Skip to content
Pre-publication draft. This Trust Center is prepared for peer review before public launch.

Privacy Policy

Legal · Bioscope Foundry, LLC (a Delaware limited liability company) · Effective date: June 23, 2026 · Last updated: June 23, 2026

Draft for legal review. Prepared from Bioscope Foundry’s public site and platform architecture. Not legal advice; review with qualified counsel before publication.
This Privacy Policy explains how Bioscope Foundry, LLC (“Foundry,” “we,” “us,” or “our”) collects, uses, and shares information through bioscopefoundry.com and the business and operational services we provide to physicians and their practices (together, the “Services”). It does not govern protected health information (PHI) that we handle on behalf of a physician practice. That information is governed by our Business Associate Agreement with the practice and described in our HIPAA Notice & Business Associate Statement.

Our two environments

Foundry operates two distinct environments with different privacy and security practices. Where it matters, this policy notes which environment applies.

Marketing site

bioscopefoundry.com: our public, informational website and application/waitlist. It uses cookies for site functionality and may use analytics. It does not process PHI. Do not submit patient information through public forms.

Operating platform

The authenticated tools we operate for member practices and their staff. This environment runs under enhanced safeguards, uses only the cookies needed for security and authentication, and may handle PHI solely as a business associate under a BAA.

1. Who we are

Bioscope Foundry is an AI-enabled management services organization (MSO) that helps independent U.S. physicians (MD/DO) start, operate, and grow their own practices. We provide an operating layer, communication and scheduling support, team coordination, protocols and knowledge management, identity and access administration, systems integration, and launch and growth infrastructure, with AI assistance woven throughout. Physicians retain 100% ownership of their practices.

2. Scope of this policy

This policy applies to information we collect from:

  • Visitors to our marketing site, including people who contact us or join our waitlist.
  • Applicants and prospective members: physicians who apply to or are evaluated for a founding cohort or membership.
  • Physician members and their staff who use the operating platform and administrative tools we operate on their behalf.

This policy does not cover:

  • Patient health information (PHI) and other “medical information.” When we create, receive, maintain, or transmit PHI on behalf of a physician practice, we act as a HIPAA business associate. That information is governed by the Business Associate Agreement (BAA) between Foundry and the practice and described in our HIPAA Notice. Patients should consult their practice’s own Notice of Privacy Practices for their rights regarding their health information. For California consumers: medical information governed by HIPAA and the California Confidentiality of Medical Information Act (CMIA) is expressly excluded from the California Consumer Privacy Act under Cal. Civ. Code § 1798.146(a)(2)–(3), so the California-specific disclosures in this policy do not apply to PHI we process as a business associate.
  • Third-party websites or services that we link to but do not control.

3. Notice at collection

At or before the point we ask you for personal information, including on our waitlist form, applicant intake forms, the voice-first onboarding interview consent screen, payment forms, and e-signature flows, we present a short notice that identifies (i) the categories of personal information and sensitive personal information we are collecting at that moment, (ii) the business or commercial purposes for which it will be used, (iii) whether the information is sold or shared (it is not), and (iv) the retention period or the criteria used to determine it. That at-collection notice links back to this Privacy Policy for the full disclosures required by Cal. Civ. Code § 1798.100(b) and the CCPA regulations. The categories, sources, purposes, recipients, and retention periods that apply to each touchpoint are enumerated in the tables in §§4 and 11 below.

4. Information we collect

The table below maps the personal information we collect from visitors, applicants, members, and practice staff to the categories enumerated in Cal. Civ. Code § 1798.140(v), and identifies the sources, business purposes, categories of recipients, and retention period for each. It covers the prior 12 months and our current practices.

