ClinivaAI

ClinivaAI legal

Cliniva AI Web Application Privacy Policy

Application policy for website access, authenticated portals, dashboards, hosted workflow tools, and customer-accessible application features.

Document details

Provider
Cliniva AI LLC
Brand
Cliniva AI / ClinivaAI
Application / Sites
clinivaai.com, app.clinivaai.com, and related Cliniva AI web portals, dashboards, hosted workflow tools, and customer-accessible application features
Version
2.2
Document Owner
Tara Shaffer
Approved By
Tara Shaffer
Approval Date
2026-08-09
Effective Date
2026-08-09
Next Scheduled Review
2027-08-09

1. Overview

This Privacy Policy explains how Cliniva AI LLC (“Cliniva AI,” “we,” “us,” or “our”) collects, uses, discloses, and protects information through our websites, web application, portals, dashboards, hosted workflow systems, support channels, and related services (the “Application”).

This Policy applies to website visitors, prospective customers, customer contacts, account administrators, clinic users, invited users, authorized staff, and other Application users. Customer contracts, BAAs, DPAs, and SOWs may provide additional or more specific rules for customer data, PHI, and regulated workflows.

2. Information We Collect

We may collect the following categories of information depending on how the Application is used:

  • Account and identity information: name, email address, role, account, clinic, customer organization, invitation status, authentication status, and password or credential metadata. Passwords are stored in hashed form.
  • Authentication and session information: session identifiers, hashed session tokens, pending OTP/enrollment data, sign-in events, invite acceptance records, timestamps, and security-related metadata.
  • Business and customer information: organization name, business type, contact information, account details, billing status, plan information, implementation materials, notes, and support requests.
  • Clinic and user-management data: accounts, clinics, memberships, roles, permissions, selected clinic context, invitations, admin actions, and audit events.
  • Healthcare workflow and patient-related data: where enabled under an appropriate agreement, patient demographics, documents, appointments, tasks, coverage, medications, vitals, problem/allergy lists, clinical orders, encounters, notes, workflow statuses, and related clinic operational records.
  • Workflow and automation data: intake, follow-up, document-routing, event-dashboard, queue, message, AI prompt/output, workflow configuration, and review-status information.
  • Billing and payment-related information: plan name, plan code, status, billing interval, charge labels, invoice data, and payment-processing metadata. Full payment-card numbers are handled by payment processors when payment features are used.
  • Communications: emails, form submissions, support messages, meeting notes, uploaded materials, feedback, and other communications with us.
  • Device, log, and usage data: IP address, browser, device, pages viewed, referring URLs, timestamps, diagnostic logs, cookie data, and actions taken in the Application.

3. Protected Health Information and HIPAA

When Cliniva AI acts as a business associate or subcontractor, PHI is governed by a signed Business Associate Agreement and applicable service terms. PHI should not be submitted through public marketing pages, unsecured forms, or non-secure channels unless expressly authorized.

Customers are responsible for determining whether data is PHI, obtaining required patient authorizations or notices, assigning appropriate user roles, reviewing outputs, and using the Application in compliance with HIPAA and other healthcare laws. Cliniva AI uses PHI only as permitted by the applicable BAA, written agreements, and law.

4. Cookies and Similar Technologies

The Application may use cookies, local storage, session storage, and similar technologies for:

TypePurposeExamples
Essentialauthentication, session management, invite acceptance, security, CSRF protection, load balancing, and app operationsession cookies, pending OTP/enrollment cookies
Preferenceremembering interface or workflow contextselected clinic or application preferences where enabled
Analytics / diagnosticsunderstanding usage, performance, errors, and security eventsfirst-party logs; approved third-party analytics only on expressly allowlisted, form-free public pages
Marketing / online data partnersmeasuring campaigns, website referrals, visitor identification, business outreach, and advertising or marketing communicationsapproved online data partner or RB2B/Retention.com tracking only on expressly allowlisted, form-free public pages

You can control cookies through your browser. Disabling essential cookies may prevent the Application from working. Where required by law, non-essential analytics, marketing, or online data partner technologies should be controlled through our cookie banner or consent-management settings.

