MERLIN DIRECT PRIMARY CARE

WEBSITE PRIVACY POLICY

Last Updated: August 13, 2026

 

  1. Scope and Acceptance

Merlin Healthcare, PLLC d/b/a Merlin Direct Primary Care (“Merlin DPC,” “we,” “us,” or “our”) operates merlindpc.com and related webpages, forms, scheduling links, and online features that link to this Website Privacy Policy (collectively, the “Website”). This policy describes the personal information we may collect through the Website, how we use and disclose it, and the choices that may be available to you.

This policy applies to Website visitors, prospective patients, patients using general Website features, family members, employer representatives, and other individuals who communicate with us through the Website. It does not replace our Notice of Privacy Practices or any patient-specific consent, authorization, membership agreement, or other healthcare document.

By accessing or using the Website, you acknowledge that you have reviewed this policy. If you do not agree with this policy, please do not submit information through the Website.

  1. Information We Collect

The information we collect depends on how you interact with the Website and the services you request. We may collect the following categories of information:

  • Contact and identity information, such as your name, email address, telephone number, mailing address, date of birth when needed, and the names or contact information of a parent, guardian, family member, or authorized representative.
  • Inquiry and membership information, such as whether you are interested in an individual, family, child, or employer membership; your preferred contact method; appointment or meet-and-greet requests; and questions or comments you submit.
  • Appointment and service information, such as the date and type of appointment requested, communications concerning scheduling, and information needed to coordinate services. Detailed medical information submitted through a patient portal, electronic health record, telehealth platform, or during care may be protected health information and is addressed in Section 9.
  • Payment and transaction information, such as billing contact information, membership payment status, transaction dates, and limited payment details. Full payment-card information is typically processed by a third-party payment processor and may not be stored by Merlin DPC.
  • Communications, including emails, contact-form submissions, telephone or text-message preferences, support requests, feedback, and other correspondence with us.
  • Device and usage information, such as Internet Protocol (IP) address, browser type, device type, operating system, approximate location derived from IP address, referring pages, pages viewed, links clicked, date and time of access, and other interactions with the Website.
  • Cookie and similar-technology information, including identifiers used to operate the Website, remember preferences, measure performance, understand Website traffic, prevent fraud, and support embedded content.
  • Information from third parties, such as scheduling, electronic health record, patient portal, payment, analytics, communications, referral, or business partners, where permitted by law and consistent with your relationship with those parties.
  1. How We Collect Information

We may collect information:

  • Directly from you when you complete a form, request an appointment, enroll or inquire about membership, make a payment, choose a contact preference, communicate with us, or otherwise provide information.
  • Automatically when you visit or use the Website through cookies, pixels, tags, server logs, analytics tools, and similar technologies.
  • From service providers and platforms that support scheduling, patient communications, electronic health records, payments, website hosting, forms, analytics, cybersecurity, and other business operations.
  • From referral sources, family members, authorized representatives, employers, or other third parties when they have authority or permission to provide the information.
  1. How We Use Information

We may use personal information for the following purposes:

  • Provide and administer the Website, respond to inquiries, schedule meet-and-greets or appointments, process membership requests, and deliver requested services.
  • Communicate with you by telephone, email, text message, or other methods you select, including appointment reminders, follow-up communications, membership information, service updates, and responses to questions.
  • Process payments, maintain transaction records, administer memberships, and support billing and accounting activities.
  • Provide, coordinate, and improve healthcare services as permitted by applicable law and described in our Notice of Privacy Practices.
  • Operate, maintain, troubleshoot, secure, personalize, analyze, and improve the Website, including measuring Website traffic and the effectiveness of content.
  • Protect patients, visitors, staff, the practice, and others; prevent fraud or misuse; maintain cybersecurity; and investigate suspected unlawful, unsafe, or malicious activity.
  • Send educational, promotional, or practice-related communications where permitted by law and consistent with your choices. You may opt out of promotional email or text communications as described below.
  • Comply with legal, regulatory, licensing, professional, contractual, reporting, recordkeeping, and enforcement obligations, and establish, exercise, or defend legal claims.
  1. Cookies, Analytics, and Embedded Content

We and our service providers may use cookies and similar technologies to operate and improve the Website. These technologies may fall into the following categories:

  • Essential technologies that support core Website functions, security, forms, and navigation.
  • Analytics and performance technologies that help us understand how visitors use the Website and identify technical or content improvements.
  • Functionality technologies that remember preferences or support features such as maps, videos, scheduling, or other embedded services.
  • Advertising and campaign-measurement technologies, used on general marketing pages to measure the reach and performance of Merlin DPC advertising. Merlin DPC does not use protected health information for advertising, does not use it to build advertising audiences, and does not permit advertising platforms to receive medical information you submit for care-related purposes. Advertising platforms are not business associates of Merlin DPC and are not authorized to receive protected health information.

