Data & Privacy Policy

Effective Date: March 17, 2026  |  Last Updated: August 23, 2026  |  Version: 2026.08.23

This Data & Privacy Policy ("Policy") describes how Provider Plexus, Inc. ("Provider Plexus," "Company," "we," "us," or "our") collects, uses, discloses, stores, and protects information when you use our products, services, applications, and platforms (collectively, the "Services"). This includes the Provider Plexus web application, browser extension, mobile application, telehealth patient portal, audio streaming and transcription services, and all associated APIs.

We understand that the data you entrust to us includes sensitive health information. We take this responsibility seriously and are committed to protecting your privacy in compliance with the Health Insurance Portability and Accountability Act ("HIPAA"), applicable state privacy laws, and industry best practices.

1. Information We Collect

1.1 Information You Provide Directly

1.2 Information Collected Automatically

1.3 Information Collected Through the Mobile Application

When you use the Provider Plexus mobile application (iOS), the following additional information may be collected:

What the Mobile App Does Not Collect:

On-Device Security: All credentials and sensitive data stored locally on the device are encrypted using platform-provided secure storage (iOS Keychain). The app performs device integrity checks (jailbreak detection) locally; no device security data is transmitted to our servers. All API communication uses HTTPS with certificate pinning to prevent man-in-the-middle attacks.

1.4 Information from Third-Party Sources

2. How We Use Information

2.1 Providing and Operating the Services

2.2 Security and Compliance

2.3 Improvement and Analytics

2.4 Communications

2.5 Legal Compliance

2.6 Google Workspace API Data and Limited Use

Provider Plexus's use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Provider Plexus does not use Google Workspace API user data to create, train, or improve generalized or foundational artificial intelligence or machine learning models. We use this data only to provide or improve user-facing features requested by the user.

3. Protected Health Information (PHI)

3.1 HIPAA Compliance

When Provider Plexus processes PHI on behalf of a Covered Entity, we do so as a Business Associate under HIPAA. Our handling of PHI is governed by the applicable Business Associate Agreement (BAA) and the HIPAA Privacy, Security, and Breach Notification Rules.

3.2 Minimum Necessary Standard

We apply the HIPAA minimum necessary standard, accessing and processing only the minimum amount of PHI required to fulfill the specific purpose for which it was provided.

3.3 PHI Safeguards

PHI is subject to enhanced protections, including:

3.4 Breach Notification

In the event of a breach of unsecured PHI, Provider Plexus will notify the affected Covered Entity without unreasonable delay and no later than as required under HIPAA (currently 60 calendar days from discovery). We will cooperate with the Covered Entity in fulfilling its breach notification obligations to affected individuals and the U.S. Department of Health and Human Services (HHS).

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data

Provider Plexus does not sell, rent, or trade your personal information or PHI to third parties for marketing, advertising, or any other commercial purpose.

4.2 Service Providers and Subcontractors

We share data with third-party service providers who assist in delivering the Services, subject to appropriate contractual and security safeguards:

4.3 Legal Requirements

We may disclose information when we believe in good faith that disclosure is necessary to:

4.4 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of the transaction. We will notify you of any such change and any choices you may have regarding your information.

4.5 With Your Consent

We may share information with third parties when you have given us explicit consent to do so.

5. Data Retention

5.1 Retention Periods

We retain information for as long as necessary to fulfill the purposes described in this Policy, comply with our legal obligations, and enforce our agreements:

5.2 Deletion

When data is no longer needed, it is securely deleted or de-identified using industry-standard methods. In addition, when a customer organization's account is terminated, we destroy that organization's dedicated data-encryption key, which renders all of that organization's remaining encrypted data unrecoverable. This cryptographic key destruction operates at the level of a customer organization and is not available for the deletion of an individual person's records; individual deletion requests are fulfilled by secure deletion of the underlying records. Because encrypted backups are retained for disaster-recovery purposes, key destruction becomes fully effective once the applicable backup-retention period has elapsed. Records we are required by law to retain, including security and audit logs and records of disclosures retained for six (6) years under HIPAA, are preserved independently of this process before key destruction and are not affected by it.

6. Your Rights and Choices

6.1 Access and Portability

You have the right to request access to the personal information we hold about you. Where technically feasible, we will provide your data in a structured, commonly used, machine-readable format.

6.2 Correction

You have the right to request correction of inaccurate or incomplete personal information. For PHI, amendment requests will be handled in accordance with HIPAA requirements.

6.3 Deletion

You may request deletion of your personal information, subject to our legal obligations to retain certain data (e.g., medical records retention requirements, audit logs, and legal holds).

6.4 Restriction of Processing

You may request that we restrict certain processing of your personal information in specific circumstances as permitted by applicable law.

6.5 Opt-Out of Communications

You may opt out of non-essential communications by following the unsubscribe instructions in our emails or by contacting us. You cannot opt out of essential service-related communications (e.g., security alerts, account notifications).

