1. Scope of this policy
This Privacy Policy explains how RadiusDocs, operated by [TO CONFIRM: legal entity name] ("RadiusDocs", "we", "us"), handles personal information in connection with our marketing website at radiusdocs.ai and our business services. RadiusDocs is also branded as CaseOS in some materials. This policy applies to the same company under either name.
RadiusDocs is a business-to-business platform. Our customers are organizations: personal injury law firms, pain management clinics, chiropractic clinics, IME physicians, life care planners, and insurance adjusters. We do not offer the service to consumers, and we do not market to patients or claimants directly.
1.1 Two different kinds of data, governed by two different agreements
Read this section before anything else. It is the most important distinction in this document.
- Website and business contact data. This is information about you as a visitor, a prospect, or an authorized user at a customer organization: your name, work email, firm or practice, role, and the technical data our website collects. This policy governs that data.
- Customer records inside the application. This is the medical record content our customers upload to docs.radiusdocs.ai, along with the chronologies, demand letters, IME reports, life care plans, medical necessity letters, and medical summaries generated from it. That content frequently contains protected health information (PHI) belonging to the customer's own patients or clients. This policy does not govern that content.
PHI is governed by the BAA, not by this policy. When RadiusDocs processes medical records uploaded by a customer, we act as a HIPAA Business Associate. The customer is the Covered Entity, or a Business Associate acting on behalf of one, and remains responsible for the records it uploads. Our handling of that PHI is governed by the signed Business Associate Agreement (BAA) between RadiusDocs and the customer, by the customer's written instructions, and by HIPAA. Where this Privacy Policy and a signed BAA would produce different results for PHI, the BAA controls. Nothing on this website changes, limits, or substitutes for a BAA.
If you are a patient, a claimant, or another individual whose medical records may have been uploaded by one of our customers, RadiusDocs is not the right place to start. Contact the law firm, clinic, physician, or insurer that holds your records. They control those records and they decide how requests about them are handled. We will support our customer in responding, as required by the BAA, but we cannot act on those records on our own.
This policy should be read together with our Terms of Service, our SMS Terms, and our Security and HIPAA page.
2. Information we collect
2.1 Information you submit to us
When you request a demo or contact us through the website, we collect the information you enter in the form:
- Name
- Work email address
- Firm or practice name
- Role (for example attorney, paralegal or case manager, physician, chiropractor, IME physician, life care planner, or insurance adjuster)
- Approximate monthly case or record volume
- A short description of the problem you are trying to solve
- Optionally, a mobile phone number and your consent to receive text messages from us
Providing a mobile number and SMS consent is optional. It is never required in order to request a demo, start a trial, or buy the service. Message frequency varies, and message and data rates may apply. See our SMS Terms for the full terms, and see Section 9.3 below for how to opt out.
2.2 Account and billing data
When your organization creates an account at docs.radiusdocs.ai, we collect the information needed to operate it: user names, work email addresses, credentials in hashed form, role and permission settings, organization details, and records of activity within the account such as sign-ins, uploads, and documents generated. For paid plans we collect billing contact details and subscription records. Card payments are processed by our payment processor. We do not store full payment card numbers on our systems.
2.3 Records uploaded by customers
Customers upload medical records and related case documents so the platform can produce structured, citation-backed work product. This content, and the output generated from it, typically contains PHI about the customer's patients or clients. We process it only as a service provider to the customer, only on the customer's instructions, and only under the BAA described in Section 6. We do not use it to build marketing lists, we do not sell it, and we do not train AI models on it.
2.4 Information collected automatically
When you visit the marketing website, we and our providers collect standard technical data:
- Log data: IP address, date and time of the request, pages viewed, referring URL, and similar server log entries.
- Device and browser data: browser type and version, operating system, language, and screen or viewport characteristics.
- Cookies and similar technologies: small files and equivalent storage used to keep the site working, remember preferences, and measure how marketing performs.
- Meta Pixel: the marketing website loads the Meta Pixel, which reports page views and conversion events such as clicking a trial or demo call to action back to Meta for advertising measurement and audience building. Because Meta may use that data to build advertising audiences, California law treats this as sharing personal information for cross-context behavioral advertising. Section 9.6 explains how to opt out.