Third-Party Analytics and Online Data Partner Isolation

Third-party analytics, session-replay, advertising, and marketing-identification technologies—including Google Analytics, Microsoft Clarity, RB2B/Retention.com, and similar technologies—are denied by default. They may load or receive events only on an exact public route that has completed privacy and security review, has been placed on the Application’s technical allowlist, and does not contain or render a login, registration, authentication, appointment, scheduling, contact, support, intake, workflow, patient, or other form capable of receiving PHI or individually identifying health information.

These technologies are technically blocked on authenticated portals and application routes; clinical and patient workflows; login, registration, invitation, OTP, legal-acceptance, and password-reset flows; scheduling, contact, intake, and workflow-conversation pages; unknown or dynamic routes that have not been expressly approved; and every other route or form capable of receiving PHI. Cookie consent or an opt-in does not override this isolation. A third-party technology may be enabled in a PHI-capable context only after Cliniva AI confirms the legally required permission and a BAA or other agreement required for that use.

The Application enforces this boundary through an exact-route allowlist, centralized vendor-event guards, and a full-document navigation boundary when a user moves from an approved page to a denied page so a previously loaded vendor runtime cannot observe the denied route. Automated regression tests inventory application routes and the rendered dependency graph for every form. The tests fail if an allowlisted route renders a form, a new form lacks route coverage, a denied route becomes eligible through prefix or fallback matching, or marketing events can invoke a vendor on a denied route. This treatment reflects HHS guidance that authenticated portals and login or registration interactions may involve PHI. See HHS guidance on online tracking technologies.

You may opt out of this advertising by visiting https://app.retention.com/optout. If international company-level identification or GDPR-related identification features are enabled, you may also opt out of certain personal data collection by visiting https://www.rb2b.com/rb2b-gdpr-opt-out.

5. How We Use Information

We use information to:

  • provide, operate, secure, and maintain the Application;
  • authenticate users, manage sessions, process invitations, and enforce role-based access;
  • create and manage accounts, clinics, customer records, users, memberships, permissions, and audit logs;
  • support healthcare workflow features where authorized;
  • process customer requests, implementation tasks, support tickets, and service communications;
  • provide AI-assisted workflow routing, summarization, classification, and automation features subject to human review;
  • administer billing, plans, subscriptions, invoices, and payment processing;
  • monitor performance, troubleshoot errors, prevent fraud, and detect security incidents;
  • comply with legal, contractual, accounting, tax, audit, HIPAA, privacy, and security obligations;
  • enforce agreements and protect our rights, users, customers, and services; and
  • improve Application usability, reliability, and security using feedback, non-PHI operational or diagnostic data, or de-identified or aggregated information where permitted by law and the applicable BAA;
  • conduct marketing, business outreach, campaign measurement, and online data partner activities where enabled and legally permitted.

6. Legal Bases for Processing

Where GDPR or similar law applies, we rely on one or more of the following legal bases:

PurposeLegal Basis
Account access, authentication, service delivery, billing, and supportContractual necessity
Security monitoring, fraud prevention, diagnostics, limited service improvement, and administrative operationsLegitimate interests, subject to the PHI restrictions in this Policy and any applicable BAA
HIPAA/healthcare, tax, accounting, legal response, and regulatory obligationsLegal obligation
Optional marketing, non-essential cookies, and certain communicationsConsent where required
PHI processing as a business associateApplicable BAA and customer instructions, plus legal obligations

7. How We Share Information

We may share information with:

  • Customer organizations and authorized administrators to manage their accounts, clinics, users, roles, workflows, billing, audit events, and data;
  • Service providers such as cloud hosting, database, email, security, analytics, monitoring, payment, support, document, AI/API, and infrastructure providers;
  • Online data partners and marketing vendors such as RB2B/Retention.com or similar providers, if enabled only on expressly allowlisted, form-free public pages, to support website visitor identification, campaign measurement, business outreach, and advertising or marketing communications;
  • Integration partners when a customer authorizes integrations with EHR/EMR, calendar, messaging, document, CRM, payment, or other systems;
  • Professional advisors such as lawyers, accountants, auditors, insurers, and security consultants;
  • Authorities or third parties when required by law, subpoena, court order, regulatory request, or to protect rights and safety;
  • Business transaction parties in connection with a merger, financing, acquisition, reorganization, or sale of assets; and
  • Others with consent or customer instruction.

