← Aitality home

AITALITY Privacy Policy

Effective date: September 22, 2026

This Privacy Policy explains how AITALITY, LLC, a Texas limited liability company, collects, uses, discloses, retains, and protects personal information through the AITALITY website, applications, credentialing portfolio, document tools, sharing features, reminders, integrations, and related services. It also explains the choices and privacy rights that may be available to you.

AITALITY is designed to let health care professionals organize and share their own professional credentialing information. Do not upload patient records or patient protected health information. This Policy should be read with the AITALITY Terms of Service and any privacy notice presented when information is collected. Capitalized terms that are not defined in this Policy, such as “Services,” “User Content,” and “Authorized Recipients,” have the meanings given in the Terms of Service.

1 Scope and our role

This Policy applies when AITALITY determines why and how personal information is processed, including information from individual providers who create their own accounts and visitors to our website. If AITALITY processes information solely on behalf of an enterprise customer under a written agreement, that customer may be the controller or business responsible for the information and its privacy notice may apply. Direct requests concerning enterprise-controlled information to that customer; we will assist as required by our agreement and applicable law.

This Policy does not govern third-party websites, boards, employers, payers, credentialing authorities, identity providers, or integrations that have their own privacy practices.

2 Personal information we collect

2.1 Account and contact information

We may collect your name, professional title, credentials, email address, telephone number, mailing address, username, password hash, account preferences, organization, and communications preferences.

2.2 Professional credentialing information

Depending on the features you use, we may collect or derive information concerning professional licenses, certifications, education, training, residencies and fellowships, continuing medical education, work history, hospital affiliations and privileges, references, malpractice coverage and claims history, professional memberships, sanctions or disciplinary disclosures, work authorization, curriculum vitae information, and application responses.

2.3 Documents and sensitive information

Documents you choose to upload may contain government identifiers, driver’s-license or passport information, citizenship or immigration status (for example, in work-authorization documents), date of birth, Social Security or tax-identification numbers, signatures, photographs, W-9 information, immunization or occupational-health records, financial information, and other sensitive personal information. Upload only information necessary for the feature being used. Credentialing forms you upload or complete may request optional information, such as race, ethnicity, or disability or accommodation information; provide it only if you choose to. We process sensitive personal information only as reasonably necessary to provide the features you request and, where required by law, with your consent. We do not intentionally collect payment-card numbers through ordinary document-upload fields; card payments should be entered only through the designated payment processor.

2.4 Verification and integration information

When you connect or request verification from a licensing board, certification organization, continuing-education source, identity provider, employer, payer, or other service, we may receive identifiers, authorization tokens, verification results, credential status, issue and expiration dates, continuing-education records, and related metadata. The available data depends on the integration and your authorization.

2.5 Usage, device, and technical information

We may automatically collect IP address, device and browser type, operating system, identifiers, approximate location derived from IP address, referring pages, pages and features used, clicks, session times, error logs, security events, and cookie or similar-technology data.

2.6 Transactions, support, and communications

We may collect subscription and transaction records, billing contact information, support requests, survey responses, feedback, email and notification interactions, and records of communications. Our payment processor may collect payment credentials directly under its own privacy policy; AITALITY generally receives a token and limited transaction details rather than a full card number.

2.7 Information about other people

If you provide information about a reference, colleague, authorized recipient, employer contact, or other person, you must have authority to provide it and must give any required notice. Avoid uploading information about patients or unrelated individuals.

3 Sources of personal information

We collect personal information:

4 How we use personal information

We may use personal information to:

Where applicable law requires a legal basis, we process information as necessary to perform a contract, with consent, to comply with legal obligations, and for legitimate interests such as providing, securing, supporting, and improving the Services, balanced against your rights.

5 Document processing, artificial intelligence, and automated tools

AITALITY may use optical character recognition, rules-based automation, machine learning, and artificial intelligence to classify documents, extract fields, identify possible issue or expiration dates, detect duplicates, suggest credential categories, prefill forms, and generate administrative content. These tools can make mistakes. Review all extracted or generated information before relying on or sharing it.

