Privacy Policy
Adlight Technologies LLC — Adlightech platform, including WaitingMed, Carolina AI, AI Inbox & AI Worklist
This Privacy Policy covers Adlight Technologies LLC and its Adlightech platform, including WaitingMed and all associated products — Carolina AI, AI Inbox, and AI Worklist — as well as all related mobile applications and services accessible via adlightech.com, waitingmed.com, ai-inbox.app, or any other website, IP address, subdomain, or API endpoint designated by Adlightech from time to time (collectively, together with the Site, our "Service").
This Privacy Policy ("Policy") describes the information that we gather on or through the Service, how we use and disclose such information, and the steps we take to protect such information. By visiting the Site, or by purchasing or using the Service, you accept the privacy practices described in this Policy.
This Policy is incorporated into, and is subject to, the Adlightech Terms & Conditions. Capitalized terms used but not defined in this Policy have the meaning given to them in the Adlightech Terms & Conditions.
Definitions
- "Client" means a licensed customer of Adlightech.
- "Client Data" means personal data, reports, addresses, and other files, folders, or documents in electronic form that a User of the Service stores within the Service.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Public Area" means the area of the Site that can be accessed both by Users and Visitors, without needing to log in.
- "Restricted Area" means the area of the Site that can be accessed only by Users, and where access requires logging in.
- "User" means an employee, agent, or representative of a Client, who primarily uses the restricted areas of the Site for the purpose of accessing the Service in such capacity.
- "Visitor" means an individual other than a User, who uses the public area, but has no access to the restricted areas of the Site or Service.
What personal information do we collect?
We collect different types of information from or through the Service. The legal bases for Adlightech's processing of Personal Data are primarily that the processing is necessary for providing the Service in accordance with our Terms of Service and that the processing is carried out in Adlightech's legitimate interests, further explained in "How do we use your information?" below. We may also process data upon your consent, asking for it as appropriate.
User-provided Information
When you use the Service, as a User or as a Visitor, you may provide, and we may collect, Personal Data. Examples of Personal Data include name, email address, mobile phone number, and credit card or other billing information. Personal Data also includes other information, such as geographic area or preferences, when linked to information that identifies a specific individual. You may provide us with Personal Data in various ways on the Service — for example, when you register for an Account, use the Service, post Client Data, interact with other users through communication or messaging capabilities (including Carolina AI voice interactions), or send us customer-service related requests.
Information Collected by Clients
A Client or User may store or upload into the Service Client Data, including data processed through AI Inbox (faxes, PDFs, emails, SMS, WhatsApp) and AI Worklist. Adlightech has no direct relationship with the individuals whose Personal Data it hosts as part of Client Data. Each Client is responsible for providing notice to its customers and third persons concerning the purpose for which the Client collects their Personal Data and how it is processed in or through the Service as part of Client Data.
Automatically Collected Information
When a User or Visitor uses the Service, we may automatically record certain information from the User's or Visitor's device using various technologies, including cookies, "pixels," or "web beacons." This may include IP address or other device address or ID, web browser and/or device type, pages visited before or after using the Service, content viewed or interacted with, and dates/times of access or use. We also may use these technologies to track interaction with email or SMS messages, such as whether a message is opened, clicked, or forwarded.
Voice and Call Data
Carolina AI, our bilingual AI voice agent, processes call audio and transcripts to answer, transfer, and log calls on behalf of Clients. Call recordings, transcripts, and related metadata are Client Data, processed solely per the Client's direction, and are subject to the same retention and disclosure limits described in this Policy.
Integrated Services
You may be given the option to access or register for the Service through the use of your username and password for certain third-party services (each, an "Integrated Service"), such as a Google account, or otherwise authorize an Integrated Service to provide Personal Data to us. By authorizing us to connect with an Integrated Service, you authorize us to access and store your name, email address(es), profile picture URL, and other information the Integrated Service makes available, and to use and disclose it per this Policy.
Information from Other Sources
We may obtain information, including Personal Data, from third parties and sources other than the Service, such as our partners, advertisers, and Integrated Services. If we combine information from other sources with Personal Data collected through the Service, we treat the combined information as Personal Data under this Policy.
How do we use your information?
