Cohera Health

Legal

Privacy Policy

Effective date: October 16, 2025

AIspire360, Inc. ("AIspire360," "we," "us," or "our") provides AI-driven healthcare and operational solutions including clinical documentation, patient and clinician applications, APIs, voice agents, and related services (collectively, the "Services"). This Privacy Policy explains how we handle information when you use our Services.

1. Who we are and our role

AIspire360 is a corporation in the State of Delaware, United States. We provide the Services to healthcare organizations and professionals. When a healthcare organization (or an individual customer) uses our Services, it controls the patient information that is entered into or generated by the Services. In that context, AIspire360 acts as a service provider under applicable state privacy laws and as a Business Associate under HIPAA, or as a sub-Business Associate if our customer is a Business Associate. For our own business operations, such as billing our clients, account management, and software analytics, AIspire360 may act as an independent controller of limited account and usage information that relates to our direct relationship with you.

2. Information we process

Your access to this app is based on a license between us and our client. Accordingly, any identifiable personal data you or our client provides to us will be used for the purpose our client requested, as well as for managing our client relationships, providing you with important information, or facilitating our business operations and analytics. We will not ask for more personal data than is necessary for these purposes. We may also maintain logs of your access and use of our services, and these logs may be attributable to you.

A. Account and administrative information

  • Account profile — Name, role, organization, contact details, and authentication data for authorized users.
  • Billing — Subscription tier, invoicing contacts, and payment-related data handled by our payment processor.
  • Support communications — Messages, requests, or feedback you choose to send us.

B. Technical and usage information

  • Device and log data — IP address, device type, browser type, app version, and event logs that help us secure and maintain the Services.
  • Cookie and analytics data — Limited website analytics on our public site. We do not embed tracking cookies inside authenticated clinical workflows.

C. Information provided by you

  • Content entered by users — Notes, transcripts, and other records created by users including identifiable patient data.
  • Audio input for transcription — Audio captured during clinical encounters or related sessions, used to generate transcripts for you. See Section 4 regarding recordings and retention.
  • Identifiers and scheduling context — Contact information, appointment timestamps, and similar context that your organization chooses to include.

3. How we use information

We use information for the following and similar purposes:

  • Provide and maintain the Services — Create user accounts, transcribe audio to text, store transcripts for your organization, and deliver product features that your organization requests.
  • Security and integrity — Monitor for abuse, troubleshoot issues, and protect the Services and our users.
  • Compliance — Meet legal, regulatory, and audit obligations, including HIPAA where applicable, and honour user and patient rights requests that are directed to us by our customer.
  • Anonymized analytics and improvement — Generate anonymized data, statistics and performance metrics that do not identify any individual or patient.

We do not use information for model training in a way that would identify any individual.

4. Recording and transcription of clinical notes

  • Consent responsibility — Customers and their users are responsible for obtaining all required consents before recording any individual. You must follow your organization's policies and applicable laws when using the recording feature.
  • No retention of audio recordings — Audio recordings are used only to generate a transcript. We do not retain audio after transcription completes, except for short-lived buffering that is technically necessary for processing and error recovery.
  • Clinical notes are securely stored — Clinical notes may be delivered into your organization's storage system through an integration with this application. AIspire360 does not store identifiable clinical notes or transcripts after acceptance by the customer, other than short-lived encrypted caches that are automatically purged.
  • Access and controls — Access to clinical notes is managed in your organization's storage system. Within the AIspire360 software, only authorized users may initiate recordings and route clinical information to their record system.

5. De-identification and anonymization

When we generate anonymized data, analytics or quality metrics, we use de-identification techniques designed to remove direct identifiers and to minimize the risk of re-identification.

  • We do not attempt to re-identify de-identified or anonymized data.
  • We do not combine de-identified data with other data in a way that would identify a person.
  • We may use de-identified or aggregated information to improve accuracy, reliability, and performance of the Services.

Customer-controlled patient information remains under the customer's control and is not used for model training without explicit, written opt-in.

6. Data retention of identifiable information

  • Patient information — Clinical notes and related patient content are securely stored. AIspire360 does not store identifiable clinical notes after acceptance by the customer, other than short-lived encrypted processing caches and minimal system logs.
  • Audio recordings — Not retained after transcription completes, except for short-lived technical buffering as described in Section 4.
  • Account and administrative data — Retained for the duration of the customer relationship and as needed for legal, audit, and tax purposes. When no longer needed, we delete or anonymize this data.

7. Sharing and disclosure

We disclose information in the following situations:

  • Service providers and subprocessors — We use trusted vendors to host infrastructure, process payments, perform support, and provide technology components. These vendors access information only to perform services for us and are bound by confidentiality and security obligations.
  • Customer-designated destinations — For example your electronic health record system. We transmit information to those systems only on your instructions.
  • Legal compliance and protection — We may disclose information if required by law or valid legal process, or to protect the rights, safety, or property of our clients, users, their patients, or the public.
  • Business transfers — If we engage in a merger, acquisition, or asset sale, we will continue to protect information as described in this policy.

We do not sell identifiable personal information, and we do not share identifiable personal information for cross-context behavioural advertising.

8. Security

We implement administrative, technical, and physical safeguards designed to protect information within our custody. These include encryption in transit and at rest, access controls, audit logging, and vulnerability management. No method of transmission or storage is perfectly secure. Customers should configure user permissions and retention settings that reflect their own policies and regulatory obligations.

9. International data transfers

This application is designed and intended for use exclusively within the United States. All data processing and storage occur in the United States. If you access or attempt to use the Services from outside the United States, you understand that your information will still be transferred to and processed in the United States, and such use may not be permitted under local laws.

10. Your choices and rights

If you are an account user, you can update profile information within the product or by contacting us at enterprise@aispire360.com. Depending on your state, you may have additional privacy rights.

11. Changes to this policy

We may change or update this Privacy Policy from time to time. Your continued use of the Services after such modifications constitutes your acceptance of the updated Privacy Policy. You may request a copy of this policy by contacting us.

Support

Contact us at enterprise@aispire360.com or write to AIspire360, Inc., Delaware, United States.

← Back to home