Legal

Privacy Policy

Effective Date: September 5, 2026

Last Updated: September 5, 2026

DownStream Health Technologies, Inc. (“DownStream,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit downstream.co, create or use a DownStream account, communicate with us, or otherwise interact with our products and services.

DownStream provides contractual intelligence and assurance software that helps organizations identify and manage contractual obligations, map commitments to frameworks and controls, and maintain evidence related to those commitments.

If you have questions about this Privacy Policy or our privacy practices, contact us at privacy@downstream.co.

1. Scope of This Privacy Policy

This Privacy Policy applies to personal information we process in connection with:

  • the DownStream website;
  • the DownStream software platform;
  • customer accounts and user profiles;
  • sales and marketing activities;
  • customer support;
  • product trials and demonstrations;
  • billing and account administration;
  • communications with DownStream; and
  • other interactions with DownStream where this Privacy Policy is referenced.

This Privacy Policy does not apply to third-party websites, products, or services that may be linked from DownStream.

2. Customer Data and Customer Content

Organizations using DownStream may upload or create information within the platform, including contracts, business associate agreements, security addenda, policies, reports, assessments, certifications, evidence files, internal controls, mappings, comments, and related business records.

We refer to this information collectively as Customer Content.

For Customer Content, DownStream generally acts as a service provider or processor on behalf of the organization that controls the DownStream account. The customer organization determines what information is submitted to the platform and how that information is used.

If you are an employee, contractor, customer, or other individual whose information appears in Customer Content, privacy requests relating to that information should generally be directed to the organization that uploaded or controls the information.

DownStream will assist customers with appropriate privacy requests where required by contract or applicable law.

3. Important Notice Regarding Protected Health Information

DownStream is designed for healthcare organizations but is not currently intended to receive, store, or process Protected Health Information (“PHI”) regulated by the Health Insurance Portability and Accountability Act (“HIPAA”) unless DownStream has expressly agreed in writing to do so.

Customers and users should not upload PHI to DownStream unless DownStream has expressly authorized such use and any required contractual arrangements, including a Business Associate Agreement where applicable, are in place.

The fact that DownStream supports healthcare compliance, contractual intelligence, HIPAA-related contractual analysis, or healthcare security frameworks does not mean the DownStream platform is automatically authorized to process PHI.

Questions concerning permitted data may be directed to privacy@downstream.co or compliance@downstream.co.

4. Information We Collect

A. Information You Provide Directly

We may collect information you provide when creating or managing an account, including:

  • name;
  • business email address;
  • job title;
  • company or organization name;
  • phone number;
  • account credentials;
  • organization information;
  • user role;
  • billing information;
  • support communications;
  • feedback; and
  • other information you choose to provide.

B. Customer Content

When authorized users use DownStream, we may process Customer Content such as:

  • contracts;
  • contractual clauses;
  • obligations;
  • metadata;
  • framework mappings;
  • internal controls;
  • policies;
  • SOC reports;
  • penetration testing reports;
  • certifications;
  • evidence files;
  • assurance documentation; and
  • other business records uploaded by customers.

Customer Content may contain personal information depending on the documents submitted by the customer.

C. Usage and Technical Information

We may automatically collect information about how users interact with DownStream, including:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • pages or features accessed;
  • dates and times of access;
  • session information;
  • authentication events;
  • error and diagnostic information; and
  • product usage information.

We use this information for security, product operation, troubleshooting, analytics, and service improvement.

D. Sales and Business Communications

If you request a demonstration, contact sales, attend a meeting, participate in a pilot, or otherwise communicate with us, we may collect:

  • contact information;
  • employer and role;
  • business needs;
  • meeting information;
  • communications;
  • sales notes; and
  • information related to a potential or existing business relationship.

Sales inquiries may be directed to sales@downstream.co.

