Legal

Privacy Policy

How we collect, use, and protect your information

VGT MEDIA, LLC d/b/a PI Chiro Nexus · Effective August 25, 2026

VGT MEDIA, LLC, d/b/a PI Chiro Nexus (“Company,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our websites, purchase our services, use our software platform, receive messages from us, or otherwise interact with us.

This Policy covers pichironexus.com, app.pichironexus.com, drpersonalinjurygrowth.com, and the software, portals, forms, and messaging services we operate at those domains (together, the “Services”).

1. The Two Roles We Play — Please Read First

We handle two very different kinds of information, and your rights differ depending on which one is at issue.

(a) Company Data — we are the controller

This is information about our own customers and prospects: the chiropractic practices that buy our Services, the doctors and staff who hold accounts, visitors to our marketing websites, and businesses we contact about our Services. We decide how this information is used, and this Privacy Policy governs it.

(b) Clinic Data — we are a service provider acting for the clinic

This is information a clinic uploads, imports, or generates inside our platform about its own patients, leads, and contacts. We process that information only on the clinic’s documented instructions in order to deliver the Services. The clinic — not PI Chiro Nexus — decides how that information is used, and the clinic’s own privacy notice governs it.

If you are a patient, a lead, or a contact of a clinic that uses our platform and you want to access, correct, or delete your information, please contact that clinic directly. If you contact us instead, we will refer your request to the clinic and assist the clinic in responding; we will not unilaterally change or delete a clinic’s records, because they are not ours to change.

For Clinic Data we act as a “service provider” under the California Consumer Privacy Act and as a “processor” under other United States state privacy laws. We do not sell Clinic Data, we do not share it for cross-context behavioral advertising, we do not retain or use it outside the direct business purpose of providing the Services, and we do not combine it with information we receive from other clinics.

2. Protected Health Information and HIPAA

Clinics that use our platform are covered entities under the Health Insurance Portability and Accountability Act (“HIPAA”). To the extent we create, receive, maintain, or transmit Protected Health Information (“PHI”) on a clinic’s behalf, we act as a Business Associate.

PHI is not governed by this Privacy Policy. It is governed by the Business Associate Agreement executed between us and the clinic, which controls in the event of any conflict with this Policy. Our Business Associate Agreement is available at pichironexus.com/baa. Among other things, it obligates us to safeguard PHI, to limit use and disclosure to what the agreement and HIPAA permit, to notify the clinic of any breach of unsecured PHI, to bind our subcontractors to equivalent terms, and to return or destroy PHI at the end of the engagement.

We do not use PHI for our own marketing, we do not sell PHI, and we do not use PHI to train artificial intelligence models. See Section 6.

3. Information We Collect

Depending on how you interact with us, we may collect the following categories of information.

3.1 Company Data (about our customers, prospects, and site visitors)

  • Identifiers and contact information — name, practice or company name, email address, telephone number, mailing and business address, and account usernames.
  • Account and authentication information — login credentials in hashed form, authentication tokens, session records, password reset records, and multi-factor settings. We do not store your password in readable form.
  • Commercial and billing information — plan and subscription status, purchase and renewal history, invoices, refunds, disputes and chargebacks, and billing address. We do not collect or store full payment card numbers; card data is collected and stored by our payment processor.
  • Practice and onboarding information — practice details, locations, providers, services offered, hours and availability, scheduling preferences, intake responses, marketing goals, advertising account identifiers, and other operational information you provide so we can deliver the Services.
  • Agreement and acceptance records — the agreements you sign electronically, the date and time of signature, the signer’s name and email, and the IP address from which the signature was submitted.
  • Communications — emails, text messages, in-app messages, support tickets, chat transcripts, call notes, and correspondence with our team.
  • Call and meeting recordings and transcripts — where a sales, onboarding, or support call is recorded, the audio recording and its automated transcript. We disclose recording at the start of the call and obtain consent where required by law. You may decline to be recorded.
  • Usage and telemetry information — login timestamps, features accessed, pages viewed, documents opened and acknowledged, actions taken in the platform, and administrative access to your account by our staff.
  • Technical information — IP address, browser type and version, operating system, device identifiers, referring URL, and approximate location derived from IP address.

3.2 Business Contact Data (about attorneys, firms, and other businesses)

To support clinic outreach, our platform assembles lists of attorneys, law firms, and other businesses from third-party business data providers and public business listings. This data consists of business contact information — firm name, business address, business telephone number, business email address, website, and practice area. It is not obtained from the individuals themselves. If you are an attorney or business contact and you wish to be removed from our data, see Section 13.

