Legal

Privacy Policy

Effective 3 August 2026

1. Information we collect

Information provided directly — name, email, organization, role — when requesting a demo or making contact, plus standard usage data (IP address, browser type, pages visited) via analytics tools.

2. Protected health information (PHI)

Medical imaging data is processed within ISO 27001-certified infrastructure and is never stored — no database is deployed, and studies are automatically deleted 2 hours after receipt. DICOM identifiers are used only to route results back to the correct study and are deleted with it. PHI is not sold, shared, or used for marketing. BAAs are available for all US healthcare customers.

3. Data retention

Contact-form data is retained for business relationship management. Medical imaging data is not retained — automatic purge 2 hours after receipt, a server configuration parameter that can be shortened per deployment.

4. Third-party services

Cloud infrastructure providers, subject to PurpleAI security requirements, handle hosting and processing. Distribution partners — SaveLife.AI, CARPL.ai, VSee — process data under their own privacy policies when PurpleAI solutions are accessed through their platforms.

5. Your rights

Access, correction, or deletion requests go to purpleai@purple-ai.co; responses within 30 days.