Privacy Policy
Effective date: August 18, 2025
Vital Audio Systems Inc. ("Vital Audio," "we," "us," or "our") builds software classified as Software as a Medical Device (SaMD) that extracts cardiopulmonary measurements from short voice clips and related signals. We provide our technology to healthcare organizations and research partners and, in some cases, interact directly with individuals ("you").
This Privacy Policy explains what information we collect, how we use and share it, and your rights and choices. It is written to meet or exceed requirements under U.S. federal and state privacy laws (including HIPAA and state consumer health and biometric laws), and international laws such as the GDPR/UK GDPR, where applicable.
Important role clarification
- • When we process Protected Health Information (PHI) on behalf of a healthcare provider or health plan, we act as a Business Associate under HIPAA, and our processing is governed by a Business Associate Agreement ("BAA"). In those situations, the provider or plan is the Covered Entity and controls the use of PHI.
- • When we collect personal information directly from you (e.g., through our website, pilot enrollment forms, or research studies we sponsor), we act as a data controller (GDPR/UK GDPR) or a business (state privacy laws) for that data.
- • We do not share mobile contact information with third parties or affiliates for marketing or promotional purposes. Information may be shared with subcontractors in support services, such as customer service. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
1) Scope
This Policy applies to: (a) our public websites and portals; (b) our SaMD platform and services; (c) communications by phone, SMS, and email; and (d) research or product-improvement programs we conduct or sponsor. This Policy does not replace a HIPAA Notice of Privacy Practices provided by your healthcare provider. If there is a conflict between a provider's Notice and this Policy with respect to PHI we process for that provider, the provider's Notice and our BAA prevail.
2) Information we collect
We collect the following categories of information (exact fields depend on the deployment and your provider's configuration):
Account & contact
- • Name, email, phone number, role, organization
- • Authentication identifiers (e.g., user ID), access logs, device/browser metadata (e.g., IP address, user agent)
Clinical & program enrollment
- • Patient identifiers permitted by HIPAA minimum necessary, e.g., MRN, treatment unit, care team
- • Demographics permitted/required by the Covered Entity (e.g., DOB, sex at birth)
Audio, voice & sensor-derived data
- • Short voice clips captured during calls, and optional environmental audio if enabled
- • Derived features and outputs: heart rate (HR), blood pressure (BP), heart rhythm regularity/irregularity, heart rate variability (HRV), respiratory rate (RR), and quality metrics
- • Timestamps, session metadata, telephony routing and quality-of-service data
Support & operations
- • Communications with us (support tickets, emails, call recordings where legally permitted)
- • Audit logs, access logs, and security telemetry (e.g., failed logins, API usage)
Website & analytics
- • Cookie or similar identifiers; coarse geolocation (from IP), pages viewed, referrers
- • We do not use cross-context behavioral advertising or sell personal information
Research/feedback (optional)
- • Study participation records, survey responses, and additional consents you give
- • If we ever use data beyond care operations, we obtain an appropriate written consent/authorization (or IRB approval and waiver, as applicable)
Biometric information
We do not create or store biometric identifiers (e.g., face templates, voiceprints) for identity verification or authentication. We extract physiological features from short audio to compute health metrics and discard any features that could be used to re-create your voiceprint. If a deployment requires biometric matching (rare), we will obtain the written consent and publish a retention schedule before enabling it.
3) Sources of information
- • You, your authorized representative, or your healthcare provider
- • Telephony carriers and communications service providers used to connect a call
- • Our platform components (application, logs, and security tools)
- • Third-party vendors acting on our behalf (e.g., cloud hosting, analytics)
- • Public sources (e.g., NPI registry) to validate provider identities
4) How we use information
We use information as permitted by law and contract to:
- Deliver our services: place/receive text messages and calls; capture short video, audio and voice clips; compute and return cardiopulmonary metrics; display results in dashboards or secure messages; and provide integrations (e.g., into EHRs).
- Operate, secure, and improve: maintain uptime; detect, prevent, and investigate abuse, fraud, or security incidents; conduct troubleshooting and quality assurance; optimize signal processing and ML performance.
- Support care operations: scheduling, care-team notifications, training, and credentialing of users.
