This document is published in English only, and the English text is the version that applies.

Privacy/Version 1.0

Privacy Policy

What the assistant collects, where it goes, how long it stays, and what you can ask us to do about it.

Effective
27 August 2026
Sections
16
Reading time
About 14 minutes

The short version

  • Symptom information is treated as health data: encrypted at rest, scoped to one business, and logged on every read.
  • It never goes to an analytics tool, an advertising network or a client-side error reporter.
  • We never sell personal information and never share it for advertising.
  • Sessions are deleted on a fixed retention clock, and you can ask us to delete yours sooner.
  • You choose what to type. Please do not include your name, ID numbers or documents — the assessment does not need them.

This summary is here to help you read the document. It is not part of the agreement, and the numbered sections below are what applies.

1

Who this policy covers

It covers our website, the dashboard, and the assistant wherever it is embedded. On a branded assistant, the business is the one in charge of the data and we act on its instructions.

This policy explains how [registered company name and number] ("Vertex Health", "we", "us") handles personal information across the Vertex Health website, the business dashboard, and the embeddable health assistant (the "Assistant").

  • Free tier — the Assistant embedded with no business identifier, including on our own site. We decide why and how the information is processed, so we are the controller for it.
  • Branded tier — the Assistant embedded by a business with its identifier. That business decides why and how patient information is processed and is the controller; we act as its processor, and as its business associate where HIPAA applies. The business's own privacy notice governs, alongside this one.
  • Business accounts — the account and organization data of the people who sign in to the dashboard. We are the controller for that.

Where we act as a processor or business associate, we handle information only on the business's documented instructions, and a data processing agreement or business associate agreement with that business takes precedence over this policy to the extent of any conflict.

2

What we collect

What you type into the assessment, a small amount of technical data needed to keep the service up, and — only if you offer it — contact details.

From patients using the Assistant:

  • Health information you enter — the symptoms you describe or select, your answers to the assistant's questions, the structured clinical signals derived from them, and the outcome the session reached. This is sensitive information, and in some places it is legally special-category data or protected health information.
  • Contact details, but only if you choose to leave them after an escalation: name, email, phone and a free-text note. This is always optional and the assessment works without it.
  • Session metadata — the language of the session, the address of the page the assistant was embedded on, the business identifier, timestamps, which rule set and model version produced the outcome.
  • Technical and security data — your IP address, used to apply rate limits and to run the bot check, and standard request data such as user agent and time of request.

From business users of the dashboard: name, email address, authentication data and organization membership (handled by our authentication provider), the branding and contact details you configure, notification settings, and usage counts for billing.

We do not run analytics, advertising, session-replay or fingerprinting tools inside the Assistant, and we do not receive information about your browsing on the site that embeds it.

Please tell the assistant only what it needs to assess your symptoms. It does not need your full name, an identity or insurance number, payment details, an address, or a document, and you should not enter them.

3

How we use it

To run your assessment, to keep the service safe and available, to bill businesses, and to comply with the law. Nothing else.

  • To run the assessment: to choose the next question, to apply the deterministic red-flag rules, to produce an outcome, and to show the right escalation contacts.
  • To pass your details to the business you asked to be contacted by, when you volunteer them after an escalation.
  • To alert a business's staff that a session escalated. Those alerts carry a timestamp and a link into the dashboard, never the content of the conversation.
  • To keep the service secure and available: rate limiting, bot verification, spend caps, abuse investigation and incident response.
  • To keep the audit trail that records every access to health information.
  • To count completed assessments for billing on the white-label plan.
  • To meet legal obligations and to establish, exercise or defend legal claims.

We do not use the content of patient conversations to train AI models, we do not sell personal information, we do not share it for advertising or cross-context behavioural advertising, and we do not use it to profile you or to make automated decisions with legal or similarly significant effects. The Assistant's outcome is guidance for you to act on, not a decision made about you.

5

HIPAA and US health privacy

For US businesses we intend to act as a business associate under a signed agreement. Until those agreements are signed, the service is not for real patient traffic.

