Privacy Statement
Effective Date November 28, 2024
Introduction
Cofactor AI, Inc. (“Cofactor AI”, “we”, or “us”) is a Delaware corporation that builds AI-powered revenue cycle integrity software for healthcare organizations.
We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Cofactor AI Privacy Statement (this “Privacy Notice”) describes how Cofactor AI may collect, use, store, disclose, and process your personal information, through your access to or use of Cofactor AI products and services, including those at https://www.cofactorai.com/, related websites, and other offerings (collectively, the “Services”). By using the Services, you signify your acceptance of this Privacy Notice. If you do not agree to this Privacy Notice, please do not use the Services. We recognize that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Notice as we undertake new personal data practices or adopt new privacy policies. We will update this Privacy Notice by posting changes at this URL, https://www.cofactorai.com/privacy, and we may send notification emails regarding such changes. Your continued use of the Services will be deemed to be your acceptance of those changes.
Privacy Notice Applicability
This Privacy Notice applies when you access the Services or share information with Cofactor AI. Please note that this Privacy Notice applies only to the Services and not to any other third-party website linked to or from it, or any third-party website in which Cofactor AI content or functionality is embedded. We do not control the privacy policies or practices of others.
How We Collect and Use (Process) Your Personal Information
In general, Cofactor AI collects personal information about its users and customers through the information you provide via the Services, including through website and software input fields, phone, email, web chat, or in other such way. This information includes, but is not limited to:
uired in order for you to access certain functionality of the Services, such as those mentioned above or for tracking your preferences, subscribing to a newsletter, or initiating other such actions.
In general, Cofactor AI collects personal information about its users and customers through the information you provide via the Services, including through website and software input fields, phone, email, web chat, or in other such way. This information includes, but is not limited to:
· Profile or contact data: first and last name, email, phone number, unique identifiers such as usernames, passwords, and signature;
· Demographic data: age/date of birth, zip code, postal address, emails;
· Personal health information: information provided to your care provider, information pertaining to your symptoms, medical history, and diagnosis, health status, test results, and other medical records (“Medical History”);
· Device/IP data: IP address, device ID, browser type, information collected automatically through cookies and similar technology, device type, domain names, and access time/logs;
· Web analytics: web page interactions, referring webpages/source through which you accessed the Services; non-identifiable request IDs; statistics associated with the interaction between device or browser and the Services; and
· Inferences drawn from other personal data: profiles reflecting user attributes, profiles reflecting user behavior, inferences about preferences or aptitudes.
We use this information to provide the Services to you. You have the choice on what information to share and the Services you want to engage. You can choose not to provide information to us, but in general some information about you is required in order for you to access certain functionality of the Services, such as those mentioned above or for tracking your preferences, subscribing to a newsletter, or initiating other such actions.
From time to time, the Cofactor AI receives personal information about individuals from third parties, including affiliated entities, partners, and other independent third-party sources. Typically, information collected from third parties may include further details on your Medical History, use of the Services, and updated demographic information. We may also collect your personal data from a third-party website (e.g., LinkedIn).
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to this email.
Additionally, you may provide personal information to us to facilitate your access to and interaction with a third-party provider, such as your care provider, (“Third-Party Providers”) and the Third-Party Provider may provide us your personal information to facilitate the Services. Third-Party Providers are the administrators of your data when it is provided to and processed on the Services. If you direct us to provide personal information and/or your Medical History to such Third-Party Provider or permit the Third-Party Provider to provide such information to Cofactor AI, any usage of that information will be subject to the agreement(s) in place between you and such Third-Party Provider. We are not a party to that agreement, and any concerns you have outside of the information stated in this Privacy Notice must be directed to the Third-Party Provider.
Cookies
Cookies, also known as tracking cookies or browser cookies, and similar technologies such as web beacons, clear GIFs, pixel tags, and JavaScript (collectively, “Cookies”) are small pieces of data, usually text files, placed on a computer, tablet, phone, or similar device when you use that device to access the Services. We use the following types of Cookies:
-
Essential Cookies. Essential Cookies are necessary for providing you with the Services and features that you requested. For example, these Cookies allow you to log into and stay logged into secure areas of the Services, save language preferences, and more. These Cookies are required to make the Services available to you, so they cannot be disabled.
-
Functional Cookies. Functional Cookies are utilized to record your choices and settings, maintain your preferences over time, and recognize you when you return to our Services. These Cookies help us personalize our content for you, greet you by name, and remember your preferences, and more.
