SOTERIA HEALTHCARE TECHNOLOGIES LLC
PRIVACY POLICY
Soteria Healthcare Technologies LLC ("Soteria," "we," "our," or "us") respects your privacy and is committed to protecting the personal information entrusted to us.
This Privacy Policy explains how Soteria collects, uses, stores, discloses, protects, and otherwise processes information obtained through our websites, mobile applications, credentialing systems, visitor management systems, biometric authentication systems, facility access management systems, and related services (collectively, the "Services").
By accessing or using the Services, you acknowledge that you have read and understand this Privacy Policy.
1. WHO WE ARE
Soteria Healthcare Technologies LLC provides credentialing, compliance management, visitor management, facility access management, biometric authentication, and related technology services to healthcare facilities and vendors.
Our customers include:
Hospitals
Healthcare Systems
Surgery Centers
Healthcare Facilities
Medical Device Representatives
Pharmaceutical Representatives
Contractors
Service Providers
Other Credentialed Vendors
2. INFORMATION WE COLLECT
The information we collect depends on how you interact with the Services.
A. Account Information
We may collect:
Full name
Email address
Phone number
Business address
Employer information
Job title
Username
Password credentials
Professional identifiers
B. Credentialing Information
We may collect information required by Healthcare Facilities including:
Professional licenses
Certifications
Training records
Insurance documentation
Background screening status
Vaccination records
Compliance documentation
Government-issued identification
Driver's license information
Facility-specific credentialing requirements
C. Visitor Management Information
We may collect:
Check-in history
Facility access records
Badge issuance information
Visitor logs
Access approvals
Facility visitation records
Entry and exit records
D. Protected Health Information (PHI)
Certain Services may involve the collection, storage, transmission, or processing of Protected Health Information ("PHI") as defined under HIPAA.
When PHI is processed through the Services, Soteria maintains safeguards designed to comply with applicable HIPAA requirements and any applicable Business Associate Agreement ("BAA").
E. Biometric Information
Soteria may collect and process biometric information used for identity verification and facility access management.
This may include:
Palm vein biometric templates
Palm authentication records
Biometric verification logs
Soteria does not retain facial recognition templates.
Users may submit profile photographs for credentialing and identification purposes. These photographs may be used in connection with facility access verification but are not converted into retained facial recognition templates.
F. Device and Technical Information
We may collect:
IP address
Browser type
Device identifiers
Operating system
Access times
Referring URLs
Login history
Application activity logs
Error logs
Security logs
G. Location Information
Certain Services may utilize location-enabled technologies to facilitate facility access, visitor management, and operational functionality.
Location information is used solely for operational and security purposes and is not sold or used for advertising.
3. HOW WE COLLECT INFORMATION
We collect information:
Directly From You
When you:
Register for an account
Upload documents
Complete credentialing requirements
Purchase subscriptions
Submit support requests
Participate in surveys
From Healthcare Facilities
Healthcare Facilities may provide:
Credentialing requirements
Access permissions
Compliance requirements
Visitor management information
From Employers
Employers may provide information necessary for credentialing and account administration.
From Service Providers
Authorized service providers may provide:
Background screening results
Training completion records
Identity verification information
Compliance verification data
Automatically
Through cookies, analytics tools, log files, security systems, and related technologies.
4. HOW WE USE INFORMATION
We use information to:
Provide the Services
Verify identities
Administer credentialing programs
Manage facility access
Process subscriptions
Authenticate users
Issue credentials and badges
Maintain visitor records
Provide customer support
Monitor security
Detect fraud
Improve Services
Comply with legal obligations
Fulfill contractual obligations
Enforce our agreements
We do not use PHI, biometric information, or credentialing information for advertising purposes.
5. HIPAA AND PROTECTED HEALTH INFORMATION
Where applicable, Soteria serves as a Business Associate under HIPAA.
When acting as a Business Associate:
PHI is used only for authorized purposes;
Access is limited to authorized personnel;
Appropriate safeguards are maintained;
Disclosures are restricted as required by law and applicable agreements;
PHI is not sold;
PHI is not used for advertising or marketing.
If a conflict exists between this Privacy Policy and an applicable Business Associate Agreement, the Business Associate Agreement shall control with respect to PHI.
6. BIOMETRIC INFORMATION
Soteria may collect palm vein biometric templates to:
Verify identity
Prevent fraud
Facilitate credentialing
Control facility access
Improve security
Soteria does not sell, lease, trade, license, disclose for marketing purposes, or otherwise monetize biometric information.
Soteria does not retain facial recognition templates.
Palm biometric templates are generally retained during an active subscription and are deleted following termination or expiration of the applicable subscription unless retention is required by law or contractual obligation.
