Who this policy covers
It covers our website, the dashboard, and the assistant wherever it is embedded. On a branded assistant, the business is the one in charge of the data and we act on its instructions.
This policy explains how [registered company name and number] ("Vertex Health", "we", "us") handles personal information across the Vertex Health website, the business dashboard, and the embeddable health assistant (the "Assistant").
- Free tier — the Assistant embedded with no business identifier, including on our own site. We decide why and how the information is processed, so we are the controller for it.
- Branded tier — the Assistant embedded by a business with its identifier. That business decides why and how patient information is processed and is the controller; we act as its processor, and as its business associate where HIPAA applies. The business's own privacy notice governs, alongside this one.
- Business accounts — the account and organization data of the people who sign in to the dashboard. We are the controller for that.
Where we act as a processor or business associate, we handle information only on the business's documented instructions, and a data processing agreement or business associate agreement with that business takes precedence over this policy to the extent of any conflict.
What we collect
What you type into the assessment, a small amount of technical data needed to keep the service up, and — only if you offer it — contact details.
From patients using the Assistant:
- Health information you enter — the symptoms you describe or select, your answers to the assistant's questions, the structured clinical signals derived from them, and the outcome the session reached. This is sensitive information, and in some places it is legally special-category data or protected health information.
- Contact details, but only if you choose to leave them after an escalation: name, email, phone and a free-text note. This is always optional and the assessment works without it.
- Session metadata — the language of the session, the address of the page the assistant was embedded on, the business identifier, timestamps, which rule set and model version produced the outcome.
- Technical and security data — your IP address, used to apply rate limits and to run the bot check, and standard request data such as user agent and time of request.
From business users of the dashboard: name, email address, authentication data and organization membership (handled by our authentication provider), the branding and contact details you configure, notification settings, and usage counts for billing.
We do not run analytics, advertising, session-replay or fingerprinting tools inside the Assistant, and we do not receive information about your browsing on the site that embeds it.
Please tell the assistant only what it needs to assess your symptoms. It does not need your full name, an identity or insurance number, payment details, an address, or a document, and you should not enter them.
How we use it
To run your assessment, to keep the service safe and available, to bill businesses, and to comply with the law. Nothing else.
- To run the assessment: to choose the next question, to apply the deterministic red-flag rules, to produce an outcome, and to show the right escalation contacts.
- To pass your details to the business you asked to be contacted by, when you volunteer them after an escalation.
- To alert a business's staff that a session escalated. Those alerts carry a timestamp and a link into the dashboard, never the content of the conversation.
- To keep the service secure and available: rate limiting, bot verification, spend caps, abuse investigation and incident response.
- To keep the audit trail that records every access to health information.
- To count completed assessments for billing on the white-label plan.
- To meet legal obligations and to establish, exercise or defend legal claims.
We do not use the content of patient conversations to train AI models, we do not sell personal information, we do not share it for advertising or cross-context behavioural advertising, and we do not use it to profile you or to make automated decisions with legal or similarly significant effects. The Assistant's outcome is guidance for you to act on, not a decision made about you.
Legal bases (GDPR and equivalents)
For health data we rely on your explicit consent, which you can withdraw. For security and billing we rely on legitimate interests and contract.
- Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) for the health information you enter into the Assistant. You give it by accepting the notice before the assessment starts, and you can withdraw it at any time — see section 10. Withdrawal does not affect processing that already happened.
- Performance of a contract (Art. 6(1)(b)) for operating a business account, providing the dashboard, and billing.
- Legitimate interests (Art. 6(1)(f)) for keeping the service secure, preventing abuse and controlling cost, and for aggregated, de-identified analysis of how the service performs. We balance those interests against your rights, and use the least identifying data that works.
- Legal obligation (Art. 6(1)(c)) where we must keep records or respond to lawful requests.
- Establishment, exercise or defence of legal claims (Art. 9(2)(f)) where health data is involved in a dispute.
Where a business embeds the branded Assistant, that business is responsible for the legal basis for processing its patients' data and for any consent its jurisdiction requires.
HIPAA and US health privacy
For US businesses we intend to act as a business associate under a signed agreement. Until those agreements are signed, the service is not for real patient traffic.
Where a US covered entity embeds the branded Assistant, information about its patients is protected health information, that business is the covered entity, and we act as its business associate under a business associate agreement. We use and disclose protected health information only as that agreement and HIPAA permit, apply administrative, physical and technical safeguards, and report security incidents and breaches as required.
As of 2026-08-27, the business associate agreements with our infrastructure and AI vendors are not yet signed, and Vertex Health is in development. The Service must not be used with real patient traffic until they are in place.
On the free tier there is no covered entity and no business associate relationship. HIPAA generally does not apply to information an individual chooses to enter for themselves, but we treat it with the same technical protections described in section 8 regardless.
Service providers and AI processing
A short list of vendors runs the service. Conversation text is sent to our AI provider to generate replies, under a no-training, no-retention arrangement.
The providers we rely on:
- Vercel — application hosting and delivery
- OpenAI — generation of assistant replies and question selection
- Clerk — authentication and organization management for business accounts
- Our managed Postgres host — encrypted storage of session records
- Cloudflare — Turnstile bot verification before a patient's first message
To produce a reply and choose the next question, the text of the conversation is sent to our AI provider. We contract for zero data retention and for your content not to be used to train models. We do not send the provider your name, contact details or business identifiers, and we instruct patients not to include identifying details in the first place.
