Privacy Policy
DocuFindr builds AI software that touches sensitive healthcare workflows, so we take the privacy and security of your data seriously. This policy explains what we collect, how we use it, and the rights you have — whether you're visiting our website, evaluating our platform, or a client whose team processes protected health information (PHI) through DocuFindr.
Introduction
DocuFindr, Inc. ("DocuFindr", "we", "us", or "our") provides an AI-powered pre-denial validation platform used by DME suppliers, infusion centers, home health agencies, and specialty clinics to automate intake, prior authorization, and denial management. We do not sell, rent, lease, or trade your personal information to any third party.
This Privacy Policy describes how we collect, use, and safeguard personal information when you visit docufindr.ai, request a demo, use the DocuFindr platform, or otherwise communicate with our team. By using our website or services, you agree to the practices described here.
We may update this policy periodically. The "Last Updated" date at the top of this page reflects the most recent revision — we encourage you to check back from time to time.
1. Information We Collect
(i) Personal Information
Depending on how you interact with us, we may collect:
- Identity data: Your name, job title, and organization
- Contact data: Email address, phone number, and business address
- Technical data: IP address, browser type and version, device type, and operating system
- Communication data: Messages sent through our contact form, demo requests, or emails
- Usage data: How you interact with our website and marketing content, including pages viewed and links clicked
We collect this information when you:
- Visit or navigate our website
- Submit a "Request a Demo," "Contact Us," or pilot-inquiry form
- Communicate with us as a prospective or existing client
- Subscribe to product updates or download resources such as whitepapers or ROI calculators
- Attend a webinar or industry event where DocuFindr is present
(ii) Mobile Communication
If you provide a mobile number and opt in, you agree to receive texts or calls related to your inquiry, demo scheduling, or account updates. You may opt out at any time by replying STOP or contacting us directly. We never share mobile opt-in data with third parties for marketing purposes.
(iii) Non-Personal Data
We also collect aggregated, non-identifying analytics — browser type, device category, referring URL, and session duration — primarily through Google Analytics, to understand and improve website performance.
2. Protected Health Information (PHI)
The DocuFindr platform processes clinical and administrative documentation — such as CMNs, DWOs, referrals, and prior-authorization packets — on behalf of our healthcare provider and supplier clients. Where this data includes Protected Health Information under HIPAA, DocuFindr acts as a Business Associate, not as the data owner.
- PHI is processed solely to deliver the validation, intake, and denial-prevention services our clients contract us for
- Our handling of PHI is governed by a signed Business Associate Agreement (BAA) with each client, which controls in the event of any conflict with this general policy
- We do not use client PHI for advertising, marketing, or to train models shared across unrelated clients without explicit authorization
- Access to PHI within DocuFindr is restricted to authorized personnel on a least-privilege basis and logged for audit purposes
3. How We Use Your Information
We use the personal information we collect to:
- Respond to enquiries and provide information about our platform and services
- Schedule and deliver product demos and manage the sales process
- Fulfil client agreements and support onboarding, implementation, and account management
- Send service communications such as product updates, security notices, or account information
- Improve our website and product by understanding how visitors and users engage with our content
- Send marketing communications where you've opted in, including newsletters and event invitations
- Comply with legal and regulatory obligations, including healthcare-industry recordkeeping requirements
- Process job applications submitted through our careers page or by email
We will not use your information for purposes incompatible with those above without first obtaining your consent.
5. Disclosing Your Information
DocuFindr does not sell, trade, or rent your personal information. We may share it only in these limited circumstances:
- Sub-processors and service providers: Vendors who help us deliver our services (e.g., cloud hosting, CRM, email delivery). All sub-processors that may touch PHI are bound by a Business Associate Agreement.
- Legal requirements: When required by law, subpoena, or governmental authority, or to protect the rights, property, or safety of DocuFindr, our clients, or others.
- Business transfers: If DocuFindr merges with, is acquired by, or sells part of its business, personal data may transfer as part of that transaction. We will notify affected users before data becomes subject to a different privacy policy.
- Fraud and security: To detect, investigate, and prevent fraudulent activity or security incidents.
6. Security
We take the security of your data seriously and apply administrative, technical, and physical safeguards appropriate to a HIPAA-regulated environment, including:
- Encrypted data in transit (TLS/HTTPS) and at rest across the platform
- Role-based access controls limiting data access to authorized personnel only
- Secure, HIPAA-eligible cloud hosting infrastructure with audit logging
- Regular security reviews, vulnerability scanning, and penetration testing
- Signed Business Associate Agreements (BAAs) with clients and sub-processors handling PHI
No method of transmission over the internet or electronic storage is 100% secure. If you believe your interaction with DocuFindr is no longer secure, contact us immediately at sales@docufindr.ai.
7. Third-Party Links
Our website may link to third-party sites — payer resources, integration partners, or industry publications — for your convenience. These links are provided for reference only; DocuFindr does not endorse and is not responsible for the privacy practices, content, or security of external sites.
We encourage you to review the privacy policy of any external website before providing personal information. This policy applies solely to information collected by DocuFindr.
8. Data Retention
We retain personal information only as long as necessary to fulfil the purposes it was collected for, including legal, accounting, or regulatory requirements.
- Enquiry and prospect data is retained for up to 3 years after your last interaction, unless you become an active client
- Client and PHI data is retained for the duration of the engagement and thereafter per the applicable BAA and HIPAA retention requirements
- Marketing preferences are retained until you opt out or withdraw consent
- Website analytics data is aggregated and anonymized after 26 months
When data is no longer required, we delete or de-identify it in a secure manner consistent with our retention schedules and any applicable BAA.
9. Your Rights
Depending on your location and applicable law, you may have the right to:
- Access a copy of the personal data we hold about you
- Rectify inaccurate or incomplete personal data
- Erasure of your personal data, subject to legal exceptions
- Restrict processing of your personal data in certain circumstances
- Data portability — receive your data in a structured, machine-readable format
- Object to processing for marketing purposes at any time
- Withdraw consent where processing is based on consent, without affecting prior lawful processing
To exercise these rights, contact us at sales@docufindr.ai. We respond within 30 days and may need to verify your identity first.
If you are a resident of the EEA, California (CCPA), or another jurisdiction with specific data protection laws, you may have additional rights — contact us for jurisdiction-specific guidance. If your health data was processed through a client of ours, requests are generally directed to that client as the HIPAA Covered Entity.
10. Changes to This Policy
DocuFindr may update, modify, or amend this Privacy Policy at any time. When we do, we update the "Last Updated" date at the top of this page. For material changes, we may also provide more prominent notice, such as a homepage banner or direct email to affected users.
Continued use of our website or platform after any change constitutes acceptance of the updated terms. We encourage you to review this page periodically.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your information, reach out to our team: