1. Introduction and scope
CAN Mobilities, Inc. ("CAN," "we," "us," or "our") is a Delaware corporation headquartered in Palo Alto, California. We build technology that supports care — including CareOS, our AI-powered healthcare operating platform; CAN Companion, our AI-supported care assistant; CAN Devices, our connected health hardware; CareOS Public Health; and our websites, mobile applications, web applications, and related professional and support services (collectively, the "Services").
This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information when you visit our websites, request a demo, subscribe to communications, use our applications and devices, or otherwise interact with the Services. It also explains the privacy rights available to you and how to exercise them.
This Policy does not apply to information practices of our customers (such as hospitals, health systems, insurers, government agencies, and care organizations, each a "Customer") or of third parties that we do not control. Where we process information on behalf of a Customer, that Customer's own privacy notices and agreements govern, as described in Section 2.
By using the Services, you acknowledge the practices described in this Policy. If you do not agree with this Policy, please do not use the Services.
2. Our roles: controller and business associate
CAN acts in two distinct roles, and your rights and our obligations differ depending on which applies:
- CAN as a controller (or "business"). When you visit can.co, request a demo, subscribe to our newsletter, apply for a job, or communicate with us directly, CAN determines how and why your personal information is processed. This Policy applies in full to those activities.
- CAN as a business associate or service provider. When a Customer deploys CareOS, CAN Companion, or CAN Devices to support the care of its patients, members, or populations, CAN processes information — including Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA") — on the Customer's behalf and under its instructions, pursuant to a Business Associate Agreement ("BAA") or equivalent data processing agreement. In that context, the Customer's notice of privacy practices governs, and requests concerning your health records should be directed to your provider, plan, or program in the first instance.
If you contact us about information we hold as a business associate or service provider, we will refer your request to the relevant Customer and support their response as required by our agreements and applicable law.
3. Information we collect
The information we collect depends on how you interact with the Services. Categories include:
- Identity and contact data — name, email address, phone number, postal address, employer, job title, and organization type (for example, when you request a demo or subscribe to updates).
- Account and authentication data — usernames, credentials, single sign-on identifiers, multi-factor authentication tokens, role and permission assignments, and access logs.
- Health and clinical data — when authorized by a Customer or by you, information such as medical history, conditions, diagnoses, medications, allergies, laboratory and imaging results, vital signs, care plans, appointment and encounter records, and communications with care teams. This data is typically PHI processed under a BAA.
- Device and sensor data — measurements and telemetry from CAN Devices (such as CAN Go) and from third-party connected devices you choose to link, including blood pressure, glucose, weight, heart rate, activity, gait, and location data where you enable location-based features (for example, fall detection or emergency response).
- AI interaction data — the content of your conversations with CAN Companion, prompts, responses, feedback you provide on AI outputs, and related metadata, handled as described in Section 6.
- Communications data — messages, emails, call recordings where permitted by law and disclosed to you, support tickets, and survey responses.
- Technical data — IP address, browser type and version, operating system, device identifiers, app version, language settings, crash reports, and diagnostic logs.
- Usage data — pages viewed, features used, time spent, referral sources, and interaction patterns within the Services.
- Inferences — risk scores, care-gap flags, adherence signals, and care-plan recommendations generated by the Services.
- Job applicant data — résumés, work history, references, and related information if you apply for a position with CAN.
4. Sources of information
We collect information:
- Directly from you, when you fill out forms, create an account, communicate with us, or use the Services.
- Automatically, through cookies, software development kits, server logs, and similar technologies, as described in our Cookie Notice.
- From Customers, who provision accounts, configure care programs, and transmit clinical and administrative data to the platform.
- From connected systems at your or a Customer's direction, including electronic health record systems, health information exchanges, payers, pharmacies, laboratories, and device platforms.
- From CAN Devices and linked third-party devices and wearables.
- From service providers and publicly available sources, such as analytics providers and business contact databases, in connection with our marketing and sales activities.
5. How we use information
We use personal information for the following purposes:
- To provide, operate, maintain, and secure the Services, including hosting, storage, synchronization across devices, and technical support.
- To deliver care-related functionality authorized by you or a Customer — care coordination, reminders, medication management, remote monitoring, alerts and escalations, education, navigation, and AI-assisted experiences.
- To personalize the Services, including remembering preferences and tailoring content and workflows to your role.
- To authenticate users, prevent fraud and abuse, enforce our terms, and protect the safety, rights, and property of CAN, our Customers, and users.
- To respond to inquiries, demo requests, and support tickets, and to administer newsletters and communications you request (you may unsubscribe at any time).
- To conduct product analytics, research, quality assurance, testing, and improvement of the Services, using de-identified or aggregated data wherever practicable.
