Privacy Policy
Effective Date: August 13, 2026
Version: 1.0
Operator: ARYX LLC (aryx.pro). The contracting party named on an Order Form controls for that transaction.
1. Introduction and Scope
This Privacy Policy ("Policy") explains how ARYX LLC and its affiliates ("ARYX", "we", "us", or "our") collect, use, disclose, and otherwise process Personal Information in connection with the ARYX website at https://aryx.pro, the ARYX Accounts identity and billing hub (aryx.pro / app.aryx.pro), and the ARYX software applications and related services (collectively, the "Services").
ARYX operates a multi-tenant B2B software platform for health-plan enrollment, administration, and billing. Our applications include EnrollFlow (member enrollment, which processes Protected Health Information), ARYX CRM (lead and member relationship management for Tenant staff), ARYX Accounts (central sign-up, single sign-on, org/tenant provisioning, and the subscription/billing engine), AdvisorIQ, and our IT Ticketing / Support application.
This Policy applies to Personal Information we process as a controller (or "business" under U.S. state privacy laws) — principally information about our prospective and actual business customers, website visitors, and the individuals who administer accounts on behalf of a Tenant. It also describes, at a high level, the categories of information we process as a processor / service provider (and, where applicable, a HIPAA business associate) strictly on behalf of and under the documented instructions of our Tenants. Section 3 explains this distinction, which is critical to how privacy rights are exercised.
Capitalized terms not defined inline have the meaning given in the ARYX Terms of Service (see /legal/terms) and, where applicable, the Data Processing Addendum (see /legal/dpa).
2. Definitions
- Customer / Tenant — a health plan, agency/brokerage, or benefit administrator that subscribes to the Services under a written agreement with ARYX.
- Authorized User — an individual (typically Tenant staff) permitted by a Tenant to access the Services.
- Member Data — Personal Information about a Tenant's members, enrollees, applicants, and prospects that a Tenant (or its Authorized Users) submits to or generates within the Services, including via EnrollFlow.
- PHI — Protected Health Information as defined by HIPAA, processed within EnrollFlow and related components on behalf of a Tenant.
- Personal Information — information relating to an identified or identifiable individual, including "personal data" (GDPR) and "personal information" (CCPA/CPRA).
- Processor / Subprocessor — an entity that processes Personal Information on behalf of a controller (here, ARYX acts as Processor for Tenants; our own vendors act as Subprocessors to ARYX).
- Services — as defined in Section 1.
3. Our Roles: Controller vs. Processor / Business Associate
ARYX plays two distinct privacy roles, and your rights and our obligations depend on which applies:
(a) ARYX as Processor / Service Provider / Business Associate. For Member Data and PHI submitted to or generated within the Services, the Tenant is the controlling entity (controller / covered entity or its business associate). ARYX processes such data solely to provide the Services and only on the Tenant's documented instructions, as set out in the applicable subscription agreement, Data Processing Addendum (see /legal/dpa), and, for PHI, the Business Associate Agreement (see /legal/baa). If you are a member, enrollee, or applicant of a health plan, agency, or administrator that uses ARYX, please direct privacy requests to that organization; we will support them in responding, but the Tenant determines the purposes and means of processing.
(b) ARYX as Controller. For information we determine the purposes and means of processing — including account registration and administration data for Authorized Users, billing and subscription data for Tenants, website and product usage/analytics data, security and audit logs, and sales and marketing communications — ARYX acts as a controller / business. The remainder of this Policy focuses primarily on this controller-role processing, with cross-references to the Tenant-facing terms where relevant.
4. Personal Information We Collect
We collect the following categories, depending on how you interact with the Services:
- Account and identity data (controller): name, business email, employer/Tenant affiliation, role, username, and authentication credentials managed through ARYX Accounts. Authentication is provided via Supabase Auth; we do not store passwords in plaintext.
- Billing and transaction data (controller, for Tenants): subscription plan, bundle selection, billing contact, transaction history, and stored payment-profile references. Card payments are handled through Authorize.Net using its Customer Information Manager (CIM). Card data is tokenized in-browser via Accept.js (opaqueData); the primary account number (PAN) and CVV never reach ARYX servers or our database (PCI-DSS SAQ-A posture). See /legal/billing and ARYX's refund and settlement standards (see also /legal/billing).
