Privacy Policy
Introduction
Forthbridge, LLC (“Forthbridge,” “we,” “us,” or “our”) operates the Forthbridge OS platform, its applications, and its websites — including forthbridge.com, docs.forthbridge.ai, and forthbridge.ai. This Privacy Policy is incorporated into Forthbridge’s Terms of Service and describes how Forthbridge collects, uses, and protects personal information across all of these services. This Privacy Policy applies only to Forthbridge’s services and where Forthbridge controls data collection and use. It does not apply to any third-party websites, actions, or offers (Third-Party Services), regardless of links or connections through the platform or websites. We do not control Third-Party Services, which have separate privacy practices.
Throughout this Privacy Policy “you” or “your” is defined as you or any individual whose personal information is covered by the requirements specified in this Privacy Policy. If you are accepting this Privacy Policy on behalf of any other person or entity, you represent and warrant that you have obtained all necessary authorizations to do so, you have the legal authority to bind that person or entity to this Privacy Policy, you will inform such person or entity of the terms of this Privacy Policy, and references to “you” or “your” refer to that person or entity.
Protected Health Information
Protected Health Information (PHI) processed through the Forthbridge OS platform is governed by the Business Associate Agreement (BAA) in place for your organization — either directly with Forthbridge or through an authorized partner such as Atticus Health. Forthbridge acts as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA).
This Privacy Policy does not govern PHI. PHI is subject to the terms of the applicable BAA and HIPAA regulations. Details on PHI handling practices are available in our security documentation. To the extent any provision of this Privacy Policy conflicts with HIPAA or the applicable BAA, HIPAA and the BAA shall control with respect to PHI.
Information We Collect
From Platform Users
When providers, staff, patients, employers, employees, or affiliated organizations use Forthbridge OS applications, we collect:
- Account information— Name, email address, phone number, and role, collected through the platform’s self-hosted identity provider.
- Usage data— Actions taken within the platform, features accessed, and interaction patterns.
- Device information— Browser type, operating system, and device identifiers.
- Session data— Login timestamps, session duration, and IP addresses.
From Website Visitors
When you visit our websites or submit forms, we may collect:
- Contact information— Name, email address, company, and job title submitted through contact or demo request forms.
- Analytics data— IP address, browser type, referring URL, and pages visited.
Sensitive Personal Information
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) and certain other state privacy laws, certain categories of personal information may be classified as “Sensitive Personal Information.” This may include precise geolocation data and certain background information. Forthbridge collects and uses Sensitive Personal Information only to the extent necessary to deliver the platform and services, fulfill legal obligations, or as otherwise permitted by applicable law. California residents and residents of certain other jurisdictions have the right to limit Forthbridge’s use of Sensitive Personal Information to purposes necessary to perform the services. See the Your Rights section below for instructions on how to exercise this right.
How We Use Your Information
We use the information we collect to:
- Provide and operate the Forthbridge OS platform and its applications.
- Authenticate users and enforce access controls.
- Communicate about services, updates, and security notices (with opt-out for non-essential communications).
- Improve platform functionality, user experience, and our products and services.
- Develop new features and offerings.
- Maintain security, detect anomalies, and prevent abuse.
- Comply with legal obligations.
- Create de-identified or aggregated data for product development.
Forthbridge does not use personal information for targeted advertising, profiling for automated decision-making, or sale to third parties. Before any personal information is used to create de-identified or aggregated data for product development, it undergoes a de-identification process designed to satisfy the requirements of applicable law.
How We Share Your Information
Forthbridge does not sell personal information. We do not sell or share personal information for cross-context behavioral advertising or targeted advertising as those terms are defined under applicable state privacy laws.
We may share information with:
- Infrastructure providers— Under BAAs, solely to operate and secure the platform.
- Analytics providers— Under BAAs (e.g., Snowflake), for platform analytics and reporting.
- Authorized partner organizations— Such as Atticus Health, where your access to the platform is provided through a partner arrangement. Information shared with authorized partners is limited to what is necessary to administer your access and services.
- As required by law— In response to valid legal process, court orders, or regulatory requirements.
- In connection with a business transfer— If Forthbridge is involved in a merger, acquisition, financing, sale of assets, or similar transaction, personal information may be transferred, disclosed, or assigned to the relevant parties as part of that transaction. We will provide notice before personal information becomes subject to a different privacy policy.
Data Security
Forthbridge implements layered security controls to protect personal information, including AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, audit logging, and continuous monitoring. All infrastructure is deployed on dedicated, HIPAA-compliant cloud resources in the United States. All personal information and Customer Data is stored and processed within the United States. If you access the platform from outside the United States, please be aware that your information will be transferred to, processed, and stored in the United States, where data protection laws may differ from those in your country of residence. By using the platform, you consent to this transfer. Forthbridge applies the same data protection standards described in this Privacy Policy to all personal information regardless of where it is processed.
In accordance with applicable state data security laws, Forthbridge maintains a reasonable data security program that includes: (i) administrative safeguards, such as designating employees responsible for the security program, conducting risk assessments, training personnel on data security practices, and selecting service providers capable of maintaining appropriate security measures; (ii) technical safeguards, such as encryption of personal information in transit and at rest, access controls limiting data access to authorized personnel, monitoring systems to detect unauthorized access or anomalous activity, and secure software development practices; and (iii) physical safeguards, such as secure facilities and infrastructure for data storage, disposal procedures for physical records containing personal information, and controls on physical access to systems that store personal information. Forthbridge reviews and updates its security program on an ongoing basis to address new and evolving risks.
Breach Notification
In the event of a security breach that compromises the security, confidentiality, or integrity of personal information, Forthbridge will:
- Investigate and contain the incident promptly upon discovery.
- Notify affected individuals, organizations, and regulators as required by applicable federal and state breach notification laws, including HIPAA (45 CFR Part 164, Subpart D). In the event of a breach affecting a large number of users, Forthbridge may supplement direct notice with a prominent notice on its websites. Breach notifications will describe the nature of the breach, the categories of information affected, the steps Forthbridge has taken to address and remediate the breach, and the steps individuals can take to protect themselves. Where required by applicable law, Forthbridge will notify relevant state attorneys general and other applicable regulatory authorities.
Data Retention
Platform data is retained in accordance with HIPAA requirements and our data retention policies:
- Clinical records— 7 years
- Audit logs— 7 years
- Application logs— 90 days
- Session data— 30 days
After the applicable retention period expires, data is securely deleted or de-identified in accordance with NIST 800-88 guidelines.
Where Forthbridge is required by applicable law to retain information for a longer period, or where retention is necessary to protect Forthbridge’s legal interests, Forthbridge will retain information accordingly. When retention periods expire, Forthbridge will delete or de-identify the relevant information in accordance with its internal data management procedures.
Your Rights
The following information is provided to satisfy requirements under applicable state privacy laws, including those in California (CCPA/CPRA), Virginia (The Virginia Consumer Data Protection Act), Colorado (The Colorado Privacy Act), Connecticut (The Connecticut Data Privacy Act), Texas (The Texas Data Privacy and Security Act), and other states with comprehensive privacy legislation. To the extent that personal information constitutes PHI governed by HIPAA, it may be exempt from these state laws and the rights below apply only to non-PHI personal information.
Categories of Personal Information Collected. In the preceding twelve (12) months, we may have collected the following categories of personal information:
| Category | Examples | Source |
|---|---|---|
| Identifiers | Name, email address, phone number, IP address | Directly from you, automatically collected |
| Internet or network activity | Browser type, pages visited, features accessed, interaction patterns | Automatically collected |
| Professional or employment information | Job title, organization, role | Directly from you |
| Geolocation data | IP-derived approximate location | Automatically collected |
| Inferences | Usage patterns and preferences drawn from the above | Derived from collected data |
Your Rights. You may have the right to:
- Access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we share it. Patients may access and export their health records through the platform.
- Delete personal information we have collected from you, subject to legal retention requirements.
- Correct inaccurate personal information.
- Portability— obtain a copy of your personal information in a portable and readily usable format.
- Opt out of the sale of personal information, targeted advertising, or profiling. (Forthbridge does not engage in these activities, but we honor opt-out requests if exercised).
- Non-Discrimination— Forthbridge will not discriminate against you for exercising your privacy rights.
Limit Use of Sensitive Personal Information.You have the right to direct Forthbridge to limit its use and disclosure of Sensitive Personal Information to purposes necessary to perform the services, as permitted by the CPRA and certain other jurisdictions’ privacy laws. To exercise this right, contact us at privacy@forthbridge.com with the subject line “Limit Use of Sensitive Personal Information.”
To exercise any of these rights, contact us at privacy@forthbridge.com. You may also designate an authorized agent to submit a privacy request on your behalf. Forthbridge may require written proof of the agent’s authorization and may verify your identity directly before processing the request. We will respond to verifiable requests within forty-five (45) days, with one forty-five (45) day extension where reasonably necessary. If we deny your request, we will explain the reason and provide instructions for appeal.
Universal Opt-Out Signals. Forthbridge honors Global Privacy Control (GPC) and similar browser-based opt-out signals as required by applicable state laws.
Do Not Sell or Share My Personal Information. Forthbridge does not sell personal information for monetary compensation. However, to the extent any disclosure of personal information through cookies or similar tracking technologies could be construed as “selling” or “sharing” under the CPRA or other applicable state privacy laws, you may opt out of such practices by contacting us at privacy@forthbridge.com with the subject line “Do Not Sell or Share” or by using any opt-out mechanism available on our websites. Once you opt out, Forthbridge will not share your personal information with third-party advertising partners for advertising purposes. Opting out does not affect our ability to use your information to provide the services, send transactional communications, or comply with legal obligations. Your opt-out preference will be honored within fifteen (15) business days of receipt. Residents of states with applicable opt-out rights under state privacy law — including Colorado, Connecticut, Texas, and Virginia — may submit opt-out requests using the same mechanisms above.
