Home › Privacy policy
Privacy policy
Effective date: 7 January 2023
Last updated: 19 August 2026
1. Introduction
AmeriTechies Inc. ("AmeriTechies", "Company", "we", "our", or "us") provides business and healthcare technology, including the NeuroEZ electronic health record platform, merchant payment processing, point of sale and business management software, electronic visit verification, and IT consulting and support.
This Privacy Policy explains how we collect, use, protect, and share personal information when healthcare providers, merchants, organizations, and other entities ("Clients") use or lease our software and services (the "Service"), and when visitors use our websites.
By using the Service or submitting information through our websites, Clients and their end users agree to the terms of this Privacy Policy.
2. Information we collect
2.1 Client and account information
- Name, organization, and contact details, including email address, telephone number, and postal address
- Business details supplied during onboarding, such as legal entity name, structure, and ownership
- Billing and payment information
- User credentials and authentication data
2.2 Enquiry information from our websites
- Details submitted through our forms: name, business name, email address, and telephone number
- Business context you choose to share, such as business type, number of locations, monthly card volume, current processor, and current point of sale system
- Documents you send us, including processing statements submitted for a rate review
- Correspondence with our sales and support teams
2.3 Patient data processed through the Service
Our Service stores and processes protected health information ("PHI") on behalf of our Clients. This may include:
- Demographics, including name, date of birth, and gender
- Medical history, treatments, and diagnoses
- Lab results, prescriptions, and imaging records
- Insurance and billing details
- Records of services delivered, including dates, times, locations, and the individuals providing and receiving care where visit verification is used
We act as a Business Associate, or a subcontractor Business Associate, under HIPAA and process this data only as instructed by our Clients and as permitted by the applicable Business Associate Agreement ("BAA"). Where this policy and an executed BAA conflict with respect to PHI, the BAA controls.
The Client is the Covered Entity or controlling party for that data and remains responsible for the lawfulness of its instructions, for obtaining any required patient consents or authorisations, for its own safeguards, and for notifying individuals and authorities in the event of a breach, unless a BAA expressly provides otherwise.
We may create de-identified information in accordance with 45 C.F.R. § 164.514(a)–(b). De-identified and aggregated information is not PHI and may be used and retained without restriction to operate, secure, support, and improve our services and to develop new products, provided it is not re-identified and is not disclosed in a form that identifies any individual or Client.
2.4 Payment information
We facilitate payment processing through third-party bank payment processors, acquiring banks, and payment gateways. Which provider is used depends on the arrangement that best fits a given Client's business, risk profile, and processing requirements, and may change over time or differ between Clients.
- Cardholder payment credentials are collected and processed directly by the applicable payment processor or gateway
- We do not store full card numbers or sensitive authentication data on our servers
- We may retain limited billing details such as transaction amounts, dates, payment status, authorisation results, and partial identifiers such as the last four digits of a card
- We may receive settlement, chargeback, and reserve information from processors in connection with account administration and risk monitoring
Use of payment services is also subject to the terms and privacy practices of the payment processor, acquiring bank, or gateway handling the transaction. We will identify the relevant provider on request.
2.5 Usage and device information
- IP addresses, browser type, operating system, and device identifiers
- Logs of user interactions with the system, including authentication events
- Performance data and diagnostic information
2.6 Location and time data
Where a Client uses features that verify the delivery of services in the field, such as electronic visit verification, the Service records the time and location at which a visit is started and completed, together with the identity of the person providing the service. This is collected because federal and state programs require it, and it is processed on behalf of the Client as PHI.
2.7 Information we ask you not to send
Please do not send patient health information, full card numbers, or Social Security numbers through our website forms or by ordinary email. Where sensitive material is needed, contact us and we will provide a secure method.
3. How we use information
- Providing, maintaining, supporting, and improving the Service
- Preparing the rate comparison, proposal, or quotation you requested
- Completing merchant applications and underwriting with acquiring banks and payment processors, where you have asked us to proceed
- Ensuring data security and regulatory compliance
- Customer support and technical assistance
- Payment processing, settlement, and account management
- Fraud prevention, risk monitoring, and account verification
- Conducting aggregated and anonymised analytics to improve performance and reliability
- Meeting legal, regulatory, card network, and record-keeping obligations
We do not sell personal information, and we do not share it with third parties for their own marketing purposes.
