Intake AI (“Intake AI,” “we,” “us,” or “our”) is committed to protecting the privacy and security of the information entrusted to us.
This Privacy Policy explains how we collect, use, process, store, disclose, and protect information when you visit our website, use the Intake AI platform, connect third-party systems, use our workflows, APIs, browser extension, or other products and services that reference this Privacy Policy (collectively, the “Services”).
Intake AI provides AI-powered software for clinical research operations. Our Services allow authorized users to connect and work across clinical research documents, systems, and data; ask questions across those sources; generate and manage study materials; and automate supported clinical research workflows.
A separate Chrome Extension Privacy Policy provides additional information about data collected and processed specifically through the Intake AI Chrome Extension.
Who This Privacy Policy Applies To
This Privacy Policy applies to:
- visitors to our website (“Visitors”);
- organizations that purchase, evaluate, or otherwise use Intake AI (“Customers”);
- employees, contractors, investigators, coordinators, and other individuals authorized by a Customer to use Intake AI (“Authorized Users”); and
- individuals whose information may be contained in documents, systems, records, or other data submitted to or accessed through the Services.
When Intake AI processes Customer Content on behalf of a Customer, the Customer generally determines why and how that information is used. Depending on the applicable law and contractual arrangement, Intake AI may act as a data processor, service provider, contractor, or business associate with respect to that information.
For information we collect for our own business purposes, such as account information, website analytics, security information, and business communications, Intake AI may act as the data controller or business responsible for that information.
Information We Collect
We may collect the following categories of information.
Contact and Account Information
When you request a demonstration, communicate with us, create an account, or use the Services, we may collect information such as your name, email address, organization, job title, telephone number, account identifier, role, and other information you choose to provide.
We may also process authentication information necessary to securely authenticate you and associate you with the appropriate organization and permissions.
Customer Content
Customers and Authorized Users may upload, submit, generate, connect, or otherwise make information available to Intake AI. Customer Content may include:
- study protocols;
- informed consent forms;
- schedules of assessments;
- case report forms and source-document templates;
- standard operating procedures;
- budgets and financial documents;
- staffing records, training records, and site documentation;
- clinical trial and study information;
- communications and files from connected systems;
- information contained in CTMS, EDC, eSource, document-management, email, and other clinical research systems;
- prompts, questions, instructions, comments, corrections, and feedback submitted by users;
- information generated by Intake AI in response to Customer Content; and
- other documents, records, structured data, or unstructured data a Customer chooses to provide.
Depending on how a Customer uses the Services, Customer Content may contain personal information, sensitive personal information, clinical information, or protected health information (“PHI”).
Information From Connected Services
If you authorize Intake AI to connect to a third-party service, we may receive and process information from that service according to the permissions you grant.
Connected services may include email systems, document-storage platforms, clinical trial management systems, clinical research platforms, public databases, and other applications supported by Intake AI.
We may process authorization tokens, identifiers, metadata, files, messages, records, or other content necessary to provide the connected functionality.
Your use of a third-party service remains subject to that provider’s terms and privacy practices.
Browser Extension Data
If you use the Intake AI Chrome Extension, we may process information from supported browser-based clinical research systems, including relevant page content, form structure, field information, screenshots of an active supported page, workflow instructions, interaction results, user corrections, and technical information necessary to provide the Extension’s functionality.
For additional information, please review the Intake AI Chrome Extension Privacy Policy.
Usage and Technical Information
We may automatically collect technical and usage information such as:
- IP address;
- browser and device type;
- operating system;
- timestamps;
- session identifiers;
- pages or features used;
- application events;
- error and diagnostic information;
- workflow status and completion information;
- system performance and reliability information; and
- security and audit events.
We use this information to operate, secure, troubleshoot, evaluate, and improve the Services.
Cookies and Similar Technologies
Our website and web applications may use cookies and similar technologies for authentication, security, preferences, analytics, performance measurement, and other operational purposes.
Where required by applicable law, we will provide appropriate choices regarding non-essential cookies.
How We Use Information
We may use information collected through the Services to:
- provide, operate, maintain, and improve Intake AI;
- authenticate users and enforce organization- and role-based permissions;
- retrieve, organize, index, search, and analyze Customer Content;
- generate AI-powered answers, summaries, mappings, documents, recommendations, and other outputs requested by users;
- automate supported clinical research workflows;
- connect and synchronize authorized third-party systems;
- populate, configure, or otherwise interact with supported clinical research systems at the direction of authorized users;
- provide source citations, provenance, audit trails, and workflow verification;
- provide customer support;
- detect, investigate, and prevent security incidents, abuse, fraud, or unauthorized access;
- monitor reliability, performance, and product usage;
- conduct research, testing, evaluation, quality assurance, and product development;
- develop, train, fine-tune, evaluate, validate, and improve artificial intelligence and machine-learning systems as described below;
- communicate with Customers and users about the Services;
- comply with applicable laws, regulations, court orders, and legal obligations; and
- establish, exercise, or defend legal rights.
Artificial Intelligence and Model Training
Intake AI uses artificial intelligence and machine-learning technologies to provide and improve the Services.
