Effective Date: April 12, 2026
Last Updated: August 19, 2026
Version: 2026-08-19
CPET-Insight, Inc. (“CPET-Insight,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the information you share with us. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website, interact with us, or use our services
By using our website or services, you acknowledge that information will be handled as described in this Privacy Policy. This Privacy Policy is a notice describing our practices; it is not a contract. Where processing requires your consent under applicable law, we will obtain that consent separately, and use of the website alone is not consent
Plain-language summary: We collect limited website and business information to respond to inquiries, operate our website, support service relationships, and meet legal obligations. General website forms are not intended for protected health information
HIPAA Notice: When CPET-Insight handles protected health information (PHI) in connection with covered clinical services, that information may be subject to the Health Insurance Portability and Accountability Act (HIPAA) and applicable business associate obligations. If applicable, PHI handling is governed by a Business Associate Agreement, service agreement, or equivalent documentation, available upon request at [email protected]. CPET-Insight acts as a business associate and does not issue a Notice of Privacy Practices; the health care provider that collected the information is responsible for its own Notice of Privacy Practices and for notifying patients about its privacy practices. This Privacy Policy covers general website and business information collection and does not replace any applicable HIPAA, BAA, service-agreement, or clinical privacy documentation
1. Information We Collect
We may collect the following categories of information:
A. Information You Provide Directly
When you contact us, request a demo, submit an inquiry, or otherwise interact with us, we may collect:
- Name
- Email address
- Organization name
- Professional role or title
- Phone number, if provided
- Any other information you include in your message or submission
B. Information Collected Automatically
When you visit our website, we may automatically collect certain technical and usage information, including:
- IP address
- Browser type and version
- Device type and operating system
- Referring pages
- Pages viewed and date/time of visit
- General usage and interaction data
C. Cookies and Similar Technologies
Our website does not currently set analytics, advertising, or other non-essential cookies. Limited technical cookies may be set by our hosting or content-delivery providers where required for the site to load and function correctly
If we introduce non-essential cookies or similar tracking technologies in the future, we will update this Privacy Policy and, where required by applicable law (including the EU ePrivacy Directive), request your consent before setting them
D. California Notice at Collection
For California residents, the table below summarizes the categories of personal information we may collect through our website and general business interactions in the preceding 12 months, the sources of that information, the business or commercial purposes for which we use it, and the categories of third parties with whom we may share it:
| Category (Examples) | Sources | Business Purpose | Shared With |
|---|---|---|---|
| Identifiers: name, email address, IP address, device identifiers | Directly from you; automatically via the website | Respond to inquiries, operate and secure the website, communicate about services | Cloud hosting and infrastructure providers, email delivery providers, CRM platforms, professional advisors, legal or regulatory bodies where required |
| Personal Records (Cal. Civ. Code §1798.80): phone number, mailing information if provided | Directly from you | Respond to inquiries and follow-up communications | Same categories as above |
| Commercial / Professional Information: organization name, professional role or title, business context of inquiry | Directly from you | Qualify demo requests, tailor communications, understand user needs | CRM platforms, professional advisors under confidentiality |
| Internet or Network Activity: browser type, pages viewed, referring pages, date and time of visit | Automatically via the website | Website performance, security, general usage understanding | Cloud hosting and infrastructure providers |
| Inferences (if drawn): basic segmentation such as clinician vs. individual inquiry type | Derived from the categories above | Route inquiries to the appropriate internal pathway | Not shared externally except as part of the categories above |
We do not knowingly collect sensitive personal information through our general website forms. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. Retention periods for each category are described in Section 7
2. How We Use Information
We may use the information we collect to:
- Respond to inquiries and communicate with you
- Provide information about our platform, services, or partnerships
- Schedule demonstrations or follow-up conversations
- Operate, maintain, and improve our website and services
- Monitor website performance, security, and analytics
- Comply with legal obligations
- Protect the rights, safety, and integrity of CPET-Insight, our users, and others
Lawful Basis for Processing (GDPR)
