← Back

Privacy Policy

Last updated: June 30, 2026

1. Scope & Company Information

This Privacy Policy describes how Sycana Health AI LLC ("Company," "we," "us," or "our") collects, uses, stores, shares, and protects information when you use the CredVault credential tracking and compliance management platform (the "Service").

This policy applies to all users of the Service, including practice owners, administrators, credentialing coordinators, providers, and any other authorized users. If you have questions, contact us at privacy@sycana.com.

2. Information We Collect

Account Information:

When you register, we collect your name, email address, organization name, and a hashed password. We do not store passwords in plaintext.

Provider Credential Data:

You may enter or upload provider information including names, license numbers, DEA registration numbers, NPI numbers, CAQH profile identifiers, board certification details, malpractice insurance information, credentialing documents, and expiration dates. The Service is intended for provider credential metadata — not patient health records, clinical notes, treatment data, or patient PHI.

Sensitive Provider Identifiers:

Certain sensitive fields (such as Social Security numbers and dates of birth) are protected by role-based access controls and logged to an append-only audit trail. You should only enter these fields when operationally necessary.

Payment Information:

Subscription payments are processed by Stripe. We do not collect or store full credit card numbers. Stripe may share with us limited information such as the last four digits of your card, card brand, expiration date, and billing address.

Usage & Technical Data:

We collect usage data such as pages visited, features used, login timestamps, IP addresses, browser type, and device information. This data helps us operate, improve, and secure the Service.

Communications:

If you contact us via email, we retain records of those communications. We may also record support interactions for quality assurance purposes.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service;
  • Send transactional emails (email verification, password reset, credential expiration reminders, weekly summaries);
  • Send SMS notifications for credential reminders (if you opt in);
  • Process subscription payments and manage billing;
  • Respond to support requests and inquiries;
  • Detect, investigate, and prevent security incidents, fraud, or abuse;
  • Comply with legal obligations;
  • Generate aggregated, anonymized analytics to improve the Service.

We do not use your data for advertising, sell your data to third parties, or use your credential data to train AI models without your explicit consent.

4. Legal Basis for Processing (GDPR)

For individuals in the European Economic Area (EEA) or United Kingdom, our legal bases for processing your information are:

  • Contractual Necessity: Processing is necessary to perform our agreement with you (e.g., creating your account, providing the Service, processing payments).
  • Legitimate Interests: Processing for security, fraud prevention, and Service improvement is based on our legitimate interests, which are not overridden by your privacy rights.
  • Consent: Where required by law, we rely on your consent (e.g., for certain optional communications). You may withdraw consent at any time.
  • Legal Obligation: Processing may be necessary to comply with applicable laws.

5. Data Sharing & Subprocessors

We do not sell your personal information. We share data only with trusted subprocessors necessary to operate the Service. Each is bound by contractual data processing agreements consistent with this Privacy Policy:

SubprocessorPurposeData Location
AWS EC2 / S3Cloud hosting, compute, file storageUnited States
ResendTransactional email deliveryUnited States
TwilioSMS notification deliveryUnited States
StripePayment processing & billingUnited States
AI Document ParsingData extraction from uploaded credential documentsUnited States

We may also disclose information if required by law, legal process, or governmental request, or to protect the rights, property, or safety of the Company, our users, or others.

6. HIPAA & Protected Health Information

CredVault is designed for provider credential metadata — not patient health records. We take the following approach to HIPAA:

  • The Service is not intended for patient health records, clinical notes, treatment data, or patient PHI as defined by HIPAA;
  • You may not upload or transmit patient PHI unless a fully executed Business Associate Agreement (BAA) is in place between your organization and Sycana Health AI LLC;
  • If you are a covered entity or business associate requiring a BAA, email hello@sycana.com to initiate the process;
  • Credential provider data (license numbers, NPI, DEA, CAQH) stored in the Service is generally not considered PHI but remains encrypted and access-controlled;
  • All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Sensitive provider identifiers are additionally protected by role-based access controls and audit logging;
  • Access to all data is logged to an append-only audit trail.

7. Data Security

We implement administrative, physical, and technical safeguards to protect your data:

  • Encryption in transit: All communications are protected by TLS 1.2+ with strong cipher suites;
  • Encryption at rest: Data is encrypted using AES-256 on AWS infrastructure;
  • Access controls: JWT-based authentication with per-user token versioning, role-based access (member, owner, admin);
  • Audit logging: All credential changes, provider modifications, and administrative actions are logged;
  • Infrastructure: Hosted on AWS EC2 in isolated containers with health checks and automated restarts;
  • Password security: Passwords are hashed using bcrypt and never stored in plaintext.

While we take these measures seriously, no security measure is perfect. We cannot guarantee absolute security.

8. Data Retention & Deletion

We retain your information for as long as your account is active or as needed to provide the Service. Specifically:

  • Active accounts: Data is retained for the duration of your subscription;
  • Deleted accounts: Upon account deletion, Your Data is scheduled for purging within 30 days, except where retention is required by law (e.g., billing records retained for tax purposes);
  • Backups: Encrypted backups are retained according to operational necessity and are securely destroyed thereafter;
  • Data export: You may request a full export of your data at any time before account deletion by emailing privacy@sycana.com.

9. Your Rights

For all users:

  • Access: You can view the data associated with your account from within the Service;
  • Correction: You can update most account and provider data directly through the Service. For corrections you cannot make yourself, email us;
  • Deletion: You may request account deletion from your settings or by emailing privacy@sycana.com;
  • Data portability: You may request a machine-readable export of your data;
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time.

California Privacy Rights (CCPA):

California residents have the right to know what personal information we collect, the right to request deletion, the right to opt out of sales (we do not sell data), and the right to non-discrimination for exercising these rights. To exercise your CCPA rights, email privacy@sycana.com. We will verify your identity before processing your request.

EEA / UK Rights (GDPR):

Individuals in the EEA or UK have additional rights to: request access to your data, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and the right to object to processing. To exercise these rights, email privacy@sycana.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

Nevada Privacy Rights:

Nevada residents may submit a request to opt out of the sale of personal information. We do not sell personal information.

10. Cookies & Tracking

We use browser local storage to maintain your session (JWT token). We do not use third-party tracking cookies, advertising cookies, or analytics cookies. The Service does not respond to Do Not Track (DNT) signals because our current practices do not involve the type of tracking that DNT is designed to limit.

11. International Data Transfers & Children's Privacy

International Transfers: Your data is stored on AWS servers in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. We rely on appropriate safeguards (Standard Contractual Clauses where applicable) to ensure your data receives adequate protection.

Children's Privacy: The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will take steps to delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Material changes will be communicated via email to the address associated with your account. We encourage you to review this policy periodically.

13. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our data practices:

We will acknowledge receipt of privacy-related inquiries within 5 business days and respond substantively within 30 days.