Privacy Policy

Last updated: June 2026

This is a preview-stage draft for the haau3 platform and is not legal advice. It will be replaced with reviewed legal copy before general availability.

Overview

This policy explains what the haau3 platform collects and how we use it. The platform is a non-PHI control plane: it is designed to handle public and synthetic healthcare data, not protected health information.

Information we collect

We collect account information you provide (such as name, email, and organization), authentication data managed by our identity provider, and operational data such as API usage and logs needed to run and secure the Services.

No PHI by default

The platform does not require or expect protected health information. Do not send PHI except through Services explicitly designated to receive it under an executed agreement. APIs serve public or synthetic data (for example, provider availability, directory, and synthetic patients).

How we use information

We use information to provide and improve the Services, authenticate users, enforce usage limits, communicate with you, and maintain security. We do not sell your personal information.

Third-party processors

We rely on reputable infrastructure and identity providers to operate the platform. These processors handle data on our behalf under their own security and privacy commitments.

Data retention

We retain account and operational data for as long as your organization uses the Services and as needed for legitimate business and legal purposes.

Your choices

You can access and update your account information, and request deletion of your organization’s data, subject to legal and operational constraints.

Changes

We may update this policy from time to time and will communicate material changes through the platform or by email.

Contact

Questions about this policy can be directed to hello@haau3.com.