Privacy Policy

Effective and last updated: 2026-08-19

1. About EigenH AI

This Privacy Policy describes how EigenH AI, Inc. (“EigenH AI,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the EigenH AI public website, business activities, account administration, and software services.

EigenH AI, Inc. is a Delaware corporation.

Registered office:

131 Continental Dr, Suite 305
Newark, Delaware 19713
United States

This registered office is provided for corporate identification purposes. Privacy and support requests should be sent to support@eigenh.ai.

2. Scope

This Privacy Policy applies to:

  • The EigenH AI public website.
  • Contact and demonstration requests.
  • Business and marketing communications.
  • Account and organization administration.
  • Customer support.
  • The EigenH AI SaaS platform.
  • Authorized integrations and administrative workflows.

A separate Customer Agreement, Order Form, Data Processing Agreement, or Business Associate Agreement may contain additional or different requirements. Where such an agreement applies, it controls to the extent of any conflict relating to customer service data.

3. HIPAA and PHI Boundary

EigenH AI provides technology to healthcare organizations. Depending on the customer relationship and configured services, EigenH AI may create, receive, maintain, or transmit Protected Health Information (PHI) or electronic Protected Health Information (ePHI) on behalf of a healthcare organization.

In those circumstances, EigenH AI acts as a Business Associate, and the processing of PHI or ePHI is governed by the applicable Customer Agreement, Business Associate Agreement, customer instructions, and applicable law.

Customers must not submit PHI or ePHI unless EigenH AI has approved the applicable production use case in writing and a Business Associate Agreement is in effect.

This public Privacy Policy is not a healthcare provider’s Notice of Privacy Practices. Patients should normally contact their healthcare provider directly to exercise HIPAA rights relating to their health records. EigenH AI will assist its customers as required by an applicable agreement or law.

4. Information We Collect

4.1 Website and business contact information

We may collect:

  • Name.
  • Business email address.
  • Telephone number.
  • Mobile telephone number and text-messaging consent, where you provide them (see Section 19).
  • Organization or practice name.
  • Professional role or title.
  • Information provided in a contact or demo request.
  • Communications sent to EigenH AI.

Do not submit medical information, patient records, insurance information, or other PHI through a general public contact form unless EigenH AI specifically instructs you to use an approved secure workflow.

4.2 Account and administrative information

We may collect information associated with creating and managing an EigenH AI account, including:

  • Account name and identifier.
  • Business contact details.
  • Organization and location membership.
  • Role and permission information.
  • Authentication and security events.
  • Configuration activity.
  • Support communications.

4.3 Technical information

We may collect technical and usage information such as:

  • IP address.
  • Browser and device type.
  • Operating system.
  • Timestamps.
  • Referring pages.
  • Website and application activity.
  • Cookie or similar identifiers.
  • Error and diagnostic information.
  • Security and authentication logs.

4.4 Customer service data

When configured and authorized by a customer, EigenH AI may process service data such as:

  • Patient name and contact information.
  • Appointment requests and appointment details.
  • Practice, provider, service, and location information.
  • Reminders and follow-up status.
  • Call or chat logs.
  • Recordings, transcripts, summaries, and workflow outcomes.
  • Intake and administrative information.
  • Insurance or eligibility-related administrative information.
  • PMS, EHR, scheduling, or integration data.
  • Tasks and authorized staff actions.

Customer service data may include PHI or ePHI.

When a customer enables voice features, EigenH AI may process call audio, recordings, transcripts, summaries, call metadata, and workflow outcomes on the customer’s behalf. A healthcare practice, as the Covered Entity or organization directing the call, is responsible for determining whether a call may be recorded and for providing notices or obtaining consent required by the laws that apply to each call participant. When EigenH AI acts as a Business Associate, it processes that data under the applicable Business Associate Agreement and the customer’s instructions.

Recording announcements are configurable. A customer must enable and test the notice appropriate for its calling workflow. Some U.S. states require the consent of every party to a call. The customer must account for one-party consent requirements and for laws described as two-party or all-party consent laws, including changes in a participant’s location.

5. How We Obtain Information

We may obtain information:

  • Directly from website visitors, customers, users, or authorized representatives.
  • Through use of the website or platform.
  • From customer-authorized PMS, EHR, scheduling, communication, or other integrations.
  • From service providers supporting the platform.
  • From business partners where legally permitted.
  • From public business sources for legitimate business-to-business purposes.