The deterministic red-flag rules run on our own infrastructure and are not delegated to the model, so an emergency outcome does not depend on a third party.
We keep this list current and will publish changes here. Business Customers with a data processing agreement receive advance notice of new subprocessors as that agreement provides. Contact privacy@getvertexhealth.com to be told about changes.
How we protect it
Encrypted at rest, scoped to one business on every query, audited on every read, and kept out of logs and third-party tools. No system is perfectly secure.
- Health information and volunteered contact details are encrypted at rest with AES-256-GCM. Keys are held separately from the database.
- Every query is scoped to a single business, so one tenant's sessions cannot be reached from another's.
- Every read of health information from the dashboard writes an append-only audit log entry identifying who read what and when.
- Health information stays behind one storage boundary. It is never sent to analytics, client-side logging, error reporting or any third-party SDK, and is never written to application logs.
- The Assistant runs inside an isolated iframe, so the page embedding it cannot read the conversation.
- Widget sessions are protected by short-lived signed tokens, per-IP and per-origin rate limits, and a bot check before the first message.
- Dashboard access requires authentication and is restricted to members of the business's organization.
No method of transmission or storage is completely secure. While we work to protect your information with appropriate technical and organizational measures, we cannot guarantee absolute security, and you share information with us on that understanding. If a breach affects you, we will notify you and the relevant authority where the law requires it.
How long we keep it
Sessions carry a 30-day deletion deadline. Audit logs and billing records are kept longer because the law requires it.
- Triage sessions, transcripts, clinical signals and volunteered contact details: deleted after 30 days. Each session record carries its own deletion deadline, and a scheduled purge removes rows past it.
- Audit log entries: kept for as long as required by the health privacy laws that apply to the business, which under HIPAA is at least six years.
- Business account and billing records: for the life of the account and then as long as tax and accounting law requires.
- Aggregate counters (daily token spend, monthly completed assessments): retained without any link to a session or an individual.
- Rate limit counters: minutes to hours, and then discarded.
We may keep information longer where we must to comply with a legal obligation, or to establish, exercise or defend a legal claim. When a business closes its account, its sessions are deleted along with it.
Your rights
Access, correction, deletion, portability, objection, and withdrawal of consent. Anonymous sessions are hard to find, so tell us what you can to help us locate yours.
Depending on where you live, you have some or all of the following rights: to access the personal information we hold about you; to have it corrected; to have it deleted; to restrict or object to processing; to receive it in a portable format; to withdraw consent at any time; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any of them, email privacy@getvertexhealth.com. We respond within the time the applicable law allows — under the GDPR, one month, extendable where a request is complex.
Patients use the Assistant anonymously and we do not create accounts for them. If you left no contact details, we may genuinely be unable to work out which session was yours, and we may have to ask for details — such as the approximate time and the site you used it on — to locate it. If we still cannot identify you, we may be unable to act on the request, and we will tell you so.
Where a branded assistant is involved, the business is the controller and requests are usually best sent to it. Send yours to us anyway if you prefer; we will pass it on and support the business in responding.
We will not discriminate against you for exercising a privacy right. In the EEA or the UK you may also complain to your supervisory authority, and elsewhere to your local regulator, though we would appreciate the chance to address it first.
US state privacy rights
California and other state residents have rights to know, delete, correct and limit use of sensitive information. We do not sell or share personal information.
If you are a resident of California, Colorado, Connecticut, Virginia, Texas or another US state with a comprehensive privacy law, you have the rights described in section 10, plus the right to know the categories of personal information collected, the sources, the purposes, and the categories of recipients, and the right to limit the use and disclosure of sensitive personal information.
Health information you enter into the Assistant is sensitive personal information. We use it only to provide the assessment you asked for and for the purposes listed in section 3, which are the purposes permitted without a separate right to limit. We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we do not knowingly collect personal information from anyone under 16.
You may use an authorized agent to make a request; we may ask for proof of authority. Contact privacy@getvertexhealth.com to exercise a right or to appeal a decision, where the law gives you a right of appeal.
International transfers
Data may be processed outside your country, under standard contractual clauses or another approved safeguard.
We and our providers operate internationally, so your information may be processed in a country other than your own, including the United States. Where information moves out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on the European Commission's standard contractual clauses, the UK international data transfer addendum, or another lawful transfer mechanism, together with the technical measures in section 8.
You can request a copy of the relevant safeguards from privacy@getvertexhealth.com.
Children
The assistant is for adults. A parent or guardian may use it for a child and is responsible for what they enter.
The Service is not directed to children and children must not use it on their own. A parent or legal guardian may use it in relation to a child in their care, and is responsible for the information they enter. We do not knowingly collect personal information directly from a child. If you believe a child has used the Assistant unsupervised, contact us and we will delete the session.
Changes to this policy
We will update this page and change the effective date. Material changes are announced.
We may update this policy as the Service changes. The version and effective date at the top of the page always reflect the current text, and material changes will be announced on the website and, for Business Customers, by email or in the dashboard before they take effect.
Contact us
Privacy questions and requests go to privacy@getvertexhealth.com.
[registered company name and number], [registered address]. Privacy contact: privacy@getvertexhealth.com.
Our representative in the European Union under Article 27 GDPR is [EU representative]. Our United Kingdom representative is [UK representative].
Version 1.0, effective 27 August 2026.