Humanate Digital, Inc. ("Humanate," "we," "us," or "our") respects your privacy. This Privacy Policy explains what information we handle in connection with the website at humanate.ai (the "Site") and our SMS text messaging program, how we use and protect it, and the choices available to you.
Our Role as a Business Associate
Humanate provides AI-powered digital avatar agent technology to healthcare clinics, hospitals, and other healthcare organizations ("Covered Entities"). We act as a business associate, as defined under HIPAA, to the Covered Entities that use our platform, under signed Business Associate Agreements ("BAAs").
Humanate does not directly collect personal information or consent from patients. Any patient information we handle, including for the SMS program described in Section 3, is provided to us by the Covered Entity, based on information and consent that Covered Entity has already collected.
The Covered Entity's own Notice of Privacy Practices governs how your protected health information (PHI) is used and disclosed under HIPAA. This Privacy Policy addresses only how Humanate, as a business associate, handles the limited information described below.
1. Information We Handle
1.1 Information we receive from Covered Entities
As a business associate, Humanate receives certain information from the Covered Entities we serve, such as a patient's name, mobile phone number, appointment details, and existing consent records, solely to operate our AI avatar agent platform and SMS appointment-reminder program on that Covered Entity's behalf. We do not independently solicit, collect, or verify this information or consent directly from patients; we rely on the Covered Entity to have collected it properly.
1.2 Information you provide directly to Humanate
If you visit the Site as a prospective client, job applicant, vendor, or other visitor (rather than as a patient), and you voluntarily submit information through a contact form or similar, we collect what you provide (for example, your name, email address, and message).
1.3 Automatically collected information
When you visit the Site, we may automatically collect certain technical information such as your IP address, browser type, device type, and pages visited, typically through cookies or similar technologies.
2. How We Use Information
We use the information described above to:
- Send appointment and visit-related SMS reminders and notifications to patients, on behalf of and as directed by the applicable Covered Entity, using the phone number and consent record that Covered Entity provided to us;
- Respond to inquiries and provide customer support, including replies to HELP and STOP requests;
- Comply with our obligations under applicable BAAs, HIPAA, and other legal requirements, and enforce our Terms of Use;
- Maintain the security and integrity of our systems.
We do not use information received from Covered Entities, including SMS opt-in information, for any purpose beyond operating the services described in this Policy and our agreements with those Covered Entities.
3. SMS Program: Data Handling
3.1 No Third-Party Sharing
Mobile phone numbers and consent records Humanate receives from a Covered Entity are not shared, sold, rented, or disclosed to any third parties or affiliates for their own marketing or promotional purposes. This information is used solely by Humanate, and the service providers described in Section 4 below acting only on our behalf, to operate the SMS program for that Covered Entity.
3.2 Source of Consent
Consent to receive SMS messages is collected by the Covered Entity as part of its own patient intake, scheduling, or consent process, not directly by Humanate. See Section 4.2 of our Terms of Use.
3.3 Opt-Out
A recipient may stop receiving messages at any time by replying STOP. Humanate will notify the applicable Covered Entity of the opt-out.
4. How We Share Information
We do not sell personal information. We may share information only with:
- Service providers who perform functions on our behalf, for example our SMS delivery provider, currently Amazon Web Services End User Messaging, under contractual obligations to protect the information and use it only to provide services to us;
- The Covered Entity that provided the information to us, for example to share delivery status or opt-out confirmations so its records stay current;
- Legal and safety purposes, where required to comply with law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Humanate, our users, or others.
5. Data Security
We maintain administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction, consistent with HIPAA regulations, our internal Information Security and Data Management policies, and our obligations under applicable BAAs.
6. Data Retention
We retain information received from Covered Entities, including SMS opt-in and consent records, for as long as necessary to operate the SMS program, respond to opt-out requests, and comply with our BAA and other legal and regulatory obligations.
7. Your Choices and Rights
- SMS: Reply STOP to any text message to opt out at any time.
- Access, correction, or deletion of your information: Because Humanate holds patient information as a business associate rather than as the party with a direct relationship to you, requests to access, correct, or delete your information should generally be directed to the Covered Entity you receive care from. You may also contact us at info@humanate.ai and we will coordinate with the applicable Covered Entity as needed.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The effective date above reflects the most recent revision. Material changes will be reflected on this page.
9. Contact Us
If you have questions about this Privacy Policy, you may contact: