Legal
Privacy Policy
Effective date: July 20, 2026. This Privacy Policy describes how Intellyverse LLC handles personal and sensitive information collected through PT AI Note Helper, including the no-PHI operating model, BAA availability, subprocessors, security safeguards, and EEA/UK data-subject rights. Contact privacy@intellyverse.com with any questions.
Scope
Intellyverse LLC, a Florida limited liability company (“we,” “us,” or “our”), understands that protecting your personal information is important. This Privacy Policy sets out our commitment to protecting the privacy of personal information provided to us, or collected by us, when you interact with PT AI Note Helper, including the public website, authenticated workspace, AI-assisted drafting, draft storage, billing features, and related support services (collectively, the “Service”).
This Privacy Policy takes into account the requirements of the U.S. federal and state privacy laws, the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) where applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”) for individuals located in the European Economic Area (“EEA”), and the UK GDPR and Data Protection Act 2018 for individuals located in the United Kingdom. Appendix 1 outlines the additional rights of individuals located in the EEA and UK, and how we process the personal information of those individuals.
This Privacy Policy is written for business, clinician, and other professional users of the Service. It is not a substitute for a signed Business Associate Agreement (“BAA”), Data Processing Agreement (“DPA”), or customer order form. If a signed BAA, DPA, or other written agreement applies to your account and conflicts with this Policy for PHI handling, the signed agreement controls to the extent of the conflict.
The information we collect
Personal information is information or an opinion, whether true or not and whether recorded in a material form or not, about an individual who is identified or reasonably identifiable. The types of personal information we may collect about you include:
- Identity Data including your name, professional credentials, and the name of the organisation you work for.
- Contact Data including your telephone number, address, and email.
- Financial Data including bank account and payment-card details handled by our third-party payment processor (currently Stripe). We do not have access to your full payment-card number.
- Health information limited to non-PHI clinical-drafting inputs (for example, encounter type, body region, intervention class) that you choose to type into the Service. The Service is designed as a no-PHI drafting tool. You agree not to submit PHI to the Service. If you require PHI-enabled processing, a BAA is available on request.
- Transaction Data including details of payments to and from you, subscription plan, billing cycle, and other details of products and services you have purchased.
- Technical and Usage Data when you access the Service, including Internet protocol (IP) address, login data, browser session, geo-location data, statistics on page views and sessions, device and network information, acquisition sources, search queries, and access and use of our website (including through the use of Internet cookies or analytics).
- Profile Data including your username and password for our Service, profile picture, purchases or orders you have made with us, content you send, receive, and share through the Service, and support requests you have made.
- Interaction Data including information you provide to us when you participate in any interactive features, including surveys, contests, promotions, activities, or events.
- Marketing and Communications Data including your preferences in receiving marketing from us and our third parties and your communication preferences.
- Professional Data including, where you are a worker of ours or applying for a role with us, your professional history such as previous positions and professional experience.
Sensitive information (including health information)
Sensitive information is a sub-set of personal information that is given a higher level of protection. Sensitive information means information relating to your racial or ethnic origin, political opinions, religion, trade union or other professional associations or memberships, philosophical beliefs, sexual orientation or practices, criminal records, health information, or biometric information.
The types of sensitive information we may collect are limited to the non-PHI clinical-drafting inputs described above. We do not intentionally receive PHI through the Service, and we apply technical safeguards (including server-side redaction, encryption, and audit logging) designed to reduce the risk that PHI is submitted, stored, or routed to AI providers.
If at any time we need to collect sensitive information about you beyond what is reasonably necessary to provide the Service, and unless otherwise permitted by law, we will first obtain your consent and we will only use the information as required or authorised by law.
How we collect personal information
- When you interact directly with us, including face-to-face, over the phone, over email, or online.
- When you complete a form, such as registering for events or newsletters, or responding to surveys.
- When you apply for a job with us.
- From third parties, such as details of your use of any website we operate (from our cookie providers and marketing providers; see our Cookie Policy for more detail on the use of cookies).
- From publicly available sources, such as Google and LinkedIn.
Why we collect, hold, use, and disclose personal information
Personal information: We collect, hold, use, and disclose your personal information for the following purposes:
- To enable you to access and use the Service, including to provide you with an account and authenticated workspace.
- To contact and communicate with you about our business, including in response to any support requests you lodge with us or other enquiries you make with us.
- To contact and communicate with you about any enquiries you make with us via any website we operate.
- For internal record-keeping, administrative, invoicing, and billing purposes.
- For analytics, market research, and business development, including to operate and improve our Service, associated applications, and associated social media platforms.
- For advertising and marketing, including to send you promotional information about our events and experiences and information that we consider may be of interest to you.
