Privacy Policy

RadSwift — Cloud Ultrasound Service · Version 1.0

Effective date: June 10, 2026

📡 RadSwift processes imaging data from your PACS via an encrypted cloud pipeline. Data is retained for a maximum of 24 hours, then permanently deleted. A Business Associate Agreement (BAA) is available for institutions that require one under HIPAA.

Publisher: RadSwift  |  Version: 1.0  |  Effective: June 10, 2026

Overview

RadSwift ("Service", "we", "us") is a cloud-based workflow automation service that receives ultrasound imaging data from your PACS, extracts measurements using AI, and returns structured report text to your reporting system. This policy describes what data we receive, how we handle it, and how we protect it.

This policy applies to the RadSwift cloud ultrasound service. For the RadSwift DXA desktop application — which processes data entirely locally — see the RadSwift DXA Privacy Policy.

1. What Data We Receive

When a study completes in your PACS and is routed to RadSwift, we receive:

We do not collect personal information about clinicians or staff beyond what is necessary to operate the service (e.g., the email address provided at setup for support communication).

2. How We Process Data

Imaging data received from your PACS is:

No patient data is stored beyond the 24-hour processing window. We do not use patient imaging data for AI model training, product development, or any purpose other than delivering the extraction service to your institution.

3. Patient Data and HIPAA

Because RadSwift receives and processes DICOM data that may contain Protected Health Information (PHI), RadSwift acts as a Business Associate under HIPAA for institutions that are Covered Entities or Business Associates.

4. Data Security

We implement the following technical safeguards:

5. Sub-processors

RadSwift uses the following sub-processor to deliver the Service:

We do not share patient data with any other third party.

6. Data Retention

Imaging data (DICOM files) and extracted measurement data are automatically and permanently deleted from our systems within 24 hours of receipt. Audit logs (which contain event metadata but not patient imaging data) are retained for 6 years in accordance with HIPAA requirements.

7. Changes to This Policy

We may update this Privacy Policy from time to time. Updated versions will be published at radswift.com/privacy-cloud.html with a revised effective date. We will notify active institutions of material changes in advance.

8. Applicable Law

This Privacy Policy is governed by the laws of the State of New York. If you are located in the European Economic Area or United Kingdom, you may have rights under the GDPR or UK GDPR — please contact us to discuss your specific situation.

9. Contact Us

For privacy questions, BAA requests, or security documentation, contact:

Last updated: June 10, 2026