Rezilir Health® GDPR Statement | General Data Protection Regulation
Menu
Menu

Rezilir Health® GDPR Statement

This statement describes how Rezilir Health LLC collects and processes personal data with respect to data subjects covered by the EU General Data Protection Regulation (GDPR) and the UK GDPR. Depending on your geographic location, some parts of this statement may not apply to you.

Except as described below, we are the data controller of personal data collected from our website, our patient intake and scheduling processes, and our products and services. Our physical address is 1930 Harrison Street, Suite 404, Hollywood, FL 33020, USA, and you may reach us by emailing therezilirway@rezilirhealth.com.

Our EU Representative is Osano International Compliance Services Limited, ATTN: PE9B, 25 North Wall Quay, Dublin 1, D01 H104, Ireland.

Our UK Representative is Osano UK Compliance LTD, ATTN: PE9B, 42–46 Fountain Street, Belfast, Antrim, BT1 5EF, United Kingdom.

GDPR Principles

We comply with the core principles of the GDPR:

  • Lawfulness, fairness, and transparency — we process personal data lawfully and keep you informed about our processing.
  • Purpose limitation — we use personal data only for the specific, explicit, and legitimate purposes described in this statement and our Privacy Policy.
  • Data minimization — we collect only the data necessary and relevant for our activities.
  • Accuracy — we keep data as up to date as possible and correct or erase inaccurate data.
  • Storage limitation — we keep personal information only as long as necessary for the stated purposes.
  • Integrity and confidentiality — we protect and secure the personal data we store and process.
  • Accountability — we maintain records of our processing activities and continually review our practices.

Sources of Data Collection

  • When you directly share it with us — for example, when you request an appointment, register on our patient portal, contact us, sign up for our newsletter or eBook, or provide information in person, by phone, by text, or by email.
  • Automatically through your use of our website — such as your IP address, pages visited, time spent, and device information, collected via cookies and similar technologies (subject to your consent through our Osano consent banner).
  • From third-party sources — as part of providing treatment and obtaining payment, we may receive health information from other healthcare providers, laboratories, and insurers, and from individuals involved in your care, as described in our HIPAA Notice of Privacy Practices.

Categories of Personal Data

We collect the following categories of personal data:

  • Name
  • Phone number
  • Mailing address
  • Email address
  • Date of birth
  • Gender
  • Username / patient portal credentials
  • IP address and online identifiers
  • Geographic location data (estimated from IP)

Special Categories of Personal Data

As a healthcare provider, we collect personal data classified as “special category” under the GDPR. This may include:

  • Health information
  • Genetic data (e.g., in connection with genomic testing such as IntellxxDNA)
  • Biometric or neurocognitive data collected during assessments

We process special-category data on the basis of your explicit consent and/or for the provision of healthcare, and we handle patient health information in accordance with HIPAA. 

How We Use Your Personal Information

  • To provide our medical, telehealth, and wellness services.
  • To schedule, confirm, and remind you of appointments (including by text message, with your consent).
  • To contact you and respond to your requests.
  • To process payments and fulfill product, supplement, and program orders.
  • To improve and optimize our website and services.
  • To market our services, with your consent.
  • To detect and prevent fraud and for security purposes.
  • To comply with applicable legal obligations.

Sharing of Your Personal Information

Under no circumstance will we sell, trade, or rent any of your personal information. With your consent or as otherwise permitted by law, we may share personal data with:

  • Service providers, processors, and vendors acting on our behalf, limited to what they need to perform their services under contract (see the Subprocessors table below).
  • Professional advisors such as legal, accounting, and banking professionals.
  • Public authorities and law enforcement, pursuant to legal obligations or valid legal process.

Legal Basis of Processing

We rely on the following legal bases:

  • Consent — e.g., newsletter, text messaging, non-essential cookies, and processing of health data for non-treatment purposes.
  • Performance of a contract — to provide services you request or purchase.
  • Legal obligation — including medical recordkeeping and other regulatory requirements.
  • Vital interests — to protect your vital interests or those of another person (e.g., a medical emergency).
  • Legitimate interests — such as analytics, marketing, and security, where not overridden by your rights.

International Data Transfer Mechanisms

We are located in the United States. When we transfer personal data of individuals in the EU/EEA, Switzerland, or the UK to the US, we rely on the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with additional safeguards where appropriate. To obtain information about these transfer mechanisms, contact therezilirway@rezilirhealth.com.

Data Processing Agreement

A Data Processing Agreement (DPA) governs how our processors handle personal data on our behalf. A copy of our DPA is available upon request.

Your Data Subject Rights

Subject to applicable law, you have the rights of: confirmation, access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection (including to direct marketing), the right not to be subject to solely automated decision-making, and the right to withdraw consent at any time.

To exercise these rights, contact us at therezilirway@rezilirhealth.com. We may require verification of your identity before processing a request. You also have the right to lodge a complaint with a Data Protection Authority; a list of EU authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en, and in the UK with the Information Commissioner’s Office (ICO).

Automated Decision Making and Profiling

We do not make decisions about individuals based solely on automated processing, and we do not use profiling for such decisions. Our clinicians are involved in decisions about your care. 

Subprocessors

We engage the following processors, who may receive certain categories of personal data under contract and only for the purposes below:

Subprocessor

Contact

Categories of Personal Data Shared

Purpose

Osano

osano.com

Consent records, IP address, online identifiers

Cookie/tracking consent management

Freshpaint

freshpaint.io

Website usage/event data (personal and health information stripped before onward sharing)

HIPAA-safe analytics & marketing data governance

Google (Analytics / Ads)

google.com

Pseudonymized usage data, online identifiers (post-consent, PHI removed)

Website analytics & advertising

Meta Platforms

facebook.com

Pseudonymized usage data, online identifiers (post-consent, PHI removed)

Advertising

ActiveCampaign

activecampaign.com

Name, email, phone number

Email & SMS communications

MD HQ

md-hq.com

Patient contact and health information, portal credentials

Patient portal / practice management (EHR)

Fullscript

fullscript.com

Name, contact, order information

Supplement dispensary and order fulfillment

Website hosting provider

kinsta

Website data, IP address

Website hosting & infrastructure