Privacy Policy
Last Updated: September 27, 2026
Our Core Promise: Privacy by Design
RyniX is built on a "Privacy-First" architecture. The RyniX application runs on your hospital's servers, and patient identities stay inside your hospital. To generate the answer your clinician asked for, RyniX sends de-identified clinical context to the analysis service RyniX operates, under a Business Associate Agreement.
1. Introduction
RyniX Inc. ("we," "our," or "us") respects your privacy and is committed to protecting the sensitive healthcare data that our platform processes. This Privacy Policy explains how we collect, use, and safeguard information when you use our Personalized Decision Aide platform.
2. How Our Technology Works
The RyniX application runs on servers your hospital provides and controls. The model that produces the analysis runs on infrastructure RyniX operates. This means:
- RyniX reads your electronic health record read-only, through its FHIR R4 interface, with credentials your hospital issues and can revoke at any time. RyniX never writes to the record.
- Before anything leaves your servers, RyniX removes the patient's name, medical record number, address, telephone number, email address and exact dates. The de-identified clinical context is then sent to infrastructure RyniX operates, under a Business Associate Agreement.
- Whether de-identified information is kept after an answer, and for how long, is set by your hospital before go-live: nothing kept, kept for operations and support only, or kept to improve a model.
- Your data stays yours. RyniX uses your hospital's information to improve a model only with a separately signed permission from your hospital.
3. Information We Collect
We collect minimal information necessary to operate and improve our service:
- Account Information: Name, email address, role, and institutional affiliation of authorized users.
- Usage Metrics: Aggregated data on how the platform is used (e.g., feature adoption rates) to improve user experience.
- Service Quality Data: Ratings clinicians give to suggestions and service performance measures, used to improve RyniX.
4. HIPAA
RyniX signs a Business Associate Agreement with each hospital and is built to support its HIPAA obligations. Patient identities stay on the hospital's servers. De-identified clinical context is processed on infrastructure RyniX operates, under that agreement.
5. Data Security
Security is our foundation. We are committed to regular security reviews and penetration testing to protect the integrity of our platform.
6. Contact Us
If you have any questions about our privacy practices, please contact us at:
RyniX Inc.
info@rynix.ai
