Privacy Policy
Last updated: July 2, 2026
1. Introduction
VivaLyn Labs ("we," "our," or "us") respects privacy and is committed to protecting healthcare data. This policy explains what information we collect when clinics, hospitals, providers, and healthcare organizations use Vivalyn EMR, MedScribe, and related healthcare AI services.
2. Information We Collect
- Account Information: name, email address, phone number, organization details, and support contact information.
- Usage Data: product interactions, feature usage, device metadata, diagnostics, and operational logs.
- Clinical Audio and Transcription Data: audio, transcript, and generated draft notes processed through MedScribe for clinical documentation, according to the customer's selected deployment model.
- Health Data: patient records, prescriptions, medical history, lab results, billing context, and related data managed in Vivalyn EMR.
- Contact Data: information submitted through website forms, demos, support requests, or sales conversations.
3. How We Use Information
- To provide, maintain, secure, and improve our products.
- To support EMR workflows, AI-assisted clinical documentation, billing, lab, pharmacy, and analytics features.
- To communicate about demos, onboarding, support, training, product updates, and service notices.
- To monitor security, detect unauthorized access, and maintain auditability.
- To comply with legal, contractual, and regulatory obligations.
4. Data Storage and Security
Vivalyn EMR and MedScribe use secured environments with encryption, role-based access control, audit trails, and customer-specific deployment options. Depending on the selected plan and governance requirements, data may be hosted in cloud, private cloud, or on-premise infrastructure.
We follow healthcare-grade security practices including HTTPS, authentication, access separation, input validation, backup controls, and operational monitoring.
5. Third-Party Services
We may use approved infrastructure, model, analytics, communication, and support providers to deliver the service. These providers process data only as required to operate the product and are governed by contractual safeguards.
6. Data Sharing
We do not sell, rent, or trade healthcare data. We may share data only when required by law, necessary to protect users and systems, or needed by trusted service providers operating under appropriate data processing obligations.
7. Customer Controls
Customers can configure user roles, access permissions, deployment choices, and administrative controls based on their operational and compliance requirements.
8. Your Rights
Depending on your jurisdiction and contract terms, you may have the right to access, correct, delete, or export personal data. Healthcare organizations remain responsible for patient-data governance within their legal and clinical obligations.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected on this page and, where appropriate, communicated through product or customer channels.
10. Contact Us
VivaLyn Labs
Email: privacy@vivalynlabs.com