- Comply with law: respond to lawful requests, perform audits, meet medical-device obligations (e.g., post-market surveillance, adverse event reporting).
- Research & product improvement (optional): only with appropriate consent/authorization or IRB approval, we may use de-identified or limited datasets to validate algorithms and improve clinical utility.
- Communications: provide service, safety, and account notices; respond to your requests. We do not use PHI for marketing without your written authorization.
5) Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, our legal bases include: contract performance, legitimate interests (e.g., security, service improvement; balanced against your rights), consent (where required), legal obligations, and, for special-category data, healthcare and public interest in public health (Articles 9(2)(h),(i)), or explicit consent. We rely on controller–processor agreements with healthcare customers when acting as a processor/Business Associate.
6) Sharing & disclosures
We share information only as needed, under contract, and with safeguards:
- • Your healthcare provider or study sponsor: to deliver clinical services or research per their instructions.
- • Vendors/Processors (subprocessors): cloud hosting, security monitoring, telephony and messaging, analytics, and support. We execute DPAs/BAAs as required, require strong security (e.g., SOC 2/ISO 27001 or equivalent controls), and restrict use to our documented purposes.
- • Affiliates: for internal operations under this Policy.
- • Legal & safety: to comply with law, prevent harm, or protect rights.
- • Business transfers: in a merger, acquisition, or asset sale, subject to continued protections and notices.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We prohibit our processors from re-identifying de-identified data or using personal information for their own marketing.
7) Retention
We keep information only as long as necessary for the purposes above or as required by law/contract:
- • Raw audio from clinical capture: processed in memory and not retained by default. If enabled for quality review, retained no longer than 30 days then automatically deleted, unless a longer period is required by a customer contract or legal hold.
- • Derived metrics & reports: retained per the customer's record-retention policy (often 7–10 years for medical records) or for the duration of our contract plus allowed archival period.
- • Research data: per protocol and regulatory requirements (e.g., at least 2 years after last marketing application approval or study completion, whichever is later), and then de-identified or deleted.
- • Audit & security logs: 12–24 months unless needed longer for investigations.
- • Backups: encrypted, with automated deletion in ≤ 35 days (rolling).
- • Website analytics cookies: per cookie banner settings and browser controls.
Where specific laws require shorter retention (e.g., biometric data laws) or a public retention policy, we follow those rules and publish or link to the schedule.
8) De-identification and limited datasets
We support HIPAA Safe Harbor and Expert Determination de-identification methods. De-identified data will not be used to attempt re-identification. For limited datasets under HIPAA, we enter into a data use agreement and restrict uses to research, public health, or healthcare operations.
9) Your privacy rights
Your rights depend on your relationship with us and applicable laws.
Under HIPAA (PHI processed for a provider):
Request access and copies; request amendments; obtain an accounting of certain disclosures; request restrictions; and request confidential communications. Submit requests through your provider (Covered Entity). If you contact us directly, we will coordinate with the provider as required by our BAA.
Under U.S. state privacy laws (non-PHI personal information):
You may have rights to access, correct, delete, obtain a portable copy, opt out of sale/share/targeted advertising, and limit the use of sensitive personal information. See Section 12 for state-specific notices.
Under GDPR/UK GDPR:
Rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (where we rely on consent). You also have the right to lodge a complaint with your supervisory authority.
To exercise rights: use our web form at [privacy portal URL], email privacy@vitalaudio.io, or mail Attn: Privacy Officer, Vital Audio Systems Inc., [Postal Address]. We will verify your identity, respond within the legal timeframe, and never discriminate for exercising your rights.
10) Cookies and analytics
We use strictly necessary cookies for security and session management. With your consent, we may use functional or performance analytics to improve our website. You can manage preferences through our cookie banner and your browser settings. We do not use third-party advertising cookies.
