Privacy Policy
How this website handles information, how that differs from your protected health information, and the terms under which the site is provided.
Last updated: 12 August 2026 · Effective: 12 August 2026
- Scope of this policy
- Website data vs. protected health information
- Information collected
- How information is used
- Legal bases for processing
- When information is shared
- Service providers
- Cookies and tracking
- No sale of personal information
- Retention
- Security
- Email, forms and unencrypted communication
- Your privacy rights
- State-specific disclosures
- International visitors
- Children and minors
- Third-party links
- No medical advice; no clinician–patient relationship
- Emergencies
- Disclaimer of warranties
- Limitation of liability
- Indemnification
- Governing law and disputes
- Changes to this policy
- Contact
1. Scope of this policy
This Privacy Policy describes how KleinMind Psychiatry & Wellness, A Nursing Professional Corporation — a professional nursing corporation also referred to in the ordinary course as "KleinMind Psychiatry & Wellness," "KleinMind," or "Klein Mind," and in this policy as "the practice," "we," "us," or "our" — collects, uses, and discloses information through the website located at kleinmind.com and any related pages, forms, or email addresses published on it (together, the "Site"). References to any of those names mean the same legal entity.
This policy applies to visitors to the Site. It does not create, and is not intended to create, any clinician–patient relationship, contract for care, or duty of care. By accessing or using the Site you acknowledge that you have read and understood this policy.
If you do not agree with any part of this policy, please discontinue use of the Site.
2. Website data is not the same as your protected health information
This is the most important distinction in this document.
Information submitted through this Site is website data. It is governed by this policy. It is not a clinical record, is not stored in an electronic health record, and should not be treated as a confidential clinical communication.
Protected health information ("PHI") created once you become a patient is governed separately. If and when you establish care with the practice, your clinical information is handled under the Health Insurance Portability and Accountability Act ("HIPAA") and applicable state law, and is described in the practice's Notice of Privacy Practices, which is provided to you as part of the intake packet. That Notice — not this policy — governs your clinical record.
Where the two documents differ with respect to PHI, the Notice of Privacy Practices controls. Where they differ with respect to Site usage data, this policy controls.
Nothing in this policy should be read as a representation that information you send through a website form or an unencrypted email is protected to the standard applicable to PHI.
3. Information collected
3.1 Information you provide voluntarily
- Contact and inquiry information — your name, email address, telephone number, and any content you choose to include when you email the practice or complete a pre-screening or contact form.
- Scheduling information — availability, preferred appointment times, and similar logistical details.
- Anything else you choose to send. You control what you write. Please do not include detailed clinical, diagnostic, medication, or crisis information in an initial web or email communication.
3.2 Information collected automatically
- Log and device data — IP address, browser type and version, operating system, device type, screen dimensions, referring URL, pages requested, and date and time of access.
- Usage data — pages viewed, time on page, navigation paths, and interactions with links or buttons.
- Approximate location — derived from IP address at a city or regional level. The Site does not request precise geolocation.
3.3 Information from third parties
The Site may receive limited technical information from the hosting provider, content delivery networks, font providers, or analytics services described in Section 7.
3.4 Information not collected
The Site does not knowingly collect payment card numbers, Social Security numbers, government identification numbers, insurance member identifiers, or biometric identifiers. Do not submit these through the Site.
4. How information is used
Information collected through the Site is used to:
- respond to inquiries and determine whether the practice is an appropriate fit for what you are seeking;
- schedule, confirm, reschedule, or cancel appointments;
- send administrative communications relating to your inquiry or appointment;
- operate, maintain, secure, debug, and improve the Site;
- analyse aggregate traffic patterns and content performance;
- detect, investigate, and prevent fraud, abuse, security incidents, and unlawful activity; and
- comply with legal, regulatory, licensure, and professional obligations.
Information collected through the Site is not used for behavioural advertising, profiling for automated decision-making with legal or similarly significant effects, or the training of third-party machine learning models.
5. Legal bases for processing
Where a legal basis is required by applicable law, processing is carried out on the basis of: your consent, where you have provided it; the performance of steps taken at your request prior to entering into an agreement for services; compliance with a legal obligation; and our legitimate interests in operating a secure, functional website and responding to inquiries, where those interests are not overridden by your rights.
6. When information is shared
Information is not sold, rented, or traded. It may be disclosed in the following circumstances:
- Service providers. To vendors that operate the Site or support practice administration, as described in Section 7, and only to the extent needed to perform their function.
- Legal requirements. Where disclosure is required by subpoena, court order, warrant, regulatory demand, licensure investigation, or other applicable legal process.
- Safety. Where disclosure is permitted or required by law to prevent or lessen a serious and imminent threat to the health or safety of any person.
- Professional obligations. Including mandatory reporting duties imposed by state or federal law.
- Enforcement. To investigate suspected violations of these terms, protect the rights, property, or safety of the practice or others, or defend legal claims.
