Legal
Privacy Policy
How Kodap collects and handles information about the people who visit our site, the staff who use the platform, and the patients whose referrals move through it.
01About this Policy
This Privacy Policy explains how Kodap collects, uses, and protects information when you visit kodap.ai, contact us through our lead form, or use the Kodap platform as part of a clinic’s workforce. It applies to information Kodap collects in its own capacity as a business.
Patient Protected Health Information (PHI) is treated differently. When Kodap processes a patient’s PHI inside the platform, it does so as a HIPAA Business Associate to the patient’s clinic. That processing is governed by the Business Associate Agreement (“BAA”) between Kodap and the clinic, and by the clinic’s own Notice of Privacy Practices — not by this Policy. Section 6 describes our role at a high level.
02Who this covers
Marketing-site visitors
People who visit kodap.ai, request information through the lead form, or correspond with us about a potential subscription.
Workforce users
Coordinators, owners, administrators, and other staff who use the Kodap operator console under their clinic’s subscription.
Indirect contacts
Referring providers, billers, and other parties Kodap interacts with on behalf of a customer clinic. The clinic remains the responsible party for these interactions; this Policy describes Kodap’s role.
03Information we collect
From marketing-site visitors
- Information you submit through the lead form: your name, clinic name, email address, phone number, and the approximate weekly referral volume you reported.
- Standard request data your browser sends: IP address, user agent, the page you came from, and timestamps.
- A small number of strictly functional storage values used to operate the site (for example, scroll-reveal state). The marketing site does not currently set advertising cookies and does not use third-party advertising trackers.
From workforce users of the platform
- Account information your clinic provides: name, business email, role, and the multi-factor authentication factor you enroll.
- Authentication and audit metadata: login timestamps, source IP, MFA challenges, actions taken in the console, and reasons captured when a recommendation is overridden. These records are maintained to satisfy HIPAA’s Audit Controls requirement and our internal logging policy.
- Device information: browser, operating system, and screen size — collected only to operate the console and diagnose issues.
Patient information (PHI)
When a clinic places a referral into the platform, the platform stores patient demographics, insurance details, payer responses, PMP and state-program findings, clinical notes from referral packets, outreach attempts and replies, and any documents the patient uploads. As noted above, this processing is governed by the BAA.
04How we use information
Marketing-site information
- To respond to your inquiry, schedule a follow-up conversation, and provide information about Kodap.
- For a small amount of internal analytics — for example, which sections of the site convert to inquiries — using aggregated request data.
- To send infrequent product updates to people who have asked for them. Every such message includes a clear opt-out.
Workforce-user information
- To authenticate users, enforce role-based access, and maintain an audit trail of system activity.
- To provide and improve the Service, deliver support, and meet legal and regulatory obligations.
Patient information (PHI)
Used only to provide and improve the Service for the clinic that placed the patient’s information into the platform, and only as permitted by the BAA. Specific uses include surfacing the referral on the clinic’s worklist, performing eligibility and program checks on the clinic’s behalf, sending clinic-authorized outreach to the patient, and producing audit records.
06Patient information & the BAA
Kodap is a HIPAA Business Associate to each of its customer clinics. The clinic — not Kodap — is the Covered Entity that owes patients the protections of the HIPAA Privacy Rule.
Patients seeking to exercise rights under HIPAA (access, amendment, accounting of disclosures, restrictions) should contact the clinic that referred them to the platform. Kodap supports clinic responses to such requests.
Kodap will notify the affected clinic within 24 hours of becoming aware of any incident reasonably likely to involve unauthorized access to PHI, consistent with HIPAA Breach Notification timing.
07Security
Kodap maintains administrative, physical, and technical safeguards designed to protect information we hold:
- TLS 1.2+ on every transport.
- AES-GCM field-level encryption of identified patient fields, and customer-managed-key (CMK) wrapped encryption-at-rest for storage holding patient information.
- Multi-factor authentication for workforce users, role-based access, account lockout, and append-only audit logging.
- Annual penetration testing, quarterly internal reviews, annual workforce HIPAA training, and a documented incident response plan.
No system can guarantee perfect security. We encourage workforce users to enable strong authentication factors and keep their devices current.
08Data retention
- Marketing-lead information is retained for as long as is reasonably necessary to follow up, and — where the lead has not become a customer — deleted within 24 months unless you ask us to stay in touch longer.
- Workforce account information is retained for the life of the clinic’s subscription plus the period required by HIPAA documentation rules (six years from the last touch).
- Patient information (PHI) is retained according to the BAA and the clinic’s instructions, and at minimum for the period required by HIPAA documentation rules. Backups expire on their normal cycle.
- Audit logs are retained for the period required by HIPAA’s Audit Controls requirement and Kodap’s logging policy.
09Your choices
Marketing emails
You can opt out of any product update from us by replying to the message or emailing info@kodap.ai. Service-related notices are not promotional and may continue.
Patient SMS opt-out
Patients can reply STOP to any SMS sent through the platform; the platform records the opt-out and stops further messages on the clinic’s behalf.
Browser controls
You can clear local storage at any time. We honor Global Privacy Control signals where the law requires us to.
10State privacy rights
If you are a marketing-site visitor or workforce user covered by a U.S. state privacy law that grants you rights of access, deletion, correction, or portability (for example, the California Consumer Privacy Act, the Colorado Privacy Act, the Texas Data Privacy and Security Act, or similar), you may exercise those rights by contacting privacy@kodap.ai. We do not sell personal information and we do not engage in cross-context behavioral advertising.
PHI handled under HIPAA is exempt from these state laws; requests about PHI should go through your clinic, as described in Section 6.
11Children’s information
The marketing site is not directed at children. We do not knowingly collect personal information from children under 13. When a clinic places PHI for a minor patient into the platform, that information is handled under the BAA in the same way as PHI for any other patient, with the clinic acting as the patient’s Covered Entity.
12International users
Kodap is operated from the United States, and the Service is intended for U.S. clinics and their U.S.-resident patients. If you access the marketing site from outside the United States, you understand that information will be processed in the United States under U.S. law.
13Changes to this Policy
We may update this Policy from time to time. The “Last updated” date at the top of this page reflects the most recent change. Material changes affecting how we handle information will be communicated through the marketing site or, for active customers, by email to the clinic’s administrative contact.
14Contact
Questions about this Policy can be sent to:
- Email: privacy@kodap.ai (or info@kodap.ai)
- Phone: (405) 874-6968
- For HIPAA questions about a specific patient’s PHI, please contact the clinic that referred you to the platform.