Privacy Policy
Effective Date: February 18, 2026
Newf Technology, Inc. ("Company," "we," "us," or "Newf Technology"), operating as AlignSure, provides the AlignSure compliance platform ("Platform"). This Privacy Policy describes how we collect, use, disclose, and protect information when you use our Platform and related services.
For customers who execute a Business Associate Agreement (BAA) with us, the BAA governs our handling of Protected Health Information (PHI) and takes precedence over this Privacy Policy to the extent of any conflict.
1. Information We Collect
1.1 Account Information
When you register for an AlignSure account, we collect information provided by your Microsoft identity provider, including your name, email address, organizational affiliation, and role. We do not collect or store passwords.
1.2 Platform Usage Data
We collect information about how you interact with the Platform, including features accessed, actions taken, timestamps, IP addresses, browser type, and device information. This data is used to improve the Platform and ensure its security.
1.3 Customer Data
The Platform processes data provided by or on behalf of our customers, including compliance documentation, organizational records, and configuration settings. The nature and extent of customer data processed depends on how customers use the Platform.
1.4 Protected Health Information (PHI)
In the course of providing compliance services, the Platform may process PHI as defined by the Health Insurance Portability and Accountability Act (HIPAA). PHI is handled exclusively in accordance with the applicable BAA and HIPAA regulations.
2. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Platform
- Authenticate users and enforce access controls
- Generate compliance reports and audit documentation
- Communicate with users about their accounts and the Platform
- Detect, prevent, and respond to security incidents
- Comply with legal obligations and regulatory requirements
3. PHI Handling
AlignSure processes PHI solely as a Business Associate under HIPAA. Our handling of PHI is governed by the BAA executed with each applicable customer. Key safeguards include:
- PHI is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Access to PHI is restricted to authorized personnel on a minimum-necessary basis
- PHI is logically isolated by customer tenant
- PHI is not used for marketing, analytics, or any purpose outside the scope of the BAA
- PHI is not sold to third parties under any circumstances
4. Data Retention
We retain account information for the duration of the customer relationship and for a reasonable period thereafter as required by law or legitimate business purposes. Customer data, including PHI, is retained in accordance with the terms of the applicable service agreement and BAA. Upon termination of services, customer data is deleted or returned in accordance with contractual obligations.
5. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information, subject to legal retention requirements
- Object to or restrict certain processing activities
- Receive your information in a portable format
For rights related to PHI, please refer to the Notice of Privacy Practices provided by your Covered Entity (our customer). AlignSure, as a Business Associate, processes PHI at the direction of the Covered Entity.
6. Breach Notification
In the event of a breach of unsecured PHI, AlignSure will notify the affected Covered Entity without unreasonable delay and in no case later than the timeframes specified in the applicable BAA and HIPAA Breach Notification Rule. Notification will include the identification of the individuals affected, a description of the breach, and recommended steps for mitigation.
7. Contact Information
For questions about this Privacy Policy or to exercise your privacy rights, contact us at:
Newf Technology, Inc.
Privacy Inquiries
Email: privacy@alignsure.com
This Privacy Policy may be updated periodically. We will notify customers of material changes through the Platform or via email. Continued use of the Platform after changes become effective constitutes acceptance of the revised policy.