Cardio AI
Cardio AI · Heart Matters
MedCRM Healthcare Suite

Privacy Statement

Effective date: 8 July 2026 · Last updated: 8 July 2026 · Version 1.0

1. Scope & who we are

MedCRM (the "Platform") is a healthcare customer-relationship-management application operated by Cardio AI ("Cardio AI," "we," "us") and offered under the Cardio AI brand. This Privacy Statement explains how we handle information when a healthcare organization ("Customer") and its authorized users access the Platform.

For most health information processed in the Platform, the Customer is the data controller / HIPAA covered entity and Cardio AI acts as a data processor / business associate that processes such data only under the Customer's instructions and any executed Business Associate Agreement ("BAA").

2. Information we collect

Account & organization data

Names, work email addresses, roles, organization name and email domain, and authentication data (passwords are stored only as salted Argon2 hashes; we never store them in plaintext).

Health & operational data entered by users

Patient records, appointments, care-management enrollments and activities, care gaps, telehealth session metadata, messages, quality measures, and related clinical/operational content the Customer chooses to store.

Usage & device data

Log data such as IP address, timestamps, actions taken (audit logs), browser type, and security events used to operate, secure, and troubleshoot the Platform.

Billing data

Subscription tier and status. Card payments are processed by our payment provider (Stripe); we do not store full card numbers.

3. Protected Health Information (PHI)

When the Platform is used with real PHI under a signed BAA, we process PHI solely to provide the contracted services, safeguard it with administrative, physical, and technical measures, and do not sell it or use it for advertising. Until a BAA and compliance review are complete, the Platform must be used only with test or de-identified data.

4. How we use information

We do not sell personal information or PHI, and we do not use PHI for targeted advertising.

Where applicable law (such as the GDPR) requires a legal basis, we rely on: performance of our contract with the Customer; compliance with legal obligations; our legitimate interests in securing and improving the Platform; and, where required, consent. For PHI, processing is governed by HIPAA and the applicable BAA.

6. Sharing & disclosure

RecipientPurpose
Subprocessors (hosting, database, email, payments, video)Operate the Platform under contract and, where relevant, a BAA.
The Customer's own authorized usersAccess governed by the Customer's role and approval settings.
Legal / regulatory authoritiesWhen required by law or to protect rights, safety, and security.
Successor entityIn a merger, acquisition, or asset transfer, subject to this Statement.

7. Third-party integrations

The Platform can connect, at the Customer's configuration, to external systems including FHIR servers, HL7 gateways, and DICOM/PACS imaging systems, as well as payment (Stripe) and telehealth video (Jitsi/WebRTC) services. When enabled, data is exchanged with those systems under the Customer's direction and the third party's own terms. Public telehealth video servers are not HIPAA-compliant and must be replaced with a self-hosted or BAA-covered deployment before use with PHI.

8. Data security

We apply layered safeguards including encrypted transport (TLS), hashed credentials, role-based and permission-based access control, account-approval workflows, session expiration, and audit logging. No method of transmission or storage is perfectly secure; we work to protect information but cannot guarantee absolute security.

9. Data retention

We retain data for as long as the Customer's account is active or as needed to provide the Platform, then delete or de-identify it in accordance with the Customer's instructions, the BAA, and applicable law. Customers may request export or deletion of their data as described in their agreement.

10. Your privacy rights

Depending on your jurisdiction (e.g., GDPR, UK GDPR, CCPA/CPRA and other US state laws), individuals may have rights to access, correct, delete, restrict, or port personal information, and to object to certain processing. Because the Customer controls most data in the Platform, please direct requests to your organization; we assist Customers in fulfilling verified requests as required by law and the BAA.

11. Cookies & analytics

The Platform uses strictly necessary cookies and local storage to keep you signed in and maintain your session. It does not use third-party advertising cookies. Any product analytics are limited to operating and improving the service.

12. Children's privacy

The Platform is intended for use by healthcare organizations and their staff, not by children, and is not directed to individuals under 16. Pediatric patient records entered by a Customer are handled as PHI under the applicable agreement.

13. International transfers

If information is processed in a country other than where it was collected, we use appropriate safeguards (such as standard contractual clauses) where required by law.

14. Changes to this Statement

We may update this Statement to reflect changes to the Platform or the law. Material changes will be communicated through the Platform or to the Customer's administrator, and the "Last updated" date above will change.

15. Contact us

Cardio AI — Privacy & Support
Email: support@cardioailive.com
Product: MedCRM Healthcare Suite (Cardio AI)
For data-subject or HIPAA requests about records in your organization's account, contact your organization's administrator or Privacy Officer.