How we collect, use, and protect your information
VGT MEDIA, LLC d/b/a PI Chiro Nexus · Effective August 25, 2026
VGT MEDIA, LLC, d/b/a PI Chiro Nexus (“Company,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our websites, purchase our services, use our software platform, receive messages from us, or otherwise interact with us.
This Policy covers pichironexus.com, app.pichironexus.com, drpersonalinjurygrowth.com, and the software, portals, forms, and messaging services we operate at those domains (together, the “Services”).
We handle two very different kinds of information, and your rights differ depending on which one is at issue.
This is information about our own customers and prospects: the chiropractic practices that buy our Services, the doctors and staff who hold accounts, visitors to our marketing websites, and businesses we contact about our Services. We decide how this information is used, and this Privacy Policy governs it.
This is information a clinic uploads, imports, or generates inside our platform about its own patients, leads, and contacts. We process that information only on the clinic’s documented instructions in order to deliver the Services. The clinic — not PI Chiro Nexus — decides how that information is used, and the clinic’s own privacy notice governs it.
If you are a patient, a lead, or a contact of a clinic that uses our platform and you want to access, correct, or delete your information, please contact that clinic directly. If you contact us instead, we will refer your request to the clinic and assist the clinic in responding; we will not unilaterally change or delete a clinic’s records, because they are not ours to change.
For Clinic Data we act as a “service provider” under the California Consumer Privacy Act and as a “processor” under other United States state privacy laws. We do not sell Clinic Data, we do not share it for cross-context behavioral advertising, we do not retain or use it outside the direct business purpose of providing the Services, and we do not combine it with information we receive from other clinics.
Clinics that use our platform are covered entities under the Health Insurance Portability and Accountability Act (“HIPAA”). To the extent we create, receive, maintain, or transmit Protected Health Information (“PHI”) on a clinic’s behalf, we act as a Business Associate.
PHI is not governed by this Privacy Policy. It is governed by the Business Associate Agreement executed between us and the clinic, which controls in the event of any conflict with this Policy. Our Business Associate Agreement is available at pichironexus.com/baa. Among other things, it obligates us to safeguard PHI, to limit use and disclosure to what the agreement and HIPAA permit, to notify the clinic of any breach of unsecured PHI, to bind our subcontractors to equivalent terms, and to return or destroy PHI at the end of the engagement.
We do not use PHI for our own marketing, we do not sell PHI, and we do not use PHI to train artificial intelligence models. See Section 6.
Depending on how you interact with us, we may collect the following categories of information.
To support clinic outreach, our platform assembles lists of attorneys, law firms, and other businesses from third-party business data providers and public business listings. This data consists of business contact information — firm name, business address, business telephone number, business email address, website, and practice area. It is not obtained from the individuals themselves. If you are an attorney or business contact and you wish to be removed from our data, see Section 13.
A clinic may cause the following to be processed in our platform: contact information for patients and leads; appointment and scheduling information; the content of text messages and emails exchanged between the clinic and those individuals; lead source and campaign attribution; intake and case information; and, in some configurations, information relating to a person’s physical condition, treatment, or accident. Information in this category is Clinic Data, and information that identifies a patient of the clinic is PHI. See Sections 1 and 2.
California and several other states define personal information by fixed statutory categories. In the preceding twelve months we have collected the following categories of Company Data. This is the same information described in Sections 3.1 and 3.2, relabeled to match the statute.
The only category of sensitive personal information we collect as Company Data is account log-in credentials, which we hold in hashed form solely to authenticate you. We do not collect government identifiers, financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, or the contents of your mail, email, or text messages as Company Data.
We use sensitive personal information only to perform the Services, secure your account, and prevent fraud — never to infer characteristics about you. Because we limit it to those purposes already, no request is needed to restrict it.
Health information about a clinic’s patients is Clinic Data and Protected Health Information. It is governed by the Business Associate Agreement, not by this Policy. See Sections 1 and 2.
We do not use Clinic Data or PHI for any of the marketing, product-improvement, or model-training purposes described above.
