Privacy Policy
Effective Date: December 5, 2025
Last Updated: December 5, 2025
Introduction
At Seventure Flow, protecting your privacy is at the core of how we operate, just like safeguarding your revenue cycle is. We're a healthcare technology company focused on revenue cycle management (RCM) services, and we handle sensitive information with the utmost care, especially protected health information (PHI) under HIPAA. This Privacy Policy explains how we collect, use, share, and protect your information when you interact with our website, platform, or services.
This policy applies to all users of our services, including healthcare providers, practice administrators, billing teams, and authorized personnel. If you're a patient whose data is processed through one of our clients (e.g., a medical practice), your privacy rights are primarily governed by that client's HIPAA Notice of Privacy Practices, we act as a Business Associate and support their compliance. We adhere to HIPAA, the California Consumer Privacy Act (CCPA/CPRA), and other relevant laws like GDPR for international users.
We may update this policy periodically to reflect changes in our practices or laws. We'll notify you of significant updates via email (if we have your address), a prominent notice on our site, or in-app alerts. Your continued use after changes indicates acceptance.
1. Introduction to Our Privacy Practices
This section gives you a high-level overview of our approach to privacy. We believe privacy protections should be as reliable as our RCM tools, built to last and easy to understand. Our practices are guided by principles of transparency, security, and user control, ensuring we only handle what we need and give you tools to manage it.
Key commitments include
- Collecting data only for essential RCM functions like claims processing and audits.
- Using industry-leading security for PHI, including encryption and access controls.
- Providing clear opt-outs and rights requests without hassle.
- Regular audits and training to stay compliant with evolving regulations.
1.1. Why Privacy Matters at Seventure Flow?
In healthcare, privacy isn't just a policy, it's a promise. We process billions in claims annually, which means handling PHI that could impact patient care if mishandled. We prioritize yours to build long-term partnerships with practices. This means no unnecessary data retention, no selling your info, and proactive breach notifications.
1.2. Scope of This Policy
This policy covers all online and offline interactions with Seventure Flow, including our website, mobile app (if applicable), customer support, and integrations with EHR/PM systems. It doesn't apply to third-party sites we link to check their policies for details.
2. Information We Collect
We collect information thoughtfully and only what's needed to provide tailored RCM services, improve our platform, and meet legal obligations. This mirrors detailed breakdowns in financial privacy notices, categorizing data by source for clarity. We explain each type below, with examples relevant to healthcare workflows.
2.1. Information You Provide Directly
You share this when signing up, requesting a demo, uploading claims files, or connecting systems always with your explicit input or consent. Examples include: your full name, email, phone, practice details like, NPI, tax ID, specialty like dermatology or cardiology, billing credentials, and PHI such as patient demographics, ICD-10 codes, CPT procedures, dates of service, and denial reasons from your EHR exports. We also collect payment info (e.g., bank details for invoicing) via secure forms, but we don't store full card numbers ourselves.
This data powers core services like personalized audits and dashboards, ensuring accuracy in your revenue recovery.
2.2. Information We Collect Automatically
As you browse our site or use the platform, technical details are captured to enhance functionality and security like how apps track usage for better experiences. This includes IP address, browser/OS type, device ID, session duration, pages viewed (e.g., audit reports), search queries, and interaction logs. Cookies and similar tech help remember preferences, like dashboard layouts.
We use this for non-intrusive analytics, never tying it to PHI without safeguards.
2.3. Information from Third Parties and Partners
We receive data from trusted sources you authorize, such as API feeds from EHRs (e.g., Epic's FHIR endpoints for claims data) or clearinghouses (e.g., eligibility checks via Change Healthcare). Public directories like NPPES provide verification data, and with consent, partners might share aggregated benchmarks (e.g., specialty-specific AR days). We only integrate what's necessary for seamless RCM.
3. How We Use Your Information
Your data fuels our mission to streamline billing and reduce denials, but we use it purposefully and transparently. Like detailed use cases in consumer finance policies, we outline each purpose, the data involved, and why it matters, always balancing service delivery with privacy.
