Privacy Policy
Last updated: September 22, 2026
Roman Copilot AI, Inc., doing business as Roman AI (“Roman AI,” “we,” “us,” or “our”), is committed to protecting the privacy and security of information processed through our website, platform, and services.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you interact with Roman AI.
1. Information We Collect
Information provided by customers and users
We may collect information such as:
- Name
- Email address
- Phone number
- Company or practice name
- Job title
- Account and login information
- Communications, support requests, and feedback
- Business and billing information
- Information submitted during onboarding, demonstrations, pilots, or use of the Roman AI platform
Healthcare and customer data
Roman AI may receive or process information from healthcare customers, including operational, patient-related, scheduling, treatment, communication, and other healthcare information necessary to provide our services.
Where such information constitutes Protected Health Information (“PHI”) under HIPAA, Roman AI processes it on behalf of the applicable healthcare customer.
Information collected automatically
When you use our website or platform, we may collect:
- IP address
- Browser and device information
- Operating system
- Usage and activity information
- Log data
- Cookies and similar technologies
2. How We Use Information
We use information to:
- Provide, operate, maintain, and improve Roman AI services
- Analyze clinic operations and identify actionable revenue opportunities
- Create and manage user accounts
- Authenticate users and protect account security
- Provide customer support
- Analyze product usage and performance
- Develop and improve product features
- Communicate with customers and users
- Detect, investigate, and prevent fraud, misuse, unauthorized access, and security incidents
- Comply with contractual, legal, regulatory, and compliance obligations
- Enforce our agreements and policies
3. Information Sharing
We do not sell personal information to advertisers.
We may share information with:
- Healthcare customers: Information may be made available to the healthcare organization responsible for the applicable patient or account.
- Service providers and subprocessors: Third-party providers may support hosting, infrastructure, communications, security, analytics, development, and other business functions.
- Professional advisers: Including attorneys, accountants, auditors, consultants, and compliance advisers.
- Legal and regulatory authorities: Where required by law, regulation, subpoena, court order, or other legal process.
- Business transaction parties: In connection with a merger, acquisition, financing, restructuring, or sale of all or part of our business.
Service providers and subprocessors are subject to contractual privacy and security obligations appropriate to the services they provide.
Where a provider creates, receives, maintains, or transmits PHI on our behalf, Roman AI requires appropriate HIPAA protections, including a Business Associate Agreement where required.
4. HIPAA Compliance
Roman AI may act as a Business Associate under the Health Insurance Portability and Accountability Act (“HIPAA”) when it creates, receives, maintains, or transmits PHI on behalf of a Covered Entity.
In such circumstances:
- Roman AI handles PHI in accordance with HIPAA
- Roman AI enters into Business Associate Agreements with applicable healthcare customers
- PHI is used or disclosed only as permitted by the applicable agreement and law
- Access to PHI is restricted to authorized personnel and systems with a legitimate business need
- Roman AI maintains administrative, technical, and physical safeguards designed to protect PHI
Individuals seeking to exercise HIPAA rights relating to PHI should generally contact the healthcare provider or organization responsible for their information. Roman AI will assist the applicable Covered Entity as required by law or contract.
5. Data Security
Roman AI maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, or misuse.
These safeguards may include:
- Access controls and least-privilege access
- Multi-factor authentication
- Encryption in transit and at rest where appropriate
- Logging and monitoring
- Security awareness training
- Vendor risk management
- Vulnerability management
- Incident response procedures
- Backup and recovery controls
No information system can be guaranteed to be completely secure.
6. Data Retention
Roman AI retains information for as long as reasonably necessary to:
- Provide and support our services
- Maintain customer relationships
- Meet contractual obligations
- Comply with legal and regulatory requirements
- Resolve disputes
- Protect the security and integrity of our systems
Customer and healthcare data is retained and deleted in accordance with applicable customer agreements, Business Associate Agreements, legal requirements, and Roman AI retention policies.
7. Your Privacy Rights
Depending on your location and applicable law, you may have rights regarding your personal information, including the right to request:
- Access
- Correction
- Deletion
- Information regarding how your personal information is used or disclosed
- Restriction or objection to certain processing, where applicable
These rights may be subject to legal and contractual limitations.
Requests involving PHI maintained on behalf of a healthcare provider may be referred to the applicable healthcare provider.
8. Subprocessors
Roman AI may engage service providers and subprocessors to support delivery of its services.
These providers may support functions such as:
- Cloud hosting and infrastructure
- Security
- Communications
- Analytics
- Development
- Compliance
- Business operations
Where required, subprocessors are subject to contractual privacy and security obligations, including Business Associate Agreements where applicable.
Where required by applicable agreement or law, customers authorize Roman AI’s use of subprocessors through their applicable service agreement, customer terms, or data processing terms.
9. Cookies and Analytics
Our website and services may use cookies and similar technologies to:
- Operate the website
- Maintain security
- Understand usage
- Improve performance
- Analyze interactions with our services
Users may control certain cookies through their browser settings.
10. Children
Roman AI’s website and commercial services are not directed to children under 13, and we do not knowingly collect personal information directly from children through our public website.
11. Changes to This Privacy Policy
Roman AI reviews this Privacy Policy at least annually to confirm its continued accuracy and suitability and updates it as necessary.
We may also update this policy when our services, practices, legal obligations, or technology change.
When updates are made, we will revise the Last updated date.
Where required by law or where changes materially affect how personal information is used, we will provide appropriate notice to affected customers or users.
12. Contact Us
For privacy-related questions, complaints, disputes, or requests, contact:
Roman Copilot AI, Inc. d/b/a Roman AI
Email:
rk@romancopilot.ai