Privacy policy
Privacy policy.
Two situations, handled differently: information you give us through this website, and information processed at a customer’s front desk on their behalf. This says which is which, who controls what, and how to get it changed.
1. Who this policy covers
This policy explains how we handle personal information in two separate situations, because our obligations are genuinely different in each and it matters which one applies to you.
- This website. When you browse hibridge.live, submit a demo request, or contact us, we are the controller of that information. This policy governs it in full.
- The HiBridge platform at a customer’s front desk. When you check in at a kiosk or speak to a receptionist on screen at a clinic, school, agency, gym, hotel, office, plant, store, or building, the organisation operating that front desk is the controller of your information. We process it on their behalf, under their instructions and our contract with them. If you want your information corrected or deleted in that context, that organisation is the right place to start, and we will support their request.
If you are not sure which applies, contact us and we will tell you.
2. Information we collect through this website
- Information you give us. On the demo and contact forms: your name, email address, phone number, organisation name, business type, number of locations, and anything you write in the message field.
- Booking information. If you schedule a call through our booking calendar, the details you enter there and the time you select.
- Technical information. Your IP address, browser and device type, referring page, pages viewed, and approximate location derived from IP, collected through analytics as described in section 6.
We do not ask for, and do not want, health information, government identifiers, or payment card details through this website. Please do not send them to us through a web form or by email.
3. Information processed through the HiBridge platform
At a customer’s front desk, the platform is designed to handle only what that front desk needs in order to serve the visitor. Depending on how the operator has configured it, that can include:
- Identity and appointment details a visitor confirms at check-in, such as name and year of birth
- Documents a visitor chooses to scan at the counter, such as an identification card or an insurance card
- Intake forms, acknowledgements, terms acceptance, and a signature captured on screen
- Payment authorisation for a copay or account balance, handled as described in section 5
- A live video and audio session between the visitor and a receptionist, as described in section 4
- A record that the visitor arrived, and any note the receptionist makes in the operator’s own systems
The operator decides which of these are collected, who among their authorised users may see them, and how long they are kept in their own systems. We do not use information processed on an operator’s behalf to build profiles, to market to visitors, to train artificial intelligence models, or for any purpose of our own. We do not sell it.
The platform is designed so that sensitive information is not displayed unnecessarily on screens visible to other people in the lobby.
4. Video reception sessions
A HiBridge session connects a visitor at the front desk to a real receptionist working live. There is no chatbot, no automated avatar, and no artificial voice standing in for a person in the visitor-facing role.
The live video and audio connection is carried by RingCentral, a third-party communications platform we license as part of our infrastructure. Under our agreement, RingCentral transports the session and is not permitted to use the content of it for its own purposes. RingCentral handles the data it processes under its own privacy notice, which you can read at ringcentral.com/legal/privacy-notice.html. That notice governs RingCentral’s own processing; this policy governs ours.
Whether any part of a session is recorded, and for how long any recording is kept, depends on the configuration agreed with the operator of that front desk. Where recording is enabled, the operator is responsible for notifying visitors as required by law. If you want to know what applies at a specific location, ask that operator, or ask us and we will confirm the configuration to them.
5. Payments
Where a front desk collects a copay or balance at the kiosk, the card details are captured and processed by a third-party payment processor under its own security obligations. We do not store full card numbers on our systems. We may retain a transaction reference and amount so that the operator has a record of the payment.
6. Cookies and analytics on this website
This website uses Google Tag Manager to load Google Analytics. That measurement sets cookies and collects the technical information described in section 2 so we can understand which pages are useful, how people arrive, and where they give up. We use it to improve the site.
We do not run advertising retargeting pixels on this website, and we do not sell website visitor data.
You can block or delete cookies in your browser, use a browser that blocks trackers, or install Google’s Analytics opt-out extension. Blocking analytics does not affect your ability to use the site or submit a form. We honour Global Privacy Control signals where our tooling receives them.
