Our Privacy Policy

Last modified: May 27, 2024

The main points first — in plain english

  • The policy below explains how Granville Labs Inc. ("GLI") collects and uses personal information through our website and electronic communications. 

  • We provide a web-based solution for clinicians to research patient medical histories. We deal with health information and take this responsibility very seriously. We are subject to federal and state laws and the practices of the clinics we work with. 

  • Our services are not substitutes for professional medical advice, diagnosis, or treatment. Providers use our services as guides but retain ultimate responsibility for medical decisions.

  • We use health information to improve medical care, avoid medication errors, support care coordination, and reduce duplicate testing.

  • We collect personal information directly from users and through automated technologies. This includes identifiers like name, address, email, and health information, as well as internet usage data.

  • We use cookies and analytics tools to collect usage data. Users can manage cookie settings through their browsers, but disabling cookies may affect functionality.

  • We use personal information to respond to requests, provide and improve services, verify identity, prevent fraud, for marketing, and to comply with legal obligations. 

  • We may share personal information with third-party service providers, while protecting their rights and complying with legal requirements. 

  • This summary is not a substitute for the full privacy notice below. In case of any discrepancy, the policy below takes precedence.

    ______________________________________________________________________________

1. Introduction.

This Privacy Policy describes how Granville Labs Inc., a Delaware corporation  (“GLI,” “we,” “our,” or “us”) collects and uses Personal Information about you through the use of our websites at www.granvillelabs.ai and www.granvillelabs.com  (the “Sites”) and through email, text, and other electronic communications between you and GLI. GLI respects your privacy, and we are committed to protecting it through our compliance with this Privacy Policy. 

This Privacy Policy (our “Privacy Policy”) describes the types of information we may collect from you or that you may provide when you visit our Sites and/or and use our services available through the Sites (the “Services”). It also describes our practices for collecting, using, maintaining, protecting, and disclosing that information. This policy applies to information we collect on our Sites and Services; in emails, phone conversations and other electronic messages between you and our Sites and Services; and when you interact with our advertising and applications on third party websites and services, if those applications or advertising include links to this policy.

It does not apply to information collected by us offline or through any other means, including on any other website operated by us or any third party including through any application or content (including advertising) that may link to or be accessible from or on the Sites or Services.

GLI does not provide any medical or clinical services directly to patients. We help clinicians focus on practicing medicine. We provide a web based solution that allows physicians to research the medical histories of complex patients.  Licensed professionals (“Providers”) use the Sites and our Services in their provision of health care services to you. Both GLI and the Providers may use and disclose your personal information collected through the Sites and Services, but how each use and disclose that information depends on whether it is health information or another type of personal information.

We believe that your health information should have heightened privacy protections, which are also required by certain federal and state privacy laws. We treat all health information that you provide when interacting with your Provider as personal health information.  All collection, use, and disclosure of your health information by Providers is governed by their Notice of Privacy Practices. Please review your Provider’s Notice of Privacy Practices for more information on how they protect your health information and your rights under applicable laws.

Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, you should elect not to use our sites and services. By accessing or using our sites, you agree to this privacy policy and our terms of use. This privacy policy may change from time to time. Your continued use of our sites or services after we make changes is deemed to be acceptance of those changes, so please check this privacy policy periodically for updates.


2DISCLAIMER. 

The sites and the services are not intended to be a substitute, nor a replacement, for professional medical advice, diagnosis, or treatment, and any content made available through the services is not intended to be, and should not be relied upon or construed as, the practice of professional healthcare or medical advice or the provision of medical care.

The services should not be used as the sole basis for any medical decisions or diagnosis. Providers are responsible for disclosing the use of generative artificial intelligence in the course of any medical decisions or diagnosis. Providers can use the services as a guide, but the ultimate responsibility for diagnosis and treatment lies with providers. GLI is not responsible for any omissions or inaccuracies in the services or for any decisions made based on the services. The services do not constitute professional healthcare advice, diagnosis, treatment, suggestions, or recommendations. 

