Healthiago Legal

Privacy Policy

Last Updated: July 20, 2026

1. Scope and Consent

This Privacy Policy describes how Healthiago ("Healthiago," "we," "us," or "our") collects, uses, discloses, retains, and safeguards personal data when you visit our websites (including healthiago.ai, docs.healthiago.ai, and status.healthiago.ai), create or use an account, interact with our remote patient monitoring and connected care platform (the "Services"), communicate with us, or otherwise engage with Healthiago.

By accessing or using the Services, submitting information to us, or continuing to use the Services after this Policy is posted or updated, you acknowledge that you have read and understood this Privacy Policy. Where applicable law requires consent for specific processing activities (for example, certain cookies, marketing communications, or processing of sensitive categories of data), we will obtain consent through an affirmative mechanism before that processing occurs, and you may withdraw consent as described in the User Rights section below, without affecting the lawfulness of processing based on consent before its withdrawal.

Healthiago provides technology services to healthcare organizations, clinicians, care teams, patients, caregivers, and other authorized users. When we process protected health information ("PHI") on behalf of a covered entity or business associate customer, we do so as a business associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"), subject to a Business Associate Agreement ("BAA") and our related HIPAA policies where those instruments apply. This Privacy Policy describes our general personal-data practices for the Services and marketing sites; HIPAA-specific patient rights and uses of PHI may also be governed by your healthcare provider's notice of privacy practices and the applicable BAA.

2. Types of Personal Data Collected

We collect personal data that you provide directly, data generated through your use of the Services, and data we receive from customers, devices, and service providers as needed to operate the platform. Depending on your role and how you interact with Healthiago, this may include the following categories.

2.1 Identifiers and account information

We may collect name, email address, telephone number, postal or billing address, organization name, job title or role, username, authentication credentials, multi-factor authentication factors, account identifiers, invitation tokens, and similar contact or identity data. For patients and caregivers enrolled by a healthcare organization, we may also process medical record numbers or other internal identifiers assigned by the customer organization.

2.2 Health and clinical-related data (where applicable)

When authorized under a customer relationship and applicable law, the Services may process vital-sign readings and device telemetry (for example blood pressure, heart rate, weight, glucose, SpO2, and temperature), care-plan and enrollment information, clinical alerts, encounter or task notes entered by care teams, social determinants of health screening responses, and other health-related information necessary to deliver remote monitoring and care-coordination features. This information may constitute PHI when linked to an identifiable individual in a covered healthcare context.

2.3 Usage data and product analytics

We collect information about how you interact with the Services, including pages and features visited, clicks, session duration, referral URLs, search queries within the product (where enabled), error events, feature adoption metrics, and approximate timestamps of activity. We use this information to maintain reliability, improve usability, and detect abuse.

2.4 Device, network, and technical metrics

We automatically collect device type, operating system, browser type and version, IP address, approximate location derived from IP (city/region level), language settings, time zone, unique device or browser identifiers, and diagnostic logs related to performance, connectivity, and security. For connected monitoring devices, we may receive device serial numbers, firmware or model identifiers, transmission timestamps, and pairing or assignment status.

2.5 Cookies and similar technologies

We use cookies, local storage, session storage, pixels, and similar technologies to keep you signed in, remember preferences, maintain session security, measure traffic, and understand how our public sites are used. Essential cookies are required for authentication, load balancing, and fraud prevention. Analytics or preference cookies, where used, are employed to improve the Services and may be controlled through your browser settings or any consent mechanism we present. You may refuse non-essential cookies, but some features may not function correctly if essential cookies are blocked.

2.6 Communications and support content

If you contact us by email, demo request form, support ticket, newsletter signup, or similar channels, we collect the content of your message, attachments you choose to send, and metadata needed to respond (such as ticket identifiers and correspondence history).

3. Purpose of Processing and Data Usage

Healthiago processes personal data for the following purposes, based on one or more lawful bases under applicable law (including performance of a contract, legitimate interests that are not overridden by your rights, compliance with legal obligations, and consent where required):

We do not sell personal information for monetary consideration. We do not use PHI for marketing to patients without a permissible authorization or other lawful basis. Where we create de-identified data sets, we do so in a manner designed to reduce re-identification risk and may use such data for analytics, research, benchmarking, and product development consistent with applicable law and customer agreements.

4. Third-Party Data Sharing, Disclosures, and Service Providers

We share personal data only as described in this Policy, our customer agreements (including BAAs), and as required or permitted by law. Recipients may include:

Our subprocessors that handle PHI are required to enter into appropriate contractual safeguards (including BAAs where required). A current summary of material subprocessors is available to customers upon request at support@healthiago.ai, and we update that inventory as part of our vendor management program.

We do not permit service providers to use personal data for their own independent marketing purposes. Public documentation and status sites may use third-party fonts or analytics that receive limited technical data (such as IP address) under those providers' terms.

5. Data Retention and Secure Deletion

We retain personal data only for as long as reasonably necessary to fulfill the purposes described in this Policy, to provide the Services, to comply with legal, regulatory, tax, accounting, and audit requirements, to resolve disputes, and to enforce our agreements. Retention periods vary by data category and customer configuration. Typical practices include:

When retention ends, we delete personal data or irreversibly de-identify it using secure deletion mechanisms appropriate to the storage medium, including application-level deletion, database record removal or anonymization, and lifecycle policies on encrypted object storage. Backup media are overwritten or expire according to defined backup rotation schedules. Where immediate physical destruction of media is not feasible, data remains encrypted and inaccessible pending backup expiry.

6. Data Security Measures

Healthiago implements administrative, technical, and physical safeguards designed to protect personal data and PHI against unauthorized access, alteration, disclosure, or destruction. Measures include, without limitation:

No method of transmission or storage is completely secure. If you believe your account or data has been compromised, contact us immediately at support@healthiago.ai or support@healthiago.ai. We maintain incident response procedures, including breach assessment and notification processes required under HIPAA and applicable state or international law.

7. User Rights — Access, Rectification, and Deletion

Subject to applicable law and the nature of your relationship with Healthiago (for example, whether you are a website visitor, an organization administrator, or a patient whose data is controlled by a healthcare provider customer), you may have rights to:

To exercise these rights, email support@healthiago.ai with the subject line "Privacy Rights Request," and include your name, the email associated with your account (if any), a description of the request, and enough information for us to verify your identity. Patients seeking access to medical records maintained by their healthcare provider should generally direct requests to that provider; Healthiago will support the provider under the BAA and HIPAA access procedures.

We will respond within the timeframes required by applicable law (for example, without undue delay and within one month under the GDPR, subject to permitted extensions, and within timeframes specified by the CCPA/CPRA for California consumer requests). If we deny a request in whole or in part, we will explain the reasons and available appeal or complaint options where required.

8. Region-Specific Disclosures — GDPR and CCPA

8.1 European Economic Area, United Kingdom, and Switzerland (GDPR frameworks)

If you are located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, the EU General Data Protection Regulation, UK GDPR, and related local laws (collectively, "GDPR frameworks") may apply to our processing of your personal data. Under those frameworks, Healthiago may act as a "controller" for website, marketing, account administration, and security data that we determine the purposes and means of processing, and as a "processor" (or service provider) when we process personal data — including health data — solely on documented instructions of a customer organization that is the controller.

Lawful bases for controller processing may include: performance of a contract with you; legitimate interests in operating, securing, and improving the Services (balanced against your rights); compliance with legal obligations; and consent where required. Special-category health data is processed only where permitted, including where necessary for healthcare purposes under applicable conditions, under a BAA/customer instruction, or with explicit consent where that is the applicable basis.

Where we transfer personal data from the EEA/UK/Switzerland to the United States or another country that has not been deemed to provide adequate protection, we implement appropriate safeguards such as Standard Contractual Clauses (and UK International Data Transfer Addendum where applicable), supplemented by technical and organizational measures. You may request information about relevant transfer mechanisms by contacting support@healthiago.ai.

You also have the right to lodge a complaint with a supervisory authority in your country of residence or work. We encourage you to contact us first so we can address your concerns directly.

8.2 California Consumer Privacy Act / CPRA (CCPA rights)

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, "CCPA") provides additional rights regarding personal information. In the preceding twelve (12) months, we may have collected the categories of personal information described in Section 2 (identifiers; internet or other electronic network activity; geolocation approximations; professional information; and, in healthcare service contexts, health-related information). We collect this information from you, your devices, our customer organizations, and service providers for the business purposes described in Section 3.

California residents may have the right to: (a) know the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we disclose personal information; (b) delete personal information we collected from you, subject to exceptions; (c) correct inaccurate personal information; (d) opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising, if applicable; and (e) limit use and disclosure of sensitive personal information to purposes permitted by the CCPA.

Healthiago does not sell personal information as that term is commonly understood, and we do not sell or share personal information for cross-context behavioral advertising. We do not discriminate against you for exercising CCPA rights. To submit a verifiable consumer request, email support@healthiago.ai or contact support@healthiago.ai. You may designate an authorized agent to make a request on your behalf, subject to proof of authorization and identity verification. Certain PHI and provider-directed processing may be subject to HIPAA rather than, or in addition to, the CCPA; we will explain the applicable framework when responding.

Other U.S. state privacy laws (including those in Virginia, Colorado, Connecticut, Utah, and Texas, among others) may provide similar rights. Residents of those states may contact us at the same email address to exercise applicable rights.

9. Children's Privacy

The Services are not directed to children under the age of 13 (or the higher age defined by local law for digital consent), and we do not knowingly collect personal data from children for our own independent purposes without appropriate authorization. Patient minors may be enrolled by a healthcare organization or parent/guardian in accordance with applicable law and customer configuration. If you believe we have collected personal data from a child inappropriately, contact support@healthiago.ai and we will take prompt steps to delete or secure the information as required.

10. International Users

Healthiago is operated from the United States. If you access the Services from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States and other countries where we or our subprocessors maintain facilities. Those countries may have data-protection laws different from your jurisdiction. We apply the safeguards described in this Policy regardless of location.

11. Changes to This Privacy Policy and Annual Review

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or Services. When we make material changes, we will post the updated Policy on this page, update the "Last Updated" date above, and, where required by law or contract, provide additional notice (such as email or an in-product notification).

Healthiago reviews this Privacy Policy at least annually as part of our compliance and information-security governance program, and more frequently when we introduce material new processing activities, enter new jurisdictions, or receive regulatory guidance that affects our disclosures. The annual review is owned by our Privacy Officer (or designee) with input from Security and Legal stakeholders. Continued use of the Services after an update becomes effective constitutes acceptance of the revised Policy, except where applicable law requires a different consent mechanism.

12. Contact Us

For privacy questions, rights requests, or concerns about this Policy, contact:

Related documents: our Terms of Service govern use of the Services. Platform status is published at https://status.healthiago.ai. The application-hosted canonical copy is also available at https://healthiago.ai/privacy-policy.