Legal & Compliance

Privacy Policy

DocuFindr builds AI software that touches sensitive healthcare workflows, so we take the privacy and security of your data seriously. This policy explains what we collect, how we use it, and the rights you have — whether you're visiting our website, evaluating our platform, or a client whose team processes protected health information (PHI) through DocuFindr.

Last Updated: August 26, 2026Applies to:docufindr.ai & DocuFindr PlatformQuestions: sales@docufindr.ai

Introduction

DocuFindr, Inc. ("DocuFindr", "we", "us", or "our") provides an AI-powered pre-denial validation platform used by DME suppliers, infusion centers, home health agencies, and specialty clinics to automate intake, prior authorization, and denial management. We do not sell, rent, lease, or trade your personal information to any third party.

This Privacy Policy describes how we collect, use, and safeguard personal information when you visit docufindr.ai, request a demo, use the DocuFindr platform, or otherwise communicate with our team. By using our website or services, you agree to the practices described here.

We may update this policy periodically. The "Last Updated" date at the top of this page reflects the most recent revision — we encourage you to check back from time to time.

Scope:This policy covers personal data collected through our website, product demos, contact and pilot-request forms, sales communications, and — separately, as described in Section 2 — protected health information processed on behalf of our clients through the DocuFindr platform.
Section 01

1. Information We Collect

(i) Personal Information

Depending on how you interact with us, we may collect:

  • Identity data: Your name, job title, and organization
  • Contact data: Email address, phone number, and business address
  • Technical data: IP address, browser type and version, device type, and operating system
  • Communication data: Messages sent through our contact form, demo requests, or emails
  • Usage data: How you interact with our website and marketing content, including pages viewed and links clicked

We collect this information when you:

  • Visit or navigate our website
  • Submit a "Request a Demo," "Contact Us," or pilot-inquiry form
  • Communicate with us as a prospective or existing client
  • Subscribe to product updates or download resources such as whitepapers or ROI calculators
  • Attend a webinar or industry event where DocuFindr is present

(ii) Mobile Communication

If you provide a mobile number and opt in, you agree to receive texts or calls related to your inquiry, demo scheduling, or account updates. You may opt out at any time by replying STOP or contacting us directly. We never share mobile opt-in data with third parties for marketing purposes.

(iii) Non-Personal Data

We also collect aggregated, non-identifying analytics — browser type, device category, referring URL, and session duration — primarily through Google Analytics, to understand and improve website performance.

Section 02

2. Protected Health Information (PHI)

The DocuFindr platform processes clinical and administrative documentation — such as CMNs, DWOs, referrals, and prior-authorization packets — on behalf of our healthcare provider and supplier clients. Where this data includes Protected Health Information under HIPAA, DocuFindr acts as a Business Associate, not as the data owner.

  • PHI is processed solely to deliver the validation, intake, and denial-prevention services our clients contract us for
  • Our handling of PHI is governed by a signed Business Associate Agreement (BAA) with each client, which controls in the event of any conflict with this general policy
  • We do not use client PHI for advertising, marketing, or to train models shared across unrelated clients without explicit authorization
  • Access to PHI within DocuFindr is restricted to authorized personnel on a least-privilege basis and logged for audit purposes
If you are a patient:If your records may have passed through DocuFindr as part of your provider's workflow, requests regarding your health information should be directed to your healthcare provider or supplier, who remains the HIPAA Covered Entity responsible for your records.
Section 03

3. How We Use Your Information

We use the personal information we collect to:

  • Respond to enquiries and provide information about our platform and services
  • Schedule and deliver product demos and manage the sales process
  • Fulfil client agreements and support onboarding, implementation, and account management
  • Send service communications such as product updates, security notices, or account information
  • Improve our website and product by understanding how visitors and users engage with our content
  • Send marketing communications where you've opted in, including newsletters and event invitations
  • Comply with legal and regulatory obligations, including healthcare-industry recordkeeping requirements
  • Process job applications submitted through our careers page or by email

We will not use your information for purposes incompatible with those above without first obtaining your consent.

Section 04

4. Cookies

Our website uses cookies to run correctly, understand site usage, and deliver relevant content. A cookie is a small text file stored on your device that helps us recognize your browser and remember preferences.