3.3 Clinic Data (about a clinic’s patients, leads, and contacts)

A clinic may cause the following to be processed in our platform: contact information for patients and leads; appointment and scheduling information; the content of text messages and emails exchanged between the clinic and those individuals; lead source and campaign attribution; intake and case information; and, in some configurations, information relating to a person’s physical condition, treatment, or accident. Information in this category is Clinic Data, and information that identifies a patient of the clinic is PHI. See Sections 1 and 2.

3.4 The Same Information, Stated in the Statutory Categories

California and several other states define personal information by fixed statutory categories. In the preceding twelve months we have collected the following categories of Company Data. This is the same information described in Sections 3.1 and 3.2, relabeled to match the statute.

  • Identifiers — collected. Name, email address, telephone number, postal address, account username, IP address.
  • Commercial information — collected. Records of services purchased or considered, subscription and renewal history, billing and transaction records.
  • Internet or other electronic network activity — collected. Pages viewed, features used, login timestamps, and how you interact with our websites and platform. We do not collect your browsing activity on other companies’ websites.
  • Geolocation data — collected, at approximate city and state level only, derived from IP address. We do not collect precise location.
  • Professional or employment-related information — collected. Practice name, professional title, license information, and business address.
  • Audio, electronic, visual, or similar information — collected. Recordings and transcripts of sales, onboarding, and support calls, where recording is disclosed and permitted. See Section 3.1.
  • Inferences — collected. Preferences and characteristics drawn from the information above, used to tailor the Services and our recommendations to you.
  • Biometric information — not collected.
  • Education information — not collected.
  • Characteristics of protected classifications — not collected. We do not ask for or record race, religion, age, sex, disability, or similar characteristics.

3.5 Sensitive Personal Information

The only category of sensitive personal information we collect as Company Data is account log-in credentials, which we hold in hashed form solely to authenticate you. We do not collect government identifiers, financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, or the contents of your mail, email, or text messages as Company Data.

We use sensitive personal information only to perform the Services, secure your account, and prevent fraud — never to infer characteristics about you. Because we limit it to those purposes already, no request is needed to restrict it.

Health information about a clinic’s patients is Clinic Data and Protected Health Information. It is governed by the Business Associate Agreement, not by this Policy. See Sections 1 and 2.

4. Where the Information Comes From

  • Directly from you — forms, checkout, onboarding, intake questionnaires, support requests, calls, and messages.
  • Automatically from your device when you use our websites or platform.
  • From the clinic that granted you access, when we provision an account on the clinic’s behalf.
  • From our payment processor, regarding transactions, renewals, failed payments, and disputes.
  • From third-party business data providers and public business listings, for the Business Contact Data described in Section 3.2.
  • From advertising and CRM platforms you connect to your account, at your direction and using credentials you supply.

5. How We Use Information

  • Provide, operate, secure, maintain, and improve the Services.
  • Create and administer accounts, authenticate users, and provision access.
  • Process payments, manage subscriptions and renewals, and handle refunds, disputes, and chargebacks.
  • Deliver software access, features, onboarding, training, and support.
  • Communicate with you about your account, service changes, product updates, security notices, and legal notices.
  • Send marketing communications about our own Services, subject to your right to opt out at any time.
  • Generate reports, audits, scripts, summaries, and recommendations for you, including with the assistance of artificial intelligence as described in Section 6.
  • Monitor service quality, investigate incidents, and troubleshoot technical problems.
  • Detect, prevent, and address fraud, abuse, unauthorized access, and other misuse.
  • Maintain records evidencing the services we delivered, for use in billing disputes and legal proceedings.
  • Comply with legal obligations and enforce our agreements.

We do not use Clinic Data or PHI for any of the marketing, product-improvement, or model-training purposes described above.

6. Artificial Intelligence and Automated Processing

Our Services use artificial intelligence. We want you to know exactly where, and on what.

6.1 Where we use it

  • Generating practice audits, marketing analyses, and recommendations from the information you submit during onboarding.
  • Drafting and rewriting outreach copy — emails, call scripts, and messages — in your practice’s voice, at your request.
  • Drafting and classifying support responses, and summarizing or transcribing calls and messages.
  • Summarizing account activity for internal operational alerts.

