01
Scope and contract hierarchy
This Privacy Policy explains how Cardon Health handles information collected through our public website, demo and sales conversations, account administration, and product workflows.
When a customer uses Cardon Health under an order form, pilot agreement, master services agreement, data processing agreement, business associate agreement, or similar written agreement, those documents govern the customer relationship and control if they conflict with this public policy.
- Public website channels are for general inquiries and should not be used to send patient information.
- Product environments may process protected health information only under the applicable customer agreement and BAA.
- Patients who want access to medical records should contact their home-health agency or provider directly.
02
Information we collect
We collect information you provide directly, such as your name, work email, agency, role, phone number, demo request details, support messages, and other business contact information.
For authorized product users, we may process account and security information such as name, email, role, organization membership, session metadata, user agent, IP address, authentication events, passkey or two-factor settings, and invitation status.
In product deployments, Cardon Health may process visit, patient, chart, evidence, QA, consent, audit, delivery, and integration data that customers submit or direct us to process. Depending on the configured workflow, that may include home-visit audio, clinical notes, OASIS answers, evidence spans, wound or medication images, signatures, EHR references, and related operational metadata.
03
Website analytics and device data
The public website uses Google Analytics with IP anonymization, Vercel Analytics, and Vercel Speed Insights to understand traffic, page performance, and reliability. These tools may collect page views, approximate location inferred from network information, browser and device details, referrer, performance metrics, and similar usage data.
Website analytics are separate from product audit logs. Product audit logs exist to support security, access review, chart review, delivery workflows, and customer administration.
04
How we use information
We use information to provide, secure, maintain, and improve Cardon Health; respond to inquiries; schedule demos; administer accounts and organizations; authenticate users; deliver product notifications; support customer workflows; investigate security events; comply with legal obligations; and enforce applicable agreements.
Product data is used to operate the contracted service, including drafting chart content, linking answers to evidence, supporting clinician and QA review, delivering charts to approved destinations, and maintaining auditability. Model improvement or secondary use of customer data, if any, is handled only as allowed by the applicable customer agreement and BAA.
05
Protected health information and HIPAA
Cardon Health is designed for home-health workflows that can involve protected health information. To the extent Cardon Health acts as a business associate for a covered entity or another business associate, we process protected health information according to the applicable BAA, customer instructions, and applicable law.
Cardon Health does not ask visitors to send protected health information through public forms, ordinary email, or other non-approved channels. Customers should use approved product and support channels after the appropriate agreements are in place.
- Customer administrators control authorized users and organization access.
- Clinicians and agencies remain responsible for patient consent, chart review, and signed clinical documentation.
- Breach, security incident, retention, and deletion obligations for protected health information are handled under the applicable BAA and customer agreement.
07
Security
Cardon Health uses administrative, technical, and physical safeguards intended to protect information against unauthorized access, disclosure, alteration, and destruction. These safeguards include role-based access, authentication controls, encryption, audit logging, access review, and security monitoring appropriate to the deployment.
No internet-connected system can be guaranteed to be perfectly secure. If we identify a security incident affecting customer data, we will investigate and provide notices as required by applicable agreements and law.
08
Where data is stored
Cardon Health data is stored in the United States. The application runs on Vercel, and the production database runs on Neon in the AWS us-east-1 (N. Virginia) region. Clinical documents are kept in private storage in the United States. Data is encrypted in transit and at rest.
09
Retention and deletion
We retain website, account, support, and business contact information for as long as needed to provide the service, manage the relationship, comply with legal obligations, resolve disputes, maintain security, and enforce agreements.
Retention and deletion of customer product data, including protected health information, are governed by the applicable customer agreement, BAA, customer configuration, legal requirements, backup practices, and approved deletion workflows.
10
Your choices and rights
You may contact us to request access, correction, deletion, or restriction of personal information we maintain about you, subject to identity verification, legal limits, and customer agreement obligations.
Authorized product users should contact their customer administrator for account access changes. Patients and caregivers should contact the relevant home-health agency or provider for medical-record requests, treatment questions, or HIPAA individual-rights requests.
11
Children's privacy
Cardon Health is a business service for home-health, home-care, and hospice agencies. It is not directed to children, and we do not knowingly collect personal information directly from anyone under 18. Agencies may record information about patients who are minors as part of their care records. That information is protected health information handled under the agency's agreement and BAA and is used only to provide the service. If you believe a child has given us personal information directly, contact privacy@cardonhealth.ai and we will delete it.
12
Updates and contact
We may update this Privacy Policy as Cardon Health, our subprocessors, or legal requirements change. The effective date above reflects the latest version posted on this site.
13
Privacy officer and grievances
Agentic Labs Inc. has a designated privacy officer, who also acts as grievance officer for Cardon Health. The privacy officer oversees how personal information is handled, answers privacy questions and data requests, investigates complaints, coordinates the response to any privacy incident, and keeps this policy current.
Contact the privacy officer at privacy@cardonhealth.ai. We acknowledge privacy requests and complaints within 2 business days and aim to resolve them within 30 days.
Security and contracting questions can also be sent to hello@cardonhealth.ai.