Privacy Policy
MedOS by Cairn
Effective Date: June 2026 Last Updated: August 22, 2026
Cairn Advisory, LLC ("Provider," "we," "us," or "our") operates MedOS, a cloud-based membership administration and patient engagement platform for concierge and direct-care medical practices. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information in connection with the Services.
1. Information We Collect
We collect information in the following ways:
1.1 Information You Provide Directly
- Account Registration: Name, email address, phone number, organization name, and account credentials
- Practice Profile: Practice name, locations, contact details, branding assets, and sending identity
- Member Records: Information your practice enters about its members — names, contact details, postal addresses, membership tier, contract terms, and renewal dates
- Content You Create: Campaign emails, surveys and the responses to them, intake form submissions, and patient-facing library content
- Support Requests: Communications with our support team, including subject matter and attachments
1.2 Information Collected Automatically
- Device Information: Device type, operating system, browser type, and unique device identifiers
- Access Logs: IP address, access times, pages visited, and duration of sessions
- Cookies: We use first-party cookies only, and only for functional purposes — keeping you signed in and remembering interface preferences. We do not use advertising cookies, third-party tracking pixels, or cross-site tracking
- Email Engagement: For emails sent through the platform, our delivery provider records delivery, open, click, and bounce events
1.3 Information From Third Parties
- Optional Integrations: If you connect a CRM (HubSpot) or content platform (Prismic), we exchange the records you authorize with that service. These integrations are off unless you enable them
- Referral Sources: If another provider refers your organization, we may receive that information
2. How We Use Your Information
2.1 Service Delivery
- Providing access to MedOS and operating your membership and communication workflows
- Customizing your experience and personalizing features
- Sending transactional emails (account confirmations, password resets, billing notifications)
- Troubleshooting and technical support
2.2 Improvement and Analytics
- Analyzing usage patterns to improve platform features and user experience
- Conducting research and development of new features
- Generating aggregated, de-identified analytics reports
- Measuring performance and reliability
We do not train machine learning models on your data. Where you enable an AI feature, the relevant content is sent to the third-party provider you configure, using credentials you supply, and is processed under that provider's terms.
2.3 Communications
- Sending administrative notices and updates about the Services
- Notifying you of changes to this Privacy Policy or the Services
- Responding to your inquiries and feedback
- Marketing communications (with your opt-in consent)
2.4 Legal Compliance
- Complying with applicable laws, regulations, and legal processes
- Protecting against fraud, security threats, and abuse
- Enforcing this Privacy Policy and our Terms of Service
- Protecting the rights, property, and safety of Provider, you, and others
3. Data Sharing and Disclosure
3.1 Service Providers
We share personal information with trusted service providers who assist us in operating the platform, including:
- Supabase — database, authentication, and file storage
- Vercel — application hosting and scheduled job execution
- Resend — outbound email delivery
- Anthropic or OpenAI — only where you enable an AI feature and supply credentials
- HubSpot or Prismic — only where you connect that integration
All service providers are contractually obligated to maintain the confidentiality and security of your information and to use it only to provide services on our behalf.
3.2 Business Transfers
If Provider is involved in a merger, acquisition, bankruptcy, or asset sale, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
3.3 Legal Requirements
We may disclose personal information if required by law, court order, subpoena, or government request, or if we believe disclosure is necessary to:
- Comply with legal obligations
- Enforce our Terms of Service and other agreements
- Protect the security or integrity of the Services
- Protect against fraud or security threats
- Protect the rights, property, and safety of Provider, you, or others
3.4 Aggregated and De-identified Data
We may share aggregated, de-identified data that cannot identify you with third parties for marketing, research, and analytics purposes.
4. Data Retention
- Account Information: Retained while your account is active and for 12 months after termination (unless longer retention is required by law)
- Access Logs: Retained by our hosting and database providers according to their standard retention periods
- Customer Data: Retained for 30 days after account termination to allow you to export data; then permanently deleted
- Usage Analytics: Aggregated and anonymized data may be retained indefinitely
- Support Correspondence: Retained in our email system for reference and dispute resolution
For healthcare data governed by HIPAA or state privacy laws, retention periods are determined by applicable regulations and our Business Associate Agreement, if applicable.
5. Your Rights and Choices
5.1 Access and Portability
You have the right to request access to your personal information and to receive a portable copy in a commonly used, machine-readable format.
5.2 Correction and Update
You may request correction or update of inaccurate or incomplete information.