- To comply with legal, regulatory, tax, accreditation, and audit obligations, and to establish, exercise, or defend legal claims.
- For any other purpose disclosed to you at the time of collection or with your consent.
We do not use PHI for advertising. We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under California law.
6. AI features and CAN Companion
CareOS and CAN Companion use large language models and other machine-learning techniques to assist clinicians, patients, families, and care teams — for example, summarizing records, drafting communications, answering questions, surfacing care gaps, and supporting navigation. We apply the following safeguards to AI processing:
- We use only models hosted or contracted under terms consistent with HIPAA, including BAAs with model providers where PHI is processed.
- Patient data is not used to train third-party foundation models.
- Model providers are contractually prohibited from retaining inputs or outputs beyond the inference window and from any secondary use of the data.
- PHI processed by AI features remains within U.S.-based environments unless a Customer agreement expressly provides otherwise.
- AI outputs presented in clinical contexts are designed to support — not replace — professional judgment, and material AI-generated content is labeled where required by law.
We may use de-identified data (as defined in Section 12) to evaluate, fine-tune, and improve our own models and safety systems.
7. How we share information
We disclose personal information only as necessary to operate the Services and as permitted or required by law:
- With the Customer that sponsors or authorizes your account, and with users the Customer designates (such as your care team).
- With family members, caregivers, and other individuals you invite or authorize within the Services.
- With service providers and sub-processors — such as cloud hosting, communications delivery, analytics, and customer support vendors — bound by written contracts that limit their use of the information to providing services to us and, where PHI is involved, by BAAs.
- With connected systems at your or a Customer's direction, including EHRs, payers, pharmacies, laboratories, and device platforms.
- With emergency services or designated contacts, where you have enabled safety features (such as fall detection or emergency response) that are designed to make such disclosures.
- With professional advisors, including lawyers, auditors, and insurers, under confidentiality obligations.
- In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to confidentiality protections and, where required, notice to you or the affected Customer.
- To comply with law — including responding to subpoenas, court orders, and lawful requests by public authorities — and to protect the rights, property, safety, and security of CAN, our users, our Customers, and the public.
We maintain a list of material sub-processors and make it available to Customers under their agreements.
8. HIPAA and protected health information
Where CAN processes PHI as a business associate, we do so in accordance with HIPAA, the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and our BAAs. Among other commitments, we:
- Use and disclose PHI only as permitted by the applicable BAA and as required by law.
- Implement administrative, physical, and technical safeguards that satisfy the HIPAA Security Rule.
- Report security incidents and breaches of unsecured PHI to the affected Customer without unreasonable delay and within the timeframes required by law and contract.
- Ensure that subcontractors handling PHI agree to equivalent restrictions through written agreements.
- Support Customers in fulfilling individual rights requests, including access, amendment, and accounting of disclosures.
- Return or destroy PHI at the end of the engagement where feasible, as directed by the Customer.
To exercise HIPAA rights with respect to your health records, contact your healthcare provider, health plan, or program administrator. You may also contact our HIPAA Privacy Officer at hipaa@can.co with questions about our practices.
9. Cookies and tracking technologies
We use strictly necessary cookies, preference cookies, and limited first-party analytics on our websites. We do not use cross-site advertising trackers or behavioral advertising cookies, and we honor Global Privacy Control (GPC) signals as a valid opt-out where required by law. For details, including how to manage cookies, please see our Cookie Notice at can.co/cookies.
10. Data retention
We retain personal information only as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law. Retention periods depend on:
- The nature and sensitivity of the information (clinical records are governed by Customer instructions, BAAs, and medical-records retention laws).
- The duration of your relationship or your Customer's relationship with CAN.
- Legal, regulatory, accreditation, tax, and audit obligations.
- The need to resolve disputes, enforce agreements, and maintain security and backup integrity.
When information is no longer needed, we delete it, de-identify it, or securely archive it and isolate it from further processing. PHI held as a business associate is returned or destroyed in accordance with the applicable BAA.
11. Security
CAN maintains a written information security program aligned with the HIPAA Security Rule, the NIST Cybersecurity Framework, and SOC 2 Type II controls. Our safeguards include:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256).
- Strong authentication, including single sign-on and multi-factor authentication, with role-based, least-privilege access controls.
- Network segmentation, continuous monitoring, logging, and alerting.
- Vulnerability management, secure software development practices, and regular third-party penetration testing.
- Personnel security measures, including background checks where permitted by law, confidentiality obligations, and security training.
- Documented incident response, disaster recovery, and business continuity plans.
No system is perfectly secure. If we determine that a breach affecting your personal information triggers a notification obligation, we will notify you and/or the affected Customer and regulators as required by applicable law. Please report suspected vulnerabilities or incidents to security@can.co.
