Solavia Decision Suite Privacy Notice
This privacy notice describes how personal information, including health-related information, may be collected, used, disclosed, and otherwise processed in connection with the use of the Solavia Decision Suite and related services. Please review it carefully.
We are Committed to Your Privacy
NYU Langone Health and Dana-Farber Cancer Institute, which together own and operate the Solavia Decision Suite (“Solavia” or the “Platform”), are committed to maintaining the privacy, confidentiality, and security of personal information, including consumer health information, as that term is defined in this Notice (collectively “Personal Information”) processed in connection with the Platform and related services. The Platform is offered to hospitals and health care providers for professional use (our “Customers”).
Depending on the context, Solavia may process Personal Information:
- on behalf of a Customer, its affiliates, and the health care practitioners employed by or associated with Customer or its affiliates in connection with providing the Services under an applicable customer license agreement, business associate agreement, data processing agreement, or similar contract (collectively, “Platform Agreements”); and/or
- for its own business purposes, such as account administration, billing, support, security, analytics, research and development, legal compliance, and operation of the Website.
We will only use or disclose Personal Information as described in this Privacy Notice (“Notice”), the applicable Platform Agreements, and as otherwise permitted or required by law.
Notice Content
This Notice describes:
- The types of information that we receive from you when you interact with the Platform in your capacity as an end-user of the Platform, visitor to our website, or other user of our Services (“you”);
- The sources from which we collect such information;
- How we use and process the Personal Information that we collect;
- When and why we may disclose Personal Information to third parties;
- How we use de-identified and aggregated data;
- How long we retain Personal Information;
- Your choices regarding the collection and processing of Personal Information collected through use of the Platform; and
- How to contact us regarding our privacy practices.
Scope and Acceptance of Notice
This Notice applies to Personal Information collected or processed by Solavia in connection with:
- the Platform;
- Solavia.com and any other Solavia-related website or digital property that links to or posts this Notice, including any successor websites (together, the “Website”); and
- related support, communications, account administration, and business operations (collectively, the “Services”).
This Notice does not apply to:
- information collected through e-mails and business communications with us related to the Services;
- third-party websites, applications, or services that are not operated or controlled by Solavia, even if accessed through the Services;
- information processed by you outside the Services;
- employment-related information of NYU Langone Health and Dana Farber Cancer Institute workforce members; or
- information subject to a separate privacy notice, policy, or contractually negotiated data terms.
- Where we process Customer Data (as defined herein), including patient-related information, on behalf of a Customer, such processing is also governed by the applicable Platform Agreements.
By using the Services, you accept the terms set forth herein and consent to our collection, use, disclosure, retention, and other processing of your information as described in this Notice. This Notice is incorporated into and made a part of the underlying Platform Agreement. IF YOU DO NOT AGREE WITH ANY PART OF THIS NOTICE OR THE PLATFORM AGREEMENT, PLEASE DO NOT USE ANY OF THE SERVICES. This Notice may be amended or updated from time to time to reflect changes in our practices with respect to the handling of Personal Information, or changes in applicable privacy laws. Whenever possible, we will provide you with advance written notice of our changes to this Notice. We will not make retroactive changes that reduce your rights unless we are legally required to do so. Your continued use of the Services after the effective date constitutes your acceptance of the amended Notice. The amended Notice supersedes all previous versions.
How and From What Sources We Collect Information
1. We Collect Information That You Provide To Us.
We collect information, including Personal Information, that you or your organization provide to us in connection with the Services, including the following:
User account information: We require everyone with access to our Services to have an account with us. When you or your employer creates a Solavia account, we collect Personal Information including your name, email address, phone number, organization name, title or role, username, account credentials, authentication details, and related account administration information.
Content data: In connection with use of the Platform, Customers and their authorized users may submit, provide, upload, transmit, or otherwise make available information through the Services, which may include clinician information, such as clinician NPI, clinician first and last name, clinician email address, patient medical records number, patient first and last name, patient date of birth, pathway selections, treatment plan selections, and other information entered into or generated through the Platform (“Customer Data”). To the extent Customer Data includes Protected Health Information (“PHI”) or other regulated information, such information is processed in accordance with applicable Platform Agreements and law.