Types of Cookies We Use

TypePurposeStatus
Required CookiesEssential for the website to function — page navigation, session security, and access to protected areas.Always On
Analytics CookiesHelp us understand visitor behavior — pages visited, session duration, traffic sources — via tools like Google Analytics.Optional
Performance CookiesCollect page-load and responsiveness data so we can optimize site performance.Optional
Targeting CookiesBuild an interest profile to deliver relevant ads on platforms such as LinkedIn and Google.Optional

Third parties that may set cookies on our behalf include Google Analytics, HubSpot, LinkedIn, and Meta, each governed by their own privacy policies. You can manage or disable cookies in your browser settings at any time; disabling some cookies may affect site functionality.

Section 05

5. Disclosing Your Information

DocuFindr does not sell, trade, or rent your personal information. We may share it only in these limited circumstances:

  • Sub-processors and service providers: Vendors who help us deliver our services (e.g., cloud hosting, CRM, email delivery). All sub-processors that may touch PHI are bound by a Business Associate Agreement.
  • Legal requirements: When required by law, subpoena, or governmental authority, or to protect the rights, property, or safety of DocuFindr, our clients, or others.
  • Business transfers: If DocuFindr merges with, is acquired by, or sells part of its business, personal data may transfer as part of that transaction. We will notify affected users before data becomes subject to a different privacy policy.
  • Fraud and security: To detect, investigate, and prevent fraudulent activity or security incidents.
Important Protection:We never sell personal data or client PHI. Every sub-processor with access to PHI is contractually bound by a BAA and data-processing terms that mirror our own obligations under HIPAA.
Section 06

6. Security

We take the security of your data seriously and apply administrative, technical, and physical safeguards appropriate to a HIPAA-regulated environment, including:

  • Encrypted data in transit (TLS/HTTPS) and at rest across the platform
  • Role-based access controls limiting data access to authorized personnel only
  • Secure, HIPAA-eligible cloud hosting infrastructure with audit logging
  • Regular security reviews, vulnerability scanning, and penetration testing
  • Signed Business Associate Agreements (BAAs) with clients and sub-processors handling PHI

No method of transmission over the internet or electronic storage is 100% secure. If you believe your interaction with DocuFindr is no longer secure, contact us immediately at sales@docufindr.ai.

Section 07

7. Third-Party Links

Our website may link to third-party sites — payer resources, integration partners, or industry publications — for your convenience. These links are provided for reference only; DocuFindr does not endorse and is not responsible for the privacy practices, content, or security of external sites.

We encourage you to review the privacy policy of any external website before providing personal information. This policy applies solely to information collected by DocuFindr.

Section 08

8. Data Retention

We retain personal information only as long as necessary to fulfil the purposes it was collected for, including legal, accounting, or regulatory requirements.

  • Enquiry and prospect data is retained for up to 3 years after your last interaction, unless you become an active client
  • Client and PHI data is retained for the duration of the engagement and thereafter per the applicable BAA and HIPAA retention requirements
  • Marketing preferences are retained until you opt out or withdraw consent
  • Website analytics data is aggregated and anonymized after 26 months

When data is no longer required, we delete or de-identify it in a secure manner consistent with our retention schedules and any applicable BAA.

Section 09

9. Your Rights

Depending on your location and applicable law, you may have the right to:

  • Access a copy of the personal data we hold about you
  • Rectify inaccurate or incomplete personal data
  • Erasure of your personal data, subject to legal exceptions
  • Restrict processing of your personal data in certain circumstances
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing for marketing purposes at any time
  • Withdraw consent where processing is based on consent, without affecting prior lawful processing

To exercise these rights, contact us at sales@docufindr.ai. We respond within 30 days and may need to verify your identity first.

If you are a resident of the EEA, California (CCPA), or another jurisdiction with specific data protection laws, you may have additional rights — contact us for jurisdiction-specific guidance. If your health data was processed through a client of ours, requests are generally directed to that client as the HIPAA Covered Entity.

Section 10

10. Changes to This Policy

DocuFindr may update, modify, or amend this Privacy Policy at any time. When we do, we update the "Last Updated" date at the top of this page. For material changes, we may also provide more prominent notice, such as a homepage banner or direct email to affected users.

Continued use of our website or platform after any change constitutes acceptance of the updated terms. We encourage you to review this page periodically.

Section 11

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your information, reach out to our team:

We acknowledge privacy requests within 2 business days and aim to fully resolve them within 30 days.