6. How We Use Information

We may use information to:

  • Provide, operate, maintain, and secure EigenH AI services.
  • Create and administer customer accounts.
  • Support authorized AI voice and chat workflows.
  • Coordinate appointments, reminders, intake, follow-ups, and tasks.
  • Provide customer support.
  • Authenticate users and enforce permissions.
  • Monitor reliability and troubleshoot problems.
  • Detect abuse, fraud, or security threats.
  • Improve product functionality and user experience.
  • Meet contractual and legal obligations.
  • Respond to inquiries and demo requests.
  • Communicate with business contacts about EigenH AI products, subject to applicable opt-out rights.

Customer service data is processed to provide the services requested by the customer and in accordance with the applicable agreement and customer instructions.

7. AI-Enabled Processing

EigenH AI may use AI-enabled systems to support administrative workflows, including understanding requests, generating summaries, identifying workflow outcomes, and assisting authorized staff.

AI-generated information may be incomplete or inaccurate. Customers and authorized users are responsible for reviewing outputs before relying on them or using them to update patient, appointment, or practice records.

EigenH AI workflows are not intended to provide diagnosis, treatment, emergency triage, or clinical advice.

Customer Data and AI Model Training

EigenH AI does not use customer PHI to train general-purpose or foundation AI models. Where third-party AI providers support authorized customer workflows, EigenH AI uses service configurations and contractual terms intended to prevent customer content from being used to train those providers’ general-purpose models, and confirms the applicable settings as part of vendor review.

EigenH AI does not sell patient data and does not use PHI for advertising.

8. Cookies and Analytics

This section concerns the public website and public contact or demo forms. It does not describe analytics for customer service data or PHI.

The public website uses cookies and related technologies for website measurement, contact management, bot protection, or error monitoring. The current production technologies are:

Vendor or servicePurposeData it may touch
Google Tag ManagerLoads and manages the website tags listed below after a visitor’s first pointer interactionPage/event metadata and browser, device, or network information used by configured tags
Google Analytics 4Measures website traffic, traffic sources, and page performancePage views and events, referring page, approximate location derived from IP address, browser and device information, cookie identifiers
PostHogProvides website analytics with autocapture and session replay enabledPage views and interactions such as clicks or navigation; page content displayed in the browser; technical identifiers and session state
Apollo.ioIdentifies the organization associated with a visit and supports sales and marketing operationsIP address, page and visit metadata, browser and device information
RB2BMatches a United States visitor’s IP address to an individual professional identity for business-to-business sales outreachIP address, page and visit metadata, and the professional identity RB2B matches from its own data, such as a name or professional profile
CalendlyRuns the scheduling calendar embedded on the book-demo page and books the meeting you selectName, email address, time zone, the meeting time you select, and the answers you give to the booking questions
SentryMonitors website errors and performancePage or route information, browser or device details, IP address, error traces, and diagnostic events
Amazon Web Services (AWS)Hosts and delivers the public website through S3 and CloudFrontNetwork request data such as IP address, requested URL, headers, or timestamps

The Cookie Policy lists the individual cookies each of these services sets, what each one does, and how long it lasts.

PostHog session replay can reproduce the page content displayed in a browser and the visitor’s interactions with it. Form input values are masked in replay. PostHog may use cookies or local storage for identifiers and session state.

RB2B is a business-to-business visitor identification service. It matches visits originating from United States IP addresses against its own identity data, which means EigenH AI may learn the name or professional profile of an individual who visited the public website without that person submitting a form. RB2B does not perform this match on visits from outside the United States. RB2B is registered as a data broker in California, Texas, Vermont, and Oregon, and a person may ask RB2B directly to be excluded from its data. A person may also ask EigenH AI to stop this processing by using the contact details in Section 14.

Google Tag Manager is a tag-management system and may not set a cookie itself. Sentry and the AWS or Resend services do not function as advertising cookies in this deployment, but they process the technical or form data described above. The cookies and storage used by the remaining browser-based services may change when those vendors update their services.

EigenH AI does not intend for customers or users to place PHI into public website analytics systems. Customers must use approved product workflows for patient or healthcare information.

Visitors can decline non-essential cookies from the notice shown on a first visit, and can change that choice at any time from the Your Privacy Choices link in the site footer. EigenH AI also recognizes the Global Privacy Control browser signal — see Section 15.3. Browser controls may allow visitors to restrict or delete certain cookies in addition to these choices. Restricting cookies may affect some website features.

9. Website Vendors and Customer-Service Subprocessors

The named vendors in Section 8 support the public website, marketing operations, or the book-demo workflow. They are not approved to receive PHI merely because they appear in that list.

