Customer Data Privacy Notice.
This notice explains how Mulholland, Inc. ("Mulholland," "we," "us," or "our") handles customer data: the data our customers put into MarzyOS and the data we handle while performing services for them. It is a summary. Each customer's signed agreements govern: the Master Services Agreement (which includes the Data Processing Addendum), the Business Associate Agreement, our Professional Services Terms, and each Order Form and statement of work (SOW). If anything here differs from those agreements, the agreements control.
Where this notice describes a specific term, it describes the current versions: MSA v1.6 (including the DPA), BAA v1.1, and PST v1.5. If your Order Form incorporates an earlier version, that version governs. For personal information we handle for our own purposes, such as on our websites, see our Privacy Policy.
Our role.
For customer data, we act on the customer's behalf. Under the DPA, we are the customer's processor and, under California law, its service provider. When a customer's Order Form incorporates our BAA, we are also its HIPAA business associate. If a customer is itself a processor or business associate for someone else, we act as its subprocessor or subcontractor.
As between us, you own the data you connect or submit, your ontology, and output, and we treat them as your confidential information. We process customer data on your documented instructions, which include the agreements themselves and what you direct through the platform.
What customer data we handle.
- Data you connect or submit. Documents, records, messages, business rules, and other material your team puts into MarzyOS or gives us while we work for you, and data we retrieve from your own systems, such as your practice-management system, at your direction.
- Data we access at your direction. Information we retrieve from third-party portals and services you ask us to work in, such as an insurance payer's portal.
- Output. The results, records, reports, and communications MarzyOS produces for you.
- Records the platform generates. The model of your business we configure in MarzyOS (your ontology), model inputs and outputs, workflow traces, receipts and session recordings, and the corrections, ratings, and labels your users or our staff make.
When your Order Form or SOW includes billing and revenue-cycle services, the claims, appeals, statements, correspondence, and account and payment records we prepare or submit in your name are your customer data too.
Customer data can include personal information about your patients, clients, contacts, vendors, and employees, and about your users. Your users' account details, such as their names and work email addresses, are customer data that we handle for you. The one exception is what we use to administer our own contract and billing relationship with you, such as the contact details of the people who manage your account with us, sign your agreements, or receive your invoices; our Privacy Policy covers that use.
You may not give us protected health information, payment-card data, government ID numbers, biometric identifiers, or children's personal data unless a signed agreement allows it; for health information, that means an Order Form that incorporates our BAA.
How we use it.
- To provide, secure, support, maintain, and improve MarzyOS and our services for you, including any billing and revenue-cycle services in your Order Form or SOW.
- To follow your instructions and to comply with the law.
- Under MSA v1.4 or later, to create de-identified data, as described under "Model training" below.
We use and disclose protected health information only as the BAA permits. As a service provider, we do not sell or share personal information in customer data, as California law uses those words.
We disclose customer data to others only at your direction or as the agreements allow, or where the law requires. For example, at your direction we share it with insurance payers and clearinghouses when we check benefits or submit claims for you. When we provide billing and revenue-cycle services, we submit claims, appeals, and statements to payers and patients only in your name and, unless your Order Form or SOW says otherwise, they pay you, not us.
How customer data is kept separate.
Each customer's data is logically isolated within our multi-tenant environment. Every customer record carries a tenant identifier that cannot be changed, and forced row-level security in the database lets a customer's sessions read and write only that customer's data. Named Mulholland engineers can reach data across customers for support, operations, and security. They do not use that access to export, combine, or de-identify customer data; only service identities bound to a single customer do that. Single-tenant or customer-hosted deployment is available only where an Order Form or addendum expressly provides for it.
Subprocessors and locations.
We use subprocessors, such as cloud hosting, model providers, and network services, to run MarzyOS and our services. Annex C of the DPA lists our current subprocessors with each one’s purpose and processing location, and under the DPA the Subprocessor List on our Trust Center at trust.mulholland.ai is the authoritative list.
Not all processing happens in the United States. For example, our serving edge operates globally, and for customers whose Order Form or SOW includes billing and revenue-cycle services, individual revenue-cycle support contractors in the Philippines may do part of that work, under written confidentiality terms and, for protected health information, subcontractor business associate terms. Our subprocessor list identifies this contractor category and its location rather than each person. Before a contractor first processes your personal data, we send you a notice of the engagement, without names, and on request we tell you who has worked, or is assigned to work, on your data.