You can usually manage cookies through your browser settings. Blocking some cookies may cause parts of the Website to function incorrectly. Where required by applicable law, we will provide additional consent or opt-out controls for nonessential technologies.

The Website may include content or tools provided by third parties, such as maps, videos, scheduling tools, social-media features, or patient-service platforms. Those providers may collect information under their own privacy notices when you interact with their content or leave our Website.

  1. Email, Telephone, and Text Communications

Merlin DPC uses a HIPAA-compliant messaging platform (Spruce) for secure text and voice communication with patients, and this is our default channel for anything involving your health information. Ordinary email and standard text messages sent outside that platform are not fully secure and can be intercepted, misdirected, or viewed by others with access to your device or account. When you provide contact information or select a preferred contact method, you authorize Merlin DPC to respond through that method. If you ask us to communicate with you by ordinary email or standard text message because you prefer it, we will honor that request and you accept the additional risk that comes with an unsecured channel. Even then, do not use an unsecured channel to send highly sensitive medical, financial, or identification information unless we instruct you to do so.

You may unsubscribe from promotional emails using the unsubscribe link in the message. Where available, you may opt out of nonessential text messages by replying STOP or by contacting us. Opting out of promotional communications does not prevent us from sending administrative, transactional, security, appointment, membership, or care-related communications that are permitted by law. Message and data rates may apply.

Consent to receive promotional text messages is not a condition of purchasing a membership or receiving healthcare services, unless otherwise clearly disclosed and permitted by law.

  1. How We Disclose Information

We may disclose personal information as reasonably necessary for the purposes described in this policy, including:

  • Service providers that support website hosting, forms, scheduling, electronic health records, patient portals, telehealth, payment processing, communications, analytics, cybersecurity, data storage, customer support, accounting, and professional services.
  • Healthcare providers, laboratories, imaging facilities, pharmacies, specialists, hospitals, and other care partners when permitted or authorized by law and described in our Notice of Privacy Practices.
  • Professional advisers and insurers, such as attorneys, accountants, auditors, consultants, and insurance carriers, subject to appropriate confidentiality obligations.
  • Government, regulatory, licensing, law-enforcement, judicial, or other authorities when disclosure is required or permitted by law, legal process, professional obligations, or to protect health, safety, rights, or property.
  • Parties involved in a potential or completed reorganization, financing, sale, merger, acquisition, transfer, or other business transaction, subject to applicable legal and confidentiality requirements.
  • Other parties at your direction, with your consent or authorization, or as otherwise described when the information is collected.

We do not sell protected health information. We do not sell personal information for monetary consideration. Certain analytics or online outreach activities may be treated as “selling,” “sharing,” or “targeted advertising” under some state privacy laws even when no money is exchanged. Where those laws apply, we will provide required notices and opt-out options.

  1. Third-Party Websites and Services

The Website may link to or integrate with third-party websites and services that Merlin DPC does not control. For example, selecting an online scheduling, payment, map, video, social-media, or patient-portal link may take you to a separate platform. This policy does not govern a third party’s independent privacy or security practices. Review the privacy notice and terms of each third-party service before providing information.

Where a third party processes protected health information on our behalf, Merlin DPC will use contractual and other safeguards required by applicable healthcare privacy law. However, information you provide directly to an unrelated third party may be governed solely by that third party’s policies.

  1. Medical Information, HIPAA, and the Notice of Privacy Practices

Personal information that Merlin DPC creates, receives, maintains, or transmits in connection with healthcare services may qualify as protected health information (“PHI”) under the Health Insurance Portability and Accountability Act and related law. PHI is handled in accordance with applicable healthcare privacy and security requirements and Merlin DPC’s Notice of Privacy Practices.

The Notice of Privacy Practices explains how medical information may be used and disclosed and describes patient rights concerning medical records. Requests to access, amend, restrict, receive an accounting of disclosures, obtain confidential communications, or exercise other HIPAA rights should be made using the process stated in the Notice of Privacy Practices.

Merlin DPC’s Notice of Privacy Practices is available at https://merlindpc.com/notice-of-privacy-practices, in the office, and in paper form on request.

A general Website inquiry does not automatically become part of a medical record. However, information may become part of your medical record if it is used to provide, coordinate, document, or manage healthcare services.

