This Privacy Policy explains the categories of information that may be collected, used, stored, and disclosed when you use the Victor Evidence website, contact us about research, or, where separately approved, create and use an account for the limited research prototype used to test and evaluate VictorMind and Victor Evidence (the “Research Prototype”).
This Policy should be read together with the Terms of Use, Acceptable Use Policy, and any additional research notice, consent form, or participation agreement provided for a particular study or evaluation.
1. Information You Provide
Depending on how you interact with the website or Research Prototype, information you provide may include:
- your name, email address, professional or organizational information, and other information included in a research inquiry or communication;
- account-registration and account-administration information for approved participants;
- acknowledgments, consents, or confirmations associated with authorized research participation or account activation;
- messages, questions, prompts, feedback, and other information you intentionally submit through the Research Prototype; and
- communications sent through the Contact page or other authorized communication channels.
Do not provide information that you are not authorized to disclose.
2. Account, Authentication, and Security Information
For approved Research Prototype accounts, systems may process information necessary to create, authenticate, secure, and administer the account. This may include account identifiers, email address, password-related authentication records, account role and status, activation status, authenticator/TOTP enrollment status, session records, login timestamps, expiration or revocation information, and security or audit events.
Passwords and authenticator setup secrets should be handled using appropriate security controls. Users must not send passwords, authenticator setup secrets, one-time authentication codes, or active session credentials through the public Contact page.
3. Research Prototype Interactions
During the current limited testing phase, approved participant interactions may be temporarily retained only as reasonably necessary to verify that VictorMind and Victor Evidence are functioning, retrieving evidence, and displaying results as intended. Temporary testing records may include submitted prompts or questions, system responses, research-session identifiers, interaction timestamps, evidence-retrieval or evidence-selection records, source references, and other system-generated technical or evaluation information.
The current testing process is not intended to create patient records, patient profiles, a medical-information database, or a permanent repository of participant questions and responses. Testing interaction data is intended to be deleted when it is no longer needed for the applicable testing and evaluation purpose. Account, authentication, security, audit, and legally required records may have separate retention periods. The temporary research-data collection functionality may be disabled when the applicable testing and evaluation phase is completed.
4. VictorMind Working Context and Account Separation
The Research Prototype may maintain temporary working context or state associated with an authenticated participant in order to support the participant's active interaction with the system. Account authentication and access controls are used to associate authorized working context with the appropriate account.
Temporary working context is distinct from shared research resources and from research records retained for authorized research or administrative purposes. Ending or resetting an active working context does not necessarily delete research records that are retained under the applicable research notice, consent, security, or retention process.
5. Technical, Security, and Diagnostic Information
Systems used to operate and secure the website and Research Prototype may process ordinary technical and diagnostic information, such as request information, timestamps, IP or network information where generated by infrastructure, browser or device information where available, application logs, error information, security events, authentication events, and other operational data reasonably necessary to provide, protect, troubleshoot, and administer the service.
6. How Information May Be Used
Information covered by this Policy may be used, as applicable, to:
- respond to research inquiries and other communications;
- review, approve, administer, enable, disable, secure, or terminate authorized research access;
- create and administer participant accounts and authentication;
- operate, maintain, secure, troubleshoot, and improve the website and Research Prototype;
- conduct the disclosed testing and evaluation of VictorMind and Victor Evidence;
- temporarily inspect research interactions and system behavior as necessary to verify system operation, retrieval, evidence handling, display, debugging, and evaluation;
- detect, investigate, and prevent security incidents, fraud, abuse, unauthorized access, and policy violations;
- maintain appropriate research, security, audit, and administrative records; and
- comply with applicable legal obligations and valid legal process.
7. Patient Information, PHI, and Sensitive Medical Information
Do not submit patient-identifiable information, protected health information (“PHI”), medical records, confidential patient case details, or other regulated patient information through the public website, Contact page, or any Research Prototype feature that has not been expressly authorized for that purpose.
The public website and ordinary research access do not, by themselves, establish a HIPAA-compliant environment, a business associate relationship, or authorization to submit PHI. Any activity involving regulated or sensitive medical information requires an expressly authorized environment and the technical, contractual, institutional, ethical, privacy, and legal controls applicable to that activity.
8. Service Providers and Infrastructure
Information may be processed by service providers used to host, operate, secure, communicate with, or support the website and Research Prototype. Depending on the services actually used, these may include hosting or cloud infrastructure, database providers, authentication or security infrastructure, communications or email providers, language-model or AI service providers, and other technical vendors.
