Privacy Policy

Effective / last updated: August 6, 2026

This explains what our website collects, why we collect it, who else sees it and how to stop it. It is written to be read, not filed — if anything here is unclear, call us and we will talk it through.

Who we are and what this policy covers

Wele Clinic is the registered assumed name of Omidvari Psychiatry P.C., a New York domestic professional service corporation. We are an outpatient psychiatry practice at 1123 Broadway, Suite 1117, New York, NY 10010, registered with the New York Department of State under identification number 6877780. In this policy, "we" and "us" mean that practice.

This policy covers the two websites we control: weleclinicnyc.com, the site you are reading now, and appointments.weleclinicnyc.com, where appointments are booked. The booking site is hosted and operated for us by our scheduling provider, so that provider’s own privacy terms apply to it in addition to this one.

Two different sets of rules are at work here, and it helps to keep them apart. This Privacy Policy covers information the website collects from visitors. The information in your medical record — what you tell your psychiatrist, your diagnosis, your treatment notes, your billing — is protected health information under HIPAA, and it is governed by our Notice of Privacy Practices, which gives you stronger and more specific rights than this document does. If you are a patient asking about your record, that is the document you want.

This policy takes effect on August 6, 2026 and applies from that date. If you have a question about it, or you want to make a request about your information, here is how to reach the person who handles privacy for the practice.

By phone
(646) 874-9340, Monday to Friday, 9:00 am to 8:00 pm Eastern Time.
By post
1123 Broadway, Suite 1117
New York, NY 10010
Response time
We answer requests about website information within 30 days. Requests about your medical record follow the timelines in our Notice of Privacy Practices.

Information we collect

What you give us

Most of what we hold about you, you typed in yourself. There are three places on this site where that happens: the intake form on our contact page, the insurance-verification form on our insurance page, and the chat window in the corner of every page. All three are built and hosted by RunPractice (assets.runpractice.ai, api.runpractice.ai), so what you type goes to them and to us.

Depending on which one you use, that can include:

  • Your name.
  • Your phone number and email address.
  • How you would prefer us to contact you — phone, email or text.
  • Your insurance details, so we can check your benefits before a first session.
  • Your reason for getting in touch.
  • Medications you are currently taking.
  • Treatments you have already tried.
  • Anything else you choose to write in a free-text box or a chat message.

We also hold what you tell us on the phone when you call, and what you send us if you write to us.

What is collected automatically

Like almost every website, ours records some technical information about the visit itself, whether or not you ever contact us:

  • Your IP address.
  • Your device, browser and operating system.
  • The page or search that sent you here.
  • Which pages you looked at, and how long you spent on each one.
  • Clicks, scrolls and other on-screen interactions.

What we do not collect

We do not collect or store payment card details anywhere on this website. There is no checkout here. Payment for a visit is taken at the practice at the time of your appointment, or through our separate booking site, which is run by our scheduling provider on its own systems.

We also do not ask for detailed clinical information through a web form, a chat message or email — and we would rather you did not send it. A sentence about why you are getting in touch is plenty. The full history belongs in your appointment, where it is protected as part of your medical record and where your psychiatrist can actually respond to it.

In an emergency

Wele Clinic is not an emergency service. If you're experiencing a medical or psychiatric emergency, call 911 or go to the nearest emergency room. If you're having thoughts of suicide, call or text 988.

Our forms, chat and email are not monitored around the clock, so please do not use them to tell us you are in crisis. Call 911, or call or text 988, or go to your nearest emergency room.

How we use information

We use what we collect to:

  • Answer your question, return your call and book your appointment.
  • Check your insurance benefits before a first session, so the cost is not a surprise.
  • Run, secure and improve the website — for example, to see which pages actually help people find care, and which ones people give up on.
  • Meet our legal, professional and record-keeping obligations as a New York medical practice.

We do not sell personal information. We do not use health-related information to target advertising, and we do not use it to build, upload or expand an advertising audience of any kind.

That rule reaches into how the website is built, not just into what we promise. The measurement events this site sends are named for the button that was pressed, never for a condition, a diagnosis or a treatment. The two we currently send are "call_click" and "book_click", each with a note of which part of the page the button was in. Nothing in an event name says anything about you.

Cookies, analytics and session recording

Three third-party services run on this site. Each one is named below with what it is for, because a list of "categories of cookies" tells you nothing useful.

Google Tag Manager

Container GTM-N28S6JC2. This is not a measurement tool in itself — it is the container that decides which measurement tags load on a page. We use it to count how many people reach each page and how many use the call and booking buttons, so we can tell whether the site is doing its job.

