LEGAL & COMPLIANCE

Privacy Policy

Last revised: August 18, 2026

1. Information We Collect

We collect minimal data required to build and deploy custom enterprise integrations and AI pipelines. This includes: organizational contact data, secure api access tokens explicitly provided by clients, and server telemetry logs necessary to maintain system uptime.

2. Zero-Trust Data Retention

We enforce strict zero-retention policies across all custom AI streams and large language model pipelines. Customer dataset interactions, prompt payloads, and clinical session recordings are processed in memory and never stored, sold, or used to train public foundation models.

3. Data Security & Encryption Protocols

All information is protected using industry-standard TLS 1.3 cryptographic encryptions in transit and AES-256 encryptions at rest. Access control relies on strictly audited hardware security modules (HSM) and automated IAM principle credentials.

4. Third-Party Service Integrations

Our applications communicate with EHR APIs, cloud services, and database providers (such as Epic, AthenaHealth, Twilio, DailyCo, AWS, and Azure) only under strict, client-approved system roles and BAA compliance agreements.

5. Updates to This Policy

We may revise this policy periodically. We will notify registered administrators of any changes by updating the last revised date at the top of this document.

Security & Privacy Questions?

If you have questions about data processing, encryption protocols, or BAA compliance, contact our security administration directly at: contact@ace78.tech.