Effective Date: October 1, 2026
Last Updated: October 1, 2026
AccredReady LLC respects the privacy and security of personal information entrusted to us.
This Privacy Policy explains how AccredReady LLC ("AccredReady," "AIHARP," "we," "us," or "our") collects, uses, discloses, stores, and protects personal information in connection with the AI Healthcare Accreditation Readiness Platform ("AIHARP" or the "Service"), our website at accredready.com, and related services.
This Privacy Policy should be read together with our Terms and Conditions and, where applicable, any Data Processing Addendum ("DPA"), Business Associate Agreement ("BAA"), enterprise agreement, or other written agreement between AccredReady and a Customer.
AIHARP is operated by:
AccredReady LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110
United States
Email: privacy@accredready.com
AccredReady LLC is a New Mexico domestic limited liability company.
AIHARP provides healthcare organizations with software designed to support accreditation readiness, quality management, compliance preparation, evidence management, assessments, corrective action management, survey preparation, and related activities.
Our role depends on the circumstances in which personal data is processed.
AccredReady generally determines the purposes and means of processing personal information relating to:
For these activities, AccredReady generally acts as the data controller or equivalent responsible party under applicable privacy law.
Healthcare organizations and other Customers may upload, create, or manage information through AIHARP, including evidence, assessments, policies, corrective action records, accreditation documentation, and other Customer Data.
Where a Customer determines why and how personal data contained in Customer Data is processed and AccredReady processes that information to provide the Service according to the Customer's instructions, the Customer generally acts as the controller and AccredReady generally acts as its processor or service provider.
In those circumstances, requests concerning personal information contained within Customer Data may need to be directed to the relevant Customer.
A separate Data Processing Addendum may govern such processing.
The information we collect depends on how you use the Service.
We may process:
We do not store passwords in plain text.
We may process information concerning Customers and their participating Facilities, including:
Customers may upload, enter, generate, or store information through AIHARP, including:
The content of Customer Data is controlled principally by the Customer.
When Users use AI-assisted features, we may process:
Only information reasonably required to perform the requested AI function should be submitted to AI Features.
We may process:
Payment card information is processed by our payment processor.
AccredReady does not store full payment card numbers or card security codes.
We may automatically collect technical information such as:
We may maintain records showing:
AIHARP is designed for healthcare accreditation and quality-management activities. As a result, documents uploaded by Customers could contain sensitive personal information or health-related information.
Customers should not upload identifiable patient or other sensitive personal information unless it is necessary, lawful, authorized, and appropriate for the relevant purpose.
Customers should use de-identified, anonymized, pseudonymized, redacted, or minimized information whenever reasonably practicable.
In particular, Customers are responsible for:
AIHARP is not intended to replace a Customer's clinical electronic health record or other designated clinical system of record.
Customers subject to the U.S. Health Insurance Portability and Accountability Act ("HIPAA") must not use the Service to process Protected Health Information in circumstances in which AccredReady would be required to act as a Business Associate unless an applicable Business Associate Agreement has first been executed.
Customers subject to the Saudi Personal Data Protection Law ("PDPL") remain responsible for determining the lawful basis and requirements applicable to personal and health data they control.
Where AccredReady processes such information on behalf of a Customer, AccredReady will process it subject to applicable contractual obligations and applicable law.
We may process personal data for the following purposes.
To:
To:
To:
To send:
We will obtain consent for promotional or marketing communications where required by applicable law.
To:
To:
Customer Data is primarily processed to provide the Service requested by the Customer.
We do not sell Customer Data.
We do not use identifiable Customer Data to train general-purpose artificial-intelligence models for AccredReady or third parties unless the Customer has expressly authorized that use.
We may use information that has been appropriately aggregated or de-identified so that it no longer reasonably identifies an individual, Customer, or Facility for purposes such as:
Where applicable law treats de-identified or anonymized information as personal data unless specified conditions are satisfied, we will apply those legal requirements.
The legal basis for processing depends on the information, purpose, applicable law, and our relationship with the individual or Customer.
Where applicable, we may process personal data because:
Processing is necessary to:
Processing may be necessary to comply with:
Where permitted by applicable law, we may process personal data where necessary for legitimate interests such as:
provided those interests are not overridden by applicable rights and restrictions.
We do not rely on legitimate interests to process sensitive personal data where applicable law prohibits that basis.
Where consent is legally required, we will request it before conducting the relevant processing.
Where processing is based solely on consent, consent may generally be withdrawn subject to applicable law.
