Legal

Privacy Policy

Adlight Technologies LLC — the Adlightech platform

Covering Carolina AI, AI Inbox, AI Worklist, and WaitingMed

Last Updated: September 2026

Previous version published May 2026.

This Privacy Policy covers Adlight Technologies LLC and its Adlightech platform, including WaitingMed and all associated products — Carolina AI, AI Inbox, and AI Worklist — as well as all related mobile applications and services accessible via adlightech.com, waitingmed.com, ai-inbox.app, or any other website, IP address, subdomain, or API endpoint designated by Adlightech from time to time (collectively, together with the Site, our "Service").

WaitingMed is a service of Adlight Technologies LLC. Both brands, and all domains listed above, are operated by the same legal entity.

This Privacy Policy ("Policy") describes the information that we gather on or through the Service, how we use and disclose such information, and the steps we take to protect such information. By visiting the Site, or by purchasing or using the Service, you accept the privacy practices described in this Policy.

This Policy is incorporated into, and is subject to, the Adlightech Terms & Conditions. Capitalized terms used but not defined in this Policy have the meaning given to them in the Adlightech Terms & Conditions.

Definitions

  • "Client" means a licensed customer of Adlightech.
  • "Client Data" means personal data, reports, addresses, and other files, folders, or documents in electronic form that a User of the Service stores within the Service.
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Public Area" means the area of the Site that can be accessed both by Users and Visitors, without needing to log in.
  • "Restricted Area" means the area of the Site that can be accessed only by Users, and where access requires logging in.
  • "User" means an employee, agent, or representative of a Client, who primarily uses the restricted areas of the Site for the purpose of accessing the Service in such capacity.
  • "Visitor" means an individual other than a User, who uses the public area, but has no access to the restricted areas of the Site or Service.

What personal information do we collect?

We collect different types of information from or through the Service. The legal bases for Adlightech's processing of Personal Data are primarily that the processing is necessary for providing the Service in accordance with our Terms of Service and that the processing is carried out in Adlightech's legitimate interests, further explained in "How do we use your information?" below. We may also process data upon your consent, asking for it as appropriate.

User-provided Information

When you use the Service, as a User or as a Visitor, you may provide, and we may collect, Personal Data. Examples of Personal Data include name, email address, mobile phone number, and credit card or other billing information. Personal Data also includes other information, such as geographic area or preferences, when linked to information that identifies a specific individual. You may provide us with Personal Data in various ways on the Service — for example, when you register for an Account, use the Service, post Client Data, interact with other users through communication or messaging capabilities (including Carolina AI voice interactions), or send us customer-service related requests.

Information Collected by Clients

A Client or User may store or upload into the Service Client Data, including data processed through AI Inbox (faxes, PDFs, emails, SMS, WhatsApp) and AI Worklist. Adlightech has no direct relationship with the individuals whose Personal Data it hosts as part of Client Data. Each Client is responsible for providing notice to its customers and third persons concerning the purpose for which the Client collects their Personal Data and how it is processed in or through the Service as part of Client Data.

Automatically Collected Information

When a User or Visitor uses the Service, we may automatically record certain information from the User's or Visitor's device using various technologies, including cookies, "pixels," or "web beacons." This may include IP address or other device address or ID, web browser and/or device type, pages visited before or after using the Service, content viewed or interacted with, and dates/times of access or use. We also may use these technologies to track interaction with email or SMS messages, such as whether a message is opened, clicked, or forwarded. This information is gathered from all Users and Visitors.

Voice and Call Data

Carolina AI, our bilingual AI voice agent, processes call audio and transcripts to answer, transfer, and log calls on behalf of Clients. Call recordings, transcripts, and related metadata are Client Data, processed solely per the Client's direction, and are subject to the same retention and disclosure limits described in this Policy.

WhatsApp Business Platform

AI Inbox supports patient and customer communication over the WhatsApp Business Platform, operated by Meta Platforms, Inc. ("Meta"). Where a Client enables this channel, we receive and process messages sent to and from the Client's WhatsApp Business account, including message content, the sender's telephone number and WhatsApp profile name, attachments, and delivery and read metadata.

All such data is Client Data. It is processed solely to deliver, route, classify, and log messages on behalf of the Client, in accordance with the Client's instructions, and is subject to the same retention limits, security safeguards, and disclosure restrictions described elsewhere in this Policy.

