LEGAL
Privacy Policy
Last Updated: June 29, 2026
This Privacy Policy describes how Quickflows.ai (“Quickflows,” “we,” “our,” or “us”) collects, uses, discloses, and safeguards information when you use our services, including our workflow automation platform and any third-party health data integrations accessed on your behalf.
This Policy applies to all users and is specifically designed to comply with applicable federal and state privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA), the Federal Trade Commission Act (FTC Act), and applicable state consumer protection statutes. Our health data practices also align with the CARIN Alliance Code of Conduct, the ONC Model Privacy Notice (MPN), and CMS recommended best practices for app developers.
1. Information We Collect
1.1 Information You Provide
We collect information you provide directly to us when you:
- Fill out a contact form, request a demo, or register for an account
- Communicate with our team via email or phone
- Authorize our application to access your health information through a third-party health plan API (such as SelectHealth)
This may include your name, work email address, company name, phone number, and any details you share about your operations.
1.2 Health Information Accessed via Third-Party APIs
When you explicitly authorize Quickflows to connect with a health plan’s API on your behalf (e.g., SelectHealth’s Patient Access API), we may access the following categories of health data as permitted by your authorization:
- Claims and Explanation of Benefits (EOB) data – including insurance claims history, cost-sharing information, and payment records
- Clinical data – including diagnoses, medications, lab results, and clinical notes
- Coverage and benefits information – including plan details, deductibles, copays, and coverage limits
- Provider information – including in-network providers and care team details
This data is accessed solely through FHIR-based APIs using SMART on FHIR / OAuth 2.0 authorization flows, and only with your explicit, informed consent.
1.3 Technical and Usage Data
We automatically collect limited technical data when you visit our website or use our platform, including your IP address, browser type, pages visited, and referring URLs. This is used solely to improve our services and understand how visitors interact with our content.
2. How We Use Your Information
2.1 Permitted Uses
We use the information we collect only for the following purposes:
- To provide and operate our workflow automation platform and services
- To fulfill the specific purpose for which you authorized access to your health information
- To respond to your inquiries, schedule demonstrations, and send relevant service updates
- To improve our platform, fix bugs, and enhance the user experience
- To comply with applicable legal obligations
2.2 Health Data – Strict Use Limitations
Health information accessed through third-party APIs (including claims, clinical, coverage, and provider data) is used ONLY for the specific purpose you authorized. We will not:
- Use your health data for advertising, marketing, or promotional purposes
- Use your health data to make or inform employment decisions
- Use your health data for credit, insurance underwriting, or financial decisions not authorized by you
- Use your health data for any secondary purpose beyond what you explicitly authorized
This limitation is a core commitment of our service and aligns with the CARIN Alliance Code of Conduct and CMS recommended best practices for third-party app developers.
3. We Will Never Sell Your Health Data
Quickflows does not sell, rent, trade, or otherwise transfer your personal information or health data to third parties for their own commercial purposes. This prohibition applies unconditionally, including in the event of a business transaction such as a merger, acquisition, or sale of assets.
In the event of a change of ownership or business acquisition, any acquirer will be required to honor the terms of this Privacy Policy or obtain fresh consent from you before using your information in any manner inconsistent with it.
4. How We Share Your Information
We do not share your personal or health information except in the following limited circumstances:
- Service Providers: We share data with trusted third-party vendors (e.g., cloud hosting, analytics, customer communication tools) who process data on our behalf and are contractually required to protect it and use it only as directed by Quickflows.
- Health Plan APIs: When you authorize API connections (e.g., SelectHealth), data is exchanged only as required to fulfill your authorized request.
- Legal Requirements: We may disclose information if required by law, court order, or government authority, or to protect the rights, property, or safety of Quickflows, our users, or the public.
- With Your Consent: We may share your information for any other purpose with your explicit prior consent.
We do not share your health data with data brokers, advertisers, or any third party for purposes unrelated to the service you have requested.
5. HIPAA and Health Data Compliance
To the extent that Quickflows accesses, processes, or stores Protected Health Information (PHI) as defined under HIPAA, we comply with all applicable requirements of the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (45 CFR Parts 160 and 164).
Where required, we enter into Business Associate Agreements (BAAs) with covered entities and other business associates. We implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI in accordance with the HIPAA Security Rule.
We also comply with all applicable state health privacy laws, which may provide additional protections beyond HIPAA.
