Effective Date: April 10, 2026

  1. Introduction and Scope

    Guru by ChaturAI (“Guru,” “Platform,” “we,” “us,” or “our”) is a physician-built clinical decision intelligence platform designed to support oncology care through guideline-concordant recommendations, complexity triage, and care coordination. This Privacy Policy describes how ChaturAI (“Company”) collects, uses, stores, discloses, and protects information — including Protected Health Information ( PHI ) — in connection with the Guru platform.

    This Policy applies to:

    • Clinicians, physicians, and healthcare providers who access Guru directly
    • Health systems, safety-net hospitals, and Federally Qualified Health Centers (FQHCs) that deploy Guru under institutional agreements
    • Patients whose health information is processed through the platform by authorized healthcare providers
    • Any individual or entity that interacts with Guru through the Microsoft Azure ecosystem
  2. This Privacy Policy is intended to satisfy requirements for publication on the Microsoft Azure Marketplace and does not constitute legal advice. Institutions deploying Guru must execute a separate Business Associate Agreement (BAA) prior to processing any PHI.

  3. Information We Collect

    1. Protected Health Information (PHI)

      When deployed by a covered entity or business associate under a signed Business Associate Agreement, Guru may process the following categories of PHI submitted by authorized clinicians:

      • Cancer histology, staging, and diagnosis information
      • Biomarker and genomic data (e.g., NGS findings, MSI/TMB status, germline variants)
      • Treatment history, prior lines of therapy, and response data
      • Patient comorbidities, performance status (ECOG), and organ function data
      • Social determinants of health (SDOH) data collected during clinical intake
      • Insurance and payer information relevant to treatment planning

      Guru does not store PHI beyond the active clinical session unless a formal Data Use Agreement (DUA) or BAA with explicit data retention terms has been executed with the deploying institution.

    2. Clinician and User Account Data

      When clinicians and administrators register for or access Guru, we may collect:

      • Name, professional title, and institutional affiliation
      • Email address and authentication credentials (managed via Microsoft Azure Active Directory)
      • Usage logs including session timestamps, queries submitted, and recommendations reviewed
      • Device identifiers and IP addresses for security and audit purposes
    3. Automatically Collected Technical Data

      Guru automatically collects certain technical data to maintain platform integrity and improve performance:

      • Audit logs of every recommendation generated, including the data inputs, retrieved guideline sources, and tier assignment
      • Error and diagnostic logs for system monitoring
      • Aggregated, de-identified analytics on platform usage patterns
  4. How We Use Information

    1. Primary Clinical Purposes

      PHI and clinical data submitted to Guru are used exclusively for the following purposes:

      • Generating guideline-concordant oncology treatment recommendations via our RAG-based Decision Support Engine
      • Assigning complexity triage tier (Tier 1, 2, or 3) to route cases appropriately
      • Matching patients to eligible clinical trials via the ClinicalTrials.gov API
      • Generating prior authorization documentation for insurance submission
      • Screening for social determinants of health and surfacing appropriate resources
    2. Platform Operations

      User account data and technical data are used to:

      • Authenticate users and manage access controls through Microsoft Azure AD
      • Maintain complete audit trails for every clinical recommendation as required by HIPAA
      • Monitor system performance, detect unauthorized access, and ensure data integrity
      • Provide customer support to institutional partners
    3. Research and Improvement

      De-identified and aggregated data may be used to improve the accuracy and coverage of the platform’s clinical knowledge base. Any use of data for research purposes beyond platform operations requires:

      • Explicit written consent from the deploying institution
      • A separate Data Use Agreement specifying purpose, scope, and data handling
      • IRB oversight where applicable under federal research regulations
  5. HIPAA Compliance

    1. Business Associate Status

      ChaturAI operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act when processing PHI on behalf of covered entities. All institutions deploying Guru must execute a Business Associate Agreement (BAA) with ChaturAI prior to any PHI being entered into the platform.

    2. Minimum Necessary Standard

      Guru is designed to receive and process only the minimum PHI necessary to generate a clinical recommendation or triage assignment. Clinicians are instructed to enter only the data fields relevant to the active clinical query.

    3. Security Safeguards

      ChaturAI implements the following safeguards as required by the HIPAA Security Rule:

      • Administrative Safeguards: Workforce training, access management policies, and incident response procedures
      • Physical Safeguards: Data hosted on Microsoft Azure infrastructure with SOC 2 Type II and FedRAMP-authorized data centers
      • Technical Safeguards: End-to-end encryption (TLS 1.2+ in transit, AES-256 at rest), role-based access controls, multi-factor authentication, and automated session timeouts
    4. Breach Notification

      In the event of a HIPAA-defined breach of unsecured PHI, ChaturAI will:

      • Notify affected covered entities without unreasonable delay and within 60 days of discovery
      • Provide a breach notification report including the nature of the breach, categories of PHI involved, number of individuals affected, and steps taken to mitigate harm
      • Cooperate fully with the covered entity’s obligations to notify affected individuals and the U.S. Department of Health and Human Services (HHS)
  6. GDPR Compliance (European Users)

    1. Applicability

      To the extent that Guru processes personal data of individuals located in the European Economic Area (EEA), the United Kingdom, or Switzerland, ChaturAI complies with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national implementing legislation.

    2. Legal Bases for Processing

      Under GDPR, ChaturAI relies on the following legal bases for processing personal data:

      • Article 6(1)(b)— Processing necessary for the performance of a contract with the deploying institution
      • Article 6(1)(c)— Processing necessary for compliance with legal obligations (e.g., HIPAA-equivalent EU health data regulations)
      • Article 9(2)(h)— Processing of special category health data for medical diagnosis and provision of healthcare, performed by a healthcare professional subject to professional secrecy obligations
    3. Data Subject Rights

      Individuals whose data is processed by Guru through EU-based deployments have the following rights under GDPR, exercisable by contacting us at the address in Section 11:

      • Right of Access (Article 15): Request a copy of personal data we hold about you
      • Right to Rectification (Article 16): Request correction of inaccurate or incomplete data
      • Right to Erasure (Article 17):Request deletion of personal data where retention is no longer justified
      • Right to Restriction (Article 18):Request limitation of processing in certain circumstances
      • Right to Data Portability (Article 20):Receive your data in a structured, machine-readable format
      • Right to Object (Article 21):Receive your data in a structured, machine-readable format Object to processing based on legitimate interests

      Exercise of data subject rights related to PHI within an active clinical relationship is subject to applicable healthcare regulations and may require coordination with the treating institution.

    4. International Data Transfers

      If personal data is transferred outside the EEA, ChaturAI relies on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate transfer mechanisms, to ensure an adequate level of data protection.

    5. Data Protection Officer

      ChaturAI will designate a Data Protection Officer (DPO) upon reaching processing thresholds requiring such appointment under Article 37 GDPR. Until such time, data protection inquiries may be directed to the contact in Section 11.

  7. Information Sharing and Disclosure

    ChaturAI does not sell, rent, or trade personal data or PHI. We may share information only in the following circumstances:

    1. With Deploying Institutions

      Audit logs and recommendation records are accessible to the deploying institution’s authorized administrators in accordance with the executed BAA and institutional agreement.

    2. With Service Providers

      We engage trusted third-party service providers to support platform operations, including Microsoft Azure (cloud infrastructure and authentication). All subprocessors are bound by data processing agreements that restrict their use of data to services performed on our behalf.

    3. Legal and Regulatory Disclosure

      We may disclose information where required by law, court order, regulatory authority, or to protect the rights, property, or safety of ChaturAI, its users, or the public.

    4. De-identified Data

      Aggregated, de-identified data from which all PHI identifiers have been removed in accordance with 45 CFR §164.514 may be used for research, quality improvement, and publication purposes without restriction.

  8. Data Retention

    PHI processed in active clinical sessions is not retained beyond the session unless explicitly agreed under a signed DUA or BAA. Clinician account data is retained for the duration of the institutional subscription plus 12 months. Audit logs are retained for a minimum of 6 years in accordance with HIPAA requirements. Upon termination of an institutional agreement, ChaturAI will return or securely destroy PHI as directed by the institution within 30 days.

  9. Pediatric and Adolescent/Young Adult Patients

    Guru is a clinical platform accessed exclusively by licensed healthcare providers. It is not directed at or accessible to children directly. Processing of health information related to pediatric or AYA patients occurs solely within the clinical relationship and is governed by applicable HIPAA regulations and institutional policies. Guru’s complexity triage algorithm automatically assigns Tier 3 (Mandatory MDT) status to all pediatric and AYA cases.

  10. Security

    ChaturAI employs commercially reasonable and industry-standard technical, administrative, and physical security measures to protect data against unauthorized access, alteration, disclosure, or destruction. These include encryption at rest and in transit, role-based access controls, multi-factor authentication via Azure AD, and regular security assessments. No system is impenetrable; we encourage users to report suspected security incidents immediately to the contact in Section 11.

  11. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in law, platform capabilities, or business practices. When we make material changes, we will update the Effective Date at the top of this document and notify institutional partners by email or in-platform notice at least 30 days prior to the change taking effect. Continued use of Guru after the effective date of any update constitutes acceptance of the revised Policy.

  12. Contact Information

    For privacy-related inquiries, to exercise data subject rights, or to report a security concern, please contact:

    Guru by ChaturAI — Privacy Office

    Email:privacy@chatur.ai

LEGAL NOTICE: This Privacy Policy is a draft prepared for initial Azure Marketplace publication review. It should be reviewed and approved by qualified healthcare privacy counsel before final publication or distribution to institutional partners.