We do not use the Meta Pixel or any other advertising tag to collect protected health information, and we do not transmit protected health information to advertising platforms. The Meta Pixel and our other marketing tags are loaded by the marketing website at radiusdocs.ai. They are not part of the application at docs.radiusdocs.ai, and no advertising or analytics tag is present in that application's source code. [TO CONFIRM: that no advertising or analytics tag is injected into docs.radiusdocs.ai at the hosting or deployment layer, outside the application source code]
2.5 Information from other sources
We may receive limited business contact information from public sources, professional directories, event and webinar registrations, and referral partners, and we may combine it with what you have given us. We use this only for business-to-business outreach about RadiusDocs.
3. How we use information
We use the information described in Section 2 to:
- Respond to demo requests, questions, and support tickets
- Create, provision, and administer accounts, including trials
- Provide the service, which includes generating chronologies, demand letters, IME reports, life care plans, medical necessity letters, and medical summaries from records the customer uploads
- Bill customers, manage subscriptions, and collect payment
- Send service and administrative messages such as onboarding steps, security notices, changes to terms, and outage or maintenance notices
- Send marketing email, and text messages where you have consented, about features, pricing, and educational content
- Measure and improve marketing performance, including advertising measurement and audience building through the Meta Pixel
- Monitor, secure, and troubleshoot the platform, including detecting abuse, fraud, and unauthorized access
- Improve product quality and reliability using aggregated or de-identified operational metrics
- Comply with legal obligations and enforce our Terms of Service
We do not train AI models on customer data. Records uploaded by customers, and the work product generated from them, are not used to train, fine-tune, or otherwise improve any AI model, whether our own or a third party's. Our contracts with AI model providers prohibit those providers from training on data we send them. Customer content is processed to produce that customer's output, and for no other purpose.
We do not sell personal information. We do disclose limited website activity data to Meta through the Meta Pixel for advertising measurement and audience building, which California law treats as sharing for cross-context behavioral advertising. Section 9.4 describes what is shared, and Section 9.6 explains how to opt out.
4. Why we process personal information
RadiusDocs operates in the United States and our processing is governed primarily by United States federal and state law. Where a legal basis framework applies to you, the following describes why we process personal information:
| Purpose | Basis |
|---|---|
| Providing the service to a customer organization and billing for it | Performance of a contract with the customer, and our legitimate interest in operating the business |
| Responding to demo requests and sales inquiries | Steps taken at your request before entering a contract, and our legitimate interest in business-to-business outreach |
| Marketing email to business contacts | Legitimate interest, subject to an opt-out in every message, or consent where required |
| Text messages to a mobile number you provided | Your express consent, which you can withdraw at any time |
| Cookies, advertising measurement, and audience building | Consent where required, otherwise legitimate interest in measuring marketing, subject to the opt-out in Section 9.6 |
| Security monitoring, fraud prevention, and audit logging | Legitimate interest in protecting the platform, and legal obligation |
| Handling PHI on behalf of a customer | The signed BAA and the customer's written instructions, under HIPAA |
| Responding to lawful requests and preserving records | Legal obligation |
5. Disclosure to third parties and subprocessors
We do not sell personal information. We disclose it only in the situations below.
5.1 Service providers and subprocessors
We use vendors to run the platform. They may access personal information only to perform work for us, under written contracts that restrict their use of the data and require appropriate safeguards.
| Category | What they do | May access PHI |
|---|---|---|
| Cloud hosting and storage | Run the application, databases, and record storage | Yes, under a BAA |
| AI model providers | Process record text under contract to generate work product | Yes, under a BAA, with training on our data contractually prohibited |
| Error monitoring and infrastructure tooling | Detect faults and keep the service available | Possible incidental access, under a BAA |
| Email delivery | Send transactional and marketing email | No |
| SMS delivery | Send text messages to numbers that opted in | No |
| Website analytics and advertising | Measure marketing performance and build advertising audiences, including the Meta Pixel | No |
| Payment processing | Process card and invoice payments | No |
| Support and CRM tooling | Track sales conversations and support tickets | No, and customers are asked not to place PHI in support tickets |
Every subprocessor that can access PHI is bound by a Business Associate Agreement that flows down the HIPAA obligations we owe our customers. Subprocessors that never touch PHI, such as our marketing and advertising tools, are covered by ordinary data protection terms instead. A current list of subprocessors is available to customers and prospective customers on request at privacy@radiusdocs.ai. [TO CONFIRM: whether a public subprocessor list will be published and whether customers receive advance notice of new subprocessors]
5.2 Other disclosures
- Within a customer organization. Account administrators can see the users, activity, and documents in their own workspace.