CCPA category (§ 1798.140(v))Examples Foundry collectsSourcesBusiness purposeCategories of recipientsRetention
A. IdentifiersLegal name, email address, postal address, phone number, IP address, account identifiers, National Provider Identifier (NPI), Employer Identification Number (EIN) of the practice entity, doctor’s date of birth.Directly from you (waitlist, application, onboarding); from CRM/pipeline tools when you are referred; from professional-credential verification sources.Evaluate applications; verify professional eligibility; provision accounts, domains, and email; administer agreements; communicate with you; security and fraud prevention; legal compliance.Service providers (hosting, email, CRM, identity/credential verification, registered-agent, workspace provisioning, e-signature); legal/regulatory recipients when required.Active account + 7 years after closure (or the period required by applicable tax, corporate, or HIPAA recordkeeping rules, whichever is longer).
B. Customer records / commercial information (§ 1798.140(v)(1)(B), (D))Practice name, specialty, planned or existing business details, agreements and signed contracts, payment-method tokens and transaction references (we do not store full card numbers), invoice and billing history.Directly from you; from our payment processor and e-signature provider.Provide, operate, and bill for the Services; administer agreements; maintain audit trails; tax and accounting compliance.Payment processor; e-signature provider; accounting and tax service providers; banking partner.7 years from the close of the calendar year of the transaction (tax/business records); contracts retained for the longer of contract term + 7 years.
C. Internet or other electronic network activity (§ 1798.140(v)(1)(F))IP address, browser and device type, pages viewed, referring URLs, session timing, interactions with the marketing site, authentication and audit-log events on the operating platform.Automatically from your browser/device when you visit the marketing site or use the operating platform; from analytics and security tooling.Operate and secure the Services; understand site usage; detect and prevent fraud, abuse, and security incidents.Hosting provider (Cloudflare); analytics provider (being finalized); security/logging provider.Marketing-site analytics: up to 14 months. Platform audit/security logs: at least 6 years (HIPAA-aligned).
D. Geolocation data (§ 1798.140(v)(1)(G))Approximate (city/region-level) location inferred from IP address for security and fraud-prevention purposes. We do not intentionally collect precise geolocation (within 1,850 feet).Automatically from your IP address.Security, fraud prevention, login anomaly detection, regional service routing.Hosting provider; security tooling.90 days for fraud/security signals; longer where embedded in a retained audit log.
E. Audio, electronic, visual, or similar information (§ 1798.140(v)(1)(H))Voice recordings of the onboarding interview, generated transcripts and structured fields derived from those responses, and any voice/video submitted to support.Directly from you, with notice and consent obtained before recording begins.Conduct the onboarding interview; generate a practice launch plan; evaluate fit for membership; train internal reviewers; quality assurance.Voice-AI provider under contract; internal reviewers; e-signature/CRM where the transcript is attached to an application.Raw audio: 24 months after the interview, then deleted (extracted transcripts and structured fields retained for the life of the application/membership).
F. Professional or employment-related information (§ 1798.140(v)(1)(I))Medical license number and state, NPI, specialty, board certifications, training/credential history, current and prior practice affiliations, professional references.Directly from you; from credential-verification sources (e.g., state medical-board lookups, NPPES); from references you authorize us to contact.Verify eligibility for membership; perform compliance and quality-of-care diligence; provision regulated accounts that require NPI.Credential-verification providers; e-signature/CRM; legal/regulatory recipients on request.Life of the application or membership + 7 years.
G. Inferences drawn from the above (§ 1798.140(v)(1)(K))Internal scores, tags, and summaries derived from your application materials and interview (e.g., readiness indicators, launch-timeline categorizations, internal fit notes).Generated by Foundry from the categories above; AI-assisted draft outputs reviewed by humans before any material decision.Evaluate applications; tailor onboarding; internal analytics. Inferences are not used for advertising and are not sold or shared.Internal personnel only; the underlying inputs may reach the recipients listed elsewhere in this table.Life of the application or membership; deleted on request unless retention is required by law.

We do not knowingly collect personal information from minors (see §15). We do not collect biometric identifiers within the meaning of § 1798.140(v)(1)(E) for identification purposes; voice audio collected during onboarding is treated as Sensitive Personal Information (see §5).

Information from third parties

We receive information from our customer-relationship and pipeline tools when a physician is referred or progresses through evaluation, and from identity- and credential-verification sources (including state medical-board lookups and the NPPES NPI registry) used to confirm professional eligibility.

5. Sensitive Personal Information

Under Cal. Civ. Code § 1798.140(ae) and § 1798.121, specified categories of personal information are designated Sensitive Personal Information (“SPI”). The SPI Foundry collects, and the purpose for each, is:

  • Account log-in credentials in combination with any password, security question, or access code that would permit access to an account, collected only to authenticate you to the operating platform; secrets are stored hashed or in managed secret stores, never in plain text.
  • National Provider Identifier (NPI): treated as a professional identifier used to verify physician eligibility and to provision regulated accounts that require it.
  • Payment-method tokens (financial account information), collected via our payment processor to bill for the Services. Foundry does not store full card numbers.
  • Voice recordings made during the onboarding interview, audio data is processed only to conduct the interview, generate transcripts, and inform membership decisions. Recordings are not used for biometric identification.
  • Precise geolocation, if and only if we ever collect it (see §4(D)). We currently do not, and would update this section before doing so.

