Privacy Policy

Effective Date: July, 2026 

Privacy Policy – Deal Health-AI™ by Prescriptas, Inc.

Prescriptas, Inc. (“Prescriptas,” “we,” “our,” or “us”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and disclose information when you use Deal Health-AI™, our AI-powered SaaS platform (the “Service”). This Policy should be read together with our Terms of Use.

1. Eligibility

The Service is available only to individuals who are at least 18 years of age. We do not knowingly collect personal information from individuals under 18. If we discover that we have collected such information, we will delete it promptly.

2. Information We Collect

We collect information in the following categories:

  1. Account Information: name, email, company, billing and payment information, and login credentials.
  2. Customer Content: information, documents, and inputs submitted or provided by users through the Service, including deal data, uploaded documents, CRM-derived information, conversational interactions with AI-powered features, prompts, instructions, responses, notes, corrections, and other customer-supplied deal context.
  3. Customer Data: refers more broadly to Customer Content together with system-generated data associated with the Customer’s use of the Service.
  4. Usage Data: IP address, device type, browser version, operating system, log data, feature usage, and support interactions.
  5. Cookies and Tracking Data: information collected through cookies or similar technologies (see Section 12).
  6. Other Information: any data you choose to provide through in-app forms, support channels, or communications.
  7. Location Information for Setup Convenience: To simplify setup, the Service may auto-detect your country based on your browser or region settings, or, where necessary, by temporarily using your IP address to determine your approximate location. This information is used solely to pre-populate country or region fields (for example, when selecting a phone country code) and is not stored, logged, or shared. You can always change this selection manually.

3. How We Use Information

We use personal information to:

  1. Provide, operate, and improve the Service.
  2. Process transactions and deliver requested functionality.
  3. Provide customer support and respond to inquiries.
  4. Personalize experiences and deliver tailored content.
  5. Detect, prevent, and address technical or security issues.
  6. Enforce our Terms of Use and comply with legal obligations.
  7. Analyze aggregated and anonymized usage data to improve platform features and system performance.
  8. Send service-related communications, including security alerts, system notifications, and administrative messages.

4. Legal Basis (GDPR)

For Customer Content processed on behalf of business customers, Prescriptas acts as a data processor, and the customer organization acts as the data controller.

For users located in the European Economic Area, United Kingdom, or Switzerland, our legal bases for processing personal data include:

  1. Contract performance: to provide the Service you subscribed to.
  2. Consent: when you opt into certain processing (e.g., marketing communications).
  3. Legal obligations: to comply with applicable law.
  4. Legitimate interests: to improve the Service, secure systems, and support business operations (balanced against your rights).

5. AI-Generated Outputs

Deal Health-AI™ uses artificial intelligence to generate outputs such as recommendations, summaries, insights, and templates.

  1. These AI-generated outputs may be incomplete, inaccurate, or inconsistent. Customers remain solely responsible for reviewing, validating, and determining the appropriateness of AI-generated outputs before relying on them.
  2. AI-generated outputs are produced through automated processing and are not reviewed or verified by Prescriptas personnel prior to delivery to users.

6. Automated Decision-Support and AI Transparency

  1. Deal Health-AI™ uses automated systems, including artificial intelligence and machine learning models, to analyze Customer Content and generate analytical outputs such as insights, recommendations, summaries, and deal health assessments.
  2. These outputs are generated through automated processing and are not independently reviewed or verified by Prescriptas personnel before being delivered to users.
  3. The Service is designed to provide decision-support tools and analytical assistance. It does not make automated decisions that produce legal effects or similarly significant impacts on individuals.
  4. Customers remain solely responsible for evaluating and determining how to use any AI-generated outputs in their business operations.

7. AI Providers & Automatic Model Switching

Deal Health-AI™ uses multiple artificial intelligence model providers (“AI Providers”) to process Customer Content and generate outputs. To ensure reliability, uptime, and performance, Prescriptas may automatically route or re-route Customer Content between AI Providers (“Auto-Pivot”) based on latency, performance thresholds, outages, or other operational conditions.

Customer acknowledges and agrees that:

  1. Use of Multiple Providers: Prescriptas may use any current or future AI Provider, including but not limited to OpenAI, Google, Anthropic, or other providers, without requiring Customer approval.
  2. Automatic AI Routing: The Service may automatically switch between AI Providers without notice when performance or availability issues are detected. This routing is part of normal Service operation.
  3. Processing by AI Providers: Customer Content submitted to AI Providers is processed solely to deliver the Service. Prescriptas does not permit AI Providers to use Customer Content or Customer Data to train, fine-tune, or improve their models. Customer Content is processed solely to deliver the Service to that Customer.
  4. Subprocessors: AI Providers function as subprocessors. Prescriptas maintains an up-to-date list of subprocessors available upon request or through its website.
  5. No Guarantee of a Specific Provider: Prescriptas may add, remove, or substitute AI Providers at any time. Prescriptas does not guarantee that any specific AI model or provider will be used for any request.

8. Protection of Customer Contact Personal Information

  1. Deal Health-AI™ does not use any Customer Content or Customer Data to train, fine-tune, or improve general-purpose artificial intelligence models.
  2. As an added layer of protection, the Service includes an automated data-protection mechanism that removes or masks personally identifiable information (“PII”) related to Customer’s end clients (“Customer Contacts”) before any Customer Content is processed by an AI Provider.
  3. For purposes of this Policy, PII means any information that can identify an individual directly or indirectly, including names, employer names tied to an individual, email addresses, phone numbers, physical addresses, job titles, CRM contact identifiers, account identifiers, or any other data associated with a specific person.
  4. When activated, the PII masking function is designed to remove or mask such information from Customer Content prior to transmission to an AI Provider. Customer Content processed through supported fields and formats is transmitted to AI Providers with identified Customer Contact PII masked or removed.
  5. Customers may activate or deactivate this function if needed. Customers remain responsible for avoiding the intentional or unintentional submission of unmasked PII in unsupported fields or formats.
  6. If Customer elects to not activate this function, Customer acknowledges that personally identifiable information may be transmitted to AI Providers as part of normal Service operation.

