Privacy Policy
Effective 10 August 2026 · icdsbs.com is operated by Vlumu, LLC
This policy explains what Vlumu, LLC ("we") does with information when you use icdsbs.com and the claim scrubbing service (the "Service"). It is written to be read, not to be survived.
1. Who is responsible for what
For your account and billing information, we are the controller. For the claim data you submit, you are the controller and we act as your processor: we process it on your instructions, to provide the Service. A data processing agreement is available on request through the contact form.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Organisation name, contact name, work email, phone, country, the system you run | To create and support your account, and to contact you about it |
| Billing | Subscription status, invoices, the last four digits and brand of a card | To take payment and meet accounting obligations. Full card numbers never reach our servers — payment is handled by Stripe's hosted checkout |
| Claim data | Diagnosis and procedure codes, drug codes, quantities, service dates, amounts, payer, and a salted hash of the membership number | To run the checks and produce your findings |
| Technical | IP address, request time, endpoint, user agent, API key prefix | Security, abuse prevention, rate limiting and troubleshooting |
What we deliberately do not keep
- Patient names — discarded at ingest. If a name column is present in an uploaded file it is dropped and reported back to you as dropped, not stored.
- Raw membership, national ID or subscriber numbers — replaced at ingest with a salted SHA-256 hash. The hash lets a rule confirm an identifier was present and consistent; it cannot be reversed to recover the number.
- Clinical notes, images or free-text history. The Service has no use for them and does not ask for them.
Please do not send us data the Service does not need. If you do, we may delete it.
3. Legal basis
Where GDPR or a comparable law applies, we rely on: performance of a contract (providing the Service and taking payment); legitimate interests (keeping the Service secure, preventing abuse, and contacting existing customers about the Service they use); and legal obligation (tax and accounting records). Where you are a controller sending us claim data, you are responsible for your own lawful basis, including any consent or notice your regulator requires.
4. Who else processes data
We keep this list short on purpose.
| Provider | Purpose | Location |
|---|---|---|
| Contabo GmbH | Server hosting and storage | Germany |
| Cloudflare, Inc. | Network protection, bot filtering (Turnstile), TLS termination | Global edge |
| Stripe, Inc. | Payments and subscription billing | United States and EU |
| Brevo (Sendinblue SAS) | Transactional email — verification, receipts, key recovery | European Union |
We do not sell personal data, we do not share it for advertising, and we do not use your claim data to train models for anyone else.
5. Where data is processed
The Service runs on servers located in Germany. If you are subject to rules requiring health data to remain in a particular country — for example Saudi data residency requirements — you should confirm that our design meets them before sending live data. We have built the Service so that no patient names or raw identifiers leave your systems, which is intended to help; it is not a legal opinion, and it is not a substitute for your own assessment.
6. How long we keep it
- Claim batches and findings: kept while your account is open so you can re-read your own audits. Deleted on request.
- Account records: kept while your account is open and for up to 12 months afterwards.
- Invoices and payment records: kept for 7 years, because tax law requires it.
- Technical logs: up to 90 days.
- Operator audit records: kept indefinitely. They exist to show who changed an account and when, and would be worthless if they could be trimmed.
7. Security
- All traffic is encrypted in transit (TLS). The origin server accepts connections only through Cloudflare.
- API keys are stored as SHA-256 hashes with a short public prefix for lookup. We cannot read your key; nobody can recover it from our database.
- Access to production is restricted to named administrators using SSH keys, not passwords.
- Identifiers are hashed before storage, so a database copy does not reveal who a claim was for.
No system is perfectly secure. If we discover a breach affecting your data we will tell you promptly and describe what happened.
8. Your rights
Depending on where you are, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive it in a portable form, and to complain to a supervisory authority. Ask through the contact form and we will respond within 30 days. If your request concerns claim data you submitted as a controller, we will refer it to you and assist you in answering it.
9. Cookies and similar technology
We use no advertising or analytics cookies and we do not track you across sites. The application stores your API key in your browser's session storage so you are not asked for it on every page; it is cleared when you close the tab. Cloudflare Turnstile sets what it needs to tell a human from a script on our signup and contact forms.
10. Children
The Service is sold to healthcare organisations and is not directed at children. We do not knowingly collect personal data from children through this site. Note that claim data may relate to patients of any age; that data is pseudonymised at ingest as described above.
11. Changes
If we change this policy materially we will update the effective date and notify account holders by email.
12. Contact
Privacy questions, data requests and breach reports: contact us.