Privacy Policy
Last Updated: December 11, 2025
This Privacy Policy explains how Dr. Kaylie Tejeda and Wholesum, LLC (“Company,” “we,” “us,” or “our”) collect, use, disclose, and protect your information when you use our website and online services (“Service”). By using the Service, you agree to the practices described in this Privacy Policy.
1. Scope and Relationship to HIPAA
We operate as a functional medicine and coaching practice. We may handle two types of information:
1.1 Protected Health Information (PHI) Under HIPAA
If you receive clinical services, certain information is classified as PHI and is protected under the Health Insurance Portability and Accountability Act (“HIPAA”).
PHI is governed by our HIPAA Notice of Privacy Practices, not this Privacy Policy. If there is a conflict, the HIPAA notice controls for PHI.
1.2 Information Covered by This Privacy Policy
This Privacy Policy applies to Personal Data collected through:
- Our website
- Online forms
- Scheduling and communication tools
- Email or marketing interactions
- Coaching or educational programs
2. Definitions
Account: A unique account created to access parts of the Service.
Company: Refers to Dr. Kaylie Tejeda and Wholesum, LLC, 7901 4th St N, St. Petersburg, Florida 33702, USA.
Device: Any device capable of accessing the Service.
Personal Data: Any information that identifies or relates to an identifiable individual.
Service: The website and online services at https://kaylietejeda.com.
Usage Data: Information collected automatically during use of the Service.
Service Provider: A third-party entity that processes data on our behalf.
3. Information We Collect
3.1 Personal Data You Provide
We may collect information including:
- Name
- Email address
- Phone number
- Mailing address
- Account login details (if applicable)
- Payment information (via secure processors)
- Information submitted through forms, scheduling tools, or inquiries
- Information shared during coaching programs
If you become a clinical patient, additional health information is collected as PHI and handled under HIPAA.
3.2 Non-Clinical Health Information
If you share health-related information through coaching, educational programs, or forms, it is treated as Personal Data unless collected for clinical care.
3.3 Usage Data
Automatically collected information may include:
- IP address
- Browser type and version
- Pages visited
- Date and time of visits
- Time spent on pages
- Device identifiers
- Diagnostic data
4. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service, improve performance, understand how users interact with the website, and deliver relevant content.
For detailed information on the types of cookies used and how to manage or withdraw your consent, please refer to our Cookie Policy.
5. Third-Party Analytics and Tracking
We may use third-party service providers to analyze website usage, support communication, improve performance, and deliver relevant content. These partners may use cookies or similar technologies to collect information about your online activity over time and across different websites and devices.
For more information, please see our Cookie Policy.
We do not sell Personal Data under any applicable privacy law, including the CCPA/CPRA.
6. How We Use Personal Data
We may use Personal Data to:
- Operate and maintain the Service
- Provide coaching and educational services
- Schedule sessions and manage communications
- Process payments and complete transactions
- Respond to inquiries and support requests
- Send administrative and service-related messages
- Deliver newsletters or updates (with your consent where required)
- Improve the quality and performance of our Service
- Detect, prevent, or respond to fraud or misuse
- Comply with legal and regulatory obligations
PHI is used strictly in accordance with HIPAA rules.
7. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process Personal Data under one or more of the following bases:
- Consent
- Performance of a contract
- Compliance with legal obligations
- Legitimate interests (such as improving our website, preventing fraud)
- Vital interests
- Public interest (rare situations)
8. How We Share Personal Data
We may share Personal Data with:
Service Providers
For hosting, analytics, scheduling, communications, payment processing, or other operational needs.
Coaching or Clinical Team Members
To deliver services you request. PHI is shared according to HIPAA.
Business Partners or Collaborators
When jointly offering programs or events.
Successors in a Business Transaction
If the Company undergoes a merger, acquisition, or asset transfer.
Legal Authorities
When required by law or necessary to protect rights, safety, or property.
With Your Consent
For purposes disclosed at the time of collection.
We do not sell Personal Data.
9. Data Retention
We retain Personal Data only as long as necessary to:
- Provide the Service
- Fulfill the purpose for which it was collected
- Meet legal, tax, or regulatory requirements
- Resolve disputes
- Enforce agreements
Clinical records are retained according to HIPAA and state law.
10. International Data Transfers
Your information may be transferred to and processed in the United States or other jurisdictions where privacy laws may differ. We use appropriate safeguards when legally required.
11. Your Privacy Rights
11.1 GDPR (EEA) Rights
If you are in the EEA, you may have the right to:
- Access Personal Data
- Correct inaccurate information
- Request deletion
- Restrict or object to processing
- Request data portability
- Withdraw consent at any time
11.2 CCPA/CPRA (California) Rights
If you are a California resident, you may have the right to:
- Know what Personal Data we collect
- Access specific information
- Request deletion
- Correct inaccurate data
- Opt out of the sale or sharing of Personal Data (we do not sell data)
- Limit the use of sensitive Personal Data (if applicable)
- Be free from discrimination for exercising your rights
To exercise your rights, contact us using the information in Section 16. Identity verification may be required.
12. Do Not Track
The Service does not respond to “Do Not Track” signals. You may manage cookie preferences through your browser, device settings, or Cookie Policy tools.
13. Children’s Privacy
The Service is not directed to children under 13. We do not knowingly collect Personal Data from children without appropriate parental consent. If you believe a child has provided Personal Data, contact us so we can take appropriate action.
Clinical services for minors are governed by HIPAA and applicable state laws.
14. Links to Other Websites
The Service may contain links to third-party websites not operated by us. We are not responsible for their content or privacy practices. We encourage you to review their privacy policies before providing any information.
15. Security
We use commercially reasonable safeguards to protect Personal Data. However, no method of transmission or electronic storage is completely secure. If a data incident occurs, we will follow applicable legal requirements for notification and response.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised “Last Updated” date. Continued use of the Service after updates constitutes acceptance of the revised policy.
17. Contact Us
If you have questions or wish to exercise your privacy rights, you may contact us at:
Email: legal@drkaylie.com
Also see our other legal pages: Terms & Conditions | Cookie Policy | Disclaimer

