Privacy Policy
FLORENCE APP, LLC ("Florence", "we", "us"), a limited liability company organized under the laws of the State of Delaware, United States of America, registered with the Delaware Division of Corporations under file number 10487084, with a Registered Agent address at Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA, is committed to the radical protection of the privacy of its users ("User") and of their patients.
This Privacy Policy describes how we collect, use, process and delete your information when you use the Florence website, the Florence mobile app and Florence Web.
Its purpose is to set out the rules and principles governing the processing of data belonging to Users and to third parties — above all, patients (PHI) — so as to give full effect to Florence's "Privacy-First" philosophy.
We are not a data company. We are a tools company.
Versão Aplicável: Este texto em inglês foi escrito para usuários nos Estados Unidos e estabelece os compromissos da Florence de acordo com as leis dos Estados Unidos. Se você pratica medicina no Brasil, a versão brasileira estabelece sua relação com a Florence e seus deveres e direitos sob as leis brasileiras. Você pode trocar o idioma clicando no ícone no canto inferior direito da página. Ambas as versões descrevem os mesmos serviços, adaptadas às realidades de cada país.
BY CLICKING "I ACCEPT" WHEN CREATING YOUR ACCOUNT, OR BY USING THE PLATFORM, YOU REPRESENT THAT YOU ARE AT LEAST 18 YEARS OLD AND THAT YOU HAVE READ, UNDERSTOOD AND FULLY AGREED TO THESE PROVISIONS. IF YOU DO NOT AGREE, DO NOT USE THE PLATFORM.
1. KEY DEFINITIONS
For the purposes of this Policy, we use the vocabulary of HIPAA (45 C.F.R. Parts 160 and 164):
Platform: The Florence website (www.florence-app.com), the Florence mobile app, and Florence Web (app.florence-app.com).
User: The person using the Platform. Presumed to be a health care professional or a student in a health care field.
Account Data: The User's own information (email address, password, account identifier) necessary to access the service.
Personal Information: Any information relating to an identified or identifiable individual.
Protected Health Information (PHI): Individually identifiable health information, as defined at 45 C.F.R. § 160.103. For Florence, this covers patient audio, transcripts and clinical notes processed through the Platform.
Sensitive Information: Health information, genetic and biometric data, and information about children — categories that receive heightened protection under HIPAA and under state consumer health data laws.
Covered Entity: A health care provider, health plan or clearinghouse subject to HIPAA. **When you use Florence with your patients, you are the covered entity.**
Business Associate: A vendor that creates, receives, maintains or transmits PHI on a covered entity's behalf. Florence performs that function for you, and does so under a Business Associate Agreement where one has been executed. See Section 4.2.
Processing: Any operation performed on personal information: collection, generation, receipt, classification, use, access, reproduction, transmission, distribution, filing, storage, deletion, evaluation, transfer or extraction.
2. WHAT WE COLLECT (AND WHAT WE DO NOT KEEP)
2.1. Account Data (what we keep)
To deliver the service, manage subscriptions and authenticate you, we collect and store:
Note: We do NOT store card numbers, bank account numbers or any other payment credentials. That processing is handled entirely by Stripe, Inc.
We do NOT collect your Social Security Number, taxpayer identification number, or any government-issued identification number.
For this Account Data, Florence acts as the controller and you are the individual to whom it relates.
2.2. PHI and Sensitive Information (what we do NOT keep)
Acting as your Business Associate, Florence processes PHI only as follows:
Florence applies a Time-To-Live (TTL) mechanism to sessions, so that sessions are PERMANENTLY DELETED after a set period. A newly created session has a TTL of 60 minutes, renewed while it remains active; a session whose Results have been delivered has a fixed TTL of 60 minutes. Disconnecting or ending the session (by starting a new one) deletes the old session immediately, regardless of the TTL.
For "abandoned" sessions — for example, where the User lost connectivity and could not recover the session — a 24-hour TTL applies, enforced at the database level.
Once a session is deleted, the data it held cannot be recovered by anyone: not by the User, and not by Florence App, LLC or its contractors and service providers.
Florence App, LLC does NOT use audio, transcripts or clinical data to train, calibrate or improve its artificial intelligence models.
As between you and your patient, the processing of that patient's information is your responsibility as the covered entity.
3. HOW WE SHARE DATA
Florence does not sell, rent or trade your data. We do not sell or share personal information, and we do not process it for cross-context behavioral advertising or targeted advertising. Sharing occurs only with essential infrastructure providers ("subprocessors"), under confidentiality agreements:
Service Providers and Vendors: To deliver certain Platform features, including the software and other technology necessary to provide the service;
Authorities: Government bodies, including regulators, in response to lawful process or for oversight of our compliance with legal obligations.
