Malibu Protocol Privacy Policy
- Document control
- MP-PRIV-BETA-1.1
- Effective date
- August 19, 2026 (private beta)
- Last updated
- August 24, 2026
- Controller
- Westward Science LLC (d/b/a Malibu Protocol)
- Privacy requests
- privacy@malibuprotocol.com
This Privacy Policy explains how Westward Science LLC, d/b/a Malibu Protocol ("Malibu Protocol," "Westward," "we," "us," or "our"), collects, uses, discloses, and protects personal information through malibuprotocol.com, our patient portal, support channels, transactions, and related services (the "Services").
This policy covers Westward's practices. Clinical services are supplied by Beluga Health, P.A. or another medical practice identified before care (the "Provider Group"). The Provider Group's Notice of Privacy Practices and privacy policy separately explain how the Provider Group uses and discloses medical information. An independent dispensing pharmacy's notice may also apply.
1. Our role and health information
Westward is not a healthcare provider. For the contracted clinical workflow, Westward acts as a business associate when it creates, receives, maintains, or transmits protected health information on behalf of the Provider Group. In that role, HIPAA, the Provider Group's instructions, and our business associate agreement restrict our use and disclosure of that information.
For information Westward collects to administer its own account, payment, security, legal, and consumer-support obligations outside its business-associate capacity, Westward may have independent duties under this policy and applicable consumer privacy law. Information received as a business associate cannot be repurposed for Westward's independent analytics or marketing merely because this policy describes those activities.
Other personal health information may be governed by consumer-protection, state consumer-health-data, or breach-notification laws even when HIPAA does not apply to a particular record. We apply the purpose, access, security, and disclosure controls described here based on the information and our role.
For Washington consumers and others covered by similar state laws, our separate Consumer Health Data Privacy Policy provides additional disclosures and rights.
2. Information we collect
The information we collect depends on how you use the Services.
Information you provide
- Identity and contact information: name, email address, mobile number, date of birth, and identity-verification information.
- Location and delivery information: state and physical-location attestation at the time of care, billing address, shipping address, and delivery instructions. The proposed launch does not collect precise GPS coordinates.
- Account information: authentication records, account preferences, consent and policy versions, communication preferences, and support history.
- Health and care information: sex assigned at birth, health history, conditions, symptoms, allergies, medications, measurements, treatment preferences, questionnaire answers, photographs or documents you submit, clinician communications, prescription and fulfillment status, and other information needed for requested care.
- Transaction information: selected service, order, amount, status, refund, chargeback, subscription, and payment-method token. Our payment processor, not Westward, should collect full card details at launch.
- Communications: messages and attachments you send through authorized support or care channels, requests, complaints, reviews, and survey responses.
- Privacy-request information: request type, verification evidence, authorized-agent documentation, response, and appeal.
Information collected automatically
- IP address, browser and device type, operating system, language, date and time, requested host and route category, security events, and diagnostic logs;
- essential session, authentication, fraud-prevention, load-balancing, and beta access records;
- campaign parameters contained in a public marketing-page request, such as source, medium, campaign, or creator code, if present in the URL or request logs.
At launch, we do not use third-party advertising pixels, cross-site behavioral profiling, keystroke capture, or session replay on the Services. Clinical, account, portal, Ops, and Studio surfaces prohibit marketing trackers. The proposed launch does not persist a marketing attribution ledger. If that changes, we will update this policy before the new collection begins and implement the consent and rights controls required by law.
Information from others
We may receive information from:
- the Provider Group and clinicians, such as visit identifiers, status, prescription or referral outcome, care communications, and records needed for contracted administrative functions;
- dispensing pharmacies, laboratories, and carriers, such as fulfillment, shipment, exception, and delivery status;
- payment processors, such as tokenized payment method, authorization, payment, refund, dispute, and fraud signals;
- identity, security, or fraud-prevention providers approved for the workflow;
- a person you authorize or a legally recognized personal representative; and
- advertising or creator links, limited to allowlisted campaign parameters and codes that you use to reach the public marketing site.
