Consent, E-Signature & Enrollment Authorization Policy
Effective Date: August 13, 2026
Version: 1.0
Operator: ARYX LLC (aryx.pro). The contracting party named on an Order Form controls for that transaction.
1. Purpose and Scope
This Policy governs how the ARYX platform operated by ARYX LLC ("ARYX", the "Services") captures, records, and preserves electronic consent, electronic signatures, and enrollment and payment authorizations. Its objective is to ensure that every enrollment authorization and authorization-to-bill captured in EnrollFlow — and every associated consent to transact electronically — is legally valid, attributable, and provable in the event of a dispute, chargeback, audit, or regulatory inquiry.
The Policy applies to:
- ARYX, in its role as software and workflow-orchestration provider;
- Customers (also referred to as "Tenants") — the health plans, agencies/brokerages, and benefit administrators that operate on the platform;
- Authorized Users — Tenant staff who configure enrollment workflows and act on behalf of a Tenant; and
- Members — the enrollees and prospective enrollees who provide consent and execute authorizations through EnrollFlow.
This Policy addresses U.S. electronic-transaction law, principally the federal Electronic Signatures in Global and National Commerce Act ("ESIGN Act", 15 U.S.C. §§ 7001 et seq.) and the Uniform Electronic Transactions Act ("UETA") as adopted by the applicable state(s). It does not, by itself, establish the substantive terms of any enrollment or payment obligation; those are governed by the Tenant's plan documents and the applicable Terms. It should be read together with ARYX's refund and settlement standards, ARYX's data ownership and retention terms (retention of authorization records), ARYX's audit logging standards (records of consent as evidence), and ARYX's electronic communications standards (Tenant responsibility to obtain communications consent).
2. Definitions
Capitalized terms not defined here have the meaning given in the master Terms. Key terms:
- Electronic Record — a contract, disclosure, authorization, or other record created, generated, sent, communicated, received, or stored by electronic means within the Services.
- Electronic Signature — an electronic sound, symbol, or process attached to or logically associated with an Electronic Record and executed or adopted by a person with the intent to sign the record (per ESIGN/UETA). Within EnrollFlow this includes typed-name adoption, checkbox/affirmation ("click-through") acceptance, and equivalent affirmative acts.
- Enrollment Authorization — a Member's affirmative act consenting to enroll in a Tenant plan or benefit on the disclosed terms.
- Authorization-to-Bill — a Member's affirmative authorization permitting the Tenant (via the Services and the Processor) to initiate one-time and/or recurring charges against a stored payment method, on disclosed terms (amount, frequency, duration).
- Processor — Authorize.Net, the payment gateway used to tokenize and submit charges. ARYX uses Authorize.Net CIM (Customer Information Manager) stored payment profiles together with a schedule-driven recurring charge engine.
- Consent Record — the immutable evidentiary record ARYX generates when a consent, signature, or authorization is captured (see Section 7).
- Member Data / PHI — member personal information and, in EnrollFlow, protected health information subject to HIPAA.
- Subprocessor — a third party engaged to process data in support of the Services (e.g., Supabase, Vercel, Resend, GoTo).
3. Consumer Consent to Transact Electronically (ESIGN / UETA)
Before any Enrollment Authorization or Authorization-to-Bill is captured, EnrollFlow presents each Member with an electronic-transactions consent disclosure and requires the Member to affirmatively consent to conducting the transaction electronically. Consistent with ESIGN § 7001(c), that disclosure discloses, at minimum:
- that the Member consents to receive disclosures, authorizations, and records electronically, and to sign electronically;
- the Member's right to receive records on paper and how to request a paper copy, and any fee for doing so (default: no fee — no fee for paper copies);
- the right to withdraw consent, and the procedure and any consequences of withdrawal (see Section 8);
- whether consent applies to a single transaction or to an ongoing relationship;
- how to update contact information used to deliver electronic records; and
- the hardware and software requirements reasonably needed to access and retain the Electronic Records (a current mainstream browser, an internet connection, and the ability to view/download PDF or HTML documents).
Consent is captured through an affirmative act (checkbox plus button, or typed-name adoption) — never through pre-checked boxes, silence, or inactivity. Where ESIGN requires it, EnrollFlow uses a reasonable demonstration step confirming the Member can access records in the format in which they will be delivered before consent is treated as effective.
