Privacy Policy
Important: QuanTAVI processes medical imaging data (DICOM) entirely within your browser. Patient image data is never transmitted to or stored on QuanTAVI servers. All CT analysis and measurements happen locally on your device.
01 Who We Are
QuanTAVI is a medical imaging software platform designed to support CT-based planning for aortic valve procedures, including TAVR (Transcatheter Aortic Valve Replacement), SAVR (Surgical Aortic Valve Replacement), and Valve-in-Valve interventions. The platform is developed and operated by QuanTAVI.
This Privacy Policy explains how QuanTAVI collects, uses, and protects information when you access our website at quantavi.com and when authorized users access the QuanTAVI software platform.
For privacy inquiries, please contact us at [email protected].
02 Information We Collect
We collect information in two contexts: (a) visitors to our marketing website, and (b) authorized users of the QuanTAVI software platform.
Website visitors
- Contact form submissions: Name, professional email address, institution or organization, and any message content you choose to submit when requesting information or a demonstration.
- Usage data: Pages visited, time spent, referring URLs, browser type, and general geographic region (country/city level), collected via analytics.
- Technical identifiers: IP address, browser fingerprint characteristics, and session identifiers for security and analytics purposes.
Platform users
- Account information: Name, professional email address, institution, and role (e.g., interventional cardiologist, cardiac surgeon).
- Platform usage data: Feature interactions, workflow steps completed, session duration, and error logs for product improvement.
- Device information: Browser type, operating system, screen resolution, and graphics capabilities relevant to rendering performance.
We do not collect payment information directly. If payment processing is required, it is handled by a third-party PCI-compliant payment processor and we receive only transaction confirmation data.
03 Medical Imaging Data (DICOM)
QuanTAVI does not transmit or store patient medical imaging data on its servers.
All DICOM image processing, CT analysis, anatomical measurements, and procedural planning calculations are performed entirely within your local browser environment. Image data loaded into the platform stays on your device.
When you load DICOM studies into QuanTAVI, those images are processed using your device's CPU and GPU resources. The resulting measurements, annotations, and planning outputs you choose to save are stored according to your institution's data governance policies — either locally or within a DICOM server you control (such as an Orthanc instance on your network).
QuanTAVI does not have access to, and does not receive any copy of, the patient imaging data you use within the platform. We cannot identify any patients from information held on our servers.
Institutions connecting QuanTAVI to their own DICOM infrastructure (e.g., a local PACS or research server) are responsible for ensuring that connection is consistent with their own data protection obligations, including applicable patient privacy laws such as HIPAA in the United States or applicable national laws under GDPR in Europe.
04 How We Use Information
Information we collect is used for the following purposes:
- Service delivery: Providing access to the QuanTAVI platform, responding to support requests, and managing user accounts.
- Communication: Responding to contact form inquiries, sending product updates to users who have opted in, and notifying users of changes to the platform or this policy.
- Product improvement: Analyzing anonymized usage patterns to identify usability issues, improve workflow design, and prioritize new features. No personally identifiable clinical data is used for this purpose.
- Security and integrity: Detecting and preventing unauthorized access, abuse, or fraud. Maintaining logs necessary for security audits and incident response.
- Legal compliance: Meeting obligations under applicable law and responding to valid legal requests.
We do not sell, rent, or trade personal information to third parties for marketing purposes. We do not use your information to train AI or machine learning models without explicit, separate consent.
05 Cookies and Tracking
We use a small number of cookies and similar technologies to operate and improve the website and platform.
Essential cookies are required for the website and platform to function. They include session authentication tokens and security cookies. These cannot be disabled without breaking core functionality.
Analytics cookies collect anonymized data about how visitors interact with our website — pages visited, time on page, and navigation paths. We use this to understand which content is most useful. We use privacy-focused analytics tools that do not build cross-site user profiles.
Preference cookies remember settings you configure within the platform (such as display preferences) so they persist between sessions.
We do not use advertising or tracking cookies, and we do not allow third-party advertising networks to place cookies on our site.
You can control cookies through your browser settings. Note that disabling essential cookies will affect platform functionality. If you are in a jurisdiction where consent is required before setting non-essential cookies, we will request this before they are set.
06 Data Security
We take reasonable and appropriate technical and organizational measures to protect the information we hold against unauthorized access, disclosure, alteration, and destruction.
- All data in transit between your browser and our servers is encrypted using TLS 1.2 or higher.
- Account passwords are hashed using industry-standard algorithms; we do not store passwords in plain text.