5. How We Use Information

We may use personal information to:

  • provide and operate DownStream;
  • authenticate users;
  • create and manage customer organizations;
  • process contracts and Customer Content;
  • extract and structure contractual obligations;
  • generate framework and control mappings;
  • provide assurance and evidence-management functionality;
  • respond to user questions;
  • maintain account and organization settings;
  • provide customer support;
  • process payments and administer subscriptions;
  • communicate about products, services, and account matters;
  • operate product trials;
  • improve product functionality;
  • diagnose technical problems;
  • protect the security and integrity of DownStream;
  • detect fraud, abuse, or unauthorized access;
  • comply with legal obligations;
  • enforce agreements;
  • protect our rights and the rights of customers and users; and
  • perform other activities disclosed at the time information is collected.

6. Artificial Intelligence and Automated Processing

Certain DownStream features use artificial intelligence and machine learning technologies to analyze Customer Content.

Depending on the feature being used, portions of documents or structured data may be transmitted to third-party artificial intelligence service providers for processing.

Such processing may include:

  • document metadata extraction;
  • identification of contractual obligations;
  • categorization of contractual requirements;
  • suggested framework mappings;
  • structured analysis;
  • search and question answering; and
  • related product functionality.

DownStream applies technical and contractual controls intended to limit such processing to the purpose of providing the service.

Customers should not submit PHI or other information prohibited by their agreement with DownStream.

DownStream does not represent that artificial intelligence output is legal advice, compliance certification, or a substitute for professional judgment. AI-generated or AI-assisted results may require human review.

For questions regarding AI processing or data handling, contact privacy@downstream.co.

7. How We Share Information

We do not sell personal information.

We may share information with the following categories of recipients.

Service Providers

We may use service providers that assist with:

  • cloud infrastructure;
  • database hosting;
  • authentication;
  • file storage;
  • artificial intelligence processing;
  • email delivery;
  • payment processing;
  • analytics;
  • monitoring;
  • customer support; and
  • other operational functions.

These providers may process information only as necessary to provide services to DownStream and subject to applicable contractual restrictions.

A current list of subprocessors is available at downstream.co/subprocessors.

Customer Organizations

If you use DownStream through your employer or another organization, administrators of that organization may be able to access information associated with your account, activity, or Customer Content.

Legal and Safety Requirements

We may disclose information if reasonably necessary to:

  • comply with law, regulation, subpoena, court order, or legal process;
  • respond to lawful government requests;
  • investigate fraud or security incidents;
  • enforce our agreements;
  • protect DownStream, our customers, users, or others; or
  • establish, exercise, or defend legal claims.

Corporate Transactions

Information may be disclosed or transferred in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction.

8. We Do Not Sell Personal Information

DownStream does not sell personal information for monetary consideration.

We also do not use Customer Content for third-party advertising.

If our practices materially change, we will update this Privacy Policy and provide any legally required choices or notices.

9. Cookies and Similar Technologies

DownStream may use cookies and similar technologies to:

  • maintain authenticated sessions;
  • remember user preferences;
  • protect account security;
  • understand website usage;
  • improve performance; and
  • support essential platform functionality.

Some cookies are necessary for DownStream to function and cannot reasonably be disabled while using authenticated portions of the service.

Where required by law, we will obtain appropriate consent before using non-essential cookies.

More detail is available in our Cookie Policy at downstream.co/cookies.

10. Payment Information

DownStream may use third-party payment processors, including Stripe, to process payments and subscriptions.

DownStream generally does not directly store full payment card numbers.

Payment processors may collect information such as:

  • payment card information;
  • billing address;
  • transaction information;
  • tax information; and
  • business identity information.

Payment processing is subject to the payment provider's own privacy terms.

Billing questions may be directed to billing@downstream.co.

11. Data Security

DownStream uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, disclosure, alteration, or destruction.

These measures may include:

  • access controls;
  • role-based permissions;
  • encryption;
  • tenant isolation;
  • private storage;
  • logging;
  • authentication controls;
  • secure development practices; and
  • security monitoring.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Security concerns or vulnerability reports should be sent to security@downstream.co.

Please do not include sensitive customer information in an initial vulnerability report.

