1. Introduction
Aurevia MD Technologies, Inc. ("Aurevia," "Company," "we," "us," or "our") is a Delaware corporation headquartered in San Diego, California. We develop clinical intelligence technology designed to support healthcare providers in delivering better patient care.
This Privacy Policy describes how we collect, use, disclose, and protect personal information when you visit our website (aureviamd.com), interact with our services, or otherwise engage with us. This Policy applies to individuals worldwide, including residents of the United States (with specific provisions for California residents), Canada, the European Economic Area (EEA), United Kingdom, Australia, and New Zealand.
Important Notice Regarding Health Information: This Privacy Policy governs information collected through our corporate website and business operations. To the extent Aurevia processes Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA) on behalf of healthcare provider clients, such processing is governed by Business Associate Agreements with those clients and applicable HIPAA regulations, not this Privacy Policy.
2. Scope and Applicability
This Privacy Policy applies to:
- Visitors to our website and online properties
- Prospective and current customers, partners, and vendors
- Individuals who contact us for information or support
- Job applicants and candidates
- Any other individuals whose personal information we process in connection with our business activities
This Policy does not apply to de-identified or anonymized data that cannot reasonably be used to identify an individual, or to publicly available information from government records.
3. Information We Collect
3.1 Information You Provide Directly
We collect information you voluntarily provide, including:
- Contact Information: Name, email address, telephone number, mailing address, professional title, and organizational affiliation.
- Account Information: Username, password, and account preferences if you create an account with us.
- Communications: Content of messages, inquiries, or feedback you send to us.
- Business Information: Company name, industry, role, and other professional details relevant to our business relationship.
- Employment Application Information: Resume, work history, education, references, and other information submitted in connection with job applications.
3.2 Information Collected Automatically
When you visit our website, we automatically collect certain information, including:
- Device and Browser Information: IP address, device type, operating system, browser type and version, device identifiers, and screen resolution.
- Usage Data: Pages visited, links clicked, time spent on pages, referring URL, and other interactions with our website.
- Location Data: General geographic location inferred from your IP address.
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, pixels, and similar technologies as described in Section 10.
3.3 Information from Third Parties
We may receive information about you from third parties, including:
- Business partners and referral sources
- Service providers that help us maintain our website and operations
- Publicly available sources and professional networking platforms
- Background check providers (for employment purposes, with your consent where required)
4. How We Use Your Information
We use personal information for the following purposes:
- Providing Services: To deliver our products and services, process transactions, and manage your account.
- Communications: To respond to inquiries, provide customer support, send service-related notifications, and communicate about our products and services.
- Marketing: To send promotional materials, newsletters, and other marketing communications where permitted by law and consistent with your preferences.
- Analytics and Improvement: To analyze website usage, understand user preferences, and improve our products, services, and website.
- Security: To protect our systems, detect and prevent fraud, and ensure the security of our operations.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests.
- Employment: To evaluate job applications, conduct background checks where permitted, and manage the employment relationship.
5. Legal Bases for Processing (EEA, UK, and Similar Jurisdictions)
For individuals in the European Economic Area, United Kingdom, and jurisdictions with similar requirements, we process personal data based on the following legal grounds:
- Contract Performance: Processing necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract.
- Legitimate Interests: Processing necessary for our legitimate interests, such as operating our business, improving our services, marketing, and ensuring security, where those interests are not overridden by your rights and interests.
- Legal Obligation: Processing necessary to comply with legal obligations to which we are subject.
- Consent: Where you have given explicit consent to the processing for specific purposes, which you may withdraw at any time.
6. Disclosure of Information
We may share your personal information with the following categories of recipients:
- Service Providers: Third parties that perform services on our behalf, such as hosting, analytics, payment processing, customer support, and marketing services. These providers are contractually obligated to protect your information and use it only for the purposes we specify.
- Business Partners: Trusted partners with whom we collaborate to provide joint services or offerings.
- Professional Advisors: Lawyers, accountants, auditors, and other professional advisors in connection with the services they provide to us.
- Legal and Regulatory Authorities: Government entities, regulators, and law enforcement when required by law, legal process, or to protect our rights, property, or safety.
- Business Transactions: In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred to the acquiring entity.
- With Your Consent: Other parties when you have given us explicit permission to share your information.
We do not sell personal information as that term is commonly understood or as defined under applicable privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
7. International Data Transfers
Aurevia is headquartered in the United States, and your personal information may be transferred to and processed in the United States and other countries where we or our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
For transfers from the EEA, UK, or Switzerland to countries not deemed to provide an adequate level of data protection, we implement appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreement or UK Addendum to SCCs
- Other lawful transfer mechanisms as appropriate
For transfers from Australia, we comply with the Australian Privacy Principles regarding cross-border disclosure. For transfers from New Zealand, we ensure compliance with the New Zealand Privacy Act 2020 requirements for overseas disclosure. You may request a copy of the safeguards we use by contacting us using the information provided below.
8. Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. In determining retention periods, we consider:
- The nature and sensitivity of the information
- The purposes for which we process the information
- Applicable legal, regulatory, or contractual requirements
- Whether the information is needed to establish, exercise, or defend legal claims
When personal information is no longer required, we will securely delete or anonymize it.
9. Data Security
We implement technical, administrative, and physical security measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Access controls and authentication requirements
- Regular security assessments and monitoring
- Employee training on data protection and security
- Incident response procedures
Our security program is aligned with industry standards and frameworks, including NIST Cybersecurity Framework and SOC 2 trust principles. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience on our website, analyze usage patterns, and deliver relevant content. The types of cookies we use include:
- Essential Cookies: Required for the website to function properly and cannot be disabled.
- Analytics Cookies: Help us understand how visitors interact with our website by collecting anonymous usage data.
- Functional Cookies: Enable enhanced functionality and personalization.
- Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness.
You can manage cookie preferences through your browser settings or through any cookie consent mechanism we provide on our website. Note that disabling certain cookies may affect website functionality.
11. Your Privacy Rights
11.1 California Residents (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: You have the right to opt out of the sale of your personal information or sharing for cross-context behavioral advertising. As stated above, we do not sell personal information.
- Right to Limit Use of Sensitive Personal Information: If we collect sensitive personal information, you have the right to limit its use to purposes necessary to provide our services.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
Categories of Personal Information Collected: In the preceding 12 months, we may have collected the following categories of personal information: identifiers (name, email, IP address); commercial information (transaction history); internet/electronic activity (website usage); professional/employment information; and inferences drawn from any of the above.
To exercise these rights, please contact us using the information provided in Section 16. We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf.
11.2 European Economic Area and United Kingdom Residents (GDPR/UK GDPR)
If you are located in the EEA or UK, you have the following rights under the General Data Protection Regulation (GDPR) or UK GDPR:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data in certain circumstances.
- Right to Restriction of Processing: Request that we limit the processing of your personal data in certain circumstances.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Right to Lodge a Complaint: File a complaint with your local data protection authority.
For EEA residents, the lead supervisory authority is determined by our establishment in the EU. For UK residents, the supervisory authority is the Information Commissioner's Office (ICO).
11.3 Canadian Residents (PIPEDA and Provincial Laws)
If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws:
- Right to Access: Request access to your personal information held by us.
- Right to Correction: Request correction of inaccurate or incomplete personal information.
- Right to Withdraw Consent: Withdraw consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions.
- Right to Complain: File a complaint with the Office of the Privacy Commissioner of Canada or applicable provincial privacy commissioner.
11.4 Australian Residents (Privacy Act 1988)
If you are an Australian resident, you have rights under the Privacy Act 1988 and the Australian Privacy Principles (APPs):
- Right to Access: Request access to your personal information.
- Right to Correction: Request correction of inaccurate, incomplete, out-of-date, or misleading personal information.
- Right to Complain: Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.
11.5 New Zealand Residents (Privacy Act 2020)
If you are a New Zealand resident, you have rights under the Privacy Act 2020 and the Information Privacy Principles (IPPs):
- Right to Access: Request access to your personal information.
- Right to Correction: Request correction of personal information that is inaccurate, incomplete, misleading, or not up to date.
- Right to Complain: Lodge a complaint with the Office of the Privacy Commissioner if you believe we have interfered with your privacy.
12. Children's Privacy
Our website and services are not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child without appropriate parental consent, we will take steps to delete that information promptly. If you believe we may have collected information from a child, please contact us immediately.
13. Third-Party Links and Services
Our website may contain links to third-party websites, applications, or services that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policies of any third-party sites you visit.
14. Do Not Track Signals
Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want to have your online activity tracked. There is currently no uniform standard for how to respond to DNT signals, and our website does not currently respond to DNT signals. However, you can manage your cookie preferences and tracking as described in Section 10.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this Policy and, where required by law, provide additional notice (such as a prominent notice on our website or direct communication to you). We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Aurevia MD Technologies, Inc.
Attn: Privacy Officer
101 Park Plaza, Unit 631
San Diego, CA 92101
United States
Email: privacy@aureviamd.com
For EEA and UK residents, you may also contact your local data protection authority with concerns about our data processing practices.
17. Governing Law
This Privacy Policy and any disputes arising out of or related to it shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of law principles, except where mandatory local data protection laws apply.
* * *
© 2026 Aurevia MD Technologies, Inc. All rights reserved.