This Privacy Policy describes how Calarity, Inc. (“Calarity,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes information about individuals who access or use the Calarity mobile application and related services (collectively, the “Services”).
We use reasonable administrative, technical, and physical safeguards designed to protect information.
We do not sell, disseminate, transfer, share, or otherwise disclose identifiable Personal Information or PHI for value. We may create and use De-identified Data (and/or aggregated data). We may share, license, and/or sell De-identified Data for lawful business purposes, including research, analytics, product development, and AI model training and improvement. You may opt out of certain uses of your information as described in the “Opt-Out of De-identified Data Use” section below.
2. Definitions
For purposes of this Privacy Policy:
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual.
“Health Information” means information about an individual’s health condition, health status, symptoms, treatment, diagnosis, or related healthcare information that is collected or generated through the Services.
“PHI” (Protected Health Information) means “protected health information” as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”) to the extent HIPAA applies to the relevant information and processing (for example, where Calarity is acting as a business associate to a covered entity under an applicable Business Associate Agreement).
“Private Information” means Personal Information, Health Information, and PHI (to the extent applicable).
“De-identified Data” means information that has been de-identified so that it does not identify you and cannot reasonably be used to identify you. Where HIPAA applies, De-identified Data means information that has been de-identified in accordance with the HIPAA “Safe Harbor” method by removing the identifiers required by HIPAA and where we do not have actual knowledge that the remaining information could be used to identify an individual.
3. Scope and Users
This Privacy Policy applies to all users of the Services, including individuals who use the Services in a personal capacity and healthcare professionals and their authorized staff who use the Services in connection with patient care. We refer to all such persons as “Users.”
4. Information We Collect
We collect Private Information in the following ways:
A. Information you provide
Examples may include: Account information (such as name, email address, phone number, login credentials); communications and content you submit through the Services (including recordings, transcripts, notes, messages, and other inputs, as applicable); and support requests and customer service communications.
B. Information collected automatically
Examples may include: Device and usage information (such as device identifiers, operating system, app version, log data, interactions, performance data); approximate location inferred from IP address; and cookies or similar technologies where applicable (for example, pixels in emails)
C. Information provided by others
Examples may include information a healthcare professional enters about a patient, or information provided by an organization that enables access to the Services.
5. How We Use Information
We use Private Information to: Provide, maintain, and improve the Services; create transcripts, summaries, documentation, and other outputs as part of the Services; communicate with you about the Services; provide customer support; conduct security, fraud prevention, and integrity monitoring; and comply with legal obligations and enforce our agreements
6. De-identified Data; Research; AI Training; Commercialization
A. Creating De-identified Data
We may create De-identified Data and/or aggregated data from Private Information.
B. How we may use, share, and commercialize De-identified Data
We may use, disclose, share, transfer, license, and/or sell De-identified Data for lawful business purposes, including: research and publications (in aggregated or summarized form); analytics and benchmarking; product development and improvement; training and improving our AI models and features (including transcription, note generation, and service enhancements); and promoting and marketing our business (for example, through statistics, insights, or performance claims derived from De-identified Data).
C. No sale or disclosure of identifiable Personal Information or PHI for value
We do not sell, disseminate, transfer, share, or otherwise disclose identifiable Personal Information or PHI for value.
D. De-identification safeguards
We maintain measures designed to help keep De-identified Data de-identified, including limiting access, applying technical controls, and using contractual restrictions where appropriate. We do not attempt to re-identify De-identified Data except as permitted by law (for example, to test the effectiveness of de-identification).
7. How We Disclose Information (Other than De-identified Data)
We may disclose Private Information as follows:
A. Service Providers
We may disclose Private Information to vendors, consultants, and other service providers that help us provide the Services and operate our business, including database hosting and maintenance, telecommunications, information security, fraud detection and prevention, email management, data analytics, marketing, advertising, user support, and identity verification.
B. Research institutions (De-identified Data)
We may disclose De-identified Data to research institutions and other partners for research consistent with this Privacy Policy.
C. Business transfers
We may disclose Private Information in connection with a business transaction (or potential transaction) involving a merger, acquisition, financing, reorganization, bankruptcy, receivership, dissolution, sale of assets, or similar event.
D. Legal and safety
We may access, preserve, and disclose Private Information if we believe it is reasonably necessary to comply with law or legal process, protect the rights, safety, and property of Calarity or others, or prevent fraud or security issues.
E. With your consent
We may disclose Private Information in a manner not described in this Privacy Policy if you consent.
8. HIPAA and Healthcare Use (When Applicable)
When Calarity receives, creates, maintains, or transmits PHI on behalf of a covered entity and HIPAA applies, Calarity will handle that PHI in accordance with HIPAA and any applicable Business Associate Agreement. If there is a conflict between this Privacy Policy and an applicable Business Associate Agreement with respect to PHI, the Business Associate Agreement will control.
9. Opt-Out of De-identified Data Use
A. What you can opt out of
You may opt out of: use of your information to create De-identified Data for AI model training and improvement; and use of your information to create De-identified Data that is shared, licensed, or sold for external research, analytics, or other commercial purposes.
B. What opt-out does not affect
Your opt-out will not affect: our ability to provide the Services (including generating transcripts, notes, summaries, and other features you request); our ability to use Private Information for security, fraud prevention, troubleshooting, quality assurance, and system integrity; our ability to comply with law, respond to lawful requests, and enforce our agreements; retention of information as required or permitted by law or contract (including retention obligations related to HIPAA or applicable Business Associate Agreements); and use of information that has already been de-identified prior to your optout (to the extent permitted by law).
C. How to opt out
You may opt out in either of the following ways: In-app control: Use the privacy controls within the app settings to toggle off De-identified Data use for (i) AI training and (ii) external research/commercialization; or email request to privacy@calarity.com with the subject line “Deidentified Data Opt-Out” and include the email address and phone number associated with your account.
We will use commercially reasonable efforts to apply your opt-out within 30 days. If you opt out, certain features may improve more slowly over time, but your core access to the Services will not be restricted solely because you opted out.
10. Data Retention
We retain Private Information for the period reasonably necessary to provide the Services and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Where HIPAA applies, we retain PHI as required by applicable agreements and law. We may retain De-identified Data and/or aggregated data for as long as permitted by law.
11. Security
We employ administrative, technical, and physical safeguards designed to protect Private Information. However, no security measure can guarantee security, and data may be accessed, disclosed, altered, or destroyed despite our safeguards. In the event of a breach involving Private Information, we will notify affected individuals as required by applicable law.
12. Push Notifications
If you consent to receive push notifications, you may withdraw your consent at any time by adjusting the appropriate operating system settings on your mobile device.
13. Do Not Track
The Services may not respond to “Do Not Track” signals.
14. Changes to this Privacy Policy
We may modify this Privacy Policy from time to time. When we make changes, we will update the Effective Date and post the updated Privacy Policy through the Services. If required by law, we will provide additional notice.
15. Contact Us
If you have questions about this Privacy Policy or Calarity’s privacy practices, contact us at:
Email: privacy@calarity.com
Mailing Address:
Calarity
ATTN: Privacy Policy
73 White Bridge Road
Suite 103-207
Nashville, TN 37205