Trust Center & Governance

Privacy Policy

How Exxari collects, processes, stores, and safeguards personal health data and online account details.

1. Our Privacy Commitment

Exxari ("we," "us," or "our") is dedicated to maintaining high standards of data privacy and transparency across our web applications, diagnostic tools, and associated platforms (collectively, the "Services").

This policy outlines how personal health information and user data are handled under relevant laws, including HIPAA and applicable federal and state data privacy regulations.

Regulatory Scope Notice:

This Privacy Policy forms an integral part of our HIPAA compliance framework. Covered Entities and Healthcare Providers using our services should also review our formal Business Associate Agreement (BAA).

2. Information We Collect

2.1 Information Provided Directly

  • Account Credentials: Full name, professional title, email address, contact numbers, and access credentials.
  • Clinical & Health Data: Laboratory reports, blood panels, diagnostic data, medical history, and biomarker metrics uploaded to the workstation.
  • Billing & Subscription: Billing address and payment transaction identifiers (processed via PCI-DSS compliant payment gateways).

2.2 Automatically Collected System Telemetry

  • Device & Network Data: IP addresses, browser types, operating systems, and device identifiers.
  • Usage Logs: System feature interactions, page response times, error logs, and session duration telemetry.
  • Cookies & Identifiers: Session state tokens and technical cookies required for application stability.

2.3 Third-Party & Partner Data

  • Information submitted by authorized healthcare providers or integrated clinical EHR systems.
  • Identity verification metrics supplied by fraud prevention services.

3. How We Use Information

Data collected by Exxari is used strictly for operational, clinical, and security purposes:

  1. Service Delivery: Processing biomarker records, extracting panel metrics, and displaying analytical summaries.
  2. System Communications: Dispatching service updates, security alerts, and transactional account notices.
  3. Infrastructure Integrity: Monitoring system reliability, diagnosing performance issues, and preventing unauthorized access.
  4. Regulatory Compliance: Fulfilling auditing obligations and maintaining statutory HIPAA compliance logs.

4. Information Sharing & Disclosure

We do not sell personal data or medical records. Information is shared only under the following defined parameters:

  • Subcontractors & Subprocessors: Cloud storage vendors and infrastructure providers bound by non-disclosure protocols and BAAs.
  • Clinical Authorization: Sharing records with explicitly authorized care providers or clinical partners upon user direction.
  • Legal Requirements: Disclosures mandated by valid subpoenas, court orders, or statutory healthcare regulations.
  • Anonymized Analytics: De-identified, aggregated dataset metrics used strictly for algorithmic evaluation and performance benchmarking.

5. Security & Technical Safeguards

We implement technical and physical controls matching NIST and HIPAA security guidelines:

  • AES-256 bit encryption applied to all stored database fields and data at rest.
  • TLS 1.2+ secure socket layer protection for all API communication in transit.
  • Mandatory Multi-Factor Authentication (MFA) across all platform accounts.
  • Continuous network vulnerability scans and periodic third-party penetration audits.

6. Data Retention Schedule

Information is retained in accordance with statutory requirements and active account status:

  • Account Profile Data: Maintained for the duration of active registration plus 3 years.
  • PHI & Clinical Records: Retained for a minimum of 6 years in accordance with HIPAA mandates.
  • Financial Transaction Logs: Retained for 7 years as required by federal tax and financial regulations.
  • Audit Logs: Preserved for 2 years for continuous security monitoring.

7. Individual Privacy Rights & Choices

Users retain explicit rights regarding their personal data under applicable privacy frameworks:

  1. Right to Access & Portability: Obtain an exportable copy of account data and uploaded records.
  2. Right to Rectification: Request correction of inaccurate profile or account information.
  3. Right to Erasure: Request account deletion, subject to statutory healthcare retention laws.
  4. Communication Preferences: Opt out of non-essential account or promotional updates at any time.

Privacy Office & Contact Information

If you have questions regarding this policy, wish to submit a privacy request, or need to report a data security issue, please contact our designated Privacy Officer:

Office AddressPrivacy Office, Exxari Inc.