Sandy Health
Platform
Intelligent VerificationAmbient Scribe and AI ChatRevenue IntelligenceAgentic Scheduling & IntakeAdaptive Prior Authorizations
Who it's for
For practicesFor physicians
Resources
ROI calculatorTestimonialsInfrastructureQ&ATrust Center
Company
AboutCareersSecurityContact
Sign inBook a demo
PlatformFor practicesFor physiciansTestimonialsTrust CenterCareersSecurityContactSign inBook a demo

Privacy Policy

Last Updated: July 17, 2026

Welcome to Sandy Health. Your privacy is important to us. This Privacy Policy (this “Privacy Policy”) explains how Sandy AI, Inc., d/b/a Sandy Health (“Sandy Health,” “we,” “our,” or “us”) collects, uses, discloses, and otherwise processes (collectively, “process”) personal information in connection with our websites, including https://sandyhealth.com and its subdomains (the “Websites”), and our hosted platform and related products and services (the “Platform”, and together with the Websites, the “Products”).

Please read this Privacy Policy carefully. By accessing or using the Products, you acknowledge that you have read and understand this Privacy Policy. If you do not agree, please do not access or use the Products.

IMPORTANT NOTICE FOR PATIENTS AND PROTECTED HEALTH INFORMATION (PHI). Sandy Health provides its Platform to health care providers, health plans, and other covered entities and business associates under HIPAA (our “Customers”). When we process protected health information (“PHI”), including audio recordings and transcripts created through the Platform, we do so as a business associate on our Customers’ behalf, governed by the Health Insurance Portability and Accountability Act (“HIPAA”) and our Business Associate Agreement (“BAA”) with the applicable Customer, and not by this Privacy Policy. If you are a patient and have questions about your PHI, please contact your health care provider, who is responsible for that information. This Privacy Policy governs the personal information that Sandy Health itself controls, as described in Section 1.

SUMMARY OF KEY POINTS

What this Policy covers. This Privacy Policy covers personal information that Sandy Health processes as a controller, such as information about visitors to our Websites and the administrators and authorized users of our Customers. It does not cover PHI that we process as a business associate on behalf of our Customers, which is governed by HIPAA and the applicable BAA.

What personal information do we process? Depending on how you interact with us, we may process contact and account information, communications, device and usage data, and information collected through cookies and similar technologies.

Do we process sensitive personal information? As a controller, we do not knowingly process sensitive personal information for purposes that require an opt-in or “limit” right beyond providing the Products. PHI is handled under HIPAA and the BAA, not this Policy.

Do we sell or “share” personal information? We do not sell personal information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. We honor recognized opt-out preference signals, including the Global Privacy Control (GPC).

How do we share information? We share personal information with service providers and subprocessors that help us operate the Products, with our affiliates, in connection with a business transfer, and where required by law or with your consent.

What are your rights? Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to opt out of certain processing. See Sections 11 and 12.

How can you contact us? Email us at legal@sandyhealth.com or write to us at the address in Section 14.

1. SCOPE OF THIS POLICY; RELATIONSHIP TO HIPAA

Information we control (covered by this Privacy Policy).

This Privacy Policy applies to personal information that Sandy Health determines the purposes and means of processing, that is, information we process as a “controller” or “business.” This includes information about: visitors to and users of our Websites; prospective customers and the individuals who inquire about, evaluate, purchase, or administer the Products on behalf of a Customer; the administrators and authorized end users (“Users”) who access the Platform on behalf of a Customer (such as their names, business contact details, account credentials, and Platform usage and log data); and individuals who communicate with us, attend our events, or receive our marketing.

Information we process on behalf of our Customers (NOT covered by this Privacy Policy).

When our Customers use the Platform, we process information, including PHI, audio recordings, and transcripts, as a “business associate,” “processor,” or “service provider” on the Customer’s behalf and under the Customer’s instructions. That information is governed by HIPAA, the applicable BAA, and the Customer’s own privacy notices and policies, not by this Privacy Policy. Our Customers are responsible for providing any required notices to, and obtaining any required consents or authorizations from, the individuals whose information they submit to the Platform. If you are a patient or other individual whose information was provided to us by a Customer, please direct your privacy requests to that Customer (for example, your health care provider), and we will support the Customer in responding as required by HIPAA and the BAA.

2. WHAT INFORMATION DO WE COLLECT?

Personal information you provide to us.

We collect personal information that you voluntarily provide when you register for or use the Products, express interest in the Products, participate in activities through the Products, request support, or otherwise communicate with us. This may include:

  • name and job title;
  • business email address, telephone number, and mailing address;
  • username, password, and other account or authentication credentials;
  • contact and communication preferences;
  • the contents of messages, support requests, and feedback you send us; and
  • billing and transaction information (such as company name, tax identification number, and payment details) submitted in connection with an Order Form.

