Legal

Privacy Policy

This Privacy Policy explains how Elizian and MyWoosah Inc. collect, use, disclose, retain, and protect personal information through the Elizian website, platform interactions, communications, and related services.

Metadata Ledger

Effective
2026-07-30
Last updated
2026-07-30
Version
1.0

Privacy at a Glance

  • A. Privacy at a GlanceWe collect information you provide, information generated through use of our services, and limited technical information.
  • B. Protected Health InformationWe use information to operate, secure, improve, support, and communicate about Elizian.
  • C. Customer InformationWe disclose information to authorized customers, service providers, legal authorities where required, and other parties as described in this policy.
  • D. Protected Health InformationHealthcare customer data may also be governed by customer agreements and Business Associate Agreements.
  • E. Account InformationEligible individuals may have privacy rights depending on their location and applicable law.
  • F. Sensitive InformationWe use reasonable administrative, technical, and organizational safeguards, but no system can be guaranteed completely secure.
  • G. Individual Privacy RightsWe do not publish or expose sensitive healthcare information through public marketing pages.

This summary does not override or replace the complete policy below.

02.

Scope

“Elizian,” “we,” “us,” and “our” refer to MyWoosah Inc. when operating the Elizian website, platform, services, and related communications. Elizian is the enterprise healthcare execution platform developed, owned, and operated by MyWoosah Inc.

This policy applies to personal information collected through the Elizian public website, resource center, contact and briefing forms, operational assessment forms, marketing communications, events and webinars, customer and prospective-customer communications, platform account administration where not otherwise governed by customer contracts, support communications, job-applicant interactions where applicable, and website technologies.

  • Customer agreements, Business Associate Agreements, employment or contractor policies, provider agreements, separate notices presented at collection, customer-controlled patient or member portals, and third-party websites may be governed separately.
03.

Protected Health Information and Customer Data

The public website Privacy Policy generally governs personal information collected through Elizian public website and marketing pages, resource downloads, forms, communications, cookies, and similar interactions.

When Elizian processes protected health information on behalf of a healthcare customer acting as a covered entity or another business associate, processing may be governed by the customer agreement, a Business Associate Agreement, applicable healthcare privacy and security requirements, customer instructions, and other contractual documentation.

The customer organization may be the appropriate party to contact about patient or member records, access to or amendment of protected health information, restrictions, accounting of healthcare disclosures, and other HIPAA rights.

This Privacy Policy does not replace a customer’s HIPAA Notice of Privacy Practices. If this policy conflicts with a signed Business Associate Agreement concerning protected health information, the applicable signed agreement governs to the extent of the conflict. Not all Elizian data is protected health information, and HIPAA does not apply to every website visitor or interaction.

04.

Information We Collect

The categories collected depend on the interaction, configured customer deployment, and signed agreements.

A. Information You Provide

  • Name, business email, telephone number, job title, organization, organization type, state or region, message content, operational challenge, requested resource or assessment, event registration information, account credentials, support requests, communications preferences, and job-application materials where applicable.

B. Account and Enterprise User Information

  • User identity, organization, role, permissions, authentication data, login activity, account status, support history, and audit events.

C. Technical and Usage Information

  • IP address, browser and device type, operating system, referring page, pages viewed, date and time, click activity, session information, error logs, performance data, security events, and approximate location derived from IP where permitted.

D. Customer-Submitted Data

Enterprise customers may submit or direct Elizian to process information relating to patients, members, providers, employees, caregivers, family members, case workflows, referrals, authorizations, services, and operational communications. Precise categories depend on the configured deployment and signed agreements.

E. Sensitive Information

Where required for an authorized service, information may include health or disability information, government identifiers, financial information, authentication credentials, geolocation where enabled, information concerning children or dependents, or other legally defined sensitive personal information.

F. Information from Third Parties

  • Enterprise customers, authorized administrators, integration partners, identity providers, referral sources, event partners, service providers, public business sources, and customer-authorized systems.
05.

How We Collect Information

Collection sources depend on the services and integrations actually enabled for the relevant interaction or customer environment.

  • Forms and account creation.
  • Platform use and customer-authorized workflows.
  • Customer integrations, secure file transfers, APIs, and single sign-on.
  • Email, telephone, customer support, resource downloads, and events.
  • Active cookies, website technologies, security monitoring, and authorized third parties.
06.

How We Use Information

For customer-controlled data, Elizian may process information according to customer instructions and signed agreements.

  • Operate, provide, and configure Elizian customer deployments.
  • Authenticate and administer users; route and manage authorized workflows.
  • Communicate with customers and users, respond to inquiries, and provide support.
  • Process briefing and assessment requests and deliver requested resources.
  • Improve website usability, maintain security, detect fraud or misuse, monitor performance, and conduct authorized analytics.
  • Meet contractual and legal obligations, enforce agreements, protect rights and safety, and conduct corporate administration.
  • Evaluate job applicants where applicable; send permitted marketing communications; maintain opt-out and suppression records.
07.

How We Disclose Information

Elizian does not make customer data freely available across organizations. Disclosure depends on configured permissions, workflow, customer instructions, applicable law, and agreements.

A. Enterprise Customers and Authorized Users

Information may be disclosed within the applicable customer organization and to users authorized under its configured roles and permissions.

B. Service Providers and Subprocessors

Service providers may support cloud hosting, identity management, communications, customer support, security, analytics, document management, payment processing where applicable, integrations, and professional advice. They are expected to process information only for authorized purposes and under applicable contractual obligations.

C. Healthcare and Service-Delivery Participants

Where configured and authorized, information may be made available to relevant hospitals, health plans, providers, agencies, care teams, community organizations, transportation or equipment providers, and other authorized participants.

E. Corporate Transactions

  • Potential merger, financing, acquisition, reorganization, sale of assets, due diligence, or insolvency.
08.

Cookies and Tracking Technologies

Elizian uses technologies that are active and configured for the relevant context. These may include strictly necessary, security, functional, analytics, advertising, embedded-content, or session-replay technologies. Where consent is required, nonessential technologies remain inactive until consent is provided.

Advertising pixels, session replay, and analytics technologies are not used in authenticated or health-related areas unless appropriate privacy, security, and contractual safeguards apply. Technology configurations may differ across public marketing pages, resource pages, briefing forms, authenticated platform pages, patient or member workflows, and customer-specific environments.

CategoryPurposeProvider / TechnologyDurationStatus
Strictly necessary and securityMaintain website operation, session continuity, authentication where used, and security.Elizian service environment
Session and security technologies
Session or as required for security and account continuityActive

Sale, Sharing, and Targeted Advertising

Elizian provides privacy choices and opt-out mechanisms where required by applicable law. Available requests may be submitted through the Privacy Request form.

09.

Artificial Intelligence and Automated Processing

Where configured and authorized, Elizian may use automated tools to assist with summarization, classification, requirement extraction, workflow prioritization, provider-match recommendations, risk identification, communication drafting, and operational insights.

AI outputs may require human review. AI does not replace licensed clinical judgment and does not independently make medical-necessity decisions, payer authorization decisions, or employment or supervision decisions for providers. Customer configurations may differ, and personal information used with AI tools is subject to applicable agreements and controls.

Elizian does not use Customer Data to train generalized AI models unless expressly authorized by the customer in a signed agreement. Personal information used for product improvement, analytics, or AI-assisted processing remains subject to applicable contractual, privacy, and security controls.

10.

Data Retention

Elizian retains personal information only for as long as reasonably necessary for the purposes described in this policy, to provide services, satisfy contractual obligations, resolve disputes, maintain security, and comply with law. Retention periods vary by information type, context, customer instructions, and legal requirements.

When deletion is required, information may be removed or de-identified from active systems subject to applicable agreements and law. Residual copies may remain in protected backups until routine rotation or may be preserved where legally required.

Information categoryPublished retention periodBasis
Marketing leadsAs long as reasonably necessaryOperational, contractual, and legal requirements
Resource requestsAs long as reasonably necessaryOperational, contractual, and legal requirements
Account informationAs long as reasonably necessaryOperational, contractual, and legal requirements
Security logsAs long as reasonably necessaryOperational, contractual, and legal requirements
Customer dataAs long as reasonably necessaryOperational, contractual, and legal requirements
Support recordsAs long as reasonably necessaryOperational, contractual, and legal requirements
Job applicationsAs long as reasonably necessaryOperational, contractual, and legal requirements
Consent recordsAs long as reasonably necessaryOperational, contractual, and legal requirements
Cookie recordsAs long as reasonably necessaryOperational, contractual, and legal requirements
Legal holdsAs long as reasonably necessaryOperational, contractual, and legal requirements
11.

Data Security

Elizian uses reasonable administrative, technical, and organizational safeguards appropriate to the information and service. Depending on implementation, safeguards may include role-based and least-privilege access, encryption in transit, encryption at rest where implemented, logging, monitoring, authentication, access reviews, incident-response procedures, business-continuity controls, vendor management, secure development, vulnerability management, and workforce training.

No method of transmission or storage can be guaranteed to be completely secure.

Visit the Trust Center
12.

Individual Privacy Rights

Depending on location and applicable law, an eligible individual may request access, confirmation of processing, correction, deletion, portability, withdrawal of consent, an appeal, a marketing opt-out, or a complaint. Where applicable, rights may also include opting out of sale, sharing, or targeted advertising and limiting sensitive-data use.

Exceptions may apply. Identity verification may be required. Authorized agents may need to provide authority. When Elizian acts as a processor or business associate, the request may be directed to the relevant enterprise customer.

Submit a Privacy Request

Please do not submit patient, member, clinical, or other sensitive health information through this public form.

13.

State-Specific Privacy Rights

Privacy rights vary by jurisdiction. Where applicable, state law may provide rights to access, correct, delete, or obtain a copy of personal information; opt out of certain sale, sharing, profiling, or targeted advertising; limit certain uses of sensitive information; use an authorized agent; or appeal a decision. Requests may be submitted through the Privacy Request form below.

Privacy rights vary by location. Submit a Privacy Request to exercise rights available under applicable law.

14.

Healthcare and Sensitive Information

Elizian may process sensitive information only as necessary for authorized customer workflows, contractual services, security, legal compliance, user-directed requests, or other disclosed purposes.

Sensitive information may be subject to HIPAA, state health privacy laws, consumer health-data laws, contractual restrictions, customer instructions, or additional consent requirements. Do not submit patient, member, clinical, or other sensitive health information through general public or marketing forms.

15.

Children’s Privacy

The public website is intended for business and professional audiences and is not directed to children under 13. Elizian does not knowingly collect children’s personal information through public marketing pages without appropriate authorization.

Customer-configured workflows involving children may be governed by customer agreements, applicable law, and authorized adult or organizational participation.

16.

International Visitors and Data Transfers

Elizian processes personal information in accordance with applicable law and contractual requirements. Where information is transferred across borders, Elizian and its customers use safeguards appropriate to the transfer and the services involved. Rights and available contact paths may vary by jurisdiction.

17.

Third-Party Services and Links

The website may link to third-party websites or use embedded services. Elizian does not control those parties’ privacy practices, and their notices may govern their independent collection and use. Users should review relevant third-party notices.

18.

Business Transfers

Information may be disclosed or transferred in connection with a proposed or completed merger, financing, acquisition, reorganization, sale of assets, due diligence process, or insolvency, subject to applicable law and contractual restrictions.

20.

Updates to This Policy

This policy may be updated to reflect changes in services, practices, law, or contractual requirements. The last-updated date and version will be revised when changes take effect. Material changes may be communicated through reasonable methods, and prior versions may be archived for reference.

21.

Contact Us

Use the contact paths below for privacy requests, security reports, patient or member record requests, accessibility, support, and general inquiries. For information controlled by an Elizian customer, such as a hospital, health plan, provider, or government program, contact that organization directly unless instructed otherwise.

Legal entity: MyWoosah Inc.

Accessibility

info@myelizian.com

For requests concerning patient or member information controlled by a hospital, health plan, provider, government program, or other Elizian customer, contact that organization directly unless instructed otherwise.