Legal

Kirklin Solutions Privacy Policy

Effective Date: August 25, 2026 · Last Updated: August 25, 2026

1. Purpose and Scope

Kirklin Solutions, Inc. (“Kirklin Solutions,” “we,” “us,” or “our”) respects the privacy of individuals whose personal information we collect, use, maintain, or process.

This Privacy Policy explains how Kirklin Solutions collects, uses, discloses, protects, retains, and otherwise processes personal information when individuals:

  • Visit or use our websites;
  • Use our applications, software, platforms, or services;
  • Communicate with us;
  • Become or remain a customer, user, subscriber, vendor, or business contact;
  • Apply for employment or work with Kirklin Solutions; or
  • Otherwise interact with Kirklin Solutions.

This Privacy Policy applies to personal information processed by Kirklin Solutions in its role as a business, data controller, or data processor, as applicable.

Kirklin Solutions may process information relating to employees, prospective employees, customers, users and visitors to its websites, subscribers, vendors, and other stakeholders. Our privacy practices are designed to address applicable privacy and data protection requirements.

Where Kirklin Solutions processes information on behalf of a customer or other data controller, that processing may also be governed by the applicable contract, Data Processing Agreement (“DPA”), Business Associate Agreement (“BAA”), or other written agreement.

2. Applicable Privacy and Data Protection Laws

Kirklin Solutions complies with applicable privacy and data protection laws based on the nature and location of the individuals, data, and processing activities involved.

Depending on the circumstances, applicable requirements may include:

  • General Data Protection Regulation (GDPR);
  • UK GDPR and applicable UK data protection law;
  • California Consumer Privacy Act (CCPA), as amended by applicable California privacy legislation;
  • Australia Privacy Act and applicable Australian privacy requirements;
  • Brazil General Data Protection Law (LGPD);
  • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA);
  • Quebec privacy requirements;
  • Singapore Personal Data Protection Act;
  • Argentina Personal Data Protection Law; and
  • Other applicable federal, state, provincial, national, or regional privacy laws.

Kirklin Solutions maintains privacy practices intended to address the requirements applicable to its activities and the jurisdictions in which it operates.

3. Information We Collect

The types of information we collect depend on how an individual interacts with Kirklin Solutions.

3.1 Personal Information

We may collect personal information that can identify, relate to, describe, or reasonably be associated with an individual. This may include:

  • Name;
  • Business or personal email address;
  • Telephone number;
  • Business or organizational information;
  • Job title or role;
  • Account and authentication information;
  • Information submitted through forms or communications;
  • Information relating to employment or business relationships;
  • IP address and device information;
  • Website and application usage information; and
  • Other information voluntarily provided to us.

3.2 Usage and Technical Information

When individuals access our websites, applications, or services, we may collect technical and usage information, including:

  • IP address;
  • Browser type;
  • Operating system;
  • Device type;
  • Date and time of access;
  • Pages or services accessed;
  • Referring websites;
  • Diagnostic information;
  • Log information;
  • Security and authentication events; and
  • Other information necessary to maintain and secure our services.

3.3 Cookies and Similar Technologies

Kirklin Solutions may use cookies, web beacons, scripts, tags, and similar technologies to operate, secure, maintain, and analyze our websites and services.

Cookies may be used to:

  • Maintain website functionality;
  • Remember preferences;
  • Support authentication;
  • Analyze website usage;
  • Detect security issues; and
  • Improve the performance and functionality of our services.

Where required by applicable law, Kirklin Solutions will obtain consent before using non-essential cookies or similar tracking technologies.

Individuals may configure their browsers to reject or notify them about cookies. Disabling certain cookies may affect the functionality of portions of our websites or services.

4. Healthcare and Sensitive Information

Kirklin Solutions provides technology and services that may involve healthcare-related information. Where Kirklin Solutions processes protected health information (“PHI”) on behalf of a healthcare organization or other covered entity, such processing may be subject to the Health Insurance Portability and Accountability Act (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), applicable state privacy laws, and the terms of an applicable BAA.

Kirklin Solutions will process PHI only for permitted purposes and in accordance with applicable contractual and legal requirements.