Under no circumstances will GLI be liable for any loss or damage caused by your reliance on information obtained through the sites. It is your responsibility to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content available through the sites. Please seek the advice of medical professionals, as appropriate, regarding the evaluation of any specific information, opinion, advice or other content. Never disregard professional advice, including medical advice, or delay in seeking it, because of something you have read on this site. If you are experiencing a true medical emergency you should dial 911.

3. Children Under the Age of 18. Our Sites and Services are not targeted to or intended for children under the age of 18 without parental consent.  Providers may treat children under the age of 18 but they do so only with the consent of their parent or legal guardian.   If you learn that we have collected personal information from someone under the age of 13 that was not provided with the supervision and consent of the minor’s parents or legal guardian, contact us directly. If you believe we have impermissibly collected personal information from someone under the age of 13, please contact us using the information below.

4. Information We Collect About You and How We Collect It. We collect different types of information about you, including information that may directly identify you, information that is about you but individually does not personally identify you, and information that we combine with our other users. This includes information that we collect directly from you or through automated collection technologies.

We collect several types of information that on its own, or in combination with other information, could reasonably identify users of our Sites and Services (collectively, “Personal Information”), and specifically information by which you may be personally identified. 

  • We may obtain information directly from you.  This includes details such as name, address, e-mail address, home, work, and mobile telephone numbers, date of birth, credit or debit card number (for payment purposes only), medical history, health insurance subscriber information, and health information. Please note that you do not need to register for an account simply to view the Sites.  Use of the Services requires establishment of an account. 

  • We may collect information about you automatically when you navigate through the Sites or the Services.  This includes information about your Internet connection, the equipment you use to access our Sites or Services and usage details, such as network traffic data, logs, referring/exit pages, date and time of your visit to our Sites or Services, error information, click stream data, and other communication data and the resources that you access and use on the Sites or Services. 

  • The Services may include functionality that allows certain kinds of interactions between the Sites and your account on a third-party website or application, such as a social media network. The use of this functionality may involve the third-party site providing information to us. For example, we may provide links on the Sites to facilitate sending a communication from the Sites. These third parties may retain any information used or provided in any such communications or activities and these third parties’ practices are not subject to our Privacy Policy. We may not control or have access to your communications through these third parties. Further, when you use third-party sites or services, you are using their services and not our services and they, not we, are responsible for their practices. You should read the applicable third-party privacy policies before using such third-party tools on our Sites.  


‍5. Cookies and other Tracking Technologies.

We may use various methods and technologies to store or collect Usage Information (“Tracking Technologies”). Tracking Technologies may set, change, alter or modify settings or configurations on your computer or mobile phone (“Device”). A few of the Tracking Technologies currently used on the Sites or which may be used in the future, include, but are not limited to, the following (as well as future-developed tracking technology or methods that are not listed here):

Cookies (or browser cookies). We and our service providers may use cookies, pixel tags, web beacons, and other technologies to receive and store certain types of information whenever you interact with our Sites and Services through your computer or mobile device. A “cookie” is a small piece of data sent from a website and stored on the user’s computer by the user’s web browser while the user is browsing. On your computer, you may refuse to accept browser cookies by activating the appropriate setting on your browser, and you may have similar capabilities on your mobile device in the preferences for your operating system or browser. However, if you select this setting you may be unable to access certain parts of our Sites or Services. Unless you have adjusted your browser or operating system setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Sites or Services.

Google Analytics. We use Google Analytics, a web analytics service provided by Google, Inc. (“Google”) to collect certain information relating to your use of the Sites or Services. Google Analytics uses cookies to help the Sites analyze how users use the site. You can find out more about how Google uses data when you visit our Sites by visiting “How Google uses data when you use our partners’ sites or apps”, (located at www.google.org/policies/privacy/partners/).We may also use Google Analytics Advertising Features or other advertising networks to provide you with interest-based advertising based on your online activity. For more information regarding Google Analytics please visit Google’s website, and pages that describe Google Analytics, such as www.google.org/analytics/learn/privacy.html.
 
