Hermosa Strategy ← Back to home

Privacy Policy

Hermosa Strategy, LLC · AI Medical Record Review Platform

DocumentHermosa Strategy Privacy Policy
Effective DateApril 17, 2026
Governing LawCalifornia (CCPA/CPRA); HIPAA; Federal Law
Privacy Contactprivacy@hermosastrategy.com
HIPAA Security OfficerR. Alexander Comley
Subprocessors DisclosedAmazon Web Services, Inc. (AWS Bedrock)
OrganizationHermosa Strategy, LLC
Privacy Emailprivacy@hermosastrategy.com
General Contactlegal@hermosastrategy.com
Platformapp.hermosastrategy.com



Effective: April 17, 2026 | app.hermosastrategy.com

1. INTRODUCTION AND SCOPE

This Policy applies to: (a) law firm subscribers and their authorized users; (b) visitors to our website and marketing pages; and (c) individuals whose personal information is processed through the Platform in connection with legal matters (to the extent applicable). This Policy does not apply to Protected Health Information (PHI) processed under a Business Associate Agreement, which is governed by that BAA and applicable HIPAA regulations.

1.1 Acceptance. By using the Platform, you acknowledge that you have read and understood this Policy. This Policy is incorporated by reference into our Terms of Service.

1.2 Scope of HIPAA. Where the Platform processes PHI on behalf of a covered entity law firm client, such processing is governed by the applicable Business Associate Agreement and HIPAA regulations (45 CFR Parts 160 and 164), which take precedence over this Policy with respect to PHI.

2. INFORMATION WE COLLECT

2.1 Account and Registration Information. When you register for the Platform, we collect: firm name; contact name and title; email address; phone number; billing address; and payment information (processed by our payment processor; we do not store full payment card numbers).

2.2 Usage Information. We automatically collect technical data when you access the Platform, including: IP address; device type, browser, and operating system; session duration and access timestamps; features and pages accessed; and error logs and performance data.

2.3 Subscriber Data. You may upload documents, medical records, case materials, and other content to the Platform (“Subscriber Data”). Subscriber Data may include PHI, attorney work product, and confidential client information. We process Subscriber Data only as directed by you and as necessary to provide the Services.

2.4 Communications. We collect information you provide when you contact us for support, respond to surveys, or communicate with us by any means.

2.5 Cookies and Tracking Technologies. We use cookies, web beacons, and similar technologies to maintain session state, authenticate users, and collect usage analytics. You may configure your browser to refuse cookies, but doing so may impair Platform functionality. We do not use cross-site tracking for advertising purposes.

3. HOW WE USE INFORMATION

We use collected information for the following purposes:

To provide, operate, maintain, and improve the Platform

To authenticate users and maintain account security

To process payments and manage subscriptions

To provide customer support and respond to inquiries

To send transactional communications (account notices, billing, security alerts)

To monitor for security incidents, fraud, and abuse

To comply with legal obligations, including HIPAA, CCPA, and applicable law

To enforce our Terms of Service and other agreements

To generate anonymized, de-identified, and aggregated analytics about Platform usage (never individual-level PHI)

We do not use Subscriber Data, including PHI, to train AI models or for any purpose beyond providing the contracted Services without your express written consent.

4. SUBPROCESSORS — AMAZON WEB SERVICES AND AWS BEDROCK

We disclose here, as required by applicable law and sound data processing practice, that the following third-party subprocessors process data on our behalf in connection with the Platform. We have contractual agreements with each subprocessor that impose data protection obligations at least as protective as those in this Policy and applicable law.

Amazon Web Services, Inc. (AWS)

Cloud infrastructure: compute, storage, networking, security

Subscriber Data including PHI; account data; audit logs

BAA executed via AWS Artifact; HIPAA-eligible services; SOC 2 Type II; ISO 27001; FedRAMP

AWS Bedrock (Amazon Web Services, Inc.)

AI model inference — processes document text to generate AI Output

Document text submitted for AI processing (may include PHI)

Covered under AWS BAA; HIPAA-eligible; tenant-isolated; data not used to train foundation models

4.1 AWS Bedrock Specific Disclosure. AWS Bedrock is the AI inference service underlying our Platform. When you submit documents for AI processing, the text content of those documents is transmitted to AWS Bedrock for processing. AWS has represented that input data submitted to AWS Bedrock is not used to train or improve foundational AI models. All data transmitted to AWS Bedrock is covered under our executed HIPAA Business Associate Agreement with AWS.

4.2 No Other AI Training on Your Data. We do not transmit your Subscriber Data to any AI provider other than AWS Bedrock. We do not use your Subscriber Data to train, fine-tune, or evaluate any AI model without your express written consent.

4.3 Subprocessor Updates. We will notify Subscribers of any material changes to our subprocessor list at least thirty (30) days in advance by email or in-Platform notice, providing an opportunity to object.

5. DISCLOSURE OF INFORMATION

5.1 Service Providers. We may share information with vetted service providers who assist in operating the Platform (e.g., payment processors, email providers), subject to confidentiality obligations. All such providers are prohibited from using your information for any purpose other than providing services to us.