Healthcare information received or processed on behalf of a customer is not necessarily information that Kirklin Solutions independently controls. In these circumstances, the applicable healthcare organization or other customer may remain the data controller or covered entity, while Kirklin Solutions acts as a service provider, data processor, or business associate.

5. How We Use Personal Information

Kirklin Solutions may use personal information for legitimate business, contractual, operational, security, and legal purposes, including to:

  • Provide, operate, maintain, and support our services;
  • Establish and manage user accounts;
  • Authenticate and authorize users;
  • Communicate with customers, users, and business contacts;
  • Respond to questions, requests, and support inquiries;
  • Perform contractual obligations;
  • Manage customer and vendor relationships;
  • Maintain and improve our websites, applications, and services;
  • Develop and improve products and services;
  • Monitor and analyze service usage;
  • Detect, investigate, and prevent security incidents, fraud, abuse, or unauthorized activity;
  • Maintain system and network security;
  • Meet legal and regulatory obligations;
  • Establish, exercise, or defend legal claims;
  • Maintain business records;
  • Conduct audits and compliance activities; and
  • Perform other purposes disclosed at the time information is collected.

Kirklin Solutions does not use personal information for purposes that are incompatible with the purposes for which it was collected unless permitted or required by applicable law.

6. Lawful Basis for Processing

Where applicable, Kirklin Solutions identifies and documents the lawful basis for processing personal information. Depending on the circumstances, processing may be based on:

  • Consent;
  • Performance of a contract;
  • Compliance with a legal obligation;
  • Protection of vital interests;
  • Performance of a task carried out in the public interest; or
  • Legitimate interests, where those interests are not overridden by the rights and freedoms of the individual.

Where processing is based on consent, individuals may withdraw consent where permitted by applicable law. The withdrawal of consent does not affect the lawfulness of processing that occurred before consent was withdrawn.

Kirklin Solutions maintains procedures for identifying and documenting the applicable legal basis for processing.

7. Privacy and Data Protection Principles

Kirklin Solutions follows core privacy principles when processing personal information, including:

  1. Lawfulness, fairness, and transparency — Personal information is processed lawfully, fairly, and transparently.
  2. Purpose limitation — Information is collected for specified, explicit, and legitimate purposes.
  3. Data minimization — We seek to collect only information that is adequate, relevant, and reasonably necessary.
  4. Accuracy — Reasonable measures are taken to maintain accurate and current information.
  5. Storage limitation — Information is retained only as long as reasonably necessary for its purpose or as required by law or contract.
  6. Integrity and confidentiality — Appropriate technical and organizational safeguards are used to protect personal information against unauthorized access, unlawful processing, loss, destruction, or damage.

These principles are consistent with the privacy and data protection principles established in Kirklin Solutions' internal privacy policy.

8. Disclosure and Sharing of Personal Information

Kirklin Solutions may disclose personal information when reasonably necessary and permitted by applicable law. Information may be shared with:

  • Customers and organizations for whom we provide services;
  • Service providers and technology vendors that support our operations;
  • Cloud hosting and infrastructure providers;
  • Security, compliance, and auditing providers;
  • Professional advisers;
  • Legal counsel;
  • Government agencies, regulators, or law enforcement when legally required;
  • Other parties when necessary to protect the rights, safety, security, or property of Kirklin Solutions, our customers, users, or others; and
  • Other parties with the individual's authorization or as otherwise permitted by law.

Kirklin Solutions requires appropriate contractual protections for relationships involving the processing of personal information. Where required, contracts may include data processing terms, confidentiality requirements, security requirements, BAAs, DPAs, or other legally required provisions. Kirklin Solutions does not sell personal information for monetary consideration.

9. Data Processors and Service Providers

When Kirklin Solutions uses third-party service providers to process personal information, we seek to ensure that the provider processes information only for authorized purposes and maintains appropriate safeguards.

Where required by applicable law, Kirklin Solutions enters into appropriate contractual arrangements with processors and service providers.

Where Kirklin Solutions acts as a data processor or business associate, we will process personal information according to the documented instructions of the applicable data controller or covered entity and the terms of the applicable agreement.

10. Information Security

Kirklin Solutions recognizes that protecting personal information requires appropriate administrative, technical, and physical safeguards. Depending on the nature of the information and applicable requirements, safeguards may include:

  • Access controls and role-based permissions;
  • Authentication and multi-factor authentication;
  • Encryption;
  • Secure cloud infrastructure;
  • System monitoring and logging;
  • Vulnerability management;
  • Security testing and assessments;
  • Backup and recovery controls;
  • Incident response procedures;
  • Employee security and privacy training;
  • Confidentiality requirements; and
  • Security policies and procedures.

Although Kirklin Solutions uses reasonable safeguards to protect personal information, no electronic transmission, information system, or storage technology can be guaranteed to be completely secure.

11. Data Retention

Kirklin Solutions retains personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, satisfy contractual obligations, comply with legal and regulatory requirements, resolve disputes, enforce agreements, maintain appropriate business records, and protect our legitimate interests. Retention periods may vary depending on:

  • The type and sensitivity of the information;
  • The purpose for which it was collected;
  • Contractual requirements;
  • Legal and regulatory requirements;
  • Customer requirements; and
  • Security, audit, and business requirements.

Kirklin Solutions maintains retention schedules and considers retention requirements as part of its privacy and data protection program. When information is no longer required, it will be securely deleted, destroyed, anonymized, or otherwise disposed of in accordance with applicable requirements.

12. International Transfers

Kirklin Solutions may process or store personal information in countries other than the country in which the individual resides. Where personal information is transferred internationally, Kirklin Solutions will evaluate the applicable legal requirements and implement appropriate safeguards where required. Depending on the circumstances, safeguards may include:

  • An adequacy decision;
  • Standard Contractual Clauses;
  • Data Processing Agreements;
  • Other legally recognized transfer mechanisms; or
  • Applicable statutory or regulatory exceptions.

International transfers are reviewed in accordance with applicable privacy laws before or during the transfer process.

13. Your Privacy Rights

Depending on the individual's location and applicable law, individuals may have rights regarding their personal information. These rights may include:

  • The right to know or be informed about the collection and use of personal information;
  • The right to access personal information;
  • The right to request correction or rectification;
  • The right to request deletion or erasure;
  • The right to restrict processing;
  • The right to data portability;
  • The right to object to certain processing;
  • The right to withdraw consent where processing is based on consent;
  • The right to opt out of certain sales or sharing of personal information where applicable; and
  • Rights concerning automated decision-making and profiling where applicable.

These rights are subject to applicable legal limitations and exceptions. Kirklin Solutions may need to verify the identity of an individual before fulfilling a privacy request. Individuals may contact Kirklin Solutions using the contact information provided in this Privacy Policy to exercise applicable rights. Kirklin Solutions maintains procedures for responding to privacy requests within the timeframes required by applicable law.

14. California Privacy Rights

California residents may have additional rights under the California Consumer Privacy Act (“CCPA”) and other applicable California privacy laws.

Subject to applicable exceptions, California residents may have the right to:

  • Know what categories of personal information are collected;
  • Know the purposes for which personal information is used;
  • Request access to personal information;
  • Request deletion of personal information;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information, where applicable; and
  • Receive equal treatment for exercising applicable privacy rights.

Kirklin Solutions does not sell personal information for monetary consideration. Requests may be submitted using the contact information provided below.

15. European Economic Area and United Kingdom Privacy Rights

Individuals located in the European Economic Area or United Kingdom may have additional rights under the GDPR, UK GDPR, and applicable data protection laws.

These may include rights of:

  • Access;
  • Rectification;
  • Erasure;
  • Restriction of processing;
  • Data portability;
  • Objection;
  • Withdrawal of consent; and
  • Rights relating to automated decision-making and profiling.

Where required, Kirklin Solutions will provide information regarding the applicable processing activities, legal basis, retention period, recipients, and international transfers.

16. Children's Privacy

Kirklin Solutions does not knowingly collect personal information directly from children under the age of 13 through its general websites or services. However, certain Kirklin Solutions services may support healthcare organizations or other customers whose services involve children or pediatric populations.

In those circumstances, information relating to a child may be processed on behalf of the applicable healthcare organization or customer and subject to the applicable contractual, legal, parental, guardian, and healthcare requirements.

If Kirklin Solutions becomes aware that personal information was collected directly from a child without appropriate authorization or consent where required, we will take reasonable steps to investigate and address the situation, including deletion where appropriate and legally permitted.

17. Privacy by Design

Kirklin Solutions incorporates privacy considerations into the design and development of new or significantly modified systems, products, services, and processes that collect or process personal information.

Where appropriate, Kirklin Solutions may conduct a Privacy Impact Assessment (“PIA”) or Data Protection Impact Assessment (“DPIA”) to evaluate:

  • What personal information will be processed;
  • Why the information is needed;
  • Whether processing is necessary and proportionate;
  • Potential risks to individuals;
  • Appropriate technical and organizational safeguards;
  • Data minimization requirements;
  • Encryption and pseudonymization opportunities; and
  • Retention and secure disposal requirements.

These practices are consistent with Kirklin Solutions' privacy-by-design requirements.

18. Data Breach and Security Incident Notification

Kirklin Solutions maintains procedures for identifying, investigating, responding to, and documenting security and privacy incidents involving personal information.

If a personal data breach occurs, Kirklin Solutions will assess the incident and provide notifications to affected customers, individuals, regulators, or other parties when required by applicable law or contractual obligations.

Where Kirklin Solutions acts as a data processor or business associate, we will notify the applicable data controller or covered entity in accordance with the applicable agreement and legal requirements.

Where GDPR notification requirements apply, Kirklin Solutions will evaluate whether notification to the applicable supervisory authority is required, including the applicable 72-hour requirement where applicable.

Security and privacy incidents are managed in accordance with Kirklin Solutions' applicable incident response procedures.

19. Data Protection Officer and Privacy Responsibility

Kirklin Solutions maintains designated responsibility for privacy and data protection activities. Where a Data Protection Officer (“DPO”) is required by applicable law, Kirklin Solutions will appoint an appropriately qualified DPO or obtain appropriate external DPO services. Privacy responsibilities may include:

  • Monitoring compliance with applicable privacy requirements;
  • Supporting privacy assessments;
  • Advising on data protection obligations;
  • Supporting responses to privacy requests;
  • Reviewing privacy-related risks;
  • Supporting breach response;
  • Coordinating with customers, processors, regulators, and other relevant parties; and
  • Supporting privacy training and awareness.

20. Records of Processing Activities

Kirklin Solutions maintains appropriate documentation relating to its processing of personal information. Where required, records may include:

  • Categories of individuals whose information is processed;
  • Categories of personal information;
  • Purposes of processing;
  • Legal basis for processing;
  • Categories of recipients;
  • International transfer mechanisms;
  • Retention periods;
  • Security and privacy controls; and
  • Other information required by applicable privacy laws.

These records support Kirklin Solutions' accountability and privacy compliance obligations.

21. Confidentiality and Contracts

Kirklin Solutions requires appropriate confidentiality and contractual protections when personnel, vendors, service providers, or other third parties have access to personal information. Relationships involving the processing of personal information will be governed by appropriate agreements where required, including DPAs, BAAs, confidentiality agreements, service agreements, or other contractual provisions.

22. Changes to This Privacy Policy

Kirklin Solutions may update this Privacy Policy periodically to reflect changes in our services, business practices, technology, or applicable legal and regulatory requirements. When material changes are made, Kirklin Solutions will provide appropriate notice, including by posting an updated Privacy Policy on the applicable website. The “Last Updated” date at the beginning of this Privacy Policy identifies when the policy was most recently revised.

23. Contact Us

Questions, concerns, or requests regarding this Privacy Policy or the processing of personal information may be directed to:

Kirklin Solutions, Inc.
Privacy and Data Protection Contact
General information email: info@kirso-admin.net
Security concerns email: security@kirso-admin.net

Individuals may use this address to submit applicable privacy rights requests, privacy questions, or concerns regarding the handling of personal information.

24. Policy Review

Kirklin Solutions reviews its privacy and data protection practices periodically and at least annually to help ensure that its policies, procedures, and controls remain appropriate and aligned with applicable legal, regulatory, contractual, and organizational requirements.