Who this policy covers
Neurosonne, LLC ("Neurosonne," "we," "us") provides software for therapy organizations. This policy describes information handled through our website, communications, and services.
When a care organization uses Neurosonne to manage patient or workforce information, that organization directs its use of those records. Its privacy notices, our service agreement, and any applicable Business Associate Agreement (BAA) govern that relationship. This policy is not your healthcare provider’s Notice of Privacy Practices.
Information we handle
- Contact and business information: your name, email, phone number, organization, and information you choose to include when contacting us.
- Account information: account identifiers, organization membership, roles, sign-in and security information, preferences, and support communications.
- Service records: information authorized users enter or upload, such as patient demographics, appointments, clinical documents, signatures, insurance and billing information, and employee records.
- Technical information: IP address, browser and device information, request details, security events, and usage or performance information generated when our services are accessed.
- Payment information: payment processing is handled through payment providers such as Stripe. Transaction identifiers and payment status may be returned to Neurosonne.
Please do not send patient records, passwords, or payment-card details to our general contact email.
Why we use information
We use information to respond to inquiries, provide and support the service, manage accounts and subscriptions, process authorized transactions, deliver service communications, maintain records, investigate problems, prevent misuse, and meet applicable legal obligations. Patient information is processed for the care organization’s authorized purposes, subject to applicable agreements and law.
Providers and disclosures
Providing the service involves infrastructure, security, communication, payment, and other service providers. Our platform uses AWS infrastructure, Cloudflare delivery and security, and Stripe payment services. Information needed for a configured integration may be sent to the selected provider when that integration is used.
AI-assisted features may send the content needed for the requested task to an AI service provider. Organizations should review the feature, applicable provider terms, and the scope of their agreements before submitting sensitive information. Do not submit PHI to a feature unless its use is covered by the required agreements.
Authorized members of your organization can access information according to their permissions. We may also disclose information when required by law, to respond to valid legal process, or as necessary to address fraud or threats to security, subject to applicable confidentiality obligations. A corporate transaction involving personal information remains subject to applicable law and contractual restrictions.
Retention and safeguards
Retention depends on the information, the purpose for processing it, the care organization’s instructions, applicable agreements, and legal requirements. Records needed for security investigations, disputes, or legal obligations may need to be retained. Backup copies may remain until their retention cycle ends.
We use administrative, technical, and organizational safeguards to protect information. No service can guarantee that every security risk will be eliminated. Contact us if you believe information has been exposed or an account has been compromised; do not include the affected records in an ordinary email.
Requests and choices
Contact us to ask about information you have provided directly to Neurosonne or to request access, correction, or deletion where applicable. We may need to verify your identity and authority before acting. Responses and available rights depend on applicable law and the nature of the information.
For medical records, treatment information, or records entered by a care organization, contact that organization first. We support the organization’s handling of requests under the applicable agreement. Deleting an account does not necessarily require deletion of clinical records that the organization must retain.
You can ask us to stop optional marketing communications. Necessary account, security, and service notices may still be sent.
Children and caregivers
The public website is intended for organizations and adults evaluating the service, not for children to submit information independently. Clinical records may concern children and are handled on behalf of their care organization. Parents and other representatives should direct requests concerning a child’s record to that organization so it can verify their authority.
Where information is processed
Neurosonne is based in the United States and uses U.S. AWS regions for production hosting and recovery. External providers may process information in other locations under their applicable terms. Contact us before use if your organization has residency or international-transfer requirements.
Policy updates
Updates will be posted on this page with a revised date. Where applicable law or an agreement requires additional notice or consent for a material change, that process applies. A website policy update does not replace the terms of an executed BAA.
Contact us
Neurosonne, LLC
16650 N Kendall Dr, Suite
#213
Miami, FL 33196, United States
Email:
[email protected]
Phone:
+1 305 359 6983