Consent records: We may collect and store consents, authorizations, acknowledgements, preferences, and related metadata, that you have given, together with the date and time, method and means of consent, and any related information (e.g., the subject matter of the consent).
Communication information: When you contact us for customer support, product questions, training, implementation assistance, feedback, inquiries, or otherwise, we may collect your name, organization, contact information, email address, phone number, the content of your message, and any other information you provide us with to assist you or resolve your issue. We may monitor and record phone conversations or email communications between you and our employees for training and quality assurance purposes. We may receive a confirmation when you open or click on content in an email from us, which helps us make our communications to you more useful and interesting. We may maintain records of such communications for support, quality assurance, training, security, and compliance purposes, to the extent permitted by law.
Social media information: We may have accounts on social media sites like LinkedIn, YouTube and X (“Social Media”). When you interact with our Social Media, we will collect Personal Information that you elect to provide to us, such as your contact details and third parties that host our Social Media may provide us with aggregate information and analytics regarding your use of our Social Media.
Event, partner, and business relationship information: We may collect Personal Information from Customers, prospective Customers, vendors, partners, and service providers, such as contact details, professional information, and information relevant to our business relationship.
Testimonial and review information: If you provide feedback, survey responses, or agree to provide a testimonial, we may collect and use that information as described at the time of collection and subject to any permissions you provide.
2. We Collect Information Automatically
When you visit, access, use, or otherwise interact with our Services, we will automatically collect certain information about your visit, device, browser, network, use, or interactions (“Analytical Information”), including through automated means from your computer or device, including the following:
- Log data: Whenever you visit the Services, your browser will automatically send us your signup/sign-in action logs, SSO integration details, IP address, browser type, authentication events, account access activity and settings, date and time stamps, error logs, referring and exit pages, and system activity.
- Device information: We will automatically collect information about the device you are using to access the Services, including name of the device, hardware model, operating system, browser configuration, referring/exit pages, language settings, date/time stamps, and clickstream data. The information collected may depend on the type of device you use and its settings.
- Location Data: We may collect data that identifies the location of your mobile device or computer, including the location of the mobile device or computer used to access the Services derived from GPS or WiFi use; and the IP address of the mobile device or computer or internet service used to access the Services. We do not collect precise geolocation information unless specifically disclosed and enabled for a particular feature.
- Usage data: We will collect information about your use of our Services, including, name, email address, the features you use, actions you take (including pathway path clicked and treatment plan selected), your time zone, location, the dates and times of access, amount of time spent within the Services and types and volumes of queries you submit, and other product usage information. Where such information is associated with Customer Data, we process it in accordance with applicable Platform Agreements.
- Cookies: A cookie is a small string of information that websites you visit transfer to your computer for identification purposes. Cookies can be used to follow your activity on the Website and that information helps us to understand your preferences and improve your Website experience. Cookies are also used for such activities as remembering your access credentials for our Services. We and our service providers may use cookies, pixels, SDKs, local storage, and similar technologies to operate, secure, and improve the Services. These technologies may be used to remember preferences, maintain sessions, understand usage patterns, analyze performance, and support security functions. In addition to the cookies used by NYU Langone Health and our service providers, some cookies are placed by third parties such as Google (for analytics, described below).
We may use the following categories of cookies and similar technologies:
- Essential Cookies: these are essential in order to enable you to move around the Website and use its features, such as authentication, security, and core functionality.
- Performance and Analytics Cookies: used to measure and improve the performance and usability of the Website and Services. These include Google Analytics and they keep track of the pages that you visit on our Website and the content you access, so we can determine which content is most popular and improve the performance of our Website. These cookies primarily record aggregate and anonymous statistical data, but may capture a minimal amount of identifiable information.
- Functional Cookies: used to remember preferences and settings. These cookies remember the choices you make, such as language options or the region you are in. They help to make your visit more personal and are deleted automatically when you close your browser or the session expires.
