1. Scope and Consent
This Privacy Policy describes how Healthiago ("Healthiago," "we," "us," or "our") collects, uses, discloses, retains, and safeguards personal data when you visit our websites (including healthiago.ai, docs.healthiago.ai, and status.healthiago.ai), create or use an account, interact with our remote patient monitoring and connected care platform (the "Services"), communicate with us, or otherwise engage with Healthiago.
By accessing or using the Services, submitting information to us, or continuing to use the Services after this Policy is posted or updated, you acknowledge that you have read and understood this Privacy Policy. Where applicable law requires consent for specific processing activities (for example, certain cookies, marketing communications, or processing of sensitive categories of data), we will obtain consent through an affirmative mechanism before that processing occurs, and you may withdraw consent as described in the User Rights section below, without affecting the lawfulness of processing based on consent before its withdrawal.
Healthiago provides technology services to healthcare organizations, clinicians, care teams, patients, caregivers, and other authorized users. When we process protected health information ("PHI") on behalf of a covered entity or business associate customer, we do so as a business associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"), subject to a Business Associate Agreement ("BAA") and our related HIPAA policies where those instruments apply. This Privacy Policy describes our general personal-data practices for the Services and marketing sites; HIPAA-specific patient rights and uses of PHI may also be governed by your healthcare provider's notice of privacy practices and the applicable BAA.
2. Types of Personal Data Collected
We collect personal data that you provide directly, data generated through your use of the Services, and data we receive from customers, devices, and service providers as needed to operate the platform. Depending on your role and how you interact with Healthiago, this may include the following categories.
2.1 Identifiers and account information
We may collect name, email address, telephone number, postal or billing address, organization name, job title or role, username, authentication credentials, multi-factor authentication factors, account identifiers, invitation tokens, and similar contact or identity data. For patients and caregivers enrolled by a healthcare organization, we may also process medical record numbers or other internal identifiers assigned by the customer organization.
2.2 Health and clinical-related data (where applicable)
When authorized under a customer relationship and applicable law, the Services may process vital-sign readings and device telemetry (for example blood pressure, heart rate, weight, glucose, SpO2, and temperature), care-plan and enrollment information, clinical alerts, encounter or task notes entered by care teams, social determinants of health screening responses, and other health-related information necessary to deliver remote monitoring and care-coordination features. This information may constitute PHI when linked to an identifiable individual in a covered healthcare context.
2.3 Usage data and product analytics
We collect information about how you interact with the Services, including pages and features visited, clicks, session duration, referral URLs, search queries within the product (where enabled), error events, feature adoption metrics, and approximate timestamps of activity. We use this information to maintain reliability, improve usability, and detect abuse.
2.4 Device, network, and technical metrics
We automatically collect device type, operating system, browser type and version, IP address, approximate location derived from IP (city/region level), language settings, time zone, unique device or browser identifiers, and diagnostic logs related to performance, connectivity, and security. For connected monitoring devices, we may receive device serial numbers, firmware or model identifiers, transmission timestamps, and pairing or assignment status.
2.5 Cookies and similar technologies
We use cookies, local storage, session storage, pixels, and similar technologies to keep you signed in, remember preferences, maintain session security, measure traffic, and understand how our public sites are used. Essential cookies are required for authentication, load balancing, and fraud prevention. Analytics or preference cookies, where used, are employed to improve the Services and may be controlled through your browser settings or any consent mechanism we present. You may refuse non-essential cookies, but some features may not function correctly if essential cookies are blocked.
2.6 Communications and support content
If you contact us by email, demo request form, support ticket, newsletter signup, or similar channels, we collect the content of your message, attachments you choose to send, and metadata needed to respond (such as ticket identifiers and correspondence history).
3. Purpose of Processing and Data Usage
Healthiago processes personal data for the following purposes, based on one or more lawful bases under applicable law (including performance of a contract, legitimate interests that are not overridden by your rights, compliance with legal obligations, and consent where required):
- Service delivery: to create and administer accounts, authenticate users, enforce role-based access, deliver remote patient monitoring workflows, display clinical and operational dashboards, and provide patient and caregiver portals.
- Care coordination and clinical operations: to support care-team tasks, alerts, escalations, device assignment, and reporting that our healthcare organization customers configure within the Services.
- Security and integrity: to detect, prevent, and investigate fraud, abuse, unauthorized access, malware, and other security incidents; to maintain audit logs; and to protect the rights, property, and safety of Healthiago, our customers, users, and the public.
- Billing, contracting, and administration: to manage subscriptions, invoices, procurement, BAAs, and related business records with customer organizations.
- Product improvement and reliability: to monitor uptime, diagnose errors, improve features, and develop new capabilities using aggregated or de-identified data where feasible.
- Communications: to send service, security, and transactional notices; to respond to support requests; and, where permitted, to send product updates or marketing communications that you may opt out of at any time.
- Legal compliance: to comply with applicable laws, regulations, lawful requests, and our contractual obligations, including HIPAA, state privacy laws, and international data-protection requirements where they apply.
