Sanasign Privacy Policy

Effective date: July 28, 2026

Introduction

Sanasign, Inc. ("Sanasign," "we," "our," or "us") builds software that moves orders for care delivered in the home — plans of care, initial certifications and recertifications, supplemental and change orders, and therapy and wound care orders — from the agency that prepares them to the provider who signs them, and back again with a complete, auditable record.

This Privacy Policy (this "Policy") explains how we collect, use, and share information in connection with our website at www.sanasign.com, the demonstration version of our application, and the emails and notifications we send in connection with them (together, the "Services"). It does not apply to any other website or service, including those operated by our customers or by third parties.

Please read the next section before you use the demonstration. It explains what the demonstration is for and what you must not put into it.

HIPAA, Patient Information, and What the Demonstration Is For

Sanasign is designed to handle protected health information, as that term is defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended ("HIPAA"). It is not yet doing so.

Today, the Services consist of our public website and a demonstration environment that runs on sample data. We have not entered into business associate agreements, we are not acting as anyone's business associate, and the demonstration environment is not authorized, configured, or contracted to receive protected health information.

Do not enter information about real patients into the demonstration. Use the sample patients we provide, or invent your own. This is not a formality. Information you enter into the demonstration is not walled off the way production data will be: our team can and does look at it in the ordinary course of building the product — to reproduce a bug you reported, to see where a workflow is confusing, to fix something that broke. Demonstration data is also reset and deleted on no fixed schedule. Neither of those is an acceptable way to treat a patient's record, which is exactly why real patient information does not belong there.

If you realize that patient information has been entered into the demonstration — yours or anyone else's — tell us at [email protected] and we will delete it promptly and confirm when it is gone.

When we move to production, organizations that use Sanasign will sign a Healthcare Provider User Agreement that includes a business associate agreement. At that point we will handle protected health information as a business associate, under those agreements rather than under this Policy, and we will update this Policy to describe the arrangement. Until then, everything described here is ordinary business and website information — not patient records.

Information We Collect

Information You Provide

We collect information you give us when you:

  • Request a demonstration, subscribe to updates, or fill out any other form on our website — typically your name, email address, telephone number, the agency or practice you work for, and whatever you tell us about your timing and interest;
  • Register for or are given access to the demonstration environment, including your name, work email address, and the role you are evaluating;
  • Enter, upload, edit, comment on, send, review, decline, or sign anything within the demonstration environment;
  • Contact us for support, join a demo call or walkthrough, or respond to a survey; or
  • Correspond with us about a business relationship, a partnership, a job opening, or any other matter.

About what you enter in the demonstration: we treat it as sample data. We may view it, copy it, analyze it, and use it to diagnose problems and improve the product, and we may delete it at any time. Do not enter anything you would not be comfortable having us read — no patient information, and no confidential information belonging to you or your employer.

Information We Collect Automatically

When you visit our website or use the demonstration, we and our service providers automatically collect:

  • Device and connection information, including IP address, browser type and version, operating system, device type, screen characteristics, language settings, referring and exit pages, and the pages and features you interact with;
  • Usage information, including sign-in times, session activity, the actions you take in the demonstration, and their timing and sequence; and
  • Email engagement information, including whether a message we sent was delivered and opened and whether links in it were followed.

Information From Other Sources

The demonstration includes a searchable directory of providers and practices. Where that directory includes real professional information rather than sample records, it is drawn from public sources such as the National Plan and Provider Enumeration System (NPPES) and state licensing registries — the same information those registries publish. It is professional information: name, credential, National Provider Identifier, practice affiliation, and work contact details. It contains nothing about patients.

We may also receive information about you from partners, from colleagues at your organization who refer you to us, and from security and fraud-prevention vendors.

Payment Information

We do not currently sell subscriptions through the Services and do not collect payment card information. If that changes, we will update this Policy, and payment card details will be handled by a third-party payment processor under its own terms rather than stored by us.

Cookies and Similar Technologies

We and our service providers use cookies and similar technologies on our website and in the demonstration:

  • Strictly necessary. Required to operate the Services — to keep you signed in, maintain your session, route requests, and protect against fraud and abuse. These cannot be turned off.
  • Performance and analytics. Used to understand in aggregate how the website and demonstration are used, so we can find problems and improve them.
  • Preferences. Used to remember choices you have made, such as display settings.

We do not use cookies or similar technologies for cross-context behavioral advertising, we do not permit third parties to do so on our website or in the demonstration, and we do not display third-party advertising anywhere in the Services.

Most browsers let you refuse or delete cookies through their settings; because some are necessary, disabling them may break parts of the Services. Where applicable law requires it, we present a cookie preference control and honor the Global Privacy Control (GPC) signal. A GPC signal applies only to the browser or device that sends it.

How We Use Information

We use the information described above to:

  • Operate, secure, and maintain the website and the demonstration environment;
  • Create and administer demonstration accounts, authenticate users, and enforce access controls, including multi-factor authentication;
  • Schedule and conduct demonstrations, respond to your questions, and follow up on your interest in Sanasign;
  • Provide support, investigate and resolve technical problems, and communicate with you about your access;
  • Send service announcements, security notices, and other administrative messages;
  • Understand how the Services are used, improve their design and reliability, and develop new features;
  • Send marketing communications about Sanasign, subject to the choices described below;
  • Detect, investigate, and prevent fraud, security incidents, abuse, and violations of our Terms of Use or applicable law;
  • Comply with our legal obligations and enforce our agreements; and
  • Any other purpose we describe when we collect the information, or for which you give us permission.

Artificial Intelligence and Model Training

We do not provide information you enter into the demonstration to third parties for the training of their artificial intelligence models. Where we use machine learning or automated processing within the Services, we do so to operate and improve the Services, and we require our vendors to contractually commit to zero retention of data submitted through their interfaces for their own training purposes.