AITALITY and its service providers may process User Content to provide, secure, maintain, support, and improve the Services. We do not use identifiable credentialing documents or other identifiable User Content to train or fine-tune any artificial-intelligence model, whether our own or a third party’s, without your opt-in consent. When we use third-party AI or OCR providers, they process User Content on our behalf under contracts that prohibit them from using it to train their own models. We may use deidentified or aggregated information that cannot reasonably be linked to an individual, subject to legal restrictions and contractual commitments.

AITALITY does not use automated processing by itself to make final decisions concerning licensure, employment, enrollment, privileges, credentials, or other legal or similarly significant effects. Those decisions belong to the relevant authority or recipient, which must independently verify information. Where a law regulating automated decision-making or AI-assisted decision tools applies to a feature, we will provide the notices and choices that law requires.

6 How we disclose personal information

We may disclose personal information to the following categories of recipients for the purposes described in this Policy:

We may disclose aggregated or deidentified information where permitted by law. We require recipients of deidentified information to maintain it in deidentified form and not attempt to reidentify it when required.

7 Selling, sharing, and targeted advertising

AITALITY does not sell personal information and does not share it for cross-context behavioral or targeted advertising. We may use privacy-focused analytics that do not use cookies on our public marketing website to understand how the site is used. We do not place advertising or retargeting pixels on our website, and we do not place third-party tracking technologies in the logged-in application or on pages that display User Content. If we change these practices, we will update this Policy and provide any opt-out choices required by law, including honoring legally recognized opt-out preference signals such as Global Privacy Control.

8 User-directed sharing

You control the information you select, the recipient, and available link settings when using sharing features. A person with an unprotected or forwarded link may be able to access the shared information. Review the contents and recipient before sharing, use authentication and expiration controls when available, and revoke access when it is no longer needed. AITALITY cannot control information after a recipient downloads, copies, or separately stores it.

9 Cookies, analytics, and communication choices

We and our service providers may use cookies, software development kits, local storage, and logs to keep you signed in, remember preferences, maintain security, measure performance, diagnose errors, and understand how the Services are used. A cookie banner or settings tool, when provided, supplies additional choices. Browser settings may block some technologies but can impair functionality. Some browsers offer a “Do Not Track” setting. Because there is no common industry standard for these signals, we do not respond to them. Section 7 explains how we would handle Global Privacy Control signals.

You may unsubscribe from marketing email using the link in the message. We may continue sending transactional or service communications, including account, security, sharing, billing, reminder, and legal notices. Device and application settings may control push notifications and certain permissions.

10 Retention and deletion

We retain personal information for the period reasonably necessary to provide the Services, maintain the account, carry out the purposes described in this Policy, comply with legal and contractual obligations, resolve disputes, enforce agreements, and protect security. Retention depends on the information type, sensitivity, account status, user instructions, legal requirements, and operational needs.

Typical retention periods are:

When information is no longer required, we may delete, deidentify, or aggregate it. Residual copies may remain temporarily in backups, logs, security records, legal holds, or systems designed to prevent fraud or preserve rights. If you close an account, export information you need before access ends. AITALITY is not a permanent records custodian unless a separate signed agreement says otherwise.

11 Security and incident response

We use administrative, technical, and organizational safeguards designed for the nature of the information and Services. No system, storage method, transmission, integration, or security control is completely secure. You are responsible for protecting your credentials and devices, using available security controls, and promptly reporting suspected unauthorized access to security@aitality.com.

If a security incident occurs, we will investigate and provide notices to affected individuals, customers, or authorities when required by applicable law or contract. Do not send sensitive documents through ordinary email unless instructed to use a secure method.

12 Your privacy rights

Depending on where you live and subject to exceptions, you may have the right to:

Submit a request by emailing privacy@aitality.com. Describe the request and your state or country of residence. We may verify identity and authority using information associated with the account and may request additional information when reasonably necessary. An authorized agent may submit a request where permitted, but we may require proof of authority and direct identity confirmation. We will respond within the period required by law, generally within 45 days, which we may extend where the law permits. If we deny a request, residents entitled to appeal may reply with “Privacy Appeal” and explain the basis for the appeal. We will respond to appeals within the period required by law. If we deny your appeal, you may contact your state attorney general.

