Privacy Notice
- Effective
- July 4, 2026
- Last Updated
- July 4, 2026
- Version
- 1.0
Privacy at a Glance
At Wenixo, protecting patient privacy is fundamental to everything we build. Our products are designed to help healthcare professionals deliver efficient, high-quality care while maintaining the confidentiality, integrity, and security of the information entrusted to us.
The Privacy Notice explains how Wenixo (“Wenixo”, “we”, “our”, or “us”) collects, uses, discloses, stores, and safeguards information when providing our products, services, website, and related technologies.
Key Privacy Commitments
- HIPAA-First: Where applicable, Wenixo acts as a HIPAA Business Associate and processes Protected Health Information (PHI) only under an executed Business Associate Agreement (BAA).
- Privacy by Design: Privacy and security are integrated into the design and development of our products from the outset.
- Customer Control: Clinics retain ownership and control of their data. Wenixo processes information only as necessary to provide the requested services.
- Responsible AI: Artificial intelligence assists healthcare professionals but does not replace clinical judgment or make independent medical decisions.
- No Unauthorized AI Training: Wenixo does not use customer PHI or clinical content to train or improve artificial intelligence models without the applicable Clinic’s express written authorization.
- No Sale of Personal Information: Wenixo does not sell or rent personal information or Protected Health Information.
If you have questions about this Privacy Notice or our privacy practices, please contact us using the information provided in Section 20 – Contact Us.
Table of Contents
We’re Here to Help#
We understand that privacy is essential to the trust placed in healthcare providers and the technology they use. Whether you are a healthcare professional, patient, or visitor to our website, we are committed to being transparent about how information is handled.
If you have questions regarding this Privacy Notice, wish to report a privacy concern, or would like additional information regarding our security or compliance practices, please contact us.
Privacy Inquiries: privacy@wenixo.com
Security Reporting: security@wenixo.com
Legal Requests: legal@wenixo.com
Support: contact@wenixo.com
Website: https://www.wenixo.com
We strive to respond to privacy-related inquiries within ten (10) business days.
About Wenixo#
Wenixo LLC develops healthcare technology that helps licensed healthcare organizations deliver more efficient, secure, and compliant patient care. Our products combine artificial intelligence with secure clinical workflows to reduce administrative burden while maintaining provider oversight, patient privacy, and regulatory compliance.
Depending on the services selected by a Clinic, Wenixo may provide the following products and features:
Wenixo Ambient AI: AI-assisted transcription and clinical documentation that helps providers generate structured medical notes from patient encounters.
Wenixo Clinical Imaging: Secure clinical photography tools designed for medical documentation, longitudinal comparison, and clinical workflow management.
Wenixo Live Translation: Real-time multilingual communication tools that assist providers and patients during clinical encounters.
Additional products and services may be introduced over time. When new services materially change our privacy practices, we will update this Privacy Notice accordingly.
Who This Policy Applies To#
This Privacy Notice applies to information processed by Wenixo in connection with our website, products, and services. Specifically, it applies to:
Healthcare Organizations (“Clinics”): Licensed healthcare providers, physician practices, hospitals, ambulatory centers, and other healthcare organizations that subscribe to Wenixo services.
Clinical Users: Individuals authorized by a Clinic to access Wenixo, including physicians, physician assistants/associates (PA), nurse practitioners, nurses, medical assistants, administrators, billing personnel, contractors, and other authorized workforce members.
Patients: Patients whose information is processed through Wenixo solely on behalf of the applicable Clinic during the provision of healthcare services.
Patients do not create individual Wenixo accounts. Wenixo processes patient information only under the direction of the applicable Clinic.
Website Visitors: Individuals who visit our public website or otherwise communicate with Wenixo regarding our products or services.
Definitions#
For purposes of this Privacy Notice:
Business Associate means an entity that performs services involving Protected Health Information on behalf of a HIPAA Covered Entity, as defined under HIPAA.
Clinic means a licensed healthcare provider or healthcare organization using Wenixo products or services.
Clinical User means an individual authorized by a Clinic to access Wenixo.
Covered Entity has the meaning assigned under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).
Personal Information means information that identifies, relates to, describes, or can reasonably be associated with an identifiable individual, as defined under applicable privacy laws.
Protected Health Information (PHI) has the meaning assigned under HIPAA and generally includes individually identifiable health information created, received, maintained, or transmitted by a Covered Entity or Business Associate.
Services means Wenixo’s website, software applications, APIs, integrations, mobile applications, and any products or services that we make available to customers.
Our Role Under HIPAA#
Wenixo is designed to support healthcare organizations that are subject to the Health Insurance Portability and Accountability Act (“HIPAA”).
Where a customer qualifies as a HIPAA covered entity, Wenixo generally acts as a Business Associate when processing Protected Health Information on that customer’s behalf. Our responsibilities are governed by an executed Business Associate Agreement (“BAA”) between Wenixo and the applicable Clinic.
As a Business Associate, Wenixo processes Protected Health Information only:
- to provide the services requested by the Clinic;
- in accordance with the applicable BAA;
- in accordance with HIPAA and other applicable laws; and
- under the documented instructions of the applicable Clinic.
Wenixo does not determine medical treatment, establish patient-provider relationships, or make independent clinical decisions.
The applicable Clinic remains responsible for:
- determining the appropriate use of Wenixo;
- obtaining any required patient consent or authorizations;
- ensuring compliance with applicable healthcare laws;
- reviewing and approving clinical documentation before it becomes part of the medical record.
Where Wenixo processes information outside the scope of HIPAA, for example, website inquiries, recruiting activities, or communications regarding our services - we process such information in accordance with this Privacy Notice and applicable privacy laws.
Information We Collect#
Wenixo collects only the information necessary to provide, secure, maintain, and improve our Services. The information we collect depends on how a Clinic uses our Services and the features it has enabled.
The categories of information we collect are described below.
| Category | Examples | Purpose |
|---|---|---|
| Account Information | Name, professional title, email address, organization, user role, authentication credentials (encrypted), account preferences | To create and manage user accounts, authenticate users, and administer access to our Services. |
| Wenixo Ambient AI | Audio recordings submitted for documentation, transcriptions, AI-generated clinical notes, encounter metadata, provider edits and approvals | To generate, review, and maintain clinical documentation at the discretion of the applicable Clinic. |
| Patient Information | Patient name, date of birth, encounter identifiers, and other information entered by Clinical Users. | To associate documentation and workflows with the appropriate patient encounter and support healthcare delivery. |
| Wenixo Clinical Imaging | Clinical photographs, image metadata, capture timestamps, anatomical region identifiers, and documented patient consent records where applicable | To support clinical documentation, longitudinal comparison, and medical imaging workflows. |
| Wenixo Live Translation | Voice audio (processed only transiently during active translation sessions and never stored), transcribed and translated text, translated speech, and session metadata | To facilitate real-time communication between healthcare providers and patients. Voice audio is not stored; an encrypted transcript and an AI-generated clinical note of the session are retained on behalf of the applicable Clinic as described in Section 12. |
| Operational & Security Information | Login history, authentication events, IP addresses, browser type, device information, audit logs, API activity, and security event data | To maintain platform security, detect unauthorized activity, investigate incidents, and comply with legal and regulatory requirements. |
| Communications | Support requests, email correspondence, feedback, survey responses, and product inquiries | To respond to requests, provide customer support, and improve our Services. |
| Website Information | Pages visited, browser information, referring pages, and other technical website usage information | To operate our website, maintain security, and understand website performance. No Protected Health Information is collected through our public website. |
Information We Do Not Intentionally Collect
Unless specifically required to provide a requested service, Wenixo does not intentionally collect:
- Biometric identifiers or biometric information as defined under applicable law.
- Facial recognition data or facial geometry.
- Personal information unrelated to the delivery of our Services.
- Protected Health Information through our public website.
Clinical Users should avoid entering information into fields that are not intended to store Protected Health Information.
How We Collect Information#
Wenixo collects information from several sources depending on how our Services are used.
Information Provided by Clinics
When a Clinic establishes an account with Wenixo, we receive information necessary to create and administer the organization’s account, including organization details, authorized users, billing contacts, and administrative preferences.