- To run promotions, competitions, and/or offer additional benefits to you.
- If you have applied for employment with us, to consider your employment application.
- To comply with our legal obligations or if otherwise required by law.
Sensitive information (including health information): purposes
We only collect, hold, use, and disclose sensitive information for the following purposes:
- To provide the Service to you.
- Any purposes you explicitly consent to when requested by us (for example, participation in research programs).
- If otherwise required by law.
Our disclosures of personal information to third parties
All access to sensitive information is audited and reviewed on a regular basis to ensure access is absolutely required to provide the Service. Sensitive data will never be shared for marketing or affiliate purposes.
- Our employees and contractors with your explicit consent.
- Data storage and technology service providers (subprocessors), as set out in the section below.
- Any other third parties as required by law, such as where we receive a subpoena.
Personal information disclosures (non-sensitive)
We may disclose personal information (excluding sensitive information) to:
- Our employees and contractors.
- Data storage and technology service providers.
- Marketing service providers (for example, email campaigns to educate practitioners about our Service or inform practitioners of new features).
- Analytics and customer-relationship management service providers (for example, to assist our sales and support teams to communicate with practitioners).
- Courts, tribunals, and regulatory authorities, in the event you fail to pay for goods or services we have provided to you.
- Any other third parties as required by law, such as where we receive a subpoena.
Overseas disclosure
While we store personal information in the United States, where we disclose your personal information to the third parties listed above, those third parties may store, transfer, or access personal information outside of the United States, including but not limited to the European Economic Area, the United Kingdom, Canada, and Australia. We will only disclose your personal information overseas in accordance with applicable data-protection laws and our agreements with those third parties.
Our subprocessors
The Service is built on a small set of carefully selected subprocessors. As of the effective date of this Policy, the primary subprocessor categories are: website and application hosting (Vercel), edge and API execution (Cloudflare Workers), database, authentication, and storage (Supabase), payment processing (Stripe), and AI routing and model access (OpenRouter).
We may update subprocessors over time. A signed BAA, DPA, or order form may provide more specific subprocessor disclosure or notice rights for covered customers.
Your rights and controlling your personal information
- Your choice: Please read this Privacy Policy carefully. If you provide personal information to us, you understand we will collect, hold, use, and disclose your personal information in accordance with this Privacy Policy. You do not have to provide personal information to us; however, if you do not, it may affect our ability to do business with you.
- Information from third parties: If we receive personal information about you from a third party, we will protect it as set out in this Privacy Policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have that person’s consent to provide the personal information to us.
- Restrict and unsubscribe: To object to processing for direct marketing, unsubscribe from our email database, or opt out of communications (including marketing communications), please contact us using the details below or opt out using the opt-out facilities provided in the communication.
- Access: You may request access to the personal information that we hold about you. An administrative fee may be payable for the provision of such information. Please note, in some situations, we may be legally permitted to withhold access to your personal information. If we cannot provide access, we will advise you as soon as reasonably possible and provide you with the reasons for our refusal and any mechanism available to complain about the refusal. If we can provide access in another form that still meets your needs, we will take reasonable steps to give you such access.
- Correction: If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, please contact us using the details below. We will take reasonable steps to promptly correct any information found to be inaccurate, out of date, incomplete, irrelevant, or misleading. If we cannot correct your information, we will advise you as soon as reasonably possible and provide you with the reasons for our refusal and any mechanism available to complain about the refusal.
- Complaints: If you wish to make a complaint, please contact us using the details below and provide us with full details of the complaint. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take in response to your complaint. If you are not satisfied with our response, you may contact the U.S. Federal Trade Commission, the EU Data Protection Authority in your country, or the UK Information Commissioner’s Office, as applicable.
Storage and security
We are committed to ensuring that the personal information we collect is secure. We implement technical and organisational security measures in a layered approach to prevent unauthorised misuse, interference, loss, unauthorised access, modification, and disclosure. More details regarding the specific measures we implement are available on our Security page.
Cookies
We may use cookies on our website from time to time. We use only cookies that are reasonably necessary for the operation of the Service (for example, authentication and security) and a small set of analytics and preference cookies. We do not rely on unsecured custom auth-mirroring cookies to persist sensitive authenticated session state.
Amendments
We may, at any time and at our discretion, vary this Privacy Policy by publishing the amended Privacy Policy on our website. We recommend you check our website regularly to ensure you are aware of our current Privacy Policy.
Contact information
For any questions or notices, please contact us at:
- Intellyverse LLC, 2814 SW 6th St, Gainesville, FL 32601, USA.