Certain information may be exempt, including information needed to provide requested Services, protect security, comply with law, preserve legal claims, or meet professional and contractual recordkeeping requirements. If AITALITY processes information solely for an enterprise customer, we may direct the request to that customer.

13 California notice at collection

During the preceding 12 months, AITALITY may have collected the following categories of personal information, depending on use: identifiers; customer-record information; characteristics protected by law if voluntarily disclosed; commercial and transaction information; internet or electronic-network activity; approximate geolocation; audio, visual, or similar information; professional, employment, and education information; inferences generated to support platform features; and sensitive personal information such as account credentials, government identifiers, citizenship or immigration status, precise information contained in uploaded documents, and health-related credentialing records.

We collect and use these categories for the business and commercial purposes described in Sections 4 and 5 and from the sources in Section 3. We may disclose them to the recipient categories in Section 6. We do not use or disclose sensitive personal information to infer characteristics about a person except as permitted by California law or with required notice and choice. California residents may exercise the rights described in Section 12 and may request information about categories collected, sources, purposes, recipients, and specific pieces of personal information, subject to applicable law. Section 10 describes how long we retain these categories. In the preceding 12 months, we have not sold personal information or shared it for cross-context behavioral advertising.

14 Consumer health data

Depending on what you upload, AITALITY may collect consumer health data, such as immunization documentation, occupational-health testing, accommodation or health disclosures in credentialing forms, or other information that identifies or could be linked to a person’s health status. AITALITY collects this information directly from you or from a source you authorize; uses it to store, organize, extract, display, remind, and share credentialing materials at your direction; and discloses it to processors necessary to provide the Services and to recipients or integrations you authorize.

AITALITY does not sell consumer health data. We do not collect or use consumer health data for targeted advertising or to infer unrelated characteristics. We process it only as reasonably necessary to provide requested features, with consent when required, for security and legal compliance, and as otherwise permitted by applicable law. Do not upload patient health information or health information about another person unless AITALITY expressly requests it and you have legal authority.

Where consumer-health privacy law applies, you may request access, confirmation, withdrawal of consent, deletion, or a list of third parties or affiliates receiving the data, subject to legal exceptions. Submit a request using Section 12. Our Consumer Health Data Privacy Notice, linked from our homepage, supplements this Policy and controls where it provides additional rights.

15 HIPAA

AITALITY is not a health care provider, health plan, or health care clearinghouse merely because it provides credentialing tools. Unless AITALITY signs a Business Associate Agreement that specifically covers the relevant Services, AITALITY does not agree to act as a HIPAA business associate and the Services must not be used to upload or store patient protected health information. Professional information about a provider can still be protected by other privacy and security laws even when HIPAA does not apply. AITALITY may nonetheless be subject to state health-information laws that define covered entities more broadly than HIPAA, including Chapter 181 of the Texas Health and Safety Code, and complies with those laws where they apply.

16 Children

The Services are intended for adults and are not directed to children under 18. We do not knowingly collect personal information from children through the Services. If you believe a child has provided personal information, contact us so we can evaluate and delete it as required.

17 International processing

AITALITY is based in the United States. Personal information may be processed in the United States and other countries where we or our service providers operate. Those countries may have different privacy laws. Where required, we use appropriate contractual or legal mechanisms for cross-border transfers. Users outside the United States may have additional rights, including rights to object to or restrict processing and complain to a supervisory authority.

18 Changes to this Policy

We may update this Policy to reflect changes in law, technology, Services, or practices. We will post the updated Policy with a new effective date and provide additional notice or obtain consent when required. Material changes apply prospectively unless law permits otherwise.

19 Contact us

AITALITY, LLC
Privacy requests and questions: privacy@aitality.com
Security reports: security@aitality.com
Support: support@aitality.com