Website Privacy

Website Privacy Policy

How the public website handles information, forms, analytics, service providers, retention, and privacy requests.

Effective July 25, 2026

Website privacy and privacy in care are different.

This policy covers the public website, general inquiries, email updates, event interest, and links or handoffs to other services. The Notice of Privacy Practices explains how protected health information is handled in a clinical relationship. If both apply to the same information, the Notice and applicable health-privacy law control.

Do not use ordinary email, voicemail, general website fields, or website messages for emergencies or detailed medical information. In immediate danger or a medical emergency, call 911 or go to the nearest emergency department. In suicidal crisis or emotional distress in the United States, call or text 988.

Information & Services

What the site handles and where it goes.

Open a section for details about information, purposes, and the services currently in use.

What information might I provide?

Depending on how you use the site, you may provide your name, email address, optional phone number, a broad service or event interest, a short general question, newsletter preferences, accessibility feedback, nonclinical event registration information, or health and screening information entered in a clearly identified clinical application hosted in LuminaThera’s approved Google Workspace environment.

Do not enter clinical information in a general inquiry, newsletter form, accessibility message, or ordinary email.

What information is created through normal website use?

The site, MechanicWeb, security systems, and analytics services may process an IP address, browser and device information, request date and time, pages or files requested, referring source, language, approximate location derived from network information, error or security data, and cookies or similar identifiers.

This technical information is commonly created when a browser communicates with a web server. It is used to deliver, protect, troubleshoot, and improve the site.

How does LuminaThera use information?

Information may be used to respond to requests, route an inquiry or application, coordinate screening, scheduling or registration, send requested updates, provide accessibility support, operate and secure the site, understand broad nonclinical usage patterns, prevent misuse, meet legal and recordkeeping duties, and establish or defend legal rights.

LuminaThera does not use clinical form answers, free-text inquiry content, or care-pathway selections to create advertising profiles.

Where are website and form records stored?

MechanicWeb hosts the WordPress site. LuminaThera does not currently use a separate content-delivery network. Host systems may process ordinary request data, logs, security events, and backups while providing the service.

Inquiry and clinical application answers are sent from the browser to designated Google Workspace forms and are not intended to be received or retained by WordPress. Clinical application answers are stored in the approved Workspace account under the applicable Business Associate Agreement and are limited to authorized people involved in intake, screening, operations, privacy, security, or legal obligations.

Which other services are currently used?

Google Workspace supports approved forms, records, and email. Events Manager Pro supports nonclinical event registration. Stripe processes payments. Mailchimp manages newsletter subscriptions and email updates.

LuminaThera does not currently use an electronic health record, practice-management, or scheduling platform. This policy will be updated if a future system materially changes how information is handled. Complete payment-card numbers should be entered only into Stripe’s interface and are not intended to be stored in WordPress.

What happens when I open an embedded or linked service?

Google Forms, videos, maps, event tools, payment pages, and other embedded or linked services may receive technical information or set their own cookies when you interact with them. A plain link generally does not contact the destination until selected, while an embedded service may communicate with its provider when the page loads.

Those providers operate systems LuminaThera does not directly control. Their practices are governed by their policies and any contract LuminaThera has with them.

Analytics & Stewardship

Current tracking, safeguards, choices, and limits.

This section describes the site as it operates now, including the absence of a separate analytics consent control.

How does Google Analytics currently operate?

LuminaThera uses Google Analytics 4 (GA4) to understand broad website use, including pages visited, general referral sources, device categories, and whether navigation functions as expected. Under the current configuration, GA4 may load when you visit a page.

Google may receive an IP address, browser and device information, approximate location, referring source, page address, pages viewed, and interactions with the site. LuminaThera does not intentionally configure GA4 to receive clinical application answers, free-text messages, names, email addresses, phone numbers, or payment-card information as analytics data. The current implementation does not yet provide a separate site-level analytics consent control or comprehensive page-by-page suppression.

What choices do I have about analytics?

LuminaThera does not currently provide a separate website control to allow or decline GA4. You may use browser privacy settings, content blockers, or other browser tools to limit cookies or analytics scripts. Blocking analytics does not prevent you from reading the site, contacting LuminaThera, or seeking care, although a browser tool may affect some site functions.

LuminaThera is evaluating a direct, first-party analytics choice for a future update. This policy will be revised when that control is implemented.

Does LuminaThera sell information or use advertising surveillance?

No. As of the effective date, LuminaThera does not sell personal information or protected health information, share it for cross-context behavioral advertising, use clinical information for targeted advertising, or operate advertising pixels, session replay, or keystroke-recording tools.

When may information be disclosed?

Information may be disclosed to providers that host, secure, maintain, or support the website and communications; Google Workspace and other approved services you choose to use; clinicians, prescribers, contractors, or affiliated providers involved in a requested service; and event, payment, email, or accessibility services needed to complete a request.

Information may also be disclosed when you direct or authorize it, when required by law or legal process, when reasonably necessary to protect a person or the site’s security, or in a practice reorganization subject to applicable confidentiality and health-privacy duties. Providers handling protected health information must have a Business Associate Agreement when HIPAA requires one.

How long is information kept?

LuminaThera maintains records for periods required by applicable law and professional obligations. When no fixed period applies, information may be kept for as long as reasonably needed for care, operations, security, accounting, dispute resolution, or other legitimate and lawful purposes.

Provider-managed logs, archives, and backups may follow different schedules. Deletion from an active system may not immediately remove a protected backup or a record another provider must keep. Newsletter information is generally kept until you unsubscribe or the list is retired, with a limited suppression record retained when needed to honor an unsubscribe request.

How is information protected?

LuminaThera uses administrative, technical, and physical safeguards selected for the information and systems involved. These may include access controls, multifactor authentication, encryption, workforce training, vendor review, backups, monitoring, and incident response.

No website, email, or storage system can be guaranteed completely secure. Contact LuminaThera if you believe you sent sensitive information through the wrong channel or suspect a privacy or security issue.

What requests can I make?

Depending on the information and applicable law, you may ask LuminaThera to explain website-related personal information maintained about you, correct contact information, delete information not required or permitted to be kept, stop optional email updates, or provide an accessible alternate format.

Identity may need to be verified. A request may be limited when information is a clinical record, must be retained, is needed for security or legal claims, belongs to another person, or is otherwise exempt. HIPAA rights are described in the Notice of Privacy Practices.

What about children, international visitors, or future changes?

LuminaThera’s services are for adults age 18 and older. The public website is directed to adults and is not designed for children to submit information independently. Do not submit a minor’s information through a general website form.

LuminaThera is based in Ohio. Provider systems may process information in the United States or other places where an approved provider operates. The policy may be updated when the site, vendors, practices, or legal duties change. A new last-updated date will be posted, with additional notice or consent when required.

Contact

Questions about website privacy.

Contact LuminaThera LLC, Attn: Privacy and Security Officer, 929 Harrison Ave, Suite 200, Columbus, OH 43215. Email info@luminathera.com or call (614) 982-0262.

Do not include detailed medical information in ordinary email or voicemail. The Notice of Privacy Practices explains rights related to protected health information.

Clinical Privacy

Read the Notice of Privacy Practices.

The NPP explains how protected health information may be used and disclosed and how to exercise your rights.