Where a US covered entity embeds the branded Assistant, information about its patients is protected health information, that business is the covered entity, and we act as its business associate under a business associate agreement. We use and disclose protected health information only as that agreement and HIPAA permit, apply administrative, physical and technical safeguards, and report security incidents and breaches as required.

As of 2026-08-27, the business associate agreements with our infrastructure and AI vendors are not yet signed, and Vertex Health is in development. The Service must not be used with real patient traffic until they are in place.

On the free tier there is no covered entity and no business associate relationship. HIPAA generally does not apply to information an individual chooses to enter for themselves, but we treat it with the same technical protections described in section 8 regardless.

6

Who we share it with

The business you were escalated to, a short list of vendors that run the service, and nobody else unless the law requires it.

  • The business whose assistant you used. Its authorized staff can open the session transcript in their dashboard, and every one of those reads is written to an audit log. On the free tier there is no business, so there is nobody to route to.
  • Service providers who process data on our behalf under contract, listed in section 7.
  • Professional advisers, insurers and auditors, where necessary and under confidentiality.
  • Authorities or other parties where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims, or to prevent an imminent threat to someone's life or safety.
  • An acquirer, in a merger, acquisition, financing or sale of assets. We will require it to honour this policy or give you notice of a change.

WE DO NOT SELL PERSONAL INFORMATION, AND WE DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING. WE HAVE NOT DONE SO IN THE PRECEDING TWELVE MONTHS.

7

Service providers and AI processing

A short list of vendors runs the service. Conversation text is sent to our AI provider to generate replies, under a no-training, no-retention arrangement.

The providers we rely on:

  • Vercel — application hosting and delivery
  • OpenAI — generation of assistant replies and question selection
  • Clerk — authentication and organization management for business accounts
  • Our managed Postgres host — encrypted storage of session records
  • Cloudflare — Turnstile bot verification before a patient's first message

To produce a reply and choose the next question, the text of the conversation is sent to our AI provider. We contract for zero data retention and for your content not to be used to train models. We do not send the provider your name, contact details or business identifiers, and we instruct patients not to include identifying details in the first place.

The deterministic red-flag rules run on our own infrastructure and are not delegated to the model, so an emergency outcome does not depend on a third party.

We keep this list current and will publish changes here. Business Customers with a data processing agreement receive advance notice of new subprocessors as that agreement provides. Contact privacy@getvertexhealth.com to be told about changes.

8

How we protect it

Encrypted at rest, scoped to one business on every query, audited on every read, and kept out of logs and third-party tools. No system is perfectly secure.

  • Health information and volunteered contact details are encrypted at rest with AES-256-GCM. Keys are held separately from the database.
  • Every query is scoped to a single business, so one tenant's sessions cannot be reached from another's.
  • Every read of health information from the dashboard writes an append-only audit log entry identifying who read what and when.
  • Health information stays behind one storage boundary. It is never sent to analytics, client-side logging, error reporting or any third-party SDK, and is never written to application logs.
  • The Assistant runs inside an isolated iframe, so the page embedding it cannot read the conversation.
  • Widget sessions are protected by short-lived signed tokens, per-IP and per-origin rate limits, and a bot check before the first message.
  • Dashboard access requires authentication and is restricted to members of the business's organization.

No method of transmission or storage is completely secure. While we work to protect your information with appropriate technical and organizational measures, we cannot guarantee absolute security, and you share information with us on that understanding. If a breach affects you, we will notify you and the relevant authority where the law requires it.

9

How long we keep it

Sessions carry a 30-day deletion deadline. Audit logs and billing records are kept longer because the law requires it.

  • Triage sessions, transcripts, clinical signals and volunteered contact details: deleted after 30 days. Each session record carries its own deletion deadline, and a scheduled purge removes rows past it.
  • Audit log entries: kept for as long as required by the health privacy laws that apply to the business, which under HIPAA is at least six years.
  • Business account and billing records: for the life of the account and then as long as tax and accounting law requires.
  • Aggregate counters (daily token spend, monthly completed assessments): retained without any link to a session or an individual.
  • Rate limit counters: minutes to hours, and then discarded.