4. WHERE YOUR DATA IS PROCESSED
4.1. Server Location
Your data is processed on servers located in the United States. For users in the United States, no international transfer of your data takes place.
4.2. HIPAA and Business Associate Agreements
Florence App, LLC is not a HIPAA covered entity. When you use the Platform with your patients, you are the covered entity and Florence performs a business associate function for you.
HIPAA requires a written Business Associate Agreement (BAA) before a vendor may create, receive, maintain or transmit PHI on a covered entity's behalf (45 C.F.R. §§ 164.308(b) and 164.502(e)). If you have not executed a BAA with Florence, do not use the Platform to process PHI. A BAA is available under the Enterprise plan and on request: business@florence-app.com.
Where a BAA is in place, Florence's subprocessors are bound by downstream agreements as required by 45 C.F.R. § 164.308(b)(2).
4.3. Safeguards
Independently of any BAA, three safeguards apply to all data:
(a) Contractual Terms: Our agreements with subprocessors include terms requiring a level of protection equivalent to our own commitments.
(b) Infrastructure Security: Our infrastructure providers operate under HIPAA-aligned security requirements.
(c) Zero Retention Architecture: PHI is deleted automatically, which minimizes the exposure that any of the above has to cover.
4.4. Users Outside the United States
If you practice in Brazil, your data is transferred internationally to the United States, and that transfer is governed by the LGPD. The mechanisms relied on are described in the Portuguese version of this Policy.
5. HOW LONG WE KEEP DATA
After these periods, data is permanently deleted, unless a legal obligation requires longer retention.
6. YOUR RIGHTS
Where Florence acts as controller of your Account Data, we extend the following rights to every User, regardless of where you practice:
(a) Confirmation: The right to know whether we process your data.
(b) Access: The right to access the personal information we hold about you.
(c) Correction: The right to correct incomplete, inaccurate or outdated data.
(d) Deletion: The right to request deletion of data that is unnecessary, excessive or processed improperly.
(e) Portability: The right to receive your data in a structured, commonly used format.
(f) Withdrawal of Consent: The right to withdraw consent at any time, where processing rests on consent.
(g) Information about Sharing: The right to know with whom we share your data.
(h) Non-Discrimination: We will not degrade your service or charge you differently because you exercised any of these rights.
A note on why we offer these voluntarily. Florence does not currently meet the applicability thresholds of the California Consumer Privacy Act (CCPA/CPRA) or of comparable state privacy statutes — we are below their revenue and volume thresholds, and we do not sell or share personal information. We extend these rights to all Users anyway, because the alternative would be to give you fewer rights than we think you should have.
Complaints. You may complain to the U.S. Federal Trade Commission, to your State Attorney General, and — where a BAA is in place and the complaint concerns PHI — to the U.S. Department of Health and Human Services, Office for Civil Rights.
6.1. Exercising Your Rights
Write to dpo@florence-app.com.
We respond within 15 (fifteen) days. We hold ourselves to that deadline deliberately: it is half the 30 days HIPAA allows a covered entity to act on a patient's access request under 45 C.F.R. § 164.524.
6.2. Your Patients' Rights
Your patients' HIPAA rights — access, amendment, an accounting of disclosures — run against you, as the covered entity, not against Florence. Because of Zero Retention, Florence will in almost every case hold nothing responsive to such a request. This is why Section 1.1(c) of the Terms of Use makes copying the note into your own record your responsibility.
6.3. A Note on Ephemeral Data
Important: Because of our "Zero Retention" architecture, PHI (audio and transcripts) is deleted automatically once the User ends the session or once 60 (sixty) minutes have passed since results were generated, whichever comes first. After that automatic deletion, rights of access, correction or portability can no longer be exercised over that data — by anyone, including us.
6.4. Deleting Your Account
You can delete your Florence account and all associated data:
(a) In the app (recommended — immediate): open the Florence app and go to Profile → Delete Account. You will be asked to type a confirmation. Deletion is immediate and permanent.
(b) By email: send a request to dpo@florence-app.com from the email address registered on the account. We respond within 15 (fifteen) days.
What is deleted: all remaining sessions and PHI, your templates and settings, and your authentication identity. We retain only an anonymized record — an irreversible hash of your email address, with no name and no health data — to prevent refund fraud.
Before deleting: if you have an active paid subscription, cancel it first in the app. That way the refund policy is applied and nothing owed to you is lost.