Operations. We use information — other than Client Data — to operate, maintain, enhance, and provide features of the Service, respond to requests, and provide support. We process Client Data solely per the applicable Client's or User's directions.
Improvements. We use information to understand usage trends and preferences, improve the Service, and develop new products, services, and features.
Communications. We may use a Visitor's or User's email, phone number, or other information — other than Client Data — to contact them for (i) administrative purposes such as customer service, or addressing IP, privacy, or defamation issues related to content on the Service, or (ii) updates on promotions and events. You may opt out of promotional communications at any time.
Cookies and Tracking Technologies. We may use automatically collected information and cookies/similar technologies to: (i) personalize the Service; (ii) provide customized content and information; (iii) monitor and analyze effectiveness of Service and marketing activities; (iv) monitor aggregate site usage metrics; and (v) track entries or status in any promotions.
Analytics. We may use Google Analytics or similar tools to measure traffic on the Public Area of the Site. Google operates independently and has its own privacy policy. Data collected is used on a need-to-know basis to resolve technical issues, administer the Site, and identify visitor preferences, generally in non-identifiable form; we do not use this data to identify Visitors or Users.
Healthcare Data / HIPAA
Where a Client is a HIPAA-covered entity or business associate, Adlightech acts as a business associate (or subcontracted business associate) with respect to Protected Health Information ("PHI") processed through the Service, under a signed Business Associate Agreement ("BAA") with that Client. PHI processed through Carolina AI, AI Inbox, and AI Worklist is treated as Client Data under this Policy: it is processed solely per the Client's instructions, is not used or disclosed by Adlightech except as permitted by the BAA and applicable law, and is subject to administrative, physical, and technical safeguards consistent with the HIPAA Security Rule. Sub-processors who may handle PHI in the course of providing the Service are bound by equivalent BAA obligations where required.
To whom we disclose information?
Except as described in this Policy, we will not intentionally disclose Personal Data or Client Data to third parties without consent, except in these circumstances:
Unrestricted Information
Any information you voluntarily include in a Public Area of the Service is available to any Visitor or User with access to that content.
Service Providers (Sub-processors)
We work with third-party service providers who provide hosting, AI processing, communications, and other services for us. These parties may access or process Personal Data or Client Data as part of providing services to us. We limit information shared with them to what's reasonably necessary, and our contracts require them to maintain confidentiality.
Current sub-processors:
- Microsoft Azure — Hosting and AI document processing services (Azure Document Intelligence for AI Inbox) in the US (ISO 27001, ISO 27018, SOC 1/2/3, FedRAMP, HITRUST certifications).
- Anthropic (Claude API) — AI language processing powering AI Inbox document/referral extraction and related AI Worklist automation.
- Twilio — VoIP, SMS, and fax provider powering Carolina AI calling, texting, and fax services (ISO/IEC 27001).
- ElevenLabs — AI voice synthesis powering Carolina AI's bilingual voice interactions.
- Deepgram — Speech-to-text transcription supporting Carolina AI call processing.
- SendGrid — Email delivery infrastructure for platform notifications and AI Worklist follow-up communications.
- Amazon AWS — Hosting services (PCI-DSS, FedRAMP, GDPR, FIPS 140-2, NIST 800-171 certifications).
- Clover — Payment gateway (PCI compliant).
- Hostinger — Website hosting.
Non-Personally Identifiable Information
We may make aggregated or otherwise non-personally-identifiable information available to third parties for (i) compliance with reporting obligations; (ii) business or marketing purposes; or (iii) helping such parties understand Client, User, and Visitor interests, habits, and usage patterns.
Law Enforcement, Legal Process and Compliance
We may disclose Personal Data or other information if required by law, or in good-faith belief it's necessary to comply with a valid court order, subpoena, or warrant, or to cooperate with law enforcement.
We also reserve the right to disclose information we believe, in good faith, is necessary to (i) take precautions against liability, (ii) protect against fraudulent, abusive, or unlawful activity, (iii) investigate or defend against third-party claims, (iv) protect the security of the Service, or (v) protect our property, legal rights, or the rights and safety of others.
Change of Ownership
Information about Users and Visitors, including Personal Data, may be disclosed and transferred to an acquirer, successor, or assignee as part of a merger, acquisition, financing, or sale of assets, or in insolvency/bankruptcy, only if the recipient commits to a privacy policy substantially consistent with this one.
Client Data may similarly be transferred as part of such a transaction, solely for the purpose of continuing operation of the Service, and only if the recipient commits to substantially consistent terms.
Your choices
Access, Correction, Deletion
We provide reasonable access to Personal Data you've provided through the Service. To access, amend, delete, or transfer information, contact us at service@adlightech.com. At your request, we will have any reference to you deleted or blocked in our database.
You may update, correct, or delete your Account information at any time via your Account settings. Changes are reflected within a reasonable period, though we may retain information for backups, fraud prevention, analytics, or legal compliance.
You may decline to share certain Personal Data with us, in which case we may not be able to provide some features of the Service.
Navigation Information
You may opt out of Google Analytics collection using the Google Analytics Opt-out feature.
Opting Out of Commercial Communications
Unsubscribe at any time via instructions in the email, or by contacting service@adlightech.com. Opt-out requests may take up to ten (10) business days to process. You will continue to receive administrative messages regarding the Service.
Adlightech has no direct relationship with a Client's customers or third parties whose Personal Data it may process on behalf of a Client. Individuals seeking to access, correct, amend, delete, or withdraw consent regarding their data should direct their request to the Client they deal with directly. If a Client requests removal of data, we will respond within thirty (30) days. Requests regarding Client Data should be sent to service@adlightech.com with subject line "Data Subject Request," including sufficient information to identify the Client, its customer or third party, and the data to delete or amend.
How do we protect your information?
An external PCI-compliant payment gateway handles credit card transactions, and we conduct regular vulnerability checks. Personal information is contained behind secured networks, accessible only to personnel with specific access rights who are required to keep it confidential. Sensitive information is encrypted using industry-standard protocols and transmitted via TLS/SSL. We provide two-factor authentication (2FA) for accounts as an added layer of security.
In case of a security breach, we investigate immediately and report to the competent data protection authority within 72 hours or less, and notify affected data subjects of any high-risk breach.
Third-party Services
The Service may contain features or links to third-party websites and services. Information you provide on third-party sites is subject to those operators' own policies. We are not responsible for third-party content, privacy, or security practices. Review third parties' privacy policies before providing them information.
Data Transfer
We may transfer, process, and store Personal Data in centralized databases and with service providers located in or outside the US. When we transfer Personal Data to the US, we protect it as described in this Policy and our Terms of Service. The Service is hosted in the United States.
Data Controller and Data Processor
Adlightech does not own, control, or direct the use of Client Data stored or processed by a Client or User via the Service. Only the Client or Users may access, retrieve, and direct the use of Client Data. Adlightech is largely unaware of the specific Client Data stored or made available to the Service and does not access it except as authorized by the Client or necessary to provide the Service.
Because Adlightech does not determine the purposes or means of processing Personal Data contained in Client Data, Adlightech is not acting as a data controller under the EU General Data Protection Regulation (GDPR) with respect to such data, and does not bear the associated controller responsibilities. Adlightech should be considered only a processor (or, where applicable under HIPAA, a business associate) on behalf of its Clients and Users as to Client Data containing regulated Personal Data.
The Client or User is the data controller for any Client Data containing Personal Data, controlling how it is collected, used, and processed.
Data Retention
We retain Personal Data collected from a User for as long as the User's account is active, or as needed to fulfill the purposes for which it was collected, unless otherwise required by law:
- Contents of closed accounts are deleted within 6 months of closure.
- Backups are kept for 12 months.
- Records of legal transactions between Client and Adlightech are retained for 10 years.
Fair Information Practices
The Fair Information Practice Principles form the backbone of privacy law in the United States. In line with these principles, should a data breach occur, we will notify you via email or in-site notification within 7 business days. We also agree to the Individual Redress Principle, which requires that individuals have enforceable rights against data collectors and processors who fail to adhere to the law, including recourse to courts or government agencies to investigate and/or prosecute non-compliance.
Contact
Adlight Technologies LLC15105 D John Delaney Drive, Suite 317
Charlotte, NC 28277
service@adlightech.com