Each subprocessor is bound in writing by data protection terms at least as protective as the DPA, and we remain responsible for them. Before a new subprocessor processes customer personal data, we give customers at least 30 days' notice and a chance to object, as DPA §4.3 describes. A new subprocessor includes any company not already on the list, even one that replaces a listed provider for the same purpose and location, and a listed provider that will process new kinds of personal data or process it somewhere new. If an objection is not resolved, you may end the affected Order Form or SOW, or only the affected services, and get a refund of prepaid, unused fees for them, including billing services. Engaging or replacing an individual revenue-cycle contractor in the Philippines does not count as a new subprocessor; we send the update described above instead.
Security.
Customer personal data is encrypted at rest (AES-256 or equivalent) and in transit (TLS 1.2 or higher). Access follows least privilege, administrative access requires multi-factor authentication, and access to systems that process customer personal data is logged. Annex B of the DPA lists our security measures, and our Security page and Trust Center describe our program and its current status.
Model training.
Under version 1.4 or later of our Master Services Agreement, we may de-identify customer data that we first receive or generate on or after the effective date of the Order Form or amendment by which the customer first agrees to one of those versions (but not earlier data, or new data made by reprocessing earlier data), and use the resulting de-identified data for any lawful purpose, including to train our own models, which we may sell or license to others. Those versions bar us from using identifiable customer data to train any model used for another customer, and from letting outside model providers, such as OpenAI and Google, or other subprocessors train their own models on customer data or on de-identified data made from it. Customers on earlier versions keep the terms they signed.
De-identified data must meet the legal standard that applies to it. For protected health information, that means HIPAA's expert determination method, which we use for free text, documents, images, and model inputs and outputs, or, for structured data fields only, its safe harbor method. When we de-identify customer data, we do it inside your logically isolated environment before combining the result with any other data. We first remove credentials, payment-card data, government ID numbers, financial-account numbers, and biometric identifiers, and we do not de-identify certain data at all, including information about children under 18 and tax return information.
We maintain and use de-identified data only in de-identified form and will not attempt to re-identify it. We do not name you to others as a source, except in confidence or where the law requires, and we do not use de-identified patient information, or our models, to market to your patients. If information we treated as de-identified turns out not to be, it stays your data: we tell you, remove it, and retrain, modify, or retire any model that can output it. Once data is de-identified, it is no longer customer data. As between us and you, we own it and the models built with it, and our Privacy Policy describes how we use it.
Export and deletion.
You can export the data you connect or submit, your ontology, and output in machine-readable formats while an Order Form or SOW is in effect or we are providing free services to you and, on written request, for 60 days after they have all ended (or after the agreement is terminated, if that comes first).
Within 30 days after that 60-day period, we delete the personal data in your customer data, or return it to you first if you ask in writing during the 60 days, and we require our subprocessors to delete it too. Copies the law requires us to keep, and copies in routine backups, stay protected under the DPA until they are deleted, and we use them only for the reason we keep them. For protected health information, the BAA's return-or-destroy terms also apply. Any model we trained only for you on your identifiable data is deleted on the same schedule. De-identified data and the models built with it are not returned or deleted.
Requests about customer data.
If someone asks us to access, correct, or delete their personal information in customer data, we forward the request to the customer and refer the person to the customer, unless the law requires us to respond. We help customers respond as the DPA and BAA require, including to patient requests under HIPAA. If a government authority demands customer personal data from us, we try to redirect it to the customer and, if we must disclose, we give the customer notice first unless the law forbids it.
Security incidents.
If we confirm a security breach affecting customer personal data, we notify the customer in writing without undue delay, and within 72 hours or any shorter period the law requires, and we work to contain, investigate, and mitigate it. For protected health information, we report a breach of unsecured protected health information within 10 days after we discover it, or sooner if the law requires. We cooperate with customers on any notices they must give.
Changes to this notice.
We may update this notice from time to time. When we do, we will revise the "Last updated" date above. Updating this notice does not change any signed agreement.
Contact.
Questions about this notice or about customer data: privacy@mulholland.ai. Security matters: security@mulholland.ai. Formal notices under the agreements go to the address in the MSA, with a copy to legal@mulholland.ai.