Customer service data and PHI are separate from public website and marketing data. Additional providers may support customer-authorized voice, messaging, hosting, integration, or AI workflows. Where a provider creates, receives, maintains, or transmits PHI or ePHI, the applicable Customer Agreement, Business Associate Agreement, customer instructions, and legally required flow-down terms govern that processing.

10. How We Disclose Information

We may disclose information to:

  • Cloud infrastructure and hosting providers.
  • Communication, voice, SMS, email, and messaging providers.
  • Identity, security, logging, and support providers.
  • Analytics providers used for non-PHI public website analytics.
  • Customer-authorized PMS, EHR, scheduling, insurance, and integration providers.
  • Professional advisers, auditors, insurers, and legal advisers.
  • Government authorities where required by law.
  • Parties involved in a merger, financing, acquisition, restructuring, or sale of assets, subject to appropriate safeguards.

Service providers are permitted to process information only for authorized purposes and subject to applicable contractual requirements.

Where a vendor or subprocessor creates, receives, maintains, or transmits PHI or ePHI, appropriate contractual safeguards and a Business Associate Agreement or equivalent flow-down terms are required where applicable.

Mobile and SMS exception. Mobile phone numbers, SMS opt-in data, and text messaging consent are excluded from the disclosures described in this section. That information is not sold, rented, shared, or otherwise disclosed to third parties or affiliates for their marketing or promotional purposes. It is shared only with the service providers that assist EigenH AI in delivering its messaging services, and only as necessary to provide those services. Section 19 governs this information and controls over any other data-sharing provision in this Privacy Policy.

11. Security

EigenH AI maintains administrative, technical, and organizational safeguards intended to protect information based on the nature of the service, the information involved, the approved deployment, and the associated risks. Customer data is encrypted in transit using TLS and encrypted at rest in production environments hosted on AWS.

The security program addresses areas such as access management, authentication, data protection, logging, monitoring, incident response, vendor review, retention, and secure development.

No internet-based service can guarantee absolute security. Customers must not submit PHI until EigenH AI has confirmed that the applicable environment and contractual safeguards are approved for that use.

12. Data Retention

We retain information for as long as reasonably necessary to:

  • Provide and support the services.
  • Comply with Customer Agreements and Business Associate Agreements.
  • Meet legal, security, accounting, and operational requirements.
  • Resolve disputes.
  • Enforce applicable agreements.

Retention periods for customer service data may depend on the customer’s configuration, applicable agreement, legal requirements, and the type of data involved.

Deletion or retention requests involving patient records should normally be submitted through the relevant healthcare provider.

13. Customer and Patient Requests

Healthcare providers are generally responsible for responding to patient requests concerning access, correction, amendment, restrictions, or accounting relating to health records.

Where required by an applicable agreement or law, EigenH AI will assist the healthcare provider in responding to such requests.

Website visitors and business contacts may contact EigenH AI to request access to, correction of, or deletion of their personal information, subject to applicable law and permitted exceptions.

14. Privacy Rights and Choices

Depending on where a person resides, applicable law may provide rights regarding personal information, such as the right to request access, correction, deletion, restriction, or information about disclosures.

To submit a request, email support@eigenh.ai with the subject line “Privacy Request.”

EigenH AI may need to verify the requester’s identity and authority before completing a request.

15. California Notice at Collection and CCPA/CPRA Rights

This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), applies to EigenH AI’s processing.

15.1 Notice at collection

EigenH AI collects the following categories of personal information for the purposes described below. Section 4 gives examples, Sections 5 and 6 explain sources and uses, and Sections 8 through 10 identify the public-site technologies and recipients.

California categoryExamples EigenH AI may collectMain purposes
IdentifiersName, business email, telephone number, account identifier, IP address, cookie or similar identifierRespond to requests, administer accounts, secure services, and communicate with business contacts
Customer-record informationContact details, organization details, account information, and support correspondenceManage customer relationships, provide support, and maintain business records
Commercial informationSubscription, order, billing, service, or demo-request informationAdminister purchases, customer relationships, and requested services
Internet or electronic activityPage views, clicks, navigation, session replay, referring page, browser, device, and service activityMeasure the public website, diagnose errors, secure forms, and improve website operation
Professional informationOrganization, practice, role, title, and business contact informationRespond to business inquiries and administer customer accounts
Audio, electronic, or similar informationCall recordings, transcripts, messages, session replay, and support communicationsProvide customer-configured voice workflows, support users, and review authorized operations
InferencesCall or workflow outcomes and website interaction patternsProvide requested workflows and understand public website use
Sensitive personal informationAccount credentials and health information that may be contained in customer service dataAuthenticate users and provide customer-authorized services subject to the applicable agreement and BAA

EigenH AI retains these categories under the criteria in Section 12. It does not use public website analytics as an approved channel for PHI.

