Privacy Policy

Last updated: August 3, 2025

This Privacy Policy ("Policy") outlines how Locata AI, Inc. ("Locata," "we," "our," or "us") collects, uses, shares, and protects personal information, and what rights you have regarding your data.

This Policy applies to information collected through our website and our platform (together, the "Services") and explains our data practices in connection with individuals who interact with us, including our customers, their patients, and visitors to our site.

Please read this Policy carefully. By accessing or using the Services, you agree to the terms outlined here. If you do not agree with this Policy, please do not use our Services or provide personal information to us.

1. Information We Collect

Information You Provide to Us

We may collect personal information directly from you when you:

  • Request a demo
  • Use or access the Services
  • Communicate with our team
  • Participate in events or surveys
  • Apply for a job with Locata
  • Interact with us on social media or visit our office

This information may include your name, contact details, company name, job title, and other details you choose to share. If you are a patient of a health center that uses our platform, we may also collect your communication details if you interact with us (e.g., via notification texts), strictly on behalf of your provider.

Information We Collect Automatically

When you use our Services, we automatically collect certain information, including:

  • Log Information: IP address, browser type, access times, pages viewed
  • Device Information: Operating system, device type, browser settings
  • Usage Information: Features accessed, actions taken, frequency of usage
  • Location Information: Inferred from IP address
  • Cookies and Tracking Technologies: See Section 6 for more details

2. Health Information We Process on Behalf of Providers

Locata processes protected health information (PHI) exclusively on behalf of our healthcare provider customers in accordance with our contractual obligations and applicable laws, including HIPAA. This includes intake forms, referral documentation, insurance records, and other administrative data used to support clinical workflows.

We do not use PHI for our own purposes, and access to PHI is strictly controlled. All such data is encrypted at rest and in transit using industry-standard protocols.

3. Use of De-Identified Information

We may use aggregated or de-identified data—stripped of personal identifiers—for purposes such as:

  • Improving our machine learning tools
  • Benchmarking and reporting for providers
  • Developing new features or insights

This data does not identify individuals and may be shared externally, such as in research, publications, or provider reports.

4. How We Use Personal Information

We use your personal information to:

  • Deliver and maintain the Services
  • Communicate with you about your account or inquiries
  • Improve and analyze the performance of our platform
  • Customize user experience and content
  • Monitor security and prevent fraud or misuse
  • Comply with legal obligations
  • Send marketing communications (with opt-out options)
  • Recruit and evaluate job candidates

5. Sharing and Disclosure of Personal Information

We do not sell your personal information. We only share it in limited circumstances to provide the Services, comply with legal obligations, or with your consent. Below are the categories of third parties with whom we may share personal information, and the purposes for doing so:

Service Providers and Vendors

We engage third-party vendors and service providers who perform services on our behalf and under our instructions. These include providers of:

  • Cloud infrastructure and hosting
  • Data analytics and monitoring
  • Customer support tools
  • Communications platforms (e.g., email or SMS delivery)
  • Payment processors (where applicable)
  • CRM and sales enablement tools

These third parties are only given access to the personal information necessary to perform their designated functions and are contractually obligated to protect the information and use it only for the purposes for which it was shared.

Professional Advisors

We may share your personal information with our professional service providers, such as lawyers, accountants, auditors, or insurance providers, where necessary in the course of the services they provide to us. These parties are subject to confidentiality obligations.

Affiliates

Although Locata currently operates as an independent entity, we may in the future be part of a group of affiliated companies. If so, we may share personal information with our future affiliates for purposes consistent with this Privacy Policy and applicable law.

Business Transfers

If Locata is involved in a potential or actual merger, acquisition, financing, reorganization, bankruptcy, dissolution, or other transaction involving the sale or transfer of some or all of our business or assets, your personal information may be disclosed as part of due diligence or transferred as part of that transaction, subject to appropriate confidentiality protections.

Legal Compliance and Protection

We may disclose personal information if we believe it is necessary to:

  • Comply with applicable laws, regulations, legal processes, or government requests (including to meet national security or law enforcement requirements)
  • Enforce our agreements and policies
  • Protect the rights, privacy, safety, or property of Locata, our customers, users, or the public
  • Detect, prevent, or respond to fraud, abuse, security risks, or other malicious activity

De-Identified or Aggregated Data

We may share aggregated or de-identified data that does not reasonably identify you with third parties for research, analytics, product development, or benchmarking purposes.

With Your Consent

In some cases, we may share your personal information with third parties when you explicitly direct us to do so or provide us with your informed consent.

7. Data Security

We take the security of your information seriously. Locata uses encryption, access controls, and other safeguards to protect your data both in transit and at rest. All health data is managed using HIPAA-compliant infrastructure.

While we strive to protect your information, no digital system is 100% secure. You use the Services at your own risk, and we encourage responsible data practices on your end.

8. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy, including legal, regulatory, or operational needs. Health data is retained in accordance with our provider contracts. Usage data may be retained longer for analytics and system improvement.

9. Your Rights and Choices

Depending on your jurisdiction, you may have rights to:

  • Access the personal information we hold about you
  • Correct or update inaccurate information
  • Request deletion of your data
  • Learn how we've shared your data
  • Object to certain uses of your data

To exercise these rights, please contact us at privacy@locatahealth.com. We may require verification of your identity before fulfilling requests.

10. Job Applicants

When you apply for a job at Locata, we collect and process your application data to evaluate qualifications and fulfill our hiring obligations. This may include resumes, contact info, employment history, and optional demographic data.

11. Children

Locata does not knowingly collect personal information directly from children under the age of 16 without appropriate consent. We do not offer Services directly to minors for personal, household, or consumer use.

However, we may process personal and health information about children as part of the Services we provide to healthcare provider customers, who are responsible for collecting that information in compliance with applicable laws (including HIPAA and, where relevant, COPPA). Any such information is processed strictly on behalf of the healthcare provider and pursuant to our contractual agreements, including applicable Business Associate Agreements.

If you are a parent or guardian and believe that your child's personal information has been provided to Locata in error or without proper authorization, please contact us at privacy@locatahealth.com, and we will work with the relevant provider to address the issue.

12. Third-Party Links

Our Services may contain links to third-party websites or platforms. We do not control their privacy practices and encourage you to review their privacy policies before sharing data with them.

13. Changes to This Policy

We may update this Policy from time to time. The latest version will always be posted on our site with the date of last revision. If changes are significant, we will notify you by email or via the Services. Continued use of the Services after updates means you accept the revised terms.

14. Contact Us

If you have any questions or concerns about this Privacy Policy or our practices, please contact us at privacy@locatahealth.com.