top of page

SOTERIA HEALTHCARE TECHNOLOGIES LLC

PRIVACY POLICY

Soteria Healthcare Technologies LLC ("Soteria," "we," "our," or "us") respects your privacy and is committed to protecting the personal information entrusted to us.

This Privacy Policy explains how Soteria collects, uses, stores, discloses, protects, and otherwise processes information obtained through our websites, mobile applications, credentialing systems, visitor management systems, biometric authentication systems, facility access management systems, and related services (collectively, the "Services").

By accessing or using the Services, you acknowledge that you have read and understand this Privacy Policy.

1. WHO WE ARE

Soteria Healthcare Technologies LLC provides credentialing, compliance management, visitor management, facility access management, biometric authentication, and related technology services to healthcare facilities and vendors.

Our customers include:

  • Hospitals

  • Healthcare Systems

  • Surgery Centers

  • Healthcare Facilities

  • Medical Device Representatives

  • Pharmaceutical Representatives

  • Contractors

  • Service Providers

  • Other Credentialed Vendors

2. INFORMATION WE COLLECT

The information we collect depends on how you interact with the Services.

A. Account Information

We may collect:

  • Full name

  • Email address

  • Phone number

  • Business address

  • Employer information

  • Job title

  • Username

  • Password credentials

  • Professional identifiers

B. Credentialing Information

We may collect information required by Healthcare Facilities including:

  • Professional licenses

  • Certifications

  • Training records

  • Insurance documentation

  • Background screening status

  • Vaccination records

  • Compliance documentation

  • Government-issued identification

  • Driver's license information

  • Facility-specific credentialing requirements

C. Visitor Management Information

We may collect:

  • Check-in history

  • Facility access records

  • Badge issuance information

  • Visitor logs

  • Access approvals

  • Facility visitation records

  • Entry and exit records

D. Protected Health Information (PHI)

Certain Services may involve the collection, storage, transmission, or processing of Protected Health Information ("PHI") as defined under HIPAA.

When PHI is processed through the Services, Soteria maintains safeguards designed to comply with applicable HIPAA requirements and any applicable Business Associate Agreement ("BAA").

E. Biometric Information

Soteria may collect and process biometric information used for identity verification and facility access management.

This may include:

  • Palm vein biometric templates

  • Palm authentication records

  • Biometric verification logs

Soteria does not retain facial recognition templates.

Users may submit profile photographs for credentialing and identification purposes. These photographs may be used in connection with facility access verification but are not converted into retained facial recognition templates.

F. Device and Technical Information

We may collect:

  • IP address

  • Browser type

  • Device identifiers

  • Operating system

  • Access times

  • Referring URLs

  • Login history

  • Application activity logs

  • Error logs

  • Security logs

G. Location Information

Certain Services may utilize location-enabled technologies to facilitate facility access, visitor management, and operational functionality.

Location information is used solely for operational and security purposes and is not sold or used for advertising.

3. HOW WE COLLECT INFORMATION

We collect information:

Directly From You

When you:

  • Register for an account

  • Upload documents

  • Complete credentialing requirements

  • Purchase subscriptions

  • Submit support requests

  • Participate in surveys

From Healthcare Facilities

Healthcare Facilities may provide:

  • Credentialing requirements

  • Access permissions

  • Compliance requirements

  • Visitor management information

From Employers

Employers may provide information necessary for credentialing and account administration.

From Service Providers

Authorized service providers may provide:

  • Background screening results

  • Training completion records

  • Identity verification information

  • Compliance verification data

Automatically

Through cookies, analytics tools, log files, security systems, and related technologies.

4. HOW WE USE INFORMATION

We use information to:

  • Provide the Services

  • Verify identities

  • Administer credentialing programs

  • Manage facility access

  • Process subscriptions

  • Authenticate users

  • Issue credentials and badges

  • Maintain visitor records

  • Provide customer support

  • Monitor security

  • Detect fraud

  • Improve Services

  • Comply with legal obligations

  • Fulfill contractual obligations

  • Enforce our agreements

We do not use PHI, biometric information, or credentialing information for advertising purposes.

5. HIPAA AND PROTECTED HEALTH INFORMATION

Where applicable, Soteria serves as a Business Associate under HIPAA.

When acting as a Business Associate:

  • PHI is used only for authorized purposes;

  • Access is limited to authorized personnel;

  • Appropriate safeguards are maintained;

  • Disclosures are restricted as required by law and applicable agreements;

  • PHI is not sold;

  • PHI is not used for advertising or marketing.

If a conflict exists between this Privacy Policy and an applicable Business Associate Agreement, the Business Associate Agreement shall control with respect to PHI.

6. BIOMETRIC INFORMATION

Soteria may collect palm vein biometric templates to:

  • Verify identity

  • Prevent fraud

  • Facilitate credentialing

  • Control facility access

  • Improve security

Soteria does not sell, lease, trade, license, disclose for marketing purposes, or otherwise monetize biometric information.

Soteria does not retain facial recognition templates.

Palm biometric templates are generally retained during an active subscription and are deleted following termination or expiration of the applicable subscription unless retention is required by law or contractual obligation.

