Legal
Privacy Policy
Effective 18 August 2026
How Quantino Health AI Inc. handles personal information on this website, in the services we operate for healthcare providers, and in our patient text messaging program.
Quantino Health AI Inc. ("Quantino Health," "we," "us," "our") builds and operates AI infrastructure for healthcare organizations. This policy explains what personal information we collect, why we collect it, who we share it with, and the choices you have.
It covers three things:
- This website,
quantinohealth.com. - The services we operate on behalf of healthcare providers, including AI voice agents that answer patient calls.
- Our patient text messaging program, described in section 4.
1. Two different kinds of information, governed differently
Most of the health information that passes through our systems does not belong to us. When a healthcare provider engages Quantino Health, we act as that provider's business associate under the Health Insurance Portability and Accountability Act (HIPAA). We handle protected health information (PHI) only as that provider instructs, under a written Business Associate Agreement.
That means:
- Patient health information is controlled by the practice, not by us. How it may be used and disclosed is governed by the BAA we signed with that practice and by that practice's own Notice of Privacy Practices — not by this policy. If you are a patient and want to access, correct, or restrict your health record, contact your provider directly; we cannot act on your record without their instruction.
- We do not use PHI for our own purposes. We do not use it to advertise, we do not sell it, and we do not disclose it except as the BAA and HIPAA permit.
This policy governs the information we hold in our own right: website visitor information, business contact information, and the phone numbers and consent records in our messaging program.
2. Information we collect
Information you give us. If you email us, fill in a contact form, or apply for a role, we receive what you send — typically your name, email address, organization, and the content of your message.
Information we receive automatically when you visit this website. Our servers log IP address, browser and device type, referring page, and the pages you requested, along with the date and time. We use this to keep the site running, diagnose faults, and understand which pages are read. This website does not run advertising trackers and does not sell or share visitor information for cross-context behavioral advertising.
Information we process for our provider clients. When we operate a voice agent, messaging, or scheduling workflow for a practice, we process the information needed to do that work — including a patient's name, date of birth, phone number, appointment details, insurance details, account balance, and a recording or transcript of the call. This is PHI, and section 1 governs it.
Messaging program information. For the text messaging program described in section 4, we hold the mobile phone number, the record that consent was given and when, message content and delivery status, and any opt-out.
3. How we use information
We use the information described above to:
- provide, operate, secure, and improve our services and this website;
- respond to your enquiries and provide support;
- send appointment and account notifications on behalf of a practice, where the patient has consented (section 4);
- meet our legal, regulatory, and contractual obligations, including HIPAA;
- detect, investigate, and prevent fraud, abuse, and security incidents.
We do not use automated decision-making to make decisions about you that have a legal or similarly significant effect, and we do not use your information for targeted advertising.
4. Text messaging (SMS) information
We send text messages on behalf of the practices we serve, currently Retina Specialty Institute and Southern Eye Group. Every message is one the patient asked for during a phone call: a secure link to a billing statement, a secure link to make a payment, a payment receipt, or a secure link to complete registration before a first appointment. We send no marketing texts and no unsolicited notifications.
How consent is obtained. Consent is given verbally during a phone call the patient placed to the practice. The patient is asked whether they would like the document or link texted to them, and the agent confirms the destination mobile number out loud before sending. One message is sent per request. Consent is never a condition of receiving care.
What we hold. The mobile number, the record of the request and its date, the messages sent and their delivery status, and any opt-out request.
How to stop. Reply STOP to any message. Reply HELP for help. Full program terms, including message frequency and rate information, are in our Terms of Use.
How mobile information is shared. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are excluded from all information sharing with third parties.
Mobile numbers are disclosed only to the telecommunications providers that carry the message to the recipient's handset, and to the practice on whose behalf the message is sent. That disclosure exists solely to deliver the message you asked for.
5. How we share information
We share personal information only in these circumstances:
- With the healthcare provider whose patient or workflow the information concerns.
- With service providers who work on our behalf — cloud hosting, telecommunications and messaging carriers, AI model providers, and error monitoring. They may use the information only to perform services for us, are bound by contract, and where they handle PHI they are bound by a Business Associate Agreement.
- When the law requires it — to comply with a subpoena, court order, or lawful request from a government authority, or to protect the rights, safety, and property of Quantino Health, our clients, or the public.
- In a corporate transaction — if we are involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. Any recipient remains bound by this policy or one at least as protective, and PHI transfers only as HIPAA permits.
6. We do not sell personal information
We do not sell personal information, and we have not sold personal information in the preceding twelve months. We do not share personal information for cross-context behavioral advertising. We do not sell, rent, or trade patient health information under any circumstances.
7. Security
We encrypt personal information in transit and at rest, restrict access to it on a role-based, need-to-know basis, log administrative access, and keep audit trails for the clinical workflows we operate. We test our systems and review our controls on an ongoing basis.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you send information to us over the internet at your own risk.
8. How long we keep information
We keep personal information for as long as we need it for the purposes in this policy, and then for as long as we are required to keep it by law or by contract. PHI is retained and disposed of according to the instructions in the applicable Business Associate Agreement — the practice, not Quantino Health, sets that schedule. Messaging consent and opt-out records are kept for as long as we operate the program and for a reasonable period afterwards, because we need them to prove that consent was given and honored.
9. Your privacy rights
Depending on where you live, you may have the right to request access to the personal information we hold about you, correct it if it is inaccurate, ask us to delete it, obtain a portable copy, withdraw a consent you previously gave, and not be discriminated against for exercising these rights.
To make a request, email support@quantinohealth.com. We will verify your identity before acting, and we will respond within the time the applicable law allows.
If your request concerns a health record held by a practice we serve, we will refer you to that practice — under HIPAA they, not we, decide such requests.
10. Children
Our website and services are not directed at children under 13, and we do not knowingly collect personal information from them through this website. Where we process a minor patient's health information for a practice, we do so as that practice's business associate under section 1. If you believe a child has given us personal information directly, email us and we will delete it.
11. Where information is processed
Quantino Health is based in the United States and our services are hosted in the United States. If you access this website from outside the United States, you understand that your information will be transferred to and processed in the United States.
12. Changes to this policy
We may update this policy. When we do, we will change the effective date at the top of this page, and we will provide additional notice if the change is material. Continued use of the website or the services after an update means you accept the revised policy.
13. Contact us
Quantino Health AI Inc., 510 Corday Street, Pensacola, FL 32503, United States.
- Privacy requests: support@quantinohealth.com
- General enquiries: hello@quantinohealth.com