This Privacy Policy describes how Ariez Biocorp LLC, doing business as Aries Mens Health ("we", "us", "our"), collects, uses, stores, and shares information when you visit ariesmenshealth.com (the "Site") or use our telehealth services (the "Services"). By using the Site or Services, you agree to this Privacy Policy.
1. Information we collect
1.1 Information you provide
- Contact information: name, email address, phone number, state of residence, mailing address.
- Account information: account credentials, date of birth, emergency contact.
- Health information: medical history, symptoms, prior diagnoses, current medications, allergies, lifestyle factors, goals, and any other clinical information you submit during intake or to your clinician.
- Laboratory results: bloodwork, diagnostic panel results, and related clinical data.
- Payment information: handled by our payment processor; we do not store full card numbers on our servers.
- Communications: messages you send us through forms, email, or the patient portal.
1.2 Information collected automatically
- Device and usage data: IP address, browser type, device identifiers, referring URLs, pages visited, time on page.
- Cookies and similar technologies: we use cookies and similar technologies to operate the Site, remember preferences, and measure traffic. See "Cookies" below.
2. How we use information
- To provide, operate, and maintain the Services.
- To schedule consultations, order bloodwork, deliver clinical protocols, and coordinate with licensed pharmacies.
- To communicate with you about your account, your protocol, appointment reminders, and follow-ups.
- To respond to inquiries and provide customer support.
- To process payments and maintain billing records.
- To improve the Services, measure performance, and develop new features.
- To comply with legal, regulatory, and LegitScript program obligations.
- To detect, investigate, and prevent fraud, abuse, or security incidents.
3. HIPAA and protected health information
Protected Health Information ("PHI") created or received in the course of providing clinical services is handled in accordance with the Health Insurance Portability and Accountability Act ("HIPAA") and applicable state health-information laws. Our licensed clinicians, and any workforce members or business associates with access to PHI, are bound by HIPAA privacy and security obligations. A separate Notice of Privacy Practices describes your rights regarding PHI, including your rights of access, amendment, accounting of disclosures, and to request restrictions, consistent with 45 C.F.R. Part 164 and New York Public Health Law §18. To request a copy, email support@ariesmenshealth.com.
3.1 Business Associates
We execute written Business Associate Agreements ("BAAs") with service providers that create, receive, maintain, or transmit PHI on our behalf. Categories of Business Associates we use or anticipate using include: our HIPAA-covered intake-form vendor; our electronic health records and patient-portal platform; our secure messaging and telehealth-video vendor; our clinical laboratory partners; our licensed dispensing pharmacy partners; our bloodwork-analysis AI vendor (HATHR Medical AI); and our payment processor. We do not share PHI with any vendor that has not executed a current BAA.
3.2 New York SHIELD Act compliance
We comply with the New York Stop Hacks and Improve Electronic Data Security Act (the "SHIELD Act," N.Y. Gen. Bus. Law §899-bb) and maintain a written data-security program that includes reasonable administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of private information of New York residents. This program includes: designation of one or more employees to coordinate the security program; identification of reasonably foreseeable internal and external risks; assessment of the sufficiency of safeguards in place to control those risks; training and management of employees in security practices; vendor-selection diligence with contractual safeguard requirements; and periodic evaluation and adjustment of the program in light of changes.
4. How we share information
We do not sell your personal or health information. We share information only as follows:
- Your clinical team: licensed clinicians providing your care.
- Service providers: vendors who help operate the Services (for example, electronic health records, telehealth platforms, scheduling, secure messaging, payment processing, email, analytics). These vendors are bound by contract to appropriate confidentiality and, where applicable, Business Associate Agreements.
- Licensed pharmacies and laboratories: to order labs or fill prescriptions on your behalf.
- Legal and safety: to comply with law, legal process, or regulator requests; to enforce our terms; or to protect the rights, property, or safety of patients, staff, or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Privacy Policy.
- With your consent: for any other disclosure you direct us to make.
5. Data retention
We retain personal information for as long as needed to provide the Services and to meet legal, regulatory, tax, accounting, and clinical record-retention requirements. Medical records are retained for the minimum period required under applicable state law. When retention is no longer required, information is deleted, de-identified, or anonymized.
6. Security
We use administrative, technical, and physical safeguards designed to protect personal and health information from unauthorized access, disclosure, alteration, or destruction. These include access controls, encryption in transit (TLS 1.2 or higher) and encryption at rest for PHI, logging and monitoring, workforce security training, vendor due diligence, and periodic review of our security program. The Site is delivered through Cloudflare with always-on HTTPS, HSTS preloading, and standard security headers. No method of transmission or storage is 100% secure.
6.1 Breach notification
In the event of a breach affecting your information, we will notify you and the applicable regulators as required by law, including: HIPAA Breach Notification Rule (45 C.F.R. §§164.400–414); New York General Business Law §899-aa (the NY Information Security Breach and Notification Act); and the SHIELD Act breach-notification requirements. New York residents are entitled to notice of a breach involving their private information without unreasonable delay and, where applicable, notice to the New York State Attorney General, the New York State Department of State Division of Consumer Protection, and the New York State Police.
7. Your rights
Depending on where you live, you may have the following rights:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion of your information, subject to legal and clinical record-retention requirements.
- Object to, or restrict, certain processing.
- Withdraw consent where processing is based on consent.
- File a complaint with a regulator, including the New York State Attorney General's Bureau of Internet and Technology (28 Liberty Street, New York, NY 10005) and the U.S. Department of Health and Human Services, Office for Civil Rights.
New York patients additionally have rights under New York Public Health Law §18 to access, copy, and request correction of their medical records. To exercise any right described in this section, email support@ariesmenshealth.com. We will respond within the time required by applicable law.
8. Cookies
We use cookies and similar technologies to operate the Site, remember preferences, understand usage, and improve the Services. You can control cookies through your browser settings. Some features of the Site may not function properly if cookies are disabled.
9. Children
The Services are intended for adults 18 years of age or older. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, contact us and we will take steps to delete it.
10. Third-party links
The Site may link to third-party websites. We are not responsible for the privacy practices of those websites. Review their privacy policies before providing information.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy with a new effective date. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
12. Contact
Ariez Biocorp LLC, dba Aries Mens Health
82 Merrick Road, Amityville, NY 11701
Email: support@ariesmenshealth.com
Phone: (516) 540-2399