In connection with our use of the WhatsApp Business Platform, Adlightech complies with the Meta Platform Terms, the WhatsApp Business Messaging Policy, the WhatsApp Business Solution Terms, and Meta's Developer Data Use Policy. Specifically:

  • We use data obtained through the WhatsApp Business Platform only to provide and support the Service for the Client on whose behalf it was received.
  • We do not use this data for advertising or ad targeting, and we do not share it with advertising networks, data brokers, or information resellers.
  • We do not sell this data, and we do not use it to train or improve artificial intelligence or machine learning models.
  • We delete this data without undue delay when it is no longer needed to provide the Service, when a Client's account is closed, when a Client instructs us to delete it, or where deletion is required by law or by Meta.
  • We require our sub-processors to observe equivalent restrictions and to delete this data when they cease providing services to us.

Messages sent over WhatsApp are transmitted through Meta's infrastructure and are subject to Meta's own privacy practices, described in the WhatsApp Privacy Policy. Meta is not a business associate of Adlightech under HIPAA, and Meta does not act as a sub-processor of Adlightech. Our Client agreements limit the categories of information that may be exchanged over this channel and require the Client to obtain and document each individual's request or authorization to receive communications through it, after informing the individual that WhatsApp is an unsecured third-party messaging platform. Clients who are HIPAA-covered entities or business associates remain responsible for determining whether and how to use this channel in light of their own compliance obligations.

Individuals who wish to stop receiving WhatsApp messages from a Client may reply to opt out at any time, or may contact the Client directly.

Integrated Services

You may be given the option to access or register for the Service through the use of your username and password for certain third-party services (each, an "Integrated Service"), such as a Google account, or otherwise authorize an Integrated Service to provide Personal Data to us. By authorizing us to connect with an Integrated Service, you authorize us to access and store your name, email address(es), profile picture URL, and other information the Integrated Service makes available, and to use and disclose it per this Policy. Review each Integrated Service's own privacy policy before connecting it to our Service.

Information from Other Sources

We may obtain information, including Personal Data, from third parties and sources other than the Service, such as our partners and Integrated Services. If we combine information from other sources with Personal Data collected through the Service, we treat the combined information as Personal Data under this Policy.

How do we use your information?

Operations. We use information — other than Client Data — to operate, maintain, enhance, and provide features of the Service, respond to requests, and provide support. We process Client Data solely per the applicable Client's or User's directions.

Improvements. We use information to understand usage trends and preferences, improve the Service, and develop new products, services, and features.

Communications. We may use a Visitor's or User's email, phone number, or other information — other than Client Data — to contact them for (i) administrative purposes such as customer service, or addressing IP, privacy, or defamation issues related to content on the Service, or (ii) updates on promotions and events. You may opt out of promotional communications at any time.

Artificial intelligence and machine learning. We do not use identifiable Client Data or Protected Health Information to train, fine-tune, or otherwise improve artificial intelligence or machine learning models without the Client's express written consent. We may use de-identified and aggregated data derived from use of the Service to improve and enhance our models and algorithms, where such data has been de-identified in accordance with applicable data privacy laws and the HIPAA de-identification standard at 45 C.F.R. § 164.514. Our agreements with our AI sub-processors prohibit them from using Client Data to train their own models.

Analytics. We may use Google Analytics or similar tools to measure traffic on the Public Area of the Site. Google operates independently and has its own privacy policy. Data collected is used on a need-to-know basis to resolve technical issues, administer the Site, and identify visitor preferences, generally in non-identifiable form; we do not use this data to identify Visitors or Users.

Healthcare Data / HIPAA

Where a Client is a HIPAA-covered entity or business associate, Adlightech acts as a business associate (or subcontracted business associate) with respect to Protected Health Information ("PHI") processed through the Service, under a signed Business Associate Agreement ("BAA") with that Client. PHI processed through Carolina AI, AI Inbox, and AI Worklist is treated as Client Data under this Policy: it is processed solely per the Client's instructions, is not used or disclosed by Adlightech except as permitted by the BAA and applicable law, and is subject to administrative, physical, and technical safeguards consistent with the HIPAA Security Rule. Sub-processors who may handle PHI in the course of providing the Service are bound by equivalent BAA obligations where required.

We do not use or disclose PHI for marketing or fundraising purposes, and we do not sell PHI for any purpose.

