Privacy Notice

Effective date: July 26, 2026

In short. This website is a brochure site with a contact form. We collect only what you type into that form, plus the technical data any web server records. We do not run advertising or analytics trackers, we do not sell or share personal information, and we do not receive protected health information through this website.

Patient data reaches us only inside client engagements, under a separate written agreement and a business associate agreement. That work is governed by those contracts, not by this notice. See Protected health information.

Contents

  1. Scope of this notice
  2. Personal information we collect
  3. Cookies and tracking technologies
  4. How we use personal information
  5. How we share personal information
  6. Protected health information
  7. Your choices
  8. State privacy rights
  9. Do not sell or share
  10. Access and retention
  11. Security
  12. Children's privacy
  13. International transfers
  14. Changes to this notice
  15. How to contact us

1. Scope of this notice

This notice describes how SoftFinity Corp ("SoftFinity", "we", "us") handles personal information collected through www.softfinity.com and through ordinary business correspondence that begins there.

It does not apply to:

2. Personal information we collect

We collect two things: what you choose to send us, and the technical information a web server necessarily records.

Category What it includes and where it comes from
Identifiers and contact details Name, email address, and company name, when you enter them in our contact form or email us directly.
Message content The subject line and message body you submit, and anything you choose to include in them.
Technical and connection data IP address, request time, requested URL, HTTP status, user agent, and referring page. Our hosting provider records these in standard web server logs. Your IP address and submission time are also included in the notification email generated by the contact form.
Session data A single session identifier stored in a cookie, used to protect the contact form against cross-site request forgery. See section 3.

We do not ask for, and the contact form has no field for, government identifiers, financial account details, precise geolocation, biometric data, or health information. Please do not send those through this website.

3. Cookies and tracking technologies

We use one cookie, and only on the contact page:

Cookie Purpose and duration
PHPSESSID Strictly necessary. Links your browser to a server-side session so the contact form can verify that a submission came from the form we served, rather than from a forged request. It expires when you close your browser. It carries no identifying information itself.

We do not use advertising cookies, analytics or measurement scripts, session-replay tools, web beacons, tag managers, or social media pixels on this site.

Third-party requests

Our pages load the Fira Sans typeface from Google Fonts. Your browser therefore makes a request to fonts.googleapis.com and fonts.gstatic.com, which discloses your IP address and user agent to Google under Google's own policies. We receive no data from those requests. If you prefer to avoid them, blocking those hosts affects only the typeface, not the content.

We do not respond to browser "Do Not Track" signals, because we do not perform the kind of cross-site tracking those signals are meant to limit.

4. How we use personal information

We use what we collect to:

We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not use contact-form submissions to train machine-learning models.

5. How we share personal information

We do not sell personal information and we do not share it for cross-context behavioural advertising. We disclose it only as follows:

6. Protected health information

This website does not collect protected health information ("PHI"), and no patient data flows through it. If you are a prospective client or an EHR provider evaluating us, please do not send patient data through the contact form or by unencrypted email.

SoftFinity encounters PHI only when performing services for a client. In that context:

Individuals seeking access to, or amendment of, their own health records should contact the covered entity that holds them — normally the provider or facility — because that entity, not SoftFinity, controls those records and the process for handling such requests.

Nothing in this notice is a Notice of Privacy Practices under HIPAA. SoftFinity is not a covered entity.

7. Your choices

The simplest control is what you choose to send. Every field in our contact form is optional in the sense that you can decline to use the form at all and email or call us instead; if you leave required fields blank the form will not submit.

To stop receiving correspondence from us, reply asking us to stop, or contact us using the details in section 15, and we will close the thread.

8. State privacy rights

SoftFinity is based in California. Depending on where you live, you may have some or all of the following rights in respect of personal information we hold about you:

To exercise a right, contact us using the details in section 15 with enough information for us to locate your records — normally the email address you used and the approximate date. We will verify your request by replying to that address, and will respond within the period your state's law requires. You may use an authorised agent, in which case we may ask for proof of their authority.

If you are in the European Economic Area or the United Kingdom, you may also have rights to object to or restrict processing and to data portability, and to lodge a complaint with your supervisory authority. Our lawful basis for handling enquiry data is our legitimate interest in responding to you and in operating and securing our website.

9. Do not sell or share

SoftFinity does not sell personal information, and has not sold personal information, for monetary or other valuable consideration. We do not share personal information for cross-context behavioural advertising, and we do not disclose personal information to advertising networks or data brokers. Because there is no such activity, we do not provide a "Do Not Sell or Share My Personal Information" mechanism; there is nothing for it to switch off.

10. Access and retention

We keep business enquiries and the correspondence arising from them for as long as needed for the purpose described in section 4, and then for as long as our legal, tax, and accounting obligations require. Server logs are retained on our hosting provider's ordinary rotation schedule, which is currently weekly archives held for a limited period, and are not indexed against individuals.

To request access to, correction of, or deletion of your enquiry records, contact us using the details in section 15.

11. Security

We maintain administrative, technical, and physical safeguards appropriate to the limited data this website handles. For this site specifically, that includes serving all pages over HTTPS with HTTP requests redirected to HTTPS, transmitting form submissions over an encrypted connection, protecting the form with a cross-site request forgery token and an automated-submission trap, and keeping mail credentials outside the web root so they cannot be served as content.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a vulnerability in this site, or that your information has been compromised, please tell us at the address in section 15 and we will investigate.

12. Children's privacy

This website is intended for business use by adults. It is not directed to children, we do not knowingly collect personal information from anyone under 16, and it should not be used by anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

13. International transfers

SoftFinity operates in the United States, and this website and its supporting mail systems are hosted in the United States. If you contact us from outside the United States, the information you send will be transferred to and processed in the United States, where data protection law differs from that in your own country. Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on an appropriate transfer mechanism such as the European Commission's standard contractual clauses.

14. Changes to this notice

We may update this notice as our practices or the law change. We will revise the effective date at the top of the page, and changes apply going forward from that date rather than retroactively. Where a change is material we will make it more prominent than a date change alone. Please review this page periodically.

15. How to contact us

For any privacy question, or to exercise a right described in section 8:

SoftFinity Corp
Attn: Privacy
4444 Geary Blvd, Suite 202
San Francisco, CA 94118
United States

Email: rkagan@softfinity.com
Phone: +1 (877) 51-SEARCH