Privacy

Privacy & data handling

Damaros processes clinical data inside an institution-approved boundary under deterministic, auditable execution. This policy describes what data is handled, where it lives, and the controls that keep it governed.

Last updated · May 2026
01_SCOPE

What this covers

This policy applies to the Damaros platform and its FHIR integration when deployed for a site, sponsor, or hospital system. Protected health information (PHI) handling is governed by the executed Business Associate Agreement (BAA) or Data Processing Agreement (DPA) for each deployment, which prevails where terms differ.

02_DATA_WE_PROCESS

Data we process

03_PHI_AND_AI_BOUNDARY

PHI and AI boundary

Screening outcomes are deterministic. Eligibility verdicts come only from the engine evaluating normalized FHIR facts, never from a generative model. Luna governs AI-assisted work that sits outside the screening path, with provenance, reviewability, PHI gating, and scoped tasks enforced.

PHI never touches an LLM. No patient identifiers and no cohort-linked clinical fields are serialized into any AI-assisted path. Eligibility remains traceable to the protocol version and the evidence inputs that produced it.

Default egress posture. No transmission of patient-identifiable data to third-party assistance endpoints for screening. The deterministic path never requires it.
04_WHERE_DATA_LIVES

Where data lives

05_YOUR_CONTROLS

Access, retention, and your rights

Access is role-based and attributable. Administrative and export actions are RBAC-gated, and web sessions are time-bound. Data subject requests, retention schedules, and deletion are handled through the contracting institution under the applicable BAA or DPA. The geographic readout shown on this site is derived from a coarse IP lookup for display only and is not stored.

06_CONTACT

Contact

Privacy    anirudh@damaros.ai
Website    damaros.ai