Our Services use artificial intelligence. We want you to know exactly where, and on what.
Text submitted for AI processing is transmitted to Anthropic, PBC (the Claude family of models) under a commercial agreement. If we add or change an AI provider, we will update this Section and the list in Section 7.
Where PHI is involved, processing runs in a separate, HIPAA-ready environment governed by a Business Associate Agreement we executed with Anthropic on August 25, 2026. That environment is kept apart from the one we use for ordinary business processing, and features that are not permitted for regulated health data are blocked in it at the provider's end rather than only by our own policy.
Text we send for AI processing is not stored by our provider indefinitely — but it is not discarded the instant it is used, either. You should know the actual periods:
These periods are set by the provider and we cannot shorten them. A zero-retention configuration does exist, but it cannot be combined with the HIPAA-ready environment described in Section 6.2 — the two are mutually exclusive. We have chosen the HIPAA-ready environment, because a Business Associate Agreement and the safeguards that come with it protect PHI better than a shorter retention window would.
Some messages you receive from the platform — appointment reminders, follow-ups, and status notifications — are sent automatically rather than typed by a person. Where an automated conversational agent handles a message exchange, we will not represent it as a human being if you ask whether you are speaking with a person.
We share information only as described below. We do not share your information with any category of recipient not listed here.
Each of the following receives only the information it needs to perform its function, is bound by contract to protect it, and is prohibited from using it for its own purposes. Where the provider handles PHI, it is bound by a Business Associate Agreement.
A current list of the service providers we use is maintained in this Section. We will update it before any new provider begins processing personal information, and we will give notice of material additions as described in Section 18.
We do not sell personal information, and we have not sold personal information in the preceding twelve months, as “sell” is defined by the California Consumer Privacy Act and comparable state laws.
We do not share personal information for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not run third-party advertising pixels or advertising trackers on our websites or in our platform. We do not disclose the mobile telephone numbers or messaging opt-in records of any individual to third parties for those parties’ own marketing purposes.
We have never sold or shared the personal information of any individual we know to be under sixteen years of age.
Disclosures to the service providers listed in Section 7.1 are not sales or shares. Those providers act on our documented instructions, are contractually barred from using the information for their own purposes, and receive no payment or other value from us in exchange for personal information.
Where you provide a mobile telephone number and consent to receive text messages, we may send account, service, appointment, and — separately, and only with your consent — marketing text messages. Message and data rates may apply. Message frequency varies.
You may opt out at any time by replying STOP to any message, and you may request help by replying HELP. Opting out of text messages does not opt you out of email or account notices, which you may manage separately.
No mobile information or text messaging consent will be sold, rented, or shared with any third party for marketing purposes. Mobile numbers and consent records are disclosed only to the messaging service provider identified in Section 7.1 for the sole purpose of delivering the messages you asked to receive.
Where a clinic uses our platform to text its own patients and leads, the clinic is responsible for obtaining consent from those individuals and for honoring their opt-outs. We maintain the technical means to record consent and to suppress numbers that have opted out.
We use cookies and similar technologies that are strictly necessary to operate the Services — maintaining your login session, keeping your account secure, remembering your preferences, and balancing load. We also use limited first-party analytics to understand how our sites and platform are used and to diagnose errors.
We do not use third-party advertising cookies, retargeting pixels, or cross-site tracking technologies on our websites or in our platform.
You can usually configure your browser to limit or block cookies, though some features of the platform will not function without the strictly necessary ones.
Global Privacy Control. Where we receive an opt-out preference signal such as Global Privacy Control from your browser, we treat it as a valid request to opt out of any sale or sharing of personal information from that browser. Because we do not sell or share personal information at all, this signal does not change our handling, but it is honored.
We keep information only as long as we need it for the purpose it was collected, and then delete it or render it unidentifiable. Our standard periods are:
Backups. When we delete information from our live systems it may persist in encrypted backups for up to ninety days before those backups age out on their normal rotation. During that window the information is not used for any purpose and is not accessible through the Services.
