Xenter

Xenter Website & Business Privacy Notice

Last Updated: August 6, 2026

1. Introduction and Scope

Xenter, Inc. and its subsidiaries (“Xenter,” “we,” “us,” or “our”) respect your privacy and are committed to handling personal information responsibly.

This Privacy Notice describes how we collect, use, disclose, and process personal information in connection with:

  • Our corporate websites and digital platforms directed at healthcare providers, business partners, and the general public (including Xenter.io, XenterMD.com, and any other website that links to this Privacy Notice) (“Sites”);
  • Our relationships with healthcare provider customers and other business partners; and
  • Communications with users, customers, job applicants, and business contacts.

This Notice does not apply to XenME, Xenter’s consumer-facing health application, or to other services through which Xenter provides medical technology or clinical services directly to individual patients. Those services are addressed in the separate XenME Consumer Privacy Notice, available at xenter.io/xenme/privacy and within the XenME app.

Depending on the context in which we interact with you, Xenter may act as:

  • A business/controller — for website visitors, business contacts, job applicants, and healthcare provider customers;
  • A service provider/processor — when processing data on behalf of our healthcare provider customers in a non-HIPAA capacity (for example, account and billing administration); or
  • A HIPAA Business Associate — when we process protected health information (PHI) on behalf of HIPAA-covered healthcare providers pursuant to a Business Associate Agreement (“BAA”).

Your rights and our obligations may vary depending on which role applies to our interaction with you. Section 9 describes information we process as a HIPAA Business Associate.

3. Categories of Personal Information Collected

The following table summarizes the categories of personal information we collect through our Sites and B2B Services, the sources, our purposes, and to whom we disclose it. Retention periods are described in Section 11.

CategoryExamplesSourcesPurposesDisclosures

Identifiers

Name, business email, phone, IP address

Directly from you; Sites

Account management; communication; contracting

Vendors; healthcare provider customers

Internet & Network Activity

Browsing data, cookies, log files

Sites; analytics tools

Improve Sites; security; analytics

Analytics providers

Protected Health Information (processed as Business Associate)

Physiologic and diagnostic data processed on behalf of a covered healthcare provider

Healthcare provider customers, pursuant to a BAA

Providing contracted services to the covered healthcare provider

Only as directed by, or permitted under, the applicable BAA — see Section 9

Commercial Information

Account activity, order and billing history

Directly from you

Operations; customer support; billing

Service providers

Professional Information

Employer, job title, credentials

Directly from you; business partners

Customer engagement; contracting; recruiting

Business partners

Geolocation Data

Approximate location from IP address

Sites; devices

Security; compliance

IT/security vendors

Inferences

Profiles derived from the above

Derived internally

Service improvement; analytics

As described above

4. Sources of Personal Information

We collect personal information from the following sources:

  • Directly from you — when you visit our Sites, request information, create an account, contact us, or engage our B2B Services;
  • Healthcare provider customers — who engage Xenter to provide products and services, and, where applicable, disclose PHI to us as their Business Associate;
  • Vendors and business partners;
  • Publicly available sources; and
  • Website tracking technologies (see Section 10).

5. How We Use Personal Information

We process personal information for the following purposes:

  • Providing, operating, and improving our Sites, products, and B2B Services;
  • Supporting our healthcare provider customers, including performing our obligations as a Business Associate;
  • Conducting research, development, and quality improvement;
  • Communicating with users, customers, job applicants, and business contacts;
  • Maintaining system security, integrity, and fraud prevention;
  • Complying with legal and regulatory obligations; and
  • Analytics to develop new or improved products and services — using de-identified or aggregated data where possible (see Section 11).

When we de-identify or aggregate personal information so that it can no longer reasonably be used to identify you, we commit to maintain and use that information only in de-identified or aggregated form, and we take reasonable measures to prevent it from being re-identified. Once information has been de-identified or aggregated in this way, it is no longer “personal information,” and this Privacy Notice no longer applies to it.

6. Disclosure of Personal Information

We do not sell your personal information.