To whom we disclose information?

Except as described in this Policy, we will not intentionally disclose Personal Data or Client Data to third parties without consent, except in these circumstances:

Unrestricted Information

Any information you voluntarily include in a Public Area of the Service is available to any Visitor or User with access to that content.

Service Providers and Sub-processors

We engage third-party service providers to help us operate and deliver the Service. We limit the information shared with each provider to what is reasonably necessary for the function they perform, and our agreements with them require confidentiality, appropriate security safeguards, and — where the provider may handle Protected Health Information — an executed Business Associate Agreement consistent with HIPAA.

We distinguish between two categories of provider.

Platform Sub-processors

These providers process Client Data, which may include Protected Health Information, in the course of delivering Carolina AI, AI Inbox, and AI Worklist. Each is bound by a Business Associate Agreement where required, and each processes Client Data solely on Adlightech's documented instructions on behalf of the Client.

Sub-processorFunctionCategories of data processed
Microsoft AzurePrimary cloud infrastructure and hosting; Azure Document Intelligence optical character recognition for AI InboxDocuments, faxes, images, structured patient data at rest and in transit
Amazon Web ServicesNeural voice synthesis and supporting compute infrastructureSynthesized voice output, call session data
TwilioInbound and outbound voice, SMS, and fax transportCall audio, message content, telephone numbers, call metadata
Anthropic (Claude API)Document classification, data extraction, and AI Worklist automationDocument and message content submitted for processing
OpenAIApplication programming interface language processingDocument and message content submitted for processing
ElevenLabsBilingual voice synthesis for Carolina AIText submitted for synthesis, synthesized voice output
DeepgramSpeech-to-text transcriptionCall audio, resulting transcripts
Twilio SendGridTransactional email and AI Worklist follow-up deliveryRecipient email addresses, message content

All Platform Sub-processors listed above process and store data within the United States.

Business Operations Vendors

These providers support our corporate operations, billing, and public website. They do not have access to Client Data and do not process Protected Health Information.

VendorFunctionCategories of data processed
CloverPayment gateway for Client subscription billingClient billing contact and payment card data (PCI-DSS scope)
Intuit QuickBooksInvoicing, accounts receivable, and payment processingClient billing contact and transaction data
HostingerWebsite hostingWebsite visitor server logs and technical data
LovableWebsite hosting and build platformWebsite visitor technical data, contact form submissions
Google (Analytics 4, Tag Manager)Website traffic measurementVisitor device, browser, and usage data
Microsoft 365Business email, document storage, and prospect schedulingBusiness contact and scheduling data

Changes to our sub-processor list

We maintain this list as current. Where our agreement with a Client requires advance notice of a new or replacement Platform Sub-processor, we will provide that notice in accordance with the terms of that agreement before the new provider begins processing Client Data.

What we do not do

We do not sell Personal Data or Client Data. We do not share Client Data with advertising networks, data brokers, or any third party for advertising or marketing purposes.

Client-Directed Integrations

Separately from our sub-processors, the Service can connect to third-party systems at a Client's direction — most commonly a Client's electronic health record, practice management, or scheduling system. Examples include eClinicalWorks, athenahealth, ModMed, WebPT, Practice Fusion, Open Dental, Eaglesoft, eMedicalPractice, MEDICUS EMR, and Aesthetic Record.

These systems are not our sub-processors. They do not act on Adlightech's behalf. When the Service transmits data to or retrieves data from such a system, it does so because the Client has instructed and configured it to do so. The Client's relationship with that vendor, and the vendor's handling of the data, are governed by the Client's own agreement with that vendor and are outside the scope of this Policy.

A Client may enable, disable, or reconfigure any integration at any time.

The WhatsApp Business Platform is likewise a channel enabled at a Client's election, and Meta does not act as a sub-processor of Adlightech. See "WhatsApp Business Platform" above.

Non-Personally Identifiable Information

We may make aggregated or otherwise non-personally-identifiable information available to third parties for (i) compliance with reporting obligations; or (ii) helping such parties understand Client, User, and Visitor interests, habits, and usage patterns. We do not make available to third parties any aggregated or de-identified information derived from Client Data or Protected Health Information for advertising or marketing purposes.

Law Enforcement, Legal Process and Compliance

We may disclose Personal Data or other information if required by law, or in good-faith belief it's necessary to comply with a valid court order, subpoena, or warrant, or to cooperate with law enforcement.

