Skip to content

Privacy & Data Stewardship

Privacy Policy

CPET-Insight is committed to handling personal information responsibly, transparently, and with respect for the clinical context in which we operate

Responsible Handling

Personal information is handled with transparency and appropriate safeguards

Clinical Context

Health-related information is treated with care appropriate to healthcare workflows

Clear Boundaries

General website forms are not intended for routine PHI submission

Effective Date: April 12, 2026

Last Updated: August 19, 2026

Version: 2026-08-19

CPET-Insight, Inc. (“CPET-Insight,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the information you share with us. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website, interact with us, or use our services

By using our website or services, you acknowledge that information will be handled as described in this Privacy Policy. This Privacy Policy is a notice describing our practices; it is not a contract. Where processing requires your consent under applicable law, we will obtain that consent separately, and use of the website alone is not consent

Plain-language summary: We collect limited website and business information to respond to inquiries, operate our website, support service relationships, and meet legal obligations. General website forms are not intended for protected health information

HIPAA Notice: When CPET-Insight handles protected health information (PHI) in connection with covered clinical services, that information may be subject to the Health Insurance Portability and Accountability Act (HIPAA) and applicable business associate obligations. If applicable, PHI handling is governed by a Business Associate Agreement, service agreement, or equivalent documentation, available upon request at [email protected]. CPET-Insight acts as a business associate and does not issue a Notice of Privacy Practices; the health care provider that collected the information is responsible for its own Notice of Privacy Practices and for notifying patients about its privacy practices. This Privacy Policy covers general website and business information collection and does not replace any applicable HIPAA, BAA, service-agreement, or clinical privacy documentation

1. Information We Collect

We may collect the following categories of information:

A. Information You Provide Directly

When you contact us, request a demo, submit an inquiry, or otherwise interact with us, we may collect:

  • Name
  • Email address
  • Organization name
  • Professional role or title
  • Phone number, if provided
  • Any other information you include in your message or submission

B. Information Collected Automatically

When you visit our website, we may automatically collect certain technical and usage information, including:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Referring pages
  • Pages viewed and date/time of visit
  • General usage and interaction data

C. Cookies and Similar Technologies

Our website does not currently set analytics, advertising, or other non-essential cookies. Limited technical cookies may be set by our hosting or content-delivery providers where required for the site to load and function correctly

If we introduce non-essential cookies or similar tracking technologies in the future, we will update this Privacy Policy and, where required by applicable law (including the EU ePrivacy Directive), request your consent before setting them

D. California Notice at Collection

For California residents, the table below summarizes the categories of personal information we may collect through our website and general business interactions in the preceding 12 months, the sources of that information, the business or commercial purposes for which we use it, and the categories of third parties with whom we may share it:

Category (Examples)SourcesBusiness PurposeShared With
Identifiers: name, email address, IP address, device identifiersDirectly from you; automatically via the websiteRespond to inquiries, operate and secure the website, communicate about servicesCloud hosting and infrastructure providers, email delivery providers, CRM platforms, professional advisors, legal or regulatory bodies where required
Personal Records (Cal. Civ. Code §1798.80): phone number, mailing information if providedDirectly from youRespond to inquiries and follow-up communicationsSame categories as above
Commercial / Professional Information: organization name, professional role or title, business context of inquiryDirectly from youQualify demo requests, tailor communications, understand user needsCRM platforms, professional advisors under confidentiality
Internet or Network Activity: browser type, pages viewed, referring pages, date and time of visitAutomatically via the websiteWebsite performance, security, general usage understandingCloud hosting and infrastructure providers
Inferences (if drawn): basic segmentation such as clinician vs. individual inquiry typeDerived from the categories aboveRoute inquiries to the appropriate internal pathwayNot shared externally except as part of the categories above

We do not knowingly collect sensitive personal information through our general website forms. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. Retention periods for each category are described in Section 7

2. How We Use Information

We may use the information we collect to:

  • Respond to inquiries and communicate with you
  • Provide information about our platform, services, or partnerships
  • Schedule demonstrations or follow-up conversations
  • Operate, maintain, and improve our website and services
  • Monitor website performance, security, and analytics
  • Comply with legal obligations
  • Protect the rights, safety, and integrity of CPET-Insight, our users, and others

Lawful Basis for Processing (GDPR)

For individuals in the European Economic Area (EEA) or United Kingdom, we process your personal data on the following lawful bases:

Processing ActivityLawful Basis
Responding to inquiries and contact form submissionsLegitimate interests (responding to business enquiries)
Scheduling demos or follow-up communicationsLegitimate interests / pre-contractual steps
Operating and improving our websiteLegitimate interests (maintaining a functional, secure site)
Complying with legal obligationsLegal obligation
Analytics and usage tracking, if used (non-essential cookies)Consent
Marketing communications (where applicable)Consent

3. Clinical and Health-Related Information

CPET-Insight operates in a healthcare context. Where applicable, information submitted through our website or services may relate to clinical workflows or healthcare operations

General website forms are not intended for the submission of protected health information (PHI). Users should avoid submitting sensitive patient-identifiable information through general website forms or unsecured channels

If CPET-Insight processes healthcare information in the course of providing its software services, that processing is governed by a written agreement with the health care provider or other customer on whose behalf we process it. Where the customer is a HIPAA Covered Entity or Business Associate and we create, receive, maintain, or transmit protected health information on its behalf, that agreement is a Business Associate Agreement (BAA) and the processing is subject to HIPAA. Where HIPAA does not apply — which may be the case for customers located outside the United States — the processing is governed by a data processing agreement or other appropriate agreement, and by the privacy and security laws applicable to that customer

Important: If you need to share PHI with CPET-Insight in connection with a clinical services engagement, please do so only through the secure channels established in your service agreement. Do not send PHI via general contact forms or unencrypted email

4. Automated Processing, AI in Software Development, and Human Involvement

CPET-Insight provides software that performs automated physiologic analysis of cardiopulmonary exercise testing (CPET) data submitted by health care providers. Our platform operates as a software-as-a-service (SaaS) product, and the analytic outputs delivered for each individual test are produced by deterministic analytic software developed by CPET-Insight with input from independent clinical advisors. Large language models (LLMs) do not generate the physiologic analysis or the automated findings for any individual test. Before an analytic output (an “Output”) is released, it is also subject to CPET-Insight’s structured quality-control and clinical-review process, and CPET-Insight offers a report-scoped conversational decision-support feature to authorized provider users. Both are described below

How AI is used in our software and services

The interpretation logic within our software was authored and iteratively refined with the assistance of AI coding tools working with CPET-Insight’s independent clinical advisors. That logic is versioned software, and we continue to refine it based on real-world clinical experience and physician feedback. Where LLMs are used at CPET-Insight, they are used in supporting roles (such as internal tooling and content workflows), to assist with drafting and quality review of report narrative content within the pre-release process described below, and to power the report-scoped conversational decision-support feature described below. LLMs do not generate the analytic output of an individual test. LLM-assisted narrative content is reviewed by qualified CPET-Insight personnel before an Output is released

Report-scoped conversational decision support

CPET-Insight makes available a conversational decision-support feature that allows authorized users at the ordering or treating organization to ask questions about a specific released report. The feature is report-scoped: it processes only the data associated with that report, including the submitted test data, automated findings, and report narrative, together with the questions the user enters. It is intended for use by health care professionals and is not a channel for patients to obtain clinical advice.

Responses generated by this feature are informational decision support only. They do not modify, replace, or become part of the official Output, which remains the report released through the quality-control and clinical-review process described above, and they are not subject to that pre-release review. The ordering or treating provider remains responsible for independent review and for all patient-specific clinical decisions.

Where this feature processes protected health information, that processing is governed by this Privacy Policy and by the applicable Business Associate Agreement or other written agreement with the customer, on the same terms as the rest of the Services. Consistent with our Terms of Service, we do not use customer data, protected health information, or conversational inputs or outputs to train or fine-tune large language models, and we do not permit our LLM providers to do so. Conversational inputs and outputs are retained as described in Section 7 and in the applicable agreement.

Human involvement in clinical decisions

Analytic outputs and any risk-related signals are presented as decision support for review by the clinician responsible for your care. Before release, each Output is subject to CPET-Insight’s structured quality-control and clinical-review process. Qualified CPET-Insight personnel may review submitted data, automated findings, quality indicators, and report narratives; correct or supplement narrative content; hold an Output for further review; and authorize release. This process supports—but does not replace—the ordering or treating provider’s independent review and clinical judgment, does not establish a physician-patient relationship, and does not transfer responsibility for diagnosis, treatment, or patient-care decisions to CPET-Insight. CPET-Insight’s review is directed at the quality, consistency, and completeness of the Output itself; it is not an evaluation of your individual clinical circumstances, is not medical advice, and is not a substitute for assessment by the clinician responsible for your care. The clinician who ordered the test remains responsible for reviewing, accepting, modifying, or rejecting the Output before it informs patient care, and for all patient-specific clinical decisions

Your right to human review and to speak with a clinician

You may:

