Last updated: June 17, 2025
Decisive Connect ("Decisive Connect," "we," "our," or "us") provides workflow-automation and data-integration tools to healthcare organizations. Protecting the privacy and security of Protected Health Information ("PHI") and other personal data is core to our mission. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you:
visit Decisive Connect, its sub-domains, or any linked portals or mobile apps (collectively, the "Site");
use our cloud services, APIs, or integrations (the "Platform"); or
interact with us in any other way that references this Policy.
By accessing or using the Site or Platform, you acknowledge that you have read and understood this Privacy Policy.
When we handle PHI on behalf of a covered entity or business associate (e.g., your hospital or clinic), we do so solely as that party's "Business Associate" under the U.S. Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations, as amended by the HITECH Act. Our Business-Associate Agreement ("BAA") governs any PHI processing and will prevail over conflicting terms in this Policy. For non-PHI personal data (e.g., account credentials for hospital staff), this Privacy Policy applies.
PHI: Individually identifiable health information that is created, received, or transmitted by a Covered Entity or Business Associate, as defined by HIPAA.
Personal Information / Personal Data: Information that identifies, relates to, describes, or can reasonably be linked to an individual, whether or not it is PHI.
De-identified / Aggregated Data: Data that cannot reasonably be used to identify an individual, consistent with 45 C.F.R. § 164.514(b).
The categories of information we collect depend on how you interact with Decisive Connect and include:
Patient PHI (when the Platform is connected to an EHR): medical record number, treatment history, lab results, appointment schedules (source: your healthcare provider).
Account & Profile Data: Name, business email, professional title, NPI, role-based access settings (source: you).
Usage & Device Data: IP address, browser type, operating system, activity logs, error logs (source: automated via cookies, server logs, SDKs).
Support & Communications: Help-desk tickets, chat transcripts, survey responses (source: you).
Payment Information: Billing contact, payment card token (source: you; processed by PCI-compliant processor).
Candidate Data: Resume, LinkedIn profile, interview notes (source: job applicants).
We use the information we collect for the following purposes:
Provide, secure, and maintain the Platform: HIPAA "treatment, payment, or operations"; performance of contract.
Authenticate and manage user accounts: performance of contract.
Comply with legal or regulatory obligations: legal obligation.
Improve and develop features, detect bugs, conduct analytics: legitimate interests; for PHI, only with written customer permission or after de-identification.
Respond to support requests or security incidents:performance of contract; legal obligation.
Send service-related notices: performance of contract.
Marketing to prospective enterprise customers(never patient PHI): consent or legitimate interests.
Processing payments and preventing fraud:performance of contract; legitimate interests.
We never sell PHI or personal data. We only share information:
With your healthcare organization under the BAA.
With subprocessors / service providers bound by contractual privacy and security obligations.
For legal compliance (e.g., subpoenas, court orders) after assessing and, where possible, narrowing the request.
For corporate transactions such as mergers or acquisitions, subject to confidentiality and continuity of protections.
With your consent or at your direction.
A current list of subprocessors is available at Decisive Connect/subprocessors.
We implement administrative, physical, and technical safeguards meeting or exceeding 45 C.F.R. Part 164 Subpart C, including:
AES-256 encryption at rest and TLS 1.3 in transit
Role-based access control (RBAC) with multi-factor authentication
Annual third-party penetration testing and SOC 2 Type II audits
Audit trails and immutable logs
24x7 security-operations monitoring
Where we maintain PHI on behalf of a covered entity, that entity is responsible for addressing patient rights of access, amendment, restriction, accounting of disclosures, and confidential communications. We support these requests as required under our BAA.
California Consumer Privacy Act (CCPA) / CPRA: If you are a California resident and we process your non-PHI personal information, you may request access, deletion, correction, or opt-out of "sharing" for cross-context behavioural advertising. We do not "sell" personal info as defined by CCPA.
Other states (VA CDPA, CO CPA, CT DPA): Similar rights apply; contact us as described below.
Missouri currently has no comprehensive privacy statute, but we respect your rights under any applicable law.
When we process personal data of individuals in the European Economic Area, UK, or Switzerland, Decisive Connect acts as a Data Processor, and the healthcare organization acts as the Data Controller. Transfers to the United States are made under:
The EU-U.S. Data Privacy Framework (upon our self-certification), or
Standard Contractual Clauses (SCCs) approved by the European Commission, with supplementary safeguards (encryption, access controls, etc.).
Data subjects may exercise GDPR rights through their healthcare provider or directly via privacy@decisiveconnect.com.
We use strictly necessary cookies for authentication and security. Where permitted, we also use functional and analytics cookies (e.g., Plausible or Matomo) to understand product performance. You may control cookies through browser settings; disabling them may affect Platform functionality.
PHI: Retained in accordance with the BAA or customer instructions, then securely deleted or de-identified using NIST SP 800-88 guidelines.
Other data: Retained as long as needed to fulfill the purposes outlined above, comply with legal obligations, resolve disputes, and enforce agreements.
We maintain an incident-response plan aligned with NIST SP 800-61. In the event of a breach involving unsecured PHI, we will notify affected customers without unreasonable delay and no later than 60 days, consistent with 45 C.F.R. § 164.404.
Access / Copy of data:Email privacy@decisiveconnect.com or submit via the in-product "Privacy Request" form.
Correction / Update: Same as above.
Deletion (where permitted): Same as above.
Opt-out of marketing emails: Click the "unsubscribe" link or update notification preferences.
Do-Not-Track signals: We currently do not respond to DNT, but honor CCPA "opt-out of sale / sharing" mechanisms.
We will verify your identity (and, where applicable, authority) before honoring requests.
The Platform may link to third-party sites or incorporate third-party APIs (e.g., FHIR endpoints, cloud storage). We are not responsible for the privacy practices of those entities. Review their policies before interacting.
We may update this Privacy Policy periodically. Material changes will be posted on this page and, if significant, we will notify account owners via email or in-app alerts at least 30 days before the change takes effect.
Decisive Connect Privacy Office
Decisive Connect LLC
5424 Taylor Ln
Fort Collins, CO 80528, USA
Email: privacy@decisiveconnect.com
If you believe we have not adequately addressed your privacy concern, you may file a complaint with the U.S. Department of Health & Human Services Office for Civil Rights or your local data-protection authority.
Healthcare organizations can request our standard Business-Associate Agreement by emailing compliance@decisiveconnect.com or through the admin settings of their Decisive Connect workspace.
Decisive Connect is committed to safeguarding patient trust while enabling innovative, compliant automation for healthcare. Let us know if you have any questions or require modifications to this policy for your specific deployment.