Document Title | ContinuaOS Privacy Policy |
|---|---|
Version | 3.3 |
Effective Date | 2026 |
Governing Law | State of Oklahoma, United States of America |
Prepared By | ContinuaOS, Inc. — Legal & Compliance |
Review Cycle | Annual or upon material change |
Applies To | All visitors to the ContinuaOS website and all users of the ContinuaOS platform |
Operational Posture. The privacy and data handling practices described in this Policy are the operating standard of the ContinuaOS platform; the production environment is provisioned to this standard before the first Covered Entity’s PHI is processed. Subprocessor BAAs and DPAs are executed; PHI is processed only under executed Business Associate Agreements. Customer-specific Business Associate Agreements with each new Covered Entity customer are executed at onboarding prior to PHI processing on that customer’s tenant.
ContinuaOS does not sell personal data. We do not sell, rent, trade, or otherwise transfer your personal information to third parties for marketing or advertising purposes, under any circumstances.
1. Introduction
ContinuaOS, Inc. (“ContinuaOS,” “we,” “us,” or “our”) operates the Growth Operating System for Post-Acute Care, starting with hospice — a cloud-based, multi-tenant software-as-a-service (SaaS) platform purpose-built for hospice organizations and adjacent post-acute care providers. The platform runs the front-side of the hospice business, from the first marketer visit at a referring facility through to the completed admission, including referral coordination, intake workflow, marketer relationship intelligence, scheduling, and operational reporting.
This Privacy Policy (“Policy”) describes how ContinuaOS collects, uses, stores, discloses, and protects information about individuals who access or use the ContinuaOS platform and website (collectively, the “Services”). This Policy applies to all users of the Services, including employees, contractors, and authorized personnel of subscribing organizations, as well as visitors to the ContinuaOS public website.
ContinuaOS is committed to handling all personal and organizational data with care, transparency, and respect. The nature of the industry we serve — hospice and post-acute care — means that the data entrusted to our platform often relates to individuals at extraordinarily vulnerable moments in their lives. We take that responsibility seriously. This Policy is designed to give users and subscribing organizations a clear and complete understanding of how their data is handled.
This Policy should be read in conjunction with the ContinuaOS Terms of Service, which governs use of the platform, and any applicable Business Associate Agreement (BAA) executed between ContinuaOS and a subscribing organization for the processing of Protected Health Information (PHI) under HIPAA.
By accessing the ContinuaOS platform or website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described in this Policy, please do not access or use the Services.
2. Information We Collect
ContinuaOS collects information in several ways: directly from users when they interact with the platform, automatically through the operation of the Services, and from subscribing organizations as part of the service delivery relationship. The categories of information we collect are described below.
2.1 Account Information
When a user account is created through the invite-only provisioning process, ContinuaOS collects information necessary to establish and manage the account:
- Full name of the user
- Business email address
- Name of the subscribing organization and any associated branches
- Job title or role within the organization
- User role assigned within the ContinuaOS platform (e.g., Marketer, Admissions Coordinator, Executive Director, BDL, CEO, Organization Administrator)
- Date and time of account creation
- Identity of the administrator who issued the account invitation
2.2 Authentication and Login Data
ContinuaOS collects information related to user authentication and session activity for security and operational purposes:
- Password credentials are managed entirely by AWS Cognito; the ContinuaOS application never receives, stores, or hashes a password
- Authentication event records, including successful logins, failed login attempts, and logout events
- Session tokens and authentication timestamps
- Multi-factor authentication enrollment and verification records
- Password change and password reset event records
2.3 Usage and Activity Data
ContinuaOS automatically collects information about how users interact with the platform as part of its audit logging and security monitoring functions:
- Features accessed and actions performed within the platform
- Records viewed, created, modified, or deleted
- Reports generated and documents accessed
- Search queries entered within the platform
- Timestamps of all activity events
- Administrative actions performed, including user management and configuration changes
2.4 Device and Technical Information
When users access the platform, certain technical information is automatically collected by the platform’s infrastructure:
- IP address of the requesting device
- Browser type, version, and rendering engine (for web access, including the installable web application)
- Operating system and device type
- User agent string
- Referring URL and navigation path, where applicable
- Session identifiers and connection timestamps
This information is used primarily for security monitoring, audit logging, and troubleshooting purposes, as described in Section 3.
