Ask Rubix Technology a question. Answers come from this site's docs only. I will cite a page. I will not invent a product claim.
Privacy Policy & Terms of Service
Effective date: September 14, 2026 · Last updated: September 14, 2026
Controller / provider: Rubix Technology LLC (“Rubix,” “we,” “us”)
5030 Corporate Exchange Blvd SE, Grand Rapids, MI 49512, United States
Contact: sales@rubixtechnology.com · Main: 800-799-4407
This page has two parts: Privacy Policy — how we handle information on our Sites, including HIPAA- and PCI-related practices; Terms of Service — terms for using the Sites and related notices, including responsibility for misuse.
It is written for business and IT buyers. It is not legal advice and it does not create a certification.
Sites covered (www): rubixtechnology.com · secure-message.io · secure-desk.io · secure-guard.io · secure-assess.com · secure-watch.io · secure-store.io
Related systems (not marketing Sites): Rubix Hub at hub.rubixtechnology.com, and product applications or appliances you deploy or subscribe to.
Privacy Policy
1. Scope — marketing Sites vs product systems
Marketing Sites are public websites used for product information, documentation, contact, interest, and evaluation requests. Forms on the Sites are for business contact and sales/evaluation interest. They are not intended as PHI intake portals, patient portals, or cardholder-data capture forms.
Product systems are the software, appliances, SaaS applications, and related services customers run or subscribe to (for example Secure Message, SecureGuard, Secure Desk, Secure Assess, SecureWatch, Rubix Backup / Secure Store, and Rubix Hub). When a customer processes personal data, protected health information (PHI), or other regulated data in a product system, that processing is governed by the customer’s configuration, the applicable product terms, and any business associate agreement (BAA) or other contract in place — not by this marketing-site policy alone.
2. HIPAA (marketing Sites and product context)
Rubix builds and supports technology used by healthcare and other regulated organizations. We design practices and products with HIPAA safeguards in mind (for example least privilege, encryption in transit and at rest where applicable, auditability, and customer-controlled deployments). That is a design standard — not a claim that Rubix or any Secure product is “HIPAA certified,” “HIPAA compliant” as a blanket marketing badge, or that a particular deployment automatically satisfies a covered entity’s obligations.
- Covered entities and business associates: Where Rubix acts as a business associate for a covered entity under HIPAA, we enter into a Business Associate Agreement (BAA) when applicable. Request a BAA through sales@rubixtechnology.com or your Rubix account contact.
- PHI in product systems: PHI and other health information that customers process with Secure products is handled in those product systems under the customer’s control (and contracts), not through marketing Site forms.
- PHI on marketing Sites: Do not submit PHI, patient identifiers, clinical notes, or other sensitive health information through Site contact, interest, or evaluation forms. If you need a secure channel for regulated data, ask sales for the appropriate product or contractual path.
- Self-hosted products: Several Secure products are designed to run on infrastructure the customer controls. In those deployments, Rubix typically does not host the customer’s production PHI unless a separate hosted/managed arrangement is agreed in writing.
3. PCI DSS (payments and marketing Sites)
- Payments: Paid licenses and subscriptions are sold through Rubix Hub. Card payments are processed by PCI-compliant payment processors (including Stripe as configured on Hub). Rubix does not intend for marketing Sites to collect full payment card numbers.
- Marketing Sites: The Sites do not store full primary account numbers (PANs). Do not enter full card numbers into Site contact forms.
- Cardholder data: Cardholder data for Hub transactions is handled by the payment processor under their PCI responsibilities. Rubix’s role is limited to what Hub and the processor integration require.
- Secure Assess and PCI 11.3: Secure Assess provides defensive vulnerability assessment related to PCI DSS requirement 11.3. It is not an official ASV attestation and not a penetration test (11.4). Using Assess does not by itself make an organization “PCI certified.”
This section describes payment and Site practices. It is not a claim that Rubix holds a specific PCI certification level as a blanket public badge for all products and services.
4. Information we collect on the Sites
4.1 Information you provide
When you use a contact, interest, get-started, evaluation, or similar form, we may collect name, business email, phone, company name, job title/role, message content, product interest, and optional fields the form shows.
4.2 Information collected automatically
When you browse the Sites, we and our processors may collect IP address, approximate location derived from IP, browser and device type, referring URL, pages viewed, and timestamps; analytics via Google Analytics 4 (GA4) and, where configured, Google Tag Manager (GTM); security / bot protection such as Cloudflare Turnstile on forms; and, where configured, SEO / site-health scripts (for example Ahrefs Web Analytics) injected by our website platform.
4.3 Cookies and similar technologies
We use cookies and similar technologies for essential Site operation and security (including Turnstile) and for analytics (GA4/GTM where enabled). You can control cookies through your browser. Blocking some cookies may affect form or analytics behavior.
5. How we use Site information
We use Site information to respond to sales, evaluation, and support requests; operate, secure, and improve the Sites; understand aggregate traffic and content performance; detect fraud, spam, and abuse; and comply with law and enforce our terms. We do not sell personal information collected on the Sites as a consumer data brokerage product.
