Talys Health Privacy Policy

Effective date: August 1, 2026

Talys Health, Inc. ("Talys," "we," "our") provides an AI-powered platform that helps hospitals and health systems manage external spend and realize savings. This policy explains what personal information we handle, why, and what choices you have. It covers three situations:

It does not cover protected health information, which the next section explains.

1. Protected health information

Talys handles protected health information ("PHI") only as a business associate of its healthcare customers under HIPAA. Our use of PHI is governed by the business associate agreement we sign with each customer and by that customer's own notice of privacy practices, not by this policy.

If you are a patient, HIPAA requires that requests about your health information (access, amendment, an accounting of disclosures) go to your healthcare provider, not to us. If such a request reaches us, we will forward it to the responsible customer as our agreements require.

Please do not submit PHI or other sensitive personal information through talyshealth.com. The public website is not designed or intended to receive it.

2. Information we collect

Information you give us. When you fill out a form, request a demo, email us, or apply for a job, we receive what you send: typically your name, work email, organization, role, and the content of your message or application.

Information collected automatically. When you browse talyshealth.com, our servers log basic technical data: IP address, browser type, pages viewed, and the referring page.

Information provisioned by our customers. When a customer sets up platform access for its personnel, we receive account details for each user (name, work email, organization, role), and we generate authentication and activity records as those users sign in and use the platform.

3. How we use information

We do not sell personal information, and we do not use it for advertising or cross-context behavioral profiling. Our revenue comes from customer subscriptions, not data.

4. Artificial intelligence

The Talys platform uses large language models as part of its analytics features. That processing runs within our secured, HIPAA-eligible cloud environment and is governed by our agreements with each customer.

5. Cookies and tracking

talyshealth.com uses only the cookies needed for the site to function and, if analytics tools are enabled, first-party analytics cookies. We do not use advertising cookies or third-party tracking pixels, and we do not permit cross-site tracking of our visitors, so there is nothing for an opt-out signal to switch off. Visitors who prefer to block analytics cookies can do so in their browser without losing site functionality.

6. When we disclose information

We disclose personal information only to:

7. Retention

We keep personal information only as long as it serves the purpose it was collected for, or as law or contract requires: website logs for a short operational window, correspondence while it remains relevant, platform accounts and audit logs per our customer agreements, applicant records per employment-law requirements, and billing records per tax requirements. After that, we delete or de-identify it.

8. Security and incident notification

We operate a security program aligned with SOC 2 and the HIPAA Security Rule: encryption in transit and at rest, least-privilege access with multi-factor authentication, audit logging, continuous monitoring, and independent audits. Details are available in our Trust Center. If a security incident affects your personal information, we will notify affected parties and regulators as applicable law and our customer agreements require.

9. Where information is stored

Talys is a US company, and our services run in US cloud regions. Customer data, including any PHI, stays in the United States, and access to it is US-based, per our customer commitments. If you use our website or services from outside the US, your information will be processed in the US.

10. Your rights and choices

Email privacy@talyshealth.com to request access to, correction of, or deletion of your personal information. We verify each request and respond within 30 days. Two routing notes: requests tied to an account your employer provisioned may need to be fulfilled through that customer, and requests about patient health information go to your healthcare provider (Section 1).

State privacy laws such as the California Consumer Privacy Act may give you additional rights, including the right not to be treated differently for exercising them. We honor such requests regardless of whether a given statute applies to a company of our size, and we do not sell or "share" personal information as the CCPA defines those terms.

11. Children

Our website and services are built for healthcare professionals and organizations. No part of our service is directed at children, and we do not knowingly collect personal information directly from them. Health information about minors that a customer includes in its data is PHI handled under Section 1 and our agreement with that customer.

12. Changes to this policy

If we change this policy materially, we will update the effective date and post the new version at talyshealth.com/privacy, and we will notify customers directly of changes that significantly affect platform users.

13. Contact

privacy@talyshealth.com
Talys Health, Inc.