Foundry uses Sensitive Personal Information only for the purposes permitted by Cal. Civ. Code § 1798.121(b) and 11 CCR § 7027: namely: performing the services you have requested; preventing, detecting, and investigating security incidents; resisting malicious, deceptive, fraudulent, or illegal actions and prosecuting those responsible; ensuring the physical safety of individuals; short-term, transient processing (such as non-personalized advertising shown as part of your current interaction); performing services on behalf of the business (such as account servicing); verifying or maintaining the quality of services; and the limited internal uses to build or improve our offering that the regulation permits. We do not use SPI to infer characteristics about you. See §13 for your right to limit our use of SPI.

6. How we use information

We use the information above to:

  • Respond to inquiries, manage the waitlist, and evaluate applications;
  • Provide, operate, maintain, and improve the Services;
  • Conduct onboarding interviews and generate practice launch plans;
  • Provision accounts, domains, email, and related infrastructure;
  • Process payments and administer agreements;
  • Communicate with you about your application, account, and service updates;
  • Maintain security, prevent fraud and abuse, and keep audit trails; and
  • Comply with legal, regulatory, and contractual obligations.

We rely on your consent (for example, before recording an interview), the performance of our agreement with you, our legitimate business interests, and our legal obligations as the bases for these uses.

7. AI-assisted processing & automated decision-making

AI assistance is part of how the Services operate. Our onboarding interview uses a third-party generative-AI voice model to conduct the conversation and to help extract structured information from your responses, AI assistance supports back-office workflows, and our internal “Beacon Layer” surfaces de-identified, sanitized insights to physicians. AI outputs are intended to augment, not replace, human judgment.

Automated decision-making technology notice (Cal. Code Regs. tit. 11 §§ 7220–7222). Foundry uses automated decision-making technology (“ADMT”) to assist with:

  • AI-assisted onboarding interviews: a voice-AI agent conducts a structured conversation and extracts fields and themes from your responses;
  • AI-assisted membership and compliance evaluations: internal drafts of fit, readiness, and risk indicators are prepared by AI and presented to a human reviewer; and
  • Beacon Layer insight generation: sanitized, identifier-stripped operational signals are summarized for physicians’ own decision-making.

Logic and intended outcomes. The systems use general-purpose large language and speech models prompted to (i) elicit and structure factual information you provide, (ii) compare your application materials against documented eligibility and quality criteria, and (iii) draft summaries for human review. They do not make final decisions about acceptance, denial, pricing, or termination on their own; a qualified Foundry team member reviews and is responsible for any material decision before it takes effect.

Your rights. You may (a) request a plain-language explanation of how ADMT was used in a decision that significantly affects you, (b) ask that a human reconsider the decision, and (c) where the regulations require, opt out of the ADMT use. Submit requests to privacy@bioscopefoundry.com; we will respond within the time required by applicable law.

Any AI processing of PHI occurs only through HIPAA-eligible services covered by a Business Associate Agreement. We may use de-identified or aggregated data (which cannot reasonably identify you) to improve our services, as permitted by law. Our program aligns with recognized AI-management and information-security standards (including ISO/IEC 42001 and ISO/IEC 27001); references to these standards describe our program structure.

8. How we share information

We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined in Cal. Civ. Code § 1798.140(ad) and (ah). We disclose personal information only as described here:

  • Service providers and contractors processing information on our behalf under written contracts that restrict their use to the disclosed business purposes (see §9). Categories include hosting and infrastructure; email/communications; CRM and pipeline tools; payment processing; e-signature; identity and credential verification; voice-AI for onboarding interviews; registered-agent and entity-formation; workspace provisioning; security, audit, and observability tooling; legal, accounting, and professional advisors.
  • With your direction: for example, with providers we engage to stand up your practice.
  • Legal and safety: to comply with law, subpoena, or legal process; to enforce our agreements; or to protect the rights, safety, and property of Foundry, our members, or others.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, where we will seek assurances that the recipient honors this policy.

9. Service providers

We rely on a limited set of vetted service providers to host data, deliver email, process payments, and otherwise operate the Services, and we impose contractual limits on their use of information they process on our behalf. The current list is maintained at our Subprocessors page. Where any service provider may create, receive, maintain, or transmit PHI, we enter into a Business Associate Agreement requiring HIPAA-compliant protections before any PHI is shared.

10. Cookies & analytics

Cookie use differs by environment:

  • Marketing site (bioscopefoundry.com). We use cookies and similar technologies to operate the site, remember preferences, and understand usage, and we may use analytics.
  • Operating platform. We use only the cookies strictly necessary for security and authentication, and we do not use analytics or marketing tracking there.

You can control cookies through your browser settings; disabling some cookies may affect site functionality. See our Cookie Policy for the cookie inventory, durations, and how we honor opt-out preference signals such as Global Privacy Control.

11. Data retention

We retain each category of personal information for the period set out below, or for as long as needed to provide the Services, operate our business, and meet legal, tax, and regulatory obligations, whichever is longer, after which we delete or de-identify it. Retention is determined by reference to (a) the duration of our relationship with you and any contractual obligations, (b) statutory and regulatory recordkeeping requirements (including HIPAA’s six-year minimum for required documentation and seven-year tax recordkeeping), (c) the limitations period for legal claims, and (d) the operational need to maintain security and audit trails.

CategoryRetention periodCriteria
Waitlist and inquiry data (visitors)24 months from last contact, then deleted.Operational need; deletes earlier on request.
Application materials (non-accepted applicants)24 months from final disposition.Defense of decisions; civil-rights limitations periods.
Member account data (identifiers, customer records, professional information)Life of the membership + 7 years.Contract performance; tax/business recordkeeping.
Voice interview audio24 months after the interview, then deleted; extracted transcripts and structured fields retained as application/membership records above.Minimization of audio retention; preserve the structured outputs that informed any decision.
Payment-method tokens and transaction records7 years from the calendar year of the transaction.Tax and financial recordkeeping.
Marketing-site analyticsUp to 14 months.Provider default; reduced where the provider supports it.
Security, access, and audit logs (operating platform)At least 6 years.HIPAA § 164.316(b)(2); incident-response needs.
Cookies (per-cookie durations)See Cookie Policy.Functional/preference/security needs.
Records associated with PHI (governed by HIPAA, not this policy)Per the BAA; HIPAA-required documentation retained for at least 6 years from creation or last effective date.HIPAA § 164.316(b)(2).

12. How we protect information

We maintain administrative, physical, and technical safeguards designed to protect information, including:

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or customer-managed keys);
  • Passwordless authentication and role-based, least-privilege access controls;
  • Audit logging and monitoring of access to sensitive systems;
  • Network isolation and managed secret storage for credentials; and
  • Backup, continuity, and recovery practices.

No system is perfectly secure; we work to keep our safeguards current and review them as the business changes.

13. Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, and receive a portable copy of your personal information, to opt out of processing activities covered by applicable law, and to be free from discrimination for exercising these rights. We respond within the time required by applicable law (generally 45 days for CCPA, extendable by 45 days with notice). To make a request, contact privacy@bioscopefoundry.com; we will verify your identity before responding and will explain any denial in writing. If we deny a request, you may appeal by replying to our response.

Because Foundry acts as a service provider/business associate for PHI, requests about patient health information are directed to the relevant physician practice. If you believe we have processed your information unlawfully, you may also contact the attorney general of your state of residence.

14. California consumers

California residents receive the following disclosures required under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”), and the implementing regulations (11 CCR §§ 7000 et seq.). It supplements, and where it conflicts, controls over, the rest of this policy for California consumers. PHI that we process as a HIPAA business associate is excluded from the CCPA under Cal. Civ. Code § 1798.146 and is governed by the BAA and our HIPAA Notice instead.

