Privacy Policy

Effective date: July 3, 2026

The short version

We collect the minimum we need to run the Service. Patient health information belongs to your practice and is handled under HIPAA and a Business Associate Agreement. We run no advertising trackers, we do not sell personal information, and our AI providers may not train on your data.

1. Two roles, two rulebooks

PHI (patient data inside the Service). Here AxonTron, Inc. acts as a Business Associate of your healthcare practice (the covered entity). The practice controls this data; we process it only per our BAA and the practice's instructions. Patients: your practice's own Notice of Privacy Practices governs how your health information is used — contact your practice for requests about your medical records.

Website and account data. For visitors to axontron.com and for practice staff accounts, AxonTron acts as the data controller of basic account and usage information described below.

2. What we collect

Account data: name, work email, role, and practice affiliation — provided by you or your administrator. Service telemetry: security logs (sign-ins, approvals, administrative actions) and operational logs needed to run and audit the Service; request logs are designed to exclude PHI. Website: only essential cookies (see the Cookie Policy); no analytics or advertising trackers are active today. Voice assistants: conversations with the public “Ask AxonTron” assistant are processed to answer your question and improve the assistant's prompts; don't share medical details there.

3. How we use information

To provide, secure, and support the Service; to meet legal and contractual obligations (including HIPAA); to communicate service and security notices; and to improve the product using de-identified, aggregated operational metrics. We do not sell personal information and do not use it for third-party advertising.

4. AI processing

AI features run on enterprise model providers under agreements that prohibit using your data to train their models. Every AI output that matters clinically or financially passes a human approval gate, and all agent actions are recorded in the audit trail.

5. Sharing

We share data only with: subprocessors that host and operate the Service (cloud infrastructure, model providers, telephony/voice, payments) under contracts at least as protective as ours; your practice (for account and audit data); and authorities when the law requires it. A current subprocessor list is available on request.

6. Security & retention

Encryption in transit and at rest, tenant isolation, role-based access, and an append-only audit trail — detailed on the security page. We retain data for as long as the customer relationship lasts plus the periods in the Data Deletion Policy, or as law requires.

7. Your choices and rights

Staff can view and correct account data in the app or via their administrator. Depending on where you live you may have rights to access, correct, delete, or port personal information — email support@axontron.com and we'll respond within 30 days. For PHI, we will route requests to your practice, as HIPAA requires. The Service is not directed at children; patient-portal accounts for minors are managed by the practice.

8. Changes and contact

Material changes will be posted here with a new effective date and notified to practice administrators. Contact: support@axontron.com · AxonTron, Inc., Newark, Delaware, USA.