11) Security safeguards (defense in depth)
We implement administrative, technical, and physical safeguards proportionate to the sensitivity of the data and aligned to frameworks such as NIST 800-53/CSF, ISO/IEC 27001, and HICP. Core controls include:
Administrative
- • Governance: designated Privacy Officer and Security Officer; policies reviewed at least annually
- • Workforce: background checks; least-privilege access; mandatory security & privacy training; sanctions for violations
- • Risk management: enterprise risk register; third-party risk management; BAAs/DPAs; change management; business continuity and disaster recovery plans
- • Incident response: 24×7 monitoring, documented IR plan with defined SLAs, breach notification workflows
Technical
- • Encryption: TLS 1.2+ in transit; AES-256 at rest in databases and backups
- • Access control: SSO and MFA; role-based access; device posture checks; time-bound elevated access via just-in-time approvals
- • Network & app security: segmentation; WAF; rate limiting; secure SDLC (SAST/DAST/OSS scanning); code review; signed builds; secrets management
- • Data protection: minimal collection; ephemeral processing of raw audio; field-level encryption where appropriate; pseudonymization; comprehensive audit logging with tamper detection
- • Monitoring: centralized logging and alerting; vulnerability management; regular penetration testing by independent assessors
Physical
- • Data centers managed by vetted providers with industry certifications; restricted access; environmental and power redundancy
12) U.S. state-specific notices
Depending on where you live, the following laws may grant additional rights or impose obligations on us. We align our practices as follows:
- • California (CCPA/CPRA): we do not sell or share personal information for cross-context behavioral advertising. We honor opt-out signals, including GPC, where required. California residents can request access, deletion, correction, and restriction of sensitive personal information usage.
- • Washington (My Health My Data Act): when acting as a regulated entity for consumer health data, we obtain affirmative opt-in consent for collection and separate consent for sharing; we do not use geofencing to identify, track, or target consumers near health facilities; and we publish a consumer health data policy describing categories, purposes, and sharing.
- • Nevada (SB 370 – Consumer Health Data Privacy): we provide a clear notice of consumer health data processing and obtain separate consents for collection/sharing; sale requires written authorization.
- • Biometric laws (e.g., IL BIPA, TX CUBI, WA biometric law): if a deployment requires biometric identifiers, we will provide a public retention and destruction schedule, obtain written informed consent before collection, restrict use to stated purposes, prohibit sale, and implement reasonable safeguards.
Other comprehensive privacy laws (e.g., CO, CT, VA, UT, OR, TN, IN, IA, MT, TX, NJ, MN and others) grant similar rights; we comply as applicable and will maintain state-specific addenda on request.
13) International data transfers
If you are located outside the U.S., we may transfer your information to the U.S. or other countries where we or our vendors operate. We use approved transfer mechanisms (e.g., Standard Contractual Clauses and required assessments). Where we store data in your region at your provider's request, we will document that configuration contractually.
14) Children's privacy
Our services are not directed to children under 13 for direct sign-up. If your provider enrolls a minor, we process PHI as a Business Associate under the provider's direction and applicable minor-consent laws. If we learn that we collected personal information directly from a child under 13 without parental consent, we will delete it.
15) Call recordings & two-party consent
We do not record calls for marketing. For support and quality assurance, recordings—if enabled—are announced with clear notice and observable indicators, and we comply with one-party or all-party consent laws in the relevant jurisdiction. You may decline or request deletion where permitted by law and contract.
16) Automated decision-making & profiling
Our SaMD outputs are decision-support metrics intended to aid clinicians. We do not make fully automated decisions that produce legal or similarly significant effects about individuals without human involvement.
17) Do-not-track, opt-out, and preference signals
Your browser may send Global Privacy Control (GPC) or similar signals. Where required, we treat such signals as a valid opt-out of sale/share. You can also adjust cookie preferences in our banner.
18) How we protect your data during vendor use
We maintain a current list of subprocessors on request. Typical categories include: (i) cloud infrastructure; (ii) telephony and messaging; (iii) observability and security operations; (iv) customer support; and (v) email delivery. We require contractual confidentiality, security, and flow-down of restrictions (including BAAs/DPAs). We conduct risk assessments before onboarding and at regular intervals.
19) Breach notification
We maintain and test incident response plans. Where required by law or contract, we will notify affected customers and/or individuals without undue delay and within mandated timeframes. When acting as a Business Associate, we notify the Covered Entity and cooperate with their obligations to notify individuals, regulators, and (if applicable) the media.
20) Changes to this Policy
We may update this Policy to reflect changes in technology, laws, or our services. We will post updates with a new effective date and, where required, provide prominent notice or obtain consent.
