Privacy Policy
Effective 2026-05-10 · Review cadence: annual
Agilis Inspections is a multi-hospital facilities-inspection platform operated by Agilis Inc. (“Agilis,” “we,” “us”). This policy describes what information we collect, how we use and protect it, and the rights you have over it. Internal controls referenced below are documented in the Agilis Information Security Program and operate under a SOC 2-aligned posture.
We do not sell personal information. We do not use customer data for advertising, behavioral profiling, or to train third-party machine-learning models on identifiable content.
1. Who is the data controller
For inspection records and other customer-submitted content, the customer organization (the hospital or health system that licenses Agilis Inspections) is the controller of personal information. Agilis acts as a processor / service provider / business associate on the customer's behalf, under the terms of the customer's subscription agreement and, where applicable, a Data Processing Addendum (DPA) or HIPAA Business Associate Agreement (BAA).
For the small amount of information Agilis collects in its own right (account credentials, support tickets, billing contacts), Agilis is the controller.
2. Information we collect
- Account identifiers — verified email address, display name, role, and the hospital(s) / tenant(s) you are assigned to. Authentication is handled by Supabase Auth; passwords are never stored or transmitted in plaintext and are never logged.
- Inspection content you submit — equipment lists, inspection forms, scoring, comments, responsible-party assignments, dates, work orders, and uploaded evidence (photos, documents, attachments).
- Compliance and AgilisAI content — chapter/EP scores, sub-chapter notes, AI-review results on documents you opt into reviewing, and the document repository associated with each EP.
- Operational telemetry — authentication events (login, logout, role change, lockout), authorization decisions, privileged actions, role grants/deactivations, data exports, and related security events. Each entry records who, what, when, and outcome, with before/after values where feasible.
- Device and connection metadata — IP address, browser/device fingerprint information limited to what is needed for session security and fraud/abuse detection.
- Support correspondence — emails or messages you send to Agilis about your account or the platform.
We do not knowingly collect information about patients. Agilis Inspections is a back-of-house facilities tool; customers should not upload patient-identifying information into inspection records, and uploaded evidence should be redacted of PHI before submission. Where a customer's use case is within HIPAA scope, a BAA is executed before any PHI is processed.
3. How we use information
- To provide, secure, and operate the Agilis Inspections platform for your organization.
- To authenticate users, enforce role-based access control, and prevent unauthorized access (including account lockout after repeated failed sign-ins).
- To produce the audit trail required for SOC 2-aligned operations and for the customer's own regulatory evidence (e.g., Joint Commission, CMS, state surveys).
- To respond to your support requests and to notify you about service-impacting events.
- To investigate suspected security incidents and to comply with legal obligations (subpoenas, court orders, and regulatory directives we are required to honor).
- To improve the platform in aggregate — for example, identifying performance regressions or feature usage patterns — using de-identified or aggregated data only.
We do not use customer-submitted content to train generative-AI models. Where the platform offers AI features (for example, AI-assisted document review), inputs are sent to a contracted vendor (currently OpenAI) under terms that prohibit use of those inputs for model training. AI feature use is governed by our internal AI Governance Policy.
4. How we protect information
Customer inspection data is classified RESTRICTED under our internal Data Classification Policy. Protective controls include:
- Tenant isolation by Row-Level Security (RLS). Every customer-data table in the database has RLS policies that restrict rows to the requesting user's tenant. RLS is enforced at the database layer and cannot be bypassed by a compromised client.
- Encryption at rest. All managed databases and object storage are encrypted at rest with AES-256.
- Encryption in transit. TLS 1.2 or higher is enforced on all production endpoints, including client-to-server, edge functions, CI/CD traffic, and webhook deliveries. HSTS is set on the application front-end.
- Server-verified identity. Every privileged operation re-validates the user's identity server-side rather than trusting client-supplied claims.
- Multi-factor authentication. Required for all Agilis personnel on production systems and for all privileged application roles. Customers may enable MFA for their own users; enterprise customers may federate via SAML/OIDC SSO and inherit the IdP's MFA policy.
- Account lockout. Application accounts lock for 15 minutes after 5 consecutive failed sign-in attempts within a 15-minute window.