12. De-identified and aggregated data
We may create de-identified data in accordance with applicable standards — including the HIPAA expert-determination or safe-harbor methods where the source data is PHI — and aggregated data that does not identify any individual. We may use and disclose de-identified and aggregated data for lawful purposes, including research, benchmarking, public health analytics, and improving the Services. We commit to maintaining such data in de-identified form and will not attempt to re-identify it, except as permitted by law to test the effectiveness of our de-identification processes, and we require the same commitment from recipients.
13. Your privacy rights
Depending on your state or country of residence, you may have some or all of the following rights with respect to personal information that CAN holds as a controller or business:
- To confirm whether we process your personal information and to access a copy in a portable and readily usable format.
- To correct inaccurate personal information.
- To delete personal information, subject to legal exceptions.
- To opt out of the sale or sharing of personal information and of targeted advertising (CAN does not sell or share personal information or engage in targeted advertising).
- To opt out of profiling in furtherance of decisions that produce legal or similarly significant effects, where applicable.
- To limit the use of sensitive personal information (we use sensitive information only for purposes permitted by law).
- To appeal a denial of a rights request.
- Not to receive discriminatory treatment for exercising your rights.
To exercise these rights, email privacy@can.co with the subject line "Privacy Rights Request," or write to the address in Section 19. We will verify your identity using reasonable means before acting on a request, and we will respond within the timeframe required by applicable law. You may designate an authorized agent to act on your behalf; we may require proof of the agent's authority.
If your request concerns health records processed on behalf of a Customer, we will refer you to that Customer, as described in Section 2.
14. California residents
This section supplements the rest of this Policy for California residents and applies to personal information governed by the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). Note that PHI governed by HIPAA and medical information governed by the California Confidentiality of Medical Information Act are exempt from the CCPA.
In the preceding 12 months, we have collected the categories of personal information described in Section 3, from the sources described in Section 4, for the purposes described in Section 5, and disclosed them for business purposes to the categories of recipients described in Section 7.
- We do not sell personal information and have not done so in the preceding 12 months.
- We do not share personal information for cross-context behavioral advertising.
- We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.
- We do not knowingly collect or sell the personal information of consumers under 16 years of age.
- We honor Global Privacy Control signals as a valid opt-out preference signal.
California residents may exercise the rights described in Section 13 by emailing privacy@can.co. California's "Shine the Light" law (Civil Code § 1798.83) permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes; CAN does not make such disclosures.
15. Washington and other state health privacy laws
Where CAN collects "consumer health data" as defined by the Washington My Health My Data Act, the Nevada consumer health data law, or similar state laws — outside the scope of HIPAA — we collect and share such data only with your consent or as necessary to provide services you request, we do not sell consumer health data, and you may exercise rights of access, withdrawal of consent, and deletion by contacting privacy@can.co. If a separate Consumer Health Data Privacy Notice applies to a specific product experience, it will be presented within that experience and will control to the extent of any conflict.
16. International users and data transfers
The Services are operated from the United States and are designed for use in the United States unless otherwise agreed with a Customer. If you access the Services from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your jurisdiction.
Where the EU or UK General Data Protection Regulation applies to processing under a Customer agreement, CAN processes personal data as a processor under a data processing agreement incorporating appropriate safeguards, including standard contractual clauses where required. For questions, contact our Data Protection Officer at dpo@can.co.
17. Children's privacy
Our websites and marketing services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 through them. Pediatric care programs deployed by Customers may involve the processing of minors' health information; in those cases, processing occurs on behalf of the Customer under the applicable BAA and with the consents required by law (including parental or guardian consent where applicable). If you believe a child has provided us personal information without appropriate consent, contact privacy@can.co and we will take appropriate steps to delete it.
18. Changes to this policy
We may update this Policy from time to time to reflect changes in our practices, technologies, or legal requirements. If we make material changes, we will notify you by posting the updated Policy on can.co with a new "Last updated" date and, where required by law, by providing additional notice (such as email or in-product notice). Your continued use of the Services after the effective date of an updated Policy constitutes your acknowledgment of the changes.
19. How to contact us
If you have questions, concerns, or complaints about this Policy or our privacy practices, or wish to exercise your rights, contact us:
- CAN Mobilities, Inc., Attn: Privacy Office, 530 Lytton Avenue, Palo Alto, CA 94301, United States.
- Privacy inquiries and rights requests: privacy@can.co.
- Data Protection Officer: dpo@can.co.
- HIPAA Privacy Officer: hipaa@can.co.
- Security reports: security@can.co.
- Trust and compliance: trust@can.co.
You also have the right to lodge a complaint with your state attorney general or, for HIPAA matters, with the U.S. Department of Health and Human Services, Office for Civil Rights.