You may also manage certain cookie settings through your browser, subject to the limitations of the relevant browser or device. Please be aware, however, that when you choose to reject cookies you may limit the features and functionality of our Services.
3. We Collect Information From Third Parties
We may collect information about you from third parties, including:
- our Customers, who may provide information about their personnel, authorized users, patients, and other individuals in connection with use of the Services;
- identity, authentication, and single sign-on providers;
- service providers that support hosting, security, analytics, communications, billing, implementation, and customer support; and
- other third parties where legally permitted.
We may combine this information with information we collect from you and use it as described in this Notice.
How We Use Personal Information
For purposes of this Notice, “Personal Information” means all information accessed or collected that relates to an individual and that identifies, or can be used in conjunction with other readily-accessible information to identify, such individual (including, but not limited to, name, contact data, gender, date of birth, professional licensing information, e-mail address, physical address, phone number and health information).
Personal Information will only be collected in a manner that is consistent with the purposes for which it is provided and Solavia’s other legitimate business purposes (including, but not limited to, marketing). By signing the Platform Agreement with Solavia, you represent that no Personal Information will be provided and used in connection with the Services without you having first obtained the requisite approvals, authorizations, consents, permissions, permits, or having entered into a business associate agreement. Further, you understand that Personal Information subject to this consent requirement includes Protected Health Information as that term is defined by the Health Insurance Portability and Accountability Act of 1996, and sensitive health information such as HIV-related information, mental health information, alcohol or abuse treatment information, or genetic information.
When you interact with the Services we may process Personal Information on your behalf for the following purposes:
- to provide, administer, maintain, and/or improve our Services, including implementation, onboarding, account provisioning, authentication, workflow support, and performance of our contractual obligations;
- to provide you with support services, resolve issues or reply to your queries;
- to manage and remember your preferences and customize the Services;
- to communicate with you, including to send you information or marketing about our Services and events;
- to provide customer service, technical support, training, and implementation assistance, and to communicate with users and Customers regarding the Services;
- to analyze and study the effectiveness of our Services and to develop new features and services;
- to monitor, analyze, troubleshoot, and improve the performance, security, and integrity of the Services, including through logs, diagnostics, auditing, and other internal analytics;
- to verify your identity, prevent fraud, criminal activity and to ensure the security of our IT systems, architecture, and networks;
- to prevent misuse of the Services and enforce our legal terms, including those set forth in the Platform Agreement;
- to develop, enhance, test, and support new or existing products, services, features, and functionality, subject to applicable law and contract;
- to comply with legal, regulatory, audit, risk management, reporting, and corporate governance obligations and legal processes;
- to enforce our legal rights, contractual rights, and Platform Agreements; and
- to protect the rights, privacy, safety, or property of NYU Langone Health, Dana Farber Cancer Institute, and/or that of our affiliates, you, or other third parties.
Use of De-Identified and Aggregated Data
To the extent permitted by applicable law and contract, including the applicable Platform Agreement(s), we may create, use, disclose, license, publish, and otherwise process information that has been de-identified, anonymized, and/or aggregated so that it does not reasonably identify, and cannot reasonably be used to identify, an individual.
Where de-identified data is derived from PHI, we will de-identify such data in accordance with applicable law, contractual commitments, and, where applicable, HIPAA requirements. We may use such de-identified and aggregated data for lawful business purposes permitted by contract, including:
- operating, improving, and optimizing the Services;
- developing and validating new products, tools, models, and features;
- analytics, statistics, and benchmarking;
- quality improvement and performance measurement;
- research and development;
- training, testing, and evaluating algorithms, machine learning models, and related technologies;
- creation of reports, publications, and market insights; and
- other internal or external business purposes permitted by law and contract.
Where required by applicable law or contract, we will maintain measures designed to prevent re-identification of de-identified data and will not attempt to re-identify such data except as permitted by law for testing, validation, security, compliance, or similar lawful purposes.
