Privacy Policy & Security
Last Updated: January 11, 2025
Table of Contents
-
Introduction
-
Data Protection Officer
-
How we collect and use (process) your personal information
-
Use of BridgeHealthAI Inc..com website
-
Cookies and tracking technologies
-
Use of BridgeHealthAI Inc. services
-
When and how we share information with third parties
-
Transferring personal data to the U.S.
-
Data Subject rights
-
Security of your information
-
Data storage and retention
-
Questions, concerns, or complaints
Introduction
BridgeHealthAI Inc. is a U.S.-based company focused on empowering care workers and patients to navigate, access, and engage with health and social benefits through technology-enabled tools and services.
We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Privacy Notice describes BridgeHealthAI Inc.’s policies and practices regarding its collection and use of your personal data, and sets forth your privacy rights. We recognize that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Notice as we undertake new personal data practices or adopt new privacy policies.
Data Protection Officer
BridgeHealthAI Inc. is headquartered in Delaware, in the United States. BridgeHealthAI Inc. has appointed an internal data protection officer for you to contact if you have any questions or concerns about BridgeHealthAI Inc.’s personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to BridgeHealthAI Inc.’s data protection officer. BridgeHealthAI Inc.’s data protection officer’s name and contact information are as follows: Jinal Shah, hello@bridgehealthequity.com​
How we collect and use (process) your personal information
BridgeHealthAI Inc. collects personal information about its website visitors and customers. With a few exceptions, this information is generally limited to:
-
name
-
email
-
phone number
We use this information to provide prospects and customers with services.
We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services.
From time to time, BridgeHealthAI Inc. receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry. We may also collect your personal data from a third party website (e.g. LinkedIn)
Use of BridgeHealthAI Inc. Website
As is true of most other websites, BridgeHealthAI Inc.’s website collects certain information automatically and stores it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system and other usage information about the use of BridgeHealthAI Inc.’s website, including a history of the pages you view. We use this information to help us design our site to better suit our users’ needs. We may also use your IP address to help diagnose problems with our server and to administer our website, analyze trends, track visitor movements, and gather broad demographic information that assists us in identifying visitor preferences.
BridgeHealthAI Inc. has a legitimate interest in understanding how members, customers and potential customers use its website. This assists BridgeHealthAI Inc. with providing more relevant products and services, with communicating value to our sponsors and corporate members, and with providing appropriate staffing to meet member and customer needs.
Cookies and tracking technologies
​
This policy applies to all employees, contractors, and vendors while doing business with BridgeHealthAI Inc. and others who have access to European Union (EU) and the European Economic Area (EEA) data subject information (“personal data”) in connection with BridgeHealthAI Inc.’s operating activities.
Policy
BridgeHealthAI Inc. believes in transparency about the collection and use of data. This policy provides information about how and when BridgeHealthAI Inc. uses cookies for these purposes. Capitalized terms used in this policy but not defined have the meaning outlined in our Privacy Policy, which also includes additional details about the collection and use of information at BridgeHealthAI Inc.
What is a Cookie?
Cookies are small text files sent by us to your computer or mobile device, which enable BridgeHealthAI Inc. features and functionality. They are unique to your account or your browser. Session-based cookies last only while your browser is open and are automatically deleted when you close your browser. Persistent cookies last until you or your browser delete them or until they expire.
Does BridgeHealthAI Inc. use Cookies?
Yes. BridgeHealthAI Inc. uses cookies and similar technologies like single-pixel gifs and web beacons. BridgeHealthAI Inc. uses both session-based and persistent cookies. BridgeHealthAI Inc. sets and accesses cookies on the domains operated by BridgeHealthAI Inc. and its corporate affiliates (collectively, the “Sites”). In addition, BridgeHealthAI Inc. uses third-party cookies, like Google Analytics.
​
How is BridgeHealthAI Inc. using Cookies?
Some cookies are associated with your account and personal information to remember that you are logged in and which workspaces you are logged into. Other cookies are not tied to your account but are unique and allow us to carry out analytics and customization, among other similar things.
Cookies can be used to recognize you when you visit a Site or use our Services, remember your preferences, and give you a personalized experience that is consistent with your settings. Cookies also make your interactions faster and more secure.
Categories of Use
-
Authentication: If you're signed into the Services, cookies help BridgeHealthAI Inc. show you the right information and personalize your experience.
-
Security: BridgeHealthAI Inc. uses cookies to enable and support security features and to help detect malicious activity.
