VALOR SCRIBEAI

Privacy Policy

Operator: The Digital Agency. Platform: VA C&P Exam AI Scribe / VALOR AI Scribe. Official privacy contact: support@the-digital-agency.io. This Privacy Policy describes how we collect, protect, process, and retain provider account data and clinical information. Last updated August 2026.

Last updated August 2026

1. Information we collect

Provider Account & Identity Data (PII): Full name, medical credentials, NPI number, clinical role, practice/clinic affiliation, billing address, and account email address.

Clinical Encounter Content (PHI): Information uploaded or generated during an examination session, including ambient audio recordings, live speech-to-text transcripts, DBQ form inputs, range-of-motion degree measurements, wound/scar upload images, and AI-generated medical opinion rationale drafts.

Operational & Audit Data: Technical metadata required for security and HIPAA compliance, including user IP addresses, browser/device user agents, authentication timestamps, and immutable Row Level Security (RLS) database access logs.

2. How information is used

Core Platform Operation: To execute ambient audio transcription, DBQ field auto-population, range-of-motion calculations, wound staging analysis, and document export generation on your behalf.

HIPAA Audit Trail Compliance: To maintain legally required access logs (§ 164.312(b)) tracking every instance of PHI creation, retrieval, modification, or export.

STRICT NON-DISCLOSURE: We DO NOT sell, rent, license, or monetize any personal data or Protected Health Information (PHI). We DO NOT use clinical encounter content for marketing or advertising purposes.

3. AI processing & zero data retention (ZDR) guarantee

Enterprise AI Infrastructure: Audio transcripts and structured clinical parameters are transmitted to third-party AI LLM infrastructure providers (e.g., Azure OpenAI / OpenAI Enterprise / Anthropic) over encrypted TLS 1.3 connections strictly to return draft clinical notes.

ZERO DATA RETENTION (ZDR): All third-party AI API integrations explicitly enforce Zero Data Retention (ZDR) policies. AI providers do NOT store, log, retain, or inspect your audio buffers or transcripts after returning the initial text payload.

NO MODEL TRAINING: Your clinical data, patient dialogues, and examination records are NEVER used to train, fine-tune, or improve third-party foundation models or public AI systems.

4. Data security, encryption & storage safeguards

Encryption Standards: All data in transit is encrypted using TLS 1.3. All database records containing PHI or PII are encrypted at rest using AES-256 encryption via Supabase Vault / pgcrypto.

Account Isolation (RLS): Database records are isolated per provider utilizing strict Supabase Row Level Security (RLS) policies (`auth.uid() = provider_id`). Platform administrators cannot access patient PHI without explicit authorization.

Automatic Session Protection: The application enforces a 15-minute inactivity timer that automatically locks active encounter workspaces to prevent unauthorized physical access on shared clinical workstations.

5. HIPAA compliance & business associate agreements (BAA)

Role Designation: You (or your healthcare organization) operate as the Covered Entity or Business Associate. The Digital Agency acts as a Business Associate providing software services.

BAA Execution: To process un-anonymized Protected Health Information (PHI) through the Service, a formal Business Associate Agreement (BAA) must be executed. Request a BAA by emailing support@the-digital-agency.io.

6. Data retention, export & account deletion

Clinician Control: You retain full ownership and control of your clinical encounter files. You may export DBQ summaries or permanently delete individual encounters at any time from your dashboard.

Permanent Purging: When an encounter or account is deleted, the corresponding database rows and stored attachments are immediately removed from active systems and purged from standard automated backups within 30 days.

7. Your rights & privacy contact

For questions regarding this Privacy Policy, HIPAA compliance verification, BAA execution, or privacy-related inquiries, contact our Privacy Officer:

The Digital Agency

Email: support@the-digital-agency.io

Subject Line: Privacy & HIPAA Compliance Request