3. Why we use information
We use personal information to:
- provide, personalize, secure, and support the Services you request;
- create and administer accounts and authenticate access;
- transmit your requested clinical intake to the Provider Group and support the resulting telehealth workflow;
- coordinate permitted payment, pharmacy fulfillment, delivery, and support;
- send clinical, account, transaction, security, and fulfillment messages;
- maintain consent, policy-version, transaction, audit, and regulatory evidence;
- detect, prevent, investigate, and respond to fraud, misuse, security events, adverse events, complaints, legal requests, and rights requests;
- maintain, troubleshoot, measure, and improve service reliability and user experience using data minimized to the relevant purpose;
- calculate aggregate service, transaction, refund, and business-performance metrics using information minimized for that purpose;
- comply with law, professional requirements, contracts, and lawful process; and
- establish, exercise, or defend legal claims and protect patients, users, Westward, the Provider Group, and others.
We do not use protected health information for marketing except pursuant to a valid authorization or another basis expressly permitted by applicable law and the Provider Group. We do not train a general-purpose artificial-intelligence model on identifiable patient or clinical information.
4. How we disclose information
We disclose only information reasonably necessary for the recipient's role and the stated purpose.
- Provider Group and clinicians: to evaluate and provide requested clinical services, maintain records, communicate, bill, and perform healthcare operations permitted by law.
- Pharmacies and laboratories: to fill a valid prescription, perform an ordered service, coordinate delivery, resolve an exception, and meet their legal obligations.
- Infrastructure and service providers: hosting, database, authentication, communications, customer support, payment, security, monitoring, document, and professional-services vendors acting under contract.
- Payment networks and financial institutions: to authorize and process charges, refunds, disputes, fraud controls, and required reporting.
- Carriers and logistics providers: delivery details and the minimum order information needed to transport a package and resolve delivery problems.
- Professional advisors and insurers: legal, audit, accounting, compliance, risk, and insurance functions subject to appropriate duties.
- Authorities and protected parties: when we reasonably believe disclosure is required by law or lawful process, or necessary to protect rights, safety, systems, investigate wrongdoing, or respond to a serious threat, subject to applicable health-information restrictions.
- Business transaction counterparties: as part of a financing, merger, acquisition, reorganization, bankruptcy, or asset transfer, with appropriate confidentiality and continued legal protections.
- At your direction: to a personal representative, caregiver, provider, or other recipient you validly authorize.
We do not sell personal information or consumer health data. At launch, we do not share personal information for cross-context behavioral advertising or use third-party advertising pixels on the Services. If that position changes, we will update the applicable notices, obtain any required consent or authorization, honor opt-out signals, and complete legal/vendor review before activation.
5. Service providers and processors
We use contracted providers for hosting and application infrastructure, database services, authentication, communications, customer support, payment processing, fraud prevention, security, document management, shipping, and professional services. The implementation register separately identifies each production vendor and confirms its data, purpose, retention, subprocessors, security review, and contract status before launch.
We require processors to use information only for contracted purposes, apply appropriate safeguards, and support applicable rights and incident duties. Vendors that handle PHI must sign a compliant business associate agreement where required. Marketing-content systems may receive public content but must not receive patient, account, transaction, or clinical information.
6. Cookies and similar technologies
We use essential first-party technologies for authentication, security, preferences, beta access, service continuity, and fraud prevention. The beta gate cookie records only that the browser passed the pre-launch access gate.
We do not currently permit third parties to collect your activity over time and across unrelated websites through our Services. Because we do not engage in that collection at launch, the Services do not take a separate action in response to legacy browser "Do Not Track" settings. We recognize Global Privacy Control where it legally communicates an opt-out, and the no-sale/no- targeted-advertising launch position applies regardless of the signal.
7. Retention
We retain information only for the period reasonably necessary for the purpose collected, including requested services, continuity and safety, medical and business records, transaction reconciliation, fraud prevention, consent and legal evidence, rights requests, contracts, disputes, tax, insurance, security, backup, and applicable law.
Retention differs by record and our legal role. The Provider Group controls its medical-record retention. We may retain HIPAA business-associate records as directed or permitted by the business associate agreement. We delete, return, aggregate, or deidentify information when the applicable purpose and legal retention period end. Backup copies may persist for a limited protected cycle before deletion. Deidentified information may be retained where it cannot reasonably identify a person and we commit not to reidentify it except to test the deidentification process as permitted by law.
Numeric retention periods vary by record type and legal role. We apply the shortest period consistent with clinical continuity, tax and accounting rules, fraud prevention, dispute handling, and applicable law, then delete, return, aggregate, or deidentify the information.
8. Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity and role of the information. Controls include access limitation, authentication, encryption in transit, vendor review, secure development, logging, monitoring, backup, incident response, and workforce obligations.