7. Retention
We retain Site form submissions and related communications as long as needed for sales follow-up, security, dispute resolution, and legal obligations, then delete or de-identify when no longer needed. Analytics retention follows the settings on our analytics accounts.
8. Security
We apply administrative, technical, and physical safeguards appropriate to marketing Sites and to our business, informed by healthcare and payment-data practices (including least privilege, encryption in transit where used, and access that can be reviewed). No method of transmission or storage is 100% secure.
9. International visitors
We are based in the United States. If you access the Sites from outside the U.S., you understand information may be processed in the United States.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, or restrict certain personal information, or to object to certain processing. To make a request about Site data, email sales@rubixtechnology.com with “Privacy request” in the subject. We may need to verify your request. You may also unsubscribe from marketing email using the link in those messages (transactional and account messages may continue).
11. Children
The Sites are for business users. We do not knowingly collect personal information from children under 16 on the Sites.
12. Third-party links
Sites may link to third-party sites (including Hub, documentation hosts, or directories). Their privacy practices are their own.
13. Changes to this Privacy Policy
We may update this Privacy Policy. The “Last updated” date will change when we do. Continued use of the Sites after an update means you accept the revised Privacy Policy.
14. Privacy contact
Rubix Technology LLC
5030 Corporate Exchange Blvd SE, Grand Rapids, MI 49512
sales@rubixtechnology.com · 800-799-4407
For BAAs, privacy requests, or security questionnaires, use the same contact and note the topic in the subject line.
Terms of Service
These Terms of Service (“Terms”) govern access to and use of the Sites. Separate product licenses, Hub terms, order forms, and BAAs (if any) govern product use; if there is a conflict with a signed written agreement, that agreement controls for its subject matter.
Acceptance
By using the Sites, you agree to these Terms. If you do not agree, do not use the Sites.
Sites are informational
The Sites provide product and company information for business evaluation. Site content is not a binding offer for every feature, price, or deployment option. Hub catalog and signed agreements control commercial terms where they apply.
Accounts and Hub
Licenses, subscriptions, and paid purchases are handled through Rubix Hub and related processors. You are responsible for credentials you control and for activity under your Hub account.
Acceptable use of the Sites
You will not misuse the Sites (including scraping that degrades service, attempting unauthorized access, submitting malware, or using forms to abuse or harass). Do not submit PHI or full payment card numbers through marketing Site forms.
Disclaimer of warranties (Sites)
THE SITES AND THEIR CONTENT ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE FULLEST EXTENT PERMITTED BY LAW, RUBIX DISCLAIMS WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT FOR THE SITES. We do not warrant that the Sites will be uninterrupted, error-free, or free of harmful components.
Misuse and limitation of liability (products and services)
Important — standard software / SaaS notice. This section is intended to match the kind of misuse and responsibility language used by major software, SaaS, and AI technology companies. It is not custom “drama,” and it is not a claim that Rubix is never liable for anything under every theory of law.
Our products and services are tools. You (the customer or end user) are responsible for configuring, deploying, operating, monitoring, and securing them in line with your policies, applicable law, and security and operational best practices — including access control, patching, backups, key management, network design, monitoring, and deciding what data you process.
Rubix Technology LLC is not liable for misuse of its products or services by customers, end users, or third parties. That includes, without limitation: use in violation of law, regulation, or third-party rights; use that bypasses, disables, or ignores security controls; unauthorized access, abuse, or attacks carried out by third parties using or targeting systems you operate; and harm arising from configurations, policies, integrations, or data you choose to run.
Many Secure products are designed to run on infrastructure you control (or with keys and data paths you control). Where you host or configure the system, you control the environment in which outcomes occur. Rubix does not assume responsibility for every possible configuration or for decisions made by operators of that environment.
Documentation and marketing describe capabilities; they are not a guarantee against misuse or against every failure mode.
TO THE FULLEST EXTENT PERMITTED BY LAW, RUBIX TECHNOLOGY LLC DISCLAIMS LIABILITY FOR DAMAGES ARISING FROM MISUSE, UNAUTHORIZED USE, FAILURE TO FOLLOW DOCUMENTATION OR SECURITY BEST PRACTICES, OR ACTS OR OMISSIONS OF CUSTOMERS, END USERS, OR THIRD PARTIES. Nothing in these Terms limits liability that cannot be limited under applicable law, or rights you have under a signed written agreement (including a BAA or order form) that expressly says otherwise.
Not certifications or legal advice
These Terms and the Privacy Policy are not legal advice and are not a certification (including not a claim that Rubix is “HIPAA certified” or holds a blanket PCI certification badge). Your compliance obligations remain yours.
Indemnity (Sites misuse)
To the extent permitted by law, you will defend and hold Rubix harmless from claims arising out of your misuse of the Sites or your violation of these Terms.
Governing law
These Terms are governed by the laws of the State of Michigan, United States, without regard to conflict-of-law rules, unless a signed agreement says otherwise.
Changes to Terms
We may update these Terms. The “Last updated” date will change when we do. Continued use of the Sites after an update means you accept the revised Terms.
Contact
Questions about these Terms: sales@rubixtechnology.com · Rubix Technology LLC, 5030 Corporate Exchange Blvd SE, Grand Rapids, MI 49512 · 800-799-4407