6. How We Use Your Information.

 We may use your Personal Information for various purposes, including: 

  • Responding to requests for information, 

  • Providing, developing, customizing and improving your services, 

  • Fulfilling your requests for services, 

  • Verifying your identity and for fraud prevention,

  • Creating accounts,

  • Providing you with updates and information about services we provide, 

  • Creating user preferences regarding emails and other correspondence, 

  • Sending you marketing information about GLI and our affiliated entities,

  • Sending you email and text communications such as electronic newsletters about our Services which may be of interest to you,

  • Responding to correspondence from users, contacting users when necessary or requested and sending users information

  • Helping us address problems with and improve our Sites and our products and services, including testing and creating new products, features, and services,

  • Protecting the security and integrity of theSites , including understanding and resolving any technical and security issues reported on our Sites,

  • Resolving disputes,

  • Engaging in analysis, research, and reports regarding the use of our Sites and Services,

  • For internal business purposes and our legitimate interests. 

  • Complying with the law and protecting the safety, rights, property or security of GLI, the Services, and the general public, and

  • For purposes disclosed at the time you provide your information or as otherwise set forth in this Privacy Policy.

We may also use your information to contact you about goods and services that may be of interest to you, including through newsletters. If you wish to opt-out of receiving such communications, you may do so at any time by contacting us at  privacy@granville.ai.

7.  Protected Health Information. 

Some information GLI collects constitutes protected health information (“PHI”) under the U.S. Health Insurance Portability and Accountability Act (“HIPAA”), referred to in this Privacy Policy as “health information”. Our handling of PHI strictly adheres to all relevant federal and state laws, including the Health Insurance Portability and Accountability Act (HIPAA), to ensure that patient information is protected against unauthorized access or disclosure.

GLI is a “business associate” (as that term is used under HIPAA) that provides services to and for Providers, other health care providers and health care plans, referred to as “covered entities” under HIPAA, and enters into business associate agreements with these covered entities. GLI will use and disclose PHI only in accordance with the business associate agreements and HIPAA. 

Our use of PHI is dedicated to enhancing the quality and efficiency of medical care. Our ambition is to ensure that Providers have timely, secure and comprehensive access to information they need to make informed treatment decisions. Here are some examples of how we might use PHI, though these examples are not exhaustive:

  • Helping Screen for Appropriate Therapies: We assist healthcare providers in identifying suitable therapeutic options for patients, ensuring that treatments are tailored to individual health profiles. 

  • Avoiding Medication Errors: By providing access to comprehensive patient information, we help healthcare professionals avoid potential medication errors, enhancing patient safety.

  • Supporting the Coordination of Care: We facilitate the sharing of PHI among different health professionals to ensure seamless coordination of care, which is especially crucial for patients seeing multiple specialists.

  • Decreasing Duplicate Testing: We help reduce unnecessary duplicate testing by providing healthcare providers with access to the patient's existing medical records, thus saving time, reducing costs, and minimizing patient inconvenience.


8. Disclosure of Your Information.  We do not share, sell, or otherwise disclose your Personal Information for purposes other than those outlined in this Privacy Policy. We may disclose your Personal Information in the following circumstances:  

(a)  To Third Parties Providing Services to GLI. We may use third-party service providers to perform certain services on behalf of us or the Sites or Services, such as: (i) creating and updating Site functionality; (ii) billing or processing credit cards, and/or electronic or manual payments; (iii) assisting us in Site operations;(iv) hosting the Sites and improving performance of the Sites; (v) designing and/or operating the Sites’s features; (vi) tracking the Sites’s activities and analytics,; (vii) data enhancement; (viii) providing customer support such as technical support, (ix) enabling us and/or third parties to perform other administrative services, such as customer service, security, tech, operational support and email services; and  (x) other services designed to assist us in maximizing our business potential. 

Without limiting the foregoing, with your permission, we may share your Personal Information with those third-party service providers by whom you request to be contacted. These third-party service providers may use your Personal Information to offer you products and/or services, and for any other lawful purposes, subject to any restrictions contained herein. The information that you supply directly to any third-party service provider shall be governed by the applicable third-party service provider's privacy policy. 

We may provide these vendors with access to user information to carry out the services they are performing for you or for us. Those vendors may have additional or different privacy policies and/or privacy notices. You should be sure that you read and agree to those policies and Terms.   