- Legal and safety. We may disclose information when required by law, subpoena, court order, or other valid legal process, or to protect the rights, property, or safety of RadiusDocs, our customers, or the public. Where PHI is involved, we follow the notification and objection process set out in the BAA and HIPAA before responding, unless prohibited by law.
- Corporate transactions. If RadiusDocs is involved in a merger, acquisition, financing, or sale of assets, information may transfer to the successor. Any successor remains bound by this policy and by existing BAAs for PHI, and we will notify customers of a transfer that materially affects their data.
- With your direction. We disclose information to anyone else only when you or the customer instructs us to.
6. HIPAA and protected health information
6.1 Our role
When a customer uploads medical records, RadiusDocs acts as a HIPAA Business Associate to that customer. The customer is the Covered Entity, or a Business Associate acting for one. The customer decides what records are uploaded, what work product is generated, who inside its organization has access, and how long the records stay in the workspace. RadiusDocs does not decide those things and does not use PHI for its own purposes.
6.2 BAA on every contract
We offer a Business Associate Agreement on every contract, including trials. A signed BAA must be in place before any records containing PHI are uploaded. If you do not have an executed BAA with us, do not upload PHI. To request one, contact legal@radiusdocs.ai. The BAA governs permitted uses and disclosures of PHI, safeguards, subcontractor flow-down, individual rights support, breach notification, and return or destruction of PHI at termination.
6.3 Minimum necessary
We limit access to PHI to the minimum necessary for the purpose. Access inside RadiusDocs is role-based, restricted to personnel with an operational need, logged, and reviewed. Customers control what they upload, and we encourage customers to upload only the records actually needed for the work product they are requesting.
6.4 Individual rights requests
HIPAA rights of access, amendment, accounting of disclosures, and restriction run against the Covered Entity, not against RadiusDocs. If an individual contacts us directly about records inside a customer workspace, we will refer that individual to the customer and, where the BAA requires it, assist the customer in responding.
6.5 Breach notification
If we discover a breach of unsecured PHI, we will notify the affected customer without unreasonable delay and within the timeframe set out in the applicable BAA and the HIPAA Breach Notification Rule. Our notice will describe what happened, the PHI involved to the extent known, the individuals affected to the extent known, what we are doing in response, and what the customer may need to do. The customer, as Covered Entity, remains responsible for notifying individuals, the Department of Health and Human Services, and any others required by law. For security incidents that do not involve PHI, we notify affected customers as required by applicable state law.
7. Data retention and deletion
We keep information only as long as we need it for the purpose it was collected, or as long as the law requires.
| Data | Retention |
|---|---|
| Records uploaded by a customer, and work product generated from them | Kept while the account is active and the customer chooses to keep them. Deletable by the customer at any time. On termination, returned or destroyed per the BAA. [TO CONFIRM: standard post-termination deletion window stated in the BAA] |
| Trial account data | Deleted after the trial ends if the account is not converted to a paid plan. [TO CONFIRM: number of days trial data is retained after trial expiry] |
| Account and user records | Kept for the life of the account, then deleted or de-identified. [TO CONFIRM: retention period for account records after termination] |
| Billing and tax records | Kept as required by tax and accounting law, typically seven years |
| Demo and sales inquiries | Kept while the contact remains commercially relevant, then deleted on request or on a periodic cleanup |
| Marketing and SMS consent records | Kept for as long as needed to prove consent and to honor opt-outs, including after you unsubscribe |
| Security, audit, and access logs | Kept for a defined period to support investigation and compliance. [TO CONFIRM: audit log retention period] |
7.1 Customer-initiated deletion
Customers can delete individual records, generated documents, or an entire matter from within the application. Deletion removes the content from the active service. Encrypted backups roll off on their normal cycle, after which the deleted content is no longer recoverable. Customers can also request full account deletion by writing to support@radiusdocs.ai.
