other documentation. We may also disclose information when required by law, regulation, or court order, or to respond to authorized government requests.
6. To Maintain Security and Prevent Fraud:
We use information to detect, investigate, and prevent unauthorized access, fraudulent activity, or misuse of our services. This includes monitoring platform activity, enforcing our Terms of Service, and ensuring data protection through encryption, authentication, and system monitoring.
7. For Marketing and Educational Purposes (With Consent):
With your consent, we may send newsletters, updates about new services, promotions, and wellness-related educational materials. You can opt out of receiving marketing communications at any time by following the unsubscribe instructions in our emails or contacting us directly.
8. For Research and Analytics:
We may use de-identified or aggregated data for internal research, analytics, quality improvement, or public health reporting in accordance with HIPAA. This information does not identify you personally and is used only to evaluate and enhance the effectiveness of our programs and patient outcomes.
4. Disclosure of Your Information
We may disclose Personal Information and Protected Health Information (“PHI”) that we collect or that you provide, as described in this Privacy Policy, in accordance with HIPAA, applicable state laws, and other relevant privacy regulations. The following outlines how and when your information may be shared:
We may disclose information for treatment, payment, and healthcare operations purposes, including to licensed physicians, clinicians, and healthcare entities involved in your care through our partner Openloop, or to affiliated compounding pharmacies and laboratories that assist in medication fulfillment and diagnostic services.
We may share information with service providers and vendors that support our operations. These include companies that assist with platform hosting, data security, communication tools, payment processing, IT support, analytics, and marketing services. All such entities are required to comply with strict confidentiality and data protection obligations under Business Associate Agreements (BAAs) where applicable.
We may disclose your information to medical providers and healthcare professionals involved in your treatment plan, including physicians, pharmacists, and care coordinators who may review your health information to ensure safe and effective care. This includes sharing relevant health data, prescriptions, or communications necessary to manage your treatment.
We may share your information with our affiliates, employees, or other third parties who perform services on behalf of Vaylen or its affiliated professional entities, for operational or administrative purposes. This ensures continuity of care, platform maintenance, and compliance with professional standards.
We may disclose your information to fulfill the purpose for which it was provided. For example, if you submit a request for consultation or prescription services, your information will be shared with licensed providers or pharmacies to deliver those services.
We may share limited payment information with third-party credit card processors or financial institutions through secure, encrypted connections solely to process authorized payments or refunds.
We may disclose information as required by law or legal obligation, including to comply with subpoenas, court orders, government requests, or applicable regulatory requirements. This may include sharing information with authorities for public health reporting, fraud prevention, or law enforcement purposes where legally permitted.
We may share information to protect the rights, property, or safety of Vaylen, our patients, affiliates, or others, such as for fraud prevention, cybersecurity protection, or credit risk reduction.
We may disclose de-identified or aggregated information that cannot reasonably identify you, for any lawful purpose, including research, analytics, and service improvement. Such information is not considered Personal Information under this Privacy Policy.
We may disclose your information to entities that assist us with marketing, outreach, or communication, provided such sharing complies with applicable laws and your consent preferences.
We may share information with your consent or at your direction, including disclosures to family members, caregivers, or other individuals you authorize to receive your information.
Finally, in the event of a merger, acquisition, sale, restructuring, reorganization, or transfer of assets, your information may be transferred to the acquiring or successor entity as part of that transaction, subject to the same privacy obligations described in this Policy.
All disclosures are made only to the extent necessary and in compliance with applicable privacy, medical, and data protection laws, ensuring your information remains protected and confidential.
5. Data Security and Protection
We use measures designed to reasonably protect your Personal and Health Information from loss, unauthorized access, use, alteration, or disclosure. All data sent between your device and our platform is encrypted to keep your information safe. Access to this data is limited to authorized personnel who need it to provide services.
If you are given (or choose) a password to access certain areas of the platform, you are responsible for keeping it confidential and should not share it with anyone. Information shared in public areas may be viewed by any user.
While we work hard to protect your data, no online transmission is completely secure. We cannot guarantee the security of information sent to our platform, and any transmission is at your own risk.
When using our platform, there is a possibility that your health information may be stored unencrypted on your device. We use various safeguards to prevent this, but we cannot guarantee that these measures will always work.
6. What You Can Do to Protect Your Information
Your cooperation is essential in maintaining your account’s security. Choose a strong, unique password and do not share it with anyone. Always log out after using shared or public devices and avoid saving login credentials on unsecured devices.
If you suspect that someone has accessed your account or that your password or personal information has been compromised, contact us immediately at privacy@vaylenhealth.com.
You may also receive emails from Vaylen that include treatment or account details. Please safeguard your designated email address and ensure only you have access to it to prevent unauthorized viewing of sensitive information.