Information we collect automatically.

When you access or use the Products, we automatically collect certain information that does not necessarily reveal your specific identity but may be associated with you, including:

  • Log and usage data: service-related, diagnostic, and performance information our servers collect, such as IP address, dates and times of access, pages and features used, searches, and error or “crash” reports;
  • Device data: information about the computer, phone, tablet, or other device you use, such as device and application identifiers, browser type and settings, operating system, hardware model, and system configuration; and
  • Location data: approximate location derived from your IP address.

Like many businesses, we also collect information through cookies and similar technologies, as described in Section 5.

Information from other sources.

We may obtain information about you from third parties, such as public databases, marketing and event partners, joint-marketing partners, data providers, and social-media platforms, to help us provide and improve the Products and our marketing, and to keep our records current.

Sensitive personal information.

As a controller, we do not seek to collect or process “sensitive” personal information (such as government identifiers, financial account credentials, or health information) about Website visitors or Customer personnel, except where you provide it to us directly (for example, a tax identification number for billing). PHI and other sensitive information that our Customers submit to the Platform are handled under HIPAA and the BAA, as described in Section 1.

3. HOW DO WE USE YOUR INFORMATION?

We process the personal information we control for the following purposes:

  • to provide, operate, maintain, secure, and improve the Products;
  • to create and administer accounts and authenticate Users;
  • to provide customer support and respond to inquiries and requests;
  • to process orders, billing, and payments and to administer our contracts;
  • to communicate with you, including service and administrative messages and, where permitted, marketing;
  • to personalize and analyze use of the Products and conduct research and product development (using de-identified or aggregated data where practicable);
  • to detect, prevent, and respond to security incidents, fraud, and misuse, and to protect the rights, safety, and property of Sandy Health, our Customers, and others; and
  • to comply with legal obligations and to establish, exercise, or defend legal claims.

We may also process your information for other purposes with your consent or as otherwise permitted by applicable law.

4. WHEN AND WITH WHOM DO WE SHARE INFORMATION?

We may share the personal information we control in the following circumstances:

Service providers and subprocessors. We share personal information with vendors and service providers that perform services for us, such as cloud hosting and infrastructure, speech-to-text and transcription technology, payer-connectivity services, payment processing, analytics, communications, and security. These providers are permitted to process personal information only as needed to perform services for us and under contractual obligations to protect it. A current list or description of our subprocessors is available on request.

Affiliates. We may share information with our corporate affiliates, who are required to honor this Privacy Policy.

Business transfers. We may share or transfer information in connection with, or during negotiations of, a merger, financing, acquisition, reorganization, or sale of all or a portion of our business or assets.

Legal and safety. We may disclose information where required to comply with applicable law, regulation, legal process, or governmental request, to enforce our agreements, or to protect the rights, property, or safety of Sandy Health, our Customers, or others.

With your consent or at your direction. We may share information for other purposes with your consent or at your direction.

We do not sell personal information, and we do not “share” personal information for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. PHI is disclosed only as permitted by the applicable BAA and HIPAA.

5. COOKIES, TRACKING, AND OPT-OUT PREFERENCE SIGNALS

We and our service providers use cookies, web beacons, pixels, and similar technologies to operate and secure the Websites, remember your preferences, measure performance, and understand how the Websites are used. You can usually set your browser to remove or reject cookies; if you do, some features may not function properly.

Opt-out preference signals. We honor recognized universal opt-out mechanisms, including the Global Privacy Control (GPC). When we detect a GPC or similar opt-out preference signal from your browser or device, we treat it as a valid request to opt out of any “sale” or “sharing” of personal information for the browser or device from which it is sent, as required by applicable state law. Because no common standard for “Do-Not-Track” signals has been adopted, we do not separately respond to those signals.

6. AI AND AUTOMATED PROCESSING

The Platform includes artificial-intelligence and machine-learning features, including speech-to-text transcription provided through third-party technology, that our Customers use to process information on their own behalf. That processing is governed by HIPAA and the BAA, and the Customer, not Sandy Health, is responsible for decisions made using the Platform. With respect to the personal information that Sandy Health controls, we do not use automated processing to make decisions that produce legal or similarly significant effects about you without a lawful basis and, where required, appropriate human review. We may use de-identified and aggregated data to develop and improve our Products and underlying models, consistent with HIPAA’s de-identification standard (45 CFR § 164.514) and the BAA.

7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

We are based in, and our servers are located in, the United States. If you access the Products from outside the United States, your information may be transferred to, stored, and processed in the United States.

