IV ImgVlt

Legal

Privacy Policy

Effective date: July 9, 2026 ยท Version 2026-07-09

1. Scope and our role

This Privacy Policy explains how ImgVlt collects, uses, discloses, retains, and protects information through its public websites and the ImgVlt Service.

For account, billing, website, sales, and support information, ImgVlt generally determines the purpose of processing. For patient information submitted by a healthcare organization, that organization controls the information and ImgVlt processes it on the organization's instructions as a service provider and, where applicable, business associate. The applicable Business Associate Agreement ("BAA") governs protected health information ("PHI").

2. Information we collect

Account and organization information. Names, job titles, email addresses, phone numbers, organization details, user roles, credentials, authentication settings, and communication preferences.

Billing information. Billing contact, business name, address, phone number, plan, usage, invoices, payment status, and limited payment-method details such as card brand and last four digits. Stripe processes full card numbers and security codes; ImgVlt does not store them.

Customer and patient data. Images, DICOM files and metadata, videos, documents, reports, measurements, demographics, clinical details, workflow history, assignments, signatures, and other information Customer submits or generates in the Service.

Device, security, and usage data. IP address, browser, operating system, device identifiers, dates and times, pages and features used, errors, authentication events, audit logs, security events, and diagnostic data.

Communications. Demo requests, support messages, feedback, training interactions, and other communications. Public contact and ordinary email channels must not be used to send PHI.

3. How we use information

ImgVlt uses information to provide and operate the Service; create and secure accounts; authenticate users; store and display studies; support reporting and workflow features; process payments and invoices; provide support; communicate about service, security, billing, and legal matters; monitor reliability; prevent fraud and misuse; enforce agreements; comply with law; and protect patients, customers, ImgVlt, and others.

ImgVlt processes PHI only as permitted by the BAA, Customer's instructions, and applicable law.

4. Properly de-identified data, research, and machine learning

Where Customer has authorized it in the Terms and BAA, ImgVlt may de-identify PHI under 45 C.F.R. 164.514 using Safe Harbor or Expert Determination. De-identification may address structured fields, free text, DICOM headers, file metadata, burned-in annotations, image pixels, audio, video, and documents. Merely removing a name is not treated as sufficient.

After information has been properly de-identified so that it neither identifies nor provides a reasonable basis to identify an individual, ImgVlt may use and combine it for service analytics, quality assurance, security, benchmarking, product development, scientific and operational research, and the development, training, testing, validation, and improvement of machine-learning and artificial-intelligence systems.

ImgVlt may share properly de-identified information with approved vendors and research collaborators under written restrictions that prohibit re-identification or attempted re-identification, patient contact, patient-level advertising, sale of patient profiles, combination with other data for re-identification, and use beyond the approved purpose. ImgVlt does not provide a re-identification key. ImgVlt does not sell PHI or use PHI for advertising.

5. When we disclose information

ImgVlt may disclose information to cloud, security, communications, analytics, support, document-processing, and other service providers that need it to perform contracted services. A provider that handles PHI must be bound by the restrictions required by the BAA and HIPAA.

ImgVlt may disclose limited billing information to Stripe and related financial institutions; information to an integration Customer enables; information to professional advisers under confidentiality duties; and information when required by law or reasonably necessary to protect rights, safety, security, or the Service.

If ImgVlt is involved in a merger, financing, acquisition, reorganization, or sale of assets, information may be transferred subject to applicable confidentiality, privacy, and BAA obligations.

6. Cookies and similar technologies

ImgVlt may use cookies and local storage that are necessary for authentication, security, session continuity, preferences, and core functionality. ImgVlt does not authorize advertising trackers to collect PHI from authenticated clinical workflows. Browser settings may block some technologies, but doing so may prevent the Service from working correctly.

7. Security

ImgVlt uses administrative, technical, and physical safeguards designed to protect information, including access controls, tenant isolation, audit logging, encrypted transport, authentication protections, monitoring, and restricted workforce access. Security is a shared responsibility and no internet-connected service can guarantee absolute security.

Customer is responsible for user provisioning, device security, endpoint protection, workforce training, secure networks, exports, downloaded copies, and promptly reporting suspected incidents.

8. Retention and deletion

ImgVlt retains account and Customer Data for the subscription term and according to the selected retention settings, contractual commitments, backup cycles, legal obligations, dispute needs, and legitimate security and billing purposes. The BAA governs return, destruction, and permitted retention of PHI after termination.

Properly de-identified information and non-identifying aggregate statistics may be retained after account closure because they no longer identify a patient, subject to the contractual use restrictions described above.

9. Choices and rights

Authorized tenant administrators may review and update organization, user, and payment-method information through available account tools or by contacting ImgVlt. Business contacts may request access, correction, or deletion of their contact information and may opt out of non-essential marketing communications.

Patients should direct requests about medical records or PHI to the healthcare organization that provided care or controls the tenant. ImgVlt will assist that organization as required by the BAA and applicable law.

Depending on location and law, a person may have additional privacy rights. ImgVlt will verify and respond to valid requests and will not discriminate for exercising a legal right. Some information may be exempt or must be retained.

10. Children

The Service is sold to healthcare organizations and is not directed to children for independent account creation. Patient information about minors may be processed only on a healthcare customer's instructions and subject to the BAA and applicable law.

11. Changes to this policy

ImgVlt may update this Privacy Policy to reflect legal, operational, or product changes. Material changes will be communicated through the Service, by email, or through required re-acknowledgment. The effective date and version identify the current policy.

12. Contact

Privacy questions or requests may be sent to [email protected] for routing to the appropriate privacy contact. Do not include PHI in ordinary email.