1. Introduction
LifeOS Platforms, Inc. ("LifeOS," "we," "us," or "our") is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, disclose, and safeguard Protected Health Information (PHI) and other personal data when you use our clinical-grade AI workspace platform (the "Service").
As a provider of healthcare technology solutions, we take our obligations under the Health Insurance Portability and Accountability Act (HIPAA), the General Data Protection Regulation (GDPR), and other applicable privacy laws extremely seriously.
2. Scope
This Privacy Policy applies to:
- Website Visitors: Individuals who visit our marketing website (lifeoslabs.com)
- Platform Users: Healthcare professionals and organizations ("Customers") who access and use the LifeOS clinical AI Service
- Patient Data: Protected Health Information (PHI) uploaded to or processed by the Platform on behalf of our Customers
Note: This website is for informational purposes only and does not collect personal data from visitors. Access to the LifeOS Service requires acceptance of our Master Commercial Agreement, which includes a Business Associate Agreement (BAA) as required by HIPAA.
3. Information We Collect
3.1 Patient Data (Protected Health Information)
When you use the LifeOS Service, we collect and process Patient Data as defined under HIPAA, including:
- Patient demographics, medical history, and clinical notes
- Diagnostic information, treatment plans, and prescriptions
- Lab results, imaging data, and vital signs
- Billing codes, prior authorization forms, and insurance information
- Any other information that constitutes PHI under 45 C.F.R. § 160.103
Customer Ownership: Customer retains all ownership rights to Patient Data. We process this data solely as a Business Associate to provide the Service.
3.2 System Data (De-identified, Aggregated Data)
We collect System Data, which includes aggregated, de-identified, and statistical data derived from the operation of the Service, including:
- Metadata about service usage patterns and feature adoption
- AI model performance metrics and accuracy statistics
- System logs, error reports, and performance data
- De-identified clinical insights used for research and development
Important: System Data cannot identify Customer or any specific patient. All System Data is strictly de-identified in accordance with HIPAA standards (45 C.F.R. § 164.514(b)).
3.3 Account and Usage Information
For Authorized Users of the Service, we collect:
- Account registration information (name, email, job title, organization)
- Authentication credentials and login activity
- Audit logs for HIPAA compliance (access, modifications, exports)
- Support requests and feedback
3.4 Website Analytics (Minimal Collection)
Our marketing website collects minimal analytics data to improve user experience:
- IP address (anonymized)
- Browser type and device information
- Pages visited and time on site
- Referral source
This data is collected via privacy-focused analytics tools and does not include personally identifiable information.
4. How We Use Your Information
4.1 Service Delivery
We use Patient Data to provide the LifeOS Service, including:
- Creating and maintaining the Centralized Patient Graph
- Generating clinical notes, coding suggestions, and prior authorization forms
- Providing AI-powered clinical decision support
- Enabling autonomous agents for administrative tasks
4.2 De-identification and AI Model Training
Per Section 3.3 of our Master Commercial Agreement: Customer grants LifeOS a worldwide, perpetual, royalty-free license to:
- Host, process, and display Patient Data to provide the Service
- De-identify and aggregate Patient Data to create System Data
⚠️ Important Disclosure: Customer explicitly acknowledges and agrees that LifeOS owns all System Data and may utilize such data to train, tune, and improve its machine learning models and algorithms, provided such use strictly complies with HIPAA. This enables us to continuously improve the accuracy and effectiveness of our clinical AI.
4.3 System Data for Product Improvement
We use System Data (de-identified, aggregated data) to:
- Improve AI model performance and accuracy
- Develop new features and capabilities
- Conduct research on clinical workflows and healthcare operations
- Monitor system performance and security
4.4 Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), UK, or Switzerland, we process personal data based on the following legal grounds:
- Contractual Necessity: To perform our obligations under our agreement with you
- Legitimate Interests: To operate our business, improve our Service, and ensure security
- Legal Obligation: To comply with HIPAA, GDPR, and other applicable laws
- Consent: Where required by law, we will obtain your explicit consent
5. Zero Data Retention (ZDR) Policy
Zero Data Leakage. Encrypted End-to-End.
LifeOS implements a Zero Data Retention (ZDR) policy for all AI model API calls to third-party inference providers. This means:
5.1 Default ZDR for AI Inference
By default, LifeOS does not retain Patient Data inputs or AI-generated outputs when making inference requests to third-party AI model APIs. Data is:
- Processed for immediate response generation
- Encrypted end-to-end during transmission (TLS 1.3)
- Discarded immediately after processing
- Never stored or logged by third-party AI providers (per BAA requirements)
5.2 Usage Metadata (Excludes Patient Data)
LifeOS continuously collects usage metadata to monitor service activity and system performance. This metadata explicitly excludes any Patient Data inputs or outputs and includes only:
- API call volume and latency metrics
- Model selection and configuration parameters
- Error rates and system health indicators
- Token counts and processing times
5.3 Customer Data Control
Customers have full control over data retention settings:
- Patient Graph Data: Stored in LifeOS-controlled, HIPAA-compliant infrastructure (not shared with AI providers)
- Audit Logs: Retained for HIPAA compliance (minimum 6 years, per 45 C.F.R. § 164.316(b)(2))
- Data Export: Available anytime in standard machine-readable format (JSON/CSV)
5.4 Third-Party AI Provider Requirements
All third-party AI model providers used by LifeOS must:
- Sign a HIPAA-compliant Business Associate Agreement (BAA)
- Agree to Zero Data Retention (ZDR) for inference requests
- Not use Customer data for model training or improvement without explicit de-identification
- Maintain SOC 2 Type II or equivalent certification
- Provide end-to-end encryption (TLS 1.3 or higher)
6. HIPAA Compliance
6.1 Business Associate Status
LifeOS operates as a Business Associate under HIPAA. Our Customers are "Covered Entities," and the processing of Patient Data is governed by our Business Associate Agreement (BAA), which is part of our Master Commercial Agreement.