5.2 Legal Obligations. We may disclose information: (a) in response to a valid court order, subpoena, or legal process; (b) to comply with applicable law or regulatory requirements; (c) to protect the rights, property, or safety of Company, our users, or the public; or (d) in connection with HIPAA breach notification obligations. Where permitted by law, we will notify you before disclosing.

5.3 Business Transfers. In connection with a merger, acquisition, reorganization, or sale of all or substantially all of Company’s assets, your information may be transferred to the successor entity, subject to the same privacy protections. We will notify you of any such transfer and any material change in privacy practices.

5.4 No Sale of Personal Information. We do not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes. This includes the definition of “sale” under the CCPA/CPRA.

5.5 No Cross-Context Behavioral Advertising. We do not share your personal information for cross-context behavioral advertising as defined by the CPRA.

6. CALIFORNIA PRIVACY RIGHTS — CCPA/CPRA

This Section applies to California residents and is provided pursuant to the California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act of 2020 (CPRA), Civil Code § 1798.100 et seq.

6.1 Categories of Personal Information Collected. In the past twelve months, we have collected the following categories of personal information as defined by the CCPA:

Identifiers

Name, email, IP address, account ID

Yes

Professional / Employment Info

Law firm name, bar number, title

Yes

Commercial Information

Subscription and billing records

Yes

Internet / Network Activity

Access logs, session data, feature usage

Yes

Sensitive Personal Information

PHI processed under BAA (governed by HIPAA, not CCPA)

Yes — HIPAA-governed

Geolocation

Approximate location from IP address

Yes — limited

Inferences

Platform usage patterns for product improvement

Yes — aggregated only

6.2 Your CCPA/CPRA Rights. California residents have the following rights, subject to certain exceptions:

Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, our business or commercial purposes, and the categories of third parties with whom we share information.

Right to Delete: You may request deletion of personal information we have collected from you, subject to exceptions (e.g., where we must retain data to comply with a legal obligation or complete a transaction).

Right to Correct: You may request correction of inaccurate personal information we maintain about you.

Right to Opt-Out of Sale/Sharing: We do not sell or share personal information for behavioral advertising. No opt-out is necessary, but you may contact us to confirm.

Right to Limit Use of Sensitive Personal Information: Where we process sensitive personal information beyond what is necessary to provide the Platform, you may request we limit such processing.

Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA/CPRA right.

6.3 How to Exercise Rights. To exercise any CCPA/CPRA right, submit a verifiable consumer request to: privacy@hermosastrategy.com. We will respond within forty-five (45) days, with an extension of an additional forty-five (45) days where reasonably necessary. We may require verification of your identity before processing a request.

6.4 Authorized Agents. You may designate an authorized agent to make CCPA requests on your behalf. We will require written authorization and may verify your identity directly.

6.5 HIPAA Carveout. Personal information that constitutes PHI processed under a BAA is exempt from CCPA to the extent that such information is subject to HIPAA. We process such information in accordance with HIPAA and the applicable BAA.

6.6 “Sales” and “Sharing” of Personal Information. We have not sold or shared personal information for cross-context behavioral advertising in the past twelve months and do not intend to do so. We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age.

7. DATA RETENTION

We retain personal information for as long as necessary to: provide the Platform; fulfill the purposes described in this Policy; comply with legal obligations (including the six-year HIPAA retention requirement under 45 CFR § 164.316(b)(2)); resolve disputes; and enforce our agreements. Subscriber Data is retained for the duration of the subscription plus thirty (30) days post-termination, after which it is securely deleted. Audit logs are retained for six (6) years per our HIPAA compliance program.

8. DATA SECURITY

We implement and maintain administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, or destruction, including:

AES-256 encryption of all data at rest

TLS 1.2+ encryption for all data in transit

Multi-factor authentication (TOTP) required for all user accounts

Logical multi-tenant isolation preventing cross-firm data access

AWS CloudTrail audit logging with WORM (Write Once Read Many) protection

AWS GuardDuty continuous threat detection

Formal HIPAA Security Risk Analysis and Policies and Procedures Manual maintained

No security measures are perfect. In the event of a breach of unsecured PHI, we will notify affected parties in accordance with HIPAA breach notification requirements and our Breach Notification Procedure.

9. CHILDREN’S PRIVACY

The Platform is intended for use by licensed attorneys and legal professionals only. We do not knowingly collect personal information from individuals under the age of 18. If we learn that we have inadvertently collected personal information from a minor, we will delete it promptly.

10. THIRD-PARTY LINKS AND SERVICES

The Platform may contain links to third-party websites or integrate with third-party services. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through the Platform.

11. CHANGES TO THIS POLICY

We may update this Policy at any time. Material changes will be communicated to registered Subscribers via email or in-Platform notice at least thirty (30) days before the effective date. The updated Policy will be posted at app.hermosastrategy.com with a revised effective date. Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.

12. CONTACT US

For privacy questions, CCPA requests, or to contact our Privacy and Security Officer:

Privacy & Security Officer

R. Alexander Comley