This policy covers information Fortify 24x7 holds about you as a customer. Protected health information that our services encounter while operating on your behalf is governed by the Business Associate Agreement between us, which imposes stricter obligations than any website policy. Where the two touch the same subject, the agreement governs.
01What we hold
| Account | Your name, email address, organization, and the contacts you nominate for escalation: the identifiers needed to provision services and to reach a person when something is wrong. |
|---|---|
| Billing | Subscription records and receipts. Stripe owns the card data end to end and none of it reaches our servers. Visible to us: the final four digits, and whether the charge succeeded. |
| Service metadata | Which devices, mailboxes, servers, tenants, and company files you protect, together with job status, detection history, patch state, and case records. |
| Protected health information | Where a service encounters it, inside a recovery set or a discovery finding for instance, it sits under AES-256 while stored and TLS while moving, on infrastructure that is not the infrastructure being protected. Your material, held on your behalf. Never a dataset of ours. |
| Site logs | Ordinary web server records: requesting address, time, and which page. Nothing that advertises or profiles. |
02What we do with it
Set the services up, run them, bill for them, support them. Raise the alarm when a job keeps failing, where something resembles a security problem, or where the account itself needs a decision from you. Meet our tax and legal duties. The list ends there. No personal information is sold, and nothing kept on your behalf is ever mined, sampled, resold, or fed to a model. It exists to be guarded and returned, and for nothing else.
03Who else touches it
A short list of processors, and no one else: Stripe for card handling; the security and backup platform vendors plus the cloud storage providers whose infrastructure carries the services; and a mail delivery provider carrying receipts, alerts, and access links. Every one of them works to our instructions, pursues no purpose of its own, and is held to written obligations, business associate obligations included wherever protected health information is involved. Should a subpoena or court order land, we give what the law genuinely compels and not a line more, and you hear about it from us unless we are forbidden to say so.
04How long we keep it
Protected material is retained on the schedule of the line you purchased, for example 28 days of file versions, seven years of Exchange mail, or unlimited history for directory configuration. After a subscription ends, that material is deleted in accordance with our vendors' deprovisioning schedules and the Business Associate Agreement. Account and billing records are kept for as long as tax and and accounting rules impose. Detection and case history stays long enough to serve as evidence of the review that generated it.
05Your rights
California residents, and people in a growing number of other jurisdictions, have statutory rights to inspect, correct, port, or delete the personal information a company keeps about them. Write from the address on your account and we will meet whichever of those rights reaches us. Note that rights of individual patients over their own health information run against your organization as the covered entity, not against us; where we hold that information as your business associate, we assist you in responding rather than responding directly. Deleting an account is not reversible, nor can removal of the protected copies inside it, so we always confirm first.
06Contact
Fortify 24x7 · support@medishieldit.com