- Usage, device, and log data (controller): IP address, device/browser type, pages viewed, feature interactions, timestamps, and security/audit events generated by our hosting and database infrastructure (Vercel and Supabase).
- Cookies and similar technologies (controller): see Section 9.
- Communications data (controller): records of your correspondence with our sales, support, and IT ticketing teams, including email (delivered via Resend) and SMS/voice interactions (delivered via GoTo).
- Member Data and PHI (processor / business associate): enrollment, eligibility, demographic, contact, and health-related information that Tenants and their Authorized Users submit to EnrollFlow and other apps. ARYX processes this only per Section 3(a).
We do not intentionally collect Personal Information from the general public through EnrollFlow; that data is submitted by or on behalf of Tenants.
5. Sources of Personal Information
We obtain Personal Information (i) directly from you (e.g., when you register, subscribe, or contact us); (ii) from the Tenant on whose behalf you act, or whose members' data flows through the Services; (iii) automatically through your use of the Services (logs, cookies, analytics); and (iv) from our Subprocessors and service providers (e.g., payment status from Authorize.Net, delivery events from Resend, communication metadata from GoTo).
6. How We Use Personal Information, and Legal Bases
As a controller, we process Personal Information for the following purposes. Where the GDPR or similar laws apply, the corresponding legal basis is noted:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide, operate, and secure the Services; provision orgs/tenants; enable SSO | Performance of a contract; legitimate interests |
| Authenticate Authorized Users and enforce multi-tenant isolation | Performance of a contract; legitimate interests (security) |
| Bill Tenants, process subscription charges, and manage payment profiles | Performance of a contract; legal obligation |
| Provide customer support and respond to IT tickets | Performance of a contract; legitimate interests |
| Monitor, detect, and prevent fraud, abuse, and security incidents | Legitimate interests; legal obligation |
| Improve, analyze, and develop the Services (product analytics) | Legitimate interests; consent (where required) |
| Send administrative and transactional communications | Performance of a contract; legitimate interests |
| Send marketing communications about ARYX products | Consent and/or legitimate interests (opt-out available) |
| Comply with law and enforce our agreements | Legal obligation; legitimate interests |
For processing as a processor / business associate (Member Data and PHI), the legal basis and lawful purpose are established by the Tenant as controller/covered entity; ARYX processes only on documented instructions per Section 3(a) and the DPA/BAA.
7. How We Share Personal Information
We disclose Personal Information only as described here:
- Subprocessors and service providers. We rely on vetted vendors to deliver the Services, each bound by contractual confidentiality and data-protection obligations. Core Subprocessors include Supabase (database, authentication, storage), Vercel (application hosting), Authorize.Net (payment processing), Resend (transactional and marketing email), and GoTo (SMS/voice). A current list is maintained in /legal/subprocessors.
- Within a Tenant's boundary. Member Data and PHI are made available to the Tenant and its Authorized Users. Multi-tenant isolation is enforced at the database layer through PostgreSQL Row-Level Security (RLS), org-scoped, on Supabase, so that one Tenant cannot access another Tenant's data.
- Professional advisers and corporate transactions. We may share Personal Information with auditors, legal and financial advisers, or an acquirer/successor in connection with a merger, acquisition, financing, or asset sale, subject to appropriate safeguards.
- Legal and safety. We may disclose Personal Information to comply with law, respond to lawful requests and legal process, protect our rights and property, and protect the safety of any person.
ARYX does not sell Personal Information, and does not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. ARYX is not a bank, card network, payment processor, money transmitter, or merchant of record; the Tenant holds and controls the Authorize.Net merchant account, and settlement funds flow Processor → Tenant and never through ARYX.
8. International Data Transfers
The Services are primarily hosted in the United States. If you access the Services from outside that jurisdiction, your Personal Information may be transferred to, stored in, and processed in the United States or other countries where we or our Subprocessors operate. Where required, we implement appropriate transfer mechanisms — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — and conduct transfer risk assessments. Transfer-mechanism details for processor-role data are addressed in /legal/dpa.
9. Cookies, Analytics, and Tracking Technologies
We and our providers use cookies, local storage, and similar technologies to authenticate sessions, remember preferences, secure the Services, and understand product and website usage. We use strictly necessary cookies (e.g., session/auth tokens issued through Supabase Auth), and may use functional and analytics cookies. Where required by law (e.g., in the EU/UK), non-essential cookies are set only with your consent, obtained via our cookie banner, and you may withdraw consent at any time. You can also control cookies through your browser settings. We honor Global Privacy Control (GPC) signals where legally required. A detailed inventory may be maintained in a separate Cookie Notice.
