Privacy Policy.
Adentris, Inc. ("Adentris", "we", "us") respects privacy and handles your data with the care a healthcare AI platform must. This policy explains what we collect on our website and platform, how we use it, and the protections in place.
1. What we collect
1.1 Information you provide
- Account data: name, work email, organization, role, phone number (verified at registration).
- Documents you upload: charts, claims, VOB documents, prior auth requests, and any other files you submit for review on the platform.
- Communications: emails, support tickets, and other correspondence with our team.
1.2 Information we collect automatically
- Usage data: pages visited, features used, time spent in the platform.
- Device and connection data: browser type, operating system, IP address, referrer.
- Cookies and similar technologies: session cookies for authentication; analytics cookies for product and website improvement.
1.3 Protected Health Information (PHI)
Where customers connect Adentris to their EHR or upload patient data, the resulting information is PHI under HIPAA. PHI is processed only under a signed Business Associate Agreement (BAA) and only for the purposes of providing the platform.
2. How we use information
- To operate, secure, and improve the Adentris platform.
- To provide customer success and support.
- To send service updates, security notices, and (for opted-in users) product newsletters.
- To meet legal, regulatory, and security obligations.
We do not sell personal data. We do not use customer PHI to train external AI models.
3. AI inference and patient data
All AI inference runs inside Microsoft Azure under our signed BAA. Patient data is never sent to OpenAI, Anthropic, Google, or any external LLM API. Our AI model endpoints are hosted exclusively in HIPAA-eligible Azure regions in the United States.
4. Security
- SOC 2 Type I and Type II attestations completed.
- HIPAA-aligned architecture; BAA available.
- 42 CFR Part 2 architecture for SUD and behavioral health data.
- AES-256 encryption at rest, TLS 1.3 in transit.
- Role-based access with least-privilege design.
- Full audit logging on every system action and AI recommendation.
- US-only data residency.
5. Data sharing
We share data only with subprocessors required to operate the platform (e.g., Microsoft Azure for hosting and AI inference, Stripe for payments). All subprocessors are subject to BAAs and confidentiality requirements. We do not share customer data with advertising networks or unrelated third parties.
6. Data retention
Account data is retained while your Adentris subscription is active and for a reasonable period afterwards for legal and audit purposes. Uploaded documents and PHI are retained according to your contract terms; default retention is 30 days after deletion request. Enterprise customers can configure retention per their compliance program.
7. Your rights
Under HIPAA, GDPR (where applicable), and US state privacy laws (including CCPA/CPRA), you have rights to access, correct, delete, and (where applicable) export your personal data. To exercise these rights, contact privacy@adentris.com.
8. Children's privacy
Adentris is a B2B platform. We do not knowingly collect data from anyone under 18. Where pediatric PHI is processed under a customer BAA, the data is handled under the same HIPAA-aligned architecture as all PHI.
9. International users
Adentris is built and operated for the United States healthcare market. Data is stored and processed in US data centers. International users accessing the website should expect data to be transferred to and stored in the United States.
10. Changes to this policy
We update this policy as the platform and regulations evolve. Material changes are announced to active customers by email at least 30 days before they take effect.
11. Contact
Privacy questions: privacy@adentris.com.
Security questions: security@adentris.com.
Postal: Adentris, Inc., 15855 Caswell Ln, Reno, NV 89511.