Privacy Policy
Last updated: May 5, 2026
1. Scope and role of this policy
This Privacy Policy explains how KIVA collects, uses, stores, and shares personal information when you interact with our websites, applications, integrations, and related services. Depending on the deployment, KIVA may act as a service provider, processor, or business associate on behalf of a healthcare organization, and in some limited contexts may act as a controller for its own operational data.
When a healthcare organization uses KIVA for patient care or clinical operations, that organization generally determines the purposes for which patient and workforce data are used within its environment. In those cases, the organization's own notice of privacy practices, policies, and agreements may also apply.
2. Information we collect
We collect information you provide directly, information generated through use of the service, and information received from connected systems and service providers. The categories of information depend on the products and features your organization enables.
- Account and profile data, such as name, email address, role, organization, login metadata, and administrative settings.
- Clinical and workflow data, such as recordings, transcripts, notes, summaries, forms, scheduling details, uploaded files, patient identifiers, and other information entered into the service.
- Device, usage, and log data, such as IP address, browser type, session history, timestamps, error logs, security events, and product interaction data.
- Support and communication data, such as requests, messages, feedback, and implementation or onboarding information.
3. Sources of information
We may receive information from your organization, authorized users, patients or participants whose information is entered by users, identity providers, scheduling tools, telehealth systems, electronic health record integrations, analytics or security vendors, and other third parties you choose to connect to the service.
4. How we use information
We use personal information to deliver and maintain the service, authenticate users, process recordings and transcripts, generate draft documentation, support integrations, respond to support requests, secure the platform, investigate misuse, comply with law, and improve reliability and usability.
Where permitted by contract and law, we may also use limited operational data for service analytics, product planning, quality assurance, and security monitoring. We do not sell personal information or customer health data.
- We do not use customer health data to train general-purpose models unless that use is specifically disclosed and contractually authorized.
- We may use de-identified or aggregated information, where legally permitted, to understand service performance, adoption trends, and platform quality.
5. Legal bases and healthcare authorizations
Where applicable privacy law requires a legal basis, we rely on bases such as contract performance, legitimate interests, consent, compliance with legal obligations, protection of vital interests, or other lawful grounds recognized in the relevant jurisdiction.
Healthcare organizations using KIVA are responsible for determining whether they need patient consent, patient authorization, employee notices, call-recording disclosures, or other local legal permissions before enabling particular workflows.
6. How we share information
We may share information with subprocessors and service providers that support hosting, storage, authentication, customer support, security, communications, analytics, or implementation. We require such providers to handle data under appropriate confidentiality and security obligations.
We may also disclose information when necessary to comply with law, respond to lawful requests, enforce our agreements, protect rights or safety, investigate suspected abuse, or support a merger, financing, acquisition, reorganization, or asset transfer.
7. Retention and deletion
We retain personal information for as long as reasonably necessary to provide the service, satisfy contractual obligations, maintain security, resolve disputes, comply with law, and enforce our agreements. Retention periods may vary based on the product configuration, customer instructions, and the type of information involved.
Where available, administrators may configure retention settings or request deletion workflows. Backups and archived records may persist for a limited period as part of business continuity, legal hold, fraud prevention, or security processes.
8. Security safeguards
We maintain administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, alteration, disclosure, and destruction. These measures may include access controls, encryption in transit and at rest where appropriate, logging, monitoring, workforce access restrictions, and vendor due diligence.
No system can be guaranteed to be completely secure. You and your organization are responsible for maintaining credential security, endpoint protection, role-based access settings, and safe handling of exported or downloaded data.
9. International transfers
KIVA and its service providers may process personal information in jurisdictions other than the one in which the information was collected. Where required by law, we use appropriate safeguards for cross-border transfers, which may include contractual commitments, transfer impact reviews, and supplementary technical or organizational controls.
10. Privacy rights and choices
Depending on your location and relationship to the service, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. You may also have rights relating to automated processing or to withdraw consent where consent is the legal basis.
In many enterprise healthcare deployments, requests regarding patient or workforce data must first be directed to the healthcare organization that controls the account, because that organization determines the purposes and means of the relevant processing.
11. Children's information
KIVA is not intended for children to create independent accounts. If information relating to minors is processed through the service, that processing should occur only under the authority of a healthcare organization or authorized adult acting in accordance with applicable law.
12. AI-assisted features
Some features use machine learning or AI-assisted processing to transcribe conversations, summarize encounters, draft notes, extract structured data, or suggest tasks. These features are designed to support human workflows and may produce incomplete or inaccurate results.
Organizations and clinicians remain responsible for validating outputs before using them in patient care, billing, or compliance contexts. AI-assisted features should be enabled only where appropriate for the intended workflow, patient population, and legal environment.
13. Changes to this policy and contact
We may update this Privacy Policy from time to time to reflect changes in the service, our security practices, applicable law, or regulatory expectations. When changes are material, we will use reasonable efforts to provide notice before they take effect.
Questions or requests relating to this policy should be directed through the support or privacy contact made available within the service. If you use KIVA through a clinic, hospital, or employer, that organization may need to handle your request first where it is the controller or covered entity for the relevant information.