Data Minimization
We take reasonable steps to limit the Personal Information we collect and process to what is relevant and reasonably necessary for the purposes set out in this Notice, including the provision of Services to you. Customers are responsible for determining and submitting only the information necessary for the Services and for ensuring that they have appropriate rights and authority to provide such information to Solavia for processing in connection with the Services.
How We Share and Disclose Your Information
We may share and disclose information as described at the time information is collected or as follows:
- When you consent. We may share Personal Information with third parties if you have given us your consent to do so or give us direction to do so, subject to applicable law and contract.
- With Customers and authorized users: We may make Personal Information and Customer Data available to the relevant Customer and its authorized administrators, workforce members, agents, and users in accordance with the Customer’s configuration and instructions.
- With third party service providers performing services on our behalf. We share information, including Personal Information, with our service providers to perform the functions for which we engage them (such as platform integration, web hosting, Cloud storage and data analyses). If we engage a third-party to process Personal Information, we enter into a data processing agreement and sufficient guarantees as required by the applicable privacy laws with such third-party Processor so that it will be subject to binding contractual obligations to: (i) only process the Personal Information in accordance with our prior written instructions; and (ii) use measures to protect the confidentiality and security of the Personal Information; together with any additional requirements under applicable privacy laws.
- With affiliates and related entities: We may share information with our affiliates for purposes consistent with this Notice and applicable Platform Agreements, including operations, administration, support, compliance, and security.
- For legal purposes. We may share Personal Information that we collect from users, as needed, to comply with law, regulation, legal process, government request, audit, or enforceable governmental demand; to enforce our rights, protect our property or protect the rights, property or safety of others, and to support external auditing, compliance and corporate governance functions. We will disclose Personal Information as we deem necessary to respond to a subpoena, regulation, binding order of a data protection agency, legal process, governmental request or other legal or regulatory process. We may also share Personal Information as required to pursue available remedies or limit damages we may sustain.
- In de-identified aggregated form. We may share Personal Information about you in a de-identified, anonymized, or aggregated form that does not reasonably identify an individual, subject to applicable law and contract.
- During a Platform Agreement assignment and corporate changes. We may transfer information, including your Personal Information, in connection with the assignment of Platform Agreements or a merger, sale, acquisition or other change of ownership or control by or of us or any affiliated company (in each case whether in whole or in part) related to Solavia. When one of these events occurs, we will use reasonable efforts to notify users before your information is transferred or becomes subject to a different Notice.
We do not sell Personal Information in exchange for monetary consideration. We do not disclose Customer-submitted PHI except as permitted by applicable Platform Agreements and law.
Data Retention
We retain Personal Information for as long as reasonably necessary to fulfill the purposes described in this Notice, comply with our contractual obligations, resolve disputes, enforce agreements, and satisfy legal, regulatory, accounting, auditing, security, and operational requirements. We will retain copies of the Personal Information provided by you in a form that permits identification as long as:
- we maintain an ongoing relationship with you (e.g., where you are a user of our Services, or you are lawfully included in our mailing list and have not unsubscribed); or
- we receive your consent to store the Personal Information for a longer period of time (e.g. in the case of application documents for a later job offer).
We may also retain Personal Information to comply with applicable law, prevent fraud, resolve disputes, troubleshoot problems, assist with any investigation, enforce the Platform Agreement, collect any fees owed (as applicable), and complete other actions permitted by law.
In the event any relevant legal claims are brought, we may continue to process the Personal Information provided for such additional periods as are necessary in connection with that claim.
De-identified and aggregated data may be retained for as long as permitted by applicable law and the applicable Platform Agreements.
Retention periods for Customer Data, other than Personal Information addressed above, may vary depending on the type of information and the context in which it was collected, including:
- the duration of our relationship with the relevant Customer;
- the terms of the applicable Platform Agreements;
- the need to maintain business and security records;
- applicable legal, regulatory, tax, accounting, and compliance obligations;
- backup, archival, disaster recovery, and business continuity needs; and
- whether the information has been de-identified, aggregated, or anonymized.