For individuals in the European Economic Area (EEA) or United Kingdom, we process your personal data on the following lawful bases:
| Processing Activity | Lawful Basis |
|---|---|
| Responding to inquiries and contact form submissions | Legitimate interests (responding to business enquiries) |
| Scheduling demos or follow-up communications | Legitimate interests / pre-contractual steps |
| Operating and improving our website | Legitimate interests (maintaining a functional, secure site) |
| Complying with legal obligations | Legal obligation |
| Analytics and usage tracking, if used (non-essential cookies) | Consent |
| Marketing communications (where applicable) | Consent |
3. Clinical and Health-Related Information
CPET-Insight operates in a healthcare context. Where applicable, information submitted through our website or services may relate to clinical workflows or healthcare operations
General website forms are not intended for the submission of protected health information (PHI). Users should avoid submitting sensitive patient-identifiable information through general website forms or unsecured channels
If CPET-Insight processes healthcare information in the course of providing its software services, that processing is governed by a written agreement with the health care provider or other customer on whose behalf we process it. Where the customer is a HIPAA Covered Entity or Business Associate and we create, receive, maintain, or transmit protected health information on its behalf, that agreement is a Business Associate Agreement (BAA) and the processing is subject to HIPAA. Where HIPAA does not apply — which may be the case for customers located outside the United States — the processing is governed by a data processing agreement or other appropriate agreement, and by the privacy and security laws applicable to that customer
Important: If you need to share PHI with CPET-Insight in connection with a clinical services engagement, please do so only through the secure channels established in your service agreement. Do not send PHI via general contact forms or unencrypted email
4. Automated Processing, AI in Software Development, and Human Involvement
CPET-Insight provides software that performs automated physiologic analysis of cardiopulmonary exercise testing (CPET) data submitted by health care providers. Our platform operates as a software-as-a-service (SaaS) product, and the analytic outputs delivered for each individual test are produced by deterministic analytic software developed by CPET-Insight with input from independent clinical advisors. Large language models (LLMs) do not generate the physiologic analysis or the automated findings for any individual test. Before an analytic output (an “Output”) is released, it is also subject to CPET-Insight’s structured quality-control and clinical-review process, and CPET-Insight offers a report-scoped conversational decision-support feature to authorized provider users. Both are described below
How AI is used in our software and services
The interpretation logic within our software was authored and iteratively refined with the assistance of AI coding tools working with CPET-Insight’s independent clinical advisors. That logic is versioned software, and we continue to refine it based on real-world clinical experience and physician feedback. Where LLMs are used at CPET-Insight, they are used in supporting roles (such as internal tooling and content workflows), to assist with drafting and quality review of report narrative content within the pre-release process described below, and to power the report-scoped conversational decision-support feature described below. LLMs do not generate the analytic output of an individual test. LLM-assisted narrative content is reviewed by qualified CPET-Insight personnel before an Output is released
Report-scoped conversational decision support
CPET-Insight makes available a conversational decision-support feature that allows authorized users at the ordering or treating organization to ask questions about a specific released report. The feature is report-scoped: it processes only the data associated with that report, including the submitted test data, automated findings, and report narrative, together with the questions the user enters. It is intended for use by health care professionals and is not a channel for patients to obtain clinical advice.
Responses generated by this feature are informational decision support only. They do not modify, replace, or become part of the official Output, which remains the report released through the quality-control and clinical-review process described above, and they are not subject to that pre-release review. The ordering or treating provider remains responsible for independent review and for all patient-specific clinical decisions.
Where this feature processes protected health information, that processing is governed by this Privacy Policy and by the applicable Business Associate Agreement or other written agreement with the customer, on the same terms as the rest of the Services. Consistent with our Terms of Service, we do not use customer data, protected health information, or conversational inputs or outputs to train or fine-tune large language models, and we do not permit our LLM providers to do so. Conversational inputs and outputs are retained as described in Section 7 and in the applicable agreement.