- Business transfer. In connection with a merger, sale, reorganisation, dissolution, or transfer of practice assets, subject to applicable law governing health records.
- With your direction. Where you have asked or authorised us to share the information.
7. Service providers
The Site relies on third-party infrastructure. Depending on how you interact with it, this may include a website hosting and content-delivery provider, an email provider, a web font provider, a scheduling or intake platform, a HIPAA-eligible telehealth video platform, and an electronic health record system.
These providers process information under their own privacy terms. Where a provider handles PHI on the practice's behalf, the practice seeks a business associate agreement as required by HIPAA. The practice does not control, and is not responsible for, the independent acts or omissions of these providers, and disclaims liability for them to the fullest extent permitted by law.
8. Cookies and tracking
The Site aims to use only cookies and similar technologies that are strictly necessary for it to function, together with any analytics described here. It does not use third-party advertising cookies, retargeting pixels, or cross-site advertising identifiers.
You can configure your browser to refuse cookies or alert you when cookies are being sent. Some parts of the Site may not function correctly if cookies are disabled.
Do Not Track and Global Privacy Control. There is no uniform industry standard for responding to browser "Do Not Track" signals, and the Site does not respond to them. Where required by applicable law, the Site treats a Global Privacy Control signal as a valid request to opt out of any sale or sharing of personal information — although, as stated below, no such sale or sharing takes place.
9. No sale or sharing of personal information
KleinMind does not sell personal information, and does not share personal information for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act, or under any comparable state privacy statute. KleinMind has not sold or shared personal information in the preceding twelve months, including the personal information of any consumer under sixteen years of age.
10. Retention
Website inquiry correspondence is retained only as long as reasonably necessary for the purpose for which it was collected, to respond to your inquiry, and to meet legal, regulatory, and professional recordkeeping obligations, after which it is deleted or de-identified.
Clinical records, once care is established, are retained for the period required by applicable state and federal law and by professional standards, which is generally substantially longer. Retention of clinical records is governed by the Notice of Privacy Practices.
Server logs and aggregate analytics are retained on a rolling basis in accordance with the relevant provider's standard practice.
11. Security
The Site is served over an encrypted connection, and the practice takes commercially reasonable administrative, technical, and physical measures designed to protect information under its control against unauthorised access, disclosure, alteration, and destruction.
No system is completely secure. No method of transmission over the internet and no method of electronic storage is one hundred percent secure, and the practice cannot and does not warrant, guarantee, or ensure the security of any information transmitted to or from the Site. You transmit information at your own risk. To the fullest extent permitted by law, KleinMind disclaims all liability for unauthorised access to, interception of, alteration of, or loss of information that occurs in transit or as a result of a third-party act, including acts of hacking, phishing, credential compromise, malware, or vendor breach outside the practice's reasonable control.
If you believe your interaction with the Site is no longer secure, contact the practice immediately at the address in Section 25.
12. Email, forms, and unencrypted communication
Standard email and standard web forms are not secure or encrypted end to end. Messages can be intercepted, misdirected, forwarded, retained by intermediate servers, or accessed by anyone with access to the sending or receiving account or device.
By choosing to contact the practice by email or web form, you accept these risks and consent to receiving a reply by the same means. You are solely responsible for the security of your own devices, accounts, and email service, and for the content you choose to transmit.
Do not use email, web forms, voicemail, or text messages to communicate an emergency, a change in symptoms requiring urgent attention, or thoughts of harming yourself or anyone else. These channels are not monitored continuously and no response time is guaranteed. See Section 19.
13. Your privacy rights
Depending on where you live, you may have some or all of the following rights with respect to personal information the practice holds about you:
- Right to know or access the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of recipients.
- Right to correct inaccurate personal information.
- Right to delete personal information, subject to exceptions — most importantly, information that must be retained as part of a health record or to comply with a legal obligation cannot be deleted on request.
- Right to portability — to receive a copy in a portable, readily usable format.
- Right to opt out of sale, sharing, or targeted advertising. None of these occur.
- Right to limit the use of sensitive personal information.
- Right to withdraw consent where processing is based on consent.
- Right to non-discrimination for exercising any of these rights.
- Right to appeal a refused request, where your state provides one.
How to exercise a right. Email the address in Section 25 with the words "Privacy Request" in the subject line. The practice will acknowledge receipt and respond within the period required by applicable law. In order to protect your information, we must verify your identity before acting, which may require you to confirm information already held. An authorised agent may submit a request on your behalf with written proof of authorisation, and we may still require you to verify your identity directly.
Important limitation. Information that constitutes PHI or forms part of a designated record set is subject to HIPAA and state health-record law rather than to general state privacy statutes. Requests concerning your clinical record are handled under the Notice of Privacy Practices and applicable medical records law, which may impose different procedures, timelines, and grounds for denial.