Service providers may process information only as permitted by their applicable agreements, service terms, privacy obligations, and the configuration of the Research Prototype. This Policy does not expand a service provider's rights to information.
9. Other Disclosures
Information may also be disclosed where reasonably necessary and permitted by applicable law to protect the security, integrity, rights, or safety of the website, Research Prototype, participants, operator, or others; investigate suspected misuse or security incidents; enforce applicable terms or agreements; establish or defend legal claims; or comply with applicable law, court orders, governmental requests, or other valid legal process.
10. Sale and Targeted Advertising
Personal information collected through research inquiries, approved participant accounts, or Research Prototype interactions is not collected for the purpose of selling participant information or operating a targeted-advertising business. If practices materially change, this Policy must be updated as required before or when those new practices are implemented, and any legally required choices or notices must be provided.
11. Research Results and De-Identified or Aggregated Information
The current testing phase is not intended to build a permanent participant-interaction dataset or to create patient profiles. If aggregated or de-identified testing results are later used for research reporting, evaluation, or publication, that use must be consistent with the applicable research notice, consent or participation terms, and law.
De-identification and aggregation reduce identification risk but should not be represented as eliminating every possible re-identification risk unless that conclusion is supported by the applicable method and legal standard.
12. Retention
Research Prototype questions, responses, evidence-related testing records, and associated technical evaluation data are intended to be retained temporarily during the current testing phase and deleted when they are no longer reasonably needed to verify system operation, investigate testing results, debug problems, or complete the applicable evaluation.
Temporary testing records and VictorMind working context have different lifecycles from account, authentication, security, audit, legal, and administrative records. Those separate records may be retained for as long as reasonably necessary for their applicable purpose or as required by law. Logging out, starting a new chat, resetting working context, disabling an account, or deleting temporary testing interactions does not necessarily delete those separate records.
No fixed retention period is promised unless one is expressly stated for a particular study or category of information. Where a specific research notice, consent document, institutional requirement, agreement, or applicable law establishes a retention or deletion requirement, that requirement controls for the affected information.
13. Security
Reasonable administrative, technical, and organizational safeguards are used or should be maintained according to the nature of the information and the Research Prototype. These may include authentication, access controls, session management, account separation, encryption or protected storage where appropriate, audit controls, and administrative access restrictions.
No internet transmission, software system, authentication mechanism, database, or storage method can be guaranteed to be completely secure. Users are responsible for protecting their own credentials and promptly reporting suspected compromise.
14. Privacy Requests and Rights
Depending on where you reside and which laws apply, you may have rights concerning personal information, which may include rights to request access, correction, deletion, or other treatment of certain information, as well as rights concerning particular processing activities. These rights are subject to applicable exceptions, verification requirements, research exemptions, record-retention obligations, and other legal limitations.
Privacy questions or requests may be submitted through the Contact page. We may need to verify identity or authority before acting on a request.
15. International Processing
The website, Research Prototype, infrastructure, or service providers may process information in jurisdictions different from the participant's location. Privacy and data-protection laws differ by jurisdiction. Where applicable law requires particular safeguards for international transfers, those requirements must be addressed for the affected processing.
16. Children and Minors
The Research Prototype is intended for approved adult research participants and is not directed to children. Do not create an account or participate in the research program if you lack legal capacity to agree to the applicable terms and research conditions. The Research Prototype should not be used to submit information about minors unless that specific activity has been expressly authorized and all applicable legal, ethical, institutional, and consent requirements have been satisfied.
17. Third-Party Websites and Sources
The website or Research Prototype may contain links, citations, or references to third-party websites, publications, or services. Their privacy practices are governed by their own policies. This Privacy Policy does not control independent third-party websites or services except to the extent information is processed on behalf of the Research Prototype under an applicable service arrangement.
18. Security and Privacy Incidents
If a privacy or security incident affecting information is identified, it may be investigated and addressed in accordance with applicable legal, contractual, research, and security requirements. Notifications will be made where and to the extent required by applicable law or agreement.
19. Changes to This Privacy Policy
This Policy may be revised as the website, Research Prototype, research program, infrastructure, or legal requirements evolve. The effective date will be updated when changes are made. Where applicable law, a research consent, or an agreement requires additional notice or consent for a material change, that process will be followed.
20. Contact
Privacy questions, requests, or concerns may be submitted through the Contact page.