No system or transmission is completely secure. You are responsible for protecting your devices, email account, phone, authentication links, and account access and for notifying us of suspected unauthorized use.
If an incident requires notice under HIPAA, the FTC Health Breach Notification Rule, or state law, the responsible entity will provide notice as required.
9. Your choices and rights
Depending on your state and the information involved, you may have rights to:
- confirm whether we process your personal information and access or receive a portable copy;
- correct inaccurate information;
- delete information, subject to clinical-record, transaction, legal, security, and other permitted exceptions;
- withdraw consent for future collection or sharing where processing relies on consent, understanding that this may prevent requested care or Services;
- opt out of sale, targeted advertising, or certain profiling if any such use exists;
- limit certain uses of sensitive personal information;
- appeal a refusal of a rights request;
- use an authorized agent where law permits; and
- exercise rights without unlawful discrimination.
To exercise a Westward privacy right, contact privacy@malibuprotocol.com. We will verify the request in a manner proportionate to its sensitivity and may ask for information needed to protect you from unauthorized disclosure. We will explain a denial and any appeal process required by law.
For access, correction, amendment, restriction, accounting, or copies of a medical record controlled by the Provider Group, use the contact in the Provider Group's Notice of Privacy Practices. If a request reaches the wrong entity, we will route it as permitted and required.
10. California disclosures
California residents may have rights under CalOPPA, the CCPA/CPRA when its business thresholds and scope apply, the Confidentiality of Medical Information Act, Shine the Light, and other laws. The categories collected, sources, purposes, disclosures, retention criteria, and rights methods are described in this policy.
During the preceding 12 months, our launch position is that Westward has not sold personal information and has not shared it for cross-context behavioral advertising. We do not knowingly sell or share the personal information of people under 18. We do not offer a financial incentive in exchange for personal information unless separately disclosed and consented to as required.
If California's CCPA/CPRA applies to our business for a given period, the categories, sources, purposes, disclosure practices, retention criteria, and rights methods described in this policy are the disclosures we rely on. Contact privacy@malibuprotocol.com to exercise California privacy rights or to request a Shine the Light disclosure.
11. Consumer health data
Health conditions, treatment, medication, symptoms, measurements, reproductive or sexual health, and information showing that a person seeks health services may be "consumer health data" under state law even outside HIPAA. Our separate Consumer Health Data Privacy Policy lists the categories, sources, purposes, sharing, recipients, and methods to exercise those rights.
12. Communications choices
Clinical, safety, security, account, transaction, and fulfillment messages may be necessary to provide requested Services. Care SMS is governed by its own consent and can be revoked using the stated method, although revocation may require a different care channel.
Marketing messages are optional and separate. Marketing email includes an unsubscribe method. Marketing SMS, if introduced, requires a separate consent and supports STOP and other legally recognized revocation requests. We do not condition purchase or care on marketing consent.
13. Children
The patient Services are directed to adults age 18 and older. Public pages and security logs may collect limited device or network information before age is known. We do not knowingly permit a person under 18 to create a patient account or submit a clinical intake. If you believe a child submitted information, contact us so we can investigate and take appropriate action while preserving any record lawfully required for safety or compliance.
14. United States service
The Services are directed to adults in the United States. Information is processed in the United States. Do not use the patient Services from another country unless we expressly authorize the jurisdiction and provide the required notices.
15. Changes to this policy
We will identify the effective date and post the current policy conspicuously. We may also provide account, email, or site notice for material changes. Before collecting a new category of consumer health data or using it for an additional purpose where consent is required, we will update the relevant notice and obtain consent first. We assess this policy before a material vendor, tracker, state, product, or data-use change and update it when required.
16. Contact
Westward privacy questions and rights requests:
- Privacy: privacy@malibuprotocol.com
- General support: care@malibuprotocol.com
- Mailing address: Westward Science LLC, Attn: Legal Notices, 30 N Gould St # 67817, Sheridan, WY 82801
Do not include medical details in ordinary email. Provider privacy, medical- record, and clinical complaints should use the secure channel and contact shown in the applicable Provider Group Notice of Privacy Practices.
17. Document precedence and scope
This Privacy Policy is a notice of Westward's practices; it is not a contract that reduces rights provided by law. If a Provider Group Notice of Privacy Practices governs protected health information controlled by that Provider Group, the provider notice governs the provider's practices for that information. If a state-specific consumer health data notice grants additional rights, the additional protection applies to the extent required by law.