Privacy Policy
Last updated August 2026
1. Introduction
Iris Telehealth, Inc. (“Iris Telehealth,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy describes how we collect, use, disclose, and protect personal information in connection with our marketing website located at iristelehealth.com and any other websites, web pages, or online services that link to this Privacy Policy (collectively, the “Site”).
By accessing or using the Site, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Site.
2. Scope of This Policy
This Privacy Policy applies only to information collected through the Site. It does not apply to:
- Protected Health Information (“PHI”) that Iris Telehealth processes on behalf of a healthcare partner (such as a hospital, health system, FQHC, CCBHC, or community mental health center) under a Business Associate Agreement. PHI is governed by the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and the Notice of Privacy Practices issued by the applicable Covered Entity.
- Information collected through clinical platforms, electronic health records, video visit applications, or other tools used by our partners and their patients. Those tools are governed by the privacy notices and agreements provided by the applicable partner or platform.
- Information we collect from clinicians employed by or contracted with Iris Telehealth in their employment or contracting capacity, which is governed by separate workforce notices.
- Information collected by third-party websites or services linked from the Site. We are not responsible for the privacy practices of third parties.
Iris Telehealth operates as a Business Associate, not a Covered Entity, with respect to PHI processed on behalf of healthcare partners. Patients should refer to their healthcare provider’s Notice of Privacy Practices for information about how their PHI is used and disclosed.
3. Information We Collect
3.1 Information You Provide
We collect information you provide directly when you interact with the Site, including when you complete a contact form, request a demo, subscribe to newsletters or our Insights Center, register for an event or webinar, apply for a position, or otherwise communicate with us. This information may include:
- Name, job title, employer or organization name, and professional credentials
- Business email address, business telephone number, and mailing address
- Information about your role, organization type (e.g., health system, FQHC, CCBHC), and areas of interest in our services
- Resume, CV, employment history, and other information submitted through career applications
Any other information you choose to provide in free-text fields, attachments, or correspondence
3.2 Information Collected Automatically
When you visit the Site, we and our service providers automatically collect certain information about your device and how you interact with the Site, including:
- Device and browser information (device type, operating system, browser type and version, language settings, screen resolution)
- Network information (IP address, internet service provider, approximate geographic location derived from IP address)
- Usage information (pages visited, time spent on pages, links clicked, referring and exit URLs, dates and times of access)
- Form interaction data (fields completed, time spent on forms, submission events) collected through our marketing automation platform (Salesforce Marketing Cloud Account Engagement, formerly Pardot)
- Information collected through cookies, web beacons, pixels, tags, and similar tracking technologies (see Section 7)
3.3 Information from Third-Party Sources
We may receive information about you from third-party sources to help us identify potential customers, verify professional credentials, enrich account records, and improve our marketing. These sources may include:
- Business contact data providers (such as ZoomInfo) that supply professional contact and firmographic information
- Marketing and advertising partners, including LinkedIn, that provide audience data and engagement metrics
- Conference, event, and webinar partners and platforms (such as Becker’s Healthcare, NatCon, Millennium Alliance, Modern Healthcare) where you have provided your information
- Professional credentialing and licensing databases for clinician recruitment purposes
- Publicly available sources, including professional networking sites, public directories, and government records
4. How We Use Information
We use personal information collected through the Site for the following purposes:
- To respond to inquiries, provide requested information, and schedule and conduct demos
- To send marketing communications, newsletters, and event invitations consistent with your preferences and applicable law
- To evaluate job applications and contact applicants
- To operate, maintain, secure, and improve the Site and our marketing programs
- To analyze website usage, measure marketing campaign performance, and conduct research and analytics
- To personalize your experience on the Site and tailor content and offers to your interests
- To enforce our terms, protect our rights, prevent fraud, and comply with legal obligations
- To facilitate business transactions such as financing, mergers, acquisitions, or sales of assets
5. How We Share Information
We do not sell personal information for monetary consideration. We may share personal information in the following circumstances:
5.1 Service Providers
We share personal information with vendors and service providers that perform services on our behalf and are contractually obligated to protect that information and use it only for the purposes we direct. These include providers of:
• Marketing automation, customer relationship management, and email delivery (e.g., Salesforce, Pardot)
- Website hosting, content delivery, and performance optimization
- Analytics and tag management (e.g., Google Analytics, Google Tag Manager)
- Business contact data and account intelligence (e.g., ZoomInfo)
- Advertising and social media platforms (e.g., LinkedIn, Meta, Google Ads)
- Event registration, webinar, and conference platforms
- Applicant tracking and recruitment
- IT, security, and professional services (legal, accounting, audit)
5.2 Affiliates
We may share personal information with current and future affiliated entities for purposes consistent with this Privacy Policy.
5.3 Legal and Safety
We may disclose personal information when we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, court order, subpoena, or other legal process
- Cooperate with law enforcement or government authorities
- Enforce our terms of use or other agreements
- Protect the rights, property, or safety of Iris Telehealth, our partners, our employees, our users, or the public
5.4 Business Transfers
If Iris Telehealth is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, personal information may be transferred as part of that transaction, subject to standard confidentiality protections.
5.5 With Your Consent
We may share personal information for any other purpose with your consent or at your direction.