Withdrawal does not affect the lawfulness of processing conducted before withdrawal.
Where AccredReady acts as a processor or service provider on behalf of a Customer, we process relevant Customer Data according to that Customer's documented instructions and our contractual obligations.
Certain AIHARP features use third-party artificial-intelligence, language-model, search, or embedding technology.
When a User requests an AI-assisted function, relevant information may be transmitted to a configured AI service provider to perform the requested operation.
Depending on the feature, this information may include:
We seek to limit information submitted to AI providers to information reasonably necessary to perform the requested function.
Customers and Users should avoid placing unnecessary patient identifiers or sensitive personal information into AI prompts.
The AI provider used for a particular request may depend on the relevant AIHARP feature, technical configuration, availability, performance, and Service requirements.
We use third-party providers to operate parts of the Service.
Depending on Service configuration, these may include:
| Category | Provider or Examples | Purpose |
|---|---|---|
| Payment processing | Stripe | Subscription billing and payment processing |
| AI processing | Providers such as OpenAI, Google Gemini, DeepSeek, and other AI providers enabled within AIHARP | AI-assisted processing and language-model functionality |
| Embeddings / semantic search | Voyage AI and/or other configured providers | Embeddings, search, retrieval, and related AI functionality |
| Hosting / infrastructure | Hostinger and associated infrastructure providers | Application and infrastructure hosting |
| Backup / object storage | Cloudflare R2 and/or configured infrastructure providers | Backup and object storage |
| Titan Email / Hostinger and related delivery infrastructure | Invitations, password resets, alerts, and transactional messages | |
| Error monitoring | Sentry | Application diagnostics, error investigation, and reliability monitoring |
A provider receives only the information reasonably necessary for the services it performs, subject to the configuration and nature of the relevant integration.
We may replace or add service providers as our Service evolves.
Where required by applicable law or contractual obligation, we will apply appropriate contractual, organizational, or technical safeguards to service providers that process personal data on our behalf.
Subscription payments are processed through Stripe or another disclosed payment processor.
When you enter payment card information, that information is generally provided directly to the payment processor rather than stored by AccredReady.
Payment processors may independently process certain information under their own privacy notices and legal obligations.
AccredReady may receive transaction information such as:
We may disclose personal information:
To providers described in this Policy where reasonably necessary to provide, maintain, secure, or support the Service.
Where a Customer or authorized User instructs us to disclose, export, transmit, or otherwise process Customer Data.
Personal information and Customer Data may be accessible to other authorized Users within the same Organization or Facility according to their assigned roles and permissions.
Customer administrators are responsible for assigning appropriate access.
We may disclose information where we reasonably believe disclosure is required to:
Where legally permitted and appropriate, we may notify the affected Customer before disclosing Customer Data in response to compulsory legal process.
If AccredReady is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, information may be disclosed subject to appropriate confidentiality protections.
We do not sell personal data for monetary consideration.
AccredReady is a United States company, and AIHARP uses infrastructure and service providers that may process information in the United States and other countries.
Accordingly, personal data submitted to AIHARP may be processed outside the country in which the User or Customer is located.
Different jurisdictions may provide different levels of data protection.
Where an international transfer of personal data is subject to legal restrictions, we will apply transfer mechanisms or safeguards required of AccredReady under applicable law and our contractual obligations.
Where the Saudi PDPL and its implementing regulations apply, transfers of personal data outside the Kingdom of Saudi Arabia must comply with applicable requirements governing international transfers.
Depending on the circumstances, these requirements may include:
The Customer remains responsible for determining whether its decision to submit particular Customer Data to AIHARP constitutes a lawful international transfer where the Customer acts as the controller.
Where AccredReady acts as the Customer's processor, the applicable Data Processing Addendum may provide additional terms concerning international transfers.
We aim to collect and process personal information that is reasonably necessary for the relevant purpose.
Customers should similarly limit Customer Data to information necessary for accreditation readiness, quality management, evidence management, or other authorized uses of the Service.
In particular, Users should avoid uploading:
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, subject to applicable contractual, operational, security, backup, legal, and regulatory requirements.
Retention periods vary according to the type of information and reason for processing.
Account and subscription information may be retained while an account is active and for an appropriate period afterward for:
Customer Data is generally retained while the Customer maintains access to the Service.
Following expiration or termination, Customer Data may remain available for a limited period for export or account administration before deletion or anonymization in accordance with our retention procedures, contractual obligations, and applicable law.
