1. Who this policy covers
This policy applies to:
- Visitors to our websites and landing pages;
- Waitlist members and demo requesters who share contact information with us;
- Nurse users who use Esoteric Sync through their facility's deployment;
- Facility customers and their authorized representatives.
A note on protected health information (PHI): when Esoteric Sync processes PHI on behalf of a skilled nursing facility, we do so as a business associate under HIPAA, governed by a Business Associate Agreement with that facility. Our handling of PHI is described in our HIPAA, Security & BAA page, and where this policy and a BAA conflict with respect to PHI, the BAA controls.
2. Information we collect
Information you give us
- Contact details — name, email address, phone number, role, and facility or company name when you join our waitlist, book a demo, apply for a role, or contact us;
- Account information — credentials and profile details when a facility deployment provisions your access;
- Voice input and documentation content — audio you record and the documentation drafts generated from it, when you use the product.
Information collected automatically
- Usage data — features used, session length, and interactions with the product, used to operate and improve the service;
- Device and log data — IP address, browser type, operating system, and timestamps;
- Cookies and similar technologies — used for essential site functionality and basic analytics. You can control cookies through your browser settings.
3. How we use information
- To provide, operate, and support Esoteric Sync — including transcribing voice input and generating documentation drafts for nurse review;
- To respond to demo requests, waitlist signups, and support inquiries;
- To improve the reliability, safety, and performance of the service;
- To communicate service updates, and — where permitted — product news you can opt out of at any time;
- To comply with legal obligations and enforce our agreements.
We do not sell your personal information. We do not use PHI to train AI models.
4. How information is shared
We share information only in these circumstances:
- Service providers and subprocessors — infrastructure, transcription, and AI processing providers who handle data on our behalf under written agreements, including BAAs or equivalent data protection terms where PHI is involved. A current subprocessor list is available on request;
- Your facility — when you use Sync through a facility deployment, your facility (the covered entity) has access to documentation created in the course of your work, consistent with its own policies;
- Legal requirements — when required by law, subpoena, or to protect the rights, safety, or property of Esoteric, our users, or others;
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy's protections.
5. Data retention
Voice recordings and generated drafts are retained only for the period necessary to deliver the service and are then automatically deleted on a defined retention schedule. Contact and account information is retained while your account or our relationship with your facility remains active, and afterward as required for legal, tax, and compliance purposes. Retention of PHI is governed by the applicable BAA.
6. Security
We use administrative, physical, and technical safeguards designed to protect your information, including encryption in transit and at rest, role-based access controls, and access logging. No system is perfectly secure, and we encourage you to protect your own credentials. Details of our security program are on our HIPAA, Security & BAA page.
7. Your choices and rights
- Marketing opt-out — every marketing email includes an unsubscribe link, and opting out never affects service communications;
- Access, correction, and deletion — you may request access to, correction of, or deletion of your personal information by contacting us. Depending on where you live, you may have additional rights under applicable state privacy laws, and we honor those rights as required;
- PHI requests — requests concerning PHI (access, amendment, accounting of disclosures) are handled with and through your facility, as HIPAA requires. If a request comes to us directly, we will route it to the appropriate covered entity.
8. Children
Our websites and services are intended for adults and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.
9. Changes to this policy
We may update this policy as our product and legal obligations evolve. When we do, we will revise the effective date above, and for material changes we will provide reasonable notice — on this page or by email.
10. Contact us
Esoteric Healthcare Systems LLC
Atlanta, Georgia
Email: hello@esotericsync.com
Privacy questions or requests
Access, correction, deletion, subprocessor lists, or anything else in this policy.