ArdaBot, Inc. · A Delaware corporation
Privacy Policy
Last updated September 6, 2026
ArdaBot, Inc., a Delaware corporation (Arda, we, us), provides the Arda website, EMR, patient portal, platform, practice onboarding, and utilization-management products. This policy explains how information is handled when you use these services.
Our role and your care organization
We handle website inquiries, account administration, business contacts, and service operations for our own business purposes. When a practice or health plan uses Arda to manage information on its behalf, that organization controls the records and our handling is governed by its instructions, applicable agreements, and law. This policy does not replace your provider’s or health plan’s Notice of Privacy Practices. Contact that organization about your care, coverage, medical records, or its privacy practices.
Information we handle
Depending on the service, information includes contact details you submit, account and authentication information, organization memberships and permissions, support communications, subscription and transaction references, and technical information such as IP addresses, device and browser details, usage events, and security logs. Within authorized clinical services, information may include patient records, messages, documents, appointments, and care-payment records. Demo environments and the initial UM app are synthetic-only; do not enter real patient information there or in marketing and practice-onboarding forms.
How information is used
Information is used to provide the requested services, authenticate users, enforce permissions, coordinate authorized workflows, answer inquiries, administer subscriptions, troubleshoot issues, maintain security and audit evidence, and meet contractual and legal obligations. Product analytics are restricted to pseudonymous scopes and approved properties; clinical content does not belong in platform analytics.
Service providers and disclosures
Arda uses providers for hosting, databases, identity, payments, notifications, analytics, and enabled AI features. They receive information needed for the relevant service under applicable agreements and configurations. Payment credentials and identity-verification details are collected through Stripe-hosted flows. Records may also be disclosed to recipients authorized by you or your care organization, to comply with legal obligations, protect rights and security, or as part of a business transaction subject to applicable protections. External applications you authorize have their own privacy policies.
AI and notifications
AI features process the inputs and authorized context needed for the requested function. Do not enter patient information into public or administrative assistants. Use of protected health information with production AI requires the relevant environment and provider approvals. Generic patient email notices direct recipients to the authenticated portal; clinical details remain in Arda. Notification consent and preferences apply independently of account access.
Cookies and technical storage
Cookies and similar browser storage support authentication, security, preferences, and configured service measurement. Read the Cookie Notice for more information and browser controls. Disabling necessary storage can prevent sign-in or other essential features from working.
Retention and safeguards
Retention depends on the information, service purpose, customer instructions, contractual requirements, and applicable recordkeeping obligations. Security and audit records or backups may remain after an account closes where necessary. Arda uses access controls, isolated environments, and audit mechanisms; no system can guarantee absolute security. Account deletion does not automatically delete a practice’s legally retained medical records.
Your choices and requests
You can update available account settings and notification preferences. Contact us to request access, correction, deletion, or other privacy rights available under applicable law; we may need to verify your identity and authority. For records controlled by a practice or health plan, contact that organization; we can help route a request. Authorized representatives must provide evidence of authority. Do not send medical records, passwords, or identity documents to our general email address.
Children and authorized representatives
Public marketing and business-administration services are intended for adults. Access to a minor’s clinical record must be arranged through the care organization and applicable consent and representative-access rules. A matching email address alone does not authorize chart access.
Changes and contact
We will post revisions with an updated date and provide additional notice or obtain consent where required. For privacy questions or requests, contact ArdaBot, Inc. at hello@arda.care with the subject Privacy request. Include only the information needed to route your request; use your authenticated care portal for clinical information.