R21Digital

Legal

Privacy Policy

This Privacy Policy explains what information R21 Digital (a brand of R21 Media Group, LLC, “R21,” “we,” “us”) collects when you use r21digital.com, how we use it, and the choices you have. By using this site, you agree to this policy.

Last updated: July 31, 2026

Information we collect

When you submit our contact form, we collect the information you provide — typically your name, email address, company, and your message. We use this only to respond to you and discuss working together.

We also collect basic, non-identifying usage data automatically through analytics (such as pages visited, approximate location, device, and referral source) to understand how the site is used.

Cookies & analytics

We use Google Analytics (GA4) to measure site traffic and performance, and the Meta Pixel to measure whether our own ads on Facebook and Instagram bring people here. Both set cookies and collect usage data as described above. The Meta Pixel records that a page was viewed; we do not send it anything you type into a form. You can opt out via the Google Analytics Opt-out Browser Add-on, your Meta ad preferences at facebook.com/adpreferences, or your browser's cookie controls.

How we use your information

To respond to your inquiry, provide and improve our services and website, and — only if you've asked us to — follow up about working together. We do not sell your personal information.

How we share it

We share information only with service providers who help us operate — for example our website host (Vercel), analytics (Google), advertising measurement (Meta), and the tools we use to manage inquiries. They may process data on our behalf but are not permitted to use it for their own purposes. We may also disclose information if required by law.

Data retention

We keep contact-form submissions for as long as needed to respond and maintain our business records, and no longer than necessary. You can ask us to delete your information at any time.

Your rights

You can request access to, correction of, or deletion of the personal information we hold about you. To make a request, email us at info@r21digital.com and we'll respond within a reasonable time.

Security

We take reasonable measures to protect your information, but no method of transmission or storage is completely secure. We cannot guarantee absolute security.

Health information (HIPAA)

Most of this policy covers people who visit r21digital.com. This section is different: it covers protected health information (PHI) we handle on behalf of medical practices that hire us. If you are a patient, your rights run through your own provider rather than through us — see the patient rights paragraph below.

Some of our services connect to a practice's electronic health record — for example Practice Fusion, through its official FHIR API — to produce reports, recall lists, and care-gap summaries for that practice. When we do that work, R21 Media Group, LLC acts as a HIPAA Business Associate and the practice remains the Covered Entity. The relationship is governed by a signed Business Associate Agreement (BAA), not by this page.

Access is read-only. Practice Fusion's FHIR API does not allow writing to the chart, and we do not modify a practice's clinical record — the EHR stays the source of truth. We read only the categories the practice has authorized, typically demographics, encounters, conditions, medications, allergies, lab results, immunizations, and related clinical documents.

How we protect health information

PHI is encrypted in transit using TLS 1.2 or higher and encrypted at rest. Access is limited to the R21 personnel who need it to deliver the service, protected by multi-factor authentication, and each access is written to an audit log that records who read what and when.

PHI is processed and stored on HIPAA-eligible infrastructure located in the United States, under a Business Associate Agreement with the cloud provider. We will name our subprocessors to any practice on request, and we tell active clients before that list changes.

What we don't do with health information

We do not sell PHI. We do not use it for advertising, or for anything beyond the services the practice has contracted for. We do not use PHI to train artificial intelligence models and we do not send it to third-party AI providers. If that ever changes, we will update this policy and tell active practice clients before the change takes effect, and we would use only HIPAA-eligible providers under a signed BAA.

Health data retention, breach notice, and patient rights

We keep PHI for as long as we are providing the service to the practice, plus any period the law requires. When an engagement ends we return or securely destroy it at the practice's election within 30 days, except for records we are legally required to keep.

If we discover a breach of unsecured PHI, we notify the affected practice without unreasonable delay and within the deadline set by HIPAA and our BAA, including what happened, which data was involved, and what we are doing about it.

Because we are a Business Associate and not a Covered Entity, patients exercise their HIPAA rights — access, amendment, an accounting of disclosures — through their own practice. We support the practice in answering those requests as our BAA requires. To request a BAA or raise a health-privacy concern, email info@r21digital.com.

Children's privacy

This site is not directed to children under 13, and we do not knowingly collect personal information from them.

Changes to this policy

We may update this policy from time to time. The “last updated” date above reflects the latest version.

Contact

Questions about this policy? Email info@r21digital.com or call (480) 997-4639.