Information Provided by Clinical Users
Clinical users may provide information when they:
- Create or update their user profile.
- Record patient encounters.
- Generate clinical documentation.
- Upload clinical photographs.
- Use live translation features.
- Contact our support team.
- Submit feedback regarding our Services.
Information Generated During Use of Our Services
As our Services are used, we automatically generate operational information necessary to provide secure and reliable functionality, including authentication events, audit logs, system activity, and performance metrics.
Automatically Collected Technical Information
When users access our website or Services, we may automatically collect technical information such as:
- Device type
- Operating system
- Browser type
- IP address
- Session identifiers
- Diagnostic information
- Performance metrics
- Security logs
This information helps us maintain the availability, performance, and security of our Services.
How We Use Information#
Wenixo uses information only for legitimate business, operational, security, and healthcare purposes consistent with this Privacy Notice, our agreements with our customers, and applicable law.
| Purpose | How We Use Information |
|---|---|
| Provide Our Services | Deliver clinical documentation, imaging, translation, workflow automation, and other features requested by our customers. |
| Generate AI-Assisted Documentation | Produce draft clinical documentation and related outputs at the direction of authorized Clinical Users. |
| Authenticate Users | Verify user identity and manage secure access to our services. |
| Protect Security | Detect fraud, unauthorized access, abuse, malicious activity, and security threats. |
| Maintain Compliance | Maintain audit logs, satisfy legal obligations, and support compliance with HIPAA and other applicable laws. |
| Customer Support | Respond to support requests, troubleshoot issues, and improve customer experience. |
| Communicate with Customers | Send important service announcements, security notifications, maintenance notices, and administrative communications. |
| Improve Our Services | Analyze operational metrics, reliability, and performance to improve the quality, security, and usability of our Services. Any use of Protected Health Information for these purposes is limited to operational, reliability, security, and performance analysis conducted in accordance with applicable law and our contractual obligations. Wenixo does not use Protected Health Information to train or improve artificial intelligence models except as expressly authorized in writing by the applicable Clinic. |
What We Do Not Do
To help customers understand our privacy commitments, we believe it is equally important to explain what Wenixo does not do.
Unless expressly authorized by the applicable Clinic or required by law, Wenixo does not:
- Sell or rent personal information or Protected Health Information.
- Share Protected Health Information with advertisers or data brokers.
- Use customer Protected Health Information to train or improve artificial intelligence models.
- Permit third parties to use customer data for their own independent purposes.
- Make autonomous medical diagnoses or treatment decisions.
Artificial Intelligence#
Artificial intelligence ("AI") is an integral part of Wenixo's Services. Our AI features are designed to assist healthcare professionals by reducing administrative burden, improving documentation efficiency, and enhancing clinical workflows.
AI is intended to support and not replace the professional judgment, expertise, or decision-making of licensed healthcare providers.
AI Features
Depending on the Services enabled by a Clinic, Wenixo may use AI to:
- Generate draft clinical documentation from provider-directed recordings or transcripts.
- Assist with clinical documentation formatting and organization.
- Translate spoken conversations between providers and patients in real time.
- Enhance clinical workflow efficiency through automation and intelligent assistance.
- Support other AI-powered features introduced as part of our Services.
We continually evaluate our AI capabilities to improve performance, reliability, and usability while maintaining appropriate privacy and security safeguards.
Human Review and Clinical Responsibility
All AI-generated outputs are intended to assist Clinical Users and must be reviewed by an appropriately authorized healthcare professional before being relied upon or incorporated into the patient's medical record.
Clinical Users remain solely responsible for:
- verifying the accuracy and completeness of AI-generated content;
- exercising independent professional judgment;
- correcting inaccuracies or omissions;
- determining the appropriate diagnosis, treatment, and medical decision-making; and
- approving documentation before it becomes part of the patient's official medical record.
Wenixo does not practice medicine, provide medical advice, establish provider-patient relationships, or make independent clinical decisions.
AI Limitations
Artificial intelligence is an assistive technology and may occasionally produce inaccurate, incomplete, or unintended outputs. Examples may include:
- omitted information;
- incorrect wording;
- formatting inconsistencies;
- transcription errors;
- translation inaccuracies; or
- other generated content requiring correction.
Clinical Users should carefully review all AI-generated outputs before using them for clinical, operational, legal, or billing purposes.
AI Model Training
Protecting customer information is one of our core privacy commitments.
Unless expressly authorized in writing by the applicable Clinic, Wenixo does not use customer Protected Health Information, clinical documentation, patient recordings, medical images, or other customer clinical content to train or improve artificial intelligence models.
Where Wenixo uses third-party AI providers to deliver Services, those providers process information solely for the purpose of providing the requested functionality under contractual confidentiality obligations and, where applicable, Business Associate Agreements or other legally appropriate data processing agreements.
Responsible AI Principles
Wenixo is committed to developing and deploying AI responsibly. Our approach is guided by the following principles:
Human Oversight: AI supports healthcare professionals but does not replace human judgment.
Privacy by Design: Privacy and security considerations are incorporated throughout the design, development, testing, and deployment of AI-powered features.
Data Minimization: We process only the information reasonably necessary to provide the requested Services.
Transparency: We strive to clearly communicate how AI features operate, their intended use, and their limitations.
Continuous Improvement: We regularly evaluate AI system performance and implement improvements designed to enhance reliability, security, and usability.
Clinical Imaging & Biometric Privacy#
Certain Wenixo Services allow Clinics to capture clinical photographs for medical documentation and patient care.
These features are intended solely for legitimate healthcare purposes and are subject to the privacy and security safeguards described in this Privacy Notice.
Clinical Imaging
Clinical photographs may be collected and processed for purposes including:
- documenting clinical findings;
- monitoring treatment progression;
- supporting longitudinal comparison;
- improving clinical communication; and
- maintaining medical documentation.
Clinical photographs are associated with the applicable patient encounter and processed only on behalf of the applicable Clinic.
Patient Consent
Where required by applicable law, regulation, or Clinic policy, the applicable Clinic is responsible for obtaining any necessary patient authorization or consent before capturing clinical photographs using Wenixo.
Wenixo provides functionality to support documentation of consent where applicable but does not determine whether consent is legally required for a particular encounter.
Facial Image Detection
To help protect patient privacy and minimize the collection of biometric information, Wenixo is designed to prevent the storage of facial images within its clinical imaging workflows.
During image capture, Wenixo automatically analyzes the image to determine whether recognizable human facial features are present. Wenixo is designed to reject images in which a face is detected, preventing them from being uploaded, saved, or associated with a patient record within Wenixo.
The facial validation process is performed solely to determine whether the image satisfies Wenixo's imaging requirements. Wenixo does not use this process for facial recognition, identity verification, biometric identification, or the creation of biometric templates.
Because images containing facial features are rejected before they are accepted into the platform, Wenixo is designed to avoid the routine collection and retention of facial images through its clinical imaging functionality.
Biometric Privacy
Wenixo does not intentionally collect, capture, store, purchase, receive through trade, or otherwise obtain biometric identifiers or biometric information as those terms are defined under applicable biometric privacy laws, including the Illinois Biometric Information Privacy Act (BIPA).
Specifically, Wenixo does not:
- perform facial recognition;
- create or retain facial templates;
- generate or store facial geometry;
- identify individuals using biometric characteristics;
- sell, lease, trade, or otherwise profit from biometric information; or
- use facial images for authentication or identity verification.
Our clinical imaging workflows are intentionally designed to reject images containing recognizable facial features before they are stored, reducing the likelihood that facial images or biometric information will be collected as part of routine clinical documentation.
Image Retention
Clinical photographs are retained in accordance with:
- the applicable Clinic's retention policies;
- applicable law;
- contractual obligations; and
- Wenixo's default retention settings, where applicable.
When imaging records are scheduled for deletion, Wenixo securely deletes the associated data in accordance with our data retention practices and applicable legal requirements.
Data Sharing & Service Providers#
Wenixo shares information only as necessary to provide our Services, comply with applicable law, protect the security of our systems, or fulfill our contractual obligations. We do not sell personal information or Protected Health Information.
Service Providers
We work with carefully selected third-party service providers that assist us in operating our business and delivering our Services.
