Privacy Policy – Periscope
1.Introduction and Scope
The Periscope Group provides software platform used by HIPAA-covered entities and their business associates (our "Clients"). This Privacy Policy describes how we collect, use, and protect information from visitors to our public website at periscope365.com (the "Site").
This policy applies only to information collected through the Site itself — for example, when you browse our public pages, request a demo, submit a contact form, subscribe to communications, or apply for a job. Our platform does not provide member-facing login functionality. Individuals do not create accounts, log in, or submit personal health information directly through the Site.
Protected Health Information ("PHI") processed within the Periscope platform on behalf of our clients are governed exclusively by the Business Associate Agreement ("BAA") executed with each client and by applicable law (including HIPAA and HITECH), not by this Site policy. If you are a member or member of one of our clients and have questions about how your health information is handled, please contact that organization directly; Periscope acts as a business associate and does not have a direct relationship with, or independent right to use, client data outside of its client instructions.
2.Information We Collect on the Site
2.1 Information You Provide Directly
We collect information you choose to submit through the Site, such as when you:
- Request company or service information
- Submit a general contact, support, or inquiry
- Subscribe to a newsletter, webinar, or other marketing communication
- Apply for employment or submit a resume through a careers page or linked applicant tracking system
- Respond to a survey or questionnaire
This may include your name, business email address, phone number, job title, employer/organization name, and the content of any message you send us. We do not request or knowingly collect Social Security numbers, financial account numbers, or health information through these forms.
2.2 Information Collected Automatically
Like most websites, the Site automatically collects limited technical information when you visit, including:
- IP address and approximate geographic location
- Browser type, operating system, and device characteristics
- Pages viewed, referring/exit pages, and timestamps
- Cookie and similar tracking identifiers
This information is used in aggregate for analytics, security, and site-performance purposes and is not linked to an individual’s record.
2.3 Information We Do Not Collect Through the Site
Because the Site has no member login portal, we do not collect:
- Protected Health Information (PHI) as defined under HIPAA
- Portal credentials, record numbers, or clinical data
- Insurance, billing, or claims information belonging to an individual
3.Cookies and Tracking Technologies
We use cookies, pixels, and similar technologies to operate the Site, remember preferences, understand aggregate traffic patterns, and support marketing analytics (for example, measuring the effectiveness of a campaign that led a visitor to request a demo). Categories of cookies may include:
- Strictly necessary cookies required for core site functionality
- Performance and analytics cookies (e.g., aggregated usage statistics)
- Functional cookies that remember display or language preferences
- Marketing/advertising cookies used to measure campaign performance
You can control or disable most cookies through your browser settings. Disabling certain cookies may affect Site functionality. Where required by law, we will present a cookie consent banner allowing you to accept or reject non-essential cookies before they are set. We may use third party analytics or marketing tools. Where such tools process personal information on our behalf, we require appropriate contractual protections. In cases where a tool could receive information that might be considered PHI, under applicable guidance, we either (a) ensure a Business Associate Agreement is in place, (b) configure the tool to minimize or de-identify data, or (c) limit its use to non-PHI contexts. We do not permit tracking technologies on the Site to collect or transmit PHI.
4. How We Use Site Information
We use information collected through the Site to:
- Respond to inquiries and provide requested materials (e.g., demos, pricing, whitepapers)
- Operate, maintain, and improve the Site's functionality and security
- Communicate with prospective Clients and job applicants
- Conduct aggregate analytics on Site traffic and engagement
- Comply with legal, regulatory, contractual, and audit obligations
- Detect, investigate, and prevent fraud, abuse, or security incidents
We do not use Site visitor information to make eligibility, coverage, treatment, or other healthcare decisions about any individual.
5. How We Share Information
We do not sell personal information collected through the Site. We may share it with:
- Professional advisors (legal, audit, insurance) as needed
- Regulators, courts, or government authorities where required by law or legal process
- A successor entity in connection with a merger, acquisition, financing, or sale of assets
Any such sharing is limited to Site visitor/business-contact information described in Section 2 and is separate from, and does not include, Client PHI processed under our platform BAAs.
6. Business Associate and Covered Entity Relationships
Periscope supports covered entities and other business associates by hosting and processing PHI within isolated environments as part of our platform services. With respect to that platform data:
- Each Client relationship is governed by a signed Business Associate Agreement consistent with 45 C.F.R. Part 164, Subpart E
- PHI is processed strictly according to Client instructions and the applicable BAA, and is not used for Periscope's own marketing, Site analytics, or business development purposes
- Technical, administrative, and physical safeguards (e.g., encryption, access controls, audit logging, tenant isolation) apply to platform environments as described in our security documentation, available to Clients upon request
This Site Privacy Policy does not modify, limit, or supersede the terms of any executed BAA or Master Services Agreement, which govern in the event of any conflict regarding PHI.
7. Data Retention
We retain Site visitor information for as long as reasonably necessary to fulfill the purposes described in this policy, including responding to your inquiry, maintaining business records, and meeting legal, accounting, or reporting obligations. Marketing contact information is retained until you request deletion, subject to suppression-list retention needed to honor that request.
8. Your Privacy Choices and Rights
Depending on your location, you may have rights with respect to the personal information we hold about you as a Site visitor, which may include the right to:
- Request access to, or a copy of, the information we hold about you
- Request correction of inaccurate information
- Request deletion of your information, subject to legal and contractual exceptions
- Object to or restrict certain processing, where applicable law provides that right
To exercise any of these rights regarding Site visitor information, contact us using the details in Section 12. If you are a member of one of our clients seeking to exercise HIPAA rights (such as access to your medical record), please contact that healthcare organization directly, as Periscope is not the HIPAA covered entity for that data and will not release any data directly to members.
9. Children's Privacy
The Site is intended for business audiences — healthcare organizations, prospective clients, and job applicants — and is not directed to children. We do not knowingly collect personal information through the Site from individuals under 16 years of age.
10. Third-Party Links
The Site may contain links to third-party websites (for example, a careers/applicant-tracking portal, a scheduling tool, or a social media page). This Policy does not apply to those third-party sites, and we encourage you to review their respective privacy policies.
11. Security
We maintain administrative, technical, and physical safeguards designed to protect Site visitor information against unauthorized access, disclosure, alteration, or destruction. These safeguards include encryption of data in transit (TLS), access controls and regular security assessments. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise a privacy right described above, please contact: The HIPAA Privacy Officer: robin.eitland@periscope365.com The Security Officer: mike.birkhead@periscope365.com
13. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or applicable law. The "Effective Date" at the top of this Policy indicates when it was last revised. Material changes will be posted on this page, and where appropriate, we will provide additional notice.