Your privacy is important to us at Wizlo. We respect your privacy regarding any information we may collect from you across our website.
Wizlo, Inc. ("Wizlo," "we," "our," or "us") respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard information—including phone numbers and SMS consent data—when you interact with our website, applications, products, and services (collectively, the "Services").
Our Services are designed for healthcare providers and their patients and comply with applicable privacy laws and industry regulations, including the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Telephone Consumer Protection Act ("TCPA"), the Controlling the Assault of Non-Solicited Pornography and Marketing ("CAN-SPAM") Act, and relevant state privacy statutes.
This Policy applies to information we process:
We collect names, business names, email addresses, mailing addresses, payment details, clinic identifiers, and other information required to create and support your account.
Our systems automatically log IP addresses, browser types, device identifiers, referral URLs, pages viewed, and interactions with the Services.
To enable text messaging, we capture and store:
We use the information we collect to:
Phone numbers and associated SMS consent records are used exclusively to deliver text messages for the campaign or purpose disclosed at the time of opt-in. We do not use phone numbers obtained for transactional messaging to send marketing without a separate, explicit consent.
We do not sell or rent personal information—including phone numbers or SMS consent data—to third parties. We share information only as described below:
You agree to use the Services only for lawful, clinical, and administrative purposes. You may not:
| Category | Purpose of Sharing |
|---|---|
| Twilio. (SMS application provider) | Message orchestration and customer-support chat services |
| Telecommunication carriers and downstream SMS aggregators | Message orchestration and customer-support chat services |
| Infrastructure & cloud providers (e.g., AWS) | Hosting, storage, disaster recovery |
| Sub-processors under HIPAA Business Associate Agreements | E-prescribing, payment processing, analytics |
| Compliance & law-enforcement authorities | When legally required or to protect rights, property, or safety |
We retain phone numbers, SMS consent data, and message logs for as long as needed to (i) fulfill the purposes outlined in this Policy, (ii) comply with legal or contractual obligations, and (iii) maintain audit trails required under HIPAA or carrier regulations. When data is no longer required, we delete or de-identify it according to industry best practices.
Wizlo employs administrative, technical, and physical safeguards aligned with NIST SP 800-53 and HIPAA requirements, including encryption in transit and at rest, role-based access controls, multi-factor authentication, and continuous monitoring.
Under HIPAA, Wizlo acts as a Business Associate to healthcare providers. We sign Business Associate Agreements (BAAs), implement the required safeguards, and limit the use and disclosure of PHI to what is permitted under those BAAs.
For users in the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses or Data Processing Agreements to safeguard cross-border transfers.
Our Services are not directed to children under 13. We do not knowingly collect personal information from children without verifiable parental consent.
Depending on your location, you may have rights to access, correct, delete, or restrict the processing of your personal information. To exercise these rights, contact privacy@wizlo.com.
We may update this Privacy Policy from time to time. Material changes will be communicated via an in-app notification or email. Continued use of the Services after an update signifies acceptance of the revised Policy.
We may modify the Services or these Terms at any time. Material changes will be posted in-app or emailed to account administrators. Continued use after the effective date constitutes acceptance of the revised Terms.
These Terms are governed by the laws of the State of Nevada, excluding conflict-of-laws principles. Any dispute shall be resolved by binding arbitration in Las Vegas, Nevada, under the rules of the American Arbitration Association. Either party may seek injunctive relief in a court of competent jurisdiction.
If you have questions about this Privacy Policy, SMS practices, or our privacy and security program, please contact: