Legal
Privacy Policy
Effective Date: January 1, 2024 · Last Updated: July 1, 2026
This Privacy Policy describes how ReveliaDx, Inc. ("ReveliaDx," "we," "us," or "our") collects, uses, discloses, and retains information in connection with our electronic health record ("EHR") software-as-a-service platform, related applications, and the reveliadx.com website (collectively, the "Services").
This Policy applies to information we collect about:
- Visitors to reveliadx.com
- Users of our Services (physicians, practice staff, and other authorized users acting on behalf of a healthcare practice — "Customers")
- Individuals whose Protected Health Information ("PHI") is processed through the Services on behalf of our Customers
Important note on PHI: ReveliaDx acts as a Business Associate (as defined under HIPAA) to the healthcare practices that use our Services. PHI submitted to or generated within the Services is governed by the Business Associate Agreement ("BAA") between ReveliaDx and the applicable Customer, and by HIPAA itself — not by this Privacy Policy. This Privacy Policy addresses account-level, website, and platform data that ReveliaDx handles in its own right (e.g., account registration data, billing data, website analytics, support communications). Patients should direct questions about their medical records to their healthcare provider.
1. Information We Collect
1.1 Information You Provide Directly
- Account and registration data: name, work email, phone number, job title, practice/organization name, login credentials
- Billing information: billing address, payment method (processed by our third-party payment processor — we do not store full card numbers)
- Support communications: information you submit via email, chat, or support tickets
- Marketing preferences: information submitted through forms on reveliadx.com (e.g., demo requests, newsletter sign-ups)
1.2 Information Collected Automatically
- Usage data: pages visited, features used, timestamps, click patterns, session duration
- Device and log data: IP address, browser type, operating system, device identifiers, referring URLs
- Cookies and similar technologies: see Section 7 below
1.3 Information From Third Parties
- Google user data: if you connect a Google Workspace, Gmail, Calendar, or other Google account to the Services, we access only the specific data scopes you authorize (e.g., calendar availability, contact sync). See Section 4 for our Google-specific commitments.
- Identity and single sign-on providers: if you log in via a third-party identity provider
- Analytics and product tooling providers: aggregated or pseudonymized usage metrics
2. How We Use Information
We use the information described above to:
- Provide, operate, maintain, and improve the Services
- Authenticate users and secure accounts
- Process billing and payments
- Respond to support requests and communicate about the Services
- Send administrative notices (e.g., security alerts, policy updates)
- Monitor for fraud, abuse, and security incidents
- Comply with legal obligations
- With consent, send product updates or marketing communications (you may opt out at any time)
We do not use PHI processed through the Services for our own marketing, advertising, or unrelated commercial purposes. Use of PHI is governed exclusively by the applicable BAA and HIPAA's minimum-necessary and permitted-use standards.
3. With Whom We Share, Transfer, or Disclose Data
We share information only as described below. We do not sell personal information.
| Category of Recipient | Purpose | Examples |
|---|---|---|
| Cloud hosting and infrastructure providers | Hosting, storage, backup, and compute | e.g., AWS, Azure, or equivalent (with a BAA in place for any PHI-adjacent environments) |
| Subprocessors and service providers | Payment processing, customer support tooling, email delivery, analytics | Each is bound by contract to use data only to provide services to us and to maintain appropriate safeguards |
| Google APIs / integrated third-party platforms | To enable features you affirmatively connect (e.g., calendar sync) | Limited to the scopes you authorize; see Section 4 |
| Professional advisors | Legal, accounting, and compliance support | Under confidentiality obligations |
| Business transfers | In connection with a merger, acquisition, financing, or sale of assets | Recipient will be bound by materially equivalent privacy commitments |
| Legal and safety | To comply with law, subpoena, or legal process; to protect rights, safety, or property; to investigate fraud or security incidents | Disclosed only to the extent required or permitted |
| With your direction | When you affirmatively request or consent to a disclosure | e.g., integration you set up |
We require all third parties who process personal data on our behalf to sign data processing agreements (and BAAs, where PHI is involved) that restrict use to the purposes we specify and require appropriate security measures.
4. Google User Data — Limited Use Disclosure
If the Services access data via Google APIs (e.g., Google Workspace, Gmail, Calendar, Drive), ReveliaDx's use and transfer of that information adheres to the Google API Services User Data Policy, including the Limited Use requirements:
- We use Google user data only to provide or improve the specific user-facing feature you have authorized.
- We do not use Google user data for serving advertisements.
- Google Calendar data obtained through Google APIs is not used to develop, train, or improve generalized artificial intelligence or machine learning models and is not transferred to third-party AI/ML providers for such purposes.
- We do not allow humans to read Google user data unless: (a) we have your affirmative agreement for specific messages, (b) it is necessary for security purposes, (c) it is necessary to comply with law, or (d) our use is limited to internal operations and the data has been aggregated/anonymized.
- We do not transfer Google user data to third parties except as necessary to provide or improve the authorized feature, to comply with law, as part of a merger or acquisition (subject to continued adherence to this policy), or with your explicit consent.
- You may revoke ReveliaDx's access to your Google account data at any time via your Google Account security settings.
5. Data Retention and Deletion
5.1 Account and Platform Data
We retain account, billing, and usage data for as long as your account is active, and for one year (365 days) after account closure, to allow for reactivation and to resolve any outstanding billing or legal matters. After this period, we delete or anonymize the data unless a longer retention period is required by law.
5.2 Protected Health Information
PHI is retained in accordance with:
- The retention terms specified in the applicable Customer BAA,
- Applicable state medical records retention laws (which vary by state and can range from 6–10 years, or longer for minors), and
- HIPAA, which generally requires certain related records (e.g., authorizations, BAAs) to be retained for a minimum of six years from creation or last effective date.
Upon termination of a Customer's agreement, ReveliaDx will, per the BAA, return or securely destroy PHI within one year, unless the Customer instructs otherwise or law requires continued retention, in which case PHI will be retained under the same protections until destruction is permitted.
5.3 Deletion Requests
You may request deletion of your account data by contacting [email protected]. We will delete or anonymize data within 30 days, except where retention is required for legal, security, tax, or accounting purposes, or where data is embedded in encrypted backups that will age out on their normal deletion cycle.
5.4 Deletion of Google User Data
Where Google user data is involved, we delete such data upon your request or upon revocation of authorization, except where retention is required to comply with law.
6. Data Security
We maintain administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, access controls and audit logging, employee training, and — for PHI — safeguards consistent with the HIPAA Security Rule. No system is completely secure, and we cannot guarantee absolute security.
7. Cookies and Tracking Technologies
reveliadx.com uses cookies and similar technologies to operate the site, remember preferences, and measure site performance. You can control cookies through your browser settings. We do not use cookies within the authenticated application to serve third-party advertising.
8. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, or restrict use of your personal information, or to opt out of certain processing (e.g., under the California Consumer Privacy Act/CPRA or other applicable state privacy laws). To exercise these rights, contact [INSERT PRIVACY EMAIL]. We will verify your request and respond within the timeframe required by applicable law.
If you are a patient and your question relates to your medical records, please contact your healthcare provider directly — as a Business Associate, ReveliaDx directs patient record requests to the Covered Entity.
9. Children's Privacy
The Services are intended for use by healthcare providers and their staff, not by children. We do not knowingly collect personal information directly from children through reveliadx.com.
10. International Data
The Services are hosted in the United States and intended for use by U.S.-based healthcare practices. If you access the Services from outside the U.S., your information will be transferred to and processed in the United States.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last Updated" date and, for material changes, provide additional notice (e.g., email or in-app notification).