Scope
This policy covers avande.net. Client protected health information (PHI) is handled under each client’s Business Associate Agreement (BAA), not this policy.
Information we collect
Information you send us: name, work email, organization, organization type, interests and your message.
Technical data: browser type, device, pages visited and approximate location, collected through essential and, with your consent, analytics cookies.
How we use it
To reply to your enquiry, provide our services, improve the site and keep it secure. We do not sell personal information.
Service providers
We use vetted providers to run the site, including hosting (Cloudflare), form delivery (Web3Forms) and spam protection (hCaptcha). They process data only on our instructions.
Don’t send PHI
Please do not include protected health information in the contact form or by email. Clinical records are exchanged only through secure, contracted channels.
Security
Avandé is SOC 2 Type II and HIPAA compliant, with AES-256 encryption at rest, TLS 1.2+ in transit, MFA, role-based access and US data residency. HITRUST certification is in progress.
Retention
We keep enquiry data only as long as needed to respond and maintain business records, then delete it.
Your rights
You can ask to access, correct or delete your personal information, or opt out of marketing, by contacting us. Residents of certain US states may have additional rights.
Changes
We may update this policy. The date at the top shows the latest version.
Questions about this policy?
Use our contact form or call 1-833-328-2633. Avandé, 1000 N. West Street, Suite 1200, Wilmington, DE 19801.