Lenux SolutionsLENUXSolutions
Effective September 23, 2026

Privacy Policy

Lenux Solutions works with sensitive business and patient information every day, so this page is written to be read rather than skimmed. It explains what we collect, why we collect it, who it is shared with, how long we keep it, and the choices you have.

What we collect

Contact and business details you send us, basic technical data from our website, and the records our clients ask us to work on.

How we use it

To answer enquiries, deliver the service you hired us for, keep records accurate, and meet legal and contractual duties.

Who sees it

We do not sell personal information. Mobile information will not be shared with third parties/affiliates for marketing/promotional purposes.

Your controls

Request a copy, a correction, or deletion of your information at any time — we respond within 30 days.

Who we are

This policy is issued by Lenux Solutions LLC(“Lenux Solutions”, “we”, “us”), a business registered in Sheridan, Wyoming. We provide outsourcing services including medical billing and revenue cycle management, transportation and dispatch support, call answering, virtual assistants, and back-office administration.

For information you send us directly — such as a quote request or an email — we act as the organisation that decides why and how that information is used. Where we process records on behalf of a client under a service agreement, that client decides the purpose and we act on their documented instructions as a service provider and, for protected health information, as a business associate.

U.S. Headquarters and registered address: 30 N Gould St STE R, Sheridan, WY 82801, United States. Operations Hub: Office #8, Second Floor, Crown Plaza, Main Commercial Market Rd, Rawalpindi 46000, Pakistan.

What we collect

We hold three broad categories of information.

Information you give us

  • Contact details — name, job title, company, email address, phone number, and website.
  • Enquiry details — the service you are interested in, team size, timeline, budget range, and the message you type.
  • Correspondence — emails, calls, meeting notes, and support tickets between you and our team.
  • Billing details — invoices, purchase orders, and payment records where a commercial relationship exists.

You are never required to give us more than a working email or phone number to start a conversation. Please avoid sending health, financial, or other sensitive details in a first message — there is no need at that stage.

Information collected automatically

  • Technical data — browser type, device and operating system, screen size, and language settings.
  • Usage data — which pages you viewed, how long you stayed, the links you clicked, and the page that referred you.
  • Network data — your approximate location derived from your IP address, and the internet service provider name.

This is collected to understand what parts of the site are useful and to keep the site secure. It is used in aggregate and is not tied back to you as an individual unless there is an abuse or security investigation.

Information we handle for clients

When a healthcare provider, broker, or operator engages us, their staff and customer records come into our workspace so we can do the job. That can include patient names and dates of birth, appointment and trip details, insurance and claim information, encounter and coding data, and payment records. We treat this material under stricter controls than ordinary business data — see the HIPAA and security sections below.

How we use information

Our processing is deliberately narrow. We use information to:

  • Reply to enquiries, prepare quotes, and arrange a discovery call or demonstration.
  • Set up, deliver, and quality-assure the service you engaged us for.
  • Authenticate users, control access to systems, and prevent fraud or misuse.
  • Send service notifications such as scheduling changes, invoices, and incident alerts.
  • Provide support, investigate complaints, and resolve disputes.
  • Improve our website, scripts, workflows, and training based on what we learn.
  • Comply with contracts, tax obligations, record-keeping rules, and lawful requests.

We do not use your information to build advertising profiles. We do not sell, rent, or share consumer personal information — including phone numbers — with third parties or affiliates for marketing, promotional purposes, or lead generation.

How we share information

We share information only in the circumstances below, and every recipient is bound to use it solely for the purpose we disclose.

  • Our own workforce — team members who need the information to do their role, under confidentiality agreements.
  • Clients — the organisations we serve receive the reporting and records their agreement covers.
  • Service providers — hosting, email, telephony, CRM, ticketing, payroll, and accounting suppliers that process information for us under written data-protection terms.
  • Professional advisers — lawyers, auditors, insurers, and accountants when required.
  • Authorities — courts, regulators, and law enforcement where we have a legal duty or a valid, proportionate request.
  • Business transfers — an acquirer or successor in a merger, acquisition, or restructuring, subject to this policy.

We do not sell personal information, share it for cross-context behavioural advertising, or disclose it to anyone who is entitled to resell it.

Mobile information and SMS consent: No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except vendors or service providers strictly necessary to deliver the messaging service. This exclusion applies wherever this policy permits other information to be disclosed to partners, affiliates, advertising companies, marketing providers, or operational service providers.

HIPAA and protected health information

When we support a healthcare provider, health plan, or clearinghouse we handle protected health information (“PHI”) as a business associate. Before any PHI moves, we execute a business associate agreement that sets out permitted uses, safeguards, breach notification, and subcontractor obligations.

Our PHI commitments:

  • Minimum necessary — staff see only the records required for their assigned task, enforced through role-based permissions.
  • Workforce training — privacy and security training on onboarding and annually, with signed confidentiality acknowledgements.
  • Audit trails — access to claim, patient, and account data is logged and reviewed.
  • Incident response — suspected unauthorised access is investigated and reported to the client within the timeframe set in our agreement.
  • Return or destruction — at contract end we return or securely destroy PHI as the client instructs and confirm it in writing.