Biometric information is disclosed only:

  • To authorized Healthcare Facilities;

  • To authorized service providers acting on our behalf;

  • As required by law;

  • With user authorization.

7. COOKIES AND ANALYTICS

The Services use cookies, web beacons, analytics technologies, and similar tools to:

  • Maintain sessions;

  • Authenticate users;

  • Improve functionality;

  • Measure performance;

  • Detect security threats;

  • Analyze usage trends.

Users may modify browser settings to manage cookies, although doing so may affect Service functionality.

We may utilize analytics services such as Google Analytics to understand website usage and improve performance.

8. HOW WE SHARE INFORMATION

Soteria may disclose information to:

Healthcare Facilities

For credentialing, access management, compliance verification, visitor management, and operational purposes.

Authorized Customer Administrators

For administration of credentialing programs and facility access systems.

Service Providers

Including providers supporting:

  • Hosting

  • Security

  • Analytics

  • Identity verification

  • Background screening

  • Training verification

  • Payment processing

  • Technical support

Legal Authorities

Where required by law, subpoena, court order, or governmental request.

Corporate Transactions

In connection with mergers, acquisitions, financing transactions, asset sales, or corporate restructurings.

9. NO SALE OF INFORMATION

Soteria does not sell:

  • Personal information;

  • PHI;

  • Biometric information;

  • Credentialing records;

  • Visitor records;

  • Facility access records;

  • Customer Data.

Soteria does not share personal information for cross-context behavioral advertising.

10. DATA RETENTION

Soteria retains information only as long as reasonably necessary for operational, contractual, legal, compliance, security, audit, and business purposes.

Generally:

  • Credentialing records are retained during active subscriptions;

  • Profile photographs are retained during active subscriptions;

  • Palm biometric templates are retained during active subscriptions;

  • Visitor records, audit logs, access logs, and facility access history may be retained for operational, compliance, legal, security, and historical reporting purposes.

Retention periods may vary depending on applicable legal obligations and customer requirements.

11. INFORMATION SECURITY

Soteria maintains commercially reasonable administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, destruction, loss, misuse, or theft.

Security measures may include:

  • Encryption of data in transit;

  • Encryption of sensitive data at rest where appropriate;

  • Role-based access controls;

  • Multi-factor authentication where implemented;

  • Network security controls;

  • Audit logging;

  • Security monitoring;

  • Vulnerability management;

  • Incident response procedures;

  • Workforce confidentiality obligations;

  • Vendor security assessments.

Despite our efforts, no security system is completely secure. Users acknowledge that transmission of information over the Internet involves inherent risks.

12. SECURITY INCIDENTS AND BREACH NOTIFICATION

If Soteria becomes aware of unauthorized access to information requiring notification under applicable law, contractual obligations, HIPAA, or a Business Associate Agreement, Soteria will provide notice within a commercially reasonable timeframe after confirmation of the incident.

Notice timing may be delayed where necessary to:

  • Comply with law enforcement requirements;

  • Prevent interference with investigations;

  • Comply with legal obligations.

Soteria will cooperate with affected customers as reasonably necessary to investigate, mitigate, and respond to the incident.

13. YOUR PRIVACY CHOICES

Users may:

  • Access account information;

  • Update account information;

  • Correct inaccurate information;

  • Request deletion of eligible information;

  • Manage communication preferences;

  • Request information regarding data processing activities.

Certain information may be retained where necessary to:

  • Comply with legal obligations;

  • Complete transactions;

  • Enforce agreements;

  • Maintain security;

  • Preserve audit records;

  • Fulfill contractual obligations to Healthcare Facilities.

14. REVIEWING AND UPDATING INFORMATION

Registered users may update certain account information through their account settings.

If information cannot be modified through the Services, users may submit a request using the contact information listed below.

We may require verification of identity before fulfilling requests.

15. DELETION REQUESTS

Users may request deletion of eligible personal information.

Deletion requests may be denied or partially fulfilled where information must be retained to:

  • Comply with legal obligations;

  • Comply with HIPAA;

  • Maintain security records;

  • Fulfill contractual obligations;

  • Preserve evidence;

  • Complete investigations;

  • Exercise or defend legal claims;

  • Comply with healthcare facility requirements.

Certain visitor records, audit records, access logs, and compliance records may be retained as permitted by law.

16. MARKETING COMMUNICATIONS

Soteria may send service-related communications necessary to administer accounts and provide Services.

Where permitted by law, Soteria may send product updates, educational content, event announcements, and marketing communications.

Users may opt out of marketing communications by:

  • Following unsubscribe instructions;

  • Updating communication preferences;

  • Contacting Soteria directly.

Service-related communications may continue even if marketing communications are declined.

17. CHILDREN'S PRIVACY

The Services are intended exclusively for business and professional users.

The Services are not directed toward children under sixteen (16) years of age.

Soteria does not knowingly collect personal information from children under sixteen.

If we learn that personal information of a child under sixteen has been collected inadvertently, we will take reasonable steps to delete such information.

18. INTERNATIONAL DATA TRANSFERS

Soteria's Services are operated primarily within the United States.