7. YOUR OBLIGATIONS
As the individual whose Account Data we hold, you must:
(a) Provide truthful and current information;
(b) Take security measures to protect your Platform credentials, which must not be shared with anyone.
As the covered entity responsible for your patients' information, you must:
(c) Take security measures to protect the confidentiality and integrity of your patients' health information, including — but not limited to — not sharing the Session identifier or the pairing code with third parties;
(d) Respect the deadlines imposed by the Platform's TTL mechanisms, so that patient data is processed properly and retention time is minimized.
Florence is not responsible for breaches of privacy or data protection that result from your failure to observe these obligations.
8. INFORMATION SECURITY
Florence applies the following safeguards:
Encryption in Transit: All data travels over TLS 1.3 (Transport Layer Security).
Encryption at Rest: Temporary data is stored on encrypted disks (AES-256).
Zero Access: No Florence employee has the technical ability to listen to your audio or read your transcripts, unless you explicitly share it with us for technical support — which we do not recommend.
9. SECURITY INCIDENTS (DATA BREACH)
9.1. Internal Procedure
If a security incident occurs that could create a risk of harm, Florence will:
(a) Immediately investigate the nature and extent of the incident;
(b) Contain and mitigate the harm;
(c) Document the incident.
9.2. Notification
(a) Where a BAA is in place: Florence will notify you, as the covered entity, without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI, as required by 45 C.F.R. § 164.410. You then run your own notifications to affected individuals and to HHS. Discovery means the point at which we knew, or reasonably should have known, of the breach.
(b) Where HIPAA does not apply: the FTC Health Breach Notification Rule (16 C.F.R. Part 318) and state breach notification statutes may require notice to affected individuals, to the Federal Trade Commission and, in some cases, to the media. Florence will comply with whichever applies.
(c) Users in Brazil: notification to the Autoridade Nacional de Proteção de Dados (ANPD) is described in the Portuguese version of this Policy.
10. COOKIES AND STORAGE TECHNOLOGIES
10.1. Website (florence-app.com)
The Florence website uses local storage (cache and local storage, on your own device) to:
Remember your language preference
Load website data faster.
The Florence website does not use cookies.
Our traffic figures are inferred from our hosting provider's server logs and from Google's own search reporting, which tells us how often the site appeared in search results and how it is indexed. Neither source uses cookies, and neither stores anything on your device.
This website does not process Account Data or PHI.
10.2. Web App (app.florence-app.com)
The Web App uses local storage technologies (cache and local storage) for:
Authentication and user session
Caching note templates for performance
The active session and its temporary data (subject to the TTL policy)
The Web App uses no tracking or advertising cookies.
10.3. Mobile App (Florence App)
The mobile app stores locally (in your device):
Note templates and user preferences
Session cache (temporary data)
10.4. No Advertising
None of our platforms uses targeted advertising cookies or shares browsing data with third-party advertisers.
11. CHILDREN'S PRIVACY
11.1. Platform Users
The Florence Platform is intended exclusively for health care professionals aged 18 or over who hold a current license to practice, and for students enrolled in an accredited health care program.
We do not knowingly collect information directly from children, and the Platform is not directed to children.
11.2. Data About Pediatric Patients
We recognize that health care professionals — pediatricians among others — may use the Platform to document consultations with minor patients.
In those cases, processing follows the same "Zero Retention" architecture that applies to every patient. Florence performs a business associate function and you remain the covered entity responsible for your patients' information.
11.3. Contact
If you are a parent or guardian and believe a child's information has been processed improperly, contact dpo@florence-app.com.
NOTE: Because of the "Zero Retention" architecture and Zero Access, Florence cannot confirm whether a particular child's information was processed. That determination is beyond our technical ability to audit — which is a direct consequence of building the system so that we cannot see your data.
12. CHANGES TO THIS POLICY
We may update this Policy to reflect security improvements or legal changes. We will notify you of material changes by email to your registered address, or by notice in the Platform (mobile app notifications), at least 30 (thirty) days in advance.
13. CONTACT AND PRIVACY OFFICER
To exercise your rights or ask about our privacy architecture, contact:
Florence App, LLC
Attn: Privacy Officer
Email: dpo@florence-app.com
13.1. Privacy Officer
Name: Giovanni Araujo Bacochina
Email: dpo@florence-app.com
The Privacy Officer is responsible for:
Receiving complaints and requests from individuals;
Receiving communications from regulators and acting on them;
Advising the team on data protection practices.
Florence App, LLC — Save Time, Save Lives