“Elizian,” “we,” “us,” and “our” refer to MyWoosah Inc. when operating the Elizian website, platform, services, and related communications. Elizian is the enterprise healthcare execution platform developed, owned, and operated by MyWoosah Inc.
This policy applies to personal information collected through the Elizian public website, resource center, contact and briefing forms, operational assessment forms, marketing communications, events and webinars, customer and prospective-customer communications, platform account administration where not otherwise governed by customer contracts, support communications, job-applicant interactions where applicable, and website technologies.
- Customer agreements, Business Associate Agreements, employment or contractor policies, provider agreements, separate notices presented at collection, customer-controlled patient or member portals, and third-party websites may be governed separately.
The public website Privacy Policy generally governs personal information collected through Elizian public website and marketing pages, resource downloads, forms, communications, cookies, and similar interactions.
When Elizian processes protected health information on behalf of a healthcare customer acting as a covered entity or another business associate, processing may be governed by the customer agreement, a Business Associate Agreement, applicable healthcare privacy and security requirements, customer instructions, and other contractual documentation.
The customer organization may be the appropriate party to contact about patient or member records, access to or amendment of protected health information, restrictions, accounting of healthcare disclosures, and other HIPAA rights.
This Privacy Policy does not replace a customer’s HIPAA Notice of Privacy Practices. If this policy conflicts with a signed Business Associate Agreement concerning protected health information, the applicable signed agreement governs to the extent of the conflict. Not all Elizian data is protected health information, and HIPAA does not apply to every website visitor or interaction.
The categories collected depend on the interaction, configured customer deployment, and signed agreements.
A. Information You Provide
- Name, business email, telephone number, job title, organization, organization type, state or region, message content, operational challenge, requested resource or assessment, event registration information, account credentials, support requests, communications preferences, and job-application materials where applicable.
B. Account and Enterprise User Information
- User identity, organization, role, permissions, authentication data, login activity, account status, support history, and audit events.
C. Technical and Usage Information
- IP address, browser and device type, operating system, referring page, pages viewed, date and time, click activity, session information, error logs, performance data, security events, and approximate location derived from IP where permitted.
D. Customer-Submitted Data
Enterprise customers may submit or direct Elizian to process information relating to patients, members, providers, employees, caregivers, family members, case workflows, referrals, authorizations, services, and operational communications. Precise categories depend on the configured deployment and signed agreements.
E. Sensitive Information
Where required for an authorized service, information may include health or disability information, government identifiers, financial information, authentication credentials, geolocation where enabled, information concerning children or dependents, or other legally defined sensitive personal information.
F. Information from Third Parties
- Enterprise customers, authorized administrators, integration partners, identity providers, referral sources, event partners, service providers, public business sources, and customer-authorized systems.
Collection sources depend on the services and integrations actually enabled for the relevant interaction or customer environment.
- Forms and account creation.
- Platform use and customer-authorized workflows.
- Customer integrations, secure file transfers, APIs, and single sign-on.
- Email, telephone, customer support, resource downloads, and events.
- Active cookies, website technologies, security monitoring, and authorized third parties.
For customer-controlled data, Elizian may process information according to customer instructions and signed agreements.
- Operate, provide, and configure Elizian customer deployments.
- Authenticate and administer users; route and manage authorized workflows.
- Communicate with customers and users, respond to inquiries, and provide support.
- Process briefing and assessment requests and deliver requested resources.
- Improve website usability, maintain security, detect fraud or misuse, monitor performance, and conduct authorized analytics.
- Meet contractual and legal obligations, enforce agreements, protect rights and safety, and conduct corporate administration.
- Evaluate job applicants where applicable; send permitted marketing communications; maintain opt-out and suppression records.
Elizian does not make customer data freely available across organizations. Disclosure depends on configured permissions, workflow, customer instructions, applicable law, and agreements.
B. Service Providers and Subprocessors
Service providers may support cloud hosting, identity management, communications, customer support, security, analytics, document management, payment processing where applicable, integrations, and professional advice. They are expected to process information only for authorized purposes and under applicable contractual obligations.
C. Healthcare and Service-Delivery Participants
Where configured and authorized, information may be made available to relevant hospitals, health plans, providers, agencies, care teams, community organizations, transportation or equipment providers, and other authorized participants.
D. Legal and Safety Disclosures
- Legal process, regulatory requests, enforcement, security incidents, protection of rights, prevention of fraud, and protection from harm.
E. Corporate Transactions
- Potential merger, financing, acquisition, reorganization, sale of assets, due diligence, or insolvency.
F. With Consent or Direction
Information may be disclosed when the individual, customer, or another authorized party directs or consents to the disclosure.
Where configured and authorized, Elizian may use automated tools to assist with summarization, classification, requirement extraction, workflow prioritization, provider-match recommendations, risk identification, communication drafting, and operational insights.
AI outputs may require human review. AI does not replace licensed clinical judgment and does not independently make medical-necessity decisions, payer authorization decisions, or employment or supervision decisions for providers. Customer configurations may differ, and personal information used with AI tools is subject to applicable agreements and controls.