6.2 Which provider processes it

Text submitted for AI processing is transmitted to Anthropic, PBC (the Claude family of models) under a commercial agreement. If we add or change an AI provider, we will update this Section and the list in Section 7.

Where PHI is involved, processing runs in a separate, HIPAA-ready environment governed by a Business Associate Agreement we executed with Anthropic on August 25, 2026. That environment is kept apart from the one we use for ordinary business processing, and features that are not permitted for regulated health data are blocked in it at the provider's end rather than only by our own policy.

6.3 What we commit to

  • Your content is not used to train third-party AI models. Our AI provider is contractually prohibited from using inputs or outputs submitted through its commercial application programming interface to train its models.
  • We do not submit PHI to AI providers except where a clinic has directed us to do so for a permitted purpose and the AI provider is bound by an appropriate Business Associate Agreement.
  • AI output is a draft, not a decision. We do not use AI to make decisions about you that produce legal or similarly significant effects — such as pricing, credit, eligibility, or termination — without human review. Every AI-generated audit, script, or message is reviewable and editable by a human before it is used or sent.
  • AI output can be wrong. Generated content may contain errors and must be reviewed before you rely on it. It is not medical, legal, tax, or financial advice.

6.4 How long our AI provider keeps what we send

Text we send for AI processing is not stored by our provider indefinitely — but it is not discarded the instant it is used, either. You should know the actual periods:

  • Ordinary inputs and outputs are deleted within thirty days of being received or generated.
  • Content flagged by the provider's automated safety systems is kept for up to two years, and the scores those systems generate are kept for up to seven years. This affects a small fraction of traffic, and it applies even where a Business Associate Agreement is in place.
  • Retained content is assessed by automated systems. Any human review happens only through a controlled access path, is limited to a small approved group at the provider, and is recorded in an access log.

These periods are set by the provider and we cannot shorten them. A zero-retention configuration does exist, but it cannot be combined with the HIPAA-ready environment described in Section 6.2 — the two are mutually exclusive. We have chosen the HIPAA-ready environment, because a Business Associate Agreement and the safeguards that come with it protect PHI better than a shorter retention window would.

6.5 Automated messaging

Some messages you receive from the platform — appointment reminders, follow-ups, and status notifications — are sent automatically rather than typed by a person. Where an automated conversational agent handles a message exchange, we will not represent it as a human being if you ask whether you are speaking with a person.

7. How We Share Information — and With Whom

We share information only as described below. We do not share your information with any category of recipient not listed here.

7.1 Service providers we use to operate the Services

Each of the following receives only the information it needs to perform its function, is bound by contract to protect it, and is prohibited from using it for its own purposes. Where the provider handles PHI, it is bound by a Business Associate Agreement.

  • Supabase, Inc. — application database, authentication, and file storage. Hosted on Amazon Web Services infrastructure in the United States.
  • Vercel Inc. — website and application hosting, serverless compute, and request logging.
  • Anthropic, PBC — artificial intelligence processing, as described in Section 6.
  • Twilio Inc. — delivery of text messages (SMS) and related messaging logs.
  • Resend, Inc. — delivery of transactional and account email.
  • Whop Inc. — checkout, subscription billing, payment processing, and dispute handling. Whop collects and stores payment card details directly; we do not.
  • HighLevel Inc. (GoHighLevel / LeadConnector) — customer relationship management, contact records, pipelines, and campaign delivery.
  • LocalProspects — third-party business data provider supplying the attorney and business contact data described in Section 3.2.
  • Google LLC — where you connect a Google account or advertising account, and for document and spreadsheet based reporting.
  • Meta Platforms, Inc. — where you connect a Facebook or Instagram advertising account, so we can read and manage campaigns on your behalf.
  • Telegram Messenger Inc. — delivery of internal operational alerts to our staff. These alerts may contain a customer’s name, practice name, account status, and billing status. They do not contain PHI or payment card numbers.
  • Fathom Video Inc. — recording, transcription, and summarization of sales, onboarding, and support calls where recording is disclosed and permitted.
  • Railway Corp. — background processing for automated website builds.

A current list of the service providers we use is maintained in this Section. We will update it before any new provider begins processing personal information, and we will give notice of material additions as described in Section 18.

7.2 Other disclosures

  • To the clinic that controls your record — where you are a user or contact within a clinic’s account.
  • To professional advisors — attorneys, accountants, insurers, and auditors, under duties of confidentiality.
  • For legal reasons — where required by law, regulation, subpoena, court order, or other legal process, and to establish, exercise, or defend legal claims, including responding to payment disputes and chargebacks.
  • To protect rights and safety — to protect our rights, property, customers, and systems, or the safety of any person.
  • In a business transaction — in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets. Information transferred in such a transaction remains subject to this Policy until it is superseded by a notice that you receive in advance.

