icdsbsHomeTermsPrivacyPayment termsRefundsContact

Privacy Policy

Effective 10 August 2026 · icdsbs.com is operated by Vlumu, LLC

This policy explains what Vlumu, LLC ("we") does with information when you use icdsbs.com and the claim scrubbing service (the "Service"). It is written to be read, not to be survived.

The short version. We do not store patient names or raw patient identifiers. Membership and subscriber numbers are replaced with a salted cryptographic hash the moment a claim arrives, before anything is written to disk. What we keep is codes, quantities, amounts, dates and the findings we produced — the material needed to tell you what would have been rejected.

1. Who is responsible for what

For your account and billing information, we are the controller. For the claim data you submit, you are the controller and we act as your processor: we process it on your instructions, to provide the Service. A data processing agreement is available on request through the contact form.

2. What we collect

CategoryExamplesWhy
AccountOrganisation name, contact name, work email, phone, country, the system you runTo create and support your account, and to contact you about it
BillingSubscription status, invoices, the last four digits and brand of a cardTo take payment and meet accounting obligations. Full card numbers never reach our servers — payment is handled by Stripe's hosted checkout
Claim dataDiagnosis and procedure codes, drug codes, quantities, service dates, amounts, payer, and a salted hash of the membership numberTo run the checks and produce your findings
TechnicalIP address, request time, endpoint, user agent, API key prefixSecurity, abuse prevention, rate limiting and troubleshooting

What we deliberately do not keep

  • Patient names — discarded at ingest. If a name column is present in an uploaded file it is dropped and reported back to you as dropped, not stored.
  • Raw membership, national ID or subscriber numbers — replaced at ingest with a salted SHA-256 hash. The hash lets a rule confirm an identifier was present and consistent; it cannot be reversed to recover the number.
  • Clinical notes, images or free-text history. The Service has no use for them and does not ask for them.

Please do not send us data the Service does not need. If you do, we may delete it.

3. Legal basis

Where GDPR or a comparable law applies, we rely on: performance of a contract (providing the Service and taking payment); legitimate interests (keeping the Service secure, preventing abuse, and contacting existing customers about the Service they use); and legal obligation (tax and accounting records). Where you are a controller sending us claim data, you are responsible for your own lawful basis, including any consent or notice your regulator requires.

4. Who else processes data

We keep this list short on purpose.

ProviderPurposeLocation
Contabo GmbHServer hosting and storageGermany
Cloudflare, Inc.Network protection, bot filtering (Turnstile), TLS terminationGlobal edge
Stripe, Inc.Payments and subscription billingUnited States and EU
Brevo (Sendinblue SAS)Transactional email — verification, receipts, key recoveryEuropean Union

We do not sell personal data, we do not share it for advertising, and we do not use your claim data to train models for anyone else.

5. Where data is processed

The Service runs on servers located in Germany. If you are subject to rules requiring health data to remain in a particular country — for example Saudi data residency requirements — you should confirm that our design meets them before sending live data. We have built the Service so that no patient names or raw identifiers leave your systems, which is intended to help; it is not a legal opinion, and it is not a substitute for your own assessment.

6. How long we keep it

  • Claim batches and findings: kept while your account is open so you can re-read your own audits. Deleted on request.
  • Account records: kept while your account is open and for up to 12 months afterwards.
  • Invoices and payment records: kept for 7 years, because tax law requires it.
  • Technical logs: up to 90 days.
  • Operator audit records: kept indefinitely. They exist to show who changed an account and when, and would be worthless if they could be trimmed.

7. Security

  • All traffic is encrypted in transit (TLS). The origin server accepts connections only through Cloudflare.
  • API keys are stored as SHA-256 hashes with a short public prefix for lookup. We cannot read your key; nobody can recover it from our database.
  • Access to production is restricted to named administrators using SSH keys, not passwords.
  • Identifiers are hashed before storage, so a database copy does not reveal who a claim was for.

No system is perfectly secure. If we discover a breach affecting your data we will tell you promptly and describe what happened.

8. Your rights

Depending on where you are, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive it in a portable form, and to complain to a supervisory authority. Ask through the contact form and we will respond within 30 days. If your request concerns claim data you submitted as a controller, we will refer it to you and assist you in answering it.

9. Cookies and similar technology

We use no advertising or analytics cookies and we do not track you across sites. The application stores your API key in your browser's session storage so you are not asked for it on every page; it is cleared when you close the tab. Cloudflare Turnstile sets what it needs to tell a human from a script on our signup and contact forms.

10. Children

The Service is sold to healthcare organisations and is not directed at children. We do not knowingly collect personal data from children through this site. Note that claim data may relate to patients of any age; that data is pseudonymised at ingest as described above.

11. Changes

If we change this policy materially we will update the effective date and notify account holders by email.

12. Contact

Privacy questions, data requests and breach reports: contact us.

Vlumu, LLC
2010 State Rd 19, Unit #5042
Tavares, FL 32778
United States
Contact us