- Access to personal data within our systems is restricted to personnel who require it for their role.
- We conduct periodic security reviews and keep dependencies updated to address known vulnerabilities.
Because patient DICOM data is processed locally in your browser and never transmitted to our servers, the primary security responsibility for that data rests with you and your institution. We recommend connecting QuanTAVI only to DICOM servers hosted on secure, access-controlled networks.
No method of electronic transmission or storage is completely secure. In the event of a data breach affecting personal information we hold, we will notify affected users and relevant authorities as required by applicable law.
07 Third-Party Services
We use a limited set of third-party service providers to operate the platform. These providers have access only to the information necessary to perform their functions and are contractually obligated to protect it.
- Cloud infrastructure: Hosting, database, and storage services. Data is stored in secure data centers with appropriate certifications.
- Email delivery: For transactional emails (account confirmations, password resets) and, where opted in, product communications.
- Analytics: Anonymized, aggregated website and platform usage analytics. No personally identifiable data is shared with our analytics provider.
- Error monitoring: Automated error and crash reporting to help us identify and fix technical issues. Error reports may include device and browser metadata but are not linked to patient data.
We do not embed social media tracking pixels or use data brokers. Any links to third-party websites on our platform or marketing site are governed by those third parties' own privacy policies, which we encourage you to review.
08 Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law.
- Account data: Retained for the duration of your account plus a reasonable period after closure to allow for dispute resolution. Upon verified request, we will delete your account data.
- Contact form submissions: Retained for up to 24 months after your inquiry is resolved, then deleted unless ongoing correspondence requires otherwise.
- Usage logs and analytics: Aggregated analytics data may be retained indefinitely in anonymized form. Raw session logs are retained for up to 12 months.
- Security logs: Retained for up to 24 months to support incident investigation.
Since we do not store patient imaging data on our servers, there is no retention period applicable to DICOM content.
09 Your Rights
Depending on your location, you may have the following rights with respect to personal information we hold about you:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that inaccurate or incomplete information be corrected.
- Deletion: Request erasure of your personal data, subject to legal obligations that require us to retain certain records.
- Portability: Receive your personal data in a structured, machine-readable format where technically feasible.
- Objection and restriction: Object to certain processing activities or request that we restrict how we use your data while a complaint is investigated.
- Withdraw consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days of receiving a verifiable request. We may need to verify your identity before processing the request.
10 GDPR and International Users
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, our processing of personal data is governed by the General Data Protection Regulation (GDPR) and applicable national implementing legislation.
Legal bases for processing:
- Contract performance: Processing necessary to provide the platform services under our agreement with you or your institution.
- Legitimate interests: Analytics and product improvement activities where our interests do not override your fundamental rights. We balance these interests carefully.
- Consent: Marketing communications and non-essential cookies, where required. You may withdraw consent at any time.
- Legal obligation: Retention of certain records required by law.
If your personal data is transferred outside of the EEA, we ensure that appropriate safeguards are in place — such as Standard Contractual Clauses approved by the European Commission — to maintain an equivalent level of protection.
You have the right to lodge a complaint with your national data protection authority if you believe we are processing your personal data unlawfully. A list of EEA supervisory authorities is available at edpb.europa.eu.
11 Research Use Notice
QuanTAVI is intended for research and educational use only.
QuanTAVI is not cleared or approved by the FDA, CE marked, or authorized by any other regulatory body for clinical diagnostic or therapeutic decision-making. It must not be used as the sole or primary basis for clinical decisions affecting patient care.
Users are responsible for ensuring their use of QuanTAVI complies with the ethical and regulatory requirements of their institution and jurisdiction, including obtaining any necessary IRB or ethics committee approvals for research use of patient-derived imaging data.
Because QuanTAVI does not receive patient data from users, we are not a "covered entity" or "business associate" under HIPAA with respect to the imaging data processed locally in your browser. Users who connect QuanTAVI to DICOM servers should assess their own HIPAA obligations independently.
12 Changes to This Policy
We may update this Privacy Policy from time to time as our practices evolve or in response to changes in applicable law. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify active users by email.
We encourage you to review this page periodically. Your continued use of our website or platform after changes are posted constitutes acceptance of the revised policy, to the extent permitted by applicable law.
Previous versions of this policy are available on request by contacting [email protected].
13 Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please reach out:
QuanTAVI
Privacy inquiries: [email protected]
General contact: [email protected]
We aim to respond to all privacy-related inquiries within 5 business days.