Privacy Policy

Effective Date: January 1, 2025  ·  Last Updated: May 1, 2025

1. Introduction

SonoLynx ("we," "us," or "our"), operated by Bricklix, is committed to protecting the privacy and security of your data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our clinical ultrasound reporting platform. We prioritize the security of protected health information (PHI) and maintain strict adherence to healthcare data standards.

2. Information We Collect

We collect information necessary to provide and improve our services, including:

  • Account Information: Name, professional email address, facility name, and login credentials.
  • Clinical Data: Patient demographics, ultrasound measurements, clinical findings, and diagnostic images uploaded by users.
  • Usage Data: Log data, IP addresses, browser types, and interaction telemetry to monitor system performance and security.
  • Support Data: Information provided during customer support requests or sales inquiries.

3. How We Use Your Information

We use the collected information for the following purposes:

  • To provide, operate, and maintain the SonoLynx platform.
  • To facilitate the generation and transmission of clinical reports and HL7 messages.
  • To ensure compliance with healthcare regulations (e.g., HIPAA audit logs).
  • To provide technical support and respond to inquiries.
  • To monitor system health and prevent unauthorized access or fraudulent activity.
  • To improve the Platform's clinical logic and user experience.

4. Data Security

Security is at the core of SonoLynx. We implement enterprise-grade security measures:

  • Encryption: All data is encrypted in transit using TLS 1.2+ and at rest using AES-256.
  • Access Control: Granular role-based access control (RBAC) ensures users only see data they are authorized to access.
  • Audit Logs: Comprehensive logging of all data access and modifications to support HIPAA compliance.
  • Infrastructure: Hosted on secure, HIPAA-compliant cloud infrastructure with regular vulnerability assessments.

5. Disclosure of Information

We do not sell, rent, or trade your personal or clinical data. We may disclose information only in the following circumstances:

  • Service Providers: To trusted third-party vendors who assist in operating our Platform (e.g., cloud hosting, email delivery) under strict confidentiality agreements.
  • Legal Obligations: If required by law, subpoena, or to protect the safety and rights of SonoLynx or its users.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, subject to continued privacy protections.

6. Patient Data & HIPAA

SonoLynx acts as a "Business Associate" under HIPAA for our clinical customers. We process patient data solely on behalf of our customers and according to the terms of a signed Business Associate Agreement (BAA). We do not use patient data for marketing or any purpose other than providing the Platform services.

7. Your Rights

Depending on your jurisdiction and organization, you may have the right to access, correct, or delete your account information. Requests related to patient data should be directed to the healthcare provider who entered the information into the Platform.

8. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of any material changes by email or through a notice on the Platform. Continued use after such updates constitutes your acknowledgment of the revised policy.

9. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

SonoLynx Privacy Team
Email: connect@sonolynx.com
Address: 8402 Captons Ln, #104, Darien, IL 60561