15.2 Categories disclosed and sale or sharing

During the preceding 12 months, EigenH AI may have disclosed identifiers, customer-record information, commercial information, internet or electronic activity, professional information, and audio or electronic information to the vendors and other recipients described in Sections 8 through 10 for the stated business purposes.

EigenH AI does not exchange personal information for money. It does disclose identifiers and internet activity to the marketing and sales vendors named in Section 8 — currently Google Analytics 4, Apollo.io, and RB2B — and treats those disclosures as a “sale” or “sharing” under California law even though no money changes hands. Section 15.3 explains how to opt out, and the opt-out is available from the Your Privacy Choices link in the site footer.

The disclosures to PostHog, Calendly, Sentry, and Amazon Web Services support website measurement, meeting scheduling, error monitoring, and hosting. EigenH AI does not treat them as a sale or sharing for cross-context behavioral advertising.

Mobile phone numbers, SMS opt-in data, and text messaging consent are excluded from any sale or sharing. EigenH AI does not sell or share that information, and it is not disclosed to the marketing and sales vendors named in Section 8. See Section 19.

15.3 California rights

Subject to legal exceptions and verification, a California resident may request:

  • The categories and specific pieces of personal information EigenH AI collected about the resident, the sources, the purposes, and the categories of recipients.
  • Deletion of personal information EigenH AI collected from the resident.
  • Correction of inaccurate personal information.
  • An opt-out from the sale or sharing of personal information.
  • A limit on use or disclosure of sensitive personal information where the CCPA/CPRA provides that right.

EigenH AI will not discriminate against a resident for exercising a CCPA/CPRA right.

To opt out of the sale or sharing of personal information, use the Your Privacy Choices link in the site footer. That choice applies to the browser and device that makes it and takes no more steps than opting in.

To exercise any other right, email support@eigenh.ai with the subject line “California Privacy Request.” State the right you wish to exercise and provide enough information for EigenH AI to identify the relevant records. An opt-out request may also be sent by email with the subject line “Do Not Sell or Share My Personal Information.” Do not send medical information or account passwords by email.

EigenH AI may verify identity or authority before acting on a request. An authorized agent may submit a request on a resident’s behalf. EigenH AI may ask the agent for signed permission and may verify the resident directly where permitted by law.

A browser may send an opt-out preference signal, including Global Privacy Control (GPC). EigenH AI treats a recognized signal as a request to opt out for the browser or device that sends it: when GPC is detected, the analytics and marketing technologies in Section 8 are never loaded. The Your Privacy Choices page confirms when a signal has been recognized and honored.

Requests about patient records or PHI should normally go to the healthcare provider that controls the records. Privacy laws may exempt some medical information or PHI from parts of the CCPA/CPRA. EigenH AI will assist a customer where an applicable agreement or law requires it.

16. Processing Locations

Information may be processed in locations where EigenH AI, its customers, or its approved service providers operate.

Processing locations, hosting commitments, and data-residency requirements may be further defined in the applicable Customer Agreement or deployment documentation.

17. Children’s Privacy

EigenH AI is a business-to-business healthcare technology platform and is not directed to children for independent use.

Information about a minor may be processed only when submitted or authorized by a healthcare organization, parent, guardian, or other authorized person as part of an approved customer workflow.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our services, legal requirements, or privacy practices.

The updated version will be posted on this page with a revised “Last updated” date. Additional notice will be provided where required by applicable law or agreement.

19. SMS Communications & Mobile Information

When you provide your mobile phone number and consent to receive text messages from EigenH AI, Inc., we may use your mobile number to send appointment confirmations, appointment reminders, scheduling-related notifications, and support-related communications.

Message frequency may vary. Message and data rates may apply. You may opt out of receiving text messages at any time by replying STOP. For assistance, reply HELP.

Mobile phone numbers, SMS opt-in data, and text messaging consent will not be sold, rented, shared, or otherwise disclosed to third parties or affiliates for their marketing or promotional purposes.

Text messaging originator opt-in data and consent are excluded from any other data-sharing provisions described in this Privacy Policy.

We may share mobile information only with service providers that assist us in delivering our messaging services, and only as necessary to provide those services. Such service providers are not permitted to use mobile information or messaging consent for their own marketing or promotional purposes.

20. Contact

For privacy or data-protection questions, contact:

EigenH AI, Inc.
Email: support@eigenh.ai

Registered office:

131 Continental Dr, Suite 305
Newark, Delaware 19713
United States