Depending on the Services provided, these vendors may support:
- cloud hosting and infrastructure;
- secure data storage;
- artificial intelligence processing;
- authentication and identity management;
- transactional email delivery;
- customer support;
- system monitoring;
- security operations; and
- payment processing.
Service providers receive access only to the information reasonably necessary to perform the services for which they have been engaged.
Where required, such providers are contractually obligated to maintain appropriate confidentiality, security, and privacy protections and may process information only in accordance with our instructions.
Healthcare Customers
Information processed through Wenixo is made available to the applicable Clinic and its authorized Clinical Users in accordance with their access permissions and the instructions of the Clinic.
Legal Requirements
We may disclose information where we believe disclosure is required or permitted by applicable law, including to:
- comply with legal process;
- respond to lawful governmental requests;
- protect the rights, safety, or property of Wenixo, our customers, or others;
- investigate fraud, abuse, or security incidents; or
- enforce our legal agreements.
Business Transactions
If Wenixo is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction, information may be transferred as part of that transaction, subject to applicable confidentiality obligations and legal requirements.
Where appropriate, affected customers will be notified in accordance with applicable law.
We Never Share Information For Advertising
Wenixo does not:
- sell personal information;
- sell Protected Health Information;
- disclose customer clinical data to advertising networks;
- permit third parties to use customer clinical data for behavioral advertising; or
- allow third parties to independently commercialize customer information.
Data Retention#
Wenixo retains information only for as long as necessary to provide our Services, fulfill our contractual obligations, comply with applicable law, resolve disputes, and protect the security and integrity of our systems.
The length of time information is retained depends on the type of information involved, applicable legal requirements, and the instructions of the applicable Clinic.
| Data Category | Default Retention Practice |
|---|---|
| Clinical Documentation | Retained in accordance with the applicable Clinic's retention policies, contractual obligations, and applicable law. Where no alternative retention period is specified, Wenixo's default retention period is six (6) years. |
| Audio Recordings | Audio recordings submitted for documentation are encrypted at rest and securely deleted upon finalization of the associated clinical note, upon deletion of the encounter, or when a soft-deleted encounter is purged. Audio is not retained beyond these events except as instructed by the applicable Clinic or required by law. |
| Clinical Images | Retained according to the applicable Clinic's retention settings and applicable legal requirements. |
| Live Translation Data | Voice audio is not retained. Encrypted session transcripts and generated clinical notes are retained in accordance with the applicable Clinic's retention policies and applicable law. |
| Audit Logs | Retained for security, compliance, and operational purposes for the period reasonably necessary to satisfy legal, contractual, and regulatory requirements. |
| Account Information | Retained for the duration of the customer relationship and for a reasonable period thereafter to satisfy legal, contractual, tax, and audit obligations. |
| Website Information | Retained only as long as reasonably necessary for website administration, analytics, security, and legal compliance. |
When information is no longer required, Wenixo securely deletes or de-identifies the information using methods appropriate to the nature of the data and applicable legal requirements.
Security#
Protecting healthcare information is a fundamental responsibility of Wenixo.
We maintain a comprehensive information security program designed to protect the confidentiality, integrity, and availability of the information entrusted to us.
Our security program includes administrative, technical, and physical safeguards that are designed to meet applicable legal and regulatory requirements, including the HIPAA Security Rule where applicable.
Our security measures include, among others:
- encryption of data in transit using industry-standard protocols;
- encryption of data at rest using industry-standard cryptographic controls;
- role-based access controls that limit access to authorized users;
- authentication and identity management controls;
- comprehensive audit logging of significant system activities;
- continuous monitoring of system health and security events;
- secure cloud infrastructure hosted by trusted service providers;
- vulnerability management and regular security updates;
- incident response and breach management procedures; and
- workforce security and confidentiality training.
Although no method of transmitting or storing information can be guaranteed to be completely secure, Wenixo continually evaluates and enhances its security practices to address evolving threats and industry best practices.
Security Incidents
If Wenixo becomes aware of a confirmed security incident involving customer information, we will investigate the incident promptly, take reasonable measures to contain and remediate the issue, and notify the affected customers as required by applicable law and our contractual obligations.
