ProductSolutionsROIPricingResourcesBook a walkthrough
ProductSolutionsROIPricingResourcesBook a walkthrough

Privacy Policy

Privacy Policy

This page is a working draft prepared for a healthcare software vendor and has not been reviewed by legal counsel. Do not publish without review by a qualified attorney familiar with HIPAA, state privacy law, and your specific data-processing arrangements.

1. Overview

Nuvae ("we," "us") provides AI-based revenue-protection software to healthcare organizations. This policy explains what information we collect, how we use it, and how it's protected — including protected health information (PHI) processed on behalf of our healthcare provider and health system customers.

2. Information we collect

Account and contact information you provide directly (name, work email, healthcare provider affiliation); usage data from your interaction with our software; and, where applicable under a signed Business Associate Agreement (BAA), protected health information processed solely to deliver the contracted service.

3. How we use information

To operate and improve the Nuvae platform; to communicate with you about your account or service; and, for PHI processed under a BAA, exclusively for the purposes permitted by that agreement and the Health Insurance Portability and Accountability Act (HIPAA).

4. PHI and HIPAA

Where Nuvae processes protected health information on behalf of a covered entity, that processing is governed by a signed Business Associate Agreement (BAA), not this general policy. Contact us to request a BAA before submitting any PHI.

5. Data security

Data is encrypted in transit and at rest. Access is role-based and logged. We do not write PHI to application logs. Nuvae is HIPAA compliant and SOC 2 Type II certified — see our Trust Center for the full security and compliance posture.

6. Data retention & deletion

We retain data for as long as needed to provide the service or as required by law and applicable BAAs, and delete or return data on contract termination consistent with BAA terms. [TODO: confirm specific retention periods with legal/ops before publishing.]

7. Third parties

We do not sell personal information or PHI. Subprocessors used to deliver the service are bound by contractual confidentiality and, where applicable, BAA terms. [TODO: list actual subprocessors before publishing.]

8. Your rights

You may request access to, correction of, or deletion of your personal information, subject to legal and contractual obligations (including HIPAA retention requirements for PHI). Contact contact@nuvae.ai.

9. Changes to this policy

We'll post material changes here with an updated effective date.

10. Contact

Questions about this policy: contact@nuvae.ai.

— revenue protection · © 2026
ProductSolutionsROIPricing
CustomersResourcesAbout usCareersContact
Trust CenterPrivacy PolicyTerms of Service
HIPAA compliant · SOC 2 Type II certified · BAA available on request