Foundry Enterprise Partners

Privacy Policy

Last updated: September 10, 2026

The short version

Foundry collects information you choose to give us. If you fill in the contact form, or complete the Practice Pulse Check, we receive what you typed. We use it to reply to you, to prepare for a conversation, and to keep track of practices we have talked with. We do not sell it. We do not send you unrelated marketing from other companies.

Two specifics worth stating plainly. When you complete the Practice Pulse Check, your individual answers to the twenty-five questions never leave your browser. What reaches us is your email address, the profile of your practice you entered at the start, and your result. And this website is not a place to send patient information. If you are a client and we need to see anything about identifiable patients, that happens under a separate written agreement, not through this site.

The rest of this policy is the full account.

1. Who we are and what this policy covers

Foundry Enterprise Partners LLC is a Florida limited liability company based in Central Florida. We work as an operating partner to healthcare organizations, principally chiropractic and musculoskeletal practices.

This policy covers information we collect through www.foundryep.com, including the contact form and the Practice Pulse Check, and information we receive when you email or call us or book time on our calendar.

Section 8 covers information we receive from clients during an engagement. Section 9 covers protected health information. Those two categories work differently from website information, and the distinction matters.

This policy does not cover the practices of other companies whose services we use or link to. Section 7 names the ones that handle your information for us.

2. Information you give us

Through the contact form. Your first and last name, email address, practice name, number of locations, and whatever you write in the message field.

Through the Practice Pulse Check. The assessment begins by asking for the number of locations you operate, full-time-equivalent providers, total headcount, a revenue band, an optional exact revenue figure, and your three-year objective. It then asks twenty-five diagnostic questions. Before your report appears, it asks for your email address.

What we receive is a specific and limited set: your email address, the practice profile above, your care model and payer mix category, your score band and score range, the primary constraint the instrument named, the version of the scoring rules that produced it, and a timestamp.

Your twenty-five answers stay in your browser. The instrument does the scoring on your own device and transmits only the result. Close the tab and those answers are gone, including from us. We never had them.

When you contact us directly. Anything you include in an email, a text message, a voicemail, or a scheduled call, including notes we take during the conversation.

When you book a call. Our scheduling link opens a Microsoft Bookings page. It asks for your name, email address, and anything else the booking form requests, and it places the appointment on our calendar. No assessment answers, scores, or figures are attached to that link.

3. Information collected automatically

Server and log information. Our website is hosted by Squarespace. Their servers record standard request data: IP address, browser type and version, operating system, referring page, and the date and time of the request. Squarespace retains these logs under its own policy, not ours.

Cookies and similar technologies. Squarespace sets cookies that are necessary for the site to function and cookies that count visits and sessions. We use no other analytics service. There is no Google Analytics on this site, no advertising pixel, and no cross-site tracking tag. You can set your browser to refuse cookies. Parts of the site may not work correctly if you do.

The Practice Pulse Check itself sets no cookies and writes nothing to your device's storage.

What we do not collect here. We do not take payments through this website, so no card or bank details reach it. We do not ask for a Social Security number, a driver's license number, or any government identifier. We do not request or want patient information through this site.

4. How we use information

We use what you give us to reply to you, to answer a question, and to prepare properly for a conversation about your practice.

We keep a record of practices we have spoken with, and of Pulse Check results, in our client relationship system. That record is how we remember what you told us and pick up where we left off.

We send occasional email about Foundry's work to people who have asked us to, and to people who have completed the Pulse Check or contacted us. Every one of those messages carries an unsubscribe link that works. Replies to your own questions and messages about an active engagement are not marketing, and unsubscribing does not stop those.

We look at aggregated Pulse Check results to improve the instrument and to understand patterns across practices. That analysis works on figures with names and email addresses removed. If we publish anything from it, it will be at the level of the group and will not identify any practice.

We use log and analytics data to keep the site working, to see which pages people read, and to detect abuse.

We use information where the law requires it, or to protect our rights, our clients, or someone's safety.

Legal bases, for anyone in the United Kingdom or European Economic Area. We rely on your consent for marketing email and for non-essential cookies, on the performance of a contract for engagement work, and on our legitimate interests in operating and improving the business for the rest. You can withdraw consent at any time.

5. What we do not do with information

We do not sell your personal information for money.

We do not share your name, email address, or anything you told us about your practice with other companies for their own marketing.

We do not use Pulse Check results to identify your practice to anyone, including to another client, a private equity buyer, a payer, or a competitor, unless you ask us to.

6. When we share information

Service providers. Named in Section 7. They handle information on our behalf and under contract.

With your direction. If you ask us to introduce you to a lender, a broker, an attorney, or another advisor, we share what that introduction requires.

Professional advisors. Our own attorneys, accountants, and insurers, where they need it.

Legal requirements. In response to a subpoena, court order, or other valid legal process, or where the law otherwise requires disclosure. Where we are permitted to tell you first, we will.

Protection of rights and safety. Where disclosure is reasonably necessary to protect Foundry, our clients, or the public from harm or illegal activity.

