Privacy Policy

Effective date: July 15, 2026

Pasena, Inc. (“Pasena,” “we,” “us,” or “our”) provides an AI-powered software-as-a-service platform (the “Service”) that helps health plans and their delegated entities maintain auditing and compliance standards. This Privacy Policy describes how we collect, use, disclose, and protect personal information in connection with the Service and our public website at pasena.ai (together, the “Offerings”).

The Service is a business-to-business product. It is made available to organizations (our “Customers”) — typically health insurance companies and, where authorized, their delegated entities such as provider organizations — and is used by individuals whom those organizations authorize (“Authorized Users”). We intentionally collect only the minimum personal information needed to operate the Service.

1. Our Roles: Controller and Processor

For the limited account information of Authorized Users described in this policy (such as your name, business email address, and usage data), Pasena acts as a data controller (or “business” under U.S. state privacy laws) and this Privacy Policy applies.

For any data that our Customers submit to or process within the Service in the course of using it (“Customer Data”), Pasena acts solely as a data processor (or “service provider”) on the Customer’s behalf. We process Customer Data only in accordance with our agreements with the Customer and the Customer’s documented instructions, and this Privacy Policy does not govern that processing. To the extent Customer Data includes protected health information (“PHI”) subject to the Health Insurance Portability and Accountability Act (“HIPAA”), our handling of that information is governed by the applicable Business Associate Agreement or other written agreement with the Customer, not by this Privacy Policy.

If you are an Authorized User and have questions about how your employer or organization handles your information, please contact that organization directly.

2. Information We Collect

We collect a deliberately limited set of personal information:

  • Account information. Your name and business email address, provided by you or by your organization when your account is created. We do not ask for, and do not need, additional profile details to provide the Service.
  • Authentication data. Sign-in to the Service is handled by our identity provider, Auth0 (an Okta company). Auth0 processes your login credentials and related authentication events (such as sign-in timestamps and IP addresses) on our behalf. Pasena does not store your password.
  • Usage and device data. When you use the Offerings, our servers and service providers automatically receive the standard technical information your browser sends with every request, such as your IP address, browser type and version (user agent), device and operating system information, referring pages, and the pages and features you interact with. This information is processed by our hosting infrastructure (Amazon Web Services), our network and security provider (Cloudflare), and Datadog, which we use for logging, performance metrics, and real user monitoring (RUM). Our application logs are configured to strip personal information before storage; however, RUM and infrastructure-level access records may capture your IP address and, in some cases, your display name.
  • Communications. If you contact us (for example, for support), we collect the contents of that communication and your contact details.

We do not collect sensitive personal information about Authorized Users (such as government identifiers, financial account numbers, health information about you, or precise geolocation), and we do not purchase or otherwise obtain personal information about you from data brokers or other third-party sources.

3. How We Use Personal Information

We use the personal information described above only to:

  • Provide, operate, and maintain the Service, including authenticating you and personalizing your experience (for example, displaying your name in the application);
  • Send transactional, service-related emails, such as event notifications, account notices, and security alerts;
  • Monitor, secure, and troubleshoot the Offerings, including detecting, investigating, and preventing unauthorized access, fraud, or abuse;
  • Maintain audit trails and meet our legal, regulatory, and contractual obligations, including obligations to our Customers; and
  • Respond to your inquiries and support requests.

We do not use your personal information for marketing or advertising purposes. We do not sell personal information, we do not share it for cross-context behavioral or targeted advertising, and we do not use it to train advertising or profiling models. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

4. How We Share Personal Information

We share personal information only in the following limited circumstances:

  • Sub-processors and service providers. We use a small number of vetted vendors to operate the Service, as described in Section 5. Each is bound by contractual obligations to protect personal information and to process it only for the purposes we specify.
  • Your organization. Because the Service is provided under an agreement with your employer or organization, we may share information about your account and use of the Service (such as access logs and account status) with that organization’s administrators.
  • Legal requirements. We may disclose personal information if required to do so by law, regulation, legal process, or enforceable governmental request, or where necessary to protect the rights, property, or safety of Pasena, our Customers, or others.
  • Business transfers. If Pasena is involved in a merger, acquisition, financing, or sale of all or part of its business, personal information may be transferred as part of that transaction, subject to the commitments in this policy.