  • Request that a qualified human review your CPET results. Each Output already receives human quality-control and clinical review at CPET-Insight before release, but that review addresses the quality and accuracy of the Output rather than your individual clinical circumstances. We therefore will direct any request for clinical review of your results to the clinician or organization responsible for your care
  • Request the opportunity to discuss your results with the clinician responsible for your care. CPET-Insight does not provide clinical consultations to patients and cannot discuss your results with you directly
  • Request general information about how our analytic software processes CPET data
  • Express your point of view and contest an output that has been used in a decision affecting you

To exercise these rights, contact us at [email protected]. Depending on the context, we may direct your request to the treating clinician or the clinical organization responsible for your care

Rights under GDPR Article 22 and comparable laws

If you are located in the EEA or the United Kingdom, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you. Each Output is subject to human quality-control and clinical review within CPET-Insight before it is released. Review by the clinician responsible for your care is also a routine part of the workflow in which our software is used, and the outputs of our software are not used to make decisions about you without that review. Additional human review is available through the channels described above

EU AI Act

CPET-Insight is committed to transparency for AI-related components used in healthcare decision support. Where and to the extent the EU AI Act (Regulation (EU) 2024/1689) applies to our product or our processing, we will meet the applicable obligations for transparency, technical documentation, human oversight, and post-market monitoring for the relevant risk category. Whether and how the EU AI Act applies is assessed for each jurisdiction in which we make the Services available, and we may require additional documentation from a customer before making the Services available in a particular jurisdiction

Marketing website

This general marketing website does not perform automated decision-making about visitors. The disclosures in this section apply to CPET-Insight clinical services and are subject to the applicable Business Associate Agreement, service agreement, or equivalent clinical documentation

5. How We Share Information

We do not sell personal information. We do not share personal information for cross-context behavioral advertising purposes

We may share information in the following limited circumstances:

  • With service providers and vendors who help us operate our website, communications, and business functions - these parties are contractually bound to handle information only as directed by us. Categories of service providers we may engage include cloud hosting and infrastructure providers, email delivery providers, customer relationship management (CRM) platforms, calendaring and demo scheduling tools, and (if introduced in the future) analytics providers
  • With professional advisors, such as legal, compliance, or accounting advisors, under confidentiality obligations
  • When required by law, regulation, subpoena, court order, or other legal process
  • To protect the rights, safety, and security of CPET-Insight, our users, or others
  • In connection with a merger, acquisition, financing, restructuring, or sale of all or part of our business, subject to appropriate confidentiality protections

Any third parties we engage are contractually required to handle information in a manner consistent with applicable confidentiality and security obligations, including executing Data Processing Agreements where required under GDPR

A current list of the specific sub-processors we engage is available upon written request at [email protected]

De-identified and aggregate data

Where we process health information under a Business Associate Agreement, that agreement may permit us to de-identify the information in accordance with HIPAA and to retain and use the resulting de-identified data in aggregated datasets for quality improvement, benchmarking, research, service development, and the development, testing, validation, and improvement of our analytic methods and models. De-identified data is not protected health information under HIPAA and does not identify you. We do not attempt to re-identify individuals, and we do not disclose de-identified data in a form that identifies any patient, clinician, customer, or facility without written consent.

6. Security

We implement reasonable administrative, technical, and organizational measures to protect personal information against unauthorized access, disclosure, alteration, or destruction. Our security practices include:

  • Encryption of data in transit using TLS/HTTPS, and encryption of data at rest
  • Access controls limiting data access to authorized personnel
  • Regular review of our security practices and vendor relationships
  • Hosting with infrastructure providers with which we have executed business associate agreements, with administrative and technical safeguards aligned with the HIPAA Security Rule for systems that handle PHI

However, no method of transmission over the Internet or electronic storage is completely secure. While we strive to protect your information appropriately, we cannot guarantee absolute security. In the event of a data breach that affects your rights or interests, we will notify affected individuals and applicable regulators as and where required by law. Where the affected information is protected health information that we hold on behalf of a health care provider, we will notify that provider, which is responsible under HIPAA for notifying affected individuals, the Secretary of Health and Human Services, and, where applicable, the media. For personal data of EEA or UK residents, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, in accordance with GDPR Article 33

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy or as required by law. Our general retention guidelines are:

Data CategoryRetention Period
General website inquiries and contact form submissionsFor as long as necessary to respond to the inquiry and to maintain a record of it, and thereafter as set out in our documented retention schedule or as required by applicable law
Demo requests and sales correspondenceFor the duration of the business relationship, and thereafter as set out in our documented retention schedule or as required by applicable law
Website analytics and usage data, if collectedRetained according to the applicable analytics provider settings
Clinical / health-related informationAs specified in the applicable BAA, data processing agreement, or service agreement, and as required by HIPAA documentation requirements or other applicable law
Legal and compliance recordsAs required by applicable law (generally 7 years)
Cookie preference or consent records, if applicableAs required by applicable law and as set out in our documented retention schedule

