Quality

Privacy Policy

Intrinsic Imaging, LLC · Effective Date: October 1, 2026 · Policy Owner: Todd Joron, President & CEO

1. Purpose

Intrinsic Imaging, LLC (“Intrinsic Imaging,” “we,” “us,” or “our”) is committed to protecting the privacy, confidentiality, integrity, and availability of personal information entrusted to us.

This Privacy Policy describes how Intrinsic Imaging collects, uses, processes, stores, protects, discloses, retains, and disposes of personal information in connection with our websites, applications, cloud-based services, clinical and medical imaging services, business operations, and other services (collectively, the “Services”).

Our privacy and information security practices are designed to align, as applicable, with internationally recognized information security and privacy principles, including ISO/IEC 27001:2022 and ISO/IEC 27018:2025.

This Policy should be read together with any applicable contractual privacy terms, Data Processing Agreements (“DPAs”), Business Associate Agreements (“BAAs”), Notices of Privacy Practices, informed-consent documentation, and other notices provided in connection with particular Services.

2. Scope

This Policy applies to personal information processed by Intrinsic Imaging in its capacity as a data controller, business, covered entity, service provider, processor, business associate, cloud service provider, or other applicable role under relevant privacy and data-protection laws.

Depending on the Services provided, Intrinsic Imaging may process personal information on its own behalf or on behalf of customers, healthcare organizations, pharmaceutical companies, biotechnology companies, medical-device companies, clinical research organizations, research sponsors, investigators, and other organizations.

When Intrinsic Imaging processes personal information solely on behalf of a customer, the customer generally determines the purposes and means of the processing, subject to applicable law and contractual requirements. In those circumstances, Intrinsic Imaging processes the information according to documented instructions from the customer and applicable contractual obligations.

3. Categories of Personal Information

Depending on an individual's relationship with Intrinsic Imaging and the Services involved, we may process the following categories of personal information:

Identification and Contact Information. Name, business or residential address, email address, telephone number, username, account identifiers, professional title, employer, and similar information.

Healthcare and Clinical Information. Medical images, imaging metadata, clinical information, medical history, treatment information, clinical-trial information, study identifiers, health-related information, and other information associated with medical or clinical services.

Protected Health Information. Information that constitutes Protected Health Information (“PHI”) under the U.S. Health Insurance Portability and Accountability Act (“HIPAA”), when applicable.

Research and Clinical-Trial Information. Subject or participant identifiers, pseudonymized identifiers, study information, imaging data, clinical measurements, trial-related records, and associated metadata.

Technical and Device Information. IP addresses, device identifiers, browser information, operating-system information, authentication records, system logs, security logs, and information regarding interactions with our systems and Services.

Business Information. Information relating to customers, vendors, contractors, investigators, healthcare professionals, and other business contacts.

Employment and Contractor Information. Information concerning employees, applicants, contractors, and consultants, where applicable and subject to separate notices or policies.

We seek to collect and process only personal information that is reasonably necessary and proportionate for legitimate and authorized purposes.

4. Sources of Personal Information

We may obtain personal information directly from individuals; from our customers and their authorized representatives; from healthcare providers and healthcare organizations; from clinical-trial sponsors, contract research organizations, investigators, and research sites; from pharmaceutical, biotechnology, and medical-device companies; through authorized integrations, applications, systems, and cloud services; automatically through use of our websites, networks, systems, and Services; and from other sources authorized by applicable law, contract, or the individual.

Where Intrinsic Imaging processes information on behalf of a customer, the customer is responsible for ensuring that it has the appropriate authority and lawful basis to provide the information to us.

5. Purposes of Processing

Intrinsic Imaging may process personal information for purposes including providing, operating, maintaining, and improving our Services; performing medical imaging, imaging analysis, clinical-trial support, and related services; managing clinical and research studies; authenticating users and managing accounts; providing technical and customer support; fulfilling contractual obligations; communicating with customers, users, vendors, and business partners; protecting the security, confidentiality, integrity, and availability of our systems and information; detecting, investigating, preventing, and responding to security incidents, fraud, misuse, or unlawful activity; maintaining business and operational records; meeting legal, regulatory, contractual, quality-management, and compliance obligations; conducting authorized audits and assessments; establishing, exercising, or defending legal claims; and other purposes disclosed to individuals or authorized by applicable law.

