Legal
Privacy Policy
Effective August 13, 2026
This policy explains what information VeloComms collects, how it is used, and the choices available to you. VeloComms is operated by Velozent Technologies and is designed for healthcare organizations that must meet HIPAA obligations.
1. Who this policy covers
VeloComms is a workplace platform licensed to healthcare organizations (our customers). When your organization provisions VeloComms, that organization is the data controller for the content and directory information processed in its workspace. Velozent acts as a service provider (and, where PHI is involved, a Business Associate) processing data on the organization's behalf under its instructions.
2. Information we process
- Account and directory data: name, work email, role, department, and presence status provisioned by your organization or its identity provider.
- Content you create: messages, files, tasks, call metadata, and other records generated while using the platform.
- Operational logs: authentication events, audit entries, and technical diagnostics required to run and secure the service.
- Device and connection data: IP address and browser/user-agent, used for security and troubleshooting.
3. How information is used
- To provide the platform and its features to your organization.
- To secure accounts, detect abuse, and maintain the immutable audit trail.
- To provide AI features you invoke, under your organization's governance controls.
- To meet legal, regulatory, and contractual obligations, including retention and legal hold.
4. Protected Health Information (PHI)
Where your organization uses VeloComms to process PHI, Velozent handles that PHI only as permitted by the applicable Business Associate Agreement and only to provide and support the service. VeloComms does not sell PHI and does not use it for advertising.
5. AI features
AI capabilities operate on your organization's own content to produce drafts, summaries, triage suggestions, and search results. Governed actions require human approval before they take effect. Your organization controls which AI features are enabled and can disable them at any time.
6. Sharing
We share information with subprocessors that help operate the service (for example, infrastructure and, where enabled, AI providers), each under contractual confidentiality and security obligations. We disclose information when required by law or to protect the rights and safety of users and the public.
7. Retention
Content is retained according to the retention and legal-hold settings configured by your organization. When a record is under legal hold, it is preserved regardless of ordinary retention windows.
8. Security
We apply administrative, technical, and physical safeguards including encryption in transit and at rest, role-based access control, multi-factor authentication, and continuous audit logging. No system is perfectly secure, but security is engineered into VeloComms rather than added on.
9. Your choices and rights
Because your organization controls its workspace, requests to access, correct, or delete personal information should be directed to your organization's administrator. We support administrators in responding to such requests.
10. Changes to this policy
We may update this policy as the product and regulations evolve. Material changes will be communicated to customer organizations, and the effective date above will be updated.
This document is provided for general information about how VeloComms is built and operated and is not legal advice. Covered entities should complete their own HIPAA risk assessment and a Business Associate Agreement before processing PHI.