Privacy Policy & Data Protection Practices

Effective Date: July 9, 2026 Last Updated: July 9, 2026

AI Potline LLC (“Company,” “we,” “us,” or “our”) provides software and/or services to healthcare providers, health plans, and other organizations subject to the U.S. Health Insurance Portability and Accountability Act (“HIPAA”). This Privacy Policy explains how we collect, use, and protect information in connection with our website, products, and services.

A note on our role: AI Potline LLC is not a hospital, doctor’s office, health plan, or insurer. When we process health information on behalf of our healthcare or insurance clients, we do so as a Business Associate under HIPAA, governed by a signed Business Associate Agreement (“BAA”) with each client. If you are a patient or plan member with questions about your own medical records, please contact your healthcare provider or health plan directly — they, not us, are responsible for your HIPAA rights (access, amendment, accounting of disclosures, etc.).

1. Scope of This Policy

This Policy covers:

  • Information collected through our website, marketing, and sales process;
  • Information about our direct business clients and their authorized users; and
  • The principles governing how we handle Protected Health Information (“PHI”) on behalf of clients under HIPAA.

This Policy does not replace: (a) the Notice of Privacy Practices our covered-entity clients issue to their own patients or members, or (b) the specific terms of any Business Associate Agreement between us and a client, which governs in case of conflict.

2. Information We Collect

a. Information you provide directly Contact details (name, business email, phone, job title) when you request a demo, contact sales, or subscribe to updates; account and billing details for our direct business customers; support communications.

b. Information collected automatically IP address, browser/device type, pages visited, and similar analytics data from our website, via cookies and similar technologies (Section 6).

c. Protected Health Information (PHI) processed on behalf of clients When our covered-entity clients use our products, we may process PHI strictly as authorized under the applicable Business Associate Agreement. We do not collect PHI directly from patients or members for our own purposes.

3. How We Use Information

Non-PHI information (2a, 2b) is used to operate and improve our services, respond to inquiries, provide support, communicate about products (where permitted), and meet legal obligations.

PHI (2c) is used only as permitted or required by the applicable BAA and HIPAA — never for our own marketing, advertising, or unrelated commercial purposes, and never sold.

4. Our HIPAA Commitments as a Business Associate

  • Permitted uses only — PHI is used/disclosed only as allowed by our BAAs, applicable law, or client authorization.
  • Minimum necessary standard — we limit use, disclosure, and requests for PHI to what’s needed for the contracted service.
  • No sale of PHI, and no use of PHI for marketing without proper authorization.
  • Safeguards consistent with the HIPAA Security Rule: encryption in transit and at rest where applicable, role-based access controls, audit logging, employee training, and vendor risk management.
  • Subcontractors who may access PHI are contractually bound to protections at least as strict as ours.
  • Breach notification — we maintain procedures to detect, investigate, and report any breach of unsecured PHI to the affected client without unreasonable delay, per HIPAA and the applicable BAA.
  • Return or destruction of PHI upon termination of a client relationship, unless retention is legally required (in which case protections continue to apply).
  • Audit cooperation — we cooperate with client audits and provide documentation of our compliance where required.

5. Cookies and Tracking Technologies

We use cookies and similar technologies for [site functionality / analytics / marketing — list actual categories]. You can control cookies through your browser settings; disabling some may affect site functionality. [Add cookie consent banner details if serving EU/UK visitors or where required by state law.]

6. How We Share Information

We may share information with: service providers/subprocessors who help operate our business (cloud hosting, analytics, support tools — bound by confidentiality, and by HIPAA-compliant subcontractor agreements where PHI is involved); professional advisors; law enforcement or regulators when legally required; or a successor entity in a merger or asset sale.

We do not sell personal information, as defined under applicable state privacy laws.

7. Data Security

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction, including [encryption, access controls, monitoring, incident response planning — list actual measures]. No system is completely secure; we encourage you to also take reasonable steps to protect your own information.

8. Data Retention

Non-PHI information is retained as long as necessary for the purposes in this Policy, to meet legal obligations, and to resolve disputes or enforce agreements. PHI is retained and disposed of according to the applicable BAA and HIPAA requirements.

9. Your Privacy Rights

Depending on your state of residence, you may have rights to know what personal information we collect, request its correction or deletion, and opt out of certain sharing (e.g., under the California Consumer Privacy Act and similar laws in other states). These rights apply to the information in Sections 2(a)-2(b), not to PHI processed on behalf of clients, which is governed by HIPAA and our BAAs.

Note: some states (e.g., Washington’s My Health My Data Act, Nevada’s consumer health data law) define “consumer health data” broadly and may impose extra obligations depending on what data you collect directly from individuals. Evaluate this with counsel based on your actual data flows.

To exercise applicable rights, contact us using Section 13.

10. Children’s Privacy

Our website and services are directed at businesses and are not intended for children under 13 (or 16, where applicable). We do not knowingly collect personal information from children.

11. International Data Transfers

[Include only if relevant] If information is transferred outside the United States, we take steps designed to ensure it receives appropriate protection consistent with applicable law.

12. Changes to This Policy

We may update this Privacy Policy periodically. Updates will be posted here with a revised “Last Updated” date. Material changes will be communicated as required by law or contract.

13. Contact Us

AI Potline, LLC
131 Continental Dr, Suite 305, Newark, Delaware 19713

For HIPAA security incidents or Business Associate Agreement inquiries:
info@aipotline.com

How Can We Help You?

Need to bounce off ideas for an upcoming project or digital campaign? Looking to transform your business with the implementation of full potential digital marketing?

For any career inquiries, please visit our careers page here.