Vero Scribe Privacy Policy
Last Updated: October 2024
Introduction
Vero Scribe Inc. ("Vero Scribe", "we", "our", "us") is committed to protecting the privacy and security of the information we collect and process. This Privacy Policy governs the collection, use, disclosure, and protection of information obtained through our website (www.veroscribe.com), the Vero Platform, and all related services (collectively, the "Services").
This policy is intended to provide a clear understanding of our data practices. By accessing or using our Services, you signify your acknowledgment and consent to the terms of this Privacy Policy.
1. Definitions
- Practitioner: A qualified medical practitioner, their associated medical clinic, or other licensed health professional who uses our Services.
- Patient: An individual whose information is processed through the Platform by a Practitioner.
- Personal Information: Any information relating to an identified or identifiable natural person. This may include, but is not limited to, names, contact details, and professional credentials.
- Sensitive Health Information: A specific category of Personal Information related to the health of an individual, including medical history, clinical notes, diagnoses, and treatments. In some jurisdictions, this may be referred to as Protected Health Information (PHI).
- Platform: The proprietary Vero Scribe software and service provided to Practitioners.
- Privacy Laws: All applicable international, federal, state, and provincial privacy and data protection laws and regulations governing our handling of Personal and Sensitive Health Information.
2. Information We Collect and Process
In the course of providing our Services, we collect and process the following categories of information:
-
Personal and Professional Identifiers Information that can be used to identify you, such as your full name, email address, phone number, physical address, and date of birth. For Practitioners, this also includes professional details such as qualifications, medical registration numbers, and educational background.
-
Payment and Transactional Information Financial information required to process payments for our Services, including credit card details, bank account information, and details related to medical billing and claims.
-
Sensitive Health Information We process Sensitive Health Information about Patients as provided by Practitioners through the Platform. This is essential for the core functionality of our Services. This information may include medical histories, clinical notes, laboratory results, diagnoses, prescribed medications, and other treatment-related data.
All Sensitive Health Information undergoes a pseudonymization process, where direct personal identifiers are removed to protect individual privacy. This information is retained only for the duration specified by the Practitioner.
Under no circumstances is Patient data or Sensitive Health Information used to train, develop, or improve any of our proprietary AI models.
-
Device and Usage Data Technical information collected automatically when you interact with our Services, including device ID, device type, IP address, geo-location data, connection information, page view statistics, and standard web log data.
-
User-Provided Content Any additional information you voluntarily provide to us through customer support channels, surveys, or direct correspondence.
-
Aggregated and De-Identified Data We may de-identify and aggregate Personal Information to perform statistical analysis on service usage and performance. This data does not identify any individual and is used exclusively for internal business improvement and service optimization.
-
Recruitment Information If you apply for a position at Vero Scribe, we collect information relevant to your application, including your resume, employment history, contact details, and information from professional references.
3. Methods of Information Collection
We collect information from the following sources:
- Information You Provide Directly: We collect information when you register for an account, communicate with our team, or otherwise interact directly with our Services.
- Information from Your Use of the Services: We automatically collect technical and usage data when you access and navigate the Platform and our website.
- Information from Third-Party Sources: We may collect information from third parties, such as recruitment agencies or publicly available professional registries, in accordance with applicable laws.
4. Purposes for Which We Use Information
We use the information we collect for the following business and commercial purposes:
- To Provide and Maintain the Services: To enable your access to the Platform, manage user accounts, and deliver the core functionalities of our Services.
- To Facilitate Healthcare Delivery: To process Sensitive Health Information on behalf of Practitioners to assist them in their provision of care to Patients.
- For Research, Development, and Service Enhancement: To analyze usage patterns, improve the user experience, and develop new features and capabilities for the Platform. This purpose explicitly excludes the use of any Patient data or Sensitive Health Information for AI model training.
- For Communication: To send administrative messages, technical notices, security alerts, and support responses.
- To Comply with Legal Obligations and Law Enforcement: To adhere to applicable laws, regulations, and legal processes, and to respond to lawful requests from government or law enforcement agencies.
- For Security and Fraud Prevention: To protect the security and integrity of our Platform, our users, and our business.
- For Recruitment: To evaluate and process your application for employment with Vero Scribe.
5. Marketing Communications
Vero Scribe may periodically send communications regarding our products, services, and important updates. We distinguish between two types of communications:
- Service-Related Communications: These are essential transactional messages related to your account, security, and use of the Services (e.g., password resets, security alerts). You cannot opt out of these communications.
- Promotional Communications: These are marketing messages about new features or services. You may opt out of receiving promotional communications at any time by following the unsubscribe instructions included in each communication or by contacting us directly.
We do not sell your Personal Information to third parties for their own marketing purposes.
6. Data Storage and International Transfers
Vero Scribe implements data localization solutions for customers in Canada and the United States, storing data within their respective geographical regions.
Certain functionalities of our Platform may rely on third-party service providers whose servers are located in other countries. In such cases, we execute legally binding Data Processing Agreements (DPAs) that obligate these providers to adhere to data protection standards equivalent to or greater than our own, ensuring the security and lawful processing of your information.
7. Disclosure of Information
We do not sell your Personal Information. We may disclose your information to the following categories of third parties for legitimate business purposes:
- Service Providers: Third-party vendors who perform services on our behalf, such as cloud hosting, payment processing, and data analytics. These providers are contractually obligated to protect your information and may only use it for the purposes we specify.
- Corporate Affiliates: Our subsidiaries and related corporate entities, for purposes consistent with this Privacy Policy.
- As Required by Law: Government authorities, law enforcement, or other third parties when we are compelled to do so by a subpoena, court order, or other legal process.
- To Protect Our Rights: Where we believe disclosure is necessary to prevent physical harm or financial loss, to report suspected illegal activity, or to investigate violations of our agreements.
8. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance user experience, track website usage, and remember user preferences. You may control the use of cookies at the individual browser level, but disabling them may limit your use of certain features. We also utilize third-party analytics tools to understand service usage; however, no Sensitive Health Information is ever shared with or processed by these tools.
9. Data Security Measures
We have implemented and maintain a comprehensive security program designed to protect your information from unauthorized access, disclosure, alteration, and destruction. Our security measures include, but are not limited to:
- Encryption: All data is encrypted both at rest and in transit using industry-standard cryptographic protocols.
- Access Controls: Strict role-based access controls are enforced to ensure that personnel can only access information necessary to perform their duties.
- De-identification and Pseudonymization: We utilize technical tools to de-identify and pseudonymize data where appropriate to reduce privacy risks.
- Regular Security Audits: We conduct regular internal and external security assessments to identify and mitigate vulnerabilities.
- Secure Data Handling: We maintain policies and procedures for the secure handling and disposal of information throughout its lifecycle.
10. Your Rights and Controls
Depending on your jurisdiction, you may have the following rights regarding your Personal Information:
- Right of Access: The right to request a copy of the Personal Information we hold about you.
- Right to Rectification: The right to request the correction of inaccurate or incomplete Personal Information.
- Right to Erasure: The right to request the deletion of your Personal Information, subject to legal and contractual retention obligations.
To exercise your rights, please submit a verifiable request to us via the contact details below. We will respond to your request within the timeframe required by applicable law. We may require you to verify your identity before processing your request.
11. Updates to This Privacy Policy
We reserve the right to amend this Privacy Policy at our discretion and at any time. When we make changes, we will post the updated notice on our website and update the policy's "Last Updated" date. Your continued use of our Services following the posting of changes constitutes your acceptance of such changes.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: hello@veroscribe.com