Biometric information is disclosed only:
To authorized Healthcare Facilities;
To authorized service providers acting on our behalf;
As required by law;
With user authorization.
7. COOKIES AND ANALYTICS
The Services use cookies, web beacons, analytics technologies, and similar tools to:
Maintain sessions;
Authenticate users;
Improve functionality;
Measure performance;
Detect security threats;
Analyze usage trends.
Users may modify browser settings to manage cookies, although doing so may affect Service functionality.
We may utilize analytics services such as Google Analytics to understand website usage and improve performance.
8. HOW WE SHARE INFORMATION
Soteria may disclose information to:
Healthcare Facilities
For credentialing, access management, compliance verification, visitor management, and operational purposes.
Authorized Customer Administrators
For administration of credentialing programs and facility access systems.
Service Providers
Including providers supporting:
Hosting
Security
Analytics
Identity verification
Background screening
Training verification
Payment processing
Technical support
Legal Authorities
Where required by law, subpoena, court order, or governmental request.
Corporate Transactions
In connection with mergers, acquisitions, financing transactions, asset sales, or corporate restructurings.
9. NO SALE OF INFORMATION
Soteria does not sell:
Personal information;
PHI;
Biometric information;
Credentialing records;
Visitor records;
Facility access records;
Customer Data.
Soteria does not share personal information for cross-context behavioral advertising.
10. DATA RETENTION
Soteria retains information only as long as reasonably necessary for operational, contractual, legal, compliance, security, audit, and business purposes.
Generally:
Credentialing records are retained during active subscriptions;
Profile photographs are retained during active subscriptions;
Palm biometric templates are retained during active subscriptions;
Visitor records, audit logs, access logs, and facility access history may be retained for operational, compliance, legal, security, and historical reporting purposes.
Retention periods may vary depending on applicable legal obligations and customer requirements.
11. INFORMATION SECURITY
Soteria maintains commercially reasonable administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, destruction, loss, misuse, or theft.
Security measures may include:
Encryption of data in transit;
Encryption of sensitive data at rest where appropriate;
Role-based access controls;
Multi-factor authentication where implemented;
Network security controls;
Audit logging;
Security monitoring;
Vulnerability management;
Incident response procedures;
Workforce confidentiality obligations;
Vendor security assessments.
Despite our efforts, no security system is completely secure. Users acknowledge that transmission of information over the Internet involves inherent risks.
12. SECURITY INCIDENTS AND BREACH NOTIFICATION
If Soteria becomes aware of unauthorized access to information requiring notification under applicable law, contractual obligations, HIPAA, or a Business Associate Agreement, Soteria will provide notice within a commercially reasonable timeframe after confirmation of the incident.
Notice timing may be delayed where necessary to:
Comply with law enforcement requirements;
Prevent interference with investigations;
Comply with legal obligations.
Soteria will cooperate with affected customers as reasonably necessary to investigate, mitigate, and respond to the incident.
13. YOUR PRIVACY CHOICES
Users may:
Access account information;
Update account information;
Correct inaccurate information;
Request deletion of eligible information;
Manage communication preferences;
Request information regarding data processing activities.
Certain information may be retained where necessary to:
Comply with legal obligations;
Complete transactions;
Enforce agreements;
Maintain security;
Preserve audit records;
Fulfill contractual obligations to Healthcare Facilities.
14. REVIEWING AND UPDATING INFORMATION
Registered users may update certain account information through their account settings.
If information cannot be modified through the Services, users may submit a request using the contact information listed below.
We may require verification of identity before fulfilling requests.
15. DELETION REQUESTS
Users may request deletion of eligible personal information.
Deletion requests may be denied or partially fulfilled where information must be retained to:
Comply with legal obligations;
Comply with HIPAA;
Maintain security records;
Fulfill contractual obligations;
Preserve evidence;
Complete investigations;
Exercise or defend legal claims;
Comply with healthcare facility requirements.
Certain visitor records, audit records, access logs, and compliance records may be retained as permitted by law.
16. MARKETING COMMUNICATIONS
Soteria may send service-related communications necessary to administer accounts and provide Services.
Where permitted by law, Soteria may send product updates, educational content, event announcements, and marketing communications.
Users may opt out of marketing communications by:
Following unsubscribe instructions;
Updating communication preferences;
Contacting Soteria directly.
Service-related communications may continue even if marketing communications are declined.
17. CHILDREN'S PRIVACY
The Services are intended exclusively for business and professional users.
The Services are not directed toward children under sixteen (16) years of age.
Soteria does not knowingly collect personal information from children under sixteen.
If we learn that personal information of a child under sixteen has been collected inadvertently, we will take reasonable steps to delete such information.
18. INTERNATIONAL DATA TRANSFERS
Soteria's Services are operated primarily within the United States.