  1. Data Security

We use administrative, technical, and physical safeguards designed to protect personal information based on the nature of the information and the risks involved. These measures may include access controls, authentication, encryption where appropriate, security monitoring, vendor oversight, workforce training, backups, and incident-response procedures.

No website, transmission method, or storage system can be guaranteed to be completely secure. You are responsible for using appropriate security measures on your devices and for protecting account credentials. Notify Merlin DPC promptly if you believe information you submitted to us has been accessed or used without authorization. If a breach involving unsecured personal information or protected health information occurs, Merlin DPC will provide notification as required by applicable federal and Texas law, including the Health Insurance Portability and Accountability Act and the Texas Identity Theft Enforcement and Protection Act, and in accordance with our written breach notification policy.

  1. Data Retention

We retain personal information for as long as reasonably necessary for the purposes described in this policy, including to provide services, maintain business and medical records, administer memberships, comply with legal and professional obligations, resolve disputes, enforce agreements, and protect against fraud or security threats. Retention periods vary based on the type of information, the context in which it was collected, and applicable legal requirements.

Medical records and protected health information are retained and disposed of in accordance with applicable healthcare law, professional standards, and our records-retention policies.

  1. Your Privacy Rights and Choices

Depending on where you live and the law that applies, you may have rights concerning personal information that is not handled solely under HIPAA or another legal exemption. These rights may include:

  • The right to confirm whether we process your personal information and to access or obtain a portable copy of certain information.
  • The right to request correction of inaccurate information.
  • The right to request deletion of certain information, subject to legal, medical-record, security, and operational exceptions.
  • The right to opt out of certain sales, sharing, targeted advertising, or profiling activities, where applicable.
  • The right to withdraw consent where processing is based on consent, without affecting processing that occurred before withdrawal.
  • The right not to receive unlawful discrimination for exercising an applicable privacy right.

To submit a request, contact us using the information in Section 18 and describe the right you wish to exercise. We may ask for information needed to verify your identity and authority. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct verification with you.

If we deny a consumer privacy request and applicable law provides an appeal right, you may appeal by contacting us and writing “Privacy Appeal” in the subject line or opening of your request. Requests concerning medical records or HIPAA rights must follow the process in our Notice of Privacy Practices.

  1. Global Privacy Control and Do Not Track

Some browsers and extensions can send privacy preference signals, including Global Privacy Control (“GPC”). Where applicable law requires us to recognize a supported signal as an opt-out request, we will process the signal for the browser or device that sends it. Because there is not a uniform industry standard for other “Do Not Track” signals, the Website may not respond to all such signals.

  1. Children’s Privacy

The Website is intended for adults and for parents or guardians seeking information or healthcare services for themselves or their children. It is not directed to children under 13 for independent use, and we do not knowingly collect personal information directly from a child under 13 through the general Website without appropriate involvement of a parent or guardian. If you believe a child submitted information improperly, contact us so we can review and take appropriate action.

Healthcare information about minors is handled in accordance with applicable law, parental or personal-representative rights, professional obligations, and our Notice of Privacy Practices.

  1. Visitors Outside the United States

Merlin DPC is located in Texas and the Website is operated for services provided primarily in the United States. If you access the Website from another country, your information may be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your location.

  1. Changes to This Policy

We may update this Website Privacy Policy from time to time to reflect changes in our services, technology, vendors, practices, or legal obligations. We will post the updated policy on the Website and revise the “Last Updated” date. Additional notice will be provided when required by law. Your continued use of the Website after an update is subject to the revised policy.

1&. Review of This Policy

We will review this Website Privacy Policy per mandatory requirements applicable to maintain compliance with Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act of 2009, the HIPAA Security Rule at 45 CFR part 160, and subparts A and C of 45 CFR, part 162, and part 164.

  1. Questions, Complaints, and Regulatory Rights

Contact Merlin DPC if you have questions or concerns about this policy or our Website privacy practices. Complaints involving protected health information or HIPAA rights should be submitted using the process in our Notice of Privacy Practices. Depending on the circumstances, you may also have the right to submit a complaint to an appropriate state or federal regulator. We will not retaliate against you for submitting a good-faith privacy complaint or exercising a legal right.

  1. Contact Us

Merlin Healthcare, PLLC d/b/a Merlin Direct Primary Care
Attention: Privacy Officer

7978 Broadway, Suite 100
San Antonio, Texas 78209

Phone: (210) 201-6777
Email: contact@merlindpc.com

Website: https://merlindpc.com

END OF WEBSITE PRIVACY POLICY TEMPLATE