Where Wenixo acts as a HIPAA Business Associate, notifications relating to Protected Health Information (PHI) will be provided in accordance with the applicable Business Associate Agreement and HIPAA.
Your Privacy Rights#
Privacy rights vary depending on the individual’s relationship with Wenixo and applicable law.
Clinical Users
Subject to applicable law, Clinical Users may request to:
- access their account information;
- correct inaccurate account information;
- update account preferences;
- deactivate their account (subject to the applicable Clinic's policies);
- obtain information regarding our privacy practices; and
- submit privacy-related questions or concerns.
Certain requests may require approval by the applicable Clinic, which controls the use of Wenixo within its organization.
Patients
Patients generally interact with Wenixo through their healthcare provider rather than directly with Wenixo.
Where Wenixo acts as a HIPAA Business Associate, the applicable Clinic remains responsible for responding to requests relating to Protected Health Information, including requests to:
- access medical records;
- amend Protected Health Information;
- receive an accounting of disclosures;
- request restrictions where permitted by law; and
- exercise other rights provided under HIPAA.
Patients wishing to exercise these rights should contact their healthcare provider directly.
Wenixo assists Clinics in responding to these requests where required under our contractual obligations and applicable law.
Marketing Communications
Individuals may opt out of non-essential marketing communications at any time by following the unsubscribe instructions included in the communication or by contacting Wenixo.
Operational, security, legal, and service-related communications cannot generally be opted out of while an active customer relationship exists.
Children#
Wenixo is intended for use by licensed healthcare organizations and their authorized workforce members.
We do not knowingly provide user accounts to individuals under the age of 18.
Where healthcare providers use Wenixo in connection with the care of pediatric patients, Wenixo processes patient information solely on behalf of the applicable Clinic and in accordance with applicable law and the governing Business Associate Agreement.
The applicable Clinic remains responsible for obtaining any required parental or guardian authorizations where required by law.
State Privacy Rights#
Certain U.S. states provide residents with additional privacy rights. Where applicable, Wenixo will comply with state privacy laws governing the information we process.
California residents may have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Protected Health Information processed by Wenixo as a HIPAA Business Associate is generally exempt from the CCPA to the extent provided by applicable law. Wenixo does not sell or share personal information for cross-context behavioral advertising.
Wenixo designs its clinical imaging workflows to avoid the routine collection of facial images and biometric identifiers. Our practices are intended to comply with the Illinois Biometric Information Privacy Act (BIPA) and other applicable biometric privacy laws.
As additional U.S. privacy laws become effective, Wenixo will update this Privacy Notice as necessary to reflect applicable legal requirements.
International Users#
Wenixo's Services are intended primarily for healthcare organizations located in the United States, and information processed through our Services is generally stored and processed within the United States. Where Wenixo agrees to provide Services to an organization outside the United States, or to store or process information outside the United States, the applicable data location, cross-border transfer mechanisms, and additional contractual safeguards will be addressed in the agreement between Wenixo and that organization.
Organizations subject to international privacy or data protection laws should contact Wenixo before implementing our Services to discuss applicable contractual safeguards and compliance requirements.
Changes to This Privacy Notice#
We may update this Privacy Notice from time to time to reflect changes in our Services, legal requirements, security practices, or business operations. When material changes are made, we will:
- update the "Last Updated" date at the beginning of this Privacy Notice;
- publish the revised Privacy Notice on our website; and
- where appropriate, provide additional notice to our customers.
Continued use of our Services following the effective date of an updated Privacy Notice constitutes acceptance of the revised Privacy Notice, to the extent permitted by applicable law.
Contact Us#
If you have questions about this Privacy Notice or Wenixo’s privacy practices, please contact us:
Privacy Inquiries: privacy@wenixo.com
Security Reporting: security@wenixo.com
Legal Requests: legal@wenixo.com
Support: contact@wenixo.com
Mailing Address: 119 S Western Avenue, Suite 1 #188, Chicago, IL 60612
Website: https://www.wenixo.com
If you believe your privacy rights have been violated or wish to report a potential security concern, please contact us promptly so that we may investigate and respond appropriately.
Previous Versions
Archived versions of this Privacy Notice are listed below. The version currently in force is shown first.