Privacy Policy for Compliance
Venux AI
Compliance is provided by Venux AI Inc. (“we,” “us,” or “our”). This Privacy Policy explains how we collect, use, protect, retain, and disclose personal information and health information when you use the Compliance mobile app, website, and related services.
Questions or privacy requests can be sent to: [insert privacy email].
Information We Collect
We collect information provided by authorized organizations and users of the app, including:
- Names, email addresses, usernames, user IDs, phone numbers, addresses, dates of birth, pronouns, and profile images.
- Emergency contacts, guardians, family members, healthcare providers, and other support-contact information.
- Health and care information, including medical notes, diagnoses, medications, allergies, medical visits, care notes, care plans, doctor and facility information, incident reports, and medical documents.
- Race or ethnicity where recorded by an authorized organization for care or service-delivery purposes.
- Chat messages, comments, reactions, timeline notes, shift logs, client goals, uploaded photos, videos, certificates, documents, and other attachments.
- Account, tenant, access-control, audit, security, IP address, device/browser information, timestamps, and request-log information. We do not collect payment-card information, browsing history, device GPS location, or device calendar information unless we introduce and clearly disclose those features in the future.
How We Use Information
We use personal and health information to:
- Provide care-operation, staffing, scheduling, communication, reporting, and record-management features.
- Authenticate users and manage enterprise accounts, access permissions, and tenant memberships.
- Enable authorized users to view, create, update, and manage client, workforce, and operational records.
- Send service-related notifications, including password resets, account notices, assignments, and chat notifications.
- Maintain security, prevent unauthorized access, investigate incidents, maintain audit trails, and meet legal and regulatory obligations.
- Respond to privacy, access, correction, complaint, support, and deletion requests.
- Maintain and improve the reliability and security of the Service. We do not sell personal information. We do not use personal or health information for targeted advertising.
How We Share Information
We disclose information only when necessary to provide the Service or meet legal obligations.
Information may be available to the authorized tenant organization and its authorized users according to assigned roles and permissions. We may also use trusted service providers for cloud hosting, object storage, databases, backups, email delivery, security, and operational support.
These providers may process information only to provide services on our behalf or on behalf of the applicable tenant organization. We do not permit them to use personal or health information for their own advertising purposes.
We may disclose information when required or permitted by law, regulation, court order, government request, or to protect the safety, security, rights, or property of users, organizations, or the public.
Health Information
Compliance may process health information on behalf of care organizations, agencies, employers, or other tenant organizations.
Where Alberta’s Health Information Act applies, the relevant tenant organization may be the health-information custodian. Venux AI may act as a service provider. The tenant organization remains responsible for ensuring it has the legal authority to collect, use, and disclose information through the Service.
If you are a client, patient, resident, parent, guardian, or other individual whose information is managed by a tenant organization, contact that organization’s privacy office first for questions about care records or care decisions.
International Processing
We may use cloud and service providers located in Canada, the United States, or other jurisdictions selected by us or the relevant tenant organization. Information processed outside your province or country may be subject to the laws of that jurisdiction.
Where required, we use contractual, technical, and organizational safeguards for cross-border processing.
Security
We use administrative, technical, and organizational safeguards designed to protect information against loss, unauthorized access, use, disclosure, alteration, and destruction. These measures include authenticated access, role-based permissions, tenant separation, audit logging for sensitive records, and protected production data transmissions.
No method of transmission or storage is completely secure. Users must protect their credentials and notify their organization or us promptly if they believe their account has been compromised.
Retention and Disposal
We retain information for as long as necessary to provide the Service, meet tenant-organization requirements, comply with legal and regulatory obligations, resolve disputes, and maintain security records.
Chat messages are retained according to configured retention settings. Medical, care, incident, employment, audit, and other operational records may be retained longer where required by law, regulation, contractual obligations, or the tenant organization’s policies.
When information is no longer required, we delete, de-identify, or securely dispose of it using methods appropriate to the information and systems involved. Backup copies may remain until their normal retention period expires.
Your Privacy Rights
Depending on applicable law, you may request access to, correction of, deletion of, or information about the handling of your personal information or health information.
To make a request, email [insert privacy email] with the subject line “Privacy Request.” Include your name, associated organization, request type, and enough information to verify your identity and locate the relevant records.
Deletion requests are subject to legal, clinical-record, security, contractual, and retention obligations. If we cannot fulfill a request, we will explain the reason where required by law.
Children
Compliance is intended for authorized users of tenant organizations and is not intended for direct use by children. Tenant organizations are responsible for ensuring they have appropriate authority to provide information about minors or dependent adults.
Changes to This Policy
We may update this Privacy Policy when our practices, Service, or legal requirements change. We will post the updated policy and revise the “Last updated” date.
Contact
Venux AI Inc.
Attn: Privacy Officer
Email: contact@venuxai.com
Phone: +1 (825) 556 0898