6. HIPAA and Protected Health Information
Iris Telehealth provides telebehavioral health services to healthcare partners under written agreements that include, where required, a HIPAA Business Associate Agreement. PHI received, created, maintained, or transmitted by Iris Telehealth on behalf of a Covered Entity is handled in accordance with HIPAA, HITECH, the applicable Business Associate Agreement, and our internal HIPAA policies and procedures, including administrative, physical, and technical safeguards under 45 CFR Part 164.
This Privacy Policy does not modify or supersede any Business Associate Agreement, and patients should refer to the Notice of Privacy Practices issued by their healthcare provider for information about how their PHI is used and disclosed in the course of treatment.
7. Cookies and Tracking Technologies
We and our service providers use cookies and similar tracking technologies to operate the Site, analyze usage, deliver relevant marketing, and remember your preferences. These technologies include:
- Strictly necessary cookies, which are required for the Site to function
- Performance and analytics cookies (such as Google Analytics), which help us
- understand how visitors use the Site
- Functional cookies, which remember your preferences and choices
- Advertising and targeting cookies, which help deliver relevant advertising on the Site and on third-party platforms (including LinkedIn and other social media), and measure the effectiveness of those campaigns
You can manage cookies through your browser settings, the cookie banner provided on the Site, and opt-out tools provided by third parties (for example, the Google Analytics opt-out browser add-on, Network Advertising Initiative opt-out, and Digital Advertising Alliance opt-out tools). Disabling certain cookies may affect Site functionality.
8. Do Not Track and Global Privacy Control
Some browsers transmit “Do Not Track” signals. There is no consensus industry standard for responding to those signals, and we do not currently respond to Do Not Track signals. Where required by applicable law, we honor recognized opt-out preference signals such as the Global Privacy Control (GPC) for users in jurisdictions that legally recognize them.
9. Your Privacy Rights
9.1 General Rights
Depending on where you live, you may have rights with respect to your personal information, including the right to:
- Request access to the personal information we hold about you
- Request correction of inaccurate personal information
- Request deletion of personal information, subject to certain exceptions
- Request a portable copy of certain personal information
- Opt out of marketing communications by following the unsubscribe instructions in any email we send or by contacting us
- Opt out of certain uses or disclosures of personal information, including for targeted advertising
- Limit the use and disclosure of sensitive personal information
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
9.2 California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), provides specific rights regarding personal information. Note that personal information collected, processed, or disclosed pursuant to HIPAA or the California Confidentiality of Medical Information Act is exempt from the CCPA. Subject to that exemption, California residents have the right to:
- Know what categories and specific pieces of personal information we collect, use, disclose, and (if applicable) sell or share
- Request deletion of personal information, subject to exceptions
- Request correction of inaccurate personal information
- Opt out of the “sale” or “sharing” of personal information for cross-context behavioral advertising
- Limit the use and disclosure of sensitive personal information
- Not be discriminated against for exercising these rights
We do not sell personal information for monetary consideration. However, the use of certain advertising and analytics cookies on the Site may be considered a “sale” or “sharing” under the broad definitions in the CCPA. To opt out, please use the cookie preferences tool on the Site or contact us using the information in Section 13.
To exercise your CCPA rights, submit a verifiable consumer request using the contact information in Section 13. We will verify your identity before responding to most requests. You may designate an authorized agent to make a request on your behalf in accordance with CCPA requirements.
9.3 Other US State Privacy Rights
Residents of other US states with comprehensive privacy laws — including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — may have rights similar to those described above, subject to each state’s specific requirements and exceptions (including, in most cases, an exemption for HIPAA-regulated information). To exercise your rights, contact us using the information in Section 13.
9.4 How to Exercise Your Rights
To exercise any of the rights described in this section, contact us at privacy@iristelehealth.com or using the information in Section 13. We will respond within the time periods required by applicable law. We may need to verify your identity before fulfilling your request and may decline requests in limited circumstances permitted by law. We will not discriminate or retaliate against you for exercising your privacy rights.
10. Data Security
We maintain administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, and destruction. These safeguards include access controls, encryption of data in transit and at rest where appropriate, employee training, and ongoing monitoring of our systems. No method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.
In the event of a security incident affecting personal information, we will notify affected individuals and applicable regulatory authorities as required by law and, where applicable, in accordance with our obligations under HIPAA, HITECH, and state breach notification laws.
11. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods vary based on the type of information, the purpose of collection, and applicable legal requirements. When personal information is no longer needed, we will securely delete or anonymize it.
12. Children’s Privacy
The Site is intended for a business and professional audience and is not directed to children. We do not knowingly collect personal information from children under the age of 13 (or under 16 in jurisdictions where applicable law sets that threshold). If we learn that we have collected personal information from a child without appropriate consent, we will delete that information. If you believe a child has provided personal information to us, please contact us using the information in Section 13.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, or if you wish to exercise your privacy rights, please contact us:
Iris Telehealth, Inc.
Attn: Privacy Office
Email: privacy@iristelehealth.com
If you believe Iris Telehealth has misused your information, please contact us promptly so we can investigate and respond.
14. International Visitors
The Site is intended for users in the United States. If you access the Site from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country. By using the Site, you consent to this transfer and processing.
15. Third-Party Links
The Site may contain links to third-party websites, content, or services. We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies before providing them with personal information.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the “Last Updated” date at the top of this page and, where appropriate, provide additional notice through the Site or by other means. Your continued use of the Site after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.