7.2 Opt-out records
If you unsubscribe from marketing or opt out of text messages, we retain the minimum information needed to keep honoring that choice. Deleting that record would cause us to contact you again by mistake.
8. Security
Our security posture is described in more detail on our Security and HIPAA page. In summary:
- HIPAA compliant. We operate the platform to meet the HIPAA Security Rule and the Privacy Rule obligations that apply to a Business Associate.
- BAA on every contract. A Business Associate Agreement is available to every customer.
- Encryption. Records are encrypted in transit and at rest.
- Access controls. Access is role-based and limited to personnel with an operational need. Administrative access requires authentication controls and is logged.
- No AI training on customer data. We never train AI models on customer data, and our AI model providers are contractually prohibited from doing so.
- Tenant separation. Each customer workspace is logically separated so one customer's records are not visible to another.
- Monitoring and response. We log access, monitor for suspicious activity, and maintain an incident response process that includes the notification duties in Section 6.5.
No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed. Customers also carry part of the load: choose strong credentials, remove users promptly when they leave, and do not send PHI to us through email or support tickets. Use the application for that.
9. Your rights and choices
9.1 Access, correction, and deletion
You can ask us to confirm what personal information we hold about you, to correct it if it is wrong, or to delete it. Write to privacy@radiusdocs.ai. We will verify your identity before acting, and we will respond within the time allowed by applicable law. We may decline a request where the law permits, for example where retention is legally required. If we decline, you can appeal under Section 9.7.
These rights cover website and business contact data. For records inside a customer workspace, direct the request to the customer that controls those records. See Section 1.1 and Section 6.4.
9.2 Marketing email
Every marketing email includes an unsubscribe link. You can also write to privacy@radiusdocs.ai. Unsubscribing stops marketing messages. It does not stop service and administrative messages about an active account, such as billing notices and security alerts.
9.3 Text messages
If you consented to text messages, reply STOP to any message to opt out, and reply HELP for help. Consent to receive texts is never a condition of buying anything from us. Full details are in our SMS Terms.
9.4 California residents
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the right to know what personal information we collect, use, and disclose, the right to correct inaccurate personal information, the right to delete personal information, the right to opt out of the sale or sharing of personal information, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights.
RadiusDocs does not sell personal information, and has not sold personal information in the preceding twelve months. We do share personal information for cross-context behavioral advertising. The Meta Pixel described in Section 2.4 discloses website activity data to Meta, including online identifiers, device and browser data, IP address, and the pages viewed and conversion events recorded during your visit, and Meta may use that data to build advertising audiences. Under the CCPA and CPRA that disclosure is sharing. Section 9.6 explains how to opt out. We do not knowingly sell or share the personal information of anyone under 16.
Categories of personal information we collect are listed in Section 2, the purposes are listed in Section 3, and the categories of recipients are listed in Section 5. Medical information that is subject to HIPAA is exempt from the CCPA, so PHI handled under a BAA is governed by HIPAA and the BAA rather than by the CCPA.
Sensitive personal information. The only category of sensitive personal information we collect is account log-in credentials, which we store in hashed form as described in Section 2.2. We use them for one purpose: to authenticate users and secure accounts. That purpose is exempt from the right to limit under California Civil Code section 1798.121(d), so there is nothing for a limitation request to restrict. We do not sell or share sensitive personal information, we do not use it to infer characteristics about you, and we retain it for the period stated for account and user records in Section 7. Health information subject to HIPAA is carved out of the CCPA entirely, as described in the paragraph above.
To exercise a right, write to privacy@radiusdocs.ai. You may use an authorized agent, in which case we will ask for proof of authorization. We will not deny you service, charge a different price, or provide a lower quality of service because you exercised a right. Residents of other states with comprehensive privacy laws have similar rights, and we handle those requests through the same address.
