Luuka LLC (“Luuka,” “we,” “us,” or “our”) operates the website at https://luuka.ai and related subdomains (the “Site”), and provides AI-powered healthcare scheduling and communications services (the “Services”), including voice agents and SMS/MMS messaging.
This Privacy Policy describes how we collect, use, disclose, and protect information when you:
- Visit or use the Site (including demo request forms);
- Use or interact with our Services as a customer, authorized user, or business partner; or
- Receive SMS/MMS or other electronic communications from us or from a healthcare provider that uses Luuka.
By using the Site or Services, or by providing your mobile number to receive text messages, you acknowledge this Privacy Policy. If you do not agree, please do not use the Site or Services or opt in to messaging.
Contact: [email protected]
1. Who We Are
Luuka AI is a healthcare operations platform that helps medical practices and healthcare organizations answer scheduling calls, book and manage appointments, and send related patient communications (including appointment confirmations, reminders, and care-related notices) using AI voice and messaging technology.
When we process protected health information (“PHI”) on behalf of a covered entity or business associate customer, we do so as a business associate under a Business Associate Agreement (“BAA”), subject to HIPAA and the BAA—not solely this Privacy Policy.
2. Information We Collect
2.1 Information you provide directly
- Contact and identity information: name, email address, phone number, organization name, job title, and other details you submit on forms (e.g., demo requests).
- Account information: login credentials, role, and preferences for customer portals or admin tools.
- Communications: emails, support requests, call transcripts or recordings (where enabled), and feedback you send us.
- SMS program information: mobile phone number and messaging consent preferences when you opt in to receive texts.
2.2 Information from healthcare provider customers (and their patients)
When a clinic, practice, or other healthcare organization (“Provider Customer”) uses Luuka, we may process data they provide or that is generated through the Services, which may include:
- Patient name, date of birth, phone number, email, medical record number, and appointment details;
- Provider, location, specialty, scheduling rules, and availability;
- Call audio, transcripts, and related metadata for scheduling interactions;
- EHR/PMS data necessary to look up patients, check availability, and book, reschedule, or cancel appointments.
This information may constitute PHI. Provider Customers are responsible for obtaining any required patient notices and authorizations under applicable law.
2.3 Information collected automatically
When you visit the Site or use the Services, we may automatically collect:
- Device and usage data: IP address, browser type, operating system, device identifiers, pages viewed, referring URLs, and timestamps;
- Cookies and similar technologies: session and preference cookies, analytics cookies, and similar tools (see Section 8);
- Log and security data: access logs, error logs, and fraud/security signals.
2.4 Information from third parties
We may receive information from:
- Identity or security vendors, payment processors (if applicable), and analytics providers;
- Business partners and referral sources;
- Publicly available sources, to the extent permitted by law;
- Carrier and messaging infrastructure providers (e.g., delivery receipts, opt-out signals).
3. How We Use Information
We use information for purposes including:
- Providing and operating the Services — voice scheduling, appointment management, outbound reminders, no-show recovery, analytics for Provider Customers, and related support;
- SMS/MMS and other messaging — sending transactional and service-related messages you or your Provider Customer have authorized (see Section 5);
- Site and marketing operations — responding to demo requests, improving the Site, and (where permitted) sending product updates or marketing communications;
- Security and integrity — authentication, fraud prevention, abuse detection, and service reliability;
- Legal and compliance — complying with law, enforcing terms, defending claims, and meeting healthcare, telecom, and privacy obligations;
- Research and improvement — de-identified or aggregated analytics to improve models, product quality, and user experience (we do not use PHI for model training in a way that violates our BAAs or applicable law).
We do not sell personal information. We do not sell mobile phone numbers.
4. How We Share Information
We may share information with:
| Recipient | Purpose |
|---|---|
| Service providers / subprocessors | Cloud hosting, telephony and SMS infrastructure (including providers such as Twilio), analytics, security, customer support, and similar vendors bound by contractual confidentiality and data-protection obligations |
| Provider Customers | When you are a patient or end user interacting with a practice that uses Luuka, information may be shared with that practice as needed to provide care and scheduling services |
| Professional advisors | Lawyers, auditors, and insurers as needed |
| Authorities | When required by law, legal process, or to protect rights, safety, and security |
| Business transfers | In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards |
4.1 Mobile information — no third-party marketing sharing (CTIA / carrier requirement)
We will not share or sell your mobile phone number, SMS opt-in data, or consent to receive text messages with third parties or affiliates for their own marketing or promotional purposes.
Mobile information is used only to deliver the messaging program you consented to, to operate and support the Services, and as otherwise described in this Privacy Policy (including with infrastructure providers that process messages solely to transmit them on our behalf).
Sharing with your healthcare provider (when they are the sender or program sponsor) and with vendors that process data for us to provide the Services is not a sale or marketing transfer of your number.
