Oris

Last updated

Privacy policy

Oris builds patient acquisition systems for US med spas and dental practices. This site has one form on it. What you type into that form, plus which campaign or search sent you here, is the only personal data we ask you for — and below is the short list of everyone who touches it on the way.

AI front desk
$1,500 setup$1,200/mo
Local search
from $1,200/mo
Content
from $1,000/mo
Websites
from $3,500

List prices, in US dollars. No long lock-in — 30 days notice, any time. The audit is free and asks for nothing you have not read about on this page.

Operator
HeadPills, Wroclaw, Poland
Questions and deletion
[email protected]

The short version

We collect
Your name, work email, clinic name and city, and — if you fill them in — your website and a message.
We also attach
Which campaign, link or search brought you here, so we know which work is paying for itself.
Our host sees
Your IP address and the technical request, as every web host does. We do not read it, store it or use it for anything.
We do not collect
Patient information, health data, payment details, or anything about you unless you type it in.
We do not run
Advertising cookies, third-party trackers, session recording, chat widgets, or a font CDN.
To be deleted
Email [email protected]. No form, no account, no argument.

Who runs this site

Oris is a service line of HeadPills, a digital agency based in Wroclaw, Poland. HeadPills is the data controller for everything described here, and the only party that decides what happens to your information. You can reach a human at [email protected].

The full registered entity details — legal form, registration number and postal address — are not published on this page yet. If you need them for a due-diligence or vendor file, ask and we will send them the same day.

We have not appointed a data protection officer. Given what this site does — one form, no large-scale monitoring, no special-category data — we do not believe we are required to, but that is our reading and not a ruling, and we would rather say so than print a title nobody holds. Data questions go to the same address as everything else, and a person answers them.

What we collect

Two things, and nothing else. The first is what you type into the audit form. The second is a short set of attribution fields the site attaches to that submission automatically.

What you type

  • Your name — so a reply is addressed to a person.
  • Work email — the only way we send you the audit.
  • Clinic name and city — we cannot audit a clinic we cannot find.
  • Website — optional. It makes the audit faster and more specific.
  • Message — optional, free text. Whatever you choose to put in it.

That is the whole form. There is no phone field, no budget dropdown, no account to create, and no password to set. We never ask for patient names, medical records, insurance details or payment information, and you should not send them to us.

What the site attaches

When you arrive, a small script stores the campaign parameters in the address bar, the page you landed on, and the referring site. Those values sit in your browser's sessionStorage under the key oris_attr and are cleared the moment you close the tab. They are added to your submission only if you actually submit the form. The full list — and, in the panel at the top of this page, your own live values — is:

  • landing_page — the first page you opened on this site
  • referrer — the site or search engine you came from
  • utm_source — campaign source, if a link carried one
  • utm_medium — campaign medium
  • utm_campaign — campaign name
  • utm_content — which link inside a campaign
  • utm_term — keyword, if one was passed
  • ref — a plain referral tag we sometimes use in email
  • gclid — Google click identifier, if you arrived from an ad

We use this to tell whether a cold email, a guide or a search result produced the enquiry. It is business measurement, not profiling: nothing is built into a persistent profile, nothing is shared with an ad network, and nothing follows you to another website.

Why we are allowed to

Under the GDPR we rely on two grounds. Your form submission is handled to take steps at your request before entering into a contract — you asked for an audit, we cannot send it without your email (Article 6(1)(b)). The attribution fields rest on our legitimate interest in knowing which of our own marketing works, weighed against the fact that they describe a click rather than a person (Article 6(1)(f)). If you would rather we did not keep the attribution, say so in the message field and we will strip it.

The request data our host processes — the IP address in section 5 — rests on the same legitimate-interest ground: a public website that cannot filter automated abuse does not stay up. We do not query it, export it or join it to anything else.

Who else sees it

Three companies are involved in getting your submission from your browser into an inbox. Two of them handle the contents — the form service that carries it and the mail provider that stores the email it becomes. The third only serves the pages and never sees the form at all.

  • Web3Forms — the first stop after your browser. It receives what you submitted and turns it into an email addressed to us. Their own terms and handling are published at web3forms.com; we do not operate that service and we are not going to paraphrase their policy for them.
  • The mail provider that hosts the HeadPills inbox. This is where the email lands, where it is read, and where it stays until it is deleted. The specific provider is named on request; we would rather leave this line general than print a vendor we have not confirmed.
  • Cloudflare — serves this site. Like any web host it processes the technical request data needed to deliver a page and to block automated abuse, including your IP address. It does that on our behalf, so we name it here rather than treating it as plumbing. We write no cookie of our own; Cloudflare may set a short-lived security cookie to do that filtering, and it is the only cookie this site can cause — the next section says what that means for consent. Nothing there is analytics or advertising, and no form contents pass through it: your submission goes straight from your browser to Web3Forms.

We do not sell data, we do not rent lists, and we do not pass your details to a partner agency. If that ever changes, it changes on this page first and with a new date at the top.

