Privacy Policy

Last updated: March 2026

AI Content & Medical Disclaimer

GProv uses AI to provide informational content. GProv is not responsible for AI-generated inaccurate content. Users should always do their due diligence and consult a licensed medical professional for medical advice. Our privacy practices below apply to how we collect, use, and protect your data when you use the platform.

1. Introduction

GProv is a product of Kollitech LLC, a company registered in the United States ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, applications, and services (collectively, the "Service"). By using GProv, you agree to the practices described in this policy. If you do not agree, please do not use our services.

This policy applies to all users of GProv, including patients, healthcare providers, administrators, and visitors. We are committed to protecting your privacy and handling your data in compliance with applicable laws including the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA/CPRA), the General Data Protection Regulation (GDPR), and other applicable privacy laws.

2. Information We Collect

We may collect the following categories of information:

  • Account and profile data: name, email address, phone number, password (hashed and salted), date of birth, and other details you provide when registering or updating your profile.
  • Protected Health Information (PHI): health and clinical data you choose to enter (e.g., symptoms, medications, conditions, lab results, medical documents). This data is classified as sensitive and is handled in accordance with HIPAA and applicable data protection laws.
  • Usage and technical data: device information, IP address, browser type and version, operating system, pages visited, referring/exit pages, click patterns, session duration, and how you interact with the platform and AI features.
  • Location data: approximate or precise geolocation when you use location-based features (e.g., Find Care, "Use Current Location"), only with your explicit permission.
  • Communications: messages you send to us via support channels and, where applicable, content of secure messaging within the platform.
  • Cookies and tracking technologies: we use cookies, web beacons, and similar technologies to enhance your experience, analyze usage, and deliver relevant content. See our Cookie Policy for details.

3. Lawful Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Contract performance: to provide the Service you have requested.
  • Consent: where you have given explicit consent (e.g., for processing health data, marketing communications, or cookies).
  • Legitimate interests: for platform security, fraud prevention, service improvement, and analytics, where these interests are not overridden by your rights.
  • Legal obligation: to comply with applicable laws, regulations, or legal processes.

4. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve our services, including AI-powered features.
  • Personalize your experience and deliver relevant content and suggestions.
  • Process and store your health and clinical data as you direct.
  • Facilitate provider-patient communication and referral coordination.
  • Communicate with you (e.g., support, security alerts, product updates, and appointment reminders).
  • Comply with legal obligations, enforce our Terms of Service, and protect our rights and the safety of users.
  • Analyze usage in an aggregated, de-identified way to improve our services.
  • Detect, prevent, and respond to fraud, abuse, and security incidents.

5. AI and Third-Party Processing

Some features use AI (including third-party AI services such as Google Gemini) to generate or process content. Input you provide (e.g., symptom descriptions) may be processed by these systems to deliver responses. We require all third-party processors to maintain appropriate safeguards and process your data only in accordance with our data processing agreements and this policy. AI-generated content may be inaccurate; see our Terms of Service and Help Center for important limitations and the need to consult licensed professionals. We do not sell your personal data or PHI to third parties.

6. Disclosure of Information

We may share your information in the following circumstances:

  • Service providers: with hosting, analytics, AI, and other service providers who assist us under contractual obligations and data processing agreements to protect your data.
  • At your direction: when you direct us to share data (e.g., sharing records with a healthcare provider you choose, referral coordination).
  • Legal requirements: when required by law, court order, subpoena, or to protect rights, safety, or property.
  • Business transfers: in connection with a merger, acquisition, sale of assets, or other corporate transaction, with notice as required by law.
  • De-identified data: we may share aggregated, de-identified data that cannot reasonably be used to identify you for research, analytics, and service improvement.

7. HIPAA Compliance

To the extent that GProv processes Protected Health Information (PHI) on behalf of covered entities or their business associates, we do so in compliance with HIPAA. We maintain administrative, physical, and technical safeguards to protect PHI including encryption at rest and in transit, access controls, audit logging, and workforce training. We enter into Business Associate Agreements (BAAs) as required by HIPAA. If you believe your PHI has been improperly used or disclosed, you may file a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights.

8. Data Security

We implement industry-standard technical and organizational measures to protect your data, including:

  • AES-256 encryption for data at rest and TLS 1.2+ for data in transit.
  • Role-based access controls and multi-factor authentication for administrative access.
  • Regular security assessments, penetration testing, and vulnerability scanning.
  • Comprehensive audit logging and monitoring.
  • Incident response procedures and breach notification protocols.

No system is completely secure. You provide data at your own risk, and we encourage you to use a strong, unique password and keep your account credentials confidential.

9. Data Retention

We retain your information for as long as your account is active or as needed to provide services, and in accordance with the following:

  • Account data: retained while your account is active and for 30 days after account deletion to allow recovery.
  • Health/clinical records: retained in accordance with applicable medical record retention laws (typically 7-10 years depending on jurisdiction).
  • Audit and security logs: retained for a minimum of 6 years as required by HIPAA.
  • Support communications: retained for 3 years from resolution.
  • De-identified analytics data: may be retained indefinitely.

10. Your Rights and Choices

Depending on your location and applicable law, you may have the following rights:

All Users

  • Access, correct, or delete your personal data.
  • Export your data in a portable, machine-readable format.
  • Withdraw consent where processing is consent-based.
  • Opt out of non-essential communications.

California Residents (CCPA/CPRA)

  • Right to know what personal information we collect, use, and disclose.
  • Right to delete personal information we hold about you.
  • Right to opt out of the sale or sharing of personal information. We do not sell your personal information.
  • Right to non-discrimination for exercising your privacy rights.
  • Right to correct inaccurate personal information.
  • Right to limit the use and disclosure of sensitive personal information.

EEA/UK/Swiss Residents (GDPR)

  • Right to access, rectify, erase, or restrict processing of your data.
  • Right to data portability.
  • Right to object to processing based on legitimate interests.
  • Right to withdraw consent at any time without affecting prior processing.
  • Right to lodge a complaint with your local data protection authority.

To exercise any of these rights, contact us at privacy@gprov.com or support@gprov.com. We will verify your identity and respond within the timeframes required by applicable law (generally 30-45 days).

11. Children's Privacy

Our services are not directed to individuals under the age of 13 (or 16 in the EEA/UK). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided personal information to us, please contact us immediately at privacy@gprov.com so we can delete it. Where required by law, we will obtain verifiable parental consent before collecting information from minors.

12. International Data Transfers

Your data may be processed in countries other than your own, including the United States. We take steps to ensure that international transfers are subject to appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other mechanisms recognized by applicable law. By using the Service, you acknowledge that your data may be transferred to and processed in the United States and other jurisdictions.

13. Do Not Track

Some browsers offer a "Do Not Track" (DNT) signal. We currently do not respond to DNT signals. However, you can manage your cookie preferences through our Cookie Policy and browser settings.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. For material changes, we will provide notice through email, in-app notification, or a prominent notice on the Service at least 30 days before the changes take effect. Continued use of GProv after the effective date of changes constitutes acceptance of the updated policy.

15. Contact Us

For privacy-related questions, data requests, or complaints:

Kollitech LLC
Attn: Privacy Officer
Email: privacy@gprov.com
Phone: 628-333-5116