This policy is not about patient data. Healthplex is normally deployed on infrastructure the healthcare provider controls. In that model, patient records never reach Healthplex systems — there is no cloud copy for us to hold, analyse or disclose.
Where Healthplex does process patient data — a Healthplex-operated deployment, or a cloud AI provider a customer has explicitly enabled — that processing is governed by the executed Data Processing Addendum and HIPAA Business Associate Agreement, not by this page.
1. Who we are
Healthplex, Inc. is the data controller for this website.
Healthplex, Inc. is a Delaware corporation that builds the Healthplex EHR platform. For questions about this policy, contact privacy@healthplex.app.
2. What this policy covers
The marketing website and the sales process only. Patient data is governed by the DPA and BAA — not this document.
This Privacy Policy covers:
- Information collected when you visit healthplex.app and its subpages.
- Information collected during the sales process — contact forms, demo requests and sales conversations.
This Privacy Policy does not cover:
- Patient health information processed through a Healthplex deployment. In a self-hosted deployment that data stays with the healthcare provider and Healthplex never receives it. Where Healthplex does act as a processor, the DPA and BAA govern.
- Information you enter into a Healthplex deployment as a clinician or staff user. That processing is controlled by your employer under its own policies and applicable healthcare law.
3. Information we collect
Only what you give us voluntarily, plus anonymised page analytics and standard server logs.
3.1 Contact and inquiry data. When you complete a contact or demo request form we collect your name, work email address, organisation name, job title (if provided) and the content of your message.
3.2 Website analytics. We collect anonymised, aggregated data about page views and referrer sources to understand which pages are useful. We do not track individual visitors across sessions, and we do not use cross-site tracking, advertising pixels or retargeting networks.
3.3 Technical data. Standard web server logs may record IP address, browser type and pages requested. These are kept for security and operational purposes only and are never used for marketing.
4. Cookies
Strictly necessary cookies only. No advertising cookies, no cross-site tracking, no identifying analytics.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
hpx_session | Session continuity for the marketing site (e.g. form state) | Session — expires on browser close | Strictly necessary |
hpx_prefs | Language or theme preference, where applicable | 1 year | Strictly necessary |
We do not use Google Analytics, Mixpanel, Intercom, HubSpot tracking pixels, Meta Pixel, or any other third-party analytics or advertising cookie that identifies individual visitors or tracks them across sites.
5. How we use your information
To reply to you and — with your consent — to follow up. You can opt out at any time.
We use the information collected to:
- Respond to your inquiry or demo request.
- Send follow-up information relevant to your inquiry, with your consent.
- Improve the website using aggregated, anonymised page analytics.
We do not use your information for advertising or retargeting on third-party platforms, for sale or rental to third parties, or for automated decision-making producing legal or similarly significant effects.
Every marketing email includes an unsubscribe link. You may also opt out at any time by emailing privacy@healthplex.app.
6. Sharing your information
We share only what is necessary to run our business. We do not sell personal data, ever.
Healthplex may share the information described in Section 3 with the following categories of subprocessor:
| Category | Purpose | Location |
|---|---|---|
| Website hosting provider | Serving this website; server logs | US / EU |
| CRM / sales platform | Sales follow-up and pipeline management | US |
| Email delivery provider | Transactional and sales email | US |
The current named list is published in the Trust Center.
Healthplex will never sell, rent or trade your personal information to any third party for marketing purposes. We may disclose personal information if required by law — for example a court order — and will give you prompt notice where legally permitted to do so.
7. Your rights
You can access, correct, delete or restrict your data. We respond within 30 days.
7.1 GDPR (EU / UK). You have the right to access your personal data; rectify inaccurate data; request erasure where we have no legitimate reason to retain it; receive your data in a portable, machine-readable format; restrict processing; object to processing based on legitimate interests; and withdraw consent at any time without affecting prior processing.
7.2 CCPA / CPRA (California). You have the right to know what personal information we collect and how it is used; delete it, subject to limited exceptions; opt out of its sale (note: Healthplex does not sell personal information); and not be discriminated against for exercising these rights.
7.3 DPDP (India). You have the right to a summary of the personal data we hold, to correction and erasure, and to grievance redressal. Our Grievance Officer for India is reachable at privacy@healthplex.app. [Formal designation is in progress against the DPDP Board notification timeline.]
To exercise any of these rights, email privacy@healthplex.app. We respond within 30 days, or sooner where a shorter statutory period applies.
8. International transfers
If you contact us from the EU or UK, your data may be transferred to the US under Standard Contractual Clauses.
Healthplex is based in the United States. If you contact us from the European Union or the United Kingdom, the personal data described in Section 3 will be transferred to and processed in the US, under the EU Standard Contractual Clauses incorporated by reference into our data processing arrangements.
Data residency for patient data is a property of where the deployment runs — which, in a self-hosted deployment, is entirely your choice — and is addressed in the DPA, not here.
9. Children
This website is for healthcare professionals. We do not knowingly collect data from under-13s.
The Healthplex website is directed at healthcare professionals and business decision-makers. We do not knowingly collect personal information from individuals under 13. If we learn that we have inadvertently done so, we will delete it promptly.
10. Retention
Contact form data for up to 24 months; server logs for 90 days. Request deletion earlier at any time.
We retain contact form data — name, email, organisation, inquiry — for up to 24 months from submission, or until you request deletion, whichever comes first. After 24 months, inactive inquiry records are purged automatically. Web server logs are retained for a maximum of 90 days for security and operational purposes.
11. Security
We use industry-standard measures. No one can guarantee absolute security, and we will not pretend otherwise.
Healthplex implements reasonable technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration or destruction — including HTTPS-only transmission, access controls and regular security assessment.
No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information we will notify you and the relevant regulators as required by applicable law. To report a suspected vulnerability, see responsible disclosure.
12. Updates to this policy
We post material changes here 30 days before they take effect, and email you if we have your details.
We may update this policy to reflect changes in our practices, the platform or applicable law. For material changes we will post the updated policy with a revised "last updated" date and, where we hold your contact details, notify you by email at least 30 days before the change takes effect.
13. Contact and supervisory authority
Email privacy@healthplex.app. In the EU or UK you may also complain to your local data protection authority.
Data controller: Healthplex, Inc. — privacy@healthplex.app
EU / UK representative: [To be designated prior to EU/UK market launch.]
DPDP Grievance Officer (India): [Designation in progress per DPDP Board notification timeline.] Contact: privacy@healthplex.app
If you are in the EU or UK and believe we have not handled your personal data lawfully, you have the right to lodge a complaint with your local supervisory authority — for example the ICO in the United Kingdom, or the relevant data protection authority in your EU member state.
Healthplex, Inc. — privacy@healthplex.app