Platform Privacy Policy
1. Introduction/Scope.
This Platform Privacy Policy ("Policy") describes how Raport Inc. ("Raport," "we," "our," or "us") processes personal information through our software-as-a-service platform and related solutions (the "Platform"). Our Website Privacy Policy, available at https://raport.com/privacy-policies, applies to our public website, marketing activities, and other online services.
Our customers determine how Customer Data is used through the Platform. Raport processes Customer Data for the customer under the customer agreement and, when applicable, a business associate agreement. Customer Data may include protected health information. The applicable customer agreement controls if it conflicts with this Policy.
Raport separately controls account, billing, security, support, and service-administration information needed to operate the Platform and our business. This Policy does not replace a customer's privacy notice.
2. Information We Process.
We process the following categories of personal information through the Platform:
- Account and administrative information. Name, business contact information, organization, role, login and authentication information, account settings, billing records, and support communications.
- Customer Data. Information submitted, stored, generated, or transmitted through the Platform for a customer, including workflow records and information about patients or other people with whom the customer works.
- Connected email accounts. If an authorized user connects a Google or Microsoft email account, we process the account name and email address, provider, OAuth access and refresh tokens, granted permissions, and connection and delivery information. Raport does not receive the email account password. To send email through the connected account, Raport processes recipients, subject lines, message bodies, attachments, and delivery data. The current email integration does not read the inbox or existing messages.
- Usage and security information. IP address, device and browser information, dates and times of access, feature activity, diagnostic information, and security events.
3. How We Use Information.
We use personal information to:
- Provide, authenticate, administer, secure, support, and maintain the Platform;
- Process Customer Data as directed by the customer and permitted by the customer agreement;
- Use automated and AI-assisted Platform features to prepare and send email through a connected account as configured or directed by the authorized user or customer;
- Provide customer support, investigate errors, prevent misuse, and protect the Platform;
- Manage accounts, billing, and service communications; and
- Comply with law and enforce our agreements.
4. How We Share Information.
We do not sell personal information or use connected email account information for advertising, credit decisions, or training generalized or shared AI models. We disclose information only as described below:
- Customers, authorized users, and recipients. We make Customer Data available as directed by the customer and deliver messages to recipients selected through the Platform.
- Service providers. We use providers for hosting, infrastructure, security, communications, payment processing, analytics, and support. They may process information only to provide services to Raport and under applicable contractual restrictions.
- Legal and safety matters. We may disclose information when required by law or when reasonably necessary to protect rights, safety, and the security of the Platform.
- Corporate transactions. Information may be disclosed in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to applicable law and contractual restrictions.
Raport's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Connected Email Choices.
An authorized user may disconnect an email account through the Platform and may also revoke Raport's permissions through the Google or Microsoft account settings. Disconnecting stops future use of the connection but does not delete email already sent or records retained under the customer agreement or applicable law.
After disconnection, Raport disables the connection and deletes or renders unusable stored OAuth credentials according to its deletion procedures. Raport may retain non-credential connection and delivery records as described below.
6. Security.
We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information. OAuth tokens are encrypted at rest and transmitted over encrypted connections. No security measure is perfect, and we cannot guarantee absolute security.
7. Retention and Deletion.
We retain Customer Data under the customer's instructions and applicable agreement. Email content, attachments, and delivery records may be retained as Customer Data. We retain connected-account credentials while needed to maintain the connection and delete or render them unusable after disconnection according to our deletion procedures.
We may retain account, security, billing, and other records for legitimate administrative, legal, contractual, or security purposes.
8. Privacy Rights and Requests.
Requests concerning Customer Data should be directed to the customer that controls the account. Raport assists customers with requests as required by the customer agreement and applicable law.
Depending on where you live, you may have rights concerning personal information that Raport controls, including rights to access, correct, delete, or obtain a copy of that information. You may submit a request to privacy@raport.com. We may verify your identity before completing a request and will not discriminate against you for exercising a privacy right.
9. International Transfers.
Raport may process personal information in the United States and other countries where Raport or its service providers operate. Privacy laws in those locations may differ from the laws where you live.
10. Children and Patients.
The Platform is offered to authorized personnel of Raport customers and is not offered directly to children or patients. Customers may use the Platform to process information about patients of any age and are responsible for providing required notices and obtaining required permissions.
11. Changes To This Policy.
We may revise this Policy from time to time. We will post the updated version at https://raport.com/privacy-policies/platform and change the effective date above. We will provide any additional notice required by law or the customer agreement.
12. Contact Us.
If you have questions or concerns about this Policy or our privacy practices, contact us at privacy@raport.com.
