Privacy Policy
Effective as of November 25, 2025
Tendral Health LLC ("we," "our," or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our survey platform.
Important Notice
We do not collect, process, or store Protected Health Information (PHI) as defined by HIPAA. Our platform is designed for healthcare market research and professional surveys that do not involve patient data.
Information We Collect
Personal Information
- Name and contact information (email, phone number)
- Professional credentials (NPI, specialty, practice setting)
- Payment information (processed securely by Stripe)
- Survey responses and research data
Device and Browser Information
When you access our surveys, we automatically collect:
- Browser Information: Browser type and version, operating system and version, platform information
- Device Specifications: Device type (desktop, mobile, tablet), screen resolution, viewport dimensions, hardware specifications (processor cores, device memory), timezone and language preferences
- Device Fingerprints: Canvas, WebGL, and audio fingerprints for unique device identification and fraud prevention
Network and Connection Data
We collect information about your network connection to ensure service quality and security:
- IP Address and ISP: Your IP address, Internet Service Provider (ISP), and network organization
- Connection Type: WiFi, cellular, ethernet, and connection speed information
- Security Detection: VPN, proxy, or TOR usage detection, hosting provider detection, and threat level assessment
Geographic Information
Based on your IP address, we determine approximate location data:
- Country, state/region, and city
- Postal code (3-digit level for reporting purposes)
- Approximate latitude and longitude (city-level precision only)
Survey Access Information
We track how you interact with our surveys:
- Access Patterns: Survey access timestamps, session duration, completion status and progress, number of surveys accessed
- Source Tracking: Entry source and referrer URL, UTM campaign parameters (source, medium, campaign, term, content)
- Session Information: Session identifiers to group related activities, return visitor detection, page views per session
How We Use Your Information
We use your information for the following purposes:
Service Delivery
- Provide and maintain our survey platform
- Process payments and manage accounts
- Verify professional credentials
- Communicate with you about our services
Security and Fraud Prevention
- Detect and prevent fraudulent survey responses
- Identify automated bot activity
- Monitor for unusual access patterns
- Prevent duplicate submissions
- Protect the integrity of survey data
Analytics and Improvement
- Understand survey engagement patterns
- Optimize survey performance across devices
- Analyze geographic distribution of respondents
- Measure marketing campaign effectiveness
- Improve user experience
Quality Assurance
- Ensure response data quality
- Identify technical issues
- Monitor system performance
- Validate respondent authenticity
Artificial Intelligence and Machine Learning
- Train, develop, and improve machine learning models and AI systems
- Develop new products, features, and services powered by AI
- Enhance automated quality detection and fraud prevention systems
- Create predictive analytics and research insights
These activities may involve processing your data through third-party AI service providers listed in our Third-Party Services section.
Research and Analytics Products
- Create research reports and analytics products
- Develop industry insights and trend analyses
- Generate aggregated datasets for research purposes
- Support healthcare market research activities
Legal and Compliance
- Comply with legal obligations
- Respond to legal requests and prevent harm
- Enforce our terms of service
Information Sharing
We may share your information with:
Survey Sponsors
When you participate in a survey, the organization that sponsored that survey ("Survey Sponsor") receives your individual responses along with professional identifiers including your NPI, specialty, and practice setting. This allows Survey Sponsors to understand the professional background of respondents. Your name and contact information are not shared with Survey Sponsors unless you separately consent.
Research Reports and Analytics
We create research reports, analytics, and aggregated datasets derived from survey responses. These products do not include individual NPI numbers or other direct identifiers and are made available to healthcare organizations, research institutions, and industry clients for research and analytical purposes. These aggregated products may include statistical summaries and professional opinion trends, geographic distribution using 3-digit zip code regions, and professional demographic breakdowns by specialty and practice type.
Service Providers
Third-party vendors who assist in our operations, including AI service providers
Legal Authorities
When required by law or to protect our rights
Business Transfers
In connection with mergers or acquisitions
Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Secure hosting infrastructure
Data Retention
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Account Information: Retained for the duration of your account and up to 3 years after account closure
- Survey Responses: Individual responses are retained for 5 years for operational purposes. Survey Sponsors receive responses as described in the Information Sharing section.
- Aggregated and De-identified Data: Aggregated and de-identified data derived from survey responses may be retained indefinitely for research, analytics, and AI/ML development purposes
- Access Logs and Tracking Data: Automatically deleted after 180 days for security and analytical purposes
- Legal Compliance: Data may be retained longer if required by law or legal proceedings
Third-Party Services
We use third-party services to provide and improve our platform. Key service categories include:
- Hosting and Infrastructure: Vercel for hosting and analytics
- Database and Authentication: Supabase for data storage and user authentication
- Payment Processing: Stripe for secure payment processing; Mercury and Plaid for banking and verification services
- Communications: SendGrid for email delivery; Twilio for SMS verification
- AI Services: Anthropic, OpenAI, Voyage AI, Hugging Face, and RunPod for AI-powered features and analysis
- Incentive Delivery: Tremendous for gift card and reward delivery
For a complete and current list of our data processors, please see our Subprocessors page.
These services have their own privacy policies and we encourage you to review them. We only share the minimum information necessary for these services to function.
Your Rights
As a user in the United States, you have the right to:
- Access Your Information: Request a copy of the personal information we hold about you
- Correct Your Information: Request correction of any inaccurate or incomplete information
- Delete Your Information: Request deletion of your personal information (subject to legal retention requirements and noting that aggregated data cannot be deleted)
- Opt-Out of Certain Data Collection: You can opt-out of certain tracking via browser settings (disable cookies, use private browsing, block JavaScript)
- Data Portability: Request your data in a structured, commonly used format
- California Residents: Additional rights under CCPA including the right to know, delete, opt-out of sale (we do not sell personal information that identifies you), and non-discrimination
To exercise any of these rights, please contact us at privacy@tendralhealth.com. We will respond to your request within 30 days.
International Data Transfers
Your information may be transferred to and processed in countries other than your residence. We ensure appropriate safeguards are in place for such transfers.
Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective as of" date.
Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Tendral Health LLC
14080 Lone Bear Rd
Bozeman, MT 59715
Email: privacy@tendralhealth.com