-
Performance/Analytical Cookies. Performance/Analytical Cookies allow us to understand how visitors (like you) use the Services. These Cookies accomplish this by collecting information about the number of visitors to the Services, what pages visitors view the most, and how long visitors view specific pages. These Cookies also help us measure and manage the performance of our advertising campaigns in order to help us improve the campaigns and the Services’ content.
You have the option to decide through your internet browser’s settings whether or not to accept Cookies. Most browsers allow users to choose whether to turn off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the browser) allow you to toggle whether to accept each new Cookie. You can also clear all Cookies that are already on your device. If you do this, however, you may have to manually adjust some preferences every time you visit the Services, and some functionalities may not work. To explore what Cookie settings are available to you, look in the “settings”, “preferences” or “options” section of your browser’s menu.
To find out more information about Cookies, including information about how to manage and delete Cookies generally, please visit http://www.allaboutcookies.org/.
Use of the Services
Cofactor AI’s website and the Services collects certain information automatically and stores it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system, and other usage information about the use of Services. We use this information to help us design the Services to better suit our users’ needs. We may also use your IP address to help diagnose problems with our server and to administer our website, analyze trends, track visitor movements, and gather broad demographic information that assists us in identifying visitor preferences.
Cofactor AI has a legitimate interest in understanding how members, customers and potential customers use its website. This assists Cofactor AI with optimizing the Services, providing more relevant products and services, communicating value to our sponsors, customers, and corporate members, and providing appropriate staffing to meet you and our customer’s needs.
We may use cookies (including HTTP cookies, HTML5 cookies, and Flash cookies), log files, device identifiers, and similar tracking technologies as well as other cloud-based tools to automatically collect your preferences, performance data, and information about your web usage when you visit the Services. The Services are not designed to recognize or respond to “do not track” signals received from browsers. You can control the information collected by such tracking technologies or be alerted when cookies are sent by adjusting the settings on your Internet browser or devices, but such adjustments may affect or disable certain functionality of the Services. You can learn more about targeted ads and your ability to opt out of receiving interest-based ads at optout.aboutads.info and www.networkadvertising.org/choices.
How We Use Your Data
We process your personal information with your consent or as needed to provide you the Services. We may also use your personal information to comply with legal obligations, operate our business, protect the vital interests of you, our customers, or the public, or for other legitimate interests of Cofactor AI as described in this Privacy Notice. This may include sharing information with third parties.
More specifically, we may use your personal information to:
-
Optimize and improve the Services - We continually try to improve the Services based on the information and feedback we receive from you, including by optimizing the content on the Services.
-
Personalize the user experience - We may use your information to measure engagement with the Services, and to understand how you and our other users interact with and use the Services and other resources we provide.
-
Improve customer service - Your information helps us to more effectively develop the Services and respond to your support needs.
-
Process transactions - We may use the information you provide about yourself to fulfill your requests. We do not share this information with outside parties except to the extent necessary to provide the Services and related activities.
-
To send periodic emails - The email address you provide through our contact forms, will be used to send information and updates pertaining to the Services. It may also be used to respond to your inquiries or other requests. If you opt in to our mailing list, you may receive emails that include Cofactor AI news, updates, related product offerings and service information, and marketing material. If at any time you would like to unsubscribe from receiving future emails, we include detailed unsubscribe instructions at the bottom of each email or you may contact us via the contact information below.
-
Provide Services to Third-Party Providers - We may communicate with and transfer your information to Third-Party Providers in furtherance of our legitimate business interest with the Third-Party Provider.
We also may share your information:
-
In response to subpoenas, court orders, or other legal process; to establish or exercise our legal rights; to defend against legal claims; or as otherwise required by law. In such cases we reserve the right to raise or waive any legal objection or right available to us.
-
When we believe it is appropriate to investigate, prevent, or take action regarding illegal or suspected illegal activities; to protect and defend the rights, interests, or safety of our company or the Services, our customers, or others; or in connection with our Terms of Service and other agreements.
-
In connection with a corporate transaction, such as a divestiture, merger, consolidation, or asset sale, or in the unlikely event of bankruptcy.
We may use any aggregated information (as described below) for any purpose.
Other than as set out above, we will attempt to notify you when your personal information will be shared with third parties.