8. HOW LONG DO WE KEEP YOUR INFORMATION?

We keep the personal information we control only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). For account information, we generally retain it for the period during which the relevant account is active plus a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements. When we no longer need personal information, we delete or de-identify it or, if that is not feasible (for example, because it is stored in backup archives), we securely store and isolate it from further processing until deletion is possible. Retention of PHI is governed by the BAA and HIPAA.

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

We maintain administrative, technical, and physical safeguards designed to protect personal information against loss, misuse, and unauthorized access, disclosure, alteration, and destruction, including encryption of data in transit and at rest, access controls, and monitoring. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your account credentials and for accessing the Products in a secure environment.

10. DO WE COLLECT INFORMATION FROM MINORS?

The Products are intended for business use by health care organizations and their personnel and are not directed to children. We do not knowingly collect personal information from children under 18 as a controller. Where our Customers submit information about minors to the Platform in the course of providing health care, that information is PHI handled under HIPAA and the BAA, and the Customer is responsible for any required parental or guardian consent. If you believe we have inadvertently collected information from a child as a controller, please contact us at legal@sandyhealth.com and we will take appropriate steps to delete it.

11. YOUR PRIVACY RIGHTS

Depending on where you are located, you may have rights regarding the personal information we control, including the rights to access, correct, delete, or receive a portable copy of your information, to object to or restrict certain processing, and to withdraw consent. You may also opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us; we may still send you service-related messages. To exercise your rights, contact us at legal@sandyhealth.com. We will respond consistent with applicable law and may need to verify your identity before acting on your request. For PHI, please contact the relevant Customer, as described in Section 1.

12. U.S. STATE PRIVACY RIGHTS

Several U.S. states, including California, Virginia, Colorado, Connecticut, and Utah, and other states that have enacted comprehensive consumer privacy laws (such as Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, and Rhode Island), give their residents rights regarding personal information that a business controls. Subject to certain exceptions and to verification, residents of these states may have the right to:

  • confirm whether we process their personal information and access that information;
  • obtain a portable copy of certain personal information;
  • correct inaccurate personal information;
  • delete personal information;
  • opt out of the “sale” or “sharing” of personal information and of targeted advertising;
  • limit the use and disclosure of sensitive personal information;
  • opt out of certain profiling that produces legal or similarly significant effects; and
  • not be subject to discrimination for exercising these rights.

We do not sell personal information and do not share it for cross-context behavioral advertising or targeted advertising, and we honor the Global Privacy Control (GPC) and other recognized opt-out preference signals. Much of the information we process is exempt from these laws (for example, PHI and information processed under HIPAA and the BAA), and the rights above do not apply to that information.

Categories of personal information.

The following table summarizes the categories of personal information (as described under California law) that we may process as a controller, whether we collect each category, and whether we disclose it to service providers for a business purpose. We do not sell or “share” any category.

Category

Collected?

Disclosed to service providers?

Identifiers (e.g., name, email, IP address, account ID)

Yes

Yes

Customer records / contact and billing information

Yes

Yes

Commercial information (e.g., products purchased or considered)

Yes

Yes

Internet/network activity (usage and log data)

Yes

Yes

Geolocation (approximate, from IP address)

Yes

Yes

Professional or employment information

Yes

Yes

Sensitive personal information (as a controller)

No (except as you provide)

No

Biometric information (as a controller)

No

No

How to exercise your rights; appeals; agents.

To exercise your rights, contact us at legal@sandyhealth.com or through any request mechanism we make available. We will verify your request using information we maintain about you and will respond within the time required by applicable law. You may use an authorized agent to submit a request, provided the agent gives proof of authorization. If we decline your request, you may appeal by replying to our response or contacting us at legal@sandyhealth.com; if your appeal is denied, you may contact your state attorney general. California’s “Shine the Light” law permits California residents to request information about disclosures to third parties for their direct-marketing purposes; we do not disclose personal information for third-party direct marketing.

13. UPDATES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. The updated version will be indicated by a revised “Last Updated” date and will be effective when accessible. If we make material changes, we will provide notice by posting a prominent notice on the Websites or by other appropriate means. We encourage you to review this Privacy Policy periodically.

14. HOW TO CONTACT US

If you have questions or requests regarding this Privacy Policy or our privacy practices, please contact us at:

Sandy AI, Inc., d/b/a Sandy Health

800 N. State Street, Suite 402, Dover, DE 19901

Email: legal@sandyhealth.com

Sandy Health
The financial layer for healthcare.
Platform
Intelligent VerificationAmbient Scribe and AI ChatRevenue IntelligenceAgentic Scheduling & IntakeAdaptive Prior Authorizations
Company
AboutSecurityCareersContact
Resources
For practicesFor physiciansROI calculatorTestimonialsInfrastructureQ&ATrust Center
© 2026 Sandy Health
Privacy PolicyTerms of Service
548 Market St, PMB 403715, San Francisco, California 94104