7. How we use website information
- To respond to your enquiry and arrange and run a demo
- To send you information you asked for, and follow up on a conversation you started
- To understand which pages and topics are useful, and improve them
- To keep the site secure and prevent abuse of our forms
- To meet our legal, tax, and contractual obligations
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
8. Who we share information with
We share personal information only with service providers who need it to deliver the service, and only under contract. The categories are:
- Website and form hosting
- RingCentral, for live video and audio sessions (privacy notice)
- A payment processor, for transactions taken at a front desk
- Analytics and tag management, for website measurement
- Scheduling software, for booking demo calls
- Email and business systems we use to run the company
We may also disclose information where we are legally required to, where necessary to protect our rights or someone’s safety, or in connection with a merger or acquisition, in which case this policy would continue to apply to information already collected until it is replaced.
9. Mobile messaging and SMS
If you give us your mobile number and agree to receive text messages from us, we use it only for the purpose you agreed to, such as replying to an enquiry, confirming a demo, or sending service updates about a front desk you operate. Message frequency varies. Standard message and data rates may apply. You can stop messages at any time by replying STOP, and you can reach us by replying HELP.
No mobile information or text message opt-in data will be shared with third parties or affiliates for marketing or promotional purposes under any circumstances. All of the sharing categories described in section 8 exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Opting out of text messages does not remove you from email contact and does not affect any front desk service you use. To stop email as well, tell us at info@hibridge.live.
10. HIPAA and healthcare customers
Where a customer is a covered entity or a business associate under HIPAA, and we handle protected health information on their behalf, we act as their business associate and will enter into a Business Associate Agreement. That agreement governs our handling of protected health information and takes precedence over this policy for that information.
If you need our current HIPAA documentation, security detail, or a Business Associate Agreement for review, request it at info@hibridge.live and we will send you the actual documents rather than a summary.
11. How long we keep information
Website enquiries: we keep them for as long as needed to respond and maintain a record of the business conversation, and then for as long as required for legal and tax purposes.
Platform information: retention is set by the operator of that front desk under our agreement with them. When our agreement with a customer ends, we return or delete the information we hold on their behalf in line with that agreement, subject to any legal obligation to keep it.
12. Security
We use access controls, encryption in transit, authenticated accounts, and role-based permissions so that receptionists and administrators can reach only what their role requires. Our patented virtual reception system is designed so that a remote receptionist can complete a transaction at a counter without sensitive information being displayed to others in the lobby.
No system is perfectly secure, and we will not claim otherwise. If you believe you have found a vulnerability in our platform or this website, please tell us at info@hibridge.live and we will look at it promptly.
13. Your rights
If you are a Virginia resident, the Virginia Consumer Data Protection Act gives you the right to confirm whether we process your personal data, to access it, to correct inaccuracies, to have it deleted, to obtain a copy in a portable format, and to opt out of targeted advertising, the sale of personal data, or certain profiling. We do not sell personal data or use it for targeted advertising.
Residents of other states with comparable privacy laws have similar rights, and we apply the same process to all requests rather than distinguishing by state.
To exercise a right, email info@hibridge.live or call +1 800-909-4153. We will verify your identity before acting, and we will respond within the timeframe the applicable law requires. We will not discriminate against you for making a request. If we decline, we will tell you why and you may appeal by replying to our decision; if your appeal is denied, you may contact the Virginia Attorney General.
If your request concerns information from a check-in or a session at a specific organisation’s front desk, contact that organisation, as they control that information. Tell us as well and we will support their handling of it.
14. Children
This website is intended for business audiences and we do not knowingly collect personal information from children through it. Where a HiBridge front desk operates somewhere children are present, such as a school or a paediatric practice, information about a minor is processed on the operating organisation’s instructions and under its own policies and consents.
15. Where information is processed
We operate from the United States and our service providers process information in the United States unless a specific customer agreement provides otherwise. If you contact us from outside the United States, you are sending your information to be processed here.
16. Changes to this policy
If we change this policy we will update the effective date at the top and, where the change is significant, tell affected customers directly. Continued use of the website after an update means the updated policy applies to you.
17. Contact us
Mill Mountain Technologies, doing business as HiBridge
535 Campbell Ave SW, Roanoke, Virginia 24018, United States
Email: info@hibridge.live
Phone: +1 800-909-4153, Monday to Friday, 9am to 6pm Eastern
Need our privacy or HIPAA documentation?
Email info@hibridge.live and tell us which document you need, a Business Associate Agreement, our security detail, or a data-processing summary, and we will send the real thing.
Contact us