We do not sell personal information for monetary consideration. We do not use PHI for marketing to patients without a permissible authorization or other lawful basis. Where we create de-identified data sets, we do so in a manner designed to reduce re-identification risk and may use such data for analytics, research, benchmarking, and product development consistent with applicable law and customer agreements.
4. Third-Party Data Sharing, Disclosures, and Service Providers
We share personal data only as described in this Policy, our customer agreements (including BAAs), and as required or permitted by law. Recipients may include:
- Healthcare organization customers and authorized users: clinicians, care coordinators, administrators, and other roles designated by the customer organization that enrolls patients or manages accounts within the Services.
- Service providers and subprocessors: vendors that perform services on our behalf such as cloud hosting and infrastructure (including Amazon Web Services), database and storage services, email and transactional messaging, payment processing (where used), authentication or identity providers, device connectivity partners, monitoring and logging tools configured to minimize sensitive data, and professional advisors (legal, security, accounting) under confidentiality obligations.
- Business transfers: if we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality and, for PHI, HIPAA requirements.
- Legal and safety disclosures: we may disclose information if we believe in good faith that disclosure is necessary to comply with law, regulation, legal process, or governmental request; to enforce our agreements; or to protect against imminent harm.
Our subprocessors that handle PHI are required to enter into appropriate contractual safeguards (including BAAs where required). A current summary of material subprocessors is available to customers upon request at support@healthiago.ai, and we update that inventory as part of our vendor management program.
We do not permit service providers to use personal data for their own independent marketing purposes. Public documentation and status sites may use third-party fonts or analytics that receive limited technical data (such as IP address) under those providers' terms.
5. Data Retention and Secure Deletion
We retain personal data only for as long as reasonably necessary to fulfill the purposes described in this Policy, to provide the Services, to comply with legal, regulatory, tax, accounting, and audit requirements, to resolve disputes, and to enforce our agreements. Retention periods vary by data category and customer configuration. Typical practices include:
- Account and authentication records: retained for the life of the account and for a commercially reasonable period afterward for security, fraud prevention, and legal hold, unless a shorter period is required by agreement or law.
- Clinical and monitoring records (PHI): retained according to the customer organization's instructions, applicable medical-record retention laws, HIPAA documentation requirements, and our BAA. Upon contract termination, we return or destroy PHI in accordance with the BAA, except to the extent retention is required by law or permitted for archival copies that remain protected.
- Support tickets and operational logs: retained for a period appropriate to troubleshooting, security investigation, and service improvement, then deleted or aggregated.
- Marketing preferences and newsletter data: retained until you unsubscribe or request deletion, subject to suppression-list retention needed to honor opt-outs.
When retention ends, we delete personal data or irreversibly de-identify it using secure deletion mechanisms appropriate to the storage medium, including application-level deletion, database record removal or anonymization, and lifecycle policies on encrypted object storage. Backup media are overwritten or expire according to defined backup rotation schedules. Where immediate physical destruction of media is not feasible, data remains encrypted and inaccessible pending backup expiry.
6. Data Security Measures
Healthiago implements administrative, technical, and physical safeguards designed to protect personal data and PHI against unauthorized access, alteration, disclosure, or destruction. Measures include, without limitation:
- Encryption: TLS encryption in transit for public network connections; encryption at rest for production databases and object storage using industry-standard algorithms managed through our cloud provider controls.
- Access controls: role-based access control, least-privilege principles, multi-factor authentication for workforce and privileged access, unique user credentials, and organization-scoped tenancy isolation so customer data is segregated by design.
- Monitoring and auditability: logging of security-relevant events, alerting for anomalous conditions, vulnerability management, and periodic access reviews.
- Secure development and operations: change management, dependency scanning, secrets management, and production hardening practices aligned to our security program.
- Workforce and vendor controls: confidentiality obligations, security awareness expectations, and contractual requirements for subprocessors that process personal data or PHI.
No method of transmission or storage is completely secure. If you believe your account or data has been compromised, contact us immediately at support@healthiago.ai or support@healthiago.ai. We maintain incident response procedures, including breach assessment and notification processes required under HIPAA and applicable state or international law.
7. User Rights — Access, Rectification, and Deletion
Subject to applicable law and the nature of your relationship with Healthiago (for example, whether you are a website visitor, an organization administrator, or a patient whose data is controlled by a healthcare provider customer), you may have rights to:
- Access: request confirmation of whether we process your personal data and obtain a copy of the personal data we hold about you, subject to identity verification and legal exceptions.
- Rectification: request correction of inaccurate or incomplete personal data. Account holders may update certain profile fields directly in the Services; other corrections may require assistance from your organization administrator or our privacy team.
- Deletion: submit an explicit request that we delete personal data we hold about you. We will honor deletion requests where required by law, after verifying your identity, except where we must retain information for legal compliance, security, dispute resolution, or as instructed by a customer that is the controller of the data (for example, PHI retained under a provider's medical-record obligations).
- Restriction, objection, and portability: where applicable law provides these rights (including under the GDPR), you may request restriction of processing, object to certain processing based on legitimate interests or direct marketing, or receive personal data in a structured, commonly used, machine-readable format.
