This Privacy Policy ("Privacy Policy") covers "Personal Information" collected by Medaflo from clients, third parties at the direction of users, and client systems as well as through the operation of websites, mobile applications, and software by Medaflo, LLC and its affiliates and subsidiaries ("Medaflo," "we," and "us"), including the medaflo.com domain and its subdomains (collectively "Medaflo Service"). The Privacy Policy describes how Medaflo collects, uses, and discloses "Personal Information."
"Personal Information" means information that alone or when in combination with other information may be used to readily identify, contact, or locate you, such as: name, address, email address, phone number, date of birth, and medical record or insurance-issued ID numbers. "Personal Information" also includes identifiable health information collected about you. We do not consider Personal Information to include information that has been anonymized so that it does not allow a third party to easily identify a specific individual.
If you are a Medaflo client, your written agreement with us, including any Business Associate Agreement, governs our handling of the information you submit through the Medaflo Service. Where that agreement conflicts with this Privacy Policy, the agreement controls.
Medaflo provides health service providers and medical sales representatives with the Medaflo Service to manage pharmaceutical samples, medical product and device inventory, vendor credentialing, clinic access and scheduling, dispensing records, compliance documentation, and related administrative activities. Other than information gathered through our public marketing website, Medaflo acts as a service provider for health service providers and medical sales representatives and does not own or control the information that is submitted to us through the Medaflo Service. The information that is submitted through the Medaflo Service will be held subject to the requirements specified by our health service provider and medical sales representative clients, as well as applicable law, such as the Health Insurance Portability and Accountability Act (HIPAA).
This Privacy Policy does not reflect the privacy practices of Medaflo's health service provider or medical sales representatives clients and Medaflo is not responsible for our clients' privacy policies or practices. Medaflo does not review, comment upon, or monitor our health service provider or medical sales representatives clients' privacy policies or their compliance with their respective privacy policies, nor does Medaflo review our client's instructions to determine whether they are in compliance or conflict with the terms of a client's published privacy policy or applicable law.
The Medaflo Website. You may visit the websites of Medaflo without revealing any Personal Information. However, in some instances, Medaflo may require certain Personal Information, such as business contact information, so we can respond to your inquiries or provide you with requested information.
The Medaflo Service. The Medaflo Service may collect information, including Personal Information and health information, about you from a health service provider.
Customer Support. We may collect Personal Information through your communications with our customer-support team.
Cookies, Automatic Data Collection, and Related Technologies. Medaflo and our third-party partners, such as analytics service providers, may automatically receive and record certain non-Personal Information from users using cookies, web beacons, server logs and other similar tools. For example, Medaflo may collect information about how you visit and navigate through the Medaflo Service, when you click on a link or open a web page, use certain elements of the Medaflo Service, or open an email sent by Medaflo. Medaflo may use this information to provide certain functionality, improve the tools and services, and monitor the use of the tools and services. For example, we use these tools to save user preferences, preserve session settings and activity, help authenticate users, allow users to auto-fill sign-in pages of websites they frequently visit, and debug and evaluate the performance of the Medaflo Service. Our partners also may collect such information about your online activities over time and on other websites or apps. You may be able to change browser settings to block and delete cookies when you access the Medaflo Service through a web browser. However, if you do that, the Medaflo Service may not work properly.
Browser Privacy Signals. Some browsers offer a "Do Not Track" signal. Because there is not currently a uniform industry standard for interpreting that signal, the Medaflo Service does not respond to browser Do Not Track signals. Where applicable law requires us to recognize an opt-out preference signal, such as the Global Privacy Control, we treat the signal as a request to opt out of the sale or sharing of Personal Information or its use for targeted advertising for the browser or device from which the signal is sent. Medaflo does not currently sell or share Personal Information as those terms are defined by the California Consumer Privacy Act. Browser privacy signals do not prevent the use of cookies and similar technologies that are necessary to operate, authenticate, secure, or maintain the Medaflo Service, and they may not prevent all collection by third parties.
Internal and Service-Related Usage. We use information, including Personal Information, for internal and service-related purposes and may provide it to third parties to allow us to facilitate the Medaflo Service. We may use and retain data we collect to provide, secure, support, and maintain our services, subject to the limits described in this Privacy Policy, our client agreements, and applicable Business Associate Agreements.