9.5 Cookies and tracking choices
Most browsers let you block or delete cookies. Blocking cookies may break parts of the website. You can also limit interest-based advertising through your Meta ad preferences and through industry opt-out pages operated by the Digital Advertising Alliance and the Network Advertising Initiative. Advertising and measurement tags are loaded by our public marketing pages at radiusdocs.ai. We do not place advertising or measurement tags on the pages of the application where customer records are viewed or processed. See Section 2.4.
9.6 Do not sell or share my personal information
You can opt out of the sharing described in Section 9.4 at any time, whether or not you are a California resident. The fastest way is our Do Not Sell or Share My Personal Information page, which is linked in the footer of every page on this website. The control there takes effect immediately and stops the advertising pixel from loading in that browser.
To make the request across all of your browsers and devices, or to have us remove you from advertising audiences that were already built, write to privacy@radiusdocs.ai with "Do Not Sell or Share" in the subject line. You do not need an account, we do not charge for this, and we will not treat you differently for asking. An authorized agent may submit the request on your behalf, and we may ask for proof of that authorization.
We also detect and honor the Global Privacy Control signal. If your browser or a browser extension sends GPC, we treat it as a valid opt-out request and the advertising pixel does not load, so you do not need to take any further action.
You can also reduce this sharing yourself. Block or delete cookies in your browser, adjust your Meta ad preferences, and use the industry opt-out pages named in Section 9.5.
9.7 Appealing a decision
If we decline a rights request under Section 9.1, we will tell you why. You may appeal that decision within a reasonable period after you receive our response. Write to privacy@radiusdocs.ai with "Appeal" in the subject line, and include your original request and anything that supports it.
We will respond to an appeal in writing within 45 days of receiving it, or within 60 days for residents of Virginia, and we will explain the reasoning behind our decision. If we deny the appeal, we will tell you how to contact your state attorney general to submit a complaint. This process is available to residents of California, Virginia, Colorado, Connecticut, Texas, Oregon, and Montana, and to residents of any other state whose comprehensive privacy law provides an appeal right.
10. Children's privacy
RadiusDocs is a business service sold to organizations. It is not directed to children, and we do not knowingly collect personal information directly from anyone under 18 through our website or account signup. If we learn that we have collected such information through the website, we will delete it. This section is about direct collection from website visitors and users. It does not limit a customer's ability to upload medical records that relate to a minor patient or claimant. That content is PHI, and it is governed by the BAA and by the customer's own legal obligations.
11. International users and United States processing
RadiusDocs is based in the United States, and we store and process information on infrastructure located in the United States. [TO CONFIRM: hosting regions used, and whether any subprocessor processes data outside the United States] If you access the website or the service from outside the United States, you are sending your information to the United States, where privacy laws differ from those in your country. The service is intended for United States customers handling United States medical records, and we do not market it elsewhere. Customers subject to non-United States privacy law are responsible for confirming that using RadiusDocs is lawful for them.
12. Changes to this policy
We may update this policy as the product, our vendors, or the law changes. When we do, we will revise the date at the top of the page. If a change materially affects how we handle personal information, we will give notice through the website, by email to account contacts, or both, before the change takes effect. Material changes to how PHI is handled are made through the BAA process, not through an update to this page. Continuing to use the website or the service after an update means you accept the revised policy.
13. How to contact us
For privacy questions, rights requests, or a copy of our subprocessor list:
- Privacy: privacy@radiusdocs.ai
- Legal, including BAA requests: legal@radiusdocs.ai
- Product support and account deletion: support@radiusdocs.ai
- Mailing address: [TO CONFIRM: legal entity name and mailing address]
See also our Terms of Service, our SMS Terms, and our Security and HIPAA page. If you believe we have handled your information improperly, contact us first at privacy@radiusdocs.ai. You also have the right to complain to your state attorney general, and for health information, to the Office for Civil Rights at the United States Department of Health and Human Services.
Draft for review. This policy contains bracketed items that require confirmation by RadiusDocs before publication, and it should be reviewed by counsel alongside the current BAA template and subprocessor list.