We also reserve the right to disclose information we believe, in good faith, is necessary to (i) take precautions against liability, (ii) protect against fraudulent, abusive, or unlawful activity, (iii) investigate or defend against third-party claims, (iv) protect the security of the Service, or (v) protect our property, legal rights, or the rights and safety of others.

Change of Ownership

Information about Users and Visitors, including Personal Data, may be disclosed and transferred to an acquirer, successor, or assignee as part of a merger, acquisition, financing, or sale of assets, or in insolvency/bankruptcy, only if the recipient commits to a privacy policy substantially consistent with this one.

Client Data may similarly be transferred as part of such a transaction, solely for the purpose of continuing operation of the Service, and only if the recipient commits to substantially consistent terms.

Your choices

Access, Correction, Deletion

We provide reasonable access to Personal Data you've provided through the Service. To access, amend, delete, or transfer information, contact us at service@adlightech.com. At your request, we will delete or block any reference to you in our database, subject to the retention exceptions described under "Data Retention" below.

You may update, correct, or delete your Account information at any time via your Account settings. Changes are reflected within a reasonable period.

You may decline to share certain Personal Data with us, in which case we may not be able to provide some features of the Service.

Navigation Information

You may opt out of Google Analytics collection using the Google Analytics Opt-out Browser Add-on.

Opting Out of Commercial Communications

Unsubscribe at any time via instructions in the email, or by contacting service@adlightech.com. Opt-out requests may take up to ten (10) business days to process. You will continue to receive administrative messages regarding the Service.

Adlightech has no direct relationship with a Client's customers or third parties whose Personal Data it may process on behalf of a Client. Individuals seeking to access, correct, amend, delete, or withdraw consent regarding their data should direct their request to the Client they deal with directly. If a Client requests removal of data, we will respond within thirty (30) days. Requests regarding Client Data should be sent to service@adlightech.com with subject line "Data Subject Request," including sufficient information to identify the Client, its customer or third party, and the data to delete or amend.

How do we protect your information?

An external PCI-compliant payment gateway handles credit card transactions, and we conduct regular vulnerability checks. Personal information is contained behind secured networks, accessible only to personnel with specific access rights who are required to keep it confidential. Sensitive information is encrypted in transit using TLS 1.2 or higher and encrypted at rest. We provide multi-factor authentication for accounts as an added layer of security, along with role-based access controls and audit logging.

Breach notification

In the event of a confirmed security breach affecting Client Data, we will notify the affected Client in writing within seven (7) calendar days of discovery, consistent with the Business Associate Agreement terms in our Client agreements, and will cooperate with the Client in investigating and remediating the breach. Where a breach affects Personal Data for which Adlightech is the controller and the General Data Protection Regulation applies, we will report to the competent supervisory authority within seventy-two (72) hours and notify affected data subjects of any high-risk breach. Where a Client is a HIPAA-covered entity, the Client remains responsible for any individual and regulatory notifications required of it under the HIPAA Breach Notification Rule.

Third-party Services

The Service may contain features or links to third-party websites and services. Information you provide on third-party sites is subject to those operators' own policies. We are not responsible for third-party content, privacy, or security practices. Review third parties' privacy policies before providing them information.

Google. We have not enabled Google AdSense and do not plan to. If you use Chrome Extensions or Google add-ons developed by Adlightech, we may collect your name and email through your Google Account (with consent); this isn't shared publicly or without explicit consent.

Data Transfer

We may transfer, process, and store Personal Data in centralized databases and with service providers located in or outside the US. When we transfer Personal Data to the US, we protect it as described in this Policy and our Terms of Service. The Service is hosted in the United States.

Data Controller and Data Processor

Adlightech does not own, control, or direct the use of Client Data stored or processed by a Client or User via the Service. Only the Client or Users may access, retrieve, and direct the use of Client Data. Adlightech is largely unaware of the specific Client Data stored or made available to the Service and does not access it except as authorized by the Client or necessary to provide the Service.

Because Adlightech does not determine the purposes or means of processing Personal Data contained in Client Data, Adlightech is not acting as a data controller under the EU General Data Protection Regulation (GDPR) with respect to such data, and does not bear the associated controller responsibilities. Adlightech should be considered only a processor (or, where applicable under HIPAA, a business associate) on behalf of its Clients and Users as to Client Data containing regulated Personal Data. Adlightech does not independently transfer or make Client Data available to third parties except to sub-processors who process it on Adlightech's behalf in connection with providing the Service, as authorized by the applicable Client or User.

