Privacy Policy
Effective Date: January 1, 2025 · Last Updated: June 2025
1. Information We Collect and How We Use It
By accessing or using SHEALTH.AI, you agree that SHEALTH.AI may collect, process, store, and use information — including healthcare, imaging, clinical, and operational data — solely for providing, maintaining, securing, improving, and supporting its services.
The types of information we may collect include:
- Account credentials and administrator-assigned roles
- Medical imaging files (DICOM) uploaded to the platform
- Clinical notes, radiology reports, and workflow metadata
- Audit trail data including user actions and timestamps
- Device identifiers, browser type, and usage telemetry for security monitoring
We do not sell your data to third parties. Information is used exclusively to operate the platform and fulfil our contractual obligations to your organization.
2. Data Ownership and Customer Rights
Customer organizations retain full ownership of their data. SHEALTH.AI serves as a data processor on your behalf. You may request export or deletion of your organization's data at any time by contacting your assigned account representative or submitting a written request to our data privacy team.
SHEALTH.AI retains ownership of its software, algorithms, AI models, user-interface designs, and all other intellectual property embedded in the platform. No rights to the platform itself are transferred to customers.
3. De-identified and Aggregated Data
SHEALTH.AI may use de-identified, anonymized, or aggregated data — in compliance with applicable laws (including HIPAA Safe Harbor and Expert Determination standards) and contractual obligations — for product enhancement, research, analytics, validation, and AI model development. Such use does not identify individual patients, and re-identification is strictly prohibited by our internal policies.
4. Your Responsibilities as a User
Users are responsible for ensuring that they have all necessary rights, consents, and authorizations before submitting data to the platform. This includes obtaining appropriate patient authorizations where required under HIPAA, GDPR, or other applicable healthcare privacy laws in your jurisdiction.
You must comply with all applicable healthcare, privacy, and data protection laws when using SHEALTH.AI. If your organization operates under a Business Associate Agreement (BAA) with SHEALTH.AI, the terms of that agreement govern the use and disclosure of Protected Health Information (PHI).
5. Security Measures
SHEALTH.AI implements reasonable and industry-standard security measures to protect the information on our platform, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access controls and principle of least privilege
- Comprehensive audit logging of all data access and modifications
- Regular security assessments and vulnerability scanning
- Multi-factor authentication support for all user accounts
While we take every reasonable precaution, no system can guarantee absolute security. In the event of a data breach that triggers notification obligations, SHEALTH.AI will notify affected customer organizations in accordance with applicable law.
6. Cookies and Tracking
SHEALTH.AI uses session cookies and secure tokens solely for authentication and security purposes. We do not use third-party advertising cookies or behavioral tracking pixels on any part of the clinical platform. Minimal analytics may be collected to monitor platform performance and reliability.
7. Changes to This Policy
SHEALTH.AI may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will provide notice of material changes through the platform or via email to the organization's designated contact. Continued use of the platform after such notice constitutes acceptance of the updated policy.
Questions or Requests?
For privacy-related inquiries, data subject requests, or BAA concerns, contact your SHEALTH.AI account representative or email privacy@shealth.ai.