Privacy & Data Protection

Privacy Policy

How SparkCo collects, uses, and protects information for Skilled Nursing Facilities, Nursing Homes, and Long-Term Care communities using our AI-powered healthcare automation services.

Last updated: 2025-12-15

Information We Collect

Provider Information

Organization name, facility location(s), contact names, roles, email addresses, billing and administrative details.

Usage Data

Log data, IP addresses, device/browser type, pages and features used, timestamps, referral URLs, configuration settings.

Content Provided

Prompts, forms, configuration policies, uploaded files, and communications you submit for processing.

Integrated Data

Read-only EHR data via FHIR (PointClickCare, telephony, analytics, eFax) - minimum necessary for decision support.

How We Use Information

Service OperationsProvide, operate, secure, and improve Services
Decision SupportGenerate SBAR summaries, risk flags, communication drafts
PersonalizationFacility policies, escalation rules, nurse prompts
CommunicationsUpdates, security, support, training, onboarding
ComplianceLegal obligations, Terms enforcement
Quality AssuranceAnalytics to improve accuracy and reliability

HIPAA & Protected Health Information

Business Associate Agreement Required

If you require a Business Associate Agreement (BAA) or will process Protected Health Information (PHI), this must be explicitly agreed in writing.

Unless a BAA is executed, you agree not to submit PHI to the Services.When a BAA is in place, we process PHI according to the BAA and this Policy.

Data Sharing & Disclosure

Service Providers

InfrastructureConfidentiality obligations
AnalyticsData protection agreements
SecurityLimited access controls

Legal & Safety

Legal complianceLawful requests
Rights protectionSafety, property
Business transfersM&A, asset transfer

Your Rights & Choices

Access RightsRequest access to your information
Correction RightsUpdate or correct inaccurate data
Deletion RightsRequest deletion subject to legal limits
Data PortabilityExport your data in standard formats
Processing ObjectionObject to certain processing activities

Security Measures

Encryption at restAES-256
Encryption in transitTLS 1.3
Access controlsRBAC + MFA
Data retentionMinimum necessary

Additional Information

Children's Privacy

Services not directed to children under 13. We do not knowingly collect such data.

International Transfers

Data may be processed globally with appropriate safeguards (Standard Contractual Clauses).

Policy Changes

Material changes communicated via Services or email. Continued use constitutes acceptance.

Contact Us

For privacy questions, rights requests, BAAs, or security inquiries:

patrick@sparkco.ai

Terms of Service
Security docs
Privacy Policy - HIPAA-Compliant Healthcare AI | Sparkco AI