Questions or feedback: [email protected].
1. Who we are
LuzardoFax is a US-based online fax service based in Miami, FL. This Privacy Policy explains what personal information we collect when you use luzardofax.com (the "Service"), how we use it, and your rights regarding it.
2. Information we collect
Account information
When you sign up, we collect: your name, email address, company name, industry, and password (stored as a bcrypt hash). We never see your plaintext password.
Payment information
Billing is processed by our payment provider (Stripe). LuzardoFax does not see or store your full credit card details. We store only billing metadata (last 4 digits, brand, expiration) and Stripe customer/subscription IDs.
Fax content
Fax PDFs that you send or receive are stored in encrypted form on our infrastructure. We treat fax content as your data — we don't read, mine, or use it for any purpose other than providing the Service. See our BAA for HIPAA-specific commitments regarding Protected Health Information.
Usage data
To operate the Service, we log: IP addresses, browser user agent, timestamps of logins and fax events, audit log entries (account changes, settings changes), and aggregated usage metrics (number of pages sent/received per month).
Communications
If you contact us by email or form, we keep a record of the message and our reply, indexed by your email address, for support history.
3. How we use your information
- To provide the Service — sending and receiving faxes, sending notifications, providing the user interface and account management
- To bill you — issuing invoices, processing payments via Stripe
- To support you — responding to your questions and troubleshooting issues
- To improve the Service — analyzing aggregated usage data (never individual fax content) to identify reliability issues and feature opportunities
- To comply with law — responding to subpoenas, court orders, regulatory requests where legally required
- To maintain security — investigating fraud, abuse, and security incidents
4. What we do NOT do
- We do not sell your personal information to anyone
- We do not share your data with advertisers or marketing networks
- We do not read the content of your faxes
- We do not train AI models on your fax content or PHI
- We do not use tracking pixels or third-party analytics that build behavioral profiles
One exception, stated plainly: our public marketing pages load a review badge from a software directory. That badge receives standard request data such as your IP address and browser information. It is never present inside the LuzardoFax application, it never sees fax content or protected health information, and it does not build a profile of you across sites. If you would rather not load it, any content blocker will stop it without affecting the rest of the page.
5. Subprocessors
To provide the Service, we share specific data with the following service providers:
- Vultr (cloud infrastructure, US) — stores encrypted data at rest
- Telnyx (fax transport, US) — receives fax payloads in transit to/from PSTN. On inbound faxes we delete the carrier-side copy through their API as soon as our server has stored its own encrypted copy, and we log the result.
- SendGrid (transactional email, US) — sends notification emails on our behalf
- Stripe (payment processing, US) — handles your billing details
- Cloudflare (CDN / DDoS protection, global edge) — caches static assets only; never caches PHI or fax content
- Anthropic (AI assistant) — on luzardofax.com, receives only your chat messages. Inside your account, the help assistant also receives a limited set of non-document account details needed to answer support questions: your account name, plan, fax number, pages used this cycle and days left in it. It never receives fax documents, fax content, recipients, subjects, contacts, or PHI from our systems. Because you type the messages yourself, we automatically mask recognizable identifiers — phone and fax numbers, emails, dates, SSNs, record and policy numbers, and names introduced as a patient — before your message leaves our servers. That filter catches identifiers with a recognizable format; it cannot detect every possible detail written in free prose, so please do not enter patient information in the chat. We store only message counts and token usage, not the conversations.
6. Data retention
- Account data — retained while your account is active, plus 30 days read-only after cancellation
- Faxes and access logs — stored while your account is active. Deleted faxes are recoverable for 30 days, then removed from our active systems; encrypted backups taken earlier expire on their own 90-day cycle. Documentation required under the HIPAA Security Rule is retained for six (6) years per 45 CFR § 164.316(b)(2)(i).
- Billing records — retained as required for tax and accounting
- Support emails — 3 years for support history
- Logs (server logs without PHI) — 90 days
7. Your rights
You have the right to:
- Access your personal information — request a copy by emailing us
- Correct inaccurate information — most account data is editable in your settings
- Cancel your subscription — one click in Settings → Billing. Your account moves to read-only for 30 days, then is closed and its data follows our retention policy.
- Delete your account and data — email [email protected]. We verify that you control the account, then process the deletion request under our privacy and retention procedures. Some records may be retained where required by law, security, tax, accounting, or HIPAA documentation requirements, and encrypted backups expire on their normal lifecycle.
- Export your fax history and audit logs in CSV format
- Restrict processing in certain circumstances
- Lodge a complaint with a data protection authority (where applicable)
To exercise any of these rights, email [email protected].
8. Security
We implement administrative, physical, and technical safeguards to protect your information. See our Security page for full details: AES-256 encryption at rest, TLS 1.3 in transit, audit logging, role-based access controls, optional 2FA, and US-based data storage.
9. Children's privacy
The Service is intended for business users 18 and older. We do not knowingly collect information from children under 13. If you believe a child has provided personal information, contact us at [email protected] and we will delete it.
10. International users
LuzardoFax operates primarily in the United States and Canada. Data is stored in US-based data centers. Production runs in Miami, FL; encrypted offsite backups are held in a second US region. All data remains within the United States. If you access the Service from outside the US/Canada, you consent to the transfer of your information to the US.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email at least 30 days before taking effect. The "Last Updated" date at the top of this page indicates the most recent revision.
12. Contact us
For privacy questions, data requests, or concerns:
- Email: [email protected]
- Mail: LuzardoFax · Miami, FL · United States