Section 01

Introduction

TortFlowAI, Inc. ("TortFlow", "we", "us," or "our") provides this Individual Access Service Data Privacy & Security Notice (this "Notice") pursuant to the Trusted Exchange Framework and Common Agreement ("TEFCA") in order to inform you of how your identifiable information is used, shared and protected by us in connection with our offered Services (as defined in the next section).

Before we access, use, exchange, or share your identifiable health information, we will ask for your clear permission and keep a record of your consent to this Privacy and Security Notice, unless we are required by law to share it. Our obligations under this Notice shall continue for so long as we maintain your identifiable information.

You may revoke your consent at any time by selecting the option to revoke consent in your settings inside of the user-facing application, which involves the following steps:

  1. Sign in to your Client Access Portal using your phone number and pre-defined pin code.
  2. Navigate to the settings tab.
  3. Click revoke consent.

Alternatively, you may email support@tortflow.ai requesting consent revocation and our support team will respond within 30 days confirming your revocation. Revocation of your consent does not affect any use or exchange of your identifiable information that occurred prior to the date of revocation. Following revocation, you will no longer have access to or be able to use the Services.

Section 02

How We Use Your Identifiable Information Internally

Our services help you retrieve your medical records from one or more qualified health network(s) and make them available to your authorized attorney(s) for the purposes of qualifying for and participating in select Mass Tort Litigations ("Services").

We collect and use your Identifiable Information to:

  • Provide the Services;
  • Support and improve our operations (like quality control or technical capabilities);
  • Develop and improve new and current products and services (provided that information obtained through TEFCA Exchange is not used for this purpose); and
  • Communicate with you.

We will not access, exchange, use, and/or disclose your identifiable information to assert any type of claim against you.

Section 03

How We Share Your Identifiable Information Externally

We do not sell your identifiable information. We share your identifiable information to provide the Services by retrieving your medical records from the associated health networks and sharing them with your authorized attorney(s).

Disclosures through TEFCA are in accordance with the permitted and required uses and disclosures specified in the Common Agreement and applicable U.S. Department of Health and Human Services guidance.

We will not share your identifiable information through TEFCA until and unless you consent to such sharing.

We do not share your identifiable information with any third parties other than your authorized attorneys.

Section 04

How We Store and Protect Your Identifiable Information

We use a cloud services provider to store your data. We use commercially reasonable efforts to protect identifiable information from unauthorized or illegal access, modification, use, or destruction.

When third parties are given access to identifiable information, we will take appropriate contractual, technical and organizational measures designed to ensure that identifiable information is processed only to the extent that such processing is necessary, consistent with this Notice and in accordance with applicable law.

We also require that any third parties who are given access to identifiable information use measures to maintain the security and confidentiality of such information which are no less protective than our obligations under this Notice.

TortFlow will act in conformance with this Notice and will protect the security of the information it holds in accordance with the applicable Framework Agreement. In the event of an IAS Incident (a TEFCA Security Incident or a Breach of Unencrypted Individually Identifiable Information, as those terms are defined in the TEFCA Common Agreement), TortFlow will notify you in accordance with the requirements described in the section titled How We Will Notify You and Protect Your Identifiable Information in Case of an Improper Disclosure below.

Section 05

When We Encrypt Your Identifiable Information

We encrypt your data automatically when stored and when transmitted.

Section 06

How This Technology Accesses Other Data

In order to qualify to use the Services, we may ask for access to other device data or applications, such as your phone's camera, photos, or contacts in order to connect to a government identification/authentication application. This may require the use of your phone's camera for biometric validation of your identity.

Section 07

What You Can Do with the Identifiable Information We Collect

Once we have collected your identifiable information, you have the option to revoke consent at any time (including revocation to share your identifiable information with your authorized attorneys), or request deletion of your identifiable information. The Services allow you to access or request deletion of the data we have about you.

You can export your data by following the instructions within your user portal. You may delete your data by emailing us at support@tortflow.ai. You may also request that we provide your identifiable information to you in a machine-readable format.

We will honor your choices regarding your identifiable information within a reasonable timeframe. If Applicable Law prohibits us from deleting your identifiable information as requested, we will inform you of that limitation.

Section 08

Are There Any Costs or Fees to Me for the Services Associated with My Identifiable Information?

No, there are no costs or fees to you associated with Services related to your Identifiable Information.

Section 09

How Long Do We Retain Your Identifiable Information?

We retain your Identifiable Information for 10 years after the conclusion of the Services unless you otherwise request deletion. Once deidentified in accordance with applicable law, we may retain de-identified data for internal operational purposes, such as quality assurance, service improvement, and personnel training.

We do not use information obtained through TEFCA Exchange, or de-identified derivatives of such information, for the purpose of training artificial intelligence or machine learning models. Any use of de-identified data will be consistent with the purposes described in this Notice and with applicable TEFCA requirements.

Relevant factors impacting our retention periods include:

  • The business purposes for which we collected the information;
  • The amount, nature, and sensitivity of the identifiable information;
  • The potential risk of harm from unauthorized use or disclosure;
  • Our legal, regulatory, tax, and/or accounting obligations and applicable statutes of limitations for claims to which the information may be relevant.