4. Validity and Attribution of Electronic Signatures
An Electronic Signature captured in the Services is intended to carry the same legal effect as a handwritten signature under ESIGN § 7001(a) and UETA § 7. To support validity and attribution (UETA § 9), EnrollFlow:
- authenticates the signer's session (Member identity is established via the enrollment session and, where applicable, SSO through ARYX Accounts);
- records the specific affirmative act taken (the control clicked, the text typed, the exact on-screen language shown);
- binds the signature to the specific version of the document or authorization presented (see Section 6); and
- writes an immutable Consent Record (Section 7) at the moment of capture.
No Electronic Signature is inferred from navigation, scrolling, or partial completion. A signature is captured only when the Member performs the disclosed affirmative act on a screen that displays the operative terms.
5. Valid Enrollment Authorization and Authorization-to-Bill
5.1 Enrollment Authorization
A valid Enrollment Authorization requires that, before the Member's affirmative act, EnrollFlow display the material terms of the enrollment (plan/benefit identity, effective date or effective-date logic, and the Tenant offering it) and that the Member affirmatively assent. The Tenant is responsible for the accuracy and legal sufficiency of the plan terms displayed (Section 9).
5.2 Authorization-to-Bill (Recurring Payment Authorization)
Because ARYX initiates schedule-driven recurring charges rather than relying on gateway-native ARB, the payment authorization must be explicit and complete before capture. Prior to the Member's affirmative authorization, EnrollFlow discloses on-screen, in clear and conspicuous language, at minimum:
- the amount to be charged (or, for variable amounts, how the amount is determined and any cap);
- the frequency of charges (e.g., monthly) and the charge date or billing anchor;
- the duration of the authorization (fixed term, or until cancelled) and, for open-ended authorizations, that charges continue until the Member cancels;
- the payment method to be charged (masked card descriptor returned by the Processor);
- how to cancel or revoke the authorization and the effect of doing so; and
- that the Tenant — not ARYX — is the merchant of record and holds the Authorize.Net merchant account.
Card data is tokenized in-browser via Accept.js (opaqueData); the PAN and CVV never reach ARYX servers or the ARYX database, and ARYX stores only a Processor-issued CIM payment-profile reference. The Consent Record captures the exact authorization terms disclosed so that the "what the Member agreed to" is reconstructable independently of any later schedule change.
5.3 Changes to a Recurring Authorization
A material change to a recurring authorization (amount increase, frequency change, or extension of duration beyond what was disclosed) requires a new Authorization-to-Bill capturing the revised terms; it is not effected by silent modification of the billing schedule. Settlement-state language for the resulting charges is governed by ARYX's refund and settlement standards and by ARYX's financial-state philosophy: a charge is never represented as "Completed" or "Settled" merely because an API returned HTTP 200.
6. Document Versioning and Presentation Integrity
Every disclosure, consent text, and authorization form presented in EnrollFlow is versioned. The Consent Record stores the identifier and version of the exact document/template shown to the Member, so that ARYX and the Tenant can later produce the precise language a Member saw and assented to. When disclosure or authorization language changes, the prior version is retained and remains associated with all Consent Records that referenced it. Tenants must not rely on retroactive edits to consent text to alter the meaning of previously captured authorizations.
7. Consent Records as Evidence
At the moment any consent, signature, or authorization is captured, the Services write an immutable Consent Record intended to serve as evidence of the transaction. Each Consent Record captures, at minimum:
- Timestamp (server-side, UTC, with source);
- IP address and user agent of the capturing session;
- Member/session identifier and Tenant/org identifier;
- Document identifier and version presented (Section 6);
- Capture method (e.g., checkbox affirmation, typed-name adoption, click-through);
- the exact on-screen text/label of the control the Member acted upon; and
- for Authorizations-to-Bill, the disclosed amount, frequency, and duration and the masked payment descriptor.