Information Storage and Security
We have implemented appropriate administrative, technical, and organizational security measures designed to protect Personal Information against accidental, unlawful, or unauthorized destruction, loss, alteration, disclosure, access, and other unlawful or unauthorized forms of processing. Further, as required under applicable privacy laws, we only process your Personal Information subject to all contractual requirements of confidentiality, imposing equivalent measures upon employees and subcontractors with access to such Personal Information. These safeguards are designed with regard to the sensitivity of the information we process and the nature of the Services.
Such measures may include, as appropriate:
- access controls and authentication requirements;
- role-based permissions;
- encryption in transit and, where appropriate, at rest;
- logging, monitoring, and audit capabilities;
- vulnerability management and incident response procedures;
- workforce training and confidentiality obligations; and
- vendor and subprocessor diligence.
Because the internet is an open system, the transmission of information via the internet is not completely secure. Although we will implement measures designed to protect Personal Information, we cannot guarantee the security of your data transmitted to us using the internet – any such transmission is at your own risk and you are responsible for ensuring that any Personal Information that you send to us are sent securely. However, we do take measures to secure data in transit using encryption protocols (e.g., TLS/SSL), and access controls once data reaches our environment. In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to your Personal Information, we will respond according to the requirements of the applicable Business Associate Agreement, Data Processing Agreement or privacy law applicable to the data at issue.
Users of the Services are responsible for maintaining the confidentiality and security of any account credentials, password, user ID or other form of authentication involved in obtaining access to password protected or secure areas of any of our digital services. In order to protect you and your data, we may suspend your use of any of the Services, without notice, pending an investigation, if any breach of security is suspected. Access to and use of password protected and/or secure areas of any of the Services are restricted to authorized users only. Unauthorized access to such areas is prohibited and may lead to criminal prosecution.
Customer-submitted data
If your Personal Information was submitted to the Services by or on behalf of a Customer, including where Solavia processes such information as a service provider, processor, or business associate, Solavia generally processes that information on the Customer’s behalf. In those cases, requests regarding access, correction, deletion, or other rights should be directed to the relevant Customer, who is responsible for responding to such requests under applicable law. Solavia will assist Customers in responding to such requests as required by law or contract.
Account, Website, and direct relationship data
If Solavia collected your information directly in connection with account administration, support, billing, the Website, events, or other direct interactions, you may contact us as described below to inquire about applicable rights and choices. You may also be able to access and update certain account information through your account settings, where available.
Marketing communications
You may opt out of receiving marketing emails from us by using the unsubscribe link included in those communications or by contacting us. Even if you opt out of marketing communications, we may still send you transactional or service-related communications.
Where required by applicable state law, we will honor qualifying privacy rights requests in accordance with applicable verification and response procedures.
Links to Third Party Services
The Services may contain links to third-party websites, products, and services with which we have no affiliation. A link to any third party service does not mean that we endorse it or the quality or accuracy of information presented on it. This Notice does not apply to the privacy practices of such third parties. If you decide to visit a third party service, you are subject to its privacy notice and practices and not this Notice. We encourage you to carefully review the legal and privacy notices of all other digital services that you visit.
Users from Other Jurisdictions
Depending on your state of residence and the nature of your interaction with the Services, you may have additional rights under applicable U.S. state privacy laws. We may provide supplemental disclosures or notices to residents of certain states, including with respect to categories of Personal Information collected, purposes of use, categories of recipients, retention considerations, and available rights. Any Personal Information collected about EU or other foreign residents through the Services is processed in the United States by us or by a party acting on our behalf. When you provide personal information to us through the Services, you consent to the processing of your data in the United States. The Services are hosted in the United States.
Contact Us
If you have a question or wish to exercise any right described in this Notice, please contact the Privacy Officer at: One Park Avenue, 3rd Floor, New York, New York 10016, Attention: Privacy Officer, by phone to 1-877-PHI-LOSS or 212-404-4079, or via email to compliancehelp@nyulangone.org.
Effective Date: July 07, 2026
#146681v8