MedTech Compass Privacy Policy
For Business and Professional Use
MedTech Compass by CAHIR Solutions (Cahir AI LLC) · Effective September 26, 2026
1. Scope
This Privacy Policy explains how Cahir AI LLC, doing business as CAHIR Solutions ("CAHIR", "we", "us"), collects, uses, discloses, retains, and protects personal information in connection with the MedTech Compass platform (the "Service"). It forms part of our Subscription Terms of Service.
MedTech Compass is a business and professional service. The personal information we handle is largely business-contact and account-administration information rather than consumer or patient information.
2. Information we collect
Account and contact information: name, work email address, organization name, job title, account role, and approval status.
Billing information: plan, billing frequency, billing contact, transaction records, invoice history, and tax status. Full payment card numbers are collected and stored by our payment processor, not by CAHIR.
Content you submit: device descriptions, market and regulatory questions, uploaded evidence documents, saved views, weighting preferences, and exported reports.
Usage and technical information: pages and dashboards viewed, analyses run, exports generated, timestamps, IP address, browser and device type, and error logs.
Cookies and local storage: session cookies required for sign-in and security, and local storage used to remember display preferences such as light or dark mode.
3. How we use information
To provide, secure, and operate the Service, including authentication, access approval, seat management, and organization-scoped data isolation.
To process payments, issue receipts and invoices, manage renewals and cancellations, and meet tax and accounting obligations.
To generate analyses, scores, evidence citations, and reports you request, including through automated and AI-enabled processing.
To provide support, communicate service and billing notices, and respond to your questions.
To monitor reliability, detect abuse or fraud, enforce fair-use limits, and improve accuracy, coverage, and performance of the model and its evidence sources.
We do not sell personal information, and we do not use your submitted content to train models for other customers without your written agreement.
4. Legal bases
Where the GDPR or UK GDPR applies, we process personal information to perform our contract with you, to comply with legal obligations, and for our legitimate interests in operating, securing, and improving a business service. Where consent is required, we obtain it and you may withdraw it at any time.
5. Disclosure and processors
We share personal information with service providers acting on our behalf under contract: our cloud and database hosting provider, our payment processor, our email delivery provider, our error and performance monitoring provider, and the AI model providers used to generate analysis outputs.
We may disclose information to comply with law, enforce our agreements, protect rights and safety, or in connection with a merger, acquisition, or sale of assets. We do not disclose customer content to other customers.
6. International transfers
Our infrastructure and service providers may process information in the United States and other countries. Where required, we rely on appropriate transfer safeguards such as the European Commission's standard contractual clauses.
7. Retention
Account and content data are retained for the life of the account and for up to 12 months after termination unless you ask us to delete it sooner. Billing and tax records are retained for the period required by law, typically seven years. Security and audit logs are retained for up to 24 months.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, to portability, and to withdraw consent. Residents of California, Colorado, Connecticut, Virginia, and similar jurisdictions may also have rights to opt out of sale or sharing and to appeal a refused request. We do not sell or share personal information for cross-context behavioural advertising.
To exercise a right, email medtech@cahir.ai from the address associated with your account. We respond within the period required by applicable law and will not discriminate against you for exercising a right.
9. Sensitive and regulated data
Do not submit protected health information, patient-identifiable information, sensitive personal information, controlled technical data, or other highly sensitive information unless CAHIR has expressly agreed in writing to support that information. MedTech Compass is not offered as a HIPAA business-associate service.
10. Children
The Service is not directed to children and we do not knowingly collect personal information from anyone under 18.
11. Security and contact
Our technical and organizational safeguards are described in our Security Overview, including row-level data isolation, encryption in transit and at rest, approval-gated access, and PCI-DSS payment processing.
Questions, requests, or complaints about privacy can be sent to medtech@cahir.ai. We will update this policy as the Service evolves and will note the effective date above.
© 2026 CAHIR Solutions (Cahir AI LLC).