Privacy Policy
Last Updated:
This Privacy Policy describes how Unity Senior Health Inc., doing business as Athos, collects, uses, processes, stores, and protects personal information when you use our AI-powered training platform.
1. Introduction and Scope
This Privacy Policy describes how Unity Senior Health Inc., doing business as Athos (“Athos,” “we,” “us,” or “our”), collects, uses, processes, stores, and protects personal information when you use our website at https://useathos.ai, our AI-powered training and performance platform, and related services (collectively, the “Services”).
Athos provides artificial intelligence tools for sales training, simulation, compliance scoring, call analysis, and performance optimization for organizations in regulated industries, including insurance and healthcare.
This Policy applies when you:
- Visit our website or application
- Use AI role-play, scoring, analytics, or training tools
- Upload or process recordings or transcripts
- Connect integrations
- Interact with our sales, marketing, or support teams
By using the Services, you acknowledge that you have read and understood this Policy.
2. Information We Collect
2.1 Information You Provide
We collect personal information you voluntarily provide, including:
- Name, email, phone number
- Company and role
- Login credentials (stored securely in hashed form)
- Billing and payment details (processed by third-party providers)
- Communications and support requests
- Training and simulation content
We do not intentionally collect sensitive personal data except where such data is included in Customer Data uploaded by users.
2.2 Customer Data and Call Content
Users may upload or process:
- Audio recordings
- Transcripts
- Simulated conversations
- Call metadata
- Participant identifiers
You are responsible for obtaining required legal consent for recording and processing such data.
2.3 Automatically Collected Data
We collect technical and usage data, including:
- IP address
- Browser and device
- Operating system
- Session activity
- Feature usage
- Log and diagnostic data
- Approximate geographic region
2.4 Third-Party Sources
We may receive data from:
- Public or commercial data sources
- Marketing and analytics partners
- Integration providers
3. Information Collected Through Integrations
Athos may integrate with third-party platforms such as:
- CRM systems
- Dialers and call tracking platforms
- Transcription services
- Cloud communication tools
- Meeting and recording platforms
When you authorize integrations, we may access:
- Recordings and transcripts
- Metadata
- Participant and contact information
- Usage and activity
We use this information only to deliver the Services. We do not sell or use integration data for advertising or unrelated purposes.
4. How We Use Information
We process data to:
- Provide and operate the Services
- Deliver AI simulations, scoring, and feedback
- Improve performance and training outcomes
- Support compliance and regulatory readiness
- Authenticate and manage accounts
- Provide customer support
- Improve security and reliability
- Analyze product usage
- Communicate with users
- Fulfill legal and regulatory obligations
5. Legal Bases for Processing
Where applicable, we rely on:
- Consent
- Contractual necessity
- Legitimate interests
- Legal obligations
Users may withdraw consent at any time.
6. Data Sharing and Third Parties
We may share data with:
6.1 Service Providers — Including hosting, AI infrastructure, analytics, payments, and customer support.
6.2 Infrastructure and AI Providers — To process recordings, simulations, and analytics.
6.3 Legal and Regulatory Authorities — Where required by law.
6.4 Corporate Transactions — In mergers, acquisitions, or financing.
We do not sell personal data.
7. Cookies and Tracking Technologies
We use cookies for:
- Authentication
- Performance
- Analytics
- Preferences
Users may manage cookie settings.
8. AI-Based Services
Athos uses artificial intelligence to:
- Simulate conversations
- Score and evaluate interactions
- Generate insights
- Improve training outcomes
Safeguards:
- Customer data is used only to provide the Services
- Aggregated and de-identified data may be used to improve models
- AI outputs are advisory
- Human oversight is expected
AI does not replace regulatory, legal, or employment decisions.
9. International Data Transfers
Data may be processed in the United States and other jurisdictions.
We implement appropriate safeguards, including:
- Contractual protections
- Secure infrastructure
- Compliance with applicable frameworks
10. Your Privacy Rights
Depending on jurisdiction, users may request:
Contact: support@useathos.ai
11. U.S. State-Specific Privacy Rights
Residents of certain states may have additional rights, including:
- Data access
- Correction
- Deletion
- Opt-out of sale or sharing
Athos does not sell personal data.
12. Children's Privacy
Services are not intended for individuals under 16.
13. Data Retention
We retain data only as necessary:
| Category | Retention |
|---|---|
| Account data | Duration of account + 90 days |
| Recordings | Up to 90 days after processing |
| Transcripts | Up to 90 days |
| AI insights | Duration of account |
| Logs | 12 months |
| Payment | 7 years |
| Support | 2 years |
Users may request deletion.
14. Encryption
- TLS 1.2+ in transit
- AES-256 at rest
- Secure key management
- Encrypted backups
15. Security Program
Athos maintains a security program aligned with:
- SOC2 principles
- OWASP standards
- Regular risk assessments
- Employee security training
16. Access Controls
- Least privilege
- Role-based access
- MFA for privileged users
- Logging and monitoring
17. Encryption
Sensitive data, API credentials, and tokens are encrypted and securely stored.
18. Application and Network Security
- Segmented environments
- Firewall and monitoring
- Secure SDLC
- Code reviews
- Vulnerability scanning
19. Incident Classification
Incidents are categorized by severity and impact.
20. Incident Response
Includes:
- Detection
- Containment
- Investigation
- Recovery
- Post-incident review
21. Incident Notification
Users and regulators are notified as required by law.
22. Vendor Management
22.1 Third-Party Dependencies — We maintain a vendor inventory and risk assessments.
22.2 Vendor Oversight — Critical vendors are reviewed regularly.
23. Vulnerability Management
23.1 Identification — Includes scanning, testing, and monitoring.
23.2 Remediation — Based on severity and risk.
23.3 Responsible Disclosure — Security researchers may contact: support@useathos.ai
24. Updates
We may update this policy. Continued use after updates means acceptance.
25. Contact
Unity Senior Health Inc.
Email: support@useathos.ai
Website: useathos.ai
For security disclosures: support@useathos.ai
Have questions about our privacy policy? Contact our support team