We maintain an internal retention schedule that sets the specific periods applied to each category, and we review it periodically. After the applicable retention period, we will securely delete or anonymize your personal information unless retention is required by law

8. Your Choices and Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information. These are described below

Rights Available to All Users

  • Request access to the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of certain information we hold about you, subject to legal obligations
  • Object to or request restriction of certain processing activities
  • Withdraw consent at any time where processing is based on consent (this does not affect the lawfulness of prior processing)

Additional Rights - EEA and UK Residents (GDPR / UK GDPR)

If you are located in the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR, including:

  • Right to data portability - receive your data in a structured, machine-readable format
  • Right to object to processing based on legitimate interests
  • Right to lodge a complaint with your local supervisory authority. In the EU, the relevant authority depends on your country of residence. In the UK, the relevant authority is the Information Commissioner’s Office (ICO) at ico.org.uk

We will respond to verified requests within one month of receipt. Where a request is complex or where we receive a number of requests, we may extend that period by up to two further months, and will inform you of the extension and the reasons for it within one month of receiving the request, in accordance with GDPR Article 12(3)

Additional Rights - California Residents (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect, use, and share
  • Right to delete personal information we hold about you
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising
  • Right to limit use of sensitive personal information (where applicable)
  • Right to non-discrimination for exercising your rights

We will acknowledge your request within 10 business days and respond substantively within 45 calendar days (extendable by 45 days with notice)

Additional Rights - Residents of Other US States

Residents of certain other US states (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, and other states with similar laws that come into effect) may have rights substantially similar to those described above, including the right to access, correct, delete, and obtain a portable copy of their personal information, and the right to opt out of certain processing activities such as targeted advertising, the sale of personal information, and certain forms of profiling

We do not sell personal information, do not use personal information for targeted advertising, and do not engage in profiling that produces legal or similarly significant effects about you. To exercise applicable rights under your state law, please contact us at [email protected]. Response timeframes will follow the specific requirements of your state

How to Submit a Request

To exercise any of the rights described above, please contact us at [email protected]. We may need to verify your identity before processing your request, and we may decline a request where we are unable to verify it. An authorized agent may submit a request on your behalf on providing proof of authorization and, where required, verification of your identity

9. International Data Transfers

CPET-Insight is based in the United States, and we host and process information in the United States. CPET-Insight makes its services available to customers and users located outside the United States. If you access our website or use our services from outside the United States, information about you will be transferred to, stored in, and processed in the United States, which may not provide the same level of data protection as the laws of the country in which you are located

Where personal data is transferred from the European Economic Area, the United Kingdom, or another jurisdiction that restricts international transfers, and an approved transfer mechanism is required for that transfer, we will implement an appropriate mechanism before the transfer takes place. Depending on the jurisdiction and the circumstances, that may include:

  • A data processing agreement or international data transfer agreement with the relevant customer or vendor
  • The Standard Contractual Clauses approved by the European Commission
  • The UK International Data Transfer Addendum for transfers of UK personal data
  • Other transfer mechanisms recognized under applicable law

We have not adopted a single transfer mechanism that applies to every customer or every jurisdiction, and no particular mechanism should be assumed to be in place. The mechanism applicable to a given customer relationship is established in that customer’s contract documentation, and we may require a customer to execute a processing addendum or transfer agreement before we make the services available in a particular jurisdiction. We do not rely on your consent as the lawful basis for these transfers. If you have questions about the specific transfer mechanism applicable to your data, please contact us at [email protected]

10. Third-Party Links

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or security of those third parties. We encourage you to review their privacy policies before sharing any information with them

11. Children’s Privacy

Our website and services are not directed to children. We do not knowingly collect personal information from children under the age of 13 (or under 16 where required by applicable law, including certain EU member states under GDPR). If we become aware that we have inadvertently collected such information, we will take appropriate steps to delete it promptly. Health information relating to a minor that we process on behalf of a health care provider is submitted by that provider, not collected from the minor, and is governed by the applicable Business Associate Agreement and HIPAA rather than by this Section

If you believe we may have collected information from a child, please contact us at [email protected]

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we do, we will revise the “Last Updated” date at the top of this page. For material changes, we will provide additional notice where required by applicable law. We will not apply a material change retroactively to information already collected, and where a change requires your consent under applicable law, we will obtain that consent before the change applies to you

13. Contact Us

If you have questions about this Privacy Policy or wish to make a privacy-related request, please contact us:

CPET-Insight, Inc.

8 The Green, Suite A, Dover, DE 19901, USA

Privacy requests: [email protected]

General contact: [email protected]