8. We Do Not Sell or Share Your Personal Information

We do not sell personal information, and we have not sold personal information in the preceding twelve months, as “sell” is defined by the California Consumer Privacy Act and comparable state laws.

We do not share personal information for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not run third-party advertising pixels or advertising trackers on our websites or in our platform. We do not disclose the mobile telephone numbers or messaging opt-in records of any individual to third parties for those parties’ own marketing purposes.

We have never sold or shared the personal information of any individual we know to be under sixteen years of age.

Disclosures to the service providers listed in Section 7.1 are not sales or shares. Those providers act on our documented instructions, are contractually barred from using the information for their own purposes, and receive no payment or other value from us in exchange for personal information.

9. Text Messaging (SMS)

Where you provide a mobile telephone number and consent to receive text messages, we may send account, service, appointment, and — separately, and only with your consent — marketing text messages. Message and data rates may apply. Message frequency varies.

You may opt out at any time by replying STOP to any message, and you may request help by replying HELP. Opting out of text messages does not opt you out of email or account notices, which you may manage separately.

No mobile information or text messaging consent will be sold, rented, or shared with any third party for marketing purposes. Mobile numbers and consent records are disclosed only to the messaging service provider identified in Section 7.1 for the sole purpose of delivering the messages you asked to receive.

Where a clinic uses our platform to text its own patients and leads, the clinic is responsible for obtaining consent from those individuals and for honoring their opt-outs. We maintain the technical means to record consent and to suppress numbers that have opted out.

10. Cookies, Analytics, and Tracking Signals

We use cookies and similar technologies that are strictly necessary to operate the Services — maintaining your login session, keeping your account secure, remembering your preferences, and balancing load. We also use limited first-party analytics to understand how our sites and platform are used and to diagnose errors.

We do not use third-party advertising cookies, retargeting pixels, or cross-site tracking technologies on our websites or in our platform.

You can usually configure your browser to limit or block cookies, though some features of the platform will not function without the strictly necessary ones.

Global Privacy Control. Where we receive an opt-out preference signal such as Global Privacy Control from your browser, we treat it as a valid request to opt out of any sale or sharing of personal information from that browser. Because we do not sell or share personal information at all, this signal does not change our handling, but it is honored.

11. How Long We Keep Information

We keep information only as long as we need it for the purpose it was collected, and then delete it or render it unidentifiable. Our standard periods are:

  • Account and practice records — for the term of your subscription and up to seven years after it ends, to support tax, accounting, audit, and legal defense obligations.
  • Billing and transaction recordsseven years from the transaction, as required for tax and financial recordkeeping.
  • Signed agreements, acceptance records, and delivery evidenceseven years from signature, to evidence the services delivered in the event of a payment dispute or legal claim.
  • Text messaging logs and consent recordsfour years, to demonstrate consent and opt-out compliance.
  • Support conversations, call recordings, and transcriptsthree years.
  • Server, security, and access logstwelve months, except where a log is preserved for an ongoing investigation.
  • Marketing and prospect data — until you opt out or ask to be removed. When you opt out, we retain the minimum record necessary — typically your email address or telephone number in a suppression list — indefinitely, because that is the only way to guarantee we never contact you again.
  • Protected Health Information — as directed by the clinic and by the Business Associate Agreement, which requires return or destruction at the end of the engagement.
  • Content sent to our AI provider — held by that provider on the separate schedule described in Section 6.4, which we do not control and cannot shorten.

Backups. When we delete information from our live systems it may persist in encrypted backups for up to ninety days before those backups age out on their normal rotation. During that window the information is not used for any purpose and is not accessible through the Services.

We may retain information longer than the periods above where a legal hold, an open dispute, an investigation, or an applicable law requires it. In that case we retain only what the obligation requires, and we delete it when the obligation ends.

12. Data Security

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include encryption of data in transit using industry-standard transport layer security; encryption of data at rest; row-level access controls that separate each clinic’s data from every other clinic’s data; role-based access limits so that our personnel can reach only the data their job requires; audit logging of administrative access to customer accounts; and secure credential storage.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly if you believe your account has been compromised.

