Effective Date: April 10, 2026
-
Introduction and Scope
Guru by ChaturAI (“Guru,” “Platform,” “we,” “us,” or “our”) is a physician-built clinical decision intelligence platform designed to support oncology care through guideline-concordant recommendations, complexity triage, and care coordination. This Privacy Policy describes how ChaturAI (“Company”) collects, uses, stores, discloses, and protects information — including Protected Health Information ( PHI ) — in connection with the Guru platform.
This Policy applies to:
- Clinicians, physicians, and healthcare providers who access Guru directly
- Health systems, safety-net hospitals, and Federally Qualified Health Centers (FQHCs) that deploy Guru under institutional agreements
- Patients whose health information is processed through the platform by authorized healthcare providers
- Any individual or entity that interacts with Guru through the Microsoft Azure ecosystem
-
Information We Collect
-
Protected Health Information (PHI)
When deployed by a covered entity or business associate under a signed Business Associate Agreement, Guru may process the following categories of PHI submitted by authorized clinicians:
- Cancer histology, staging, and diagnosis information
- Biomarker and genomic data (e.g., NGS findings, MSI/TMB status, germline variants)
- Treatment history, prior lines of therapy, and response data
- Patient comorbidities, performance status (ECOG), and organ function data
- Social determinants of health (SDOH) data collected during clinical intake
- Insurance and payer information relevant to treatment planning
Guru does not store PHI beyond the active clinical session unless a formal Data Use Agreement (DUA) or BAA with explicit data retention terms has been executed with the deploying institution.
-
Clinician and User Account Data
When clinicians and administrators register for or access Guru, we may collect:
- Name, professional title, and institutional affiliation
- Email address and authentication credentials (managed via Microsoft Azure Active Directory)
- Usage logs including session timestamps, queries submitted, and recommendations reviewed
- Device identifiers and IP addresses for security and audit purposes
-
Automatically Collected Technical Data
Guru automatically collects certain technical data to maintain platform integrity and improve performance:
- Audit logs of every recommendation generated, including the data inputs, retrieved guideline sources, and tier assignment
- Error and diagnostic logs for system monitoring
- Aggregated, de-identified analytics on platform usage patterns
-
-
How We Use Information
-
Primary Clinical Purposes
PHI and clinical data submitted to Guru are used exclusively for the following purposes:
- Generating guideline-concordant oncology treatment recommendations via our RAG-based Decision Support Engine
- Assigning complexity triage tier (Tier 1, 2, or 3) to route cases appropriately
- Matching patients to eligible clinical trials via the ClinicalTrials.gov API
- Generating prior authorization documentation for insurance submission
- Screening for social determinants of health and surfacing appropriate resources
-
Platform Operations
User account data and technical data are used to:
- Authenticate users and manage access controls through Microsoft Azure AD
- Maintain complete audit trails for every clinical recommendation as required by HIPAA
- Monitor system performance, detect unauthorized access, and ensure data integrity
- Provide customer support to institutional partners
-
Research and Improvement
De-identified and aggregated data may be used to improve the accuracy and coverage of the platform’s clinical knowledge base. Any use of data for research purposes beyond platform operations requires:
- Explicit written consent from the deploying institution
- A separate Data Use Agreement specifying purpose, scope, and data handling
- IRB oversight where applicable under federal research regulations
-
-
HIPAA Compliance
-
Business Associate Status
ChaturAI operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act when processing PHI on behalf of covered entities. All institutions deploying Guru must execute a Business Associate Agreement (BAA) with ChaturAI prior to any PHI being entered into the platform.
-
Minimum Necessary Standard
Guru is designed to receive and process only the minimum PHI necessary to generate a clinical recommendation or triage assignment. Clinicians are instructed to enter only the data fields relevant to the active clinical query.
-
Security Safeguards
ChaturAI implements the following safeguards as required by the HIPAA Security Rule:
- Administrative Safeguards: Workforce training, access management policies, and incident response procedures
- Physical Safeguards: Data hosted on Microsoft Azure infrastructure with SOC 2 Type II and FedRAMP-authorized data centers
- Technical Safeguards: End-to-end encryption (TLS 1.2+ in transit, AES-256 at rest), role-based access controls, multi-factor authentication, and automated session timeouts
-
Breach Notification
In the event of a HIPAA-defined breach of unsecured PHI, ChaturAI will:
- Notify affected covered entities without unreasonable delay and within 60 days of discovery
- Provide a breach notification report including the nature of the breach, categories of PHI involved, number of individuals affected, and steps taken to mitigate harm
- Cooperate fully with the covered entity’s obligations to notify affected individuals and the U.S. Department of Health and Human Services (HHS)
-
-
GDPR Compliance (European Users)
-
Applicability
To the extent that Guru processes personal data of individuals located in the European Economic Area (EEA), the United Kingdom, or Switzerland, ChaturAI complies with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national implementing legislation.