Human involvement in clinical decisions
Analytic outputs and any risk-related signals are presented as decision support for review by the clinician responsible for your care. Before release, each Output is subject to CPET-Insight’s structured quality-control and clinical-review process. Qualified CPET-Insight personnel may review submitted data, automated findings, quality indicators, and report narratives; correct or supplement narrative content; hold an Output for further review; and authorize release. This process supports—but does not replace—the ordering or treating provider’s independent review and clinical judgment, does not establish a physician-patient relationship, and does not transfer responsibility for diagnosis, treatment, or patient-care decisions to CPET-Insight. CPET-Insight’s review is directed at the quality, consistency, and completeness of the Output itself; it is not an evaluation of your individual clinical circumstances, is not medical advice, and is not a substitute for assessment by the clinician responsible for your care. The clinician who ordered the test remains responsible for reviewing, accepting, modifying, or rejecting the Output before it informs patient care, and for all patient-specific clinical decisions
Your right to human review and to speak with a clinician
You may:
- Request that a qualified human review your CPET results. Each Output already receives human quality-control and clinical review at CPET-Insight before release, but that review addresses the quality and accuracy of the Output rather than your individual clinical circumstances. We therefore will direct any request for clinical review of your results to the clinician or organization responsible for your care
- Request the opportunity to discuss your results with the clinician responsible for your care. CPET-Insight does not provide clinical consultations to patients and cannot discuss your results with you directly
- Request general information about how our analytic software processes CPET data
- Express your point of view and contest an output that has been used in a decision affecting you
To exercise these rights, contact us at [email protected]. Depending on the context, we may direct your request to the treating clinician or the clinical organization responsible for your care
Rights under GDPR Article 22 and comparable laws
If you are located in the EEA or the United Kingdom, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you. Each Output is subject to human quality-control and clinical review within CPET-Insight before it is released. Review by the clinician responsible for your care is also a routine part of the workflow in which our software is used, and the outputs of our software are not used to make decisions about you without that review. Additional human review is available through the channels described above
EU AI Act
CPET-Insight is committed to transparency for AI-related components used in healthcare decision support. Where and to the extent the EU AI Act (Regulation (EU) 2024/1689) applies to our product or our processing, we will meet the applicable obligations for transparency, technical documentation, human oversight, and post-market monitoring for the relevant risk category. Whether and how the EU AI Act applies is assessed for each jurisdiction in which we make the Services available, and we may require additional documentation from a customer before making the Services available in a particular jurisdiction
Marketing website
This general marketing website does not perform automated decision-making about visitors. The disclosures in this section apply to CPET-Insight clinical services and are subject to the applicable Business Associate Agreement, service agreement, or equivalent clinical documentation
5. How We Share Information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising purposes
We may share information in the following limited circumstances:
- With service providers and vendors who help us operate our website, communications, and business functions - these parties are contractually bound to handle information only as directed by us. Categories of service providers we may engage include cloud hosting and infrastructure providers, email delivery providers, customer relationship management (CRM) platforms, calendaring and demo scheduling tools, and (if introduced in the future) analytics providers
- With professional advisors, such as legal, compliance, or accounting advisors, under confidentiality obligations
- When required by law, regulation, subpoena, court order, or other legal process
- To protect the rights, safety, and security of CPET-Insight, our users, or others
- In connection with a merger, acquisition, financing, restructuring, or sale of all or part of our business, subject to appropriate confidentiality protections
Any third parties we engage are contractually required to handle information in a manner consistent with applicable confidentiality and security obligations, including executing Data Processing Agreements where required under GDPR
A current list of the specific sub-processors we engage is available upon written request at [email protected]
De-identified and aggregate data
Where we process health information under a Business Associate Agreement, that agreement may permit us to de-identify the information in accordance with HIPAA and to retain and use the resulting de-identified data in aggregated datasets for quality improvement, benchmarking, research, service development, and the development, testing, validation, and improvement of our analytic methods and models. De-identified data is not protected health information under HIPAA and does not identify you. We do not attempt to re-identify individuals, and we do not disclose de-identified data in a form that identifies any patient, clinician, customer, or facility without written consent.
6. Security
We implement reasonable administrative, technical, and organizational measures to protect personal information against unauthorized access, disclosure, alteration, or destruction. Our security practices include:
- Encryption of data in transit using TLS/HTTPS, and encryption of data at rest
- Access controls limiting data access to authorized personnel
- Regular review of our security practices and vendor relationships
- Hosting with infrastructure providers with which we have executed business associate agreements, with administrative and technical safeguards aligned with the HIPAA Security Rule for systems that handle PHI
However, no method of transmission over the Internet or electronic storage is completely secure. While we strive to protect your information appropriately, we cannot guarantee absolute security. In the event of a data breach that affects your rights or interests, we will notify affected individuals and applicable regulators as and where required by law. Where the affected information is protected health information that we hold on behalf of a health care provider, we will notify that provider, which is responsible under HIPAA for notifying affected individuals, the Secretary of Health and Human Services, and, where applicable, the media. For personal data of EEA or UK residents, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, in accordance with GDPR Article 33
7. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy or as required by law. Our general retention guidelines are:
| Data Category | Retention Period |
|---|---|
| General website inquiries and contact form submissions | For as long as necessary to respond to the inquiry and to maintain a record of it, and thereafter as set out in our documented retention schedule or as required by applicable law |