2.5 Customer Data
Subscribing organizations and their authorized users upload and create data within the platform in the course of using the Services. This “Customer Data” may include:
- Patient referral records and associated intake information
- Account and contact records for healthcare facilities, physicians, and referral partners
- Operational notes, care coordination records, and workflow documentation
- Marketer activity logs, drive plans, and visit notes
- Scheduling information and task assignments
- Uploaded documents and file attachments
- Report data and operational metrics
As described in Section 7, Customer Data is owned by the subscribing organization. ContinuaOS processes Customer Data solely as a data processor acting on behalf of the subscribing organization. Customer Data may contain personally identifiable information and, in some cases, Protected Health Information (PHI) as defined under HIPAA.
2.6 Support Communications
When users contact ContinuaOS for technical support, to report an issue, or for any other purpose, we collect:
- The content of support requests, emails, and communications submitted to ContinuaOS
- Contact information provided in connection with support requests
- Records of support interactions and resolution activities
Support communications are used solely for the purpose of resolving the reported issue and improving service quality.
2.7 Cookies and Similar Technologies
The ContinuaOS platform and website may use cookies, local storage, and similar technologies for functional and security purposes. Specifically:
- Strictly Necessary Cookies. Used to maintain authenticated sessions, store user preferences, and enable core platform functionality. These cookies are required for the platform to operate and cannot be disabled.
- Security Cookies. Used to support security features such as session management, CSRF protection, and rate limiting. These cookies are required for the protection of the platform and its users.
- Analytics Cookies. Where used, analytics technologies help ContinuaOS understand how the platform and website are used in aggregate, to identify areas for improvement. Analytics data is not used to track individual users for marketing purposes.
ContinuaOS does not use cookies or tracking technologies to serve targeted advertising or to track users across third-party websites for commercial purposes.
3. How We Use Information
ContinuaOS uses the information described in Section 2 for the purposes set out below. All use of personal information is limited to what is necessary and proportionate for the stated purpose.
3.1 To Provide and Operate the Services
The primary purpose for which ContinuaOS collects and processes information is to deliver the Services to subscribing organizations. This includes provisioning and managing user accounts, authenticating users, enabling access to platform features appropriate to the user’s assigned role, storing and retrieving Customer Data as directed by the subscribing organization, executing background processes and automated workflows, and generating reports.
3.2 To Ensure Platform Security
ContinuaOS uses activity and technical data to maintain the security and integrity of the platform and to protect users and organizations from unauthorized access. This includes maintaining audit logs of authentication events and data access activity, detecting and responding to unauthorized access attempts, monitoring for unusual activity patterns, enforcing rate limits, and investigating suspected violations of the Terms of Service or Acceptable Use Policy.
3.3 To Improve the Platform
ContinuaOS uses aggregated and anonymized data derived from platform usage to improve the quality, performance, and functionality of the Services. Platform improvement activities are conducted using de-identified or aggregated data wherever possible. ContinuaOS does not use individual PHI for product improvement, model training, or benchmarking purposes.
3.4 To Communicate with Users
ContinuaOS uses contact information to communicate with users and subscribing organizations about platform notifications, service updates, support requests, security notifications, and account management communications. ContinuaOS does not send unsolicited marketing communications to users of the platform.
3.5 For Billing and Account Management
ContinuaOS uses account and contact information to process subscription fees, manage payment relationships, issue invoices, and manage subscription renewals, modifications, and terminations.
3.6 To Comply with Legal Obligations
ContinuaOS may process information where necessary to comply with applicable legal requirements, including responding to lawful requests from regulatory authorities, courts, or law enforcement; fulfilling obligations under applicable healthcare data protection laws including HIPAA; maintaining records required by applicable law; and enforcing ContinuaOS’s legal rights and defending against legal claims.
4. How We Share Information
ContinuaOS does not sell, rent, trade, or otherwise transfer personal information to third parties for marketing, advertising, or commercial purposes. This commitment is unconditional.
ContinuaOS shares information only in the limited circumstances described below, and only to the extent necessary for the stated purpose.
4.1 Service Providers and Subprocessors
ContinuaOS engages a small set of third-party service providers (“Subprocessors”) to assist in delivering the Services. These providers process data only as necessary to perform services on ContinuaOS’s behalf and are contractually prohibited from using data for any other purpose. The authoritative subprocessor list is maintained in the ContinuaOS Subprocessor Register; a summary is provided below.