We never sell, rent, or trade personal information, and we do not disclose it to third parties for their own marketing purposes.

5. Sub-processors

We use the following sub-processors to deliver the Service. Each processes personal information on our behalf, under written data protection terms, and only to the extent necessary for the purpose described:

Sub-processorPurposePersonal information processed
Auth0 (Okta, Inc.)Identity and access management (authentication and single sign-on)Name, email address, credentials, authentication event data (including IP address)
Datadog, Inc.Logging, performance metrics, and real user monitoringUsage and device data; RUM data may include IP address and display name (application logs are stripped of personal information)
Cloudflare, Inc.Content delivery, DNS, and network security (including protection against denial-of-service attacks)IP address and standard request metadata sent by your browser (such as user agent and requested URLs)
Amazon Web Services, Inc. (AWS)Cloud hosting and infrastructureAll Service data at rest and in transit; access records including IP address

We evaluate the security and privacy practices of each sub-processor before engagement and periodically thereafter. We will update this list when we add or replace sub-processors.

6. Cookies and Similar Technologies

The Offerings use only the cookies and similar technologies necessary to operate and monitor the Service:

  • Strictly necessary cookies, including session and security cookies set by Auth0 to keep you signed in and protect your session, and security cookies that Cloudflare may set to distinguish legitimate traffic from malicious traffic; and
  • Performance and monitoring technologies set by Datadog RUM to measure application performance, errors, and reliability.

We do not use advertising, social media, or cross-site tracking cookies, and we do not respond to browser “Do Not Track” signals because we do not track users across third-party websites.

7. Data Security

We maintain an information security program with administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards are aligned with recognized industry frameworks, including the AICPA SOC 2 Trust Services Criteria, and include:

  • Encryption of data in transit (TLS) and at rest within our AWS environment;
  • Role-based access controls, least-privilege access, and multi-factor authentication for personnel access to production systems;
  • Centralized logging, monitoring, and alerting, with application logs stripped of personal information;
  • Vulnerability management, change management, and secure development practices;
  • Vendor risk assessments for sub-processors; and
  • A documented incident response process. If a security incident affects your personal information, we will notify affected Customers and individuals as required by applicable law and our contractual commitments.

No system can be guaranteed to be completely secure. If you have reason to believe your account or information is no longer secure, please contact us immediately using the details in Section 12.

8. Data Retention

We retain personal information only for as long as it is needed for the purposes described in this policy: for the duration of your organization’s use of the Service, and thereafter as necessary to comply with legal, audit, and contractual obligations, resolve disputes, and enforce agreements. Operational logs and monitoring data are retained for limited periods consistent with our security and compliance requirements. When personal information is no longer required, we delete or de-identify it. Customer Data is retained and deleted in accordance with our agreements with the applicable Customer.

9. Your Privacy Rights and Choices

Depending on where you live, you may have rights under applicable privacy laws with respect to your personal information. In particular, if you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), may give you the right to know what personal information we collect, use, and disclose about you; to access a copy of it; to correct inaccurate information; to delete it; and to not receive discriminatory treatment for exercising these rights. Because we do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes requiring a right to limit, there is nothing to opt out of.

To exercise these rights, contact us using the details in Section 12. We will verify your request using the email address associated with your account, and you may use an authorized agent to submit a request on your behalf where permitted by law. Because your account exists under an agreement with your employer or organization, we may need to refer some requests (for example, deletion of an active account) to that organization, or verify your request with them, before acting. We will not discriminate against you for exercising your rights.

You cannot opt out of transactional service emails (such as security notices and event notifications) while you hold an active account, because they are necessary to provide the Service. We do not send marketing emails.

10. Data Location

Pasena is based in the United States, and the Service is hosted in AWS data centers located in the United States. If you access the Offerings from outside the United States, your personal information will be transferred to and processed in the United States.

11. Children's Privacy

The Offerings are business tools intended for use by professionals and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will delete it.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, or wish to exercise your privacy rights, contact us at security@pasena.ai or by mail at:

Pasena, Inc.
1111 Broadway, Suite 300
Oakland, CA 94607
United States

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will update the effective date above and provide notice through the Service or by email. The current version of this policy will always be available on this page.