5. SMS / Text Messaging Privacy
This section applies if you provide a mobile number to receive text messages from Luuka or from a Provider Customer using Luuka’s messaging capabilities.
5.1 Types of messages
Depending on the program and your relationship with Luuka or a Provider Customer, messages may include:
- Appointment confirmations, reminders, and pre-visit instructions;
- Reschedule, cancellation, waitlist, and no-show recovery messages;
- Care-coordination or account notices related to your appointments;
- One-time passwords or verification codes (if enabled);
- Responses to HELP / STOP and other service keywords;
- Limited product or service updates from Luuka if you separately opt in to marketing texts.
5.2 Message frequency
Message frequency varies. You may receive messages as needed based on your appointments, account activity, and preferences. For appointment-related programs, message volume typically depends on how often you schedule or change visits (for example, confirmations and one or more reminders per appointment). For other programs, you may receive recurring messages at a frequency disclosed at opt-in (e.g., up to several messages per month).
5.3 Message and data rates
Message and data rates may apply. Check your wireless plan with your carrier for details. Luuka is not responsible for carrier charges.
5.4 Opt-in and consent
We (or a Provider Customer) obtain consent before sending non-exempt commercial or recurring messages as required by applicable law (including the TCPA), carrier rules, and industry guidelines (including CTIA Messaging Principles). Consent may be obtained via web form, verbal consent during a call, paper form, keyword opt-in, or other compliant methods. SMS consent is not a condition of purchasing goods or services unless clearly stated otherwise where required.
5.5 Opt-out
You may opt out of SMS messages at any time by replying STOP (or other opt-out keywords we support). After opting out, you will receive a confirmation and we will stop sending you program messages, except as allowed by law (e.g., a single confirmation). You may re-enroll by following the opt-in instructions provided by Luuka or your Provider Customer.
5.6 Help
For help with text messaging, reply HELP or contact us at [email protected].
5.7 What we collect for messaging
For SMS programs we may process: mobile number, carrier routing data, message content and metadata, delivery status, opt-in/opt-out timestamps and method, and related device or log data needed for delivery and compliance.
6. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Site, remember preferences, measure traffic, and improve performance. You can control cookies through your browser settings. Disabling certain cookies may affect Site functionality. Where required by law, we will obtain consent for non-essential cookies.
7. Data Retention
We retain personal information only as long as needed for the purposes described in this Policy, including to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods for PHI and call recordings are governed by our agreements with Provider Customers, BAAs, and applicable law. Messaging consent records are retained as required for compliance (including carrier and TCPA-related requirements).
When information is no longer needed, we delete or de-identify it in accordance with our retention schedules and technical capabilities.
8. Security
We implement administrative, technical, and physical safeguards designed to protect personal information and PHI, including encryption in transit, access controls, logging, and vendor due diligence. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
For enterprise customers, additional security and compliance materials (including BAA availability) may be provided upon request.
9. HIPAA and Healthcare Data
- Luuka is not a covered entity under HIPAA solely by operating the marketing Site.
- When we create, receive, maintain, or transmit PHI for a Provider Customer, we act as a business associate under a BAA.
- Use and disclosure of PHI are limited to what the BAA, customer agreements, and HIPAA permit.
- Patient rights regarding PHI (access, amendment, accounting of disclosures, etc.) are primarily exercised through the Provider Customer (your healthcare organization). Contact your clinic or hospital first for PHI requests.
10. Children’s Privacy
The Site and Services are not directed to children under 13 (or under 16 where applicable). We do not knowingly collect personal information from children for marketing purposes. Scheduling communications involving minors are handled through the relevant Provider Customer’s relationship with the patient/guardian as permitted by law.
11. Your Privacy Rights
Depending on your location, you may have rights to:
- Access, correct, or delete personal information;
- Portability of certain data;
- Restrict or object to certain processing;
- Opt out of marketing emails (unsubscribe link or email us);
- Opt out of SMS (reply STOP);
- Appeal certain decisions where required by state law.
U.S. state privacy laws (e.g., CCPA/CPRA and similar laws): We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are commonly defined. You may still contact us to exercise applicable rights. We will not discriminate against you for exercising privacy rights.
To submit a request, email [email protected]. We may need to verify your identity. Authorized agents may submit requests where permitted by law.
12. International Users
The Site and Services are primarily intended for users in the United States. If you access them from outside the U.S., you understand that your information may be processed in the United States and other countries that may have different data-protection rules than your country of residence.
13. Third-Party Links and Services
The Site may link to third-party websites or services. We are not responsible for their privacy practices. Review their policies before providing information.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The “Last Updated” date at the top will reflect changes. Material changes may be communicated via the Site, email, or other reasonable means. Continued use of the Site or Services after an update constitutes acceptance of the revised Policy where permitted by law.
15. Contact Us
Luuka LLC
Website: https://luuka.ai
Email: [email protected]
For privacy requests, SMS help, or questions about this Policy, contact [email protected].
Related: Terms of Use [email protected]