Subprocessor | Function | Data Processed |
|---|---|---|
Amazon Web Services, Inc. | Production cloud infrastructure: compute, database, file storage, secrets management, monitoring, backups, and AI processing (Anthropic Claude via Amazon Bedrock; Amazon Transcribe) | All Customer Data including PHI, account information, uploaded files, audit logs, encrypted at rest with AWS KMS. BAA executed. |
Google LLC (Google Workspace) | Internal business productivity infrastructure: email, document collaboration, calendar, meetings | Internal business communications and documents only. By ContinuaOS policy, Customer PHI is not stored, transmitted, or processed in Google Workspace. BAA executed as defense-in-depth. |
Stripe, Inc. | Subscription billing and payment processing | Billing contact information and subscription transactions only. No PHI transmitted. PCI DSS Level 1 certified. |
Sentry (Functional Software, Inc.) | Error monitoring, performance tracking, uptime monitoring | Sanitized error logs only. PHI scrubbed by SDK configuration before transmission. No PHI captured. |
AI processing runs on HIPAA-eligible AWS services — Anthropic Claude models via Amazon Bedrock, and Amazon Transcribe for voice transcription — entirely within ContinuaOS’s AWS environment under the AWS BAA. The AI model provider is not a Subprocessor and does not receive Customer Data; inputs and outputs are not used for model training.
See the ContinuaOS Subprocessor Register and the ContinuaOS Vendor Security Packet for detailed subprocessor information, including certifications, data processing scope, and downstream subprocessor handling.
4.2 Legal and Regulatory Disclosures
ContinuaOS may disclose personal information where required to do so by applicable law, or where ContinuaOS reasonably believes that disclosure is necessary to: comply with a legal obligation, court order, subpoena, or lawful governmental or regulatory request; enforce ContinuaOS’s Terms of Service or other applicable agreements; protect the rights, property, or safety of ContinuaOS, its customers, platform users, or the public; or prevent or investigate suspected fraud, security incidents, or violations of applicable law. Where legally permitted, ContinuaOS will notify the affected subscribing organization of any such request prior to disclosure.
4.3 Business Transfers
In the event that ContinuaOS undergoes a merger, acquisition, reorganization, sale of assets, or similar corporate transaction, Customer Data and other information may be transferred to the successor entity as part of that transaction. ContinuaOS will provide reasonable prior notice to affected subscribing organizations of any such transfer and will ensure that the successor entity is bound by terms no less protective than those in this Policy.
4.4 With Consent
ContinuaOS may share information in ways not described in this Policy where the relevant individual or subscribing organization has provided explicit prior consent to such sharing.
5. Data Security
ContinuaOS implements a comprehensive set of administrative, technical, and physical safeguards designed to protect personal information and Customer Data against unauthorized access, disclosure, alteration, loss, and destruction. Our security program reflects the sensitivity of the healthcare and operational data managed on the platform.
5.1 Security Measures
Control | Description |
|---|---|
Encryption in Transit | All data transmitted between users and the platform is encrypted using TLS 1.2 or higher; TLS 1.3 is preferred. HTTPS is enforced at the public edge (CloudFront); origin access is restricted to CloudFront network ranges (verified July 30, 2026), and a dedicated HTTPS origin listener is a Remediation Register hardening item. Database connections are encrypted in transit; the database server requires TLS (rds.force_ssl=1, verified July 30, 2026). |
Encryption at Rest | All data stored in the platform database and file storage systems is encrypted at rest using AES-256 via AWS Key Management Service. Encryption keys are managed under AWS KMS with customer-managed key support for enterprise customers available at the PHI phase. |
Access Controls | Access to platform data is governed by role-based access controls and enforced at the database level through Row-Level Security (RLS) policies. Users can only access data belonging to their own organization. |
Audit Logging | Comprehensive audit logs capture all authentication events, data access activities, and administrative actions, with timestamps, user identities, IP addresses, and event details. The application audit log is append-only at the database layer for application roles; Account-wide multi-region AWS CloudTrail provides the infrastructure activity record (all management events, log-file integrity validation, continuous since May 28, 2026); Object-Lock archival storage is a PHI-phase hardening item. |
Security Monitoring | Amazon GuardDuty threat detection enabled account-wide in the operating region (enabled July 30, 2026), alongside account-wide multi-region CloudTrail (management events, log-file integrity validation, continuous since May 28, 2026) and CloudWatch logging. Error monitoring (Sentry) is integrated in the frontend with a PHI-scrub filter applied before transmission; monitoring activation is scheduled (Remediation Register). |
Invite-Only Access | User accounts can only be created by an authorized organization administrator through an invite-only provisioning process. Open public registration is not permitted. |
Brute Force Protection | Authentication endpoints are protected by rate limiting and progressive lockout controls to prevent brute-force and credential-stuffing attacks. |
Backup and Recovery | AWS RDS automated daily database snapshots with continuous WAL archiving enable point-in-time recovery. S3 versioning protects uploaded files against accidental deletion; cross-region replication is a documented roadmap item scheduled with the PHI-phase scale-up. |
5.2 Security Limitations
While ContinuaOS implements rigorous security controls, no information technology system or security program can guarantee absolute protection against all possible threats. ContinuaOS does not warrant that the platform or the data stored therein will be completely free from unauthorized access, interception, corruption, or loss. Users and organizations are encouraged to employ strong passwords, enable multi-factor authentication, and promptly report any suspected security incidents.
5.3 Security Incident Notification
In the event of a security incident that involves unauthorized access to personal information or Customer Data, ContinuaOS will respond in accordance with its Incident Response Plan. Affected subscribing organizations will be notified in accordance with applicable legal requirements and the procedures described in that Plan. Security incidents may be reported to ContinuaOS at security@continuaos.com.
6. Data Retention
ContinuaOS retains personal information and Customer Data for as long as necessary to fulfill the purposes for which it was collected, to provide the Services, and to comply with applicable legal, regulatory, and contractual obligations. The following retention principles apply.
6.1 Active Subscriptions
Customer Data and associated user account information is retained for the duration of the active subscription relationship. ContinuaOS does not delete Customer Data while a valid subscription is in effect, except upon the explicit written request of the subscribing organization and subject to any applicable legal retention requirements.
6.2 Following Subscription Termination
Upon expiration or termination of a subscription, the following retention schedule applies:
Data Category | Post-Termination Retention | Purpose |
|---|---|---|
Customer Data (operational records) | 30 days available for export; permanent deletion thereafter | Allow organization to retrieve data before permanent deletion |
User account information | 90 days following termination | Support, dispute resolution, security investigation |
Audit logs | Application audit log retained in the primary database without automated purge; infrastructure activity records retained without automated expiration in the account-wide multi-region AWS CloudTrail trail (all management events, log-file integrity validation, logging continuously since May 28, 2026); HIPAA-required documentation (policies, assessments, incident records) retained six (6) years per 45 C.F.R. §164.316(b)(2) | Security monitoring, compliance, HIPAA documentation retention |
Billing and payment records | 7 years | Tax and financial regulatory compliance |
Support communications | 3 years | Service quality, dispute resolution |
Security incident records | 6 years | HIPAA retention requirements; legal defense |
6.3 Earlier Deletion Upon Request
Subscribing organizations may request earlier deletion of their Customer Data by contacting ContinuaOS at support@continuaos.com. ContinuaOS will fulfill deletion requests within a reasonable timeframe, subject to the limitations described in Section 8.3 regarding legal and contractual retention obligations. Deletion requests do not affect data that ContinuaOS is required to retain by applicable law.
6.4 Data Destruction
When data reaches the end of its applicable retention period, ContinuaOS will permanently delete or destroy that data using industry-standard secure deletion methods that render the data unrecoverable. Backup copies of deleted data will be purged within the next scheduled backup cycle following permanent deletion. Detailed procedures are described in the ContinuaOS Data Retention & Deletion Schedule.
7. Customer Data Ownership
ContinuaOS operates as a data processor with respect to Customer Data. The subscribing organization remains the data controller and retains full ownership of all data, records, files, and content submitted to the platform by its users. ContinuaOS makes no claim of ownership over Customer Data, and Customer Data is not used by ContinuaOS for any purpose other than delivering the Services to the subscribing organization.
7.1 Processing on Behalf of the Customer
ContinuaOS accesses, stores, and processes Customer Data only as directed by the subscribing organization and only to the extent necessary to provide the Services. All processing activities are governed by the ContinuaOS Terms of Service and, where the Customer Data includes Protected Health Information under HIPAA, by the applicable Business Associate Agreement.