Information may be stored, processed, and transferred within the United States and other jurisdictions where our service providers operate.
By using the Services, users consent to such transfers, subject to applicable legal protections.
19. THIRD-PARTY WEBSITES AND SERVICES
The Services may contain links to third-party websites, applications, systems, or resources.
Soteria is not responsible for the privacy practices, content, security, or policies of third parties.
Users should review the privacy policies of any third-party services they access.
20. CALIFORNIA PRIVACY NOTICE
This section applies to California residents and supplements the other provisions of this Privacy Policy.
For purposes of this section, "Personal Information" has the meaning assigned under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA").
21. CATEGORIES OF PERSONAL INFORMATION COLLECTED
During the preceding twelve (12) months, Soteria may have collected:
Identifiers
Name
Email address
Telephone number
Mailing address
Username
IP address
Device identifiers
Customer Records Information
Contact information
Employment information
Professional information
Account information
Protected Characteristics
Where voluntarily provided or required by law.
Commercial Information
Subscription information
Service usage information
Transaction history
Internet Activity Information
Website usage
Application activity
Log information
Professional or Employment Information
Employer information
Job title
Credentialing information
Licensure information
Sensitive Personal Information
Government-issued identification information
Driver's license information
Biometric information
Credentialing records
Vaccination records
Certain health-related information
Precise location information where applicable
Biometric Information
Palm vein biometric templates
Biometric authentication records
Protected Health Information
Certain information may also constitute PHI subject to HIPAA.
22. SOURCES OF INFORMATION
We collect information from:
You;
Healthcare Facilities;
Employers;
Service providers;
Government databases where authorized;
Credentialing partners;
Security systems;
Analytics technologies.
23. BUSINESS PURPOSES FOR COLLECTION
Information may be collected and used for:
Credentialing administration;
Facility access management;
Visitor management;
Identity verification;
Fraud prevention;
Security monitoring;
Subscription administration;
Customer support;
Service improvement;
Compliance with legal obligations;
Performance of contractual obligations.
24. DISCLOSURES OF PERSONAL INFORMATION
Soteria may disclose information to:
Healthcare Facilities;
Authorized customer administrators;
Service providers;
Security vendors;
Government agencies;
Legal authorities;
Professional advisors;
Corporate transaction participants.
25. NO SALE OR SHARING OF PERSONAL INFORMATION
Soteria does not sell personal information.
Soteria does not share personal information for cross-context behavioral advertising.
Soteria does not sell or share:
PHI;
Biometric information;
Credentialing information;
Visitor records;
Facility access records.
26. CALIFORNIA PRIVACY RIGHTS
Subject to applicable exceptions, California residents may have the right to:
Know what personal information we collect;
Access personal information;
Correct inaccurate information;
Delete personal information;
Obtain information in a portable format;
Limit certain uses of sensitive personal information;
Be free from unlawful discrimination for exercising privacy rights.
27. EXERCISING PRIVACY RIGHTS
Requests may be submitted by:
Email;
Written request;
Authorized account portal functionality;
Authorized agents acting on behalf of a consumer.
Before fulfilling requests, Soteria may verify identity and authority.
Authorized agents may be required to provide written authorization and proof of identity.
28. SENSITIVE PERSONAL INFORMATION
Soteria uses sensitive personal information only as reasonably necessary to:
Provide Services;
Verify identity;
Administer credentialing;
Maintain security;
Comply with law;
Fulfill contractual obligations.
Soteria does not use sensitive personal information to infer characteristics for advertising purposes.
29. DO NOT TRACK SIGNALS
Because no universally accepted standard currently exists for interpreting "Do Not Track" browser signals, Soteria does not currently respond to such signals.
Users may manage cookies through browser settings.
30. CHANGES TO THIS PRIVACY POLICY
Soteria may modify this Privacy Policy periodically.
Material changes may be communicated through:
Website notices;
Application notices;
Email communications;
Account notifications.
The Effective Date at the top of this Privacy Policy indicates when the current version became effective.
Continued use of the Services after changes become effective constitutes acceptance of the revised Privacy Policy.
31. CONTACT US
For questions regarding this Privacy Policy, privacy requests, or data protection matters, contact:
Soteria Healthcare Technologies LLC
Email: support@soteriavc.com
General Support:
support@soteriavc.com
Website:
https://www.soteriavc.com
Mailing Address:
2810 N. Church St., Wilmington, DE 19802
California Privacy Requests:
legal@soteriavc.com
Security Reports:
legal@soteriavc.com
If you are submitting a privacy rights request, please provide sufficient information to allow us to verify your identity and process your request.
By using the Services, you acknowledge that you have read and understand this Privacy Policy.
