Privacy Policy – Your Data Protection Rights
Your health information deserves the highest level of protection. At Wellspring Haven, we are committed to safeguarding your privacy while delivering personalized wellness services that empower your journey.
This Privacy Policy was last updated on November 15, 2023. We recommend reviewing this policy periodically for any changes. Should significant updates occur, we will notify you through prominent notices on our website or via email.

Our Commitment to Your Privacy
-
Minimal Data Collection: We collect only the information essential for delivering our services effectively and enhancing your user experience, nothing more.
-
HIPAA-Compliant Safeguards: For all health-related information, we adhere strictly to HIPAA guidelines, ensuring robust security and confidentiality.
-
Continuous Improvement: Our privacy practices and security measures undergo regular audits and reviews to ensure they meet the highest standards.
Your Rights Under Privacy Regulations
As a user of Wellspring Haven, you have specific rights regarding your personal data. We are here to help you exercise them:
-
Access: Request copies of the personal data we hold about you.
-
Rectification: Ask us to correct any inaccurate or incomplete information.
-
Erasure: Request the deletion of your personal data under certain conditions.
-
Restriction: Request that we restrict the processing of your data under certain conditions.
-
Portability: Request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
-
Objection: Object to our processing of your personal data, under certain conditions.
For any privacy-related questions or to exercise your rights, please contact our Data Protection Officer at [email protected].
What Information We Collect and How We Use It
Wellspring Haven is designed to provide you with a personalized and effective wellness experience. To achieve this, we collect certain types of information, always with your privacy in mind.
Personal Information
This includes data you directly provide to us when you create an account, purchase services, or contact us. This may include your name, email address, phone number, and billing details. This information helps us manage your account and communicate with you.
Retention: As long as your account is active, or as required by law.
Usage Data
When you visit our website or use our services, we automatically collect data such as your IP address, browser type, pages visited, and time spent on site. This helps us understand how our services are used, allowing for continuous improvement of our platform and user experience.
Retention: Typically 12-24 months for analytics, anonymized afterward.
Health Information
This sensitive data is directly related to your wellness journey, including responses to health assessments, consultation notes, and progress tracking data. This information is crucial for providing personalized recommendations and expert guidance. All health information is collected with explicit consent and protected under stringent HIPAA-compliant measures.
Retention: Governed by HIPAA and clinical record-keeping requirements.

How We Protect Your Information
At Wellspring Haven, the security of your data is paramount. We employ a multi-layered approach to protect your information from unauthorized access, disclosure, alteration, and destruction.
Technical Safeguards
State-of-the-art encryption (TLS/SSL) for all data in transit and at rest, secure servers, robust firewalls, and stringent access controls ensure digital security.
Administrative Safeguards
Comprehensive staff training on privacy protocols, strict access limitations based on need-to-know, and regular privacy policy reviews reinforce our commitment.
Physical Safeguards
Secure facilities, restricted access to hardware, and defined protocols for secure disposal of sensitive information protect against physical breaches.
HIPAA Compliance & Continuous Vigilance
We are fully HIPAA compliant, upholding the highest standards for protected health information (PHI). Our security framework includes:
Regular Security Audits
Vulnerability Assessments
Incident Response Plans
In the unlikely event of a data breach, we have clear notification policies in place to inform affected individuals promptly and transparently.
Your Privacy Choices and Controls
Wellspring Haven empowers you with extensive control over your personal data. Your preferences matter, and we provide clear mechanisms to manage how your information is used.

Third-Party Sharing and Service Providers
Wellspring Haven partners with trusted third-party service providers to deliver and improve our services. We share your data only when necessary and always under strict confidentiality agreements.
Service Providers
We engage third parties for critical functions such as secure payment processing (e.g., Stripe, PayPal), email delivery (e.g., Mailchimp, SendGrid), and website analytics (e.g., Google Analytics). These providers are contractually bound to protect your data and use it only for the purposes agreed upon.
We only use providers that adhere to high data protection standards.
Healthcare Partners
For certain specialized services, such as lab testing or specialist consultations, we may facilitate secure data sharing with trusted healthcare partners. This is always done with your explicit consent and within a HIPAA-compliant framework to ensure continuity of care and the best health outcomes for you. You will be clearly informed before any such sharing occurs.
Your consent is always required for sharing with healthcare partners.
Legal & Business Requirements
We may disclose your information if required by law, court order, or governmental regulation, or if necessary to protect the rights, property, or safety of Wellspring Haven, our users, or the public. In the event of a merger, acquisition, or asset sale, your data may be transferred to the new entity, with prior notification and continued privacy protections.
Disclosures are strictly limited to legal or critical business necessities.

Contact Us About Your Privacy
Your privacy is our priority. If you have any questions, concerns, or wish to exercise your data protection rights, please do not hesitate to reach out.
Get in Touch Directly
Our dedicated Data Protection Officer is available to assist you.
- Email: [email protected]
- Phone: (512) 678-9012
- Address: 2847 Cedar Ridge Drive, Suite 450, Austin, TX, 78759, USA
We aim to respond to all privacy inquiries within 5 business days.
Data Protection Authority
If you believe your privacy rights have been infringed, you have the right to lodge a complaint with a supervisory authority.
Austin Regional Office for Consumer Protection
(Contact details available upon direct request for specific legal guidance)
Learn More About Your Rights (Texas OAG)