Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains how Berryhill Consulting LLC (“Rekonix,” “we,” “us,” or “our”) handles personal information through theRekonix platform, optional modules, customer-facing portals, and rekonix.com (the “Service”). It is a privacy notice, not a request for blanket consent. Where consent is legally required, we request it separately.
1. Scope and our role
This Policy applies to website visitors, account holders, authorized users, payers, support contacts, and people who use a Rekonix-hosted payment, request, document, or patient portal. It also describes information our business customers submit about other people, including customers, vendors, workers, clients, donors, owners, tenants, patients, guarantors, and providers.
Rekonix determines how it uses account, website, billing, security, and support information. For records a customer enters to run its organization, the customer generally determines the purpose and Rekonix processes the information on its behalf. The Data Processing Addendum describes that relationship. For PHI, an effective Business Associate Agreement controls.
2. Information we collect
Account, organization, and billing information
- Names, email addresses, authentication identifiers, organization and firm details, roles, invitations, and account preferences.
- Billing contact, plan, subscription, usage, invoice, and payment-status information. Stripe handles full payment-card details; Rekonix does not store full card numbers.
- Communications, support requests, feedback, and records of choices, approvals, and consents.
Customer-submitted business and financial information
- Accounts, journal entries, transactions, reconciliations, reports, budgets, forecasts, tax settings, filings-related inputs, loans, assets, inventory, projects, contracts, grants, donations, properties, and related evidence.
- Customer, vendor, worker, donor, client, owner, tenant, and other contact information, which may include names, addresses, email, phone, tax identifiers, payment instructions, and transaction history.
- Invoices, bills, statements, emails, attachments, secure client documents, imported files, notes, approvals, and audit history.
- Crypto asset, wallet, exchange, tax-lot, and transaction information when that module is used.
Connected-account information
- Bank feeds. Account names and identifiers, institution, balances, transactions, and connection status received through a bank-data provider. Bank credentials are entered in the provider interface; Rekonix does not receive them.
- QuickBooks and other imports. Accounting records, lists, transactions, attachments, metadata, and migration evidence authorized through Intuit or uploaded by the customer. Rekonix requests read access and does not write back to QuickBooks.
- Payments. Connected-account identifiers, merchant and payout status, transaction references, fees, disputes, settlement data, business-verification information, and encrypted bank or funding-source references. Payment providers handle card and bank credentials.
- Email and portals. Messages, attachments, sender and recipient information, delivery metadata, portal verification, and customer-directed drafts or responses when a firm or intake feature is used.
Healthcare information
Healthcare Billing may process patient identity and contact information, date of birth, guarantor, coverage, payer and provider identifiers, diagnoses and procedure codes, encounters, charges, claims, remittances, denials, appeals, estimates, statements, payment plans, collections status, and audit records. Customers must not submit real PHI until Rekonix confirms that Healthcare Billing is approved for live use and a BAA is effective. Rekonix does not intend the module to store clinical notes, charts, or treatment records.
Information collected automatically
- IP address, browser and device type, requested pages, timestamps, referring information, error and security events, and similar technical logs.
- Strictly necessary cookies and local storage used for authentication, security, session continuity, preferences, and requested payment or connection flows.
- Activity and audit events, such as sign-in, record access, posting, approval, export, configuration, and integration actions.
3. Sources of information
We receive information directly from users; from the organization, firm, or practice that provides access; from customer uploads and portals; from connected providers such as Clerk, Stripe, Plaid, Intuit, payment rails, email providers, and financial institutions; from public or licensed reference sources selected for a module; and automatically from the Service and its infrastructure.
4. How we use information
- Provide accounts, ledger functions, modules, reports, portals, imports, connections, payments, and customer-directed communications.
- Authenticate users, enforce roles and tenant separation, protect the Service, detect misuse, investigate incidents, and maintain audit evidence.
- Process billing, subscriptions, usage charges, receipts, refunds, and entitlement status.
- Respond to support, maintain reliability, correct errors, and communicate service, security, billing, and legal notices.
- Comply with law, valid legal process, contracts, and enforceable rights.
- Create aggregated or deidentified information to measure, secure, and improve the Service without attempting to reidentify it.
We do not sell personal information, share it for cross-context behavioral advertising, use financial or health information for advertising, or use Your Data to train general-purpose AI models.
5. AI-assisted processing
If a customer enables an AI-assisted document or workflow feature, Rekonix may transmit the selected content and instructions to the identified AI provider solely to produce the requested extraction, classification, draft, or suggestion. We configure provider access under commercial terms intended to prohibit training on customer content. Users must review outputs. We do not send PHI to an AI provider unless the healthcare BAA chain expressly permits it and the feature is approved for live PHI.