Business transfer. If Foundry is acquired, merged, or reorganized, information may transfer as part of that transaction. Any acquirer remains bound by this policy for information collected under it, or will give you notice before changing it.

7. Service providers who handle information for us

ProviderWhat it doesWhat it receives
SquarespaceWebsite hosting, forms, and built-in visit analyticsSite request logs, cookies, and contact form submissions
AttioClient relationship recordsPulse Check lead records and contact form details
Microsoft 365Email at our domain, calendar, scheduling through Microsoft Bookings, and file storageAnything you send us by email, what you enter when booking a call, and documents you send us

Each of these companies has its own privacy policy.

8. Information from client engagements

Engagement information works differently from website information, and this section governs it.

When we work with a practice, we receive operating data: financial statements, practice management and billing exports, payer contracts, employee rosters, and similar records. That information belongs to the client. Our written engagement agreement, and any confidentiality agreement signed alongside it, controls how we use it. Where that agreement and this policy differ, the agreement wins.

Within that framework, we use client information only to perform the engagement. We do not use one client's data to advise a competitor. We do not disclose that a company is a client without permission. We return or destroy engagement materials at the end of the engagement on the schedule the agreement sets, except where we are required to retain records or where retention is necessary to defend our work.

We may develop benchmarks and general observations from engagement work. Those are built from de-identified and aggregated figures, and they do not name or make identifiable any client.

9. Protected health information and HIPAA

Do not send patient information through this website or by ordinary email. Not through the contact form, not through the Practice Pulse Check, and not in an email attachment. Nothing on this site is designed to receive it. If a client needs to give us records containing patient information, we will set up an appropriate method first.

In some engagements Foundry acts as a business associate to a covered entity as those terms are used in the Health Insurance Portability and Accountability Act. Where that is the case, a written business associate agreement governs our handling of protected health information, and that agreement controls over this policy for that information.

Nothing collected through this website is protected health information. The Practice Pulse Check asks about a business. It does not ask about any patient.

10. How long we keep information

InformationHow long
Pulse Check lead recordThree years after our last contact with you, unless you ask us to delete it sooner
Contact form submissionsThree years after our last contact with you
Email correspondenceSeven years, consistent with our general business records practice
Client engagement materialsAs the engagement agreement provides, and as professional and legal record requirements allow
Site logs and analyticsAs Squarespace retains them under its own policy

Backups may hold a copy for a period after deletion from the live system.

11. Security

We use reasonable administrative and technical measures to protect information, including access controls on our systems, encryption in transit, and multi-factor authentication on the accounts that hold client and prospect records.

No method of transmission or storage is perfectly secure, and we do not claim otherwise. If a breach affecting your information occurs, we will notify you as the law requires.

12. Your choices

You can decline to complete the Pulse Check, or complete it and close the tab before the email step. Nothing reaches us if you do.

You can unsubscribe from our email at any time using the link in any message, or by writing to info@foundryep.com.

You can set your browser to refuse cookies, and you can use a browser or extension that sends a Global Privacy Control signal. We honor that signal where the law requires it.

You can ask us to delete what we hold about you. Section 13 explains how.

13. Your rights

Depending on where you live, you may have the right to know what personal information we hold about you, to get a copy of it, to have it corrected, to have it deleted, to opt out of its sale or of targeted advertising, and to be free from discrimination for asking. Residents of California, Colorado, Connecticut, Texas, Virginia, and a growing number of other states have rights along these lines under state law. Residents of the United Kingdom and the European Economic Area have rights under the UK GDPR and the GDPR, including the right to object to processing and the right to complain to a supervisory authority.

Foundry extends the substance of these rights to anyone who asks, regardless of where they live.

To make a request, write to info@foundryep.com with the subject line "Privacy request," or call us at (407) 815-4323. We will verify that the request comes from you, or from someone you have authorized in writing, before we act on it. We will respond within forty-five days, and will tell you if we need longer. There is no charge for a reasonable request.

For information a client gave us during an engagement, we will direct your request to that client, who controls it.

If we deny a request and you want that decision reviewed, say so in a reply and we will look at it again. Residents of some states may then complain to their state attorney general.

14. Children

This website is for practice owners and operators. We do not direct it to children, and we do not knowingly collect personal information from anyone under sixteen. If you believe a child has given us information, write to info@foundryep.com and we will delete it.

15. Other things worth knowing

Links to other sites. Our site links to a scheduling page and may link to other resources. Once you leave foundryep.com, the site you land on operates under its own privacy policy.

Where information is processed. Foundry operates in the United States and our service providers store information in the United States. If you use this site from outside the United States, your information will be processed here.

Changes to this policy. We will update this page when our practices change, and we will change the date at the top when we do. If a change is significant and we have your email address, we will tell you.

16. How to reach us

Email: info@foundryep.com

Phone: (407) 815-4323

Mail: Foundry Enterprise Partners LLC, c/o ZenBusiness Inc., 336 E. College Avenue, Suite 301, Tallahassee, FL 32301

This privacy policy is adapted from the Automattic privacy policy, used under a Creative Commons Attribution-ShareAlike 4.0 International license. This adaptation is licensed under the same terms.