-
Legal Bases for Processing
Under GDPR, ChaturAI relies on the following legal bases for processing personal data:
- Article 6(1)(b)— Processing necessary for the performance of a contract with the deploying institution
- Article 6(1)(c)— Processing necessary for compliance with legal obligations (e.g., HIPAA-equivalent EU health data regulations)
- Article 9(2)(h)— Processing of special category health data for medical diagnosis and provision of healthcare, performed by a healthcare professional subject to professional secrecy obligations
-
Data Subject Rights
Individuals whose data is processed by Guru through EU-based deployments have the following rights under GDPR, exercisable by contacting us at the address in Section 11:
- Right of Access (Article 15): Request a copy of personal data we hold about you
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete data
- Right to Erasure (Article 17):Request deletion of personal data where retention is no longer justified
- Right to Restriction (Article 18):Request limitation of processing in certain circumstances
- Right to Data Portability (Article 20):Receive your data in a structured, machine-readable format
- Right to Object (Article 21):Receive your data in a structured, machine-readable format Object to processing based on legitimate interests
Exercise of data subject rights related to PHI within an active clinical relationship is subject to applicable healthcare regulations and may require coordination with the treating institution.
-
International Data Transfers
If personal data is transferred outside the EEA, ChaturAI relies on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate transfer mechanisms, to ensure an adequate level of data protection.
-
Data Protection Officer
ChaturAI will designate a Data Protection Officer (DPO) upon reaching processing thresholds requiring such appointment under Article 37 GDPR. Until such time, data protection inquiries may be directed to the contact in Section 11.
-
-
Information Sharing and Disclosure
ChaturAI does not sell, rent, or trade personal data or PHI. We may share information only in the following circumstances:
-
With Deploying Institutions
Audit logs and recommendation records are accessible to the deploying institution’s authorized administrators in accordance with the executed BAA and institutional agreement.
-
With Service Providers
We engage trusted third-party service providers to support platform operations, including Microsoft Azure (cloud infrastructure and authentication). All subprocessors are bound by data processing agreements that restrict their use of data to services performed on our behalf.
-
Legal and Regulatory Disclosure
We may disclose information where required by law, court order, regulatory authority, or to protect the rights, property, or safety of ChaturAI, its users, or the public.
-
De-identified Data
Aggregated, de-identified data from which all PHI identifiers have been removed in accordance with 45 CFR §164.514 may be used for research, quality improvement, and publication purposes without restriction.
-
-
Data Retention
PHI processed in active clinical sessions is not retained beyond the session unless explicitly agreed under a signed DUA or BAA. Clinician account data is retained for the duration of the institutional subscription plus 12 months. Audit logs are retained for a minimum of 6 years in accordance with HIPAA requirements. Upon termination of an institutional agreement, ChaturAI will return or securely destroy PHI as directed by the institution within 30 days.
-
Pediatric and Adolescent/Young Adult Patients
Guru is a clinical platform accessed exclusively by licensed healthcare providers. It is not directed at or accessible to children directly. Processing of health information related to pediatric or AYA patients occurs solely within the clinical relationship and is governed by applicable HIPAA regulations and institutional policies. Guru’s complexity triage algorithm automatically assigns Tier 3 (Mandatory MDT) status to all pediatric and AYA cases.
-
Security
ChaturAI employs commercially reasonable and industry-standard technical, administrative, and physical security measures to protect data against unauthorized access, alteration, disclosure, or destruction. These include encryption at rest and in transit, role-based access controls, multi-factor authentication via Azure AD, and regular security assessments. No system is impenetrable; we encourage users to report suspected security incidents immediately to the contact in Section 11.
-
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, platform capabilities, or business practices. When we make material changes, we will update the Effective Date at the top of this document and notify institutional partners by email or in-platform notice at least 30 days prior to the change taking effect. Continued use of Guru after the effective date of any update constitutes acceptance of the revised Policy.
-
Contact Information
For privacy-related inquiries, to exercise data subject rights, or to report a security concern, please contact:
Guru by ChaturAI — Privacy Office
Email:privacy@chatur.ai
This Privacy Policy is intended to satisfy requirements for publication on the Microsoft Azure Marketplace and does not constitute legal advice. Institutions deploying Guru must execute a separate Business Associate Agreement (BAA) prior to processing any PHI.
LEGAL NOTICE: This Privacy Policy is a draft prepared for initial Azure Marketplace publication review. It should be reviewed and approved by qualified healthcare privacy counsel before final publication or distribution to institutional partners.