Privacy Policy
Last updated: April 1, 2026
Cortexa Holdings, Inc. ("Cortexa," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our analytics platform and related services (the "Service"). This policy applies to practice owners, clinicians, and administrators who use the Cortexa platform.
By using the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, phone number, practice name, role, and billing information when you register for an account
- Practice Data: Information retrieved from your connected EHR systems (SimplePractice, TherapyNotes, TheraNest, and others) including session schedules, appointment statuses, clinician rosters, and revenue data
- Communications: Information you provide when you contact our support team, submit feedback, or participate in surveys
- Payment Information: Credit card numbers, billing addresses, and transaction details processed through our third-party payment processor (Stripe). We do not store full credit card numbers on our servers
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, queries submitted, time spent on the platform, and interaction patterns
- Device Information: Browser type, operating system, device type, screen resolution, and language preferences
- Log Data: IP addresses, access times, referring URLs, and error logs
- Cookies and Tracking Technologies: We use cookies, pixels, and similar technologies as described in our Cookie Policy
1.3 Information from Third Parties
- EHR Providers: Data synced from your connected electronic health record systems, limited to the scopes you authorize during the integration setup
- Analytics Providers: Aggregated usage analytics from Google Analytics and similar services
2. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, operate, and maintain the analytics dashboard, Cortexa IQ scoring, and related features
- Personalization: To tailor the Service to your practice size, specialties, and usage patterns
- Communication: To send you service-related notifications, respond to support inquiries, and provide product updates
- Billing: To process payments and manage your subscription
- Improvement: To analyze usage patterns, diagnose technical issues, and improve the Service
- Security: To detect, prevent, and respond to fraud, abuse, and security incidents
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
- Aggregated Insights: To create anonymized, de-identified benchmarks and industry insights that do not identify any individual or practice
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: With third-party vendors who assist us in operating the Service, including cloud hosting (Amazon Web Services), payment processing (Stripe), email delivery, and customer support tools. These providers are contractually obligated to protect your data
- EHR Integrations: With your connected EHR providers to the extent necessary to sync and retrieve your practice data
- Legal Requirements: When required by law, subpoena, court order, or governmental regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change
- With Your Consent: In any other circumstances where you have provided explicit consent
4. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account Data: Retained for the duration of your subscription plus 30 days to allow for data export after cancellation
- Practice Data: Synced data from EHR integrations is retained for the duration of your subscription. Upon cancellation, this data is deleted within 30 days
- Usage and Log Data: Retained for up to 24 months for analytics and security purposes, then automatically purged
- Billing Records: Retained for 7 years as required by tax and accounting regulations
- Aggregated Data: De-identified, aggregated data may be retained indefinitely as it cannot be linked back to any individual or practice
5. Data Security
We implement industry-standard security measures to protect your information, including 256-bit AES encryption at rest, TLS 1.3 encryption in transit, role-based access controls, and continuous monitoring. For more detail, please see our Data Security page.
While we take reasonable measures to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Your Rights and Choices
6.1 All Users
Regardless of your location, you may:
- Access and download a copy of your personal information
- Correct inaccurate personal information
- Delete your account and personal information (subject to legal retention requirements)
- Opt out of marketing communications at any time
- Request information about what data we hold about you
6.2 California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, our purposes for collecting it, and the third parties with whom we share it
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions
- Right to Correct: You may request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. If this changes, we will provide an opt-out mechanism
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
6.3 European Economic Area, UK, and Swiss Residents (GDPR)
If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation:
- Legal Basis: We process your data based on contractual necessity (to provide the Service), legitimate interests (to improve the Service and ensure security), consent (for marketing communications), and legal obligations
- Right to Portability: You may request your data in a structured, machine-readable format
- Right to Restrict Processing: You may request that we limit how we use your data in certain circumstances
- Right to Object: You may object to processing based on legitimate interests
- Right to Lodge a Complaint: You may file a complaint with your local data protection authority
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days (or within the timeframe required by applicable law).
7. International Data Transfers
Cortexa is based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States. We use appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, to ensure that your data is protected in accordance with this Privacy Policy when transferred internationally.
8. Children's Privacy
The Service is designed for use by licensed healthcare professionals and practice administrators. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have collected information from a minor, we will take steps to delete it promptly.
9. Third-Party Links
The Service may contain links to third-party websites or services that are not operated by Cortexa. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice on the Service at least thirty (30) days before the changes take effect. Your continued use of the Service after the effective date constitutes your acceptance of the revised policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Cortexa Holdings, Inc.
Email: [email protected]
Website: www.usecortexa.com