Effective date: Janurary 1, 2025
VoiceBreeze LLC (“VoiceBreeze”, “we”, “our”), doing business as SiriusMed AI, provides voice‑first clinical software, patient engagement tools, and related services (the “Services”). This Privacy Policy explains how we collect, use, disclose, and protect information, including Protected Health Information (“PHI”) when applicable.
Email: info@voicebreeze.io
Address: VoiceBreeze LLC, 2121 6th Ave Seattle WA, 98121
This Policy applies to our websites (e.g., siriusmed.io), apps, APIs, WhatsApp/telephony agents, and any other channels that link to it. If a health‑care provider uses SiriusMed AI with a Business Associate Agreement (BAA), we act as the provider’s Business Associate for PHI and process PHI on their behalf. For direct‑to‑consumer use, we act as the data controller.
We do not knowingly collect data from children under 13, nor knowingly allow such users to register.
Legal bases (GDPR). Performance of a contract; legitimate interests (product security, service improvement with minimal privacy impact); consent where required (e.g., certain messaging or marketing); compliance with legal obligations.
We share data:
We do not sell personal information, including under the CCPA definition of “sale”. We do not share PHI for cross‑context behavioral advertising.
We retain information for as long as necessary to provide the Services, meet legal/contractual obligations, resolve disputes, and maintain security. PHI retention follows the BAA and applicable law. You may request earlier deletion where permissible (see Data Deletion below).
Depending on your location, you may request: access, correction, deletion, portability, restriction/objection to processing, and to opt‑out of non‑essential cookies or marketing.
How: email info@voicebreeze.io or use in‑product controls. Where we act as a Business Associate/processor, we will forward requests to the Covered Entity/controller and assist as required.
We implement administrative, technical, and physical safeguards appropriate to the data sensitivity, including encryption in transit and at rest, access controls, audit logging, least‑privilege design, and vendor risk management. No method of transmission or storage is 100% secure.
We may process data in the United States and other countries. Where required, we use appropriate safeguards (e.g., SCCs) for cross‑border transfers.
We use necessary cookies for authentication and security and, with consent where required, analytics to improve the Services. Manage preferences in the product or your browser.
We may update this Policy. The “Effective date” will indicate the latest version. Material changes will be communicated via product notice or email.
You can request deletion of your personal data (and, where applicable, PHI) in any of the following ways:
For your protection, we verify identity and ownership (e.g., email challenge, one‑time code, or admin approval for organization‑managed accounts). For PHI under a provider’s account, we act at the direction of the provider; we will forward your request to the provider if they control the data.
We will delete or irreversibly de‑identify personal data and content stored in your account, including messages, transcripts, and files, except as noted below.
We may retain limited records as required by law, for fraud prevention, accounting, or security logs, and backups that are automatically purged on a rolling schedule. PHI retained to comply with health‑care record requirements will be handled under the applicable BAA or law.
We aim to complete deletions within 30 days of verification (or the shorter period required by local law). Complex, large, or archived datasets may take up to 60 days due to backup cycles.
We will send a confirmation when deletion is complete or explain why we cannot delete specific items (e.g., legal hold).
Questions about deletion: privacy@voicebreeze.io
Questions or requests: privacy@voicebreeze.io
Security reports: security@voicebreeze.io