Artificial Intelligence Disclosures
The Forthbridge OS platform includes artificial intelligence (AI) features. This section describes how Forthbridge collects, uses, and processes personal information in connection with its AI-powered features. This section supplements the other provisions of this Privacy Policy and should be read together with them. To the extent personal information constitutes PHI governed by HIPAA, the BAA and HIPAA regulations control.
Purposes of AI Data Processing
Forthbridge processes personal information through AI systems for the following purposes:
- Facilitating the delivery of healthcare services on behalf of provider organizations, including symptom intake, patient triage, and care navigation.
- Providing clinical decision support to licensed healthcare providers, such as evidence-based treatment recommendations, medication interaction checks, and diagnostic assistance.
- Generating AI-powered responses to health-related inquiries through chat, voice, or video interfaces on the platform.
- Performing administrative functions, including appointment scheduling, intake processing, automated reminders, and billing support.
- Improving the quality, safety, and performance of Forthbridge’s AI systems, including through de-identified or aggregated data analysis.
- Detecting and preventing fraud, abuse, and security threats.
- Complying with applicable legal and regulatory requirements.
Forthbridge does not use personal health information to train generalized AI models unless it has been properly de-identified in accordance with applicable law.
Automated Decision-Making
Forthbridge’s AI systems may be used to assist in making or materially influencing decisions related to healthcare services. These AI-assisted functions are designed to support — not replace — the independent clinical judgment of a licensed healthcare provider. Depending on your jurisdiction, you may have rights related to automated decision-making, including:
- The right to be informed that automated decision-making technology is being used.
- The right to receive an explanation of the logic involved and its potential impact on you.
- The right to opt out of certain automated processing that produces legal or similarly significant effects.
- The right to request human review of an automated decision.
- The right to contest the results of automated profiling.
To exercise any of these rights, contact us at privacy@forthbridge.com.
AI Transparency
In accordance with applicable law:
- Forthbridge will disclose when you are interacting with an AI system rather than a human being.
- AI-generated communications pertaining to clinical information will include a clear disclaimer indicating that the content was AI-generated, along with instructions on how to contact a human healthcare provider.
- Forthbridge will not use terms, titles, or design elements in its AI systems that indicate or imply that the AI system holds a healthcare license.
- If an AI system contributes to a decision that adversely affects your access to healthcare services, in some jurisdictions, you may request an explanation, correction of inaccurate data, and human review by contacting privacy@forthbridge.com.
Algorithmic Fairness
Forthbridge does not deploy AI with the intent to discriminate against any individual based on race, color, national origin, sex, age, disability, religion, genetic information, or any other characteristic protected under applicable law. Forthbridge maintains processes to identify, evaluate, and mitigate known or reasonably foreseeable risks of algorithmic discrimination in its AI systems.
Children's Privacy
The Forthbridge OS platform is designed for healthcare organizations and is not directed at children under 13. We do not knowingly collect personal information from children under 13 outside of the healthcare context. If we become aware that we have collected personal information from a child under 13 outside of the healthcare context and without parental consent, we will promptly delete that information. The Patient App may be used by minors under parental or guardian supervision as part of their healthcare. Nothing in this section is intended to be an admission that Forthbridge is subject to the Children’s Online Privacy Protection Act, the Federal Trade Commission’s Children’s Online Privacy Protection Rule(s), or any similar international, federal, state, or local laws, rules, or regulations.
Cookies and Tracking
We use session cookies for authentication and platform operation. Our websites use self-hosted analytics — no tracking data is sent to third-party advertising networks. We do not use third-party advertising trackers. You may manage cookies through your browser settings. No cookies or similar tracking technologies will be activated until you have provided consent, except for those strictly necessary for platform operation and authentication. Resources for managing cookies include: https://www.allaboutcookies.org/, www.aboutads.info/choices, and https://youradchoices.com/appchoices.
Third-Party Links
The platform and documentation may contain links to third-party services. Forthbridge is not responsible for the privacy practices of third-party websites or services. We encourage you to review the privacy policies of any third-party services you access.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, such as changes to the categories of information we collect, how we use or share it, or your privacy rights, we will provide you with reasonable advance notice by sending an email to the address associated with your account and/or by posting a prominent notice on our websites, no less than thirty (30) days before the changes take effect (or such shorter period as required by applicable law). Non-material changes, such as clarifications or corrections, may take effect without notice and upon posting. The most current version of this Privacy Policy will always be available on our websites, with the “Last Updated” date at the top reflecting the date of the most recent revision. Your continued use of our services after the effective date of a revised policy constitutes acceptance of the updated policy. If you do not agree to a material change, you must stop using the services before the effective date of that change.
Further Information
For technical details on how Forthbridge implements the security and privacy practices described in this policy, see our security documentation at docs.forthbridge.ai. The commitments in this Privacy Policy are not expanded or modified by the content of our technical documentation.
Contact
Forthbridge, LLC
Email: privacy@forthbridge.com
5718 Westheimer Rd Ste 1800
Houston, TX 77057
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at the address above.