...

Privacy Policy

1. Overview

Innobot Health (“Innobot,” “we,” “our,” or “us”) is a U.S.-based healthcare-automation company that “puts existing workflows on autopilot”. We design low-code, AI-driven robotic-process-automation (RPA) and revenue-cycle solutions that help hospitals, physician groups, and payers reduce cost and administrative burden. This Privacy Policy governs all personal data processed through:

  • innobothealth.com and any sub-domain (the “Site”);

  • demo tenants, APIs, and mobile apps (collectively, the “Services”); and

  • offline interactions such as events, webinars, sales calls, and recruiting.

The Site is informational only; we do not collect or process payment card data or conduct e-commerce on the public website.

When Innobot acts as a Business Associate under the U.S. Health Insurance Portability and Accountability Act (“HIPAA”), the governing Business Associate Agreement (BAA) prevails for Protected Health Information (“PHI”).

2. Key Definitions

TermMeaning
Personal Data / Personal InformationAny information relating to an identified or identifiable natural person (GDPR Art 4(1), Cal. Civ. Code §1798.140).
Sensitive Personal DataSpecial-category data (GDPR Art 9), “Sensitive Personal Information” (CPRA), PHI (HIPAA 45 C.F.R. §160.103), biometric templates, precise geolocation, etc.
ProcessingAny operation performed on Personal Data (collection, storage, analysis, transfer, deletion, etc.).
Applicable Data-Protection Laws (“ADPLs”)EU GDPR ( GDPR 2016/679GDPR 2016/679 ), UK GDPR & DPA 2018, CCPA/CPRA ( California CCPA/CPRA ), HIPAA ( HIPAA Rules ), India DPDPA 2023 ( India Digital Personal Data Protection Act 2023 ), and any other law that applies to us.

3. Data We Collect

CategoryTypical ExamplesWhy We Collect It
Identity & ContactName, business e-mail, phone, employer, job titleDemo scheduling, newsletters, support queries, recruiting
Device & UsageIP address, browser type, OS, referring URLs, pages visited, clickstream, crash logsSite security, analytics, product improvement
Marketing PreferencesOpt-in status, webinar attendance, survey responsesSend thought-leadership, event invites, satisfaction polls
Customer-Supplied ContentFiles or data uploaded to a secure demo tenant (may include PHI)Proof-of-concept evaluation, model training (if contract permits)

No Payment Data: We never request or store credit-card numbers, bank-account details, or ACH information on the public Site.

4. How We Collect Data

  • Directly from you – web forms, chat widgets, event sign-ups, résumé submissions.

  • Automatically – server logs, first-party cookies, telemetry SDKs.

  • Third-party sources – authorized resellers, conference attendee lists, public professional profiles (e.g., LinkedIn).

5. Why & How We Use Data

PurposeGDPR BasisCPRA CategoryHIPAA Basis (if PHI)
Provide & improve the ServicesArt 6(1)(b) Contract + Art 6(1)(f) Legit. Interest“Identifiers”, “Internet Activity”§164.506(a) (TPO)
Demo scheduling & customer supportIP addArt 6(1)(b)ress, browser type, OS, referring URLs, pages visited, clickstream, crash logs “Identifiers” §164.506(c)
Product R&D / AI model training (de-identified)Art 6(1)(f) “Inference Data” (aggregated)De-identification §164.514(b)
Marketing communications (opt-in only)Art 6(1)(a) Consent“Commercial Info”N/A
Security, fraud, complianceArt 6(1)(c) Legal Obligation“Internet Activity”§164.308(a) Safeguards

Automated decision-making is limited to non-legal effects (spam filtering, dynamic UI). Human review is available on request.

6. Tracking Technologies

TypeExamplesControl
Strictly NecessarySession cookies, load-balancer tokensRequired to deliver the Site
AnalyticsFirst-party telemetry; Google Analytics 4 with IP anonymizationOpt-out via browser add-on or disable cookies
Advertising (B2B only)LinkedIn Insight TagPrior consent for EU/UK; opt-out via AdChoices

We honor Global Privacy Control (GPC) signals and Do Not Track where technically feasible.

7. Data Sharing & Disclosure

RecipientPurposeSafeguard
Cloud infrastructure & observability (ISO 27001 / SOC 2 providers)Hosting, logging, performance monitoringData-Processing Addendums; encryption
Customer-relationship toolsCRM, marketing automation, ticketingDPAs; role-based access
Professional advisorsLegal, accounting, auditsConfidentiality undertakings
Regulators & law enforcementCompliance with subpoenas, court ordersLogged & narrowly scoped
Corporate successorsMerger, acquisition, restructureNotice + continued protection

We never “sell” or “share” Personal Data as those terms are defined by the CPRA.

8. International Transfers

  • EEA/UK → USA — Standard Contractual Clauses (SCC 2021/914) + supplementary safeguards (encryption, zero-trust).

  • Other regions — Adequacy decisions, Binding Corporate Rules, or lawful derogations under GDPR Art 49.

9. Security Measures

  • TLS 1.3 with HSTS; AES-256 encryption at rest; field-level encryption for PHI.

  • Zero-trust network segmentation, least-privilege IAM, mandatory MFA.

  • 24 × 7 × 365 Security Operations Centre with SIEM, IDS/IPS, and EDR.

  • Annual SOC 2 Type II and ISO 27001 audits; HIPAA risk assessment refreshed yearly.

10. Retention & Disposal

Data SetTypical RetentionDisposal
Web & API logs24 monthsCryptographic wipe
Marketing contact recordsUntil opt-out + 24 monthsAnonymization
Contracts & legal docs7 yearsSecure shred / purge
PHI in demo tenantAs defined in BAA (usually ≤ 30 days post-demo)NIST SP 800-88 media purge

11. Your Privacy Rights

RegionRights SummaryHow to Exercise
EU/UK GDPRAccess, rectification, erasure, restriction, portability, objection, withdraw consentE-mail info@innobothealth.com; we respond ≤ 30 days
California CPRAKnow, delete, correct, opt-out of sale/share, limit sensitive PI, non-discriminationWeb form or toll-free 888-341-1009
India DPDPAAccess, correction, erasure, grievance redress, consent withdrawalContact Data Protection Officer
HIPAAInspect PHI, amend, accounting, restrict, confidential commsSubmit HIPAA Request Form

Identity verification is required; we maintain request logs for audit.

12. Children’s Privacy

The Services are not directed to children under 13 (COPPA) and we do not knowingly collect data from minors. Parents may request deletion via Section 11.

13. Changes to This Policy

We post updates here and provide 15 days’ advance notice (banner or e-mail) for material changes. Continued use after the effective date constitutes acceptance.

14. Contact

Scroll to Top

Sample Job Application Form

We are an Equal Opportunity Employer and committed to excellence through diversity.

Innobot-Health|Homepage