14.1 Your California rights

  • Right to know (Cal. Civ. Code §§ 1798.110, 1798.115). You have the right to request, twice per 12-month period, that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting or sharing it, and the categories of third parties to whom we have disclosed it. The categorical disclosures appear in §4 above; for specific pieces, submit a verifiable request to privacy@bioscopefoundry.com.
  • Right to delete (§ 1798.105). You may request that we delete personal information we collected from you, subject to the statutory exceptions (for example, to complete a transaction, detect security incidents, comply with legal obligations, or for internal uses reasonably aligned with your expectations).
  • Right to correct (§ 1798.106). You may request that we correct inaccurate personal information we maintain about you. We will use commercially reasonable efforts to correct verified inaccuracies, taking into account the nature of the information and the purposes for which we use it.
  • Right to data portability (§ 1798.130(a)(3)). When you exercise your right to know, you may receive your personal information in a structured, commonly used, and machine-readable format that allows you to transmit it to another entity without hindrance, typically JSON or CSV.
  • Right to opt out of sale or sharing (§ 1798.120). Foundry does not sell personal information and does not share it for cross-context behavioral advertising. No “Do Not Sell or Share My Personal Information” link is therefore required by § 1798.135(b)(1). If at any time we change this practice, we will update this policy and post the required opt-out link before any sale or sharing begins. We honor browser-based Global Privacy Control (GPC) signals as a valid consumer request to opt out of sale or sharing per 11 CCR § 7025, even though we have determined we do not sell or share.
  • Right to limit use and disclosure of Sensitive Personal Information (§ 1798.121). You may direct us to use the Sensitive Personal Information listed in §5 only for the purposes permitted by § 1798.121(b) and 11 CCR § 7027. Because we already restrict our use of SPI to those permitted purposes, no separate “Limit the Use of My Sensitive Personal Information” link is required by § 1798.135(a)(2); if our practices change, we will post one before expanding our use of SPI.
  • Right to non-discrimination (§ 1798.125). We will not deny goods or services, charge different prices or rates, provide a different level or quality of service, or retaliate against you for exercising any of these rights. Foundry does not operate financial-incentive or loyalty programs that would require additional disclosures under § 1798.125(b).
  • Right regarding automated decision-making (Cal. Code Regs. tit. 11 §§ 7220–7222). See §7 above for our ADMT disclosure and how to exercise the access and opt-out rights it provides.
  • Right of consumers under 16 to opt in (§ 1798.120(c)). Foundry does not knowingly collect personal information from consumers under 16, and we do not sell or share personal information of any consumer, including minors. If we change this practice, we will obtain affirmative opt-in consent from consumers between 13 and 16, and parental opt-in for those under 13, before any sale or sharing.
  • Shine the Light (Cal. Civ. Code § 1798.83). California residents may request information about disclosures of personal information to third parties for those third parties’ direct-marketing purposes. We do not disclose personal information for third-party direct marketing.

14.2 How to submit a request

Submit a verifiable consumer request by emailing privacy@bioscopefoundry.com. Include enough information for us to verify your identity, typically your name, the email address(es) we have on file, and a description of the request. We may ask for additional information to confirm your identity (for example, matching information against records you have previously provided), and we will not require you to create an account solely to submit a request. We will confirm receipt within 10 business days and respond substantively within 45 calendar days (extendable by an additional 45 days with notice). If we deny a request, you may appeal by replying to our response.

14.3 Authorized agents

You may use an authorized agent to submit a request on your behalf, in accordance with Cal. Civ. Code § 1798.140(b) and 11 CCR § 7063. For us to act on an agent’s request, we will require (i) written, signed permission from you authorizing the agent to act on your behalf (or a valid power of attorney under Cal. Probate Code §§ 4000–4465), (ii) verification of your own identity directly with us, and (iii) confirmation from you that you have authorized the agent. Agents that are businesses must be registered with the California Secretary of State as required by § 1798.140(b). We may deny a request from an agent that does not submit proof of authorization.

14.4 Notice at collection

Per Cal. Civ. Code § 1798.100(b), we provide a short notice at or before the point of collection on intake forms (waitlist, applications, voice-interview consent, payment, e-signature) summarizing the categories collected, the business purposes, retention, and a link to this policy. See §3 above.

14.5 Other California laws

California Civil Code § 1798.83 (“Shine the Light”) is addressed above. California Insurance Information and Privacy Protection Act and California Financial Information Privacy Act do not apply to Foundry’s services.

15. Children’s privacy

The marketing site and Services are intended for physicians and their businesses and are not directed to children, and we do not knowingly collect personal information from children through the site.

16. U.S. operations

Foundry serves U.S. physicians and operates in the United States. If you access the site from outside the U.S., you understand your information will be processed in the United States.

17. Changes to this policy

We may update this policy from time to time. We will post the revised version here and update the “Last updated” date. Material changes that reduce your rights or materially expand the categories of personal information we collect, the purposes for which we use it, or the parties with whom we share it will take effect no sooner than 30 days after we post the updated policy, and we will provide additional notice where required by law (for example, by email to account holders or a banner on the marketing site). Clarifications, corrections, and changes that expand your rights or narrow our practices may take effect immediately.

18. Contact us

Questions or requests about this policy or your information:

Bioscope Foundry, LLC
Privacy contact: privacy@bioscopefoundry.com
General: info@bioscopefoundry.com
11939 N. Meridian Street, Suite 125, Carmel, IN 46032

© 2026 Bioscope Foundry, LLC. All rights reserved. This draft is provided for internal and legal review and does not constitute legal advice.