(b) To Protect the Rights of GLI and Others. To the fullest extent permitted by applicable law, we may also disclose your information when required to by law or if we believe in good faith that doing so is necessary or appropriate to: (i) protect or defend the rights, safety or property of GLI, its affiliates, third parties or the general public; or (ii) to respond to claims that any content violates the rights of a third party. This includes exchanging information with other companies and organizations for fraud prevention, spam/malware protection, and other similar purposes. To the fullest extent permitted by applicable law, we have complete discretion in electing to make or not make such disclosures, and to contest or not contest any requests for such disclosures, all without notice to you. 

(c)   Disclosure to Law Enforcement   We reserve the right to release current or past personal information: (i) in the event that we believe that the Services are being or have been used to commit unlawful acts; or (ii) if the information is subpoenaed  or requested pursuant to any court order or lawful request by public authorities, including to meet national security or law enforcement requirements; provided, however, that, where permitted by applicable law, we shall provide you with e-mail notice, and opportunity to challenge the subpoena/court order, prior to disclosure of any personal information pursuant to a subpoena.

(d)  In connection with a Business Transfer. We also reserve the right to disclose and transfer all information: (i) to a subsequent owner, co-owner or operator of the Sites and/or our Services; or (ii) in connection with a merger, consolidation, restructuring, the sale of substantially all of our interests and/or assets or other corporate change, including during any due diligence process; or (iii) if we are the subject of bankruptcy proceedings; provided, however, that if we are involved in a bankruptcy proceeding, merger, acquisition or sale of all or a portion of its assets, you will be notified via email and/or a prominent notice on the Sites of any change in ownership or uses of your personal information, as well as any choices that you may have regarding your personal information..  

(e)     To Affiliates of GLI.   We may provide information to affiliates and nonaffiliated third parties who perform services or functions for us in conjunction with our services to you, but only if we have a contractual agreement with the other party which prohibits them from disclosing or using the information other than for the purposes for which it was disclosed. 

(f)    On the Basis of Consent.   Where you provide consent, we share your information as described at the time of consent, such as when authorizing a third-party application or website to access your GLI account.

(g)  For Internal Business Processes and Promotion.     Where permissible under applicable law, we may use certain information about you, such as your email address, de-identify it, to generate leads, drive traffic to GLI, or otherwise promote our products and services.  


9. Choices About How We Use and Disclose Your Information.  We offer you choices on how you can opt out of our use of Tracking Technology, disclosure of your Personal Information for our advertising to you, and other targeted advertising. We do not control the collection and use of your information collected by third parties. We strive to provide you with choices regarding the Personal Information you provide to us. We have created mechanisms to provide you with control over your Personal Information:

Tracking Technologies and Advertising. You can set your browser or operating system to refuse all or some cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of our Sites or Services may then be inaccessible or not function properly.

Promotional Offers from GLI. If you do not wish to have your email address used by GLI to promote our own products and services, you can opt-out at any time by clicking the unsubscribe link at the bottom of any promotional emails or other marketing communications you receive from us. This opt out does not apply to information provided to GLI as a result of a purchase, or your use of our services. 

Administrative Correspondence.  Please also note that if you do opt-out of receiving marketing-related emails from us, we may still send you messages for administrative or other purposes directly relating to your use of the Services, and you cannot opt-out from receiving those messages.

‍10.   Use of AI by GLI and by Third Parties 

Our Services use artificial intelligence and machine learning tools (“AI”) in many ways.  We use AI to summarize and retrieve medical information from patient health care records. We also use it to build new features, improve the Sites and Services and provide new services to our Providers.     GLI strives always to use its AI in accordance with responsible AI principles. 

11.  Aggregated information.

We may aggregate, de-identify, and/or anonymize any information collected through the Sites or Services such that such information is no longer linked to your personally identifiable information. The AI tools generally use anonymized data and aggregated information, although in some situations, Personal Information, including PHI will also be accessed. This may include medical records, app usage behavior and questions asked by clinicians in order to improve our products and services.  We may use and share this aggregated and anonymized information (non-Personal Information) for any purpose, including without limitation, for research and marketing purposes, through the use of described below and may also share such data with our affiliates and third parties.  