12. Data Retention

We retain personal information for as long as reasonably necessary to:

  • provide the services;
  • maintain customer accounts;
  • fulfill contractual obligations;
  • comply with applicable laws;
  • resolve disputes;
  • enforce agreements; and
  • maintain appropriate business and security records.

Customer Content is generally retained according to the applicable customer agreement and organization settings.

Following termination of an account or service relationship, information may remain in backups or other systems for a limited period before deletion in accordance with our retention practices.

13. Your Privacy Rights

Depending on where you live, applicable law may provide rights concerning your personal information, including the right to:

  • request access to personal information;
  • request correction;
  • request deletion;
  • obtain a copy of certain personal information;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent; and
  • appeal certain decisions concerning a privacy request.

These rights may be subject to legal exceptions.

To submit a privacy request, contact privacy@downstream.co.

We may need to verify your identity before completing a request.

If your information is contained in Customer Content controlled by a DownStream customer, we may direct your request to that customer.

14. U.S. State Privacy Rights

Residents of certain U.S. states may have additional privacy rights under applicable state law.

Depending on the jurisdiction and applicability of the law, these may include rights to:

  • know or access personal information;
  • correct inaccurate information;
  • delete personal information;
  • obtain portable copies of information;
  • opt out of certain sales, sharing, or targeted advertising activities; and
  • appeal a decision concerning a privacy request.

DownStream does not currently sell personal information as that term is commonly defined under U.S. state privacy laws.

Requests may be submitted to privacy@downstream.co.

15. California Privacy Notice

If applicable, California residents may have rights under the California Consumer Privacy Act and California Privacy Rights Act.

The categories of personal information DownStream may collect include:

  • identifiers;
  • professional or employment-related information;
  • commercial information;
  • internet or electronic network activity;
  • account information; and
  • information contained in customer-provided business records.

We collect and use this information for the purposes described in this Privacy Policy.

DownStream does not sell personal information for monetary consideration.

For privacy inquiries or requests: privacy@downstream.co.

16. International Users

DownStream is based in the United States.

If you access DownStream from outside the United States, information may be transferred to and processed in the United States or other countries where DownStream or its service providers operate.

Where required, DownStream will use appropriate mechanisms for international data transfers.

17. Children's Privacy

DownStream is a business-to-business service and is not intended for children.

DownStream does not knowingly collect personal information directly from children under 13.

If you believe a child has provided personal information directly to DownStream, contact privacy@downstream.co.

18. Marketing Communications

You may receive communications from DownStream regarding products, services, demonstrations, pilots, or company updates.

You may unsubscribe from promotional email using the unsubscribe mechanism included in the communication or by contacting us.

Account, security, legal, billing, and service-related communications may still be sent when necessary.

19. Third-Party Links and Services

DownStream may contain links to third-party websites or services.

DownStream is not responsible for the privacy, security, or content practices of third parties. We encourage users to review the privacy policies of any third-party services they use.

20. Business Customers and Data Processing Agreements

Customers requiring additional contractual privacy protections may contact DownStream regarding a Data Processing Agreement or related privacy documentation.

Requests may be sent to legal@downstream.co or privacy@downstream.co.

Security documentation may be requested through security@downstream.co or, when available, trust@downstream.co.

21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

When we make material changes, we may provide notice through the DownStream website, the DownStream application, email, or another appropriate method.

The “Last Updated” date at the top of this Privacy Policy indicates when the policy was most recently revised.

22. Contact Us

For general privacy questions, requests, or concerns:

Privacy
privacy@downstream.co

Security
security@downstream.co

Legal
legal@downstream.co

Support
support@downstream.co

General
hello@downstream.co

DownStream Health Technologies, Inc.286 Katie DriveFeasterville-Trevose, PA 19053United States

Cookies

We use essential cookies to operate DownStream, including sign-in and security. Optional analytics cookies help us understand how the public website is used. Block all turns off optional cookies. Essential cookies still run because the site cannot work without them. See the Cookie Policy.