6.6 HIPAA Rights

If your information constitutes PHI, you may have additional rights under HIPAA, including the right to:

To exercise these rights, please note that for PHI, requests should generally be directed to the healthcare provider (Covered Entity) who collected the information. The Covered Entity will coordinate with Provider Plexus as needed.

6.7 Exercising Your Rights

To exercise any of these rights, contact us at privacy@providerplexus.com. We will respond to verifiable requests within the timeframes required by applicable law (typically 30 days, with extensions available for complex requests).

7. Data Security

7.1 Technical Safeguards

7.2 Administrative Safeguards

7.3 Physical Safeguards

7.4 Reporting Security Incidents

If you discover a security vulnerability or suspect a breach, please report it immediately to security@providerplexus.com. We investigate all reported incidents promptly.

8. Cookies and Tracking Technologies

8.1 Cookies We Use

Our cookie usage differs by Service. The categories below describe every cookie set across our properties.

8.2 Your Cookie Choices

The first time you visit a web Service that would set a non-essential cookie, we show a banner offering two choices: Accept analytics cookies or Essential cookies only. No choice is required to use the Services, and until you accept we treat your visit as essential-only — that is the default, and it is also what applies if you dismiss the banner or never answer it.

Your choice is recorded in a first-party cookie named pp_cookie_consent. It stores only the choice you made, contains no identifier, and expires after one year. To change your choice, delete that cookie in your browser settings and reload the page; the banner is then shown again.

You can also control cookies through your browser settings. Disabling essential cookies will prevent you from using the Services. Disabling payment fraud-prevention cookies may cause Stripe to decline transactions. Declining or disabling analytics cookies will not affect core functionality.

8.3 Do Not Track

The Services do not currently respond to "Do Not Track" (DNT) browser signals due to the lack of an industry-wide standard for DNT implementation.

9. Children's Privacy

The Services are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13 except as part of the telehealth intake process when a parent or legal guardian provides information on behalf of a minor patient. If we learn that we have collected personal information from a child under 13 without parental consent outside of the healthcare context, we will delete that information promptly.

10. State-Specific Privacy Rights

10.1 California (CCPA/CPRA)

If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination. Note that PHI handled under HIPAA is exempt from the CCPA. To exercise your CCPA rights, contact privacy@providerplexus.com.

10.2 Other State Laws

Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others) may have additional rights regarding their personal information. We will honor applicable rights under your state's privacy law. Contact privacy@providerplexus.com to exercise your rights.

11. International Data Transfers

The Services are hosted in the United States. If you access the Services from outside the United States, your information may be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Services, you consent to such transfers. Where required by applicable law, we implement appropriate safeguards (such as Standard Contractual Clauses) for cross-border data transfers.

12. Third-Party Links and Services

The Services may contain links to third-party websites or integrate with third-party services. This Policy does not apply to information collected by third parties. We encourage you to review the privacy policies of any third-party services you interact with through the Services.

13. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we publish the updated Policy on the Services with a new effective date and a new version identifier, and we record what changed in the version history below. The Effective Date, Last Updated date, and Version shown at the top of this page identify the revision you are reading.

We do not send individual email notifications for routine changes to this Policy. The version history below is the record of what changed and when, and it is the mechanism by which we communicate changes. Where applicable law requires individual notice, or your consent, before a particular change takes effect — for example, a material change to how Protected Health Information is used or disclosed — we will provide that notice or obtain that consent before the change takes effect.

Your continued use of the Services after the effective date of any modification constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.

13.1 Version History

14. Contact Information

If you have questions, concerns, or requests regarding this Policy or our data practices, contact us:

If you believe your privacy rights have been violated, you also have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr.

15. Privacy Notice for Workforce Members

Sections 1 through 12 describe information we handle on behalf of customers, providers, and patients. This section describes the information we hold about Provider Plexus employees, contractors, and other workforce members (as that term is used in 45 CFR 160.103) because they work for or with us. It applies to you in addition to, not instead of, any notice you receive under your employment or contracting agreement.

15.1 Information We Hold About Workforce Members

15.2 How We Use It

Workforce information is used to administer your access, to operate and secure the Services, to meet HIPAA workforce training, sanction, and audit obligations, and to administer the employment or contracting relationship. We do not sell workforce information, we do not use it for advertising, and we do not use it to build profiles unrelated to your work. Where human resources, payroll, or benefits administration is carried out by a third-party provider, that provider's own privacy notice governs the records it holds.

15.3 Retention and Your Choices

Access and audit records are retained for the period required by the HIPAA Security Rule and our retention schedule. They are not deleted or amended on request, because their completeness is itself the control they exist to provide. Workforce members may ask what information we hold about them, ask us to correct inaccurate identity, role, or credentialing information, and raise a privacy concern, by emailing privacy@providerplexus.com. Raising a privacy concern will not result in retaliation.