The Client or User is the data controller for any Client Data containing Personal Data, controlling how it is collected, used, and processed.

Adlightech is not responsible for the content of Personal Data contained in Client Data, nor for how a Client or User collects, discloses, distributes, or otherwise processes such information.

Data Retention

We retain Personal Data collected from a User for as long as the User's account is active, or as needed to fulfill the purposes for which it was collected, unless otherwise required by law:

  • Contents of closed accounts are deleted within six (6) months of closure.
  • Backups are retained for twelve (12) months, after which they are overwritten in the ordinary backup cycle.
  • Records of legal transactions between Client and Adlightech are retained for ten (10) years.

Where you have requested deletion of your Personal Data, we will delete it from active systems promptly. Residual copies may persist in backups until overwritten in the ordinary cycle described above, and we may retain information where necessary to comply with a legal obligation, resolve a dispute, prevent fraud or abuse, or enforce our agreements. Any information so retained remains subject to this Policy and is not used for any other purpose.

Client Data is retained and deleted according to the terms of the applicable Client agreement. On termination, Client Data is returned or destroyed at the Client's election, with written certification of destruction where requested.

Cookies and Similar Technologies

We use cookies and similar technologies on the public areas of our websites for two purposes only.

Strictly necessary cookies enable core site navigation, security, and access to authenticated areas. The Service cannot function without them. They do not collect identifying information.

Analytics cookies allow us to measure site traffic and understand which pages visitors find useful, using Google Analytics 4. You may opt out of Google Analytics collection at any time using the Google Analytics Opt-out Browser Add-on.

We do not use advertising or behavioral targeting cookies. We do not permit advertising networks or data brokers to collect information about you through our websites, and we do not participate in cross-site advertising or interest-based ad networks.

No cookies are used within the authenticated Restricted Area in connection with Client Data.

Your State Privacy Rights

Residents of California, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive consumer privacy laws may have the following rights with respect to Personal Data for which Adlightech is the controller:

  • The right to know what Personal Data we collect, use, and disclose about you
  • The right to access a copy of that data in a portable format
  • The right to request correction of inaccurate data
  • The right to request deletion of your data
  • The right to opt out of the sale of Personal Data, of sharing for cross-context behavioral advertising, and of targeted advertising and profiling
  • The right not to be discriminated against for exercising any of these rights
  • The right to appeal a denial of any request

We do not sell Personal Data, and we do not share Personal Data for cross-context behavioral advertising or targeted advertising. Because we do not engage in these activities, no opt-out mechanism is required.

To exercise any right, contact us at service@adlightech.com with the subject line "Privacy Rights Request." We will verify your identity before responding and will respond within the timeframe required by applicable law, generally forty-five (45) days. If we deny your request, you may appeal by replying to our response; we will respond to an appeal within sixty (60) days.

Protected Health Information. Most state consumer privacy laws exempt information governed by HIPAA. Where we process PHI as a business associate on behalf of a Client, that information is governed by HIPAA and by our Business Associate Agreement with the Client rather than by state consumer privacy law. Individuals seeking to exercise rights with respect to their PHI should contact the healthcare provider or health plan they deal with directly.

Fair Information Practices

The Fair Information Practice Principles form the backbone of privacy law in the United States. In line with these principles, we notify affected parties of a data breach in accordance with the timelines set out under "Breach notification" above. We also agree to the Individual Redress Principle, which requires that individuals have enforceable rights against data collectors and processors who fail to adhere to the law, including recourse to courts or government agencies to investigate and/or prosecute non-compliance.

Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, our sub-processors, or applicable law. When we do, we will revise the "Last Updated" date at the top of this page. Where a change is material, we will provide additional notice, and for Clients we will provide notice in accordance with the terms of the applicable Client agreement. Your continued use of the Service after a revised Policy takes effect constitutes acceptance of the revised Policy.

Contact

Adlight Technologies LLC
15105 John J. Delaney Drive, Suite 317
Charlotte, NC 28277
service@adlightech.com
+1 (704) 610-5575

WaitingMed is a service of Adlight Technologies, LLC.