6. How we disclose information
- Service providers. Providers of hosting, database, authentication, email, security, support, document processing, and subscription billing process information for operational purposes under applicable contracts.
- Customer-directed integrations. We disclose information to a bank-data aggregator, financial institution, payment rail, connected processor, Intuit, mailbox provider, commerce platform, mailing provider, AI provider, or healthcare rail when a customer enables that function.
- Authorized users and firms. Information is visible to users, bookkeepers, accountants, firm staff, client contacts, portal recipients, or other parties according to the customer’s roles, links, and instructions.
- Legal and safety. We may disclose information when required by law or valid process, or when reasonably necessary to protect rights, safety, security, and the integrity of the Service.
- Business transaction. Information may transfer in a financing, reorganization, merger, acquisition, or sale, subject to confidentiality and this Policy.
Our current providers and optional recipients are described on the Subprocessor and Integration Provider List. Some providers, particularly financial institutions and payment providers, may act independently for their own fraud, compliance, and legal obligations and apply their own privacy notices.
7. Bank-data privacy
Bank-feed information is used to establish and maintain the connection, import and enrich transactions, present balances, apply customer rules, reconcile records, support the connection, and protect against fraud. We do not use it for advertising. Disconnecting invalidates or removes the Rekonix-held access token where supported; previously imported accounting and audit records remain until deleted under the customer’s account lifecycle.
Plaid-powered connections are also governed by Plaid’s End User Privacy Policy.
8. Healthcare privacy
When Rekonix processes PHI for a covered entity or business associate, Rekonix acts as a business associate to the extent stated in the executed BAA. The healthcare customer remains responsible for its HIPAA Notice of Privacy Practices and responding to patients, although Rekonix will provide assistance required by the BAA. This Privacy Policy is not a healthcare provider’s HIPAA Notice of Privacy Practices.
9. Retention and deletion
| Category | Retention approach |
|---|---|
| Account and organization records | While the account is active and afterward as needed for closure, disputes, security, tax, and legal obligations. |
| Books, documents, and audit history | As directed by the customer while active. Posted and audit records may be immutable within the Service. After verified closure, data is deleted or deidentified subject to legal holds and applicable DPA or BAA terms. |
| Connection tokens | While the connection is active. Tokens are invalidated or deleted on disconnect or expiry where supported; completed migration connections may be removed on their documented expiry schedule. |
| Billing and transaction evidence | For the subscription or transaction lifecycle and afterward as required for tax, accounting, payment disputes, fraud prevention, and legal compliance. |
| Security and technical logs | For a limited period appropriate to security, diagnostics, incident response, and legal needs. |
| Backups | Until they age out through the protected backup rotation, unless preservation is legally required. |
To close an account or request deletion, contact support@rekonix.com. We verify authority, explain records that must be retained, and confirm the applicable deletion and backup schedule. Customers should export records they are legally required to retain before closure.
10. Security
We use safeguards designed for the sensitivity of the information, including encrypted transport, managed encryption at rest, access controls, tenant-scoped authorization, audit records, protected secrets, and additional application-layer encryption for selected integration tokens, payment references, and documents. No system is completely secure. Customers share responsibility for user access, endpoints, exports, credentials, and configuration. Report suspected incidents to support@rekonix.com.
11. Your privacy rights
Depending on applicable law, you may request access, correction, deletion, portability, restriction, or an appeal of a denied request, and may use an authorized agent. You will not be discriminated against for exercising a privacy right. Because we do not sell or share personal information for behavioral advertising, no sale/share opt-out is necessary. Contact support@rekonix.com. We will verify the request and respond as required by law.
If information was submitted by a Rekonix customer, we may direct you to that customer, which controls the record. We assist customers with requests as required by contract and law.
12. Cookies and tracking
We use necessary cookies and similar storage for sign-in, security, preferences, and requested embedded payment or connection experiences. We do not currently use third-party advertising or cross-site behavioral tracking cookies. If that changes, we will update this notice and provide choices required by law before use.
13. Children and minors
Rekonix accounts are for adults and organizations and the Service is not directed to children as users. Business customers may nevertheless submit information about minors when lawfully necessary for healthcare, payroll, dependent, customer, or other business records. The customer is responsible for authority and required notices. Rekonix processes that information on the customer’s behalf and, for PHI, under an effective BAA.
14. International processing
Rekonix is based in the United States. Providers may process information in the United States and other countries where they operate. Where required, the DPA provides an appropriate transfer mechanism. Customers must not use the Service where doing so would violate applicable localization or transfer restrictions.
15. Changes to this Policy
We may update this Policy as the Service and law change. We will update the date above and provide additional notice when appropriate for a material change. Prior versions may be requested from us.
16. Contact
Contact support@rekonix.com for privacy questions, rights requests, complaints, or information about our data practices.