We may share personal information with the following categories of recipients:

  • Service providers — vendors that provide hosting, IT support, security, analytics, and other operational services on our behalf under contractual data protection obligations;
  • Healthcare provider customers — our contracting counterparties, including PHI we process on their behalf as a Business Associate;
  • Business partners — with whom we collaborate to deliver products or services, subject to contractual data protection terms;
  • Regulatory authorities and law enforcement — when required by applicable law, court order, or to protect legal rights; and
  • Successors — in connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.

We do not knowingly sell or share the personal information of minors under the age of 16.

We do not disclose personal information to third parties for their own direct marketing purposes.

7. Sensitive Personal Information

Certain categories of personal information we process in connection with our Sites and B2B Services are considered “sensitive” under applicable law, including protected health information we process as a Business Associate and, where applicable, geolocation data.

We collect and use sensitive personal information only for the following purposes:

  • Performing our contractual obligations to healthcare provider customers, including under an applicable BAA;
  • Complying with applicable law; and
  • Maintaining the security and integrity of our systems.

California residents may also request to limit the use of their sensitive personal information for purposes beyond those described above. Protected health information we process as a Business Associate is governed by the applicable BAA and HIPAA, and by the covered healthcare provider’s own HIPAA Notice of Privacy Practices, rather than by this Section.

8. Your U.S. Privacy Rights

Depending on your state of residence, you may have one or more of the rights described in the table below. These rights apply to personal information we process in our capacity as a business (controller) — for example, if you are a website visitor, job applicant, or business contact. For information we process as a Business Associate on behalf of a covered healthcare provider, different procedures apply (see Section 9).

RightDescriptionHow to Exercise

Access / Know

Request a copy of personal information we hold about you

Submit via email or web form

Delete

Request deletion of personal information

Submit via email or web form

Correct / Rectify

Request correction of inaccurate information

Submit via email or web form

Portability

Receive a copy in portable format

Submit via email or web form

Opt Out of Sale / Sharing

Opt out of sale or sharing of personal information for targeted advertising

We do not sell or share information for targeted advertising

Opt Out of Profiling

Opt out of profiling for significant decisions

We do not profile for significant decisions

Limit Sensitive PI Use

Limit use of sensitive personal information beyond certain purposes

Submit via email

Non-Discrimination

Exercise rights without discriminatory treatment

Automatic

A. How to Submit a Request

We will verify your identity before processing your request. We will respond within the timeframe required by your state’s law.

B. Appeals

If we deny your request, you may appeal our decision within 30 days by emailing privacy@xenter.io with “Privacy Rights Appeal” in the subject line. We will respond within the timeframe required by your state’s law. If your appeal is denied, you may contact your state’s Attorney General.

C. Global Privacy Control (GPC) and Opt-Out Signals

We recognize and honor browser-based opt-out preference signals, including Global Privacy Control (GPC), as required by applicable law. If we detect a GPC signal from your browser, we will treat it as a request to opt out of the sale or sharing of your personal information for targeted advertising purposes. Because we do not currently sell or share personal information for cross-context behavioral advertising (see Section 10), honoring a GPC signal has no practical effect on your experience of the Sites today. We are nonetheless configured to detect and honor GPC signals, and will apply them automatically if our practices change.

D. Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights. We will not deny services, charge different prices, or provide a different quality of service based solely on your exercise of privacy rights, except as permitted by law.

9. HIPAA and Information We Process as a Business Associate

When Xenter processes protected health information (PHI) on behalf of a HIPAA-covered healthcare provider pursuant to a Business Associate Agreement:

  • The covered healthcare provider is responsible for providing HIPAA Notices of Privacy Practices to patients;
  • The healthcare provider is responsible for fulfilling patient rights under HIPAA (access, amendment, accounting of disclosures, restriction requests, confidential communications); and
  • Patients with questions about their PHI in these contexts should contact their healthcare provider directly.

Delivering Results Directly to Patients

For certain diagnostic assessments Xenter performs on a healthcare provider's behalf — such as our Cognitive Assessment Program — the applicable Business Associate Agreement authorizes Xenter to ask the patient to use the XenME app so that we can deliver their results directly to them, in addition to delivering those results to the ordering provider. This direct-to-patient delivery is a disclosure to the individual that HIPAA permits (45 CFR §164.502(a)(1)(i)), made pursuant to, and only to the extent authorized by, the applicable BAA. The same BAA may also authorize Xenter to de-identify this information in accordance with HIPAA's de-identification standard (45 CFR §164.514), including for research, product development, and quality improvement.