We review our retention policies on an annual basis and routinely purge information when the retention period has been met.

Section 10

What Happens to Your Identifiable Information When Your Account Is Deactivated

When your account is deactivated or terminated, whether at your direction or by us, the data, including your identifiable information, is retained and used until you request deletion through the manual request process described above.

We will deidentify your data when your account is deactivated or terminated and it may be used consistent with this Notice.

Section 11

How We Will Notify You If Our Notice Changes

Any policy changes that are applicable to this Notice will be posted, and consumers can find such changes on our website at https://www.tortflow.ai/data-and-security-notice. In addition, we will provide direct notice to all currently enrolled individuals prior to the effective date of any material changes to this Notice.

A record of the changes we have made is kept in Changes to This Notice below.

Section 12

Compliance With Court Orders or Law Enforcement

We will provide notice to you (unless prohibited by applicable law) within three (3) business days of:

  • Us receiving a civil or criminal subpoena, court order, search warrant, or other demand for compulsory disclosure in accordance with applicable law with respect to your identifiable information. You will be afforded the right to object to the production of the identifiable information or seek a protective order or other appropriate remedy consistent with applicable law; or
  • Us making identifiable information available to law enforcement agencies, including through any sale of identifiable information.
Section 13

How We Will Notify You and Protect Your Identifiable Information in Case of an Improper Disclosure

TortFlow is not a Covered Entity or Business Associate under HIPAA. TortFlow follows breach notification practices consistent with the HIPAA Breach Notification Rule as a matter of policy and contractual obligation.

As an IAS Provider, TortFlow also follows breach notification requirements under the TEFCA Common Agreement and the IAS Provider Requirements SOP, which requires notification of affected individuals within sixty (60) calendar days of TortFlow's discovery of an IAS Incident (a TEFCA Security Incident or Breach of Unencrypted Individually Identifiable Information, as those terms are defined in the TEFCA Common Agreement). You will be notified in accordance with whichever standard imposes the more protective obligation.

Any such notification will include:

  • A brief description of what happened, including the date of the incident and date of discovery;
  • The types of individually identifiable information involved;
  • Steps you can take to protect yourself;
  • Steps TortFlow is taking to investigate, mitigate, and prevent future incidents; and
  • TortFlow's contact information for further questions.
Section 14

Request Only IAS Provider

Request-only service

TORTFLOW DOES NOT PROVIDE BIDIRECTIONAL SERVICES. YOU WILL HAVE THE ABILITY TO REQUEST ACCESS TO YOUR HEALTH INFORMATION VIA TEFCA EXCHANGE. YOU WILL NOT BE ABLE TO USE TORTFLOW TO SHARE YOUR HEALTH INFORMATION WITH OTHER PARTICIPANTS IN TEFCA.

Section 15

Health Insurance Portability and Accountability Act (HIPAA) Compliance

TortFlow is not a Covered Entity or a Business Associate under HIPAA. TortFlow is not a health care provider, health plan, or health care clearinghouse. When TortFlow retrieves your health information through the TEFCA network on your behalf, it does so as your authorized designee under 45 CFR § 164.524(c)(3)(ii) — your right to direct your records to a third party of your choosing.

Separately, TortFlow voluntarily maintains administrative, technical, and physical safeguards consistent with the HIPAA Security Rule for all health information it handles, and its data processing agreements impose equivalent obligations on downstream recipients. As an IAS Provider under TEFCA, TortFlow is independently subject to the privacy and security requirements of the TEFCA Common Agreement and applicable SOPs.

Section 16

How to Contact Us: Individual Access Services Users

TortFlowAI, Inc.

Section 17

Changes to This Notice

We keep a record of the changes we make to this Notice. Each entry below tells you when the change took effect and what changed, in plain language.

When we make a material change, we will tell you directly before it takes effect. We do not rely on you checking this page.

  1. 2026-08-07 Effective August 7, 2026 Material change

    We rewrote several parts of this Notice. What changed:

    • How long we keep your information. We now keep it for 10 years after your case concludes, unless you ask us to delete it sooner. The previous version did not state a fixed period.
    • What happens when you revoke your consent. Revoking does not undo any sharing that already happened, and after you revoke it you will no longer be able to use the Services.
    • Our status under HIPAA. We now state that TortFlow is not a Covered Entity or a Business Associate under HIPAA, and explain that we retrieve your records as your authorized designee under federal law. The previous version described TortFlow as a Business Associate.
    • If your information is involved in a breach. We committed to telling you within 60 days of discovering it, and listed what that message will include.
    • Training AI models. We added a commitment not to use information obtained through TEFCA, or de-identified versions of it, to train artificial intelligence or machine learning models.
    • Your rights. We added your right to receive a copy of your information in a machine-readable format, and said we will tell you if the law prevents us from deleting information you have asked us to delete.
    • Telling you about future changes. We committed to giving you direct notice before any future material change to this Notice takes effect.

© 2026 TortFlowAI, Inc. All Rights Reserved.

Back to top