Legal
Privacy Policy
Last updated 7 June 2026
This is a starting template prepared for the practice. It should be reviewed and finalized by legal counsel before launch to ensure it reflects Rivē Lume's actual data practices and complies with applicable law (including New York State requirements and, where relevant, HIPAA).
Rivē Lume ("we," "us," or "our") is a physician-led concierge medical aesthetics and wellness practice serving Brooklyn and greater New York. This policy explains how we handle information collected through this website, rivelume.com.
Scope of this policy
This policy covers only the public marketing website. The website is not a patient portal and does not request or store protected health information (PHI). Clinical care, medical records, and any PHI are handled separately under our clinical privacy practices and the HIPAA Notice of Privacy Practices.
Information we collect
When you use the enquiry form, you may choose to provide:
- Your name and email address (required to reply to you)
- A phone number and borough (optional)
- A short free-text note describing what you are considering (optional)
Please do not include medical history, diagnoses, or other sensitive health details in the enquiry note. We also receive limited technical information that our hosting and security provider processes automatically (such as IP address and basic request data) to deliver and protect the site.
How we use information
- To respond to your enquiry and arrange a consultation if appropriate
- To operate, secure, and maintain the website
- To comply with legal obligations
We do not sell your information, and we do not add you to marketing lists without your consent.
Sharing and service providers
We share information only with service providers that help us run the site, under terms that limit their use of it:
- Cloudflare — website hosting, content delivery, security, and bot protection (Turnstile).
- Resend — delivery of the enquiry email to our inbox.
We may disclose information if required by law or to protect the rights, safety, and security of the practice and others.
Retention
Enquiry messages are retained in our email inbox for as long as needed to respond and maintain our records, and then deleted in accordance with our internal retention practices. The website itself does not maintain a separate database of submissions.
Your choices and rights
You may request access to, correction of, or deletion of the enquiry information you sent us by emailing us at the address below. Depending on your state of residence, you may have additional rights regarding your personal information.
Security
We use industry-standard measures — including TLS encryption in transit and reputable processors — to protect information submitted through the site. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
Children's privacy
The website is intended for adults. We do not knowingly collect information from anyone under 18 through this site.
Changes to this policy
We may update this policy from time to time. The "last updated" date above reflects the most recent revision.
Contact
Questions about this policy may be directed to enquiries@rivelume.com.