10. Cookies and Tracking Technologies

We use cookies and similar technologies on our Sites for website functionality, performance, security, and analytics. These technologies include first-party cookies and service-provider technologies used to operate and optimize the Sites, monitor performance, understand aggregate website usage, and help protect the Sites from misuse. We do not currently use cookies or similar technologies on our Sites for targeted advertising, cross-context behavioral advertising, or third-party advertising networks. Embedded third-party content on our Sites (such as video players) may set cookies governed by those third parties’ own privacy policies, which we do not control.

Our primary website analytics tool identifies visitors through anonymized, ephemeral request hashes rather than persistent cookies. This approach does not enable cross-site tracking or persistent identification of individual visitors.

These technologies may collect or generate information such as IP address, device and browser information, pages visited, referring pages, timestamps, diagnostic data, and approximate location derived from IP address. We use this information to make our Sites function, measure and improve site performance, maintain security, troubleshoot issues, and understand how visitors interact with our content.

You can control cookies through your browser settings. If you disable or block cookies, some website features may not function properly.

11. Data Retention

We retain personal information for the periods set forth below, or longer if required by law:

Data CategoryRetention Period

Identifiers and account information

Duration of business relationship + 3 years, or as required by applicable law

Protected health information processed as a Business Associate

As specified in the applicable Business Associate Agreement, and in accordance with HIPAA

Internet activity and website data

13 months from collection, unless a shorter period is required by law

Professional and commercial information

Duration of business relationship + 3 years

Records of privacy rights requests

2 years from date of request

De-identification for Research and Analytics

We may retain de-identified or aggregated data for longer periods for research, analytics, and product and service development. See Section 5 for our commitments regarding de-identified and aggregated information.

12. Data Security

We have implemented commercially reasonable technical, administrative, and physical security safeguards designed to protect your personal information from unauthorized access, use, disclosure, deletion, and modification. These measures include encryption of data in transit and at rest, access controls, and regular security assessments.

No security measures are perfect or impenetrable, and we cannot guarantee that your information will not be accessed, disclosed, altered, or destroyed by a breach of our safeguards.

Where Xenter processes PHI as a HIPAA Business Associate, we will notify our covered-entity healthcare provider customers of any breach of unsecured PHI within the timeframe required by the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D), to enable those providers to fulfill their patient and HHS notification obligations. We will also comply with applicable U.S. state breach notification laws, which impose varying timelines (generally 30–90 days) and scope requirements across all 50 states and territories.

13. Children's Privacy

Our Sites are general-audience platforms not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13 through our Sites. If you believe we have inadvertently collected personal information from a child without appropriate consent, please contact us at privacy@xenter.io and we will take prompt steps to delete that information.

14. International Data Transfers

Xenter is headquartered in the United States. If you are accessing our Sites or B2B Services from outside the United States, your personal information may be transferred to, stored in, and processed in the United States or other jurisdictions where data protection laws may differ from those in your home country.

15. California “Shine the Light” Notice

Under California Civil Code §1798.83, California residents may request certain information about disclosures of personal information to third parties for direct marketing purposes.

Xenter does not disclose personal information to third parties for their own direct marketing purposes. Accordingly, no such disclosure list exists.

16. Changes to This Privacy Notice

We may update this Privacy Notice periodically to reflect changes in our practices, applicable law, or other operational, legal, or regulatory requirements. Changes will be reflected by updating the “Last Updated” date at the top of this Notice. For material changes affecting how we handle your personal information, we will provide additional notice (such as by email or a prominent website notice) where required by law.

We encourage you to review this Notice periodically to stay informed about how we handle your information.

17. Contact Information

For questions about this Privacy Notice, to exercise your privacy rights, or to raise a concern about our data practices, please contact:

Xenter, Inc.

344 West 13800 South, Suite 400

Draper, Utah 84020, United States

If you are a patient using XenME or otherwise receiving Xenter’s medical technology services directly, please see the XenME Consumer Privacy Notice at xenter.io/xenme/privacy.