6. Regulatory Framework Compliance
Our privacy and data handling practices are designed to comply with and align with the following frameworks, as required by SelectHealth and other health plan API access agreements:
6.1 CARIN Alliance Code of Conduct
We adhere to the CARIN Alliance Code of Conduct, which establishes responsible data practices for third-party health applications, including:
- Transparency about data collection and use
- Prohibition on selling health data
- Limiting data use to authorized purposes
- Providing users with meaningful control over their data
- CARIN Alliance Code of Conduct
6.2 FTC Privacy and Security Recommendations
We follow the FTC’s “Start with Security” framework, including:
- Collecting only the data necessary for the services we provide
- Protecting data in storage and transmission with industry-standard encryption
- Implementing access controls to limit who can view sensitive information
- Maintaining a data breach response plan
- FTC Start with Security Guide
6.3 CMS Recommended Best Practices
We follow CMS recommended best practices for payers and app developers operating under the CMS Interoperability and Patient Access Rule (CMS-9115-F), including responsible handling of patient data obtained via FHIR APIs.
- CMS Best Practices for Payers and App Developers
6.4 ONC Model Privacy Notice (MPN)
In alignment with the ONC Model Privacy Notice, we provide clear, plain-language disclosures about:
- What data we collect (see Section 1)
- How we use your data (see Section 2)
- Whether we sell your data – We do not (see Section 3)
- Who we share your data with (see Section 4)
- How you can delete your data (see Section 9)
- What happens if our business is acquired (see Section 3)
- ONC Model Privacy Notice
7. Your Rights and Controls
7.1 Right to Revoke Health Data Access
You may revoke Quickflows’ access to your health data at any time by:
- Contacting us at info@quickflows.ai
- Revoking access directly through your health plan’s member portal (e.g., SelectHealth’s developer portal)
Upon revocation, we will cease accessing your health data and will delete or de-identify any previously retrieved data within 30 days, unless we are legally required to retain it.
7.2 Access, Correction, and Deletion
Depending on your location and applicable law, you may have the right to:
- Access the personal information or health data we hold about you
- Correct inaccurate or incomplete information
- Request deletion of your personal information or health data
- Restrict or object to certain processing of your data
- Receive a copy of your data in a portable format
To exercise any of these rights, please contact us at info@quickflows.ai. We will respond within 30 days.
7.3 Know What Health Data Was Accessed
Upon request, we will provide you with a summary of what health data was accessed through third-party API connections on your behalf and when that access occurred.
8. Data Security
We implement industry-standard administrative, physical, and technical safeguards to protect your information, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256)
- Role-based access controls limiting who can access sensitive data
- Regular security assessments and vulnerability management
- Secure credential management for API tokens and OAuth credentials
- Employee training on data privacy and security practices
In the event of a data breach that affects your personal information or health data, we will notify you and applicable regulatory authorities within 60 days of discovering the breach (or within the timeframe required by applicable law, whichever is sooner). Notification will include the nature of the breach, the types of data affected, and the steps we are taking in response.
No method of transmission over the internet is 100% secure. While we implement strong safeguards, we cannot guarantee absolute security.
9. Data Retention and Deletion
We retain your personal information and health data for as long as necessary to provide our services or as required by applicable law. Health data accessed via third-party APIs is retained only as long as needed to fulfill the authorized purpose.
If you wish to have your data deleted, please contact us at info@quickflows.ai. We will delete or de-identify your data within 30 days of your request, subject to any legal retention requirements.
10. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to provide a better browsing experience, analyze traffic, and understand how you interact with our content. We do not use cookies to track your health-related activities.
You can control cookie settings through your browser preferences. Disabling cookies may affect certain features of our website.
11. Third-Party Services and Links
We use trusted third-party service providers for analytics, customer communication, scheduling, and cloud infrastructure. These providers process data on our behalf and are contractually bound to protect it and use it only as directed.
Our platform may include links to third-party websites or services. This Privacy Policy does not apply to those third-party sites, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access.
12. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a minor, please contact us at info@quickflows.ai and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of material changes by:
- Updating the “Last Updated” date at the top of this page
- Sending an email notification to registered users where appropriate
Your continued use of our services after changes are posted constitutes your acceptance of the updated policy. If you do not agree to the updated policy, you should stop using our services and may request deletion of your data.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us:
We are committed to resolving any privacy concerns promptly and transparently.