-
Preferences, Features, and Services: Cookies denote which language you prefer and what your communications preferences are. They can help fill out forms on our Sites more easily. They also provide you with features, insights, and customized content.
-
Marketing: BridgeHealthAI Inc. may use cookies to help deliver marketing campaigns and track their performance. Similarly, BridgeHealthAI Inc.’s partners may use cookies to provide us with information about your interactions with their services.
-
Performance, Analytics, and Research: Cookies help BridgeHealthAI Inc. learn how well the Sites and Services perform. BridgeHealthAI Inc. also uses cookies to understand, improve, and research products, features, and services.
What third-party cookies does BridgeHealthAI Inc. use?
You can find a list of the third-party cookies that BridgeHealthAI Inc. uses on our sites along with other relevant information BridgeHealthAI Inc. does its best to keep this table updated, but please note that the number and names of cookies, pixels, and other technologies may change from time to time.
What can you do if you don’t want cookies to be set or want them to be removed?
You can disable and delete cookies that may not be necessary for the basic functionality of our website. You may access the Cookie Manager at any time in the footer of our website, or click on the link below:
​
-
bridgehealthequity.com: Cookies - XSRF-TOKEN, bSession, hs, ssr-caching, svSession. First-party cookies
-
app.bridgehealthequity.com: Cookies - _ga, _ga_MNHDNRW. First-party cookies​​
​​
​​Performance Cookies
BridgeHealthAI Inc. uses Google Analytics to monitor and improve site performance. To opt out of Google Analytics, visit: Google Analytics Opt-Out.
Once you visit or click on links to third-party websites, their sites may use cookies. We do not control what information those websites collect or their use of cookies, and they are not subject to our Privacy Policy, including the use of cookies.
​
Sharing information with third parties
The personal information BridgeHealthAI Inc. collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, BridgeHealthAI Inc. engages third parties to send information to you, including information about our products, services, and events.
A list of our primary subprocessors is available upon request. Please contact us at hello@bridgehealthequity.com to receive this information.
We do not otherwise reveal your personal data to non-BridgeHealthAI Inc. persons or businesses for their independent use unless: (1) you request or authorize it; (2) it’s in connection with BridgeHealthAI Inc.-hosted and BridgeHealthAI Inc. co-sponsored conferences as described above; (3) the information is provided to comply with the law (for example, compelled by law enforcement to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (4) the information is provided to our agents, vendors or service providers who perform functions on our behalf; (5) to address emergencies or acts of God; or (6) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our services and website visitors and disclose the results of such aggregated (but not personally identifiable) information to our partners, service providers, advertisers, and/or other third parties for marketing or promotional purposes.
BridgeHealthAI Inc. website connects with third-party services such as LinkedIn and others. If you choose to share information from the BridgeHealthAI Inc. website through these services, you should review the privacy policy of that service. If you are a member of a third-party service, the aforementioned connections may allow that service to connect your visit to our site to your personal data.
Transferring personal data to the U.S.
BridgeHealthAI Inc. has its headquarters in the United States. Information we collect about you will be processed in the United States. By using BridgeHealthAI Inc.’s services, you acknowledge that your personal information will be processed in the United States.
Depending on the circumstance, BridgeHealthAI Inc. also collects and transfers to the U.S. personal data with consent; to perform a contract with you; or to fulfill a compelling legitimate interest of BridgeHealthAI Inc. in a manner that does not outweigh your rights and freedoms. BridgeHealthAI Inc. endeavors to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with BridgeHealthAI Inc. and the practices described in this Privacy Statement. BridgeHealthAI Inc. also enters into data processing agreements and model clauses with its vendors whenever feasible and appropriate. Since it was founded, BridgeHealthAI Inc. has received zero government requests for information.
For more information or if you have any questions, please contact us at hello@bridgehealthequity.com
Data Subject rights
This Privacy Notice is intended to provide you with information about what personal data BridgeHealthAI Inc. collects about you and how it is used.
If you wish to confirm that BridgeHealthAI Inc. is processing your personal data, or to have access to the personal data BridgeHealthAI Inc. may have about you, please contact us.
You may also request information about: the purpose of the processing; the categories of personal data concerned; who else outside BridgeHealthAI Inc. might have received the data from BridgeHealthAI Inc.; what the source of the information was (if you didn’t provide it directly to BridgeHealthAI Inc.); and how long it will be stored. You have a right to correct (rectify) the record of your personal data maintained by BridgeHealthAI Inc. if it is inaccurate. You may request that BridgeHealthAI Inc. erase that data or cease processing it, subject to certain exceptions. You may also request that BridgeHealthAI Inc. cease using your data for direct marketing purposes. In many countries, you have a right to lodge a complaint with the appropriate data protection authority if you have concerns about how BridgeHealthAI Inc. processes your personal data. When technically feasible, BridgeHealthAI Inc. will—at your request—provide your personal data to you.
Reasonable access to your personal data will be provided at no cost. If access cannot be provided within a reasonable time frame, BridgeHealthAI Inc. will provide you with a date when the information will be provided. If for some reason access is denied, BridgeHealthAI Inc. will provide an explanation as to why access has been denied.
For questions or complaints concerning the processing of your personal data, you can email us at hello@bridgehealthequity.com.
Data storage and retention
Your personal data is stored by BridgeHealthAI Inc. on its servers, and on the servers of the cloud-based database management services BridgeHealthAI Inc. engages, located in the United States. BridgeHealthAI Inc. retains service data for the duration of the customer’s business relationship with BridgeHealthAI Inc. and for a period of time thereafter, to analyze the data for BridgeHealthAI Inc.’s own operations, and for historical and archiving purposes associated with BridgeHealthAI Inc.’s services. BridgeHealthAI Inc. retains prospect data until such time as it no longer has business value and is purged from BridgeHealthAI Inc. systems. All personal data that BridgeHealthAI Inc. controls may be deleted upon verified request from Data Subjects or their authorized agents. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact us at: hello@bridgehealthequity.com
Children’s data
We do not knowingly attempt to solicit or receive information from children.
Questions, concerns or complaints
If you have questions, concerns, complaints, or would like to exercise your rights, please contact us at:
BridgeHealthAI Inc.
251 Little Falls Drive Wilmington, DE 19808
https://www.bridgehealthequity.com/company
1-847-894-9035
Security at BridgeHealth AI
Last Updated: January 11, 2025
​
Our Commitment to Security
At BridgeHealth AI, we understand the critical importance of protecting sensitive healthcare information and personally identifiable information (PII). We implement comprehensive security measures across our infrastructure, people, and processes to ensure the confidentiality, integrity, and availability of your data.
Infrastructure Security
Cloud Security
-
We operate on enterprise-grade cloud infrastructure, utilizing AWS, Azure and GCP to provide robust and reliable services.
-
Our hybrid cloud architecture implements security best practices from both platforms.
-
Regular security assessments and automated monitoring ensure our infrastructure maintains the highest security standards.
Data Protection
-
All data is encrypted in transit using TLS 1.2 or higher.
-
Data at rest is encrypted using industry-standard encryption protocols.
-
Secure backup systems with regular testing ensure data availability.
-
Strict data retention policies govern the lifecycle of all sensitive information.
Access Control & Authentication
System Access
-
Role-based access control (RBAC) ensures employees only access information necessary for their job functions.
-
Regular access reviews maintain the principle of least privilege.
-
All system access requires unique user credentials.
-
Password policies enforce strong password requirements:
-
Minimum length requirements
-
Complexity rules
-
Regular password rotation
-
Account lockout after failed attempts
-
Future Security Enhancements
We are actively working to implement:
-
Multi-factor authentication (MFA) for all user accounts
-
Single Sign-On (SSO) capabilities
-
Enhanced audit logging and monitoring
Compliance & Certifications
Current Status
We are actively working towards:
-
SOC 2 Type I compliance
-
SOC 2 Type II compliance
-
HIPAA compliance
Our security programs are built on industry frameworks including NIST and ISO 27001 guidelines.
Security Practices
Employee Security
-
Comprehensive security awareness training for all employees
-
Background checks for all new hires
-
Regular security updates and reminders
-
Clear security policies and procedures
Incident Response
-
Documented incident response procedures
-
24/7 security monitoring
-
Defined notification procedures for security events
-
Regular testing of incident response plans
Data Processing
Data Handling
-
Strict data classification policies
-
Documented data retention and deletion procedures
-
Regular data handling training for all employees
-
Secure data disposal practices
Vendor Management
-
Thorough security assessment of third-party vendors
-
Regular vendor security reviews
-
Contractual security requirements for all partners
Contact
For security-related inquiries or to report security concerns, please contact: