Care-Call.AI
← Home

Privacy Policy

Effective date: April 2026 · Last updated: April 2026

Care-Call.AI (the "Service") is operated by NIUSIA CO.,LTD. ("we", "us"). This Privacy Policy explains what personal data we collect from facility administrators, residents, and their family members, how we use and protect it, and the choices you have. Because we routinely handle Protected Health Information ("PHI") on behalf of Covered Entities, this policy is written to be compatible with the US Health Insurance Portability and Accountability Act ("HIPAA") and the California Consumer Privacy Act ("CCPA/CPRA").

1. Information we collect

  • Facility data: facility name, street and billing address, contact phone and email, and the identities of administrators you invite.
  • Resident data (may include PHI): name, age, room number, phone number, preferred call time, language, medical consent status, and the voice recordings, transcripts, AI-generated summaries, sentiment scores and anomaly flags produced by wellness calls we place on your behalf.
  • Family member data: name and email address where you enable family read-only dashboards.
  • Billing data: plan, number of active residents, invoices, and the last four digits of payment cards (full card data is stored by Stripe, never by us).
  • Usage data: IP address, browser type, pages visited, timestamps and basic error telemetry.

2. How we use your information

We use the data we collect to:

  • Deliver the Service — place AI wellness calls, generate summaries, send daily digests and anomaly alerts.
  • Operate, secure, and debug the platform and its voice engine.
  • Bill your facility through Stripe and keep required tax records.
  • Communicate with administrators about incidents, product updates, and policy changes.
  • Respond to support requests via our AI assistant (see §6).

We do not sell personal data, share it for cross-context behavioural advertising, or use PHI to train foundation models.

3. AI processing disclosure

Care-Call.AI is an AI-powered service. To deliver it we:

  • Stream live call audio to OpenAI's Realtime API to produce the AI companion's voice responses.
  • Send call transcripts to large language models (Anthropic Claude and OpenAI) to generate summaries, sentiment scores and anomaly flags.
  • Use Anthropic Claude to power the support chat assistant on this website.

All three providers are contractually bound by Data Processing Agreements that prohibit using your data to train their public models and require deletion on our instruction. Model outputs may be imperfect — see §7 of the Terms of Service for our disclaimer and the HIPAA Notice for how PHI is isolated.

4. HIPAA and PHI handling

When a facility enrolls residents on Care-Call.AI, NIUSIA CO.,LTD. acts as a Business Associate under HIPAA. On request we will sign a mutual Business Associate Agreement (BAA) before any PHI is ingested. Our technical safeguards include:

  • TLS 1.2+ in transit; AES-256 at rest for the database and audio archive.
  • Role-based access control with least-privilege defaults and mandatory 2FA for every NIUSIA staff member.
  • Immutable audit logs of every record read or change, retained for 6 years.
  • Annual third-party penetration testing and quarterly internal vulnerability scans.
  • Documented breach-notification process per HIPAA §164.400-414.

Details of resident rights are in the dedicated HIPAA Notice of Privacy Practices.

5. Sharing with sub-processors

We share data only with vetted sub-processors that are essential to the Service. Each is bound by a written Data Processing Agreement and, where PHI is involved, a Business Associate Agreement.

  • Twilio, Inc. — SIP telephony and call delivery (USA).
  • OpenAI, L.L.C. — Realtime voice model and transcript summarisation (USA, zero-retention tier).
  • Anthropic PBC — support chat and call summaries (USA, zero-retention tier).
  • Twilio SendGrid — transactional email (USA).
  • Stripe, Inc. — billing and payments (USA).
  • Vultr Holdings, LLC — managed VPS hosting, primary region us-east-nj (New Jersey, USA).
  • Cloudflare, Inc. — DNS, DDoS mitigation and edge caching (USA).

6. Data retention

We keep personal data only as long as needed:

  • Voice recordings: 90 days, then cryptographically erased.
  • Call transcripts and AI summaries: 24 months from the call date.
  • Facility and resident account data: for the life of the account plus 30 days.
  • Billing records / tax records: 7 years (US IRS §6001).
  • Audit logs: 6 years (HIPAA §164.530(j)).
  • Support chat transcripts: 12 months.

A facility administrator can request earlier deletion of a resident's records via the contact form on our website (choose the Privacy category).

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export personal data we hold about you, and to object to or limit certain types of processing. Residents of California enjoy additional rights under CCPA/CPRA including the right to know what we collect, the right to delete, the right to correct, and the right to opt out of the sale or sharing of personal information (we do not sell or share, but the right remains). To exercise any of these rights, submit a request via the contact form on our website and select the Privacy category. We will verify your identity and respond within 45 days.

8. Children

The Service is not directed to children under 13, and we do not knowingly collect personal data from children. If you believe a child's data has been provided, contact us for deletion.

9. International transfers

NIUSIA CO.,LTD. is based in Japan. Although the Service is hosted in the United States, NIUSIA engineering staff in Japan may access data in the course of support and maintenance. Transfers between the US and Japan rely on Standard Contractual Clauses and the protections afforded by Japan's APPI (Act on the Protection of Personal Information).

10. Security breaches

In the event of a security incident affecting PHI we will notify affected facilities without unreasonable delay and in no case later than 60 days after discovery, in accordance with HIPAA §164.404. We will also notify the Secretary of HHS and, where required, the media and state attorneys general.

11. Cookies

See our Cookie Policy for details of the strictly-necessary cookies we use. We do not use third-party advertising cookies.

12. Changes to this policy

We will notify facility administrators by email at least 14 days before any material change to this Privacy Policy. Non-material updates (typos, clarifications) will be reflected in the "Last updated" date above.

13. Contact

Questions, access requests or complaints can be sent via the contact form on our website (choose the Privacy category) or by mail to NIUSIA CO.,LTD., Tokyo, Japan. You also have the right to lodge a complaint with the US Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr.
Privacy Policy · Care-Call.AI