We may keep information longer where we must to comply with a legal obligation, or to establish, exercise or defend a legal claim. When a business closes its account, its sessions are deleted along with it.

10

Your rights

Access, correction, deletion, portability, objection, and withdrawal of consent. Anonymous sessions are hard to find, so tell us what you can to help us locate yours.

Depending on where you live, you have some or all of the following rights: to access the personal information we hold about you; to have it corrected; to have it deleted; to restrict or object to processing; to receive it in a portable format; to withdraw consent at any time; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

To exercise any of them, email privacy@getvertexhealth.com. We respond within the time the applicable law allows — under the GDPR, one month, extendable where a request is complex.

Patients use the Assistant anonymously and we do not create accounts for them. If you left no contact details, we may genuinely be unable to work out which session was yours, and we may have to ask for details — such as the approximate time and the site you used it on — to locate it. If we still cannot identify you, we may be unable to act on the request, and we will tell you so.

Where a branded assistant is involved, the business is the controller and requests are usually best sent to it. Send yours to us anyway if you prefer; we will pass it on and support the business in responding.

We will not discriminate against you for exercising a privacy right. In the EEA or the UK you may also complain to your supervisory authority, and elsewhere to your local regulator, though we would appreciate the chance to address it first.

11

US state privacy rights

California and other state residents have rights to know, delete, correct and limit use of sensitive information. We do not sell or share personal information.

If you are a resident of California, Colorado, Connecticut, Virginia, Texas or another US state with a comprehensive privacy law, you have the rights described in section 10, plus the right to know the categories of personal information collected, the sources, the purposes, and the categories of recipients, and the right to limit the use and disclosure of sensitive personal information.

Health information you enter into the Assistant is sensitive personal information. We use it only to provide the assessment you asked for and for the purposes listed in section 3, which are the purposes permitted without a separate right to limit. We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we do not knowingly collect personal information from anyone under 16.

You may use an authorized agent to make a request; we may ask for proof of authority. Contact privacy@getvertexhealth.com to exercise a right or to appeal a decision, where the law gives you a right of appeal.

12

International transfers

Data may be processed outside your country, under standard contractual clauses or another approved safeguard.

We and our providers operate internationally, so your information may be processed in a country other than your own, including the United States. Where information moves out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on the European Commission's standard contractual clauses, the UK international data transfer addendum, or another lawful transfer mechanism, together with the technical measures in section 8.

You can request a copy of the relevant safeguards from privacy@getvertexhealth.com.

13

Children

The assistant is for adults. A parent or guardian may use it for a child and is responsible for what they enter.

The Service is not directed to children and children must not use it on their own. A parent or legal guardian may use it in relation to a child in their care, and is responsible for the information they enter. We do not knowingly collect personal information directly from a child. If you believe a child has used the Assistant unsupervised, contact us and we will delete the session.

14

Cookies and local storage

No advertising or tracking cookies. The widget stores your language and the fact you accepted the notice; the dashboard uses a sign-in cookie.

  • The Assistant stores your language choice and the fact that you accepted the pre-assessment notice, in your browser's local storage, so you are not asked again on every visit. Clearing site data removes it.
  • Cloudflare Turnstile sets what it needs to run the bot check before your first message.
  • The dashboard uses a strictly necessary authentication cookie from our authentication provider to keep you signed in.
  • The website stores your theme and language preference locally.

We use no advertising, retargeting or cross-site tracking cookies anywhere in the Service.

15

Changes to this policy

We will update this page and change the effective date. Material changes are announced.

We may update this policy as the Service changes. The version and effective date at the top of the page always reflect the current text, and material changes will be announced on the website and, for Business Customers, by email or in the dashboard before they take effect.

16

Contact us

Privacy questions and requests go to privacy@getvertexhealth.com.

[registered company name and number], [registered address]. Privacy contact: privacy@getvertexhealth.com.

Our representative in the European Union under Article 27 GDPR is [EU representative]. Our United Kingdom representative is [UK representative].

Version 1.0, effective 27 August 2026.