Contentsquare/Hotjar

Site id 93025fbd7f529. This produces heatmaps — aggregated pictures of where visitors click and how far down a page they scroll — and session recordings, which replay the movement of a visit through the site. We use them to find layout problems: a button nobody can see, a section everybody abandons. We do not use them to identify you, and nothing they produce becomes part of anyone’s medical record.

RunPractice

Provides the intake form, the insurance-verification form and the chat window, from assets.runpractice.ai, api.runpractice.ai. What you type into any of those three goes to RunPractice and to us. It is not sent to an advertising platform.

When these load, and what they store

None of the measurement tags load when the page first opens. They wait for the first of two things: you interacting with the page — a tap, a key press, a scroll — or your browser finishing its work and going idle. Once loaded, they set cookies and store small amounts of data in your browser so that repeat visits are not counted as new ones. The chat window loads with the page.

How to turn them off

We do not currently operate a cookie-preferences panel on this site, so the controls below are the ones that work, and they work whether or not we cooperate:

  • Your browser settings. Every major browser can block or delete cookies, per-site or entirely, and private or incognito windows discard them when you close the window.
  • A content- or tracker-blocking extension. These stop the analytics and session-recording scripts from loading at all, rather than loading them and asking them to behave.
  • Hotjar publishes a standing opt-out page that stops its tracking on every site that uses it: hotjar.com/legal/compliance/opt-out.
  • Google publishes a browser add-on that opts you out of Google Analytics measurement everywhere: tools.google.com/dlpage/gaoptout.

And the simplest option of all: you do not have to use this website. Call (646) 874-9340 and we will take your details, answer your questions, check your insurance and book your appointment by phone. Nothing here has to be done in a browser.

When website information becomes protected health information

This is the question that matters most on a psychiatry website, so we will answer it directly.

Reading our public pages does not, by itself, put anything into your medical record. Analytics on an information page — a page anyone can open without signing in — measures a visit, not a patient. Looking up what Spravato is does not make you our patient and does not create a health record about you.

What you voluntarily submit is different. The moment you send us something through a form or the chat window that both identifies you and relates to your health, we treat it as protected health information. It is handled under our Notice of Privacy Practices, it is kept with the rest of our records, and it is never given to an advertising or analytics vendor.

For anything genuinely clinical — a symptom that is worsening, a medication question, a request for records — please use the phone on our contact page or the secure booking and patient portal rather than a web form, a chat message or ordinary email. Those channels are convenient; they are not the right place for your clinical history.

Service providers and business associate agreements

We are a small practice and we use outside companies to run parts of it. The categories are: website hosting, online scheduling and intake, chat, analytics and session recording, telephone service, and email.

Any company that creates, receives, maintains or transmits protected health information on our behalf is engaged under a written Business Associate Agreement meeting 45 CFR 164.502(e) and 164.504(e). That agreement:

  • Limits the company to the specific purposes we have asked it to perform, and forbids any other use of the information.
  • Requires it to apply appropriate administrative, technical and physical safeguards.
  • Requires it to report to us, promptly, any breach or security incident affecting that information.
  • Binds any subcontractor it uses to the same terms.
  • Requires the information to be returned to us or destroyed when the engagement ends.

Vendors that are not business associates do not receive protected health information. That is the line we hold: a company that measures page views does not get to hold anything about your health.

We do not publish a list naming which of our vendors is a business associate, because such a list is only worth reading if every entry is backed by a signed agreement on the day it is published. If you want to know how a specific service handles your information, ask us and we will tell you.

How we share information

We do not sell or rent personal information. We never have.

Sharing is limited to five situations:

  1. With the service providers described above, under written contract, and only so they can do the job we engaged them for.
  2. Where you direct us to — for example, sending records to another clinician you have named, or speaking to a family member you have authorised.
  3. Where the law requires it, or in response to valid legal process such as a court order or subpoena.
  4. Where it is necessary to protect the safety of you or another person, in the narrow circumstances New York law and professional practice allow.
  5. In connection with a transfer of the practice — if the practice were sold, merged or transferred to another provider, records would move with it, and the same protections would continue to apply.

We do not share information with advertising platforms for health-based targeting. We do not upload patient or enquiry lists into a customer-match tool. We do not build lookalike or similar audiences from anyone who has contacted us. If you have ever been treated here, or ever asked us about treatment, no advertising system learns that from us.

How we protect information

Every page of this website and of our booking site is served over HTTPS, encrypted with TLS. The intake and insurance-verification forms submit over that same encrypted connection to our forms provider. No card data is stored on this website at any point.

Behind that, in plain terms: access to patient information is limited to the people who need it to do their work; devices and accounts are protected by passwords and, where the service supports it, a second factor; paper is kept locked; and we review who has access when somebody joins or leaves. These are the administrative, technical and physical safeguards HIPAA calls for, described the way we actually run them.

We maintain reasonable safeguards for the private information of New York residents, as New York General Business Law section 899-bb (the SHIELD Act) requires.

If something goes wrong

No practice can promise that a breach will never happen. What we can tell you is what follows one. If private information about New York residents is exposed, we will notify the people affected and, where the law requires it, the New York Attorney General, the State Police and the Department of State, under General Business Law section 899-aa. Where protected health information is involved, notification follows the HIPAA Breach Notification Rule instead, and that includes notifying the U.S. Department of Health and Human Services.

Reporting a security problem

If you think you have found a security weakness in this website or our booking site, please tell us at (646) 874-9340. Tell us what you found and how you found it. We will not pursue or penalise anyone who reports a problem in good faith and does not access or alter other people’s information in the process.

How long we keep information

Website enquiries
Kept for as long as we need them to answer you and to keep an accurate record of the contact, then deleted. If you ask us to delete an enquiry sooner and we are not required to keep it, we will.
Analytics and recordings
Held by each vendor for the retention period configured in that vendor's account, after which the vendor deletes it. We do not keep a separate copy. Ask us and we will tell you the current periods.
Medical records
Kept far longer than anything the website holds — at least six years from the date of the last entry, as the New York rules for physicians require, and longer for a patient who was a minor. HIPAA sets its own minimum retention periods for related documents.

The difference is deliberate. A record of a clinical relationship has to outlive the relationship, because you may need it years later. A note that you filled in a web form does not.

Children

This website is not directed to children under 13, and we do not knowingly collect information from them through it. If you believe a child under 13 has sent us information through this site, call us and we will delete it.

Care for anyone under 18 is arranged directly with the practice, with a parent or guardian involved from the start — not through a form on a website.

Your choices and your rights

For information the website holds about you, you can ask us to:

  • Tell you what we hold — what you sent us, and when.
  • Correct it, if something in it is wrong.
  • Delete an enquiry, where we are not required to keep it.
  • Stop contacting you by phone, text or email, at any time and for any reason. You do not have to give us a reason.

You can opt out of analytics and session recording at any time using the controls in the cookies and analytics section above.

Your rights over your medical record are separate, stronger and set by law: the right to see and get a copy of it, to ask for it to be amended, to ask for an accounting of certain disclosures, to request confidential communications, and to complain without any effect on your care. Those are set out in full in our Notice of Privacy Practices, together with how to complain to us and to the U.S. Department of Health and Human Services.

To make a request under this policy, call (646) 874-9340 or write to us at 1123 Broadway, Suite 1117, New York, NY 10010. We may need to confirm who you are before we act, so that we are not handing your information to somebody else. We answer requests about website information within 30 days; requests about your medical record follow the timelines in the Notice of Privacy Practices.

If this site itself is the barrier — if a form, the chat window or a page is unusable for you — see our Accessibility Statement, and call us. We will do it with you by phone instead.

Other websites and embedded services

Several things you can use from this site are operated by other companies, under their own privacy policies and their own security practices: our online booking site, the intake and insurance-verification forms, the chat window, and our review profiles on Zocdoc and Google. When you use one of those, you are also dealing with the company that runs it.

Links to outside websites are provided for convenience. They are not endorsements, and we do not control what those sites contain or what they do with information you give them. It is worth reading the privacy policy of any site you land on from here.

What our website says about treatment is general information, not medical advice, and nothing on it creates a doctor–patient relationship. That is set out in our Medical Disclaimer and our Terms of Use.

Changes to this policy and how to contact us

When this policy changes, we post the new version on this page and update the effective date at the top. If a change is material — if it alters what we collect, who we share it with, or what you can ask us to do — we say so plainly at the top of the page rather than leaving you to find it.

Questions about this policy, or about anything we hold:

By phone
(646) 874-9340, Monday to Friday, 9:00 am to 8:00 pm Eastern Time.
By post
1123 Broadway, Suite 1117
New York, NY 10010
Response time
We answer requests about website information within 30 days. Requests about your medical record follow the timelines in our Notice of Privacy Practices.

If you would rather speak to someone in person, our office is at 1123 Broadway, Suite 1117, New York, NY 10010.