Security incidents. If we become aware of a breach of security leading to the unauthorized acquisition of unencrypted personal information, we will notify affected individuals and the applicable authorities without unreasonable delay and within the timeframes required by applicable law. Where the incident involves PHI, we will notify the affected clinic in accordance with the Business Associate Agreement and the HIPAA Breach Notification Rule.

13. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights with respect to Company Data:

  • Know and access — to confirm whether we process your personal information, and to obtain a copy of it and the categories of sources, purposes, and recipients.
  • Correct — to have inaccurate personal information corrected.
  • Delete — to have your personal information deleted, subject to the exceptions in Section 11 and applicable law.
  • Portability — to receive your personal information in a portable, machine-readable format.
  • Opt out of sale, sharing, and targeted advertising — which we already honor by default, because we do none of these.
  • Limit use of sensitive personal information — we do not use or disclose sensitive personal information for any purpose beyond what is necessary to provide the Services.
  • Opt out of profiling — we do not engage in profiling that produces legal or similarly significant effects.
  • Non-discrimination — we will not deny you service, charge you a different price, or provide you a lesser quality of service because you exercised a privacy right.
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting processing already carried out.

These rights are provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under comparable laws in Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky, Rhode Island, and other states as those laws take effect.

13.1 How to make a request

Email support@vgtmedia.com with the subject line “Privacy Request,” or write to us at the address in Section 19. Tell us which right you are exercising and give us enough information to locate your records.

13.2 How we verify and respond

We will verify your identity before acting, typically by confirming control of the email address or telephone number already on file, or by asking you to answer questions about information we already hold. We will not ask you for information we do not already have solely to verify a request.

We acknowledge requests within ten business days and respond substantively within forty-five calendar days. If we need more time we will tell you why and extend by up to an additional forty-five days.

13.3 Authorized agents

You may use an authorized agent to submit a request. We will require written proof of the agent’s authority and may ask you to verify your own identity directly.

13.4 Appeals

If we decline your request, we will tell you why. You may appeal that decision by replying to our response with the subject line “Privacy Appeal.” We will review the appeal and respond in writing within forty-five days, explaining the reasons for our decision. If we deny the appeal, we will provide you with a method to contact your state attorney general to lodge a complaint.

13.5 Requests about Clinic Data

If your request concerns information held by a clinic in our platform — you are a patient, lead, or contact of that clinic — we will forward your request to the clinic and support the clinic in responding, but the clinic must make the decision. See Section 1.

13.6 Requests about Business Contact Data

If you are an attorney or business contact and want your business listing removed from our data, email support@vgtmedia.com and we will remove it and add it to a suppression list so it is not re-imported.

14. California Shine the Light

California Civil Code Section 1798.83 permits California residents to request information about disclosures of personal information to third parties for those parties’ direct marketing purposes. We make no such disclosures.

15. Children’s Privacy

The Services are business software sold to healthcare practices. They are not directed to children, and we do not knowingly collect personal information directly from anyone under sixteen years of age. If we learn we have collected such information other than as Clinic Data provided by a clinic, we will delete it promptly. A clinic that treats minor patients is responsible under its own policies and under HIPAA for information about those patients.

16. Third-Party Links and Connected Accounts

Our websites and platform may link to, or connect with, third-party websites, tools, and platforms. When you connect a third-party account — for example an advertising or calendar account — you authorize us to access it using the permissions you grant, and you may revoke that access at any time through your account settings or through the third party. We are not responsible for the privacy practices of third parties, and their own privacy policies govern their handling of your information.

17. Location of Processing

We are based in the United States and we process and store information in the United States. If you access the Services from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those of your jurisdiction. The Services are not offered to individuals in the European Economic Area or the United Kingdom, and we do not target those markets.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the Effective Date above and post the updated version at pichironexus.com/privacy-policy. If we make a material change — including any change to the categories of information we collect, the purposes we use it for, the artificial intelligence disclosures in Section 6, or the service providers listed in Section 7.1 — we will provide at least thirty days’ advance notice by email to account holders or by prominent notice in the platform before the change takes effect. We maintain prior versions of this Policy and will provide a copy on request.

19. Contact Us

For questions about this Privacy Policy, to exercise a privacy right, or to report a concern about our data practices, contact us at:

VGT MEDIA, LLC

d/b/a PI Chiro Nexus

500 North Andrews Avenue, Fort Lauderdale, FL 33301

support@vgtmedia.com

Effective August 25, 2026. Questions: support@vgtmedia.com