For example, we may use Personal Information for the following purposes:
Consents and Authorizations. Medaflo may request your consent or authorization in connection with the use or sharing of Personal Information about you. In some instances, this will be because this Privacy Policy or applicable law or regulations require us to obtain such consent. In other instances, such consent will be for informational purposes. Any request to obtain your consent does not narrow the scope of this Privacy Policy. By using the Medaflo Service, you accept and agree to Medaflo's information handling practices in the manner described.
Surveys and Feedback. If we ask you to complete a survey or provide feedback, we will tell you in advance how we intend to use your response. We do not include protected health information in survey or feedback materials.
Protect the Medaflo Service and data it stores. We may use the information collected through the Medaflo Service to investigate potential or suspected threats to the Medaflo Service or to the confidentiality, integrity or availability of the information Medaflo stores and maintains.
Communications. We may send email to the email address you provide to us to verify your account and for informational and operational purposes, such as account management, customer service, or system maintenance. We may also send you marketing emails if you request more information about our products and services. Emails are often transactional or relationship messages, such as reminders and other notifications. Medaflo may not offer you the option of opting out of receiving some of these messages although Medaflo may allow you to modify how often you receive such messages. If you opt-in to receiving marketing announcements from Medaflo, we will allow you to opt-out of receiving those announcements.
Anonymized and Aggregate Data. We may de-identify and aggregate data collected through the Medaflo Service, including by de-identifying protected health information in accordance with 45 C.F.R. ยง 164.514 where applicable, as permitted by our client agreements and applicable business associate agreements. De-identified and aggregated data does not identify you, our clients, or any individual, and is not protected health information or Personal Information. We may use and disclose that data for lawful business purposes, including operating, evaluating, and improving the Medaflo Service and providing analytics, reporting, benchmarking, and research offerings. We do not attempt to re-identify de-identified data. Identifiable protected health information is handled only as permitted by our client agreements, applicable business associate agreements, and applicable law.
We Use Vendors and Service Providers. We may share information we receive with vendors and service providers retained in connection with the provision of the Medaflo Service, limited to what those vendors need for their contracted purpose. When protected health information is shared, such vendors and service providers will be bound by appropriate confidentiality and security obligations which include business associate contract obligations as required by HIPAA. A current list of the subprocessors that may process client data is available to clients on request.
Marketing. We do not rent, sell, or share Personal Information about you with other people or non-affiliated companies for their direct marketing purposes, unless we have your permission.
As Required By Law and Similar Disclosures. We may access, preserve, and disclose collected information, if we believe doing so is required or appropriate to: comply with law enforcement requests and legal process, such as a court order or subpoena; respond to your requests; or protect your, our, or others' rights, property, or safety.
Merger, Sale, or Other Asset Transfers. If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be transferred as part of such a transaction as permitted by law and by our client agreements. Protected health information transferred in such a transaction remains subject to HIPAA and to the Business Associate Agreements under which we received it.
With Your Permission. We may also disclose your Personal Information with your permission.
Medaflo's collection, use, and disclosure of information are generally governed by service agreements with our health service provider and medical sales representatives clients. Information maintained to provide these services to our business clients is retained only for as long as we have a valid business purpose and in accordance with applicable law. Medaflo may retain archived information for a period of five years (or longer if required by law) as necessary to comply with legal obligations, resolve disputes and enforce our agreements and other authorized uses under this Privacy Policy.
Backups and Operational Logs. Encrypted database backups, database operations logs used for point-in-time recovery, and application, hosting, and security logs are retained for a limited period defined in our internal retention schedule and are then purged by the applicable service. Clients may request the current schedule.
Return and Deletion. On termination of a client agreement, or on written client request, Medaflo returns client data in an industry-standard format within the period set out in the applicable agreement and then securely deletes production copies, allowing any residual encrypted backup copies to expire through the normal backup recovery lifecycle. Medaflo may retain only the limited information reasonably necessary to comply with legal or regulatory obligations, preserve information subject to a legal hold, resolve disputes, prevent fraud or security threats, maintain billing, security, and audit records, carry out Medaflo's proper management and administration or legal responsibilities as permitted by an applicable Business Associate Agreement, or follow a client's written instructions. Any retained information remains subject to the same privacy, security, and confidentiality protections, may be used only for the purpose requiring retention, and will be securely destroyed when that purpose ends. Residual backup copies remain protected until they expire. Written confirmation of deletion is available on request.
