Privacy Policy

Effective Date: October 1, 2026
Last Updated: October 1, 2026

AccredReady LLC respects the privacy and security of personal information entrusted to us.

This Privacy Policy explains how AccredReady LLC ("AccredReady," "AIHARP," "we," "us," or "our") collects, uses, discloses, stores, and protects personal information in connection with the AI Healthcare Accreditation Readiness Platform ("AIHARP" or the "Service"), our website at accredready.com, and related services.

This Privacy Policy should be read together with our Terms and Conditions and, where applicable, any Data Processing Addendum ("DPA"), Business Associate Agreement ("BAA"), enterprise agreement, or other written agreement between AccredReady and a Customer.

1. Who We Are

AIHARP is operated by:

AccredReady LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110
United States

Email: privacy@accredready.com

AccredReady LLC is a New Mexico domestic limited liability company.

AIHARP provides healthcare organizations with software designed to support accreditation readiness, quality management, compliance preparation, evidence management, assessments, corrective action management, survey preparation, and related activities.

2. Our Role When Processing Personal Data

Our role depends on the circumstances in which personal data is processed.

2.1 When AccredReady acts as a controller

AccredReady generally determines the purposes and means of processing personal information relating to:

For these activities, AccredReady generally acts as the data controller or equivalent responsible party under applicable privacy law.

2.2 When AccredReady acts on behalf of a Customer

Healthcare organizations and other Customers may upload, create, or manage information through AIHARP, including evidence, assessments, policies, corrective action records, accreditation documentation, and other Customer Data.

Where a Customer determines why and how personal data contained in Customer Data is processed and AccredReady processes that information to provide the Service according to the Customer's instructions, the Customer generally acts as the controller and AccredReady generally acts as its processor or service provider.

In those circumstances, requests concerning personal information contained within Customer Data may need to be directed to the relevant Customer.

A separate Data Processing Addendum may govern such processing.

3. Personal Data We Collect

The information we collect depends on how you use the Service.

3.1 Account and identity information

We may process:

We do not store passwords in plain text.

3.2 Organization and Facility information

We may process information concerning Customers and their participating Facilities, including:

3.3 Accreditation and Customer Data

Customers may upload, enter, generate, or store information through AIHARP, including:

The content of Customer Data is controlled principally by the Customer.

3.4 AI Feature data

When Users use AI-assisted features, we may process:

Only information reasonably required to perform the requested AI function should be submitted to AI Features.

3.5 Billing and transaction information

We may process:

Payment card information is processed by our payment processor.

AccredReady does not store full payment card numbers or card security codes.

3.6 Technical, security, and usage information

We may automatically collect technical information such as:

3.7 Acceptance and compliance records

We may maintain records showing:

4. Sensitive and Health Information

AIHARP is designed for healthcare accreditation and quality-management activities. As a result, documents uploaded by Customers could contain sensitive personal information or health-related information.

Customers should not upload identifiable patient or other sensitive personal information unless it is necessary, lawful, authorized, and appropriate for the relevant purpose.

Customers should use de-identified, anonymized, pseudonymized, redacted, or minimized information whenever reasonably practicable.

In particular, Customers are responsible for:

AIHARP is not intended to replace a Customer's clinical electronic health record or other designated clinical system of record.

4.1 U.S. Protected Health Information

Customers subject to the U.S. Health Insurance Portability and Accountability Act ("HIPAA") must not use the Service to process Protected Health Information in circumstances in which AccredReady would be required to act as a Business Associate unless an applicable Business Associate Agreement has first been executed.

4.2 Saudi health and sensitive data

Customers subject to the Saudi Personal Data Protection Law ("PDPL") remain responsible for determining the lawful basis and requirements applicable to personal and health data they control.

Where AccredReady processes such information on behalf of a Customer, AccredReady will process it subject to applicable contractual obligations and applicable law.

5. How We Use Personal Data

We may process personal data for the following purposes.

5.1 Providing the Service

To:

5.2 Security and integrity

To:

5.3 Billing and subscriptions

To:

5.4 Communications

To send:

We will obtain consent for promotional or marketing communications where required by applicable law.

5.5 Technical support and troubleshooting

To:

5.6 Legal and regulatory requirements

To:

6. Use of Customer Data for Product Improvement and AI Training

Customer Data is primarily processed to provide the Service requested by the Customer.

We do not sell Customer Data.

We do not use identifiable Customer Data to train general-purpose artificial-intelligence models for AccredReady or third parties unless the Customer has expressly authorized that use.

We may use information that has been appropriately aggregated or de-identified so that it no longer reasonably identifies an individual, Customer, or Facility for purposes such as:

Where applicable law treats de-identified or anonymized information as personal data unless specified conditions are satisfied, we will apply those legal requirements.

7. Legal Bases for Processing

The legal basis for processing depends on the information, purpose, applicable law, and our relationship with the individual or Customer.