3.1. To Provide and Enhance RCM Services
We process account details, professional info, and PHI to scrub claims, analyze denials, generate AR reports, and optimize payer reimbursements. For instance, we might use historical claims to train algorithms predicting underpayments, helping your practice recover revenue faster. This is our core contractual obligation under HIPAA Business Associate Agreements (BAAs).
3.2. For Communication and Support
Contact info enables service alerts invoices, and responses to tickets. We review chat logs or call recordings (with notice) to resolve issues quickly, like troubleshooting an integration glitch, and improve support quality.
3.3. For Security, Compliance, and Fraud Prevention
Logs and device data help monitor for threats and fulfill. We use this to protect your practice's data, complying with laws like Medicare reporting.
3.4. For Analytics and Research
Aggregated, de-identified data (stripped of all 18 HIPAA identifiers) informs industry insights, like national denial rates by specialty. This enhances our tools without compromising individuals—think of it as anonymized trends powering better features.
3.5. For Marketing and Personalization
With opt-in consent, we send RCM tips or webinar invites via email. Usage data personalizes your dashboard, but you control this anytime.
4. How We Share Your Information
Sharing is limited, vetted, and protected, never for profit. We detail recipients, purposes, and safeguards here, akin to affiliate and vendor disclosures in banking policies, with a focus on healthcare partners.
4.1. With Service Providers and Vendors
We share with cloud hosts (e.g., AWS under BAA), analytics tools (e.g., Google Analytics for anonymized traffic), and payment processors (e.g., Stripe for PCI-compliant invoicing). EHR partners receive only what's needed for integrations, all under strict contracts.
4.2. With Affiliates and Business Partners
Within the Seventure Flow family (if expanded), sharing supports unified services like cross-platform audits. External partners (e.g., credentialing firms) get minimal data with your approval.
4.3. For Legal, Safety, or Business Reasons
We disclose if required by law or to prevent harm. In mergers, data transfers with equivalent protections. We notify you unless prohibited. We never share PHI with marketers or unaffiliated parties.
5. Your Privacy Rights and Choices
Control is key, we make it simple to access, manage, or limit your data, much like opt-out portals in financial notices. Rights vary by location; here's how to exercise them.
5.1. General Rights: Access, Correction, and Deletion
Request a copy of your data, fix errors), or delete non-essential info via [email protected] We'll verify your identity and respond within 45 days.
5.2. Opt-Outs and Preferences
Unsubscribe from emails instantly via links. Disable non-essential cookies in settings.
5.3. State and International Rights
- California (CCPA/CPRA): Rights to know, delete, correct, and limit sensitive data use. We don't sell/share, submit requests online.
- Other States: Similar rights under laws like Virginia's CDPA.
No discrimination for exercising rights.
6. How We Protect Your Information
Security is non-negotiable, especially for PHI. We employ layered defenses, detailed like compliance sections in regulated industries, including encryption and response plans.
6.1. Technical and Organizational Measures
Data is encrypted, with MFA, role-based access, and annual pentests. We train staff on HIPAA and monitor with tools like intrusion detection.
6.2. Incident Response and Notifications
If a breach occurs, we investigate promptly, notify affected parties (within 60 days for HIPAA), and report to regulators.
7. Additional Disclosures:
These cover specifics like retention, cookies, and special notices.
7.1. Data Retention
We retain your information only as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with our contractual obligations to you, and meet applicable legal requirements. After that, we securely delete or anonymize it so it can no longer be associated with you or your practice.
Account information including your name, email address, practice details, NPI, login credentials, and professional profile is kept for the entire duration of our relationship with you and for an additional 10 years afterward. This extended period allows us to assist with any future re-activation, respond to audits, or resolve disputes that may arise long after a contract ends.
Financial records, such as invoices, payment history, and transaction details, are retained for 10 years from the date of the transaction. This aligns with Internal Revenue Service (IRS) requirements, Medicare/Medicaid audit rules, and standard healthcare payer contract obligations.
