Effective date: 6/29/2026 | Last updated: 7/1/2026
This Privacy Policy describes how Red Spot Interactive, LLC ("RSI," "we," "us," or "our") collects, uses, shares, and protects information across two contexts: (1) visitors and prospects who interact with our public website and marketing materials, and (2) healthcare practices and their patients who use the RSI platform under a signed agreement.RSI operates as a HIPAA Business Associate for its healthcare practice clients. Protected Health Information (PHI) processed on behalf of those clients is governed by our Business Associate Agreement (BAA) with each client and by applicable HIPAA regulations — not solely by this policy. See Section 5 for details.This policy does not constitute legal advice. RSI recommends that healthcare practices consult qualified legal counsel regarding their own HIPAA obligations.
01 — Scope & Who This Policy Covers
This Privacy Policy applies to:Website visitors and prospects who access www.redspotinteractive.com or any RSI marketing page, complete a contact form, request a demo, or otherwise engage with RSI's marketing and sales activities.Client practice administrators and staff who access RSI's platform under a signed Master Service Agreement (MSA) and Business Associate Agreement (BAA).Patients of RSI's healthcare practice clients, to the extent their information is processed within the RSI platform at the direction of their healthcare provider.This policy does not apply to RSI employees or contractors, who are subject to separate internal data handling policies.
02 — Information We Collect
Information you provide directlyContact & inquiry information: Name, email address, phone number, job title, practice name, and any message content submitted via contact forms, demo requests, audit requests, or email correspondence.Account credentials (platform users): Username, hashed password, and account profile information for RSI platform users (practice staff and administrators).Payment information: Billing contact details and payment method information processed through our third-party payment processor. RSI does not store full credit card numbers on its systems.Information collected automaticallyUsage and log data: IP address, browser type and version, operating system, referring URL, pages viewed, time on page, and other standard web server log data.Cookies and similar technologies: Session cookies, persistent cookies, and analytics pixels. See Section 6 for details.Platform usage data (client context): Feature usage, workflow activity, system performance logs, and audit trail data generated by platform users within the RSI CRM environment.Information received from third partiesPractice management system (PMS) data: Patient scheduling, appointment, and demographic data received via bidirectional integration with client-authorized PMS platforms (including ModMed, Nextech, AdvancedMD, and others), processed solely at the direction of the healthcare practice client.Marketing analytics data: Aggregated and anonymized advertising performance data from authorized platforms (such as Google Ads and Meta Ads) connected by the healthcare practice client for marketing ROI tracking.
03 — How We Use Information
For website visitors and prospectsRespond to inquiries, demo requests, and audit requests.Send marketing communications where you have opted in or where a legitimate interest exists under applicable law.Analyze website usage to improve performance, content, and user experience.Detect, investigate, and prevent fraudulent or unauthorized activity.Comply with legal obligations.For healthcare practice clients and their patientsProvide, operate, and maintain the RSI platform and all contracted services.Process patient communications (appointment reminders, recall campaigns, scheduling confirmations) as directed by the healthcare practice client.Generate analytics, dashboards, and ROI reporting as configured by the practice.Provide technical support, onboarding, and customer success services.Fulfill obligations under our MSA and BAA with each client.Maintain platform security, audit logs, and HIPAA-required access controls.RSI does not sell personal information or use patient data for RSI's own marketing purposes.
04 — How We Share Information
RSI does not sell, rent, or trade personal information. We share information only in the following circumstances.Service providers and subprocessors: RSI engages third-party vendors to support platform operations, including cloud hosting, telephony (such as Twilio and RingCentral), email delivery, payment processing, and analytics. These vendors are contractually required to process data only as directed by RSI and to maintain appropriate security standards. Vendors that may access PHI on behalf of RSI's healthcare clients are subject to a subprocessor Business Associate Agreement (BAA).Healthcare practice clients: Patient data processed within the RSI platform is made available to the healthcare practice that is RSI's contracted client and that acts as the HIPAA Covered Entity for that patient relationship. RSI processes this data solely as a Business Associate at the direction of the practice.Practice management system integrations: With client authorization, RSI exchanges data bidirectionally with client-selected PMS platforms (such as ModMed, Nextech, and AdvancedMD). These integrations are configured and controlled by the client practice.Legal and safety disclosures: RSI may disclose information if required by law, regulation, court order, or governmental authority, or to protect the safety, rights, or property of RSI, its clients, or the public.Business transfers: In the event of a merger, acquisition, or sale of all or substantially all of RSI's assets, personal information may be transferred as part of that transaction. RSI will provide notice of any such transfer and the choices available to affected individuals.
05 — HIPAA & Protected Health Information
RSI is a HIPAA Business Associate. When RSI processes Protected Health Information (PHI) on behalf of a healthcare practice client, that processing is governed by the Business Associate Agreement (BAA) executed between RSI and the client, and by the HIPAA Privacy Rule (45 C.F.R. Part 164) and Security Rule.What this means in practice:RSI accesses and processes PHI only as permitted or required by the applicable BAA and HIPAA regulations.RSI does not use or disclose PHI for purposes other than those specified in the BAA and permitted by HIPAA.RSI implements and maintains administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI (ePHI) in accordance with the HIPAA Security Rule (45 C.F.R. §§ 164.302–318).RSI maintains HIPAA-required audit logs of access to ePHI in accordance with 45 C.F.R. § 164.312(b).RSI will report to the relevant client any Breach of Unsecured PHI, as defined under 45 C.F.R. § 164.402, in accordance with the timeline and procedures specified in the BAA and under 45 C.F.R. § 164.410.RSI executes BAAs with subcontractors and vendors that handle ePHI on RSI's behalf.Patient rights under HIPAA: Patients have rights with respect to their PHI under HIPAA, including the right to access, amend, and receive an accounting of disclosures. These rights must be exercised through the patient's healthcare provider (the Covered Entity), not directly through RSI. Patients should contact their healthcare practice directly with any PHI-related requests.SMS and patient communication: RSI's platform enables healthcare practices to communicate with patients via SMS. PHI is not transmitted in SMS message bodies. Where sensitive appointment or clinical information must be shared, RSI uses a secure link handoff pattern that directs the patient to an authenticated, encrypted session. All SMS communications require prior patient consent consistent with applicable HIPAA and TCPA requirements.
