Privacy Policy

Effective date: August 25, 2026 · Applies to remeditag.com, app.remeditag.com, and the RemediTag API/CLI (the “Service”)

1. Who We Are

CCM Bridge Inc., a Minnesota corporation (“CCM Bridge,” “we,” “us”), operating RemediTag, is the entity responsible for the personal data described in this policy. Contact: contact@ccmbridge.com.

2. Scope: What RemediTag Does and Does Not Process

RemediTag is designed to validate and remediate plan-level regulatory documents (templates and produced materials such as ANOC, EOC, Summary of Benefits, Formulary, EOB, and NOA/NDN documents) for PDF/UA-1 accessibility compliance. RemediTag is not designed or intended to process documents containing individual member or beneficiary protected health information (PHI), and customers agree not to upload such documents (see the Terms of Service, Acceptable Use). Because of this scope limitation, this policy does not describe RemediTag as a HIPAA business associate, and no Business Associate Agreement is offered at this time.

3. Data We Collect

Account data: name, work email, company name, and password (hashed) when you or your organization create an account.

Document data: files you or your organization upload for processing, and the corrected output files and compliance certificates RemediTag generates.

Usage data: batch run history, API/CLI call logs, processing timestamps, and compliance scores, used to operate and support the Service.

Payment data: billing name, address, and subscription tier. Card and payment details are collected and processed directly by Stripe, our payment processor; we do not store full card numbers.

Communications: support requests and correspondence with us.

4. Why We Use It

To provide the Service (process and remediate uploaded documents, generate certificates): contractual necessity. To bill for subscriptions: contractual necessity, via Stripe. To secure, maintain, and improve the Service, and to communicate with you about it: legitimate interests. To comply with legal obligations.

5. Sharing

We do not sell personal data. We share data with: (a) Stripe, to process payments; (b) our cloud hosting provider(s), to host the Service and store uploaded documents and outputs; (c) email/support tooling providers; (d) professional advisors where necessary; (e) a successor entity in a merger or asset sale; or (f) as required by law.

Messages submitted through this Site’s contact form are delivered using a third-party transactional email service, which processes the message content solely to route it to us and does not use it for any other purpose.

This Site uses PostHog for privacy-focused website analytics. Analytics run without cookies and without storing any persistent identifier on your device; nothing is written to browser storage, so page views cannot be linked to you across visits. We do not collect names, email addresses, or other personally identifiable information through analytics, and browser Do Not Track signals are honored. PostHog processes this data on our behalf as a service provider; see PostHog’s privacy policy for details.

6. Retention

Account data is retained for as long as your subscription is active and for a reasonable period after cancellation for recordkeeping. Uploaded documents and generated outputs are retained per your account’s configured retention settings, after which they are deleted. Compliance certificates may be retained longer to support audit requests, consistent with your organization’s own retention needs.

7. Security

We use reasonable technical and organizational measures to protect account and document data, including encryption in transit and access controls. No method of transmission or storage is perfectly secure.

8. International Transfers

The Service is operated from and directed at business customers in the United States. We do not currently target users in the European Union or United Kingdom.

9. Your Rights

If you are a California resident, you may have rights under the CCPA/CPRA to know, delete, and correct personal information we hold, and to not be discriminated against for exercising these rights. We do not sell personal data. To make a request, contact contact@ccmbridge.com.

10. Children

The Service is a business tool directed at CCM operations professionals and is not directed at children under 13. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by an updated effective date. Continued use of the Service after a change constitutes acceptance.

12. Contact

contact@ccmbridge.com.

Under review. This document is currently under review by our legal team and may be updated before it is considered final.