1. Our Role: Website Visitor vs. Platform Data
For information collected through the public relaypulse.io website (for example, when you request a demo or contact us), Relay acts as the controller of that information and this Policy describes our own practices directly.
For information submitted to or generated within the Relay platform by our Customers and their authorized users — including member records, assessments, care plans, referrals, and related operational data ("Customer Data") — Relay acts as a service provider / business associate processing that data on the Customer's behalf and under the Customer's instructions, as further described in the applicable subscription agreement and, where PHI is involved, a Business Associate Agreement ("BAA"). If you are a member whose information appears in Relay, please contact the organization that provides your care or services for questions about your data; Relay does not independently control how that organization uses its data.
2. Information We Collect
Website and account information: name, work email, organization, job title, and message content when you request a demo, contact us, or create an account.
Usage and device information: log data, IP address, browser and device type, and interaction data collected automatically through cookies and similar technologies to operate and secure the website and Service.
Customer Data processed within the platform: as configured and controlled by each Customer, this may include member demographic, contact, eligibility, assessment, care plan, referral, service, encounter, provider, and financial/authorization data, some of which may constitute PHI or other sensitive personal information under applicable law.
We do not knowingly collect information directly from members of the public through the platform; Customer Data is submitted by authorized workforce members of our Customers and their partner organizations.
3. How We Use Information
We use website and account information to operate the website, respond to inquiries, provide and support the Service, communicate with Customers, and improve our product and marketing.
We process Customer Data solely to provide, secure, support, and improve the Service for the applicable Customer, in accordance with that Customer's instructions and any governing agreement — never to sell it, and never for unrelated advertising purposes.
Where permitted by law and any applicable agreement, we may use de-identified or aggregated data derived from Customer Data for analytics, benchmarking, and improving Relay's AI models and workflows, in a manner that does not identify any individual or Customer.
4. AI Processing
Relay uses artificial intelligence to support documentation, summarization, prioritization, recommendations, and other decision-support features. AI processing is designed to minimize the information sent to any model to what a given task requires, and to keep humans accountable for consequential decisions.
Where Relay uses third-party AI model providers, those providers are engaged under contractual terms restricting their use of data to providing the requested processing, consistent with applicable law and any BAA in place.
5. Legal Basis and Consent
Customer Data is processed under the legal basis and consents obtained by the applicable Customer (for example, treatment, care coordination, or program administration purposes, and any consents required by state or federal law). Customers are responsible for ensuring they have appropriate legal basis and member consent before submitting data to the Service.
Website visitor information is processed based on your consent when you submit it (for example, requesting a demo) or Relay's legitimate interest in responding to inquiries and operating the Service.
6. How We Share Information
We do not sell personal information or Customer Data.
We may share information with: subprocessors and infrastructure providers who help us deliver the Service (e.g., cloud hosting, email delivery), under contractual confidentiality and security obligations; professional advisors; regulators or law enforcement where required by law; and successors in a merger, acquisition, or asset sale, subject to continued protection of the information consistent with this Policy.
Within the platform, Customer Data is shared only as configured by the Customer's own workflows — for example, closed-loop referrals to a receiving provider organization the Customer has authorized.
7. Data Security
Relay maintains administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Customer Data, including encryption in transit and at rest, role-based access control, tenant isolation, audit logging, and least-privilege administrative access.
No system can be guaranteed completely secure; we continuously evaluate and improve our security program and will notify affected Customers of a security incident involving their data as required by applicable law and any governing agreement.
8. Data Retention
We retain website and account information for as long as needed to operate the Service and fulfill the purposes described in this Policy, and as required by law.
Customer Data is retained for the duration of the applicable subscription and for a period afterward to allow export, consistent with the governing agreement, applicable record-retention requirements (including healthcare recordkeeping laws), and Relay's data deletion practices thereafter.
9. Your Choices and Rights
You may request access to, correction of, or deletion of personal information Relay holds about you as a website visitor or account holder by contacting privacy@relaypulse.io. We will respond consistent with applicable law.
If your information appears in Relay as part of a Customer's use of the platform (for example, as a member receiving care coordinated through the Service), requests regarding that data should generally be directed to the Customer organization that submitted it, as they control that data; Relay will support the Customer in responding as required by our agreement with them and applicable law.
Depending on your location, you may have additional rights under applicable law (for example, state privacy laws), including the right to opt out of certain processing. Contact us to exercise these rights.
10. Cookies
The Relay website uses cookies and similar technologies necessary for the site to function, to remember preferences (such as language), and to understand aggregate site usage. We do not use cookies for third-party behavioral advertising.
11. Children's Information
The Relay website is not directed to children, and we do not knowingly collect personal information from children through the website. Where Customer Data submitted to the platform relates to a minor (for example, a member of a family receiving coordinated care), that data is submitted and controlled by the Customer organization in accordance with applicable law.
12. International Data Transfers
Relay primarily processes and stores data within the United States. If information is transferred internationally, we take steps designed to ensure it receives an appropriate level of protection consistent with applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices or legal requirements. We will post the updated Policy with a new "last updated" date and, for material changes, provide additional notice as appropriate.
14. Contact Us
Questions about this Privacy Policy or Relay's data practices can be sent to privacy@relaypulse.io.