Privacy Policy
Automate AI, LLC ("Automate Medical," "we," "us," or "our") operates the website at automate-medical.com and provides the Automate Medical AI platform. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website or use our services.
1. Information we collect
Personal information you provide: name, email, phone number, organization, role, and any information you include when you fill out a form, request a demo, or contact us.
Protected Health Information (PHI): if you are a customer or end-user of the Automate Medical platform, we process PHI solely to provide the platform and only under a signed Business Associate Agreement (BAA). We never use PHI to train foundation models.
Usage data: pages visited, time on page, referring URL, device type, browser type, IP address (anonymized after 30 days), and aggregated interaction data.
2. How we use information
- To provide, operate, and improve the Automate Medical platform.
- To respond to demo requests, sales inquiries, and support requests.
- To send product updates, security advisories, and educational content (with opt-out).
- To detect, prevent, and address fraud, security incidents, and abuse.
- To comply with legal obligations and enforce our agreements.
3. How we share information
We do not sell personal information or PHI. We share information only with:
- Subcontractors who provide services on our behalf (hosting, email, customer support), bound by confidentiality and security obligations.
- Regulators, courts, or law enforcement when required by law or to protect our legal rights.
- Successor entities in the event of a merger, acquisition, or sale of assets (with notice to you).
4. HIPAA, BAA, and PHI
The Automate Medical platform is built on HIPAA-aware infrastructure. PHI is encrypted at rest (AES-256) and in transit (TLS 1.2+). Every inference is logged with timestamp, accessor, action, data, model, and output. We do not route PHI through public ChatGPT, Claude.ai, or Gemini app endpoints. SOC 2 Type II is in flight.
For enterprise customers, a signed BAA is required before any PHI is processed. We do not use PHI to train foundation models under any circumstances.
5. Cookies and tracking
We use first-party cookies and similar technologies for session management, security, and aggregated analytics. We do not use third-party advertising cookies. You can disable cookies in your browser settings, but some site features may not work.
6. Data retention
Marketing and sales inquiry data: 24 months from last interaction. Platform inference logs: 6 years (HIPAA-aligned). Customer PHI: per the BAA. We delete or anonymize data on request where legally permitted.
7. Your rights
Depending on your jurisdiction (GDPR, CCPA, etc.), you may have rights to access, correct, delete, or port your personal information. To exercise these rights, email privacy@automate-medical.com.
8. Security
We use industry-standard administrative, technical, and physical safeguards. Report a vulnerability to security@automate-medical.com.
9. Children
Our services are not directed to children under 16, and we do not knowingly collect personal information from children.
10. Changes to this policy
We will post material changes on this page with a revised "last updated" date. For significant changes, we will give you notice via email or through the platform.
11. Contact
Automate AI, LLC · Boston, Massachusetts, United States
Email: privacy@automate-medical.com · Phone: (844) 8-AIMATE