How this site uses information

This page describes the public website at chrysalissurgery.com. It is not a substitute for the HIPAA Notice of Privacy Practices. Consultation and contact forms collect information that identifies a person seeking care. That combination is treated as protected health information from the first keystroke.

What the public forms collect. First name, last name, email, optional phone, optional procedure or area of interest, optional insurance name, name of insured, and state, plus a free-text message. We do not ask for a Social Security number, date of birth, insurance member ID, or diagnosis on a public form. Those are collected later through a secure follow-up after identity is established.

Where submissions go. The browser posts to this site’s own /api/lead endpoint. The live worker stores a JSON copy in Cloudflare KV and forwards a copy into the practice Contentator Forms inbox for staff. Email destinations for these forms are empty: submissions are not mailed to a plain inbox. There is no patient autoresponder with clinical detail, the thank-you on the page acknowledges receipt only. Application-level AES-256 wrapping of lead payloads is not yet implemented; that remains a practice/infrastructure task.

Retention. Stale lead purge and six-year audit-log retention still need practice policy confirmation. Do not assume automatic deletion yet.

Shop. Retail checkout is not live. When it is, shop accounts must stay isolated from consultation intake. See shop and financial interest.

Tracking. See the current cookie and tracking inventory. There is no Google Analytics, Meta pixel, GTM, or session replay on this site. We have not installed a consent manager because there are no non-essential tags to gate. If that changes, non-essential tags will stay blocked until opt-in, and advertising pixels will not load on clinical, procedure, or insurance pages.

Contact. Chrisalys Surgery, 436 N Bedford Drive, Suite 202, Beverly Hills, CA 90210. (310) 247-4729.