Aggregated Information. We may publish, share, distribute, or disclose personal information that has been aggregated with information from other users or otherwise de-identified in a manner that does not allow such data about you to be separated and identified as originating from you to third parties, including Cofactor AI partners, sponsors and advertisers. Such information may help Cofactor AI identify and analyze training, demographic, and psychographic trends and information, and report to third parties how many people saw, visited, or clicked on certain content, areas of the Services, ads, or other materials. We may also use such data for research purposes and optimizing the Services’ functionality.
Hosting Your Data
The personal information Cofactor AI collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, Cofactor AI engages third parties to send information to you, including information about our products, services, and events. Cofactor AI complies with applicable data protection laws, including applicable security breach notification requirements.
Cofactor AI currently uses Google Cloud Platform as its third-party sub processor. We reserve the right to change this sub processor at any time. We rely on Google Cloud Platform’s programs to protect personal information while stored in their respective controlled facilities. For more information on Google Cloud Platform’s security practices and processes, please see https://cloud.google.com.
Cofactor AI is headquartered in the United States. Information we collect about you will be processed in the United States. By using Cofactor AI’s services, you acknowledge that your personal information will be processed in and transferred within the United States.
Cofactor AI takes additional technological and organizational measures to protect your personal information against loss, theft, and unauthorized access, use, disclosure or modification. For example:
-
we transmit data over secured communication channels using SSL Login credentials,
-
all personal information is stored by trusted third party providers (e.g., Google Cloud Platform),
-
all systems used to provide the Services are password protected,
-
all Services usage is restricted on a per-user basis on the principle of least privilege, and
-
all data is encrypted while at rest and during transfer.
For more information or if you have any questions, please contact us at privacy@cofactorai.com.
Data Subject Rights
To the extent provided by the law of your jurisdiction, you may:
● Have the right to access certain personal information we maintain about you and request details about how we process it;
● Request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes;
● Request that we update or correct inaccuracies in that information;
● Object to our use of your personal information;
● Ask us to block or delete your personal information from our database;
● Request to download the information you have shared on the Services; and
● Confirm whether Cofactor AI transfers and stores your data in the United States.
This Privacy Notice is intended to provide you with information about what personal data Cofactor AI collects about you and how it is used.
If you wish to confirm that Cofactor AI is processing your personal data, or to have access to the personal data Cofactor AI may have about you, please contact us at privacy@cofactorai.com.
Reasonable access to your personal data will be provided at no cost. If access cannot be provided within a reasonable time frame, Cofactor AI will provide you with an approximate date when the information will be provided. If for some reason access is denied, Cofactor AI will provide an explanation as to why access has been denied.
For questions or complaints concerning the processing of your personal data, you can email us at privacy@cofactorai.com.
California Resident Privacy Rights
California Civil Code Section 1798.83 permits our customers who are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please e-mail us or write to us at the addresses below.
Data Storage and Retention
Cofactor AI will retain your information as long as necessary for the purposes outlined in this Privacy Notice, in a manner consistent with our data retention policy discussed herein, and for a commercially reasonable time thereafter for backup, archival, fraud prevention or detection or audit purposes or as permitted by applicable law. Cofactor AI will retain your personal information consistent with the original purpose of collection or as long as necessary to comply with our legal obligations; maintain accurate accounting, financial and other operational records; resolve disputes; and enforce our agreements. We will never retain your information for a period longer than permitted by law.
We determine the appropriate retention period for personal information on the basis of the amount, nature, and sensitivity of the personal information being processed; the purpose for which it was collected; the potential risk of harm from unauthorized use or disclosure of the personal information; whether we can achieve the purposes of the processing through other means; and applicable legal requirements.
After expiration of the applicable retention periods, your personal information will be deleted.
Children's Data
The Services are not directed to children, and you may not use the Services or provide any personal information to Cofactor AI if you are under the age of 18 (or the lowest age permitted by applicable law) or if you are not old enough to consent to the processing of your personal information in your jurisdiction. To our knowledge, we do not collect or process personal information of individuals under the age of 18 or the lowest age permitted by applicable law unless we receive all necessary consents from the individual’s parent or guardian. To our knowledge, we do not sell or process for the purposes of targeted advertising the personal information of minors under 18 years of age.
Questions, Concerns, or Complaints
If you have questions, concerns, complaints, or would like to exercise your rights, please contact us at:
Cofactor AI, Inc.
Attn: Privacy Department
215 N Peoria St
Suite 8
Chicago, IL 60607