Privacy Policy
How Beetony by Atulo handles your data and the data your customers send through it. Short version: we store only what we need, we rely on you to send pseudonymous patient identifiers, and you can export the full record at any time.
Data we collect
Account data (name, email, company), API call metadata (timestamps, response codes, byte counts), and the audit payload itself: the patient identifier you send, AI input, AI output, and consent state. Under the Terms you agree to send a pseudonymous patient identifier rather than a name or an MRN. Beetony stores the identifier you send without inspecting or rewriting it, so keeping directly identifying values out of the payload is your responsibility, not something we filter for you.
How we use it
Audit data is used solely to serve your dashboard, run the bias engine on aggregate patterns, and fulfill your export requests. Account data is used for billing, support, and the security of your workspace. We do not sell or share data with advertisers, ever.
Subprocessors
The third parties we use to operate the service are listed in full at /legal/subprocessors, along with the current contractual status of each. Not every subprocessor is yet under a healthcare-specific agreement; the subprocessor page states exactly which are and which are not.
Retention
Audit records are retained for the window included in your plan: one year on Starter, three years on Growth, and a custom window on Enterprise. Automatic deletion at the end of that window is not yet implemented, so records persist until you ask us to remove them. On cancellation we keep them for 30 days, then delete unless you've already exported.
Your rights
Under HIPAA, GDPR, and most US state privacy laws, you (or your patients via you) have the right to access, correct, or delete records. Send requests to privacy@beetony.com and we respond within 30 days.