Account Deactivation. If you desire to deactivate your account please contact us. Upon receiving such a request, Medaflo will deactivate your account and archive your Personal Information.
Limits to Your Requests for Access, Amendment, or Deletion. You may not be able to access, update, or delete information that you share with another user or other party through the Medaflo Service. Certain users, such as health service providers, may be required under HIPAA and other applicable laws to retain information about patients for extended periods of time. Medaflo will continue to retain such information on their behalf.
Medaflo may retain non-personal information and feedback for as long as it remains useful for legitimate business purposes, subject to any restrictions in our client agreements.
In most cases, Medaflo obtains Personal Information on behalf of a health service provider. To request access to, correction, amendment, or deletion of this Personal Information, a patient or end user should contact the health service provider to which the data was provided.
Medaflo maintains administrative, technical, and physical safeguards designed to protect the information it processes. Those safeguards are described in our Security Policy.
No data transmissions over the Internet can be guaranteed to be 100% secure. While we maintain those safeguards, we cannot ensure or warrant that information may never be accessed, disclosed, altered, or destroyed by a breach of them.
Medaflo provides its services to health service providers and medical sales representatives. When we process "protected health information" as defined by HIPAA on behalf of health service providers, we are acting as a "business associate" to them as regulated by HIPAA. Therefore, Medaflo must adopt and maintain appropriate physical, technical, administrative, and organizational procedures to safeguard and secure the protected health information we process. We also may not access, use, or disclose the protected health information except as permitted by health service provider clients and/or applicable law. Medaflo strives to protect the privacy of the Personal Information it processes, and to avoid inadvertent disclosure.
Medaflo maintains a documented incident response plan that is tested periodically. If Medaflo becomes aware of a breach of its security safeguards, it will investigate, contain, and remediate the incident and provide notifications consistent with applicable law, the HIPAA Breach Notification Rule, and the Business Associate Agreements under which we process protected health information.
By using the Medaflo Service or providing Personal Information to us, you agree that we can communicate with you electronically regarding security, privacy, and administrative issues relating to your use of this website.
The Medaflo Service is administered in the United States and is intended solely for users within the United States. Client production data, including protected health information, is stored and processed in the United States and is not stored or accessed outside the United States.
Medaflo acts as a service provider under the California Consumer Privacy Act as amended by the California Privacy Rights Act. We do not sell or share personal information as those terms are defined by that law, and we process personal information only to perform the services described in our client agreements. Medical information we process on behalf of healthcare clients is governed by HIPAA and the California Confidentiality of Medical Information Act rather than by the CCPA. California residents who wish to exercise a privacy right with respect to information a healthcare provider submitted to the Medaflo Service should contact that provider, as described under "Access / correction" above.
The Medaflo Service is not directed to persons under the age of 13 ("child" or "children"), and children may not create accounts or submit Personal Information directly to Medaflo. If Medaflo learns that a child submitted Personal Information directly to Medaflo without appropriate consent or authorization, Medaflo will delete that information as soon as practicable. If you believe a child has submitted Personal Information directly to us without appropriate consent or authorization, please contact us immediately.
Health service providers and other authorized adult users may use the Medaflo Service to provide, share, and store information about patients and other individuals, including minors and children. Medaflo processes that information on behalf of the applicable client under the client's instructions, the applicable client agreement and Business Associate Agreement, and applicable law. The preceding deletion commitment for information submitted directly by a child does not apply to patient or other records submitted by an authorized adult user on behalf of a client.
Posting of Revised Privacy Policy. We review this Privacy Policy periodically and update it when our practices, systems, or legal obligations change. We will post any adjustments on this web page, and the revised version will be effective when it is posted. If you are concerned about how your information is used, bookmark this page and read this Privacy Policy periodically.
New Uses of Personal Information. From time to time, we may desire to use Personal Information for uses not previously disclosed in our Privacy Policy. If our practices change regarding previously collected Personal Information in a way that would be materially less restrictive than stated in the version of this Privacy Policy in effect at the time we collected the information, we will make reasonable efforts to provide notice and obtain consent to any such uses as may be required by law.
If you have any questions, comments, or concerns about Medaflo or this Privacy Policy, please email us at hi@medaflo.com.
Last updated: June 30, 2026