- Withdraw consent: where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing.
To exercise these rights, email support@healthiago.ai with the subject line "Privacy Rights Request," and include your name, the email associated with your account (if any), a description of the request, and enough information for us to verify your identity. Patients seeking access to medical records maintained by their healthcare provider should generally direct requests to that provider; Healthiago will support the provider under the BAA and HIPAA access procedures.
We will respond within the timeframes required by applicable law (for example, without undue delay and within one month under the GDPR, subject to permitted extensions, and within timeframes specified by the CCPA/CPRA for California consumer requests). If we deny a request in whole or in part, we will explain the reasons and available appeal or complaint options where required.
8. Region-Specific Disclosures — GDPR and CCPA
8.1 European Economic Area, United Kingdom, and Switzerland (GDPR frameworks)
If you are located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, the EU General Data Protection Regulation, UK GDPR, and related local laws (collectively, "GDPR frameworks") may apply to our processing of your personal data. Under those frameworks, Healthiago may act as a "controller" for website, marketing, account administration, and security data that we determine the purposes and means of processing, and as a "processor" (or service provider) when we process personal data — including health data — solely on documented instructions of a customer organization that is the controller.
Lawful bases for controller processing may include: performance of a contract with you; legitimate interests in operating, securing, and improving the Services (balanced against your rights); compliance with legal obligations; and consent where required. Special-category health data is processed only where permitted, including where necessary for healthcare purposes under applicable conditions, under a BAA/customer instruction, or with explicit consent where that is the applicable basis.
Where we transfer personal data from the EEA/UK/Switzerland to the United States or another country that has not been deemed to provide adequate protection, we implement appropriate safeguards such as Standard Contractual Clauses (and UK International Data Transfer Addendum where applicable), supplemented by technical and organizational measures. You may request information about relevant transfer mechanisms by contacting support@healthiago.ai.
You also have the right to lodge a complaint with a supervisory authority in your country of residence or work. We encourage you to contact us first so we can address your concerns directly.
8.2 California Consumer Privacy Act / CPRA (CCPA rights)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, "CCPA") provides additional rights regarding personal information. In the preceding twelve (12) months, we may have collected the categories of personal information described in Section 2 (identifiers; internet or other electronic network activity; geolocation approximations; professional information; and, in healthcare service contexts, health-related information). We collect this information from you, your devices, our customer organizations, and service providers for the business purposes described in Section 3.
California residents may have the right to: (a) know the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we disclose personal information; (b) delete personal information we collected from you, subject to exceptions; (c) correct inaccurate personal information; (d) opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising, if applicable; and (e) limit use and disclosure of sensitive personal information to purposes permitted by the CCPA.
Healthiago does not sell personal information as that term is commonly understood, and we do not sell or share personal information for cross-context behavioral advertising. We do not discriminate against you for exercising CCPA rights. To submit a verifiable consumer request, email support@healthiago.ai or contact support@healthiago.ai. You may designate an authorized agent to make a request on your behalf, subject to proof of authorization and identity verification. Certain PHI and provider-directed processing may be subject to HIPAA rather than, or in addition to, the CCPA; we will explain the applicable framework when responding.
Other U.S. state privacy laws (including those in Virginia, Colorado, Connecticut, Utah, and Texas, among others) may provide similar rights. Residents of those states may contact us at the same email address to exercise applicable rights.
9. Children's Privacy
The Services are not directed to children under the age of 13 (or the higher age defined by local law for digital consent), and we do not knowingly collect personal data from children for our own independent purposes without appropriate authorization. Patient minors may be enrolled by a healthcare organization or parent/guardian in accordance with applicable law and customer configuration. If you believe we have collected personal data from a child inappropriately, contact support@healthiago.ai and we will take prompt steps to delete or secure the information as required.
10. International Users
Healthiago is operated from the United States. If you access the Services from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States and other countries where we or our subprocessors maintain facilities. Those countries may have data-protection laws different from your jurisdiction. We apply the safeguards described in this Policy regardless of location.
11. Changes to This Privacy Policy and Annual Review
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or Services. When we make material changes, we will post the updated Policy on this page, update the "Last Updated" date above, and, where required by law or contract, provide additional notice (such as email or an in-product notification).
Healthiago reviews this Privacy Policy at least annually as part of our compliance and information-security governance program, and more frequently when we introduce material new processing activities, enter new jurisdictions, or receive regulatory guidance that affects our disclosures. The annual review is owned by our Privacy Officer (or designee) with input from Security and Legal stakeholders. Continued use of the Services after an update becomes effective constitutes acceptance of the revised Policy, except where applicable law requires a different consent mechanism.
12. Contact Us
For privacy questions, rights requests, or concerns about this Policy, contact:
- Privacy: support@healthiago.ai
- Support: support@healthiago.ai
- Website: https://healthiago.ai
Related documents: our Terms of Service govern use of the Services. Platform status is published at https://status.healthiago.ai. The application-hosted canonical copy is also available at https://healthiago.ai/privacy-policy.