1. Home
  2. Privacy Policy

Privacy Policy

Last Updated: March 25, 2026

This “Notice of Information/Privacy Practices” is used to inform website visitors regarding our policies with the collection, use, and disclosure of Personal Information if anyone decides to use our Service.

If you choose to use our Service, then you agree to the collection and use of information in relation with this policy. The Personal Information that we collect is used for providing and improving the Service. We will not use or share your information with anyone except as described in this Privacy Policy.

Information Collection and Use

For a better experience while using our Service, we may require you to provide us with certain personally identifiable information, including but not limited to your name, phone number, and postal address. The information that we collect will be used to contact or identify you.

Log Data

We want to inform you that whenever you visit our Service, we collect information that your browser sends to us that is called Log Data. This Log Data may include information such as your computer’s Internet Protocol (“IP”) address, browser version, pages of our Service that you visit, the time and date of your visit, the time spent on those pages, and other statistics.

Cookies

Cookies are files with small amounts of data that are commonly used as anonymous unique identifiers. These are sent to your browser from the website that you visit and are stored on your computer’s hard drive.

Our website uses these “cookies” to collect information and to improve our Service. You have the option to either accept or refuse these cookies, and know when a cookie is being sent to your computer. If you choose to refuse our cookies, you may not be able to use some portions of our Service.

Service Providers

We may employ third-party companies and individuals due to the following reasons:

  • To facilitate our Service;
  • To provide the Service on our behalf;
  • To perform Service-related services; or
  • To assist us in analyzing how our Service is used.

We want to inform our Service users that these third parties have access to your Personal Information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.

Security

We value your trust in providing us your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.

Links to Other Sites

Our Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the Privacy Policy of these websites. We have no control over, and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Children’s Privacy

Our Services do not address anyone under the age of 13. We do not knowingly collect personal identifiable information from children under 13. In the case we discover that a child under 13 has provided us with personal information, we immediately delete this from our servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we will be able to take necessary actions.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. Thus, we advise you to review this page periodically for any changes. We will notify you of any changes by posting the new Privacy Policy on this page. These changes are effective immediately after they are posted on this page.

Contact Us

If you have any questions or suggestions about our Privacy Policy, do not hesitate to contact us:

To exercise any of these rights, please contact us using the information provided at the bottom of this policy.

6. Third-Party Services

We may share your information with trusted third-party service providers who assist us in operating our practice and website, including but not limited to:

  • Electronic Health Records (EHR) systems: For maintaining your medical records securely
  • Patient scheduling platforms: For online appointment booking and management
  • Payment processors: For securely processing credit card and other payment transactions
  • Email service providers: For sending appointment reminders and, with your consent, marketing communications
  • Analytics providers: Such as Google Analytics and Meta, for website analytics and advertising optimization
  • Cloud hosting providers: For secure storage of website data

All third-party service providers who handle PHI are required to enter into Business Associate Agreements (BAAs) with us in compliance with HIPAA. We do not sell your personal information to third parties.

7. Data Security

We implement a variety of security measures to maintain the safety and integrity of your personal and health information, including:

  • Encryption of sensitive data both in transit (via SSL/TLS) and at rest
  • Access controls limiting information access to authorized personnel only
  • Regular security assessments and audits of our systems and processes
  • Secure disposal of records containing personal or health information
  • Physical security measures at our practice location

While we strive to use commercially acceptable means to protect your information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security but are committed to taking all reasonable precautions to protect your data.

8. Data Retention

We retain your personal and health information for as long as necessary to fulfill the purposes for which it was collected, comply with our legal obligations, resolve disputes, and enforce our agreements. Medical records are retained in accordance with Colorado state law, which generally requires retention for a minimum of seven (7) years from the date of the last patient encounter, or longer as required by specific regulatory requirements.

9. Children's Privacy

Our website and services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18 without parental consent. If you believe that we have inadvertently collected information from a minor without appropriate consent, please contact us immediately so that we can take corrective action.

10. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time. Any changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website or services after changes are posted constitutes your acceptance of the revised Privacy Policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

IRIS Aesthetics & Medical Spa

Address: 1390 Dry Creek Dr, Longmont, CO 80503

Phone: (720) 738-0302

Email: info@irisaesthetics.com

If you believe your privacy rights have been violated, you also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against you for filing a complaint.