06 — Cookies & Tracking Technologies
RSI's public website uses the following categories of cookies and tracking technologies:Strictly necessary cookies: Required for the website to function (session management, security). These cannot be disabled.Analytics cookies: Used to understand how visitors interact with the website (e.g., Google Analytics). Data is aggregated and anonymized. You may opt out by adjusting your browser settings or using the Google Analytics opt-out browser add-on.Marketing and advertising cookies: May be set by third-party platforms (such as Google Ads or Meta Pixel) to measure campaign performance at the direction of RSI's marketing team. These are used only for RSI's own marketing measurement and are not shared with RSI's healthcare practice clients for patient targeting.You can control cookie preferences through your browser settings. Disabling certain cookies may affect website functionality. RSI does not currently respond to browser Do Not Track (DNT) signals but does honor opt-out requests made through cookie preference controls where available.
07 — Data Security
RSI implements administrative, technical, and physical safeguards to protect personal information and ePHI from unauthorized access, disclosure, alteration, and destruction. Our security program includes:Encryption of data in transit (TLS) and at rest.Role-based access controls and least-privilege access principles.Multi-factor authentication for platform access.Session timeout policies and automatic logoff for inactive sessions.Audit logging of access to ePHI and system events.Vulnerability management and regular security assessments.Employee security training and acceptable use policies.Incident response and breach notification procedures.No method of transmission over the internet or electronic storage is 100% secure. RSI cannot guarantee absolute security, but we are committed to maintaining industry-standard protections and notifying affected parties promptly in the event of a confirmed breach.
08 — Data Retention
RSI retains personal information for as long as necessary to fulfill the purposes described in this policy, to comply with legal and contractual obligations, and to resolve disputes.Website visitor and prospect data is retained for as long as needed to manage the business relationship and comply with applicable marketing and communications laws.Platform user account data is retained for the duration of the client's active agreement with RSI, plus any period required by the BAA or applicable law.PHI processed on behalf of clients is retained and disposed of in accordance with the terms of each BAA and applicable HIPAA requirements. RSI does not retain PHI beyond the period specified in the BAA without explicit client authorization.Audit logs are retained for a minimum of six years in accordance with HIPAA requirements (45 C.F.R. § 164.530(j)).
09 — California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information.Your rights under California law:Right to know: You may request disclosure of the categories and specific pieces of personal information RSI has collected about you, the sources of that information, the business purposes for collection, and the categories of third parties with whom RSI shares it.Right to delete: You may request deletion of personal information RSI has collected about you, subject to certain exceptions permitted by law.Right to correct: You may request correction of inaccurate personal information RSI holds about you.Right to opt out of sale or sharing: RSI does not sell personal information, and does not share personal information for cross-context behavioral advertising purposes.Right to limit use of sensitive personal information: RSI does not use sensitive personal information for purposes beyond those permitted by the CPRA without your consent.Right to non-discrimination: RSI will not discriminate against you for exercising your CCPA/CPRA rights.Important HIPAA note for California residents: PHI that is subject to HIPAA is exempt from certain CCPA rights under applicable CCPA exemptions. For PHI-related requests, patients must contact their healthcare provider directly.How to submit a request: California residents may submit a rights request by contacting RSI using the information in Section 13. RSI will respond within 45 days of receipt of a verifiable consumer request as required by California law. We may request information to verify your identity before processing the request.
10 — Children's Privacy
RSI's public website and platform are intended for use by healthcare practice professionals and adult patients. RSI does not knowingly collect personal information from children under the age of 13 through its public website. If RSI becomes aware that it has inadvertently collected personal information from a child under 13 without verifiable parental consent, RSI will take steps to delete that information promptly.Patient records for minor patients may be processed within the RSI platform at the direction of the healthcare practice (Covered Entity), consistent with applicable HIPAA and state law requirements governing minors' health information.
11 — Third-Party Links & Integrations
RSI's website and platform may contain links to third-party websites, and the platform integrates with third-party services at the direction of healthcare practice clients (such as practice management systems, telephony providers, and marketing platforms). RSI is not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you access.
12 — Changes to This Policy
RSI may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, provide additional notice (such as a notification to active platform users).Continued use of RSI's website or platform after a revised Privacy Policy becomes effective constitutes acceptance of the updated policy.
13 — Contact & Privacy Requests
If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a privacy concern, please contact us:Red Spot Interactive, LLC
1001 Jupiter Park Drive, Suite 122
Jupiter, FL 33458
Phone: 800-401-7931
Email: admin@redspotinteractive.com
For PHI-related requests or BAA inquiries, please contact your RSI account manager directly or reference "BAA / PHI Request" in the subject line of your email.