Elizian does not use Customer Data to train generalized AI models unless expressly authorized by the customer in a signed agreement. Personal information used for product improvement, analytics, or AI-assisted processing remains subject to applicable contractual, privacy, and security controls.
Elizian retains personal information only for as long as reasonably necessary for the purposes described in this policy, to provide services, satisfy contractual obligations, resolve disputes, maintain security, and comply with law. Retention periods vary by information type, context, customer instructions, and legal requirements.
When deletion is required, information may be removed or de-identified from active systems subject to applicable agreements and law. Residual copies may remain in protected backups until routine rotation or may be preserved where legally required.
| Information category | Published retention period | Basis |
|---|---|---|
| Marketing leads | As long as reasonably necessary | Operational, contractual, and legal requirements |
| Resource requests | As long as reasonably necessary | Operational, contractual, and legal requirements |
| Account information | As long as reasonably necessary | Operational, contractual, and legal requirements |
| Security logs | As long as reasonably necessary | Operational, contractual, and legal requirements |
| Customer data | As long as reasonably necessary | Operational, contractual, and legal requirements |
| Support records | As long as reasonably necessary | Operational, contractual, and legal requirements |
| Job applications | As long as reasonably necessary | Operational, contractual, and legal requirements |
| Consent records | As long as reasonably necessary | Operational, contractual, and legal requirements |
| Cookie records | As long as reasonably necessary | Operational, contractual, and legal requirements |
| Legal holds | As long as reasonably necessary | Operational, contractual, and legal requirements |
Elizian uses reasonable administrative, technical, and organizational safeguards appropriate to the information and service. Depending on implementation, safeguards may include role-based and least-privilege access, encryption in transit, encryption at rest where implemented, logging, monitoring, authentication, access reviews, incident-response procedures, business-continuity controls, vendor management, secure development, vulnerability management, and workforce training.
No method of transmission or storage can be guaranteed to be completely secure.
Depending on location and applicable law, an eligible individual may request access, confirmation of processing, correction, deletion, portability, withdrawal of consent, an appeal, a marketing opt-out, or a complaint. Where applicable, rights may also include opting out of sale, sharing, or targeted advertising and limiting sensitive-data use.
Exceptions may apply. Identity verification may be required. Authorized agents may need to provide authority. When Elizian acts as a processor or business associate, the request may be directed to the relevant enterprise customer.
Privacy rights vary by jurisdiction. Where applicable, state law may provide rights to access, correct, delete, or obtain a copy of personal information; opt out of certain sale, sharing, profiling, or targeted advertising; limit certain uses of sensitive information; use an authorized agent; or appeal a decision. Requests may be submitted through the Privacy Request form below.
Privacy rights vary by location. Submit a Privacy Request to exercise rights available under applicable law.
Elizian may process sensitive information only as necessary for authorized customer workflows, contractual services, security, legal compliance, user-directed requests, or other disclosed purposes.
Sensitive information may be subject to HIPAA, state health privacy laws, consumer health-data laws, contractual restrictions, customer instructions, or additional consent requirements. Do not submit patient, member, clinical, or other sensitive health information through general public or marketing forms.
The public website is intended for business and professional audiences and is not directed to children under 13. Elizian does not knowingly collect children’s personal information through public marketing pages without appropriate authorization.
Customer-configured workflows involving children may be governed by customer agreements, applicable law, and authorized adult or organizational participation.
Elizian processes personal information in accordance with applicable law and contractual requirements. Where information is transferred across borders, Elizian and its customers use safeguards appropriate to the transfer and the services involved. Rights and available contact paths may vary by jurisdiction.
The website may link to third-party websites or use embedded services. Elizian does not control those parties’ privacy practices, and their notices may govern their independent collection and use. Users should review relevant third-party notices.
Information may be disclosed or transferred in connection with a proposed or completed merger, financing, acquisition, reorganization, sale of assets, due diligence process, or insolvency, subject to applicable law and contractual restrictions.
Elizian may preserve, use, or disclose information where reasonably necessary to comply with law or valid legal process, respond to regulatory requests, enforce agreements, investigate misuse, protect rights or safety, or address security incidents.
Communications
Elizian may send transactional emails, account notices, security notices, service updates, support messages, and permitted marketing communications. Marketing messages provide an unsubscribe method, but operational, security, contractual, or account messages may continue where necessary.
Incident and Breach Notices
Elizian provides incident and breach notices as required by applicable law and contractual obligations. Healthcare-customer incident obligations may also be governed by Business Associate Agreements and customer contracts.
This policy may be updated to reflect changes in services, practices, law, or contractual requirements. The last-updated date and version will be revised when changes take effect. Material changes may be communicated through reasonable methods, and prior versions may be archived for reference.
Use the contact paths below for privacy requests, security reports, patient or member record requests, accessibility, support, and general inquiries. For information controlled by an Elizian customer, such as a hospital, health plan, provider, or government program, contact that organization directly unless instructed otherwise.
Legal entity: MyWoosah Inc.
Accessibility
info@myelizian.comFor requests concerning patient or member information controlled by a hospital, health plan, provider, government program, or other Elizian customer, contact that organization directly unless instructed otherwise.