If you are a patient with a question about your own records, please contact the provider who treated you. They are responsible for your record and will route your request, including any copy or amendment request, to us where needed.

International teams and transfers

Our delivery teams operate across multiple countries, including Pakistan and the United States. Information about clients and their customers may therefore be accessed from outside your home country.

Where a transfer needs a safeguard, we rely on recognised mechanisms — for example Standard Contractual Clauses with supplementary technical measures — and we keep offshore access inside client-specific workspaces rather than a shared pool. You can ask for details of the mechanism used for a particular transfer.

How long we keep information

We keep information only as long as we have a reason to, then delete or anonymise it.

  • Website enquiries from people who do not become clients: up to 24 months, so we can pick up a later conversation.
  • Client agreement records: for the life of the contract, then six years to satisfy accounting and tax rules unless a longer period is required.
  • Protected health information: held as instructed by the client under the business associate agreement, then returned or destroyed.
  • Call recordings and transcripts: retained only where the client has approved recording, and for the period stated in the service agreement.
  • Security logs: up to 12 months.

Where a legal hold, dispute, or regulatory request applies, records are preserved until that matter closes.

How we protect information

No system is risk-free, so we combine technical, physical, and organisational controls and review them regularly.

  • Encryption of information in transit, and encryption of stored data where the platform supports it.
  • Multi-factor authentication and unique named accounts — no shared logins.
  • Least-privilege access with prompt removal of permissions when someone changes role or leaves.
  • Managed devices with disk encryption, screen locks, and remote wipe.
  • No personal devices and no removable media in client-facing work areas.
  • Vendor review before onboarding, with written security and confidentiality terms.
  • Backups, monitoring, and an incident response plan that is exercised periodically.

If you believe an account or record has been exposed, contact us immediately at hello@lenuxsolutions.com so we can contain it.

Cookies and analytics

Our website uses a small number of cookies and similar technologies to remember your preferences, keep the site working, and measure which pages and search terms bring visitors in. Analytics data is reported in aggregate.

You can delete or block cookies in your browser settings at any time. Blocking strictly necessary cookies may stop forms or menus from working properly. Where a non-essential cookie is used, we ask for consent first and honour a withdrawal the same way. We do not currently recognise browser “Do Not Track” signals because there is no common standard for what one should do.

Your privacy rights

Depending on where you live, you may ask us to:

  • Confirm whether we hold your information and provide a copy of it.
  • Correct anything inaccurate or incomplete.
  • Delete your information where we have no overriding reason to keep it.
  • Restrict or pause processing, or object to processing based on legitimate interests.
  • Provide your information in a portable, machine-readable format.
  • Withdraw consent where consent was the basis, without affecting processing already done.
  • Ask questions about our no-sale and no-marketing-sharing commitment. We do not sell personal information or share mobile opt-in data and consent with third parties or affiliates for marketing.

To make a request, email hello@lenuxsolutions.com with “Privacy request” in the subject line. We will verify your identity with information we already hold rather than asking for documents you do not need to share. We respond within 30 days, and we will not discriminate against you for exercising a right.

If you are unhappy with our answer, you can escalate to a supervisory authority — in Europe, your national data protection authority; in the United States, the Federal Trade Commission or your state attorney general. For records we handle on a client's instructions, we will pass your request to that client, who is entitled to decide it.

SMS / Mobile Messaging Privacy

Lenux Solutions may collect your mobile phone number when you voluntarily provide it through our website forms, during a telephone conversation, or through another clearly disclosed opt-in method. If you opt in to receive SMS communications, we may send messages relating to inquiries, requested services, appointments, customer support, account notifications, and other communications you have requested or consented to receive.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except vendors or service providers strictly necessary to deliver the messaging service.

Message frequency may vary. Message and data rates may apply. You may reply STOP at any time to opt out of further SMS messages or reply HELP for assistance.

SMS consent is not a condition of purchasing any product or service.

Other marketing messages

We send business updates, pricing notes, and event invitations only where you have asked for them, where we have a relevant existing relationship, or where the law allows it. Every email carries an unsubscribe link and a way to reply, and opt-outs are applied promptly across our systems. Transactional messages about a service you use continue regardless of marketing preferences.

We do not sell or share email addresses, phone numbers, or other consumer personal information with third parties or affiliates for their marketing, promotional activities, or lead generation.

Children's information

Our services are directed at businesses, not children. We do not knowingly collect information from anyone under 18 outside the records a client legitimately asks us to process — for example a minor's transportation or medical appointment. If you believe a child's information has reached us incorrectly, contact us and we will remove it.

Changes to this policy

We review this policy at least annually and whenever we launch a service, change a supplier, or a law changes. The effective date at the top of this page shows when it last changed. If a revision materially affects how we use information, we will notify active clients before it takes effect.

Contact us

Questions, requests, or concerns about this policy can reach us through any of these routes.

U.S. Headquarters

Lenux Solutions LLC
30 N Gould St STE R
Sheridan, WY 82801, United States

Operations Hub

Office #8, Second Floor, Crown Plaza
Main Commercial Market Rd
Rawalpindi 46000, Pakistan