Where applicable, we may process personal data because:

7.1 Performance of a contract

Processing is necessary to:

7.2 Legal obligations

Processing may be necessary to comply with:

7.3 Legitimate interests

Where permitted by applicable law, we may process personal data where necessary for legitimate interests such as:

provided those interests are not overridden by applicable rights and restrictions.

We do not rely on legitimate interests to process sensitive personal data where applicable law prohibits that basis.

7.4 Consent

Where consent is legally required, we will request it before conducting the relevant processing.

Where processing is based solely on consent, consent may generally be withdrawn subject to applicable law.

Withdrawal does not affect the lawfulness of processing conducted before withdrawal.

7.5 Customer instructions

Where AccredReady acts as a processor or service provider on behalf of a Customer, we process relevant Customer Data according to that Customer's documented instructions and our contractual obligations.

8. AI-Assisted Processing

Certain AIHARP features use third-party artificial-intelligence, language-model, search, or embedding technology.

When a User requests an AI-assisted function, relevant information may be transmitted to a configured AI service provider to perform the requested operation.

Depending on the feature, this information may include:

We seek to limit information submitted to AI providers to information reasonably necessary to perform the requested function.

Customers and Users should avoid placing unnecessary patient identifiers or sensitive personal information into AI prompts.

The AI provider used for a particular request may depend on the relevant AIHARP feature, technical configuration, availability, performance, and Service requirements.

9. Service Providers and Subprocessors

We use third-party providers to operate parts of the Service.

Depending on Service configuration, these may include:

Category Provider or Examples Purpose
Payment processing Stripe Subscription billing and payment processing
AI processing Providers such as OpenAI, Google Gemini, DeepSeek, and other AI providers enabled within AIHARP AI-assisted processing and language-model functionality
Embeddings / semantic search Voyage AI and/or other configured providers Embeddings, search, retrieval, and related AI functionality
Hosting / infrastructure Hostinger and associated infrastructure providers Application and infrastructure hosting
Backup / object storage Cloudflare R2 and/or configured infrastructure providers Backup and object storage
Email Titan Email / Hostinger and related delivery infrastructure Invitations, password resets, alerts, and transactional messages
Error monitoring Sentry Application diagnostics, error investigation, and reliability monitoring

A provider receives only the information reasonably necessary for the services it performs, subject to the configuration and nature of the relevant integration.

We may replace or add service providers as our Service evolves.

Where required by applicable law or contractual obligation, we will apply appropriate contractual, organizational, or technical safeguards to service providers that process personal data on our behalf.

10. Payment Processing

Subscription payments are processed through Stripe or another disclosed payment processor.

When you enter payment card information, that information is generally provided directly to the payment processor rather than stored by AccredReady.

Payment processors may independently process certain information under their own privacy notices and legal obligations.

AccredReady may receive transaction information such as:

11. Disclosure of Personal Data

We may disclose personal information:

11.1 To service providers

To providers described in this Policy where reasonably necessary to provide, maintain, secure, or support the Service.

11.2 At the Customer's direction

Where a Customer or authorized User instructs us to disclose, export, transmit, or otherwise process Customer Data.

11.3 Within an Organization

Personal information and Customer Data may be accessible to other authorized Users within the same Organization or Facility according to their assigned roles and permissions.

Customer administrators are responsible for assigning appropriate access.

11.4 For legal reasons

We may disclose information where we reasonably believe disclosure is required to:

Where legally permitted and appropriate, we may notify the affected Customer before disclosing Customer Data in response to compulsory legal process.

11.5 Business transactions

If AccredReady is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, information may be disclosed subject to appropriate confidentiality protections.

We do not sell personal data for monetary consideration.

12. International Processing and Data Transfers

AccredReady is a United States company, and AIHARP uses infrastructure and service providers that may process information in the United States and other countries.

Accordingly, personal data submitted to AIHARP may be processed outside the country in which the User or Customer is located.

Different jurisdictions may provide different levels of data protection.

Where an international transfer of personal data is subject to legal restrictions, we will apply transfer mechanisms or safeguards required of AccredReady under applicable law and our contractual obligations.

12.1 Saudi Arabia

Where the Saudi PDPL and its implementing regulations apply, transfers of personal data outside the Kingdom of Saudi Arabia must comply with applicable requirements governing international transfers.

Depending on the circumstances, these requirements may include:

The Customer remains responsible for determining whether its decision to submit particular Customer Data to AIHARP constitutes a lawful international transfer where the Customer acts as the controller.

Where AccredReady acts as the Customer's processor, the applicable Data Processing Addendum may provide additional terms concerning international transfers.

13. Data Minimization

We aim to collect and process personal information that is reasonably necessary for the relevant purpose.

Customers should similarly limit Customer Data to information necessary for accreditation readiness, quality management, evidence management, or other authorized uses of the Service.

In particular, Users should avoid uploading:

14. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, subject to applicable contractual, operational, security, backup, legal, and regulatory requirements.

Retention periods vary according to the type of information and reason for processing.

14.1 Account and subscription data

Account and subscription information may be retained while an account is active and for an appropriate period afterward for:

14.2 Customer Data

Customer Data is generally retained while the Customer maintains access to the Service.