10. HIPAA and Protected Health Information
Where ARYX processes PHI within EnrollFlow or related components on behalf of a Tenant that is a HIPAA covered entity or business associate, ARYX acts as a business associate and processes PHI only as permitted by the applicable Business Associate Agreement (see /legal/baa) and the HIPAA Privacy and Security Rules. This Policy does not modify or supersede any BAA. If you are an individual whose PHI is processed through the Services, your rights with respect to that PHI (including access and amendment) are administered by the Tenant as the covered entity; please contact the health plan, agency, or administrator that provided your coverage. Our safeguards for PHI are described further in ARYX's information security program.
11. Data Subject and Consumer Privacy Rights
Depending on your jurisdiction and our role, you may have the following rights regarding Personal Information for which ARYX is the controller:
- Access / know — obtain confirmation of, and access to, the Personal Information we hold about you, and information about how we process it.
- Correction / rectification — correct inaccurate or incomplete Personal Information.
- Deletion / erasure — request deletion, subject to legal retention obligations (see ARYX's data ownership and retention terms).
- Portability — receive certain Personal Information in a portable format.
- Restriction / objection — restrict or object to certain processing, including direct marketing.
- Withdraw consent — where processing is based on consent.
- Opt out of sale/share and certain profiling (CCPA/CPRA) — note ARYX does not sell or share Personal Information as defined by those laws.
- Non-discrimination — we will not discriminate against you for exercising your rights.
To exercise these rights, contact us using Section 15. We will verify your identity before responding and will respond within the timeframes required by applicable law (e.g., GDPR: generally within one month; CCPA/CPRA: generally within 45 days, extendable). You may use an authorized agent where permitted, and you may appeal a decision or lodge a complaint with your supervisory authority (EU/UK) or state attorney general.
Important — processor-role data. For Member Data and PHI, ARYX is a processor / business associate and cannot independently grant access, correction, or deletion requests. We will refer your request to the relevant Tenant (the controlling entity) and assist the Tenant in fulfilling it as required by our agreements and applicable law.
12. Data Retention
We retain Personal Information only as long as necessary for the purposes described in this Policy, to provide the Services, and to comply with legal, tax, accounting, audit, and dispute-resolution obligations. For processor-role data, retention and deletion follow the Tenant's instructions and the applicable agreement. Retention schedules, criteria, and secure-destruction methods are defined in ARYX's data ownership and retention terms.
13. Security
We maintain administrative, technical, and organizational measures designed to protect Personal Information, including encryption in transit and at rest, org-scoped Row-Level Security for tenant isolation, least-privilege access controls, authentication through Supabase Auth, tokenization of card data via Accept.js so that PAN/CVV never reach our systems, and inbound payment webhooks verified according to Processor requirements. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Our security program is described in ARYX's information security program, and our incident-response commitments (including breach notification) are addressed in ARYX's incident response commitments.
14. Children's Privacy
The Services are intended for use by businesses and their Authorized Users, and are not directed to children. We do not knowingly collect Personal Information directly from children under 13 (or the applicable age of digital consent) in our controller capacity. Member Data submitted by Tenants may relate to individuals of any age (e.g., dependents enrolled in a health plan); such data is processed under the Tenant's authority and the BAA/DPA, not collected by ARYX directly from the individual. If you believe we have inadvertently collected such information in our controller role, contact us under Section 15 and we will delete it as required by law.
15. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Services. We will revise the "Effective Date" and, for material changes, provide additional notice (e.g., via email to Tenant administrators or an in-product notice) as required by law. Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law.
16. How to Contact Us
For privacy questions, requests, or complaints regarding ARYX's controller-role processing, contact:
- Privacy Contact: legal@aryx.pro
- Data Protection Officer / EU-UK Representative (if applicable): legal@aryx.pro
- Security Contact: legal@aryx.pro
- General Support: hello@aryx.pro
- Postal / Notice Address: the notice address designated on the applicable Order Form
If you are a member, enrollee, or applicant, please first contact the health plan, agency, or benefit administrator that provided your coverage, as they are the controlling entity for your Member Data and PHI.
Questions about this document? Contact legal@aryx.pro. Related: all legal documents · Terms of Service.