| Demo requests and sales correspondence | For the duration of the business relationship, and thereafter as set out in our documented retention schedule or as required by applicable law |
| Website analytics and usage data, if collected | Retained according to the applicable analytics provider settings |
| Clinical / health-related information | As specified in the applicable BAA, data processing agreement, or service agreement, and as required by HIPAA documentation requirements or other applicable law |
| Legal and compliance records | As required by applicable law (generally 7 years) |
| Cookie preference or consent records, if applicable | As required by applicable law and as set out in our documented retention schedule |
We maintain an internal retention schedule that sets the specific periods applied to each category, and we review it periodically. After the applicable retention period, we will securely delete or anonymize your personal information unless retention is required by law
8. Your Choices and Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information. These are described below
Rights Available to All Users
- Request access to the personal information we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion of certain information we hold about you, subject to legal obligations
- Object to or request restriction of certain processing activities
- Withdraw consent at any time where processing is based on consent (this does not affect the lawfulness of prior processing)
Additional Rights - EEA and UK Residents (GDPR / UK GDPR)
If you are located in the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR, including:
- Right to data portability - receive your data in a structured, machine-readable format
- Right to object to processing based on legitimate interests
- Right to lodge a complaint with your local supervisory authority. In the EU, the relevant authority depends on your country of residence. In the UK, the relevant authority is the Information Commissioner’s Office (ICO) at ico.org.uk
We will respond to verified requests within one month of receipt. Where a request is complex or where we receive a number of requests, we may extend that period by up to two further months, and will inform you of the extension and the reasons for it within one month of receiving the request, in accordance with GDPR Article 12(3)
Additional Rights - California Residents (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, use, and share
- Right to delete personal information we hold about you
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising
- Right to limit use of sensitive personal information (where applicable)
- Right to non-discrimination for exercising your rights
We will acknowledge your request within 10 business days and respond substantively within 45 calendar days (extendable by 45 days with notice)
Additional Rights - Residents of Other US States
Residents of certain other US states (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, and other states with similar laws that come into effect) may have rights substantially similar to those described above, including the right to access, correct, delete, and obtain a portable copy of their personal information, and the right to opt out of certain processing activities such as targeted advertising, the sale of personal information, and certain forms of profiling
We do not sell personal information, do not use personal information for targeted advertising, and do not engage in profiling that produces legal or similarly significant effects about you. To exercise applicable rights under your state law, please contact us at [email protected]. Response timeframes will follow the specific requirements of your state
How to Submit a Request
To exercise any of the rights described above, please contact us at [email protected]. We may need to verify your identity before processing your request, and we may decline a request where we are unable to verify it. An authorized agent may submit a request on your behalf on providing proof of authorization and, where required, verification of your identity
9. International Data Transfers
CPET-Insight is based in the United States, and we host and process information in the United States. CPET-Insight makes its services available to customers and users located outside the United States. If you access our website or use our services from outside the United States, information about you will be transferred to, stored in, and processed in the United States, which may not provide the same level of data protection as the laws of the country in which you are located
Where personal data is transferred from the European Economic Area, the United Kingdom, or another jurisdiction that restricts international transfers, and an approved transfer mechanism is required for that transfer, we will implement an appropriate mechanism before the transfer takes place. Depending on the jurisdiction and the circumstances, that may include:
- A data processing agreement or international data transfer agreement with the relevant customer or vendor
- The Standard Contractual Clauses approved by the European Commission
- The UK International Data Transfer Addendum for transfers of UK personal data
- Other transfer mechanisms recognized under applicable law
We have not adopted a single transfer mechanism that applies to every customer or every jurisdiction, and no particular mechanism should be assumed to be in place. The mechanism applicable to a given customer relationship is established in that customer’s contract documentation, and we may require a customer to execute a processing addendum or transfer agreement before we make the services available in a particular jurisdiction. We do not rely on your consent as the lawful basis for these transfers. If you have questions about the specific transfer mechanism applicable to your data, please contact us at [email protected]
10. Third-Party Links
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or security of those third parties. We encourage you to review their privacy policies before sharing any information with them
11. Children’s Privacy
Our website and services are not directed to children. We do not knowingly collect personal information from children under the age of 13 (or under 16 where required by applicable law, including certain EU member states under GDPR). If we become aware that we have inadvertently collected such information, we will take appropriate steps to delete it promptly. Health information relating to a minor that we process on behalf of a health care provider is submitted by that provider, not collected from the minor, and is governed by the applicable Business Associate Agreement and HIPAA rather than by this Section
If you believe we may have collected information from a child, please contact us at [email protected]
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we do, we will revise the “Last Updated” date at the top of this page. For material changes, we will provide additional notice where required by applicable law. We will not apply a material change retroactively to information already collected, and where a change requires your consent under applicable law, we will obtain that consent before the change applies to you
13. Contact Us
If you have questions about this Privacy Policy or wish to make a privacy-related request, please contact us:
CPET-Insight, Inc.
8 The Green, Suite A, Dover, DE 19901, USA
Privacy requests: [email protected]
General contact: [email protected]