- Email: privacy@intellyverse.com
- EU residents: euprivacy@intellyverse.com
- UK residents: ukprivacy@intellyverse.com
- All other locations: legal@intellyverse.com
Appendix 1: Additional rights and information for individuals located in the EEA or UK
Under the GDPR, individuals located in the EEA and the UK have additional rights that apply to their personal information. Personal information under the GDPR is often referred to as personal data and is defined as information relating to an identified or identifiable natural person (individual). This Appendix 1 sets out the additional rights we give to individuals located in the EEA and UK, as well as information on how we process the personal information of individuals located in the EEA and UK. Please read the Privacy Policy above and this Appendix carefully and contact us at the details at the end of the Privacy Policy if you have any questions.
What personal information is relevant?
This Appendix applies to the personal information set out in the Privacy Policy above. This includes any sensitive information also listed in the Privacy Policy above, which is known as ‘special categories of data’ under the GDPR.
Purposes and legal bases for processing
We collect and process personal information about you only where we have legal bases for doing so under applicable laws. We have set out below the purposes, data types, and legal bases on which we rely. Note that we may process your personal information for more than one lawful ground depending on the specific purpose for which we are using your data.
- To enable you to access and use the Service, including to provide you with an account. Data: Identity, Contact. Legal basis: Performance of a contract with you.
- To do business with you, including to provide the Service to you and assess your application to use the Service. Data: Identity, Contact. Legal basis: Performance of a contract with you.
- To contact and communicate with you about our business, including in response to any support requests or other enquiries. Data: Identity, Contact, Profile. Legal basis: Performance of a contract with you.
- To contact and communicate with you about any enquiries you make with us via our website. Data: Identity, Contact. Legal basis: Legitimate interests — to ensure we provide the best client experience by answering your questions.
- For internal record-keeping, administrative, invoicing, and billing purposes. Data: Identity, Contact, Financial, Transaction. Legal bases: Performance of a contract with you; to comply with a legal obligation; legitimate interests — to recover debts due and notify you of changes to these Terms and other administrative points.
- For analytics, market research, and business development, including to operate and improve the Service. Data: Profile, Technical and Usage. Legal basis: Legitimate interests — to keep the Service updated and relevant, develop our business, and inform our marketing strategy.
- For marketing, including to send you promotional information about our events and information we consider may be of interest to you. Data: Identity, Contact, Technical and Usage, Profile, Marketing and Communications. Legal basis: Legitimate interests — to develop and grow our business.
- To run promotions, competitions, and/or offer additional benefits to you. Data: Identity, Contact, Profile, Interaction, Marketing and Communications. Legal basis: Legitimate interests — to facilitate engagement and grow our business.
- If you have applied for employment with us, to consider your employment application. Data: Identity, Contact, Professional. Legal basis: Legitimate interests — to consider your employment application.
- To comply with our legal obligations or if otherwise required by law. Legal basis: To comply with a legal obligation.
Data transfers
The privacy protections available in the countries to which we send data for the purposes listed above may be less comprehensive than what is offered in the country in which you initially provided the information. Where we transfer your personal information outside of the country where you are based, we will perform those transfers using appropriate safeguards in accordance with the requirements of applicable data-protection laws, and we will protect the transferred personal information in accordance with this Privacy Policy and Appendix 1. This includes:
- Only transferring your personal information to countries that have been deemed by applicable data-protection laws to provide an adequate level of protection for personal information.
- Including standard contractual clauses in our agreements with third parties that are overseas.
Data retention
We will only retain your personal information for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal information for a longer period in the event of a complaint, or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.
To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the personal information and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting, or other requirements.
Extra rights for EEA and UK individuals
You may request details of the personal information that we hold about you and how we process it (commonly known as a ‘data subject request’). You may also have a right in accordance with applicable data-protection law to have your personal information rectified or deleted, to restrict our processing of that information, to object to decisions being made based on automated processing where the decision will produce a legal effect or a similarly significant effect on you, to stop unauthorised transfers of your personal information to a third party, and, in some circumstances, to have personal information relating to you transferred to you or another organisation.
If you are not happy with how we are processing your personal information, you have the right to make a complaint at any time to the relevant Data Protection Authority based on where you live. We would, however, appreciate the chance to deal with your concerns before you approach the Data Protection Authority, so please contact us in the first instance using the details set out below.
Contact for privacy questions
- If you are based in the UK: ukprivacy@intellyverse.com
- If you are based in the EEA: euprivacy@intellyverse.com
- All other locations: privacy@intellyverse.com
Contact
UK residents: ukprivacy@intellyverse.com. EEA residents: euprivacy@intellyverse.com. All other locations: privacy@intellyverse.com. Mailing address: Intellyverse LLC, 2814 SW 6th St, Gainesville, FL 32601, USA.