Consent Records are stored in Supabase Postgres and are subject to org-scoped Row-Level Security (RLS), so that a Tenant may access only Consent Records within its own tenancy. Consent Records are treated as write-once evidentiary records; administrative access, integrity controls, and export for dispute/chargeback response are described in ARYX's audit logging standards. ARYX will, on a Tenant's authenticated request and subject to the Terms, produce the Consent Record(s) needed to substantiate an authorization in a dispute.
8. Withdrawal of Consent
A Member may withdraw consent to transact electronically and may revoke an Authorization-to-Bill. Withdrawal:
- is prospective only — it does not invalidate the legal effect of records or authorizations already properly executed, or charges already initiated before withdrawal took effect;
- is captured as its own Consent Record (timestamp, method, scope);
- for an Authorization-to-Bill, causes the associated recurring schedule to be discontinued going forward per the disclosed cancellation terms and ARYX's refund and settlement standards; and
- does not, by itself, terminate the underlying plan enrollment or any non-electronic obligations, which are governed by the Tenant's plan documents.
Where a Member withdraws consent to receive records electronically but an obligation to deliver a record remains, the Tenant must arrange delivery by an alternative lawful means.
9. Tenant Responsibilities
As the entity with the direct relationship to the Member and as merchant of record, the Tenant is responsible for, and represents and warrants that:
- it has the authority to enroll each Member and to initiate charges against the Member's payment method on the disclosed terms;
- it has obtained all Member consents required for communications (email via Resend, SMS/voice via GoTo) in compliance with applicable law, as further described in ARYX's electronic communications standards;
- the plan/benefit terms, pricing, frequency, and duration displayed in EnrollFlow are accurate, current, and legally sufficient;
- it holds and controls the Authorize.Net merchant account; funds settle Processor → Tenant and never flow through ARYX; and
- it uses the Consent Records solely for legitimate enrollment, billing-substantiation, dispute-response, and compliance purposes.
ARYX provides the software mechanism to capture and preserve consent and authorization; it does not verify the Member's identity beyond the session controls described above and does not independently confirm the Tenant's authority to enroll or bill.
10. ARYX Responsibilities and Limitations
ARYX will: present the disclosures and capture controls described in this Policy; generate and preserve Consent Records; version disclosure and authorization content; and make Consent Records retrievable to the authorized Tenant. ARYX is not a bank, card network, payment processor, money transmitter, or merchant of record, and provides software and workflow orchestration only. ARYX does not provide legal advice to Tenants regarding the sufficiency of their consent language, plan disclosures, or communications-consent practices; Tenants remain responsible for legal compliance in their jurisdictions.
11. Delivery, Retainability, and Format of Electronic Records
Electronic Records are delivered in a form the Member can retain and reproduce (downloadable/printable HTML or PDF, or on-screen with a download option), satisfying ESIGN § 7001(e) retainability. A copy of, or authenticated access to, each executed authorization is made available to the Member at or promptly after capture, and confirmations may be delivered by email via Resend. Records remain accessible for the retention period defined below and in ARYX's data ownership and retention terms.
12. Retention of Authorization and Consent Records
Consent Records, executed authorizations, and versioned disclosure content are retained for the period required to substantiate the transaction and to comply with applicable law, chargeback windows, and audit needs — default retain for the life of the enrollment plus 7 years, subject to the controlling schedule in ARYX's data ownership and retention terms and to any longer HIPAA or state-law requirement. Retention, secure disposal, and legal-hold handling follow that policy. Deletion or anonymization requests are honored subject to overriding retention obligations.
13. Governing Law and Interpretation
This Policy is governed by the laws of the United States, and disputes are subject to venue in the courts designated on the applicable Order Form, without prejudice to any mandatory consumer-protection law of the Member's jurisdiction. Nothing in this Policy waives any right a Member has under the ESIGN Act, UETA as adopted in the applicable state, or other applicable law. If any provision conflicts with a mandatory provision of applicable law, that provision is modified to the minimum extent necessary to comply, and the remainder stays in effect.
14. Review and Change Management
This Policy is reviewed at least annually and upon any material change to EnrollFlow's consent-capture flow, the Processor integration, or applicable electronic-transactions law. Material changes to consent or authorization language follow the versioning discipline in Section 6.
Questions about this document? Contact legal@aryx.pro. Related: all legal documents · Privacy Policy · Terms of Service.