/ LEGAL

Privacy Policy

Effective date: June 26, 2026

This Privacy Policy explains how Convey, Inc. (“Convey,” “we,” “us,” or “our”) collects, uses, and shares personal information in connection with our websites and the Convey Unified Health Exchange (collectively, the “Service”). It also describes the choices you have about your information.

Scope — please read first: Protected Health Information (“PHI”) that Convey processes on behalf of its healthcare customers is governed by the Health Insurance Portability and Accountability Act (“HIPAA”) and the applicable Business Associate Agreement, not by this Privacy Policy. This Privacy Policy governs personal information for which Convey acts as a controller — for example, information about website visitors, prospective customers, and the account and business-contact information of our customers’ Authorized Users. If you are a patient, please contact your healthcare provider regarding their handling of your health information.

1. Information We Collect

1.1 Information you provide

  • Account and registration information, such as name, work email, organization, role, and credentials used to sign in (which may be managed through a third-party identity provider).
  • Communications, such as messages you send to us, support requests, and survey or form responses.
  • Business and billing information, such as contact details and, for paid plans, payment information processed by our payment provider.

1.2 Information collected automatically

  • Device and log data, such as IP address, browser type, operating system, and access times.
  • Usage data, such as pages viewed and features used, collected through cookies and similar technologies.

1.3 Information from third parties

We may receive information from identity providers and single sign-on services you use to access the Service, and from our integration and service-provider partners, consistent with their terms and your settings.

2. How We Use Information

  • to provide, operate, secure, and improve the Service;
  • to authenticate users and administer accounts;
  • to communicate with you about the Service, including service, security, and administrative messages;
  • to provide support, respond to inquiries, and conduct research and analytics;
  • to detect, prevent, and address fraud, abuse, and security issues; and
  • to comply with legal obligations and enforce our agreements.

3. Cookies and Similar Technologies

We use cookies and similar technologies to operate and secure the Service, remember preferences, and understand usage. You can control cookies through your browser settings, and we honor recognized opt-out signals such as Global Privacy Control where required. Some features may not function properly without certain cookies.

4. How We Share Information

We do not sell your personal information. We share personal information only as described here:

  • Service providers and subprocessors who process information on our behalf (such as hosting, identity, analytics, and support providers) under appropriate confidentiality and data- protection obligations;
  • Integrations you enable, such as electronic health record systems and partner organizations, at your direction;
  • Legal and safety purposes, when required by law or to protect rights, safety, and the integrity of the Service; and
  • Business transfers, in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

5. Data Retention

We retain personal information for as long as needed to provide the Service, fulfill the purposes described in this Policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention and return or deletion of PHI are governed by the Business Associate Agreement.

6. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest and role-based access controls. You can read more about our approach on our Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your Choices and Rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to opt out of certain processing. Where Convey processes information on behalf of a customer (including PHI), please direct your request to that organization, and we will assist them as required. To exercise rights for information Convey controls, contact us using the details below. We will not discriminate against you for exercising your rights.

8. Children’s Privacy

The Service is intended for healthcare organizations and their Authorized Users and is not directed to children. We do not knowingly collect personal information directly from children through the Service. (Health information about pediatric patients may be processed on behalf of a provider as PHI under the applicable Business Associate Agreement.)

9. U.S. Data Processing

Convey is based in the United States, and we process and store information in the United States. If you access the Service from outside the United States, you understand that your information will be processed in the United States.

10. Third-Party Services

The Service may link to or interoperate with third-party services that we do not control. Their privacy practices are governed by their own policies, and we encourage you to review them.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by posting the updated Policy with a new effective date. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.

12. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at privacy@convey.care, or by mail to Convey, Inc., 10776 N 112th Pl, Scottsdale, AZ 85259. This Policy works together with our Terms of Service.

© 2026 Convey, Inc.