12. Your Rights Regarding Your Information and Accessing and Correcting Your Information. 

You may choose to restrict the collection or use of your Personal Information In the following ways: 

Whenever you are asked to fill in a form on our website or our other Services, consider what information to include and exclude. We may provide you with access to your registration information and the ability to edit this information in your account settings dashboard and profile pages. Please be aware that even after you delete or update information within our Services, we may not immediately delete residual copies from our active servers and may not remove information from our backup systems.  Similarly, if and to the extent any information is indexable by search engines (including, without limitation, public profile information), it may not be updated by such search engines when we update it, and old versions may be archived by them or by third parties outside our control. Some of our Services may provide you with additional information and choices about your privacy, which you should review.

If you have previously agreed to our using your Personal Information for direct marketing purposes, you may change your mind at any time by writing to us using the contact information below.

We will try to comply with your request(s) as soon as reasonably practicable.

With respect to any PHI in our possession, you have certain rights under HIPAA as described in the Notice of Privacy Practices provided to you by your healthcare Provider.

13. Do Not Track Signals. We currently do not use automated data collection technologies to track you across websites. Some web browsers permit you to broadcast a signal to websites and online services indicating a preference that they “do not track” your online activities. We currently do not honor do-not-track signals that may be sent by some browsers. 

14. Data Security.  The transmission of information via the Internet is unfortunately not completely secure. Although we work diligently to try and protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted to our Sites or Services. Any transmission of Personal Information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Sites or Services.

‍15. Retention of Personal Information. We retain Personal Information that you provide to us where we have an ongoing legitimate business need to do so (for example, as long as is required in order to contact you about our Services, or as needed to comply with our legal obligations, resolve disputes and enforce our agreements).

We regularly review collected data and set data retention policies in order to delete data in accordance with contractual agreements, legal obligations and applicable data protection laws.

16.  California Privacy Rights.  California Civil Code Section 1798.83 (California’s “Shine the Light” law) permits users of our Sites or Services that are California residents and who provide Personal Information in obtaining products and services for personal, family, or household use to request certain information regarding our disclosure of Personal Information to third parties for their own direct marketing purposes. If applicable, this information would include the categories of Personal Information and the names and addresses of those businesses with which we shared your Personal Information with for the immediately prior calendar year (e.g. requests made in 2024 will receive information regarding such activities in 2023). You may request this information once per calendar year. To make such a request, please contact us by email at privacy@granville.ai or at (631) 490-4030. 

17.  International Data Transfers. Because GLI works with global companies and technologies, we may transfer your Personal Information outside of the country in which it was originally provided. This may include transfers to third parties, such as developers, service providers or affiliated entities who are location outside the United States, Canada or the European Union or the United Kingdom, where data protection laws may not offer the same level of protection as those in the U.S., E.U. or European Economic Area.  When we transfer personal data outside of these areas, we take steps to make sure that appropriate safeguards are in place to protect your Personal Information. 

17. Changes to Our Privacy Policy.  If you have questions or concerns with respect to our Privacy Policy, you may contact us at privacy@granville.ai. We may elect to change or amend our Privacy Policy; in such event, we will post the policy changes in our Privacy Policy on the Sites or at management’s discretion, send notice to our customers at their last known email address.  Changes will be effective on the date posted. If you are concerned about how your Personal Information is used, please visit our Sites often for this and other important announcements and updates. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Sites and reviewing this Privacy Policy to check for any changes.


18. Contact Information. 

If you have questions or would like additional information about our privacy practices, or if you believe your privacy rights have been violated, you may contact our Privacy Officer, Ankit Kumar via email at privacy@granville.ai or by calling (631) 490-4030 or at 1111B South Governors Avenue, Dover, DE 19904. 

Although we would hope that you would contact us first to try to resolve any issues, with respect to issues related to PHI, you may also file a complaint with the Secretary of Health and Human Services at 200 Independence Avenue, S.W. Washington, D.C. 20201, by calling 1-877-696-6775, or visiting https://www.hhs.gov/hipaa/filing-a-complaint/index.html. There will be no retaliation for filing a complaint.