Analytics, cookies and trackers

Google Analytics 4 is wired into this site but is not running. The code that would load it is conditional on a measurement ID, and no measurement ID has been configured — so no analytics script is requested, no analytics cookie is set, and no data reaches Google from this site today. We are telling you this rather than describing analytics that do not exist. When it is switched on, this section changes and the date at the top of the page changes with it.

Also worth stating plainly, because most policies bury it:

  • No advertising or retargeting pixels. No Meta pixel, no Google Ads tag, no LinkedIn insight tag.
  • No session recording or heatmaps. Nobody is watching a replay of your cursor.
  • No chat widget, so no third party sits in the corner of the page listening.
  • No embedded social feeds, no comment system, no A/B testing service.
  • Fonts are self-hosted from this domain, so no font CDN ever sees your IP address. That was a performance decision first and a privacy one second, but it counts as both.
  • The site is a static build on Cloudflare Pages. There is no database behind it, no login, and no server-side profile of you anywhere.

So there are exactly two things this site can put in your browser, and here is the whole list. The oris_attr session key described above: not a cookie, not readable by another site, gone when the tab closes. And Cloudflare's security cookie from the section before this one: set by the host to tell a human from a bot, short-lived, and no use to anyone for advertising.

Neither of them tracks you, and neither is an analytics or advertising cookie — which is why you have not been shown a consent banner. If that ever stops being true, the banner arrives before the tracker does.

How long we keep it

Your submission stays in the HeadPills inbox and in the lead list we work from. In practice that means it lives as long as the conversation does, and afterwards as a record that the conversation happened.

We have not set a fixed deletion clock yet, and we are not going to print one we do not enforce. That is the honest state of it as of 7 August 2026. What we will commit to today is the part that is entirely in your hands: ask us to delete your data and it goes, in full, including the copy in the inbox. The attribution values are the exception that solves itself — they disappear from your browser when you close the tab.

Host-side request logs are the one part we neither hold nor control: they sit with Cloudflare, on their retention schedule, and we cannot delete them on your behalf. We are not going to quote a window for somebody else's system.

Your rights, and how to get your data deleted

HeadPills is established in Poland, so the GDPR governs how we handle personal data — for everyone, not only for European visitors. US visitors get the same handling, because there is one inbox and one process and running two standards would only mean running the weaker one.

You can ask us to:

  • tell you what we hold about you, and send you a copy;
  • correct anything that is wrong;
  • delete all of it;
  • stop using it for a given purpose, or object to the legitimate-interest basis above;
  • hand it over in a portable form.

Email [email protected] with what you want. No form, no account, no verification theatre — if you write from the address you gave us, that is enough. The GDPR gives us a month to respond and we intend to be a lot faster than that. If you think we have handled it badly you can complain to a supervisory authority; ours is the Polish data protection authority, UODO.

We are not a healthcare provider

Oris sells systems to clinics. We do not treat patients, we are not a covered entity, and this website is not a channel for patient enquiries. Nothing on this site asks for health information, and the audit form is meant for the owner or manager of a practice.

If you are a patient trying to reach a clinic, contact the clinic directly — we cannot book, cancel or discuss anything on their behalf. If patient information reaches us anyway, by email or in the message field, we delete it and tell the sender we have.

Where we do work inside a clinic's systems, that engagement is governed by its own contract and, where applicable, a business associate agreement — separately from this policy, which covers this website only. We build to documented HIPAA-aware practice. We are not lawyers, and we say so in writing wherever a state adds rules of its own.

How it is stored

The site is served over HTTPS and holds nothing itself — it is static files on a CDN, with no database and no admin login to compromise. Your submission leaves your browser over an encrypted connection to Web3Forms. From there it is delivered as ordinary email, and that hop runs on mail infrastructure we do not operate: modern providers encrypt it in transit, but we are not going to guarantee a link in the chain we cannot see. Once delivered, it sits in a HeadPills mailbox and is read by the people working on Oris.

No system is perfect and we are not going to claim a certification we do not hold. We hold no ISO certificate, no SOC 2 report and no privacy seal, and we have not published an internal access policy because we have not written one. What we can tell you is exactly how few places your data sits, which is the part that actually decides the risk.

Changes to this policy

When the handling changes — a new processor, analytics actually being switched on, a retention window we decide to enforce — this page changes first and the date at the top moves. There is no mailing list for policy updates because there is no mailing list at all.

Contact, and one disclaimer

Everything on this page goes to [email protected]: access requests, deletion requests, corrections, or a question about a line you do not like. You can also read who we are, what we charge, the terms that cover the commercial side, or ask for the free audit at the foot of this page.

This is a privacy policy, not legal advice. HeadPills is a digital agency, not a law firm, and nothing here should be used as a template for your own clinic's policy — your obligations under HIPAA, state law and the FTC are not the same as ours. This document describes what this website does with data, in plain words, and that is all it is for.

Last updated .

Free clinic audit

You now know exactly what happens to what you send

So here is the form itself. We call your line the way a patient would, check what AI says about your clinic, and compare your Google profile to three local competitors. Findings in two business days, whether or not we ever work together.

  • Findings in two business days
  • No call required to receive them
  • Yours to keep either way

No spam, no list. One reply, from a human, within two business days.

Free clinic audit