We do not sell PHI. We do not sell personal information in the ordinary sense. If online data partner, advertising, or analytics activity constitutes “sale” or “sharing” under California law, we will provide required notices and opt-out mechanisms, which may include a “Do Not Sell or Share My Personal Information” link or similar control.

8. AI Providers and Model Processing

When AI-assisted features are enabled, information may be processed by approved AI model or infrastructure providers to generate workflow drafts, classifications, summaries, routing suggestions, or other outputs. Cliniva AI does not use, and does not permit an AI provider to use, PHI to train, retrain, fine-tune, or improve a general-purpose or foundation model.

PHI may be sent to an AI provider only after Cliniva AI has a signed BAA with that provider and has verified that the specific organization, project, product, endpoint, and configuration are eligible for PHI. The configuration must disable training opt-in, use modified retention or a stricter approved retention control where required, disable optional provider application-state storage where applicable, and limit the disclosed PHI to the minimum necessary. Until those controls are documented, PHI must not be sent to that provider. AI outputs require human review.

9. Data Retention

We retain information for as long as needed to provide the Application, maintain accounts, comply with agreements, resolve disputes, enforce terms, meet legal/tax/accounting/security obligations, preserve audit logs, maintain backups, and support customers. Typical retention categories include:

Data TypeTypical Retention
Account and user recordsduration of account access plus a reasonable administrative period
Sessions and authentication logsas needed for security, troubleshooting, and audit purposes
Customer and clinic recordsas directed by customer agreements and applicable law
PHI and clinical workflow recordsas required by BAA, customer instructions, and healthcare law
Billing and transaction recordsas required for accounting, tax, chargeback, and legal obligations
Support and communicationsas needed for service history, legal, and operational needs
Backups and logsretained according to backup, disaster recovery, and security practices

For PHI processed by a service provider, Cliniva AI configures provider retention to the shortest period supported by the approved service and permitted by the governing BAA. Provider application-state storage for PHI is disabled where the approved service supports or requires that control. A provider may not retain PHI for training or general model improvement. Any exception must be expressly permitted by the BAA, documented, approved, and limited to the minimum necessary.

10. Security

We use technical and organizational safeguards designed to protect information, including role-based access controls, hashed credentials and session tokens, secure cookies, audit logs, limited access, security monitoring, encryption in transit, and encryption at rest for approved PHI stores. A system is not approved to store PHI until its encryption configuration and key-management evidence have been verified. No system is perfectly secure. Users and customers must protect credentials, configure access appropriately, use secure devices, and promptly report suspected incidents.

11. Your Privacy Choices and Rights

Depending on your location and relationship to us, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, to withdraw consent where processing is based on consent, and to opt out of certain targeted advertising, sale, or sharing activities where required by law. Requests may be subject to identity verification, customer-admin approval, legal exceptions, BAA restrictions, retention obligations, and security limitations.

Authorized users seeking access to customer-controlled data should usually contact their organization’s administrator first. Privacy requests may be sent to privacy@clinivaai.com or legal@clinivaai.com. RB2B/Retention.com advertising opt-out requests may also be submitted at https://app.retention.com/optout, and GDPR-related RB2B opt-out requests, where applicable, may be submitted at https://www.rb2b.com/rb2b-gdpr-opt-out.

12. California Privacy Notice

California residents may have rights to know, access, correct, delete, and opt out of certain sale or sharing of personal information, including certain online data partner or targeted advertising activities where applicable, and to limit use of sensitive personal information where applicable. We do not discriminate for exercising privacy rights.

Categories of personal information we may collect include identifiers, professional or employment-related information, commercial information, internet or electronic network activity, account credentials, sensitive personal information where required for authorized services, and health-related information where covered by appropriate agreements. We collect and use these categories for the purposes described in this Policy.

13. International Users

Information may be processed in the United States and other countries where we or our providers operate. Where required, we use appropriate safeguards such as contractual commitments, data processing agreements, and customer instructions.

14. Children

The Application is not directed to children under 13, and we do not knowingly collect personal information from children through public websites. Healthcare customers are responsible for any lawful processing of minor patient information under their agreements and applicable law.

15. Changes to This Policy

We may update this Policy from time to time. The updated version will be posted with a new effective date. Material changes may also be communicated through the Application, email, or other reasonable notice.

16. Contact

Privacy questions or requests may be sent to privacy@clinivaai.com or legal@clinivaai.com.