Audit, authentication, and security logs may be retained for periods reasonably necessary to:
Deleted information may temporarily remain in encrypted or restricted backup systems until overwritten or deleted through normal backup-retention processes.
Backups are not intended as active archives from which ordinary deleted Customer records can necessarily be restored individually.
We may retain information longer where required by law, legal process, litigation hold, regulatory requirement, contractual obligation, or another lawful purpose.
Once information is no longer required, we will delete, anonymize, or otherwise dispose of it according to applicable requirements and our retention procedures.
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, destruction, loss, or misuse.
Depending on the relevant system and data, these safeguards may include:
We periodically review and develop these safeguards as the Service evolves.
No method of electronic transmission or storage can be guaranteed to be completely secure. Accordingly, we cannot guarantee absolute security.
Customers also play an important role in protecting information and are responsible for:
We maintain procedures designed to identify, investigate, contain, and respond to security incidents involving personal data.
Where required by applicable law or contract, we will notify affected Customers, competent authorities, or individuals of qualifying personal-data breaches within applicable time requirements.
Where AccredReady acts as a processor for Customer Data, breach-notification responsibilities between AccredReady and the Customer may be further addressed in the applicable Data Processing Addendum.
Your rights depend on applicable law and the context in which your personal data is processed.
Subject to applicable legal limitations and exceptions, you may have rights including the right to:
Requests concerning personal data for which AccredReady is the controller may be sent to:
privacy@accredready.com
We may need to verify your identity before fulfilling a request.
We will respond within the period required by applicable law.
If your personal information was submitted to AIHARP by your employer, hospital, healthcare organization, or another Customer, that Customer may be the controller of the information.
In those circumstances, we may refer your request to the relevant Customer or assist that Customer in responding as required by applicable law and our contractual obligations.
Where the Saudi Personal Data Protection Law applies, individuals may have rights provided under that law and its implementing regulations, including, subject to applicable limitations:
Requests relating to personal data controlled by AccredReady may be submitted to privacy@accredready.com.
AIHARP uses AI to assist Users with accreditation-readiness activities.
AI Features may generate analyses, recommendations, scores, classifications, drafts, summaries, or suggestions.
AIHARP is designed as a decision-support tool. AI-generated output should be reviewed by an authorized human User before it is relied upon for accreditation, regulatory, quality-management, policy, or other material decisions.
Unless expressly stated otherwise for a particular feature, AIHARP does not independently make legally binding decisions concerning individuals solely through automated processing.
We use cookies and similar technologies necessary to operate and secure the Service.
These may include cookies used for:
Where we use optional analytics, advertising, or other non-essential cookies that require consent under applicable law, we will provide an appropriate notice or consent mechanism.
You may be able to control certain cookies through your browser settings. Disabling essential cookies may prevent parts of AIHARP from functioning correctly.
AIHARP is designed for professional and organizational use and is not directed to children.
Individuals creating AIHARP accounts must be legally permitted to enter into the applicable agreement or act on behalf of the relevant Customer.
We do not knowingly solicit personal information directly from children for independent use of the Service.
Customer Data uploaded by healthcare organizations may nevertheless contain information relating to minors where the Customer has a lawful and legitimate reason to process such information. In those circumstances, the Customer is responsible for ensuring that the processing is lawful and appropriate.
The Service may contain links to or integrations with third-party websites, applications, or services.
This Privacy Policy does not govern personal information independently collected by third parties outside our role as their customer or service user.
We encourage Users to review the applicable third party's privacy notice where appropriate.
We may update this Privacy Policy periodically to reflect:
The "Last Updated" date at the beginning of this Policy identifies the current version.
If we make a material change, we will provide notice through the Service, by email, or through another reasonable method where required or appropriate.
Where applicable law requires renewed consent or acceptance, we will obtain it before conducting processing that requires such consent or acceptance.
Questions, concerns, or requests regarding this Privacy Policy or AccredReady's processing of personal data may be directed to:
AccredReady LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110
United States
Privacy Email: privacy@accredready.com
If your request concerns personal data controlled by a healthcare organization or other AIHARP Customer, we may direct you to that organization so that it can respond as the responsible controller.
If you have concerns about how AccredReady processes personal data for which we act as controller, please contact us first at:
privacy@accredready.com
You may also have the right to submit a complaint to the data-protection or regulatory authority responsible for your jurisdiction.
Nothing in this Privacy Policy limits any right to contact a competent authority where that right is provided by applicable law.