Information may be stored, processed, and transferred within the United States and other jurisdictions where our service providers operate.

By using the Services, users consent to such transfers, subject to applicable legal protections.

19. THIRD-PARTY WEBSITES AND SERVICES

The Services may contain links to third-party websites, applications, systems, or resources.

Soteria is not responsible for the privacy practices, content, security, or policies of third parties.

Users should review the privacy policies of any third-party services they access.

20. CALIFORNIA PRIVACY NOTICE

This section applies to California residents and supplements the other provisions of this Privacy Policy.

For purposes of this section, "Personal Information" has the meaning assigned under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA").

21. CATEGORIES OF PERSONAL INFORMATION COLLECTED

During the preceding twelve (12) months, Soteria may have collected:

Identifiers

  • Name

  • Email address

  • Telephone number

  • Mailing address

  • Username

  • IP address

  • Device identifiers

Customer Records Information

  • Contact information

  • Employment information

  • Professional information

  • Account information

Protected Characteristics

Where voluntarily provided or required by law.

Commercial Information

  • Subscription information

  • Service usage information

  • Transaction history

Internet Activity Information

  • Website usage

  • Application activity

  • Log information

Professional or Employment Information

  • Employer information

  • Job title

  • Credentialing information

  • Licensure information

Sensitive Personal Information

  • Government-issued identification information

  • Driver's license information

  • Biometric information

  • Credentialing records

  • Vaccination records

  • Certain health-related information

  • Precise location information where applicable

Biometric Information

  • Palm vein biometric templates

  • Biometric authentication records

Protected Health Information

Certain information may also constitute PHI subject to HIPAA.

22. SOURCES OF INFORMATION

We collect information from:

  • You;

  • Healthcare Facilities;

  • Employers;

  • Service providers;

  • Government databases where authorized;

  • Credentialing partners;

  • Security systems;

  • Analytics technologies.

23. BUSINESS PURPOSES FOR COLLECTION

Information may be collected and used for:

  • Credentialing administration;

  • Facility access management;

  • Visitor management;

  • Identity verification;

  • Fraud prevention;

  • Security monitoring;

  • Subscription administration;

  • Customer support;

  • Service improvement;

  • Compliance with legal obligations;

  • Performance of contractual obligations.

24. DISCLOSURES OF PERSONAL INFORMATION

Soteria may disclose information to:

  • Healthcare Facilities;

  • Authorized customer administrators;

  • Service providers;

  • Security vendors;

  • Government agencies;

  • Legal authorities;

  • Professional advisors;

  • Corporate transaction participants.

25. NO SALE OR SHARING OF PERSONAL INFORMATION

Soteria does not sell personal information.

Soteria does not share personal information for cross-context behavioral advertising.

Soteria does not sell or share:

  • PHI;

  • Biometric information;

  • Credentialing information;

  • Visitor records;

  • Facility access records.

26. CALIFORNIA PRIVACY RIGHTS

Subject to applicable exceptions, California residents may have the right to:

  • Know what personal information we collect;

  • Access personal information;

  • Correct inaccurate information;

  • Delete personal information;

  • Obtain information in a portable format;

  • Limit certain uses of sensitive personal information;

  • Be free from unlawful discrimination for exercising privacy rights.

27. EXERCISING PRIVACY RIGHTS

Requests may be submitted by:

  • Email;

  • Written request;

  • Authorized account portal functionality;

  • Authorized agents acting on behalf of a consumer.

Before fulfilling requests, Soteria may verify identity and authority.

Authorized agents may be required to provide written authorization and proof of identity.

28. SENSITIVE PERSONAL INFORMATION

Soteria uses sensitive personal information only as reasonably necessary to:

  • Provide Services;

  • Verify identity;

  • Administer credentialing;

  • Maintain security;

  • Comply with law;

  • Fulfill contractual obligations.

Soteria does not use sensitive personal information to infer characteristics for advertising purposes.

29. DO NOT TRACK SIGNALS

Because no universally accepted standard currently exists for interpreting "Do Not Track" browser signals, Soteria does not currently respond to such signals.

Users may manage cookies through browser settings.

30. CHANGES TO THIS PRIVACY POLICY

Soteria may modify this Privacy Policy periodically.

Material changes may be communicated through:

  • Website notices;

  • Application notices;

  • Email communications;

  • Account notifications.

The Effective Date at the top of this Privacy Policy indicates when the current version became effective.

Continued use of the Services after changes become effective constitutes acceptance of the revised Privacy Policy.

31. CONTACT US

For questions regarding this Privacy Policy, privacy requests, or data protection matters, contact:

Soteria Healthcare Technologies LLC

Email: support@soteriavc.com

General Support:
support@soteriavc.com

Website:
https://www.soteriavc.com

Mailing Address:
2810 N. Church St., Wilmington, DE 19802

California Privacy Requests:
legal@soteriavc.com

Security Reports:
legal@soteriavc.com

If you are submitting a privacy rights request, please provide sufficient information to allow us to verify your identity and process your request.

By using the Services, you acknowledge that you have read and understand this Privacy Policy.

bottom of page