1. Introduction
Tivara, Inc. ("the Company," "we," "us," or "our") operates tivarahq.com (the "Service"). Tivara builds AI voice agents that answer patient calls for healthcare clinics and specialty practices, handling appointment bookings, refill request logging, and EMR write-back for front-desk teams that cannot staff a phone line around the clock. This Privacy Policy explains what information we collect through the Service and through direct communications with you, how we use it, and the choices available to you.
We are based at 121 West Trade Street, Suite 2500, Charlotte, NC 28202, and can be reached at [email protected].
Because Tivara operates in the healthcare space, this policy addresses both general website data and the way our platform handles call-related information submitted by clinic operators. We do not operate as a covered entity under HIPAA with respect to general website visitors; however, clinics that deploy Tivara's voice agent service execute a Business Associate Agreement (BAA) that governs the handling of protected health information (PHI) separately from this policy.
2. Information We Collect
2.1 Information You Provide
We collect information you submit directly, including:
- Contact details (name, email, phone) when you fill out the early-access request form, request a pilot, or send us a message;
- Clinic or practice information you choose to share (clinic name, number of locations, EMR system in use, role);
- The content of any messages or questions you send us.
2.2 Information Collected Automatically
When you visit tivarahq.com, we automatically collect limited technical information:
- IP address and approximate location (city/region level);
- Browser type, operating system, device class;
- Pages visited, referring URLs, time on page;
- Cookie and similar identifiers (see Section 5).
2.3 Platform Call Data (Clinic Operator Context)
When clinic operators deploy the Tivara voice agent through an active service agreement, the platform processes voice audio and structured request data (appointment details, refill request text) as part of call handling and EMR write-back. This processing is governed by the BAA and applicable service agreement, not this website privacy policy. We do not use call audio or structured clinical request data to train AI models without the explicit written consent of the clinic operator.
2.4 We Do Not Knowingly Collect Children's Data
tivarahq.com is directed to healthcare clinic operators and practice managers, not to individuals under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
3. How We Use Information
We use the information we collect to:
- Respond to pilot inquiries and provide information about Tivara's voice agent service;
- Operate, maintain, and improve tivarahq.com;
- Communicate about service updates, early-access availability, and relevant product news;
- Understand how clinic operators and practice managers evaluate and engage with the site;
- Detect and prevent fraud or abuse;
- Comply with applicable legal obligations.
We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.
4. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf (hosting, email delivery, analytics) under contractual confidentiality terms;
- Authorities, when required by law or to protect rights, safety, or property;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal information to third parties.
5. Cookies and Tracking
We use cookies and similar technologies to operate the site, remember preferences, and measure usage. For details and choices, see our Cookie Policy.
6. Data Retention
We retain personal information only as long as needed for the purposes described, to comply with legal or accounting obligations, and to resolve disputes. Inactive marketing-list contacts are purged after 24 months. Server access logs are retained 90 days, then aggregated. Call-session data processed through the platform is retained per the terms of the applicable clinic BAA and service agreement.
7. Security
We apply administrative, technical, and physical safeguards to protect personal information, including TLS encryption in transit, restricted-access databases, and least-privilege access controls. Our platform is designed with HIPAA security controls in mind, including AES-256 encryption at rest and audit logging. No system is perfectly secure; we cannot guarantee absolute security.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.
9. North Carolina Residents
North Carolina does not currently have a comprehensive consumer privacy statute. As a matter of policy, we extend the following baseline rights to all U.S. residents regardless of state of residence.
9.1 Baseline Rights
- Right to Know: request the categories of personal information we have collected about you.
- Right to Delete: request deletion of personal information you have provided.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Marketing: unsubscribe from marketing emails or opt out via the link in each marketing message.
9.2 How to Exercise
Email [email protected] with a description of your request and enough detail for us to verify your identity. We respond within 45 days.
9.3 Sector-Specific Rights
If you are protected by federal sector laws (including HIPAA for health information, GLBA for financial data, or FERPA for educational records), those laws may give you additional rights with respect to data covered by them. For healthcare patients whose information may be processed through the Tivara platform by a clinic operator, rights requests should be directed to the clinic, which is the HIPAA covered entity; Tivara's role is as a Business Associate operating under the clinic's instructions.
9.4 California Visitors
If you are a California resident visiting from another state, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell personal information and do not "share" personal information for cross-context behavioral advertising.
To submit a CCPA / CPRA request, email [email protected] with the subject line "California Privacy Request."
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.
11. Contact
Questions, requests, or complaints can be sent to:
Tivara, Inc.121 West Trade Street, Suite 2500
Charlotte, NC 28202
Email: [email protected]
Phone: +1 (704) 358-0142