- Idle session timeout. Authenticated sessions automatically sign out after 15 minutes of inactivity, with a 60-second in-app warning.
- Append-only audit log with integrity chain. Access to RESTRICTED data is recorded in an append-only audit table with an MD5 hash chain that detects silent tampering. Privileged-user activity is reviewed weekly.
- Least privilege and need-to-know. Agilis personnel receive the minimum access needed. Production access is disabled by default and granted only with documented justification, time-bounded scope, and full logging. Access is reviewed quarterly.
- Secure software lifecycle. Source is in a protected GitHub repository with required reviews, required status checks, secret scanning, and dependency audits in CI. Secrets are stored only in CI secret managers, never in source.
No control is perfect. If you believe you have found a security issue, please follow our Security Policy and report it privately.
5. Subprocessors
We use a small set of contracted vendors to deliver the platform. Each undergoes annual security review under our Vendor Management Policy and is contractually bound to confidentiality, encryption-at-rest and in-transit, access-control, and incident-notification obligations.
- Supabase — managed Postgres database, authentication, object storage, edge functions. Tier 1 (critical).
- Microsoft Azure — hosting of the web front-end (Azure Static Web Apps). Tier 1.
- GitHub — source-code hosting and CI/CD. Tier 1.
- Resend — transactional email (account verification, password reset, system notifications). Tier 2.
- OpenAI — optional AI-assisted document review features. Inputs are sent under terms that prohibit training on customer data. Tier 2.
We will provide reasonable advance notice before adding or replacing a subprocessor that materially changes where customer data is processed. Customer-specific subprocessor lists are available on request to enterprise customers.
6. Data location and transfers
Customer data is stored in the United States in our managed Supabase project, with logical replication to a Supabase-managed disaster-recovery region per our Backup Policy. Where a customer requires a different data residency, the customer should contact us before contracting.
7. Retention and deletion
Retention follows our internal Data Deletion Policy. Baseline schedule:
- Active customer data — retained for the life of the account, plus a 90- to 180-day grace period after voluntary closure to permit reactivation or export.
- Audit logs — 90 days online today, with a roadmap to ship to a SIEM with one-year-plus retention.
- Backups — 30-day rolling window, managed by the underlying database provider.
- Security incident records and SOC 2 evidence — up to 7 years for incident records, 3 years for routine access-review evidence.
On a verified customer request to delete personal information, we remove the data from the live platform within 30 days and from backups within the backup-rotation window (30 days). We confirm completion to the requester. Deletion is paused only where a legal hold or overriding regulatory-retention requirement applies, and we will tell you when that is the case.
8. Your rights
Depending on where you live and the role under which we hold your information, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate or incomplete information;
- request deletion of your information;
- request a portable copy of your information;
- opt out of the sale or sharing of personal information (we do not sell or share for cross-context advertising);
- limit the use of sensitive personal information;
- withdraw consent where processing is based on consent;
- lodge a complaint with a supervisory authority.
For inspection content uploaded by your employer, please direct rights requests to your organization first, as they are the controller of that data. Agilis will support the controller in fulfilling the request. For information Agilis controls directly (your account, support tickets), contact us using the address below.
9. Cookies and similar technologies
We use only the cookies and browser-storage entries required for authenticated sessions, security (CSRF, idle timeout coordination across tabs), and basic preferences. We do not use third-party advertising or cross-site tracking cookies.
10. Children
Agilis Inspections is a workplace tool licensed by hospitals to their employees and contractors. It is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us so we can delete it.
11. Incident notification
Where a confirmed security incident affects customer data or service availability, Agilis notifies affected customers in line with our Incident Response Plan and the notification SLAs in the customer's subscription agreement (or BAA, where one is in place). Vulnerability-research disclosures are handled under our Security Policy.
12. Changes to this policy
We may update this policy as the platform, our vendors, or applicable law evolves. Material changes are communicated to active customer administrators by email at least 30 days before they take effect, except where a faster change is required by law or to address a security risk. The effective date at the top of this page indicates the latest version. Prior versions are available on request.
13. Contact
For privacy questions, rights requests, or to request a DPA / BAA, contact agilis@agilisinc.com. For security reports, please use our Security Policy and the contacts published at /.well-known/security.txt.
