NIVILIA PATIENT LIFECYCLE PARTNERS
Legal Disclosure & Compliance Statement

Website Privacy Policy

Entity: NIVILIA WELLNESS LLP (ACR-1371) • Effective Date: October 3, 2026 • Domain: https://nivilia.online
⚠️ IMPORTANT NOTICE REGARDING PROTECTED HEALTH INFORMATION (PHI)

This Public Website Does Not Collect, Solicit, or Store Patient Health Information.

This Privacy Policy governs exclusively the collection of prospective administrative business information, website telemetry, and inquiry communications collected through the public website https://nivilia.online.

If you are an active client practitioner, all operational interactions involving patient records and Electronic Health Record (EHR) data are governed strictly by our executed Master Service Agreement (MSA) and bilateral federal HIPAA Business Associate Agreement (BAA) pursuant to 45 CFR Parts 160 and 164. Our personnel operate under a strict Zero-Export Protocol where zero Protected Health Information is ever exported, downloaded, or cached locally.

1. Identification of the Data Controller

This website is operated by NIVILIA WELLNESS LLP, a Limited Liability Partnership incorporated under the Ministry of Corporate Affairs, Government of India (Registration No.: ACR-1371), with its registered office situated at:

NIVILIA WELLNESS LLP

Kotshimul, Burdwan, West Bengal, India — 712410

Executive Email: [email protected]

US Dedicated Practice Telephony: +1 (301) 215-2408

2. Scope & Purpose of this Privacy Policy

Nivilia Wellness provides specialized healthcare operations, front-office triage, and revenue cycle practice management exclusively to licensed independent solo mental health practitioners located within the United States.

This policy outlines our collection, use, retention, and transfer of personal information collected from visitors of https://nivilia.online, prospective clinical clients booking discovery evaluations, and individuals contacting our executive desk.

3. Categories of Information Collected

We collect personal information through two channels:

4. Permitted Purposes of Processing

We process your business contact details and network telemetry strictly for the following purposes:

  • Inquiry Response & Consultations: Reviewing and responding to prospective inquiries within our 2-hour response SLA window;
  • Contract & Compliance Preparation: Delivering executed Master Service Agreements, bilateral HIPAA Business Associate Agreements, and IRS Form W-8BEN-E tax treaty documentation;
  • Network Security: Detecting, preventing, and mitigating distributed denial-of-service (DDoS) attacks, automated bot abuse, and unauthorized penetration testing via Cloudflare;
  • Communication Verification: Confirming calendar bookings and synchronizing reminder notifications across our US OpenPhone telephony line.

We do not sell, rent, or lease prospective client data to data brokers or third-party advertising networks.

5. Third-Party Infrastructure & Service Providers

We utilize trusted enterprise service providers to maintain the security and availability of our public web presence:

Vendor Operational Scope Privacy Terms & Compliance
Cloudflare, Inc. Edge CDN, SSL/TLS encryption, DNS resolution, DDoS defense. Subject to Cloudflare Global Privacy Policy and DPA.
Google Workspace Calendar appointment booking, executive email hosting. Subject to Google Cloud Privacy Notice.
OpenPhone Technologies Encrypted US VoIP practice communications and inbound SMS. Subject to OpenPhone Data Processing Addendum.

6. Cookies & Tracking Technologies

Our website utilizes minimal, strictly necessary cookies deployed by our edge security provider (Cloudflare) to distinguish legitimate visitors from malicious automated web crawlers and DDoS scripts (e.g., __cf_bm and cf_clearance cookies).

We do not inject third-party cross-site advertising trackers, behavioral surveillance cookies, or Meta/Google Ads tracking pixels onto our public website.

7. International Cross-Border Data Routing

NIVILIA WELLNESS LLP is registered in the Republic of India and provides administrative support to clients in the United States. When you submit contact details via our website, your information may be accessed by our systems architects and operational leads located in India.

All cross-border data routing executes over modern encrypted channels (TLS 1.3). For active contracted clients, all administrative workflows route back through dedicated, sovereign static US VPN tunnels calibrated to the clinician's state jurisdiction, ensuring clinical EHR sessions remain confined to domestic US infrastructure.

8. Data Retention Schedule

We retain prospective clinician contact records only for as long as necessary to fulfill the business relationship or evaluate operational fit.

If a prospective inquiry does not result in an executed Master Service Agreement, their contact information and calendar intake submission will be systematically pruned within twelve (12) months unless statutory or legal dispute obligations mandate extended retention. Server edge telemetry logs maintained by Cloudflare expire on standard rolling intervals.

9. Your Statutory Privacy Rights

Depending on your jurisdiction, including California (CCPA/CPRA, CalOPPA), Virginia (VCDPA), Texas (TDPSA), Colorado (CPA), and the Republic of India (Digital Personal Data Protection Act 2023), you possess specific legal rights regarding your personal information:

  • Right to Know / Access: The right to request confirmation of whether we process your personal data and to obtain a copy of the specific pieces of information collected;
  • Right to Rectification: The right to request correction of inaccurate or incomplete personal contact details;
  • Right to Erasure: The right to request permanent deletion of your prospective lead records, subject to statutory record-keeping exceptions;
  • Right to Non-Discrimination: We will never deny services, charge differing rates, or degrade service quality because you exercised statutory privacy rights.

To exercise any of these rights, submit a formal written request to our Compliance Lead at [email protected]. We verify and respond to all verifiable statutory requests within thirty (30) business days.

10. Protection of Minors (COPPA)

Our website and services are exclusively designed and intended for licensed adult healthcare professionals in independent private practice. We do not knowingly solicit, collect, or store personal information from individuals under the age of eighteen (18). If we become aware that personal information of a minor was inadvertently collected through our contact form, we will delete that data immediately.

11. Amendments & Updates

We may update this Privacy Policy periodically to reflect changes in edge infrastructure, regulatory statutes, or operational workflows. Any revisions will be published immediately on this page with an updated "Effective Date". We encourage practitioners to review this policy periodically.

12. Contact Our Compliance & Systems Lead

For questions, privacy grievances, or statutory verification requests, direct all correspondence to: