Privacy Policy
Healthcare Privacy Commitment: As a healthcare technology company, SeraphCare is committed to protecting the privacy and security of all personal and health information in accordance with HIPAA, GDPR, and other applicable privacy regulations.
1. Information We Collect
Personal Information
We may collect the following types of personal information:
- Name, email address, phone number, and job title
- Organization or institution name and details
- Professional credentials and roles
- Communication preferences and demo requests
Health Information (PHI)
When you use our platform in a healthcare setting, we may process Protected Health Information (PHI) including:
- Patient medical records and clinical data
- Treatment information and care plans
- Diagnostic and imaging data
- Billing and insurance information
Technical Information
- IP addresses, browser type, and device information
- Website usage patterns and analytics
- System logs and performance data
- Cookies and similar tracking technologies
2. How We Use Your Information
We use collected information for the following purposes:
- Providing and improving our healthcare automation services
- Processing demo requests and customer communications
- Delivering clinical decision support and AI insights
- Ensuring platform security and preventing unauthorized access
- Complying with legal and regulatory requirements
- Conducting research and development (with proper anonymization)
3. HIPAA Compliance
Business Associate Agreement: For healthcare organizations using our platform, SeraphCare serves as a Business Associate under HIPAA and will execute appropriate Business Associate Agreements (BAAs) to ensure compliance.
Our HIPAA compliance measures include:
- Administrative, physical, and technical safeguards
- Access controls and user authentication
- Audit logs and monitoring systems
- Data encryption in transit and at rest
- Regular security assessments and training
- Incident response and breach notification procedures
4. Data Sharing and Disclosure
We do not sell personal or health information. We may share information only in the following circumstances:
- With your consent: When you explicitly authorize disclosure
- For treatment: To healthcare providers involved in patient care
- Legal requirements: When required by law or court order
- Service providers: With vendors who assist in platform operations (under strict agreements)
- Business transfers: In case of merger or acquisition (with continued privacy protections)
5. Data Security
We implement comprehensive security measures including:
- End-to-end encryption for all data transmission
- Advanced encryption standards (AES-256) for data storage
- Multi-factor authentication and role-based access controls
- Regular security audits and penetration testing
- 24/7 security monitoring and threat detection
- Secure cloud infrastructure with SOC 2 compliance
6. Data Retention
We retain information for the following periods:
- Personal information: As long as necessary for service provision
- Health information: According to healthcare record retention requirements
- Technical logs: Typically 1-2 years for security and performance analysis
- Marketing data: Until you opt out or request deletion
7. Your Rights
You have the following rights regarding your information:
- Access: Request copies of your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Request transfer of your data
- Opt-out: Unsubscribe from marketing communications
- Restriction: Request limitation of processing
8. International Data Transfers
If you are located outside the United States, please note that we may transfer your information to the US where our servers are located. We ensure appropriate safeguards are in place for such transfers.
9. Children's Privacy
Our services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or through our platform. Your continued use of our services after such changes constitutes acceptance of the updated policy.
11. Contact Information
Privacy Officer
For questions about this Privacy Policy or to exercise your rights:
Email: privacy@seraphcare.com
Address: SeraphCare Privacy Officer
[Address to be updated]
Data Protection Officer (EU)
For European users:
Email: dpo@seraphcare.com
Healthcare Providers: If you are a healthcare organization, please contact us to discuss Business Associate Agreements and additional privacy protections specific to your use case.