6.2 Safeguards and Security
We maintain administrative, physical, and technical safeguards as required by the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C), including:
- Administrative Safeguards: Security policies, workforce training, incident response procedures
- Physical Safeguards: Secure cloud infrastructure (SOC 2 Type II compliant), access controls
- Technical Safeguards: Encryption at rest and in transit, access controls, audit logging, authentication
6.3 Breach Notification
In accordance with 45 C.F.R. § 164.410, LifeOS will report any Breach of Unsecured PHI to the Covered Entity:
- Timing: Without unreasonable delay and no later than five (5) business days after discovery
- Content: Description of breach, date of incident, types of PHI involved, recommended mitigation steps
- Cooperation: Full cooperation with Customer's investigation and regulatory notifications
6.4 Minimum Necessary Standard
LifeOS requests, uses, and discloses only the minimum amount of PHI necessary to accomplish the purpose of the request, use, or disclosure, as required by HIPAA.
7. GDPR Compliance (For EU Users)
7.1 Data Controller and Processor
Under GDPR, Customer is the Data Controller and LifeOS is the Data Processor for Patient Data. LifeOS is the Data Controller for System Data (de-identified, aggregated data).
7.2 Data Subject Rights
Individuals whose data is processed by LifeOS have the following rights under GDPR:
- Right to Access: Request access to your personal data in a structured, machine-readable format
- Right to Rectification: Request correction of inaccurate personal data
- Right to Erasure ("Right to be Forgotten"): Request deletion of personal data under certain conditions
- Right to Data Portability: Request transfer of data to another controller
- Right to Restriction: Request restriction of processing under certain conditions
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time (where consent is the legal basis)
To exercise these rights, please contact your healthcare provider (the Data Controller) or contact us at enterprise@lifeoslabs.com.
7.3 International Data Transfers
Patient Data may be transferred to and processed in the United States. LifeOS ensures adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- SOC 2 Type II certified security controls
- HIPAA-compliant infrastructure and practices
7.4 Supervisory Authority
You have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.
8. Data Sharing and Disclosure
8.1 Subcontractors
In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), we may engage subcontractors who create, receive, maintain, or transmit PHI on our behalf. All subcontractors must:
- Sign a Business Associate Agreement (BAA) with the same privacy and security obligations
- Maintain SOC 2 Type II or equivalent certification
- Agree to Zero Data Retention (ZDR) for AI inference (where applicable)
We maintain a current list of subcontractors and provide reasonable advance notice of material changes.
8.2 No Selling of Data
Trust Guardrail: LifeOS will NOT:
- Attempt to re-identify any individual from De-identified Information
- Sell De-identified Information to third-party data brokers or advertisers
8.3 Legal Requirements
We may disclose information when required by law, such as:
- To comply with a court order, subpoena, or legal process
- To respond to government or regulatory requests (e.g., HHS Secretary audits per 45 C.F.R. § 164.528)
- To protect our legal rights or defend against claims
9. Your Rights
9.1 HIPAA Rights (For Patients)
Under HIPAA, you have the right to:
- Access PHI: Inspect and obtain a copy of your PHI in a Designated Record Set (45 C.F.R. § 164.524)
- Amend PHI: Request amendments to inaccurate or incomplete PHI (45 C.F.R. § 164.526)
- Accounting of Disclosures: Request an accounting of disclosures of your PHI (45 C.F.R. § 164.528)
To exercise these rights, please contact your healthcare provider (the Covered Entity). LifeOS will assist Covered Entities in fulfilling these requests.
9.2 Customer Rights (For Platform Users)
As a Customer or Authorized User, you have the right to:
- Access, export, and delete your account information
- Terminate your subscription and request data export (30-day window)
- Opt out of marketing communications
- Request correction of inaccurate information
10. Security Measures
LifeOS maintains SOC 2 Type II compliant security measures to protect PHI and personal data. For detailed information about our security practices, please see our Security Policy.
Key security controls include:
- Encryption: Data at rest (AES-256) and in transit (TLS 1.3)
- Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA)
- Audit Logging: Comprehensive logging of all PHI access and modifications
- Infrastructure Security: Cloud provider security (AWS/GCP), DDoS protection, network isolation
- Regular Assessments: Annual SOC 2 Type II audits, penetration testing, vulnerability scanning
11. Data Retention
We retain your information for the period necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required by law.
- Patient Data: Retained for the duration of the Customer's subscription. Upon termination, Customer may export data for 30 days, after which it is deleted unless legally required to retain.
- Audit Logs: Retained for minimum 6 years per HIPAA requirements (45 C.F.R. § 164.316(b)(2))
- System Data: Retained indefinitely as it is de-identified and owned by LifeOS
- Account Data: Retained until account deletion or 90 days after subscription termination
13. Contact Information
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
LifeOS Platforms, Inc.
1111B South Governors Avenue
Dover, Delaware 19904
United States
Email: enterprise@lifeoslabs.com
For HIPAA-related requests (access, amendment, accounting of disclosures), please contact your healthcare provider (the Covered Entity).