4. Data sharing and disclosure
4.1 With Clients
Patient data is controlled by our Clients. We process it strictly according to their instructions, the applicable Business Associate Agreement, and applicable law.
4.2 With payment processors and financial institutions
To open and maintain a merchant account, application and business information is shared with acquiring banks, payment processors, gateways, and underwriting partners. Because we work with more than one provider, the recipient depends on which arrangement suits the Client's requirements. Payouts, funding schedules, reserves, and dispute handling are governed by the provider through which a Client's transactions are settled.
4.3 With authorised third-party service providers
We may share data with vendors who assist with:
- Hosting and infrastructure
- Payment processing and settlement
- Security, fraud prevention, and identity verification
- Analytics and system performance
- Communications, email delivery, and support tooling
These providers are contractually required to protect data, use it only for the purposes we specify, and maintain confidentiality.
4.4 Legal compliance and protection
We may disclose information where required by law, subpoena, court order, or card network rule, or in order to:
- Comply with legal and regulatory obligations
- Prevent fraud, abuse, or financial loss
- Protect the rights, safety, and security of our users, our systems, and the public
4.5 Business transfer
In connection with a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy and any applicable Business Associate Agreement.
5. Data security measures
We implement technical, administrative, and physical safeguards, including:
- Encryption of data in transit and at rest
- Access controls and role-based permissions
- Unique credentials per user, session controls, and audit logging
- Regular security review and vulnerability testing
- Safeguards and procedures aligned with HIPAA requirements
Cardholder data security is managed in part by the payment processors and gateways we work with, each of which is required to maintain PCI DSS compliance for the services it provides.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Data retention
We retain information:
- As directed by Clients and as required by applicable healthcare regulations
- As necessary for billing, payment processing, dispute resolution, and compliance
- As required to satisfy legal, tax, card network, and audit obligations
Our general retention period is up to seven years, which reflects the record-keeping obligations that apply to payment processing and business records. Retention of PHI is governed by the applicable Business Associate Agreement and by the retention rules that apply to the Client.
Processing statements submitted for a rate review are retained only as long as needed to complete the analysis and follow up, unless you become a Client, in which case they form part of your account record.
Clients may request deletion of patient data in accordance with contractual agreements and legal requirements.
7. Client and user rights
Depending on applicable law, including HIPAA and state privacy statutes, individuals may have rights to:
- Access, correct, or delete their data
- Restrict or object to certain processing
- Receive a copy of their data in a portable form
- Opt out of marketing communications at any time
- File a complaint with a regulatory authority
Requests relating to PHI should be directed to the Client, meaning the healthcare provider or agency that holds the record. Where we receive such a request directly, we will refer it to the relevant Client rather than acting on it ourselves.
Requests concerning contact information we hold about you can be sent to us using the details in section 12, and we will respond as required by applicable law. Some records must be retained even where deletion is requested.
8. International data transfers
If Clients or users access the Service from outside the United States, data may be transferred to and processed in jurisdictions whose laws differ from those of your own. We implement safeguards such as Standard Contractual Clauses where applicable.
9. Cookies and tracking technologies
Our marketing website does not currently use analytics, advertising, or tracking cookies. We may introduce them at any time, for example to understand how the site is used or to measure advertising. If we do, this policy will be updated to name the providers and describe what they collect before those cookies are set.
The NeuroEZ platform and other authenticated applications use strictly necessary cookies and similar technologies to maintain sessions, keep users signed in, and protect against unauthorised access. These cannot be disabled without preventing the application from working. Where performance or usage analytics are used inside an application, they are used to improve system functionality and reliability.
Users can manage cookie preferences through their browser settings, though doing so may affect the operation of authenticated applications.
10. Children
Our websites are directed at businesses and are not intended for children. We do not knowingly collect personal information directly from children. Where the Service processes records relating to minors as part of a Client's patient population, that data is handled as PHI on the Client's behalf.
11. Updates to this Privacy Policy
We may update this Privacy Policy periodically. The revision date at the top of this page shows when it last changed. Material changes will be communicated by email or within the Service.
12. Contact
Questions about this policy, or requests concerning your information, can be sent to notice@ameritechies.com or by post to AmeriTechies Inc., 2600 E 26th Street B101, Minneapolis, MN, 55406. Telephone 612-234-5649, Option 2 for Support.