7.2 Customer Responsibilities
The subscribing organization is the data controller for all Customer Data and is responsible for: ensuring that it has obtained all necessary consents, authorizations, and legal permissions required to collect and submit Customer Data to the platform; ensuring that its use of the platform to process personal information and health-related data complies with applicable law, including HIPAA, applicable state privacy laws, and any other relevant regulatory requirements; managing user access, roles, and permissions within the organization’s platform tenant; and responding to rights requests from individuals whose personal information is contained within Customer Data, as described in Section 8.
7.3 HIPAA Business Associate Agreement
For organizations that are HIPAA Covered Entities, ContinuaOS will enter into a Business Associate Agreement (BAA) as required by the Health Insurance Portability and Accountability Act prior to the processing of any Protected Health Information on behalf of the Customer. Organizations with HIPAA compliance obligations must ensure that an executed BAA is in place with ContinuaOS prior to uploading or processing PHI through the platform. To request a BAA, please contact compliance@continuaos.com.
ContinuaOS does not use Customer Data for product development, model training, benchmarking, or any other purpose beyond delivering the contracted Services to the subscribing organization.
8. User Rights
ContinuaOS respects the rights of individuals with respect to their personal information. Users and subscribing organizations may exercise the rights described in this section subject to applicable law and the limitations noted below.
HIPAA Rights and the Covered Entity. If you are a patient whose information has been submitted to the ContinuaOS platform by a hospice organization, your rights under HIPAA — including the right to access, amend, and receive an accounting of disclosures of your PHI — are administered by that hospice organization as the Covered Entity. Please contact your hospice organization directly to exercise these rights. ContinuaOS will cooperate with the Covered Entity to facilitate the fulfillment of individual rights requests.
8.1 Right of Access
Users may request confirmation of whether ContinuaOS processes personal information about them, and may request a copy of the personal information ContinuaOS holds about them in its capacity as a data controller (i.e., information relating to the user’s own account and activity, distinct from Customer Data held on behalf of the organization). To submit an access request, please contact privacy@continuaos.com.
8.2 Right to Correction
Users may request correction of inaccurate or incomplete personal information held by ContinuaOS. Most account information can be updated directly within the platform by the user or the organization administrator. Where correction requires ContinuaOS’s direct intervention, requests may be submitted to privacy@continuaos.com. ContinuaOS will fulfill correction requests within a reasonable timeframe.
8.3 Right to Deletion
Users may request deletion of their personal information. ContinuaOS will fulfill deletion requests subject to the following limitations:
- Deletion requests cannot be fulfilled where ContinuaOS is required to retain data by applicable law, regulatory requirement, or active legal proceeding.
- Deletion of a user account does not automatically result in deletion of all Customer Data associated with that user’s activities, as such data remains the property of the subscribing organization.
- Audit log entries, security event records, and billing records are retained for defined periods as described in Section 6 and may not be deleted upon request where retention is required by law.
Deletion requests may be submitted to privacy@continuaos.com. ContinuaOS will respond to deletion requests within thirty (30) days and will provide written confirmation of the action taken.
8.4 Right to Data Portability
Subscribing organizations may request an export of their Customer Data in a standard machine-readable format at any time during an active subscription, and for thirty (30) days following subscription termination. Export requests may be submitted to support@continuaos.com. ContinuaOS will facilitate data exports within a commercially reasonable timeframe.
8.5 How to Submit Rights Requests
Rights requests may be submitted to ContinuaOS at privacy@continuaos.com. ContinuaOS will verify the identity of the requesting party before processing any rights request to ensure that information is not disclosed or deleted based on a fraudulent or unauthorized request. ContinuaOS will acknowledge receipt of all rights requests within five (5) business days and will endeavor to fulfill requests within thirty (30) days, except in cases of unusual complexity.
9. Cookies and Tracking Technologies
ContinuaOS uses cookies and similar technologies on its website and platform for the purposes described in this section. Cookies are small text files stored on your device by your web browser. They allow the platform to recognize your device across sessions and to provide certain functionality.
9.1 Types of Cookies Used
Cookie Type | Purpose | Can Be Disabled? |
|---|---|---|
Strictly Necessary | Required for core platform functionality including session management, authentication, and security controls. | No — required for platform operation |
Functional / Preference | Used to store user preferences such as language settings, display preferences, and session state, to provide a consistent user experience. | Limited — may affect user experience |
Security | Support security features including CSRF protection, rate limiting, and session integrity validation. | No — required for security |
Analytics | Collect aggregated, anonymized information about how the platform is used, to support product improvement. No individual user profiles are built for advertising purposes. | Yes — via browser settings |
9.2 Managing Cookies
Users may control cookie settings through their web browser’s privacy or settings interface. Most browsers allow users to block or delete cookies. However, disabling strictly necessary or security cookies will prevent the platform from functioning correctly and will prevent access to the Services.