Protected Health Information (PHI) and all claims-related data, including patient demographics, diagnoses, procedures, dates of service, and denial records are retained for a minimum of 7 years and, in many cases, up to 10 years, depending on your state’s medical record laws, your specific client agreement with us, and any payer-imposed requirements. This ensures we can support appeals, re-submissions, or regulatory inquiries long after the original claim was processed.
Audit logs that record who accessed what data and when are maintained for a minimum of 6 years, as explicitly required by the HIPAA Security Rule. System performance logs, error reports, and security event logs are kept for 12 to 24 months to enable troubleshooting and incident investigation. Support interactions including tickets, chat transcripts, and recorded onboarding or training calls are retained for 3 years to maintain quality standards and resolve any future disputes.
Marketing-related information, such as your subscription preferences, is kept only until you unsubscribe, after which it is removed within 30 days. De-identified and aggregated datasets used for industry benchmarking and product improvement are retained indefinitely because they no longer contain any information that could identify you or your patients. Cookie and analytics identifiers expire automatically after a maximum of 24 months, or sooner if you clear your browser data.
When data reaches the end of its retention period, we use industry-standard secure deletion methods or permanently anonymize it following the HIPAA Safe Harbor standard so that re-identification is impossible.
7.2. Cookies and Tracking Technologies
We use cookies, local storage, pixels, and similar technologies on our website and platform to ensure everything works smoothly, stays secure, and continuously improves based on how you use it.
Strictly necessary cookies and tokens are required for core functions such as logging in, maintaining your session, preventing cross-site request forgery (CSRF) attacks, and loading the platform securely. These cannot be turned off without breaking essential features, but they do not track you across the internet or store personal information beyond your current session.
Performance and analytics cookies primarily from services like Google Analytics, Hotjar, and Mixpanel help us understand how visitors navigate the site, which pages load slowly, where errors occur, and which features are most valuable to practices. These cookies collect anonymized data (often truncated IP addresses) and never contain PHI. You can reject or disable them at any time through our cookie consent banner or by using browser settings and opt-out tools provided by the respective providers.
Functional cookies remember your preferences such as saved dashboard layouts, preferred report filters, or language settings, so your experience feels personalized without requiring you to re-configure everything each time you log in. These are optional and can be managed in the same consent banner.
All non-essential cookies respect the choices you make in our consent management tool, which appears the first time you visit our site and can be reopened anytime via the “Cookie Settings” link in the footer. You also retain full control through your browser’s privacy settings or by installing extensions that block trackers globally.
7.3 Children’s Privacy
Our services are designed exclusively for licensed healthcare professionals and practice administrators who are 18 years of age or older. We do not knowingly collect, maintain, or process personal information from children under 13 (or under 16 in certain jurisdictions). If we discover that we have inadvertently received information from a child below these ages, we will delete it immediately and terminate any associated account.
7.4 International Data Transfers
Seventure Flow operates and stores the vast majority of data within the United States using HIPAA-compliant, U.S.-based cloud infrastructure. When data must be transferred outside the U.S. (for example, to support a client in Canada or the EU), we implement approved safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, executed HIPAA Business Associate Agreements, and, where applicable, additional technical measures like encryption and access restrictions to ensure the same level of protection applies globally.
7.5 CCPA-Specific Disclosure for California Residents
California residents have specific rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA. We collect identifiers, commercial information, professional information, internet activity, and protected health information. Sources include information you provide directly, automated collection, and authorized integrations with your EHR/PM systems. We use this information solely to deliver contracted RCM services, provide support, ensure security, and improve our platform.
We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined by CCPA. We also do not use or disclose sensitive personal information for purposes that would trigger a right to limit it under California law. You may still exercise rights to know, delete, correct, and opt out of any future sale/sharing by submitting a request to [email protected] or through our online rights portal. We will verify your identity and respond within the timelines required by law, and we will never discriminate against you for exercising these rights.
8. Contact Us
We're here to help reach our Privacy Officer anytime.
Email: [email protected]
Phone: +1 (925) 431-6007
Thank you for trusting Seventure Flow, let's keep your practice flowing securely.