Arctic Health
Graded against 808 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: Data retention
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Specifies that Website analytics data is retained for up to 24 months, establishing a defined maximum retention period for this data category.
Grants California residents the right to opt out of the sale or sharing of personal information, and includes a disclaimer that the company does not sell personal information — protective of the user.
Defines analytics cookies as used to understand visitor interactions, grants users a control right via browser settings, and prohibits the use of advertising cookies or tracking pixels for targeted advertising — user-favorable restriction on tracking use.
How to read this page: Overall risk rates what Arctic Health's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 17 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 17 citationsLast captured 2026-07-19
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Defines the scope and applicability of the Privacy Policy, identifying the controller entity, the covered Website, the data practices the policy governs (collection, use, and sharing of information), and expressly excludes the AI-powered credentialing and contracting platform from this policy's scope, noting it is subject to separate agreements including a BAA for PHI-handling entities; also establishes acceptance by continued Website use.
" Arctic Health ("we," "us," or "our") operates the website at arctic.health (the "Website"). We are committed to protecting your privacy and being transparent about how we collect, use, and share your information. This Privacy Policy appli..."
Describes the procedural framework for how healthcare organizations' PHI is handled, including the requirement for a separate Business Associate Agreement before any PHI is processed, enumeration of technical safeguards (encryption, access controls, audit logging), and breach notification procedures, and clarifies that the Privacy Policy itself governs only Website visitor personal information, not PHI.
" Arctic Health provides AI-powered services to healthcare organizations that may handle Protected Health Information ("PHI"). This Website does not collect or process PHI. This Privacy Policy governs the personal information of Website vis..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected. Contact inquiries: Retained for up to 3 years from your last interaction, or until you request deletion Email communications: Retained until you unsubscribe or request deletion"
Specifies that Website analytics data is retained for up to 24 months, establishing a defined maximum retention period for this data category.
AI-generated interpretation, not legal advice.
" Right to opt out of the sale or sharing of personal information (we do not sell your personal information)"
Grants California residents the right to opt out of the sale or sharing of personal information, and includes a disclaimer that the company does not sell personal information — protective of the user.
AI-generated interpretation, not legal advice.
" Analytics Cookies: Help us understand how visitors interact with our Website You can control cookies through your browser settings. We do not use advertising cookies or tracking pixels for targeted advertising purposes."
Defines analytics cookies as used to understand visitor interactions, grants users a control right via browser settings, and prohibits the use of advertising cookies or tracking pixels for targeted advertising — user-favorable restriction on tracking use.
AI-generated interpretation, not legal advice.
" Our Website and services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe your child has provided us with personal information, please contact us at [email protected] ."
Restricts collection of personal information from individuals under 18 and states that the Website and services are not directed to children, and provides a contact mechanism for parents to request removal of inadvertently collected information — user-protective restriction on data collection from minors.
AI-generated interpretation, not legal advice.
" Arctic Health ("we," "us," or "our") operates the website at arctic.health (the "Website"). We are committed to protecting your privacy and being transparent about how we collect, use, and share your information. This Privacy Policy applies to information collected through our Website, including any contact forms, email communications, and analytics data. It does not govern the use of our AI-powered credentialing and contracting platform, which is subject to separate agreements including a Business Associate Agreement ("BAA") for entities handling Protected Health Information ("PHI"). By accessing or using our Website, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our practices, please do not use our Website."
Defines the scope and applicability of the Privacy Policy, identifying the controller entity, the covered Website, the data practices the policy governs (collection, use, and sharing of information), and expressly excludes the AI-powered credentialing and contracting platform from this policy's scope, noting it is subject to separate agreements including a BAA for PHI-handling entities; also establishes acceptance by continued Website use.
AI-generated interpretation, not legal advice.
" If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act: Right to know what personal information is collected, used, shared, or sold"
Grants California residents the right to know what personal information is collected, used, shared, or sold, referencing specific statutory frameworks by name as the source of these additional rights.
AI-generated interpretation, not legal advice.
" If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation:"
Incorporates by reference the additional rights available under the named regulation for users in the specified jurisdictions, framing the enumerated rights that follow.
AI-generated interpretation, not legal advice.
" To exercise any of these rights, please contact us at [email protected] . We will respond to your request within 30 days."
Establishes the procedure for exercising privacy rights by directing users to contact the company at a specified address, and imposes an obligation on the company to respond within 30 days.
AI-generated interpretation, not legal advice.
" When you interact with our Website, you may voluntarily provide us with personal information, including: Your name and email address when you contact us or schedule a call Your organization name, role, and professional details when requesting information about our services Any additional information you choose to include in communications with us"
Describes the categories of personal information (name, email, organization name, role, professional details, and freely added communications content) that are collected when visitors voluntarily interact with the Website, establishing transparency obligations regarding the controller's data collection practices.
AI-generated interpretation, not legal advice.
" When you visit our Website, we may automatically collect certain information about your device and usage, including:"
Introduces the automatic collection of device and usage information when visitors access the Website, qualifying the collection as conditional ('may automatically collect').
AI-generated interpretation, not legal advice.
" We implement appropriate technical and organizational measures to protect your personal information:"
Imposes an obligation on the company to implement appropriate technical and organizational measures to protect personal information, framing the specific measures listed below.
AI-generated interpretation, not legal advice.
" Arctic Health provides AI-powered services to healthcare organizations that may handle Protected Health Information ("PHI"). This Website does not collect or process PHI. This Privacy Policy governs the personal information of Website visitors only. When healthcare organizations engage Arctic Health's platform services: A separate Business Associate Agreement ("BAA") is executed before any PHI is processed PHI is handled in accordance with HIPAA Privacy and Security Rules Technical safeguards include encryption at rest and in transit, access controls, and audit logging Breach notification procedures comply with the HIPAA Breach Notification Rule All subcontractors with access to PHI are bound by appropriate agreements"
Describes the procedural framework for how healthcare organizations' PHI is handled, including the requirement for a separate Business Associate Agreement before any PHI is processed, enumeration of technical safeguards (encryption, access controls, audit logging), and breach notification procedures, and clarifies that the Privacy Policy itself governs only Website visitor personal information, not PHI.
AI-generated interpretation, not legal advice.
" We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page. Your continued use of the Website after any changes constitutes your acceptance of the updated policy."
Establishes the procedure for notifying users of material changes to the Privacy Policy via updating the 'Last Updated' date, and deems continued use of the Website after changes as acceptance of the updated policy.
AI-generated interpretation, not legal advice.
" If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:"
Establishes the procedure by which users may submit questions, concerns, or requests regarding the Privacy Policy by contacting the organization.
AI-generated interpretation, not legal advice.
" When information is no longer needed, we will securely delete or anonymize it."
Imposes an obligation on the company to securely delete or anonymize personal information when it is no longer needed, establishing a retention limit and disposal requirement.
AI-generated interpretation, not legal advice.
" While we strive to protect your personal information, no method of transmission over the Internet is completely secure."
Disclaims absolute security guarantees for internet transmissions, limiting the organization's liability by acknowledging that no transmission method is completely secure.
AI-generated interpretation, not legal advice.
" Arctic Health is based in the United States. If you access our Website from outside the United States, your information may be transferred to, stored, and processed in the United States. If you are located in the European Economic Area, the United Kingdom, or Switzerland, we will ensure that any transfer of your personal data is carried out in accordance with applicable data protection laws."
Discloses that user data may be transferred to and processed in the United States, and imposes an obligation on the organization to ensure that transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland are carried out in accordance with applicable data protection laws — user-protective compliance commitment.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Arctic Health's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Arctic Health's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Arctic Health's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Arctic Health requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Arctic Health's published policies yet.
What the policies actually cover
0 topicsNone of Arctic Health's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected. Contact inquiries: Retained for up to 3 years from your last interaction, or until you request deletion Email communications: Retained until you unsubscribe or request deletion”Open source citation
The clause permits sale of personal data or information.
“Right to opt out of the sale or sharing of personal information (we do not sell your personal information)”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | data retention | conditional | MEDIUM | 1 |
| All applicable tiers | privacy data use | worsens | HIGH | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“Right to opt out of the sale or sharing of personal information (we do not sell your personal information)”Open timeline citation
Latest stance: indefinite or necessity based on data retention
“We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected. Contact inquiries: Retained for up to 3 years from your last interaction, or until you request deletion Email communications: Retained until you unsubscribe or request deletion”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
19 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Arctic Health's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Arctic Health's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Arctic Health's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.