We may use information about how the Services are used, and sample data entered into the demonstration, to evaluate and improve our own product — which is another reason not to enter real patient information.

How Information Is Shared

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are used in the California Consumer Privacy Act and comparable state laws.

We share information in the following circumstances:

Within your organization's demonstration workspace. If colleagues from your agency or practice are evaluating Sanasign alongside you, they may be able to see the accounts, documents, and activity within that workspace.

With counterparties in the demonstration. Sanasign is a two-sided product. When you send a sample document from one side to the other, the recipient sees it, and the sender sees when it was opened and what was done with it. That is the workflow being demonstrated.

With service providers. We use vendors to host and operate the Services and run our business — cloud infrastructure, authentication, email and notification delivery, error monitoring, analytics, scheduling, customer support, and similar functions. They may access information only as needed to perform work for us, are bound by written contracts, and may not use it for their own purposes.

For legal and safety reasons. We may disclose information when we believe in good faith it is required by law or legal process; to establish, exercise, or defend legal claims; to investigate suspected fraud, security incidents, or violations of our agreements; or to protect the rights, property, or safety of Sanasign, our users, or the public.

In a corporate transaction. If Sanasign is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its business or assets, information may be transferred as part of that transaction or the diligence preceding it, subject to confidentiality obligations. If personal information is transferred, it remains subject to this Policy until the recipient provides notice of a different one.

With your permission, or as otherwise described to you at the time.

Provider and Practice Directory

The demonstration includes a searchable directory of providers and practices, so that an agency user can find the right signer. It holds professional information only — name, credential, NPI, practice affiliation, and work contact details — drawn from public registries and from information users supply. It is not a public consumer-facing directory, it contains no ratings or reviews, it is not open to the general public, and it contains no patient information.

If your professional information appears in the directory and is inaccurate, or you would prefer it not be listed, write to [email protected] and we will correct or remove it.

Communications From Us

Some messages are part of the Services and cannot be turned off while you have access — signature and status notifications generated by the demonstration workflow, security alerts, authentication messages, and notices about changes to our terms.

Marketing communications are optional. You can opt out at any time using the unsubscribe link in any message or by writing to [email protected]. Opting out of marketing does not stop service messages.

Security

We use administrative, physical, and technical safeguards designed to protect the information we hold, including encryption of data in transit and at rest, role-based access controls, organization-level data isolation enforced at the database layer, multi-factor authentication, logging and monitoring, and confidentiality obligations for personnel with access to our systems.

No system is perfectly secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed in breach of our safeguards. Keep your credentials confidential, enable multi-factor authentication, do not share accounts, and tell us promptly at [email protected] if you believe an account has been compromised.

Because the demonstration environment is an evaluation tool rather than a production system, it does not carry the contractual security commitments that will accompany our production service. This is one more reason to keep real patient information out of it.

Data Retention

Demonstration data is not retained. We reset, overwrite, and delete demonstration environments and their contents on no fixed schedule and without notice. Do not use the demonstration to store anything you need to keep, and keep your own copy of anything you want.

We retain other information — demo requests, correspondence, account records, marketing preferences, and security and usage logs — for as long as needed for the purposes described in this Policy and to meet our legal, tax, audit, and recordkeeping obligations, resolve disputes, and enforce our agreements. Backups and disaster-recovery copies persist for a limited period after deletion from active systems and are overwritten on a rolling schedule.

Your Choices and Rights

Access and correction. You can update much of your profile information by signing in. If you cannot make a change yourself, write to [email protected] and we will help.

Deletion. You can ask us to delete your demonstration access and the personal information we hold about you. Some records — for example, those we must keep for legal or security reasons — may be retained.

Marketing. Unsubscribe at any time, as described above.

State privacy rights. Residents of California, Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws may have rights to know what personal information we hold, to obtain a copy, to correct it, to delete it, and to appeal a denial, subject to the exceptions in the applicable law. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for profiling that produces legal or similarly significant effects, so there is nothing to opt out of in those categories. Note that many of these laws exempt information used solely in a business-to-business or employment context, which describes most of what we hold; where an exemption applies, we will tell you.

To make a request, write to [email protected]. We will verify your identity before acting, will not discriminate against you for making a request, and will respond within the period the applicable law requires. An authorized agent may submit a request on your behalf with proof of authorization.

Children's Privacy

The Services are professional tools intended only for adults acting in a professional capacity. You must be at least 18 years old to use them. We do not knowingly collect personal information from children, and if we learn that we have, we will delete it.

Third-Party Websites and Services

Our website and the demonstration may link to sites and services we do not operate. This Policy does not apply to them. We do not control how they collect or use information, and you should review their privacy policies before providing information to them.

United States Only

The Services are operated in and intended for use in the United States. We do not offer them in jurisdictions where doing so would be unlawful. If you access the Services from outside the United States, you do so on your own initiative, are responsible for compliance with local law, and understand that your information will be processed in the United States.

Changes to This Policy

We will update this Policy as our business and the law change — and we expect to update it substantially when we move from demonstration to production and begin handling protected health information under business associate agreements. When we update it, we will revise the effective date above and post the new version on our website. If a change materially affects how we handle personal information, we will give additional notice by email, in the application, or prominently on our website before it takes effect. Continued use of the Services after a change takes effect means you accept it; if you do not, stop using the Services.

Contact Us

Questions about this Policy, about how we handle information, or about a privacy request:

Email: [email protected]

Mail: Sanasign, Inc. Attn: Privacy 160 Belvedere St San Francisco, CA 94117

We will respond as promptly as we can.