Talys Health Privacy Policy
Effective date: August 1, 2026
Talys Health, Inc. ("Talys," "we," "our") provides an AI-powered platform that helps hospitals and health systems manage external spend and realize savings. This policy explains what personal information we handle, why, and what choices you have. It covers three situations:
- Website visitors and prospective customers: people who browse talyshealth.com or contact us.
- Platform users: people whose employer (our customer) has given them access to the Talys platform.
- Job applicants: people who apply to work at Talys.
It does not cover protected health information, which the next section explains.
1. Protected health information
Talys handles protected health information ("PHI") only as a business associate of its healthcare customers under HIPAA. Our use of PHI is governed by the business associate agreement we sign with each customer and by that customer's own notice of privacy practices, not by this policy.
If you are a patient, HIPAA requires that requests about your health information (access, amendment, an accounting of disclosures) go to your healthcare provider, not to us. If such a request reaches us, we will forward it to the responsible customer as our agreements require.
Please do not submit PHI or other sensitive personal information through talyshealth.com. The public website is not designed or intended to receive it.
2. Information we collect
Information you give us. When you fill out a form, request a demo, email us, or apply for a job, we receive what you send: typically your name, work email, organization, role, and the content of your message or application.
Information collected automatically. When you browse talyshealth.com, our servers log basic technical data: IP address, browser type, pages viewed, and the referring page.
Information provisioned by our customers. When a customer sets up platform access for its personnel, we receive account details for each user (name, work email, organization, role), and we generate authentication and activity records as those users sign in and use the platform.
3. How we use information
- To operate, secure, and support the website and the platform, including sign-in, access control, and the audit logging we maintain as a security and HIPAA compliance measure.
- To respond to inquiries and demo requests, and to follow up about our services.
- To send marketing email, if you have engaged with us; every marketing message includes an unsubscribe link, and opting out never affects operational messages tied to a service you use.
- To evaluate job applications.
- To analyze website usage, plan capacity, and prevent abuse. We may use third-party analytics tools that process technical data on our behalf.
We do not sell personal information, and we do not use it for advertising or cross-context behavioral profiling. Our revenue comes from customer subscriptions, not data.
4. Artificial intelligence
The Talys platform uses large language models as part of its analytics features. That processing runs within our secured, HIPAA-eligible cloud environment and is governed by our agreements with each customer.
5. Cookies and tracking
talyshealth.com uses only the cookies needed for the site to function and, if analytics tools are enabled, first-party analytics cookies. We do not use advertising cookies or third-party tracking pixels, and we do not permit cross-site tracking of our visitors, so there is nothing for an opt-out signal to switch off. Visitors who prefer to block analytics cookies can do so in their browser without losing site functionality.
6. When we disclose information
We disclose personal information only to:
- Service providers. Vendors that host or support our service (for example, Amazon Web Services, which hosts our infrastructure in the United States) under contracts limiting them to providing their service to us. Any provider that could handle PHI signs a business associate agreement. Our current subprocessor list is available on request and through our Trust Center.
- Our customer, for platform users. If your access was provisioned by your employer, your account and activity records are visible to that organization under our agreement with it. Questions about your employer's practices go to your administrator.
- Professional advisors and auditors, such as our independent SOC 2 auditor, under confidentiality obligations and without PHI.
- Authorities, when legally compelled. We require valid legal process, disclose only what the process requires, and notify affected customers unless legally prohibited from doing so.
- A successor, if Talys is involved in a merger, acquisition, or sale of assets; this policy would continue to apply to the transferred information.
7. Retention
We keep personal information only as long as it serves the purpose it was collected for, or as law or contract requires: website logs for a short operational window, correspondence while it remains relevant, platform accounts and audit logs per our customer agreements, applicant records per employment-law requirements, and billing records per tax requirements. After that, we delete or de-identify it.
8. Security and incident notification
We operate a security program aligned with SOC 2 and the HIPAA Security Rule: encryption in transit and at rest, least-privilege access with multi-factor authentication, audit logging, continuous monitoring, and independent audits. Details are available in our Trust Center. If a security incident affects your personal information, we will notify affected parties and regulators as applicable law and our customer agreements require.
9. Where information is stored
Talys is a US company, and our services run in US cloud regions. Customer data, including any PHI, stays in the United States, and access to it is US-based, per our customer commitments. If you use our website or services from outside the US, your information will be processed in the US.
10. Your rights and choices
Email privacy@talyshealth.com to request access to, correction of, or deletion of your personal information. We verify each request and respond within 30 days. Two routing notes: requests tied to an account your employer provisioned may need to be fulfilled through that customer, and requests about patient health information go to your healthcare provider (Section 1).
State privacy laws such as the California Consumer Privacy Act may give you additional rights, including the right not to be treated differently for exercising them. We honor such requests regardless of whether a given statute applies to a company of our size, and we do not sell or "share" personal information as the CCPA defines those terms.
11. Children
Our website and services are built for healthcare professionals and organizations. No part of our service is directed at children, and we do not knowingly collect personal information directly from them. Health information about minors that a customer includes in its data is PHI handled under Section 1 and our agreement with that customer.
12. Changes to this policy
If we change this policy materially, we will update the effective date and post the new version at talyshealth.com/privacy, and we will notify customers directly of changes that significantly affect platform users.
13. Contact
privacy@talyshealth.com
Talys Health, Inc.