Intrinsic Imaging does not process customer personal information for purposes materially incompatible with the purposes for which the information was provided unless authorized by the customer, the individual, or applicable law.

6. Processing Instructions and Purpose Limitation

When Intrinsic Imaging acts as a processor or service provider on behalf of a customer, we process personal information according to the customer's documented instructions, applicable agreements, and legal requirements.

We do not independently use customer-provided personal information for advertising or unrelated commercial purposes unless such processing has been expressly authorized and is permitted by applicable law and contract.

If we cannot comply with a customer's instruction because we reasonably believe that doing so would violate applicable law or compromise information security, we may notify the customer as permitted or required by law.

7. Data Minimization

Intrinsic Imaging applies data-minimization principles to the collection and processing of personal information.

We seek to limit personal information to what is adequate, relevant, and reasonably necessary for authorized business, clinical, research, contractual, security, and legal purposes.

Where feasible and appropriate, Intrinsic Imaging may use de-identification, anonymization, aggregation, masking, or pseudonymization techniques to reduce privacy risks.

8. Information Security

Intrinsic Imaging maintains administrative, organizational, physical, and technical safeguards designed to protect information against unauthorized access, acquisition, disclosure, alteration, loss, destruction, or misuse.

Our information security program is designed around risk-based information security principles and may include, as appropriate, access controls and role-based authorization; identity and authentication controls; multi-factor authentication; encryption of sensitive information in transit and at rest; network and infrastructure security controls; security monitoring and logging; vulnerability management; patch and configuration management; endpoint security; secure development and change-management practices; backup and recovery controls; business continuity and disaster-recovery planning; supplier and third-party security management; security awareness and privacy training; incident detection and response; risk assessments; periodic security reviews, testing, and audits; and processes for continually improving our information security management practices.

Security controls are selected and implemented based on factors including information sensitivity, processing risks, contractual requirements, applicable laws, technological capabilities, and the nature of the Services.

No information system or method of electronic transmission can be guaranteed to be completely secure. Intrinsic Imaging therefore continually evaluates and manages information-security risks.

9. Cloud Privacy and Protection of PII

Where Intrinsic Imaging provides or uses public-cloud services involving personal information, we maintain privacy and security measures designed to address risks associated with cloud processing.

As applicable, these measures include processing personal information only for authorized purposes; maintaining documented responsibilities for handling personal information; restricting access according to legitimate business need; maintaining appropriate security controls for cloud environments; maintaining records relevant to the processing of personal information; managing subprocessors and cloud-service providers; supporting secure return, transfer, deletion, or disposal of personal information; maintaining incident-management processes; providing appropriate transparency concerning processing activities; and supporting customers in meeting applicable privacy and security obligations.

10. Disclosure of Personal Information

Intrinsic Imaging may disclose personal information to customers and authorized users when necessary to provide Services or fulfill contractual obligations; service providers and subprocessors providing hosting, infrastructure, security, communications, support, analytics, professional, or other services on our behalf; healthcare, clinical, and research organizations where necessary and authorized; professional advisers such as attorneys, accountants, auditors, and insurers; governmental or regulatory authorities where required or authorized by law; and participants in an actual or proposed merger, acquisition, financing, reorganization, sale of assets, or similar transaction, subject to appropriate safeguards.

We require third parties that process personal information on our behalf to provide appropriate confidentiality, privacy, and information-security protections consistent with the nature and risk of the processing and applicable contractual requirements.

11. Subprocessors and Third-Party Cloud Providers

Intrinsic Imaging performs due diligence and risk-based evaluation of third parties that may process personal information on our behalf.

Where appropriate, contracts with subprocessors address matters including confidentiality, information security, permitted processing, incident notification, data return or deletion, regulatory obligations, and applicable audit or assurance requirements.

Intrinsic Imaging remains responsible for managing its contractual relationships with subprocessors in accordance with applicable law and customer agreements.

Where required, customers will be informed of or provided mechanisms concerning material changes to subprocessors.

12. International Data Transfers

Personal information may be processed in jurisdictions other than the jurisdiction in which it was originally collected.

Where applicable law imposes restrictions on international transfers of personal information, Intrinsic Imaging implements appropriate transfer mechanisms and safeguards, which may include contractual protections, approved transfer