7. Data Retention and Storage
Vaylen retains your Personal Information and Protected Health Information (PHI) only for as long as necessary to provide our services, comply with legal or regulatory requirements, and fulfill the purposes outlined in this Privacy Policy.
All information is stored in secure, HIPAA-compliant data centers located within the United States. These facilities use strict access controls, encryption, and continuous monitoring to protect data from unauthorized access or loss.
When data is no longer required, it is securely deleted or anonymized in accordance with applicable federal and state laws, as well as industry best practices. This ensures that your information cannot be reconstructed or used once it is no longer needed.
If you request deletion of your account or data, Vaylen will take reasonable steps to remove your information, except where retention is required by law, for dispute resolution, or for legitimate business purposes such as maintaining medical records or financial documentation.
Regular reviews of our storage and retention practices are conducted to ensure ongoing compliance with HIPAA and applicable data protection standards.
8. Your Rights and Choices
You have certain rights regarding your Personal Information and Protected Health Information (PHI), as provided under HIPAA and applicable privacy laws. Vaylen is committed to helping you exercise these rights easily and transparently.
1. Access and Review: You may request a copy of your Personal Information or PHI that we maintain. This allows you to review and verify the accuracy of your records.
2. Correction and Updates: If you believe any of your information is incomplete or inaccurate, you can request that we correct or update it.
3. Deletion: You may request that we delete your Personal Information or deactivate your account. However, certain information may be retained where required by law or necessary for ongoing healthcare or compliance obligations.
4. Restriction of Use: You may request that we limit how your PHI is used or disclosed, though this may affect our ability to provide services in some cases.
5. Data Portability: You can request that your information be provided to you or transferred to another healthcare provider in a structured, commonly used, and machine-readable format.
6. Withdrawal of Consent: If you previously consented to specific uses or disclosures of your data, you can withdraw your consent at any time by contacting us.
7. Communication Preferences: You may choose how we contact you (e.g., via email, SMS, or phone) and opt out of non-essential communications such as marketing messages.
To exercise any of these rights or submit a privacy-related request, please contact us at privacy@vaylen.com. For your security, we may need to verify your identity before processing your request.
9. Third-Party Links and Services
Our Platform may contain links to third-party websites, applications, or services that are not operated or controlled by Vaylen. These links are provided for your convenience and may include connections to healthcare partners, payment processors, pharmacies, or other external service providers.
Please note that once you leave our Platform or interact with third-party features (such as external scheduling tools or payment gateways), their privacy practices will apply, not ours. We do not control and are not responsible for the content, privacy policies, or practices of these third-party sites or services. We encourage you to carefully review the privacy policies and terms of any third-party service before providing your Personal Information or PHI.
Vaylen may also integrate with third-party APIs or tools to enhance user experience, such as secure payment gateways, telehealth providers, or prescription services. These third parties are carefully vetted and required to adhere to data protection and confidentiality standards consistent with applicable laws.
However, we cannot guarantee the security or privacy of information you share directly with these external providers. Your use of such services is entirely at your discretion and subject to the terms set forth by those third parties.
10. Information We Collect with Cookies
Through VaylenHealth.com, we and authorized third parties may collect information from your computer or mobile device using automated tools such as cookies and local storage. This helps us enhance the functionality, performance, and security of our Platform, as well as improve your overall user experience.
The information collected through these technologies may include unique browser identifiers, IP address, browser type, operating system details, device identifiers (including advertising IDs), Internet connection information, and interaction details such as pages visited, links clicked, and referral URLs. In some cases, these technologies involve storing unique identifiers or other data on your device for later recognition.
11. Children’s Privacy
Vaylen’s Platform and services are not intended for children under the age of 18, and we do not knowingly collect Personal Information or Protected Health Information (“PHI”) from minors. If you are under 18, please do not use our Platform or provide any personal details.
If we become aware that we have inadvertently collected information from a child under 18 without proper parental or guardian consent, we will promptly delete such information from our systems.
12. Changes to This Privacy Policy
We may update or modify our Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other operational reasons. When we make changes, we will post the updated version on this page and update the “Last Updated” date at the top of the Policy.
In cases where the changes are material, such as updates that affect how we use or share your Personal Information or Protected Health Information (“PHI”), we will provide additional notice, which may include email notification, in-app alerts, or website banners, as required by law.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our Platform and services after any updates signifies your acceptance of the revised terms.
13. Contact Information
If you have any questions, concerns, or complaints about this Privacy Policy, our privacy practices, or your rights regarding your Personal Information or Protected Health Information (“PHI”), please contact us using the information below:
Vaylen Health Service
317 6th Ave.
Des Moines, IA 50309