We may use information collected through the Services to develop, train, fine-tune, evaluate, test, validate, and improve our AI models, machine-learning systems, retrieval systems, automation systems, and related technology.
Depending on the applicable Customer agreement, permissions, and legal requirements, information used for these purposes may include Customer Content, prompts, outputs, document content, workflow interactions, browser-derived information, user corrections, feedback, model results, execution traces, and other information generated through use of the Services.
We may also create aggregated, de-identified, transformed, or derived datasets for product development, model evaluation, benchmarking, reliability testing, and similar purposes.
We do not use information for model training where doing so is prohibited by applicable law, a Business Associate Agreement, a Data Processing Agreement, another written customer agreement, or other binding restriction.
Where Customer Content constitutes PHI subject to HIPAA, our ability to use that information is governed by the applicable Business Associate Agreement and applicable law. We will not use PHI for model training or unrelated product-development purposes where such use is prohibited by those requirements.
Data may also be processed by third-party artificial intelligence providers when necessary to provide AI functionality. Their processing is governed by our applicable agreements with those providers.
Because machine-learning systems are developed from large datasets, deleting particular source data may not necessarily remove statistical effects from a model that was previously trained using that data, to the extent retention of those effects is permitted by applicable law and contract.
Sensitive Information, Clinical Research Data, and PHI
The Services are designed for use in clinical research environments and may process sensitive or regulated information.
Customers are responsible for ensuring that they have the necessary authority, permissions, notices, consents, and legal basis to provide information to Intake AI and instruct us to process it.
Where Intake AI processes PHI on behalf of a HIPAA covered entity or business associate pursuant to a Business Associate Agreement (“BAA”), the BAA governs our handling of that PHI. If there is a conflict between this Privacy Policy and an applicable BAA regarding PHI, the BAA controls.
Customers may also be subject to research protocols, informed-consent requirements, institutional policies, sponsor requirements, IRB requirements, GDPR, state privacy laws, FDA requirements, or other obligations independent of Intake AI. Customers remain responsible for determining whether their use of the Services satisfies those requirements.
Data Storage and Retention
We retain information for as long as reasonably necessary to provide the Services, fulfill the purposes described in this Privacy Policy, comply with contractual and legal obligations, maintain security and audit records, resolve disputes, and enforce our agreements.
Retention periods may differ depending on the type of information, Customer instructions, contractual requirements, regulatory requirements, and how the Services are configured.
Customer Content may be deleted or returned following termination of a Customer relationship in accordance with the applicable Customer agreement and our retention procedures.
Certain records may be retained longer where required for security, fraud prevention, auditability, legal compliance, dispute resolution, backup integrity, or other legitimate purposes.
Aggregated or de-identified information that can no longer reasonably be associated with an identifiable individual or Customer may be retained for longer periods.
Data Security
We use technical and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, destruction, and loss.
These safeguards include encryption of data in transit and at rest, authenticated access, role- and permission-based controls, logging and monitoring, access restrictions, security testing, and other measures appropriate to the nature of the information being processed.
Access to sensitive information is restricted to authorized personnel and systems with a legitimate need for access.
No method of transmitting or storing information is completely secure, and we cannot guarantee absolute security.
Your Privacy Rights and Choices
Depending on where you live and the nature of our relationship with you, you may have rights to request access to, correction of, deletion of, or a copy of your personal information; object to or restrict certain processing; withdraw consent where processing is based on consent; or exercise other rights available under applicable privacy law.
Where Intake AI processes personal information on behalf of a Customer, requests concerning that information may need to be directed to the Customer that controls the information. We will assist Customers with eligible requests as required by applicable law and contract.
California residents may have additional rights under the California Consumer Privacy Act and related laws, including rights to know, access, correct, or delete certain personal information and to receive equal service when exercising applicable privacy rights.
To submit a privacy request, contact us using the information in Section 14.
International Data Transfers
Intake AI and our service providers may process information in the United States and other jurisdictions.
Where required, we use appropriate legal mechanisms and contractual protections for international transfers of personal information.
Third-Party Websites and Services
The Services may contain links to, integrate with, or operate alongside third-party websites and services.
This Privacy Policy does not govern the independent privacy practices of those third parties. We encourage you to review their privacy policies before providing information to them.
Children’s Privacy
Intake AI is designed for businesses and clinical research professionals and is not intended for use by children.
We do not knowingly permit children under 13 to create Intake AI accounts or knowingly collect personal information directly from children through our website for consumer purposes.
Clinical research data processed on behalf of Customers may include information relating to minors where a Customer is legally authorized to process that information. In such circumstances, Intake AI processes the information on behalf of the Customer and subject to the applicable agreement and legal requirements.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technology, business practices, or legal requirements.
When we make changes, we will update the “Last Updated” date above. Where required by law or where changes materially affect how we use personal information, we will provide additional notice.
Contact Us
For questions, concerns, or privacy requests relating to this Privacy Policy or Intake AI’s data practices, please contact us at:
Intake AI
- hello@useintake.ai
- Website
- https://www.useintake.ai
If you are contacting us about information controlled by a Customer organization, please identify that organization so that we can appropriately route your request.