21) Contact us
Chief Technology Officer
Vital Audio Systems Inc.
If you are in the EEA/UK and wish to contact our EU/UK representative or Data Protection Officer (if designated), please write to the Privacy Officer using the details above and your request will be routed accordingly.
Appendix A — High-assurance choices we've made (closing common gaps)
- Raw audio is ephemeral by default and automatically purged in ≤30 days if quality review is enabled; only derived cardiopulmonary metrics persist.
- No sale or cross-context advertising; analytics limited to service improvement.
- State health & biometric compliance baked in: when deployments occur in states with My Health My Data or biometric laws, we obtain separate consents, publish retention schedules, prohibit geofencing, and restrict use to stated purposes.
- Minimum necessary PHI: our default data model excludes identifiers not needed for the clinical workflow; customer-specific fields are gated behind explicit configuration.
- Research segregation: research datasets are consent-gated, access-controlled, and logically separated from production care data; linkage keys stored separately.
- Subprocessor governance: BAAs/DPAs with all PHI processors; annual security attestations; right to audit; immediate suspension for material findings.
- Verified deletion: cryptographic erasure procedures for backups and logs; deletion runbooks with evidence capture for audits.
- User rights portal: unified intake to route HIPAA, state-law, and GDPR requests with identity verification flows.
- Two-party consent compliance: call recording off by default; where enabled, multi-jurisdiction consent prompts and audio/visual indicators.
- No biometric templates: our pipeline discards features that could reconstruct a voiceprint; if a client requests biometric matching, we require written consent, a public retention schedule, and deploy a separate, consent-gated module.
Appendix B — Data inventory & retention matrix (summary)
| Category | Examples | Purpose | Legal basis/authority | Default retention |
|---|---|---|---|---|
| Account & auth | Name, email, role, user ID, logs | Access control, support | Contract; legitimate interests | Life of account + 1 year |
| Clinical capture (raw audio) | Short voice clips | Compute metrics, QA (optional) | Healthcare ops; consent | Ephemeral; ≤30 days if QA enabled |
| Derived metrics | HR, HRV, RR, flags | Clinical decision support | Healthcare ops; public interest; contract | Contract term + 7–10 yrs (per customer policy) |
| Telephony/session metadata | Timestamps, call path | Reliability, security | Legitimate interests | 12–24 months |
| Research data | Consented datasets | Validation, R&D | Consent/IRB | Per protocol; then delete/de-identify |
| Security logs | Auth events, alerts | Security, audit | Legal obligation; legitimate interests | 12–24 months |
| Backups | Encrypted snapshots | DR/BCP | Legitimate interests | ≤35 days rolling |
Appendix C — State-specific addendum (model language)
California residents: you have the right to know the categories and specific pieces of personal information we collected, sources, purposes, categories of third parties, and whether we sell/share data (we do not). You may request deletion, correction, portability, and to limit use/disclosure of sensitive personal information. Use our rights portal or email privacy@vitalaudio.io. We will verify requests and respond within statutory timelines. Authorized agents may submit requests with proof of authority.
Washington residents: we provide a Consumer Health Data policy describing categories, purposes, sharing, and how to exercise rights. We obtain separate consents for collection and sharing and written authorization for sale (we do not sell). We do not use geofencing near healthcare facilities.
Nevada residents (SB 370): separate consents for collection and sharing of consumer health data. Written authorization required for sale (we do not sell).
Illinois residents (BIPA): if biometric identifiers are ever collected (not our default), we will publish a retention and destruction schedule, obtain written informed consent, restrict use to stated purposes, and maintain reasonable security.
We will extend materially similar rights to residents of other comprehensive privacy-law states (CO, CT, VA, UT, OR, TX, TN, IN, IA, MT, NJ, MN, etc.) where applicable.
Appendix D — Contact points for regulators
U.S.: If you believe your HIPAA rights were violated, you may file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR).
EEA/UK: You may lodge a complaint with your local supervisory authority. We will provide the appropriate contact on request.
This Privacy Policy is designed to be comprehensive yet adaptable to customer-specific configurations and evolving laws. For questions or to request a signed copy, contact the Privacy Officer noted above.