Privacy Notice
Last updated: August 3, 2026
1. Introduction
Optimize AI Tech ("Optimize AI", "we") builds Medical Copilot, a Clinical Documentation & Coding Intelligence platform for healthcare organizations. This notice explains what information we process, why, and the rights available to you. It covers both visitors to this website and the data we process on behalf of our healthcare clients through the Medical Copilot platform.
2. Data We Process on Behalf of Healthcare Clients
Medical Copilot processes clinical encounter documentation on behalf of healthcare organizations, under written agreements with those organizations. Where United States law applies, we act as a Business Associate under HIPAA and execute Business Associate Agreements with our clients.
We follow strict data minimization. To perform documentation and coding review, the platform processes:
- Clinical encounter documentation, orders, results, and service descriptions provided by the client's system
- Encounter identifiers, which are encrypted at rest
- Limited demographic details needed for correct coding, such as date of birth or age and sex
We do not deliberately collect or store patient names, addresses, contact details, social security or national identity numbers, or medical record numbers. Where clinical free text supplied by a client contains identifying details, that text is protected with the same safeguards as all clinical data.
3. Safeguards
All clinical data is protected through:
- Encryption in transit and encryption of stored identifiers at rest
- Role-based access controls, user-session security, and organization-level data isolation
- A per-access audit log of every access to protected health information, recorded with hashed identifiers
- A complete decision audit trail covering queries, responses, and reviewer actions
- Regular security assessment of our practices
4. Artificial Intelligence Processing
Medical Copilot uses artificial intelligence to analyze documentation and suggest clarifications and codes. AI output is advisory: it is reviewed and confirmed by qualified professionals at the client before any use, and every recommendation carries its source text and rationale. We do not use client clinical data to train models for other clients, and processing by any technology subcontractor takes place under data-protection agreements consistent with this notice.
5. Website Data We Collect Directly
On this website we collect:
- Contact and demo requests. When you submit our contact form, we store the details you provide (such as name, work email, phone, and company) and receive them by email, in order to respond to you.
- Scheduling. Demo bookings are scheduled through Microsoft Bookings, which processes the details you enter under Microsoft's privacy terms.
- Analytics and security. We use Google Analytics to understand site usage and Google reCAPTCHA to protect our forms. These services set cookies and process technical data such as IP address and browser information under Google's privacy terms. We do not run advertising or social-media tracking pixels on this site.
- Business contact information. We process professional contact details of prospective clients for business-to-business communication. You may opt out of marketing communication at any time using the unsubscribe option in our messages or by contacting us.
6. How We Use Information
- Provide documentation review, clarification queries, and coding support to our clients
- Maintain audit trails required for compliance, appeal, and payer review
- Improve the reliability and accuracy of the platform
- Respond to enquiries and manage client relationships
- Meet our legal and contractual obligations
7. Data Retention
Clinical data processed for clients is retained according to the client agreement and applicable healthcare regulations, and is returned or deleted when the agreement ends. Website enquiry data is kept only as long as needed to handle the enquiry and any resulting relationship.
8. Legal Frameworks and Your Rights
We align our practices with the privacy laws of the markets we serve, including HIPAA in the United States, the EU and UK GDPR, the Saudi Personal Data Protection Law (PDPL), the UAE Personal Data Protection Law, and applicable US state privacy laws such as the California Consumer Privacy Act.
Depending on the law that applies to you, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Object to or restrict processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with your supervisory authority
For patient data processed on behalf of a healthcare client, requests should be directed to that healthcare organization, which controls the data; we support our clients in fulfilling them.
9. Contact Information
For privacy-related inquiries, contact our Data Protection Officer at: privacy@medcopilot.co