We may retain information longer than the periods above where a legal hold, an open dispute, an investigation, or an applicable law requires it. In that case we retain only what the obligation requires, and we delete it when the obligation ends.
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include encryption of data in transit using industry-standard transport layer security; encryption of data at rest; row-level access controls that separate each clinic’s data from every other clinic’s data; role-based access limits so that our personnel can reach only the data their job requires; audit logging of administrative access to customer accounts; and secure credential storage.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly if you believe your account has been compromised.
Security incidents. If we become aware of a breach of security leading to the unauthorized acquisition of unencrypted personal information, we will notify affected individuals and the applicable authorities without unreasonable delay and within the timeframes required by applicable law. Where the incident involves PHI, we will notify the affected clinic in accordance with the Business Associate Agreement and the HIPAA Breach Notification Rule.
Depending on where you live, you may have some or all of the following rights with respect to Company Data:
These rights are provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under comparable laws in Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky, Rhode Island, and other states as those laws take effect.
Email support@vgtmedia.com with the subject line “Privacy Request,” or write to us at the address in Section 19. Tell us which right you are exercising and give us enough information to locate your records.
We will verify your identity before acting, typically by confirming control of the email address or telephone number already on file, or by asking you to answer questions about information we already hold. We will not ask you for information we do not already have solely to verify a request.
We acknowledge requests within ten business days and respond substantively within forty-five calendar days. If we need more time we will tell you why and extend by up to an additional forty-five days.
You may use an authorized agent to submit a request. We will require written proof of the agent’s authority and may ask you to verify your own identity directly.
If we decline your request, we will tell you why. You may appeal that decision by replying to our response with the subject line “Privacy Appeal.” We will review the appeal and respond in writing within forty-five days, explaining the reasons for our decision. If we deny the appeal, we will provide you with a method to contact your state attorney general to lodge a complaint.
If your request concerns information held by a clinic in our platform — you are a patient, lead, or contact of that clinic — we will forward your request to the clinic and support the clinic in responding, but the clinic must make the decision. See Section 1.
If you are an attorney or business contact and want your business listing removed from our data, email support@vgtmedia.com and we will remove it and add it to a suppression list so it is not re-imported.
California Civil Code Section 1798.83 permits California residents to request information about disclosures of personal information to third parties for those parties’ direct marketing purposes. We make no such disclosures.
The Services are business software sold to healthcare practices. They are not directed to children, and we do not knowingly collect personal information directly from anyone under sixteen years of age. If we learn we have collected such information other than as Clinic Data provided by a clinic, we will delete it promptly. A clinic that treats minor patients is responsible under its own policies and under HIPAA for information about those patients.
Our websites and platform may link to, or connect with, third-party websites, tools, and platforms. When you connect a third-party account — for example an advertising or calendar account — you authorize us to access it using the permissions you grant, and you may revoke that access at any time through your account settings or through the third party. We are not responsible for the privacy practices of third parties, and their own privacy policies govern their handling of your information.
We are based in the United States and we process and store information in the United States. If you access the Services from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those of your jurisdiction. The Services are not offered to individuals in the European Economic Area or the United Kingdom, and we do not target those markets.
We may update this Privacy Policy from time to time. When we do, we will revise the Effective Date above and post the updated version at pichironexus.com/privacy-policy. If we make a material change — including any change to the categories of information we collect, the purposes we use it for, the artificial intelligence disclosures in Section 6, or the service providers listed in Section 7.1 — we will provide at least thirty days’ advance notice by email to account holders or by prominent notice in the platform before the change takes effect. We maintain prior versions of this Policy and will provide a copy on request.
For questions about this Privacy Policy, to exercise a privacy right, or to report a concern about our data practices, contact us at:
VGT MEDIA, LLC
d/b/a PI Chiro Nexus
500 North Andrews Avenue, Fort Lauderdale, FL 33301
support@vgtmedia.com
Effective August 25, 2026. Questions: support@vgtmedia.com