5.3 Deletion
You may request deletion of your personal information, subject to legal retention requirements and our need to maintain certain information for operational and legal purposes.
5.4 Opt-Out
- Marketing Communications: You may opt out of promotional emails by clicking "Unsubscribe" in any email or contacting us at support@cairnadvisory.co
- Cookies: You may refuse or delete cookies through your browser settings; however, this may limit functionality
- Email Engagement: Delivery and open tracking on platform emails is a function of our delivery provider. Recipients may unsubscribe from any email, which suppresses all further sends to them
5.5 California Privacy Rights (CCPA)
If you are a California resident, you have the right to:
- Know what personal information is collected, used, shared, and sold
- Delete personal information (subject to certain exceptions)
- Opt out of the "sale" of personal information
- Non-discrimination for exercising your rights
To exercise these rights, contact us at support@cairnadvisory.co with "CCPA Request" in the subject line.
5.6 European Privacy Rights (GDPR)
If you are subject to GDPR, you have the right to:
- Access, correct, and delete your personal information
- Restrict processing
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with your data protection authority
To exercise these rights, contact us at support@cairnadvisory.co.
6. International Data Transfers
MedOS is hosted in the United States. If you are located outside the United States, your information will be transferred to, stored in, and processed in the United States. By using the Services, you consent to the transfer of your information to the United States, which may have different privacy protections than your home country.
If you are subject to GDPR or other privacy laws requiring data protection mechanisms for international transfers, Provider will implement appropriate safeguards such as Standard Contractual Clauses.
7. PII vs. PHI
7.1 PII — What MedOS Stores
MedOS stores Personally Identifiable Information (PII) about the members your practice serves, and about your practice and its staff, including:
- Member names, email addresses, telephone numbers, and postal addresses
- Membership tier, contract value, and renewal dates
- Responses members give to your surveys, stored linked to the member
- Practice locations, contact details, branding, and staff accounts
7.2 PHI — What MedOS Does Not Store by Default
MedOS is not an electronic health record and provides no facility for clinical data. It does not store:
- Diagnoses, medical histories, or problem lists
- Prescriptions or medication information
- Laboratory or imaging results
- Clinical notes or treatment plans
An important qualification. Because MedOS stores member records for a medical practice, and because surveys allow members to write freely in their own words, information a practice or a member enters may in some circumstances be health-related and identifiable. MedOS is not HIPAA-compliant by default and Provider is not a Business Associate unless a BAA has been executed. Practices should choose survey questions accordingly and should not use free-text fields for clinical detail.
7.3 If Your Use Case Changes to Include PHI
If you later need to store PHI in the Services, you must contact Provider at support@cairnadvisory.co to execute a Business Associate Agreement (BAA) before storing any PHI.
Do not store PHI without a signed BAA. Doing so violates HIPAA and exposes both parties to fines and liability.
8. Security
We take reasonable measures to protect your personal information. Stated specifically, rather than in general terms:
- Encryption in transit: TLS between your browser, the application, our database, and every third-party service we use
- Encryption at rest: Provided by our database and storage provider. MedOS does not add application-level field encryption on top of it
- Tenant isolation: Access to records is scoped to a single practice and enforced by database row-level security, not by application code alone
- Administrative access: Limited to authorized Provider personnel, and re-verified against our records on every request rather than trusted from a browser session
- Change management: All changes are version-controlled and must pass automated type checking, linting, unit tests, integration tests against a real database schema, and a production build before release
- Updates: Timely patching of software dependencies and infrastructure
We do not currently maintain per-record audit logging of who viewed or changed which record, and we hold no SOC 2 report and have not had a third-party penetration test. We describe our engineering practice in more detail on request.
If we become aware of a security incident affecting your information, we will investigate it and notify you as required by applicable law. No security system is impenetrable and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
9. Third-Party Links and Services
MedOS offers optional integrations with third-party services, currently HubSpot and Prismic. Your use of these services is governed by their privacy policies, not this one. We are not responsible for the privacy practices of third parties. Review their privacy policies before connecting your accounts.
10. Children's Privacy
MedOS is designed for healthcare professionals and administrative users, not children. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at support@cairnadvisory.co.
11. Changes to This Privacy Policy
Provider may update this Privacy Policy at any time. We will notify you of material changes by posting the updated policy on the Services and updating the "Last Updated" date. Continued use of MedOS after notification constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Cairn Advisory, LLC Email: support@cairnadvisory.co