ContinuaOS does not use cookies or tracking technologies for third-party advertising, behavioral profiling, or cross-site tracking. ContinuaOS does not sell data collected through cookies to third parties.
10. Third-Party Services and Subprocessors
ContinuaOS engages third-party service providers to support the delivery of the Services. These providers act as Subprocessors and are permitted to process data only as necessary to provide services to ContinuaOS, under contractual terms that require them to protect data in a manner consistent with this Policy. The current subprocessor list is provided in Section 4.1 and maintained authoritatively in the ContinuaOS Subprocessor Register.
10.1 Third-Party Links and Integrations
The ContinuaOS website or platform may contain links to third-party websites or services. ContinuaOS is not responsible for the privacy practices, data handling, or content of third-party websites. Users who follow links to third-party sites are subject to the privacy policies and terms of those sites, not this Policy. ContinuaOS encourages users to review the privacy policies of any third-party sites they visit.
10.2 Changes to Subprocessors
ContinuaOS may engage new subprocessors or change existing subprocessors from time to time as the Services evolve. Where a new subprocessor involves a material change to how Customer Data is processed, ContinuaOS will provide reasonable prior notice to affected subscribing organizations in accordance with the terms of any applicable BAA or Data Processing Agreement.
11. Children’s Privacy
The ContinuaOS platform and website are designed for use by healthcare organizations and their professional personnel. The Services are not directed to, and are not intended for use by, individuals under the age of thirteen (13). ContinuaOS does not knowingly collect, solicit, or process personal information from children under the age of thirteen.
If ContinuaOS becomes aware that it has inadvertently collected personal information from a child under the age of thirteen, ContinuaOS will take prompt steps to delete such information. If you believe that ContinuaOS may have collected personal information from a child under thirteen, please contact us at privacy@continuaos.com.
This provision applies to the personal information of platform users. It does not apply to information about patients or individuals contained within Customer Data, which is submitted to the platform by subscribing organizations and processed under their direction in accordance with applicable healthcare law.
12. Changes to This Privacy Policy
ContinuaOS reserves the right to update or modify this Privacy Policy at any time to reflect changes in our data practices, applicable law, or the features and functionality of the Services. When we make changes to this Policy, we will update the “Effective Date” displayed at the top of this document.
12.1 Material Changes
For any modification to this Policy that materially affects how we collect, use, or share personal information, ContinuaOS will provide advance notice through one or more of the following methods:
- Email notification to the registered Organization Administrator email address(es) on file for each subscribing organization.
- A prominent notice displayed within the platform upon login, directing users to review the updated Policy.
- Publication of the updated Policy on the ContinuaOS website, with the revised effective date clearly indicated.
ContinuaOS will endeavor to provide at least thirty (30) days’ advance notice of material changes to this Policy, except where a shorter period is required by applicable law or urgent circumstances.
12.2 Continued Use as Acceptance
Your continued access to or use of the Services after the effective date of a revised Policy constitutes your acceptance of the updated terms. If you do not agree with the revised Policy, you should discontinue use of the Services and contact your organization administrator or ContinuaOS to discuss your options.
13. Contact Information
If you have questions, concerns, or requests relating to this Privacy Policy or ContinuaOS’s data practices, please contact us using the information below. ContinuaOS is committed to addressing privacy inquiries promptly and thoroughly.
Contact Type | Details |
|---|---|
Company | ContinuaOS, Inc. (a Delaware corporation) |
Mailing Address | _______________________________________________ Oklahoma _________ United States |
Privacy Inquiries | privacy@continuaos.com |
Data Rights Requests | privacy@continuaos.com · Subject: Data Rights Request |
Security & Breach Reports | security@continuaos.com |
HIPAA / BAA Inquiries | compliance@continuaos.com |
General Support | support@continuaos.com |
Platform URL | https://www.continuaos.com |
ContinuaOS will acknowledge all privacy inquiries within five (5) business days and will endeavor to resolve all requests within thirty (30) days. For complex or legally sensitive requests, ContinuaOS will communicate an extended response timeline where necessary.
— End of Document —
ContinuaOS, Inc. · Privacy Policy v3.3 · 2026