Following expiration or termination, Customer Data may remain available for a limited period for export or account administration before deletion or anonymization in accordance with our retention procedures, contractual obligations, and applicable law.

14.3 Audit and security logs

Audit, authentication, and security logs may be retained for periods reasonably necessary to:

14.4 Backups

Deleted information may temporarily remain in encrypted or restricted backup systems until overwritten or deleted through normal backup-retention processes.

Backups are not intended as active archives from which ordinary deleted Customer records can necessarily be restored individually.

14.5 Legal retention

We may retain information longer where required by law, legal process, litigation hold, regulatory requirement, contractual obligation, or another lawful purpose.

Once information is no longer required, we will delete, anonymize, or otherwise dispose of it according to applicable requirements and our retention procedures.

15. Data Security

We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, destruction, loss, or misuse.

Depending on the relevant system and data, these safeguards may include:

We periodically review and develop these safeguards as the Service evolves.

No method of electronic transmission or storage can be guaranteed to be completely secure. Accordingly, we cannot guarantee absolute security.

Customers also play an important role in protecting information and are responsible for:

16. Personal Data Breaches

We maintain procedures designed to identify, investigate, contain, and respond to security incidents involving personal data.

Where required by applicable law or contract, we will notify affected Customers, competent authorities, or individuals of qualifying personal-data breaches within applicable time requirements.

Where AccredReady acts as a processor for Customer Data, breach-notification responsibilities between AccredReady and the Customer may be further addressed in the applicable Data Processing Addendum.

17. Your Privacy Rights

Your rights depend on applicable law and the context in which your personal data is processed.

Subject to applicable legal limitations and exceptions, you may have rights including the right to:

Requests concerning personal data for which AccredReady is the controller may be sent to:

privacy@accredready.com

We may need to verify your identity before fulfilling a request.

We will respond within the period required by applicable law.

17.1 Customer-controlled data

If your personal information was submitted to AIHARP by your employer, hospital, healthcare organization, or another Customer, that Customer may be the controller of the information.

In those circumstances, we may refer your request to the relevant Customer or assist that Customer in responding as required by applicable law and our contractual obligations.

18. Saudi PDPL Rights

Where the Saudi Personal Data Protection Law applies, individuals may have rights provided under that law and its implementing regulations, including, subject to applicable limitations:

Requests relating to personal data controlled by AccredReady may be submitted to privacy@accredready.com.

19. Automated and AI-Assisted Decisions

AIHARP uses AI to assist Users with accreditation-readiness activities.

AI Features may generate analyses, recommendations, scores, classifications, drafts, summaries, or suggestions.

AIHARP is designed as a decision-support tool. AI-generated output should be reviewed by an authorized human User before it is relied upon for accreditation, regulatory, quality-management, policy, or other material decisions.

Unless expressly stated otherwise for a particular feature, AIHARP does not independently make legally binding decisions concerning individuals solely through automated processing.

20. Cookies and Similar Technologies

We use cookies and similar technologies necessary to operate and secure the Service.

These may include cookies used for:

Where we use optional analytics, advertising, or other non-essential cookies that require consent under applicable law, we will provide an appropriate notice or consent mechanism.

You may be able to control certain cookies through your browser settings. Disabling essential cookies may prevent parts of AIHARP from functioning correctly.

21. Children's Privacy

AIHARP is designed for professional and organizational use and is not directed to children.

Individuals creating AIHARP accounts must be legally permitted to enter into the applicable agreement or act on behalf of the relevant Customer.

We do not knowingly solicit personal information directly from children for independent use of the Service.

Customer Data uploaded by healthcare organizations may nevertheless contain information relating to minors where the Customer has a lawful and legitimate reason to process such information. In those circumstances, the Customer is responsible for ensuring that the processing is lawful and appropriate.

22. Links and Third-Party Services

The Service may contain links to or integrations with third-party websites, applications, or services.

This Privacy Policy does not govern personal information independently collected by third parties outside our role as their customer or service user.

We encourage Users to review the applicable third party's privacy notice where appropriate.

23. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect:

The "Last Updated" date at the beginning of this Policy identifies the current version.

If we make a material change, we will provide notice through the Service, by email, or through another reasonable method where required or appropriate.

Where applicable law requires renewed consent or acceptance, we will obtain it before conducting processing that requires such consent or acceptance.

24. Contact Us

Questions, concerns, or requests regarding this Privacy Policy or AccredReady's processing of personal data may be directed to:

AccredReady LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110
United States

Privacy Email: privacy@accredready.com

If your request concerns personal data controlled by a healthcare organization or other AIHARP Customer, we may direct you to that organization so that it can respond as the responsible controller.

25. Complaints

If you have concerns about how AccredReady processes personal data for which we act as controller, please contact us first at:

privacy@accredready.com

You may also have the right to submit a complaint to the data-protection or regulatory authority responsible for your jurisdiction.

Nothing in this Privacy Policy limits any right to contact a competent authority where that right is provided by applicable law.