9. Sharing of Information

We may share information as follows:

  1. Subprocessors and Service Providers: trusted third-party service providers who host, process, or support our operations. AI model providers used to process Customer Content or Customer Data, including automatic routing between providers to maintain uptime and performance.
  2. Third-Party Integrations: if you choose to connect third-party services (e.g., CRM or email tools), data will be shared as necessary.
  3. Data accessed through authorized third-party integrations, such as CRM systems, is treated as Customer Data and subject to the same privacy, security, and access controls described in this Policy.
  4. Legal Authorities: when required by law, regulation, subpoena, or court order.
  5. Business Transactions: in connection with a merger, acquisition, or sale of assets.

Subprocessors are bound by written agreements to safeguard data. Prescriptas maintains and makes available an up-to-date list of subprocessors upon request or via its website.

10. Data Protection & Residency

  1. Prescriptas has implemented and will maintain appropriate technical and organizational measures to protect Customer Data against unauthorized access, disclosure, alteration, or destruction.
  2. Customer Data will be stored in the country or region corresponding to the Customer’s primary business location, based on the hosting region selected by Prescriptas through its third-party cloud providers. For example, Customer Data from U.S.-based Customers will be stored in U.S. regions, and Customer Data from EMEA-based Customers will be stored in EMEA regions (e.g., Germany for German customers). Prescriptas relies on its cloud providers (such as AWS or Google Cloud) to maintain these regional hosting facilities and adheres to their in-region residency guarantees. Processing by AI Providers occurs within their respective infrastructure and does not alter Prescriptas’ commitment to regional data storage for Customer Data.
  3. Prescriptas will not intentionally move Customer Data outside of the country or region of the Customer’s primary business location except where required by law, necessary to provide the Service, or with the Customer’s prior written consent.

11. Data Retention

We retain Customer Data as long as necessary to provide the Service. Upon termination of the Service, Customer Data will be retained for up to 30 days to allow for final export, after which it may be deleted from active systems. Deleted Customer Data may persist in encrypted backup systems for up to ninety (90) days before final removal in accordance with Prescriptas’ data retention practices. We may retain limited information where required to comply with legal obligations, enforce agreements, or resolve disputes.

12. Data Subject Rights

Depending on your location, you may have rights under applicable data protection laws, including the right to:

  1. Access your data.
  2. Correct inaccurate or incomplete data.
  3. Delete your data.
  4. Restrict or object to processing.
  5. Port your data to another provider.
  6. Withdraw consent where processing is based on consent.
  7. Lodge a complaint with a supervisory authority.

Requests may be submitted to support@prescriptas.com.

13. CCPA & GDPR Compliance

If you are a resident of California, you have rights under the California Consumer Privacy Act (CCPA), including:

  1. The right to know what personal data we collect and how we use it.
  2. The right to request deletion of your personal data.
  3. The right to opt out of the sale or sharing of personal data (Prescriptas does not sell personal data).
  4. The right to non-discrimination for exercising your rights.

If you are located in the European Economic Area, the United Kingdom, or Switzerland, your data is protected under the GDPR or equivalent laws. Prescriptas acts as a data processor for Customer Data and complies with applicable requirements.

Prescriptas does not sell or share personal data for cross-context behavioral advertising purposes.

14. Cookies & Tracking

Some browsers include a “Do Not Track” signal. Because there is not yet a uniform industry standard for responding to such signals, the Service does not currently respond to Do Not Track requests. We use cookies and similar technologies to operate the Service, analyze usage, and improve features. You may disable cookies through your browser settings, but some features may not function properly.

15. Security

  1. We use industry-standard measures to protect Customer Data. However, no system is completely secure, and we cannot guarantee absolute security.
  2. These measures include encryption of data in transit and at rest, logical tenant isolation, role-based access controls, least-privilege access for personnel, and audit logging of system access.
  3. In the event of a confirmed security incident affecting Customer Data, Prescriptas will notify affected Customers without undue delay and in accordance with the security incident notification provisions described in the Terms of Use.

16. Children’s Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from individuals under 18. If such data is identified, it will be deleted promptly.

17. International Data Transfers

Customer Data will remain in the country or region of the Customer’s primary business location. Cross-border transfers will occur only where necessary to provide the Service, required by law, or with Customer’s prior written consent, and will be subject to appropriate safeguards. Where such transfers are necessary, Prescriptas will implement appropriate safeguards, such as Standard Contractual Clauses.

18. Changes to this Policy

We may update this Privacy Policy from time to time. Updated versions will be posted on our website with the effective date clearly indicated. Material changes will be communicated in advance.

19. Additional Disclosures

Customers may request data portability or export of their Customer Data by contacting support@prescriptas.com. Prescriptas will treat Customer Data as confidential and will not disclose it except as provided in this Policy or required by law.

20. Contact Us

Prescriptas, Inc.
Email: support@prescriptas.com
Address: PO Box 16, Hampton Falls, NH 03844

21. Policy Approval Record

Policy: Privacy Policy
Version: 2.0
Approved by: Prescriptas Management
Effective Date: March 2026