1. Scope and Who We Are
This Privacy Policy explains how The Biogenesys Health Tech LLC, doing business as BIOD (“BIOD,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information in connection with our public website at biod.ai, our professional clinical intelligence platform at med.biod.ai, and related support, onboarding, pilot, and business activities (collectively, the “Services”).
BIOD is a Florida limited liability company with a principal address at 2000 North Bayshore Drive, Suite 1202, Miami, Florida 33137, United States.
2. Information We Collect
A. Public website and business-contact information
When you visit biod.ai, request information, start registration, participate in a demo, or communicate with us, we may collect:
- name, work email, business phone number, job title, professional role, specialty, organization, and similar professional contact information;
- information you provide in communications, forms, feedback, or support requests;
- technical information such as IP address, browser type, device type, operating system, referring URL, approximate location derived from IP, and timestamps; and
- website interaction information, such as pages viewed, buttons clicked, campaign source, and other non-clinical usage events.
B. Account and professional-user information
If you create a BIOD professional account, we may collect account credentials, role and specialty information, organization or clinic affiliation, authentication and security events, account settings, and service-usage metadata.
C. Customer and clinical data
When authorized healthcare customers and their users use the authenticated clinical platform, BIOD may process patient identifiers, demographics, laboratory reports, biomarkers, clinical history, symptoms, medications, diagnoses, encounter information, notes, transcripts, orders, referrals, follow-up information, and derived clinical intelligence. When this information is PHI, it is handled under the applicable BAA and customer agreement.
3. Sources of Information
We may receive information:
- directly from you;
- from the clinic, practice, or organization that authorizes your use of BIOD;
- from patient information, records, files, and other data uploaded or entered by authorized users;
- from authorized integrations or third-party services selected by a customer; and
- automatically from devices, browsers, authentication systems, security tools, and permitted analytics technologies.
4. How We Use Information
We use personal information as reasonably necessary to:
- provide, operate, maintain, secure, troubleshoot, and improve the Services;
- create and administer accounts, authenticate users, and enforce role-based access;
- support clinical workflows authorized by our healthcare customers;
- extract, normalize, structure, and display laboratory and clinical information for professional review;
- generate and present clinical hypotheses, patterns, summaries, documentation, and workflow suggestions for clinician review;
- provide onboarding, customer support, training, and service communications;
- prevent fraud, misuse, unauthorized access, and security incidents;
- understand public-site performance and marketing attribution using non-clinical information;
- comply with law, contractual obligations, legal process, and regulatory requirements; and
- protect the rights, safety, integrity, and availability of BIOD, our customers, users, and others.
5. Clinical Data, PHI, and HIPAA
BIOD is not a healthcare provider and this Privacy Policy is not a HIPAA Notice of Privacy Practices. A patient’s healthcare provider or healthcare organization remains responsible for its own HIPAA obligations and patient notices.
When BIOD creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity, BIOD acts as a Business Associate to the extent described in the applicable BAA. In that role, BIOD uses and discloses PHI only as permitted by the BAA, the applicable service agreement, customer instructions, and law.
Requests by patients to access, amend, restrict, or obtain an accounting concerning PHI should generally be directed first to the healthcare provider or organization that controls the record. BIOD supports its customers in fulfilling applicable HIPAA rights as required by the BAA and law.
Our public website and ordinary business-contact systems are intended to remain outside the clinical PHI environment. Please do not include patient names, medical records, laboratory values, diagnoses, or other PHI in public website forms, marketing communications, or ordinary email unless BIOD has expressly provided an authorized secure channel.
6. AI, Model Training, and Secondary Use
BIOD uses artificial intelligence and other computational methods to provide the Services. Clinical outputs are designed for review by licensed or authorized healthcare professionals and are not autonomous medical decisions.
PHI received under a BAA is not sold, used for targeted advertising, data brokerage, unrelated profiling, or used to train or improve a general-purpose or cross-customer model by default. Any model evaluation, tuning, training, research, or product-development use involving PHI must be properly de-identified in accordance with applicable requirements or be separately authorized in writing with an appropriate legal and contractual basis.
9. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain security and audit records, satisfy customer instructions and contractual commitments, resolve disputes, enforce agreements, and comply with legal obligations.
Retention and return or destruction of PHI are governed by the applicable BAA, service agreement, customer instructions, and law. Backup copies may persist for limited periods consistent with our backup, security, and disaster-recovery processes.
10. Security
BIOD uses administrative, physical, and technical safeguards designed to protect information against unauthorized access, use, disclosure, alteration, loss, or destruction. These measures include access controls, authentication, encryption, logging, monitoring, secure development and operational practices, and incident-response procedures appropriate to the Services.
No system can be guaranteed to be completely secure. Users are responsible for protecting their credentials, devices, and authorized access and must promptly notify BIOD of suspected unauthorized use.
11. Privacy Rights and Choices
Depending on where you live and which laws apply to BIOD’s processing, you may have rights to request access to, correction of, deletion of, or a copy of certain personal information; to object to or restrict certain processing; to opt out of certain sale, sharing, or targeted-advertising activities; or to appeal a privacy-request decision.
To exercise an applicable right concerning non-PHI personal information, contact us at contact@biod.ai. We may need to verify your identity and authority before fulfilling a request.
For PHI processed on behalf of a healthcare customer, please contact the healthcare provider or organization that controls the record. BIOD will assist that customer as required by our BAA and applicable law.
You may unsubscribe from non-transactional marketing emails by using the unsubscribe mechanism in the message or by contacting us.
12. Children
BIOD’s professional platform is intended for healthcare professionals and authorized workforce members who are at least 18 years old. The public website is not directed to children under 13, and BIOD does not knowingly collect personal information from children through the public marketing website.
Patient information concerning minors may be processed within the authenticated clinical platform only when submitted or authorized by an appropriate healthcare customer and handled in accordance with applicable law and contract.
13. U.S. Processing and International Visitors
BIOD is currently focused on the United States. If you access the Services from another jurisdiction, your information may be processed in the United States or other locations used by authorized service providers, subject to applicable legal and contractual safeguards.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our Services, data practices, legal requirements, or security and compliance program. We will post the updated version with a revised effective date and provide additional notice when required by law.
15. Contact Us
Privacy questions and requests may be sent to:
The Biogenesys Health Tech LLC
2000 North Bayshore Drive, Suite 1202, Miami, Florida 33137, United States
Email: contact@biod.ai
If you are contacting us about patient PHI, please do not include PHI in ordinary email. Use your healthcare organization’s authorized channel or contact your BIOD customer-success representative for secure instructions.