Privacy Notice — Enterprise Clients
Last Updated: May 28, 2025
This Privacy Notice applies to healthcare systems, EMS agencies, and other enterprise partners using vitalvoice.ai under a commercial agreement or pilot program.
1. Information We Collect
- Account & Admin Info: Name, organization, email, usage admin settings.
- Interpreter Session Metadata: Language detected, timestamps, session IDs, user IDs.
- Transcripts: Interpreted text transcripts are stored for audit, compliance, and QA purposes.
- Voice Input: Not stored. Processed in real-time only.
- Device Data: Technical details to support service and security.
2. Transcript Handling
- Transcripts are stored encrypted by default for up to 90 days.
-
Your organization can:
- Access and download transcripts
- Request early deletion
- Set a shorter auto-deletion period
- Users may request deletion of their transcripts through their administrator.
3. HIPAA & BAA Compliance
We act as a Business Associate under HIPAA and support BAA execution with all Covered Entities. Security includes:
- End-to-end encryption (TLS 1.3)
- Role-based access
- Comprehensive audit logs
4. Data Localization and Security
- All data is stored in the U.S. on HIPAA-aware infrastructure.
- We do not store or transfer data outside the United States unless explicitly required or authorized.
5. Subprocessors
We work with subprocessors including OpenAI, LiveKit, Stripe, Render, GitHub, ChatGPT (OpenAI API), and Apple Developer Program. A full list is maintained at vitalvoice.ai/privacy/subprocessors.
6. Incident Response
In the event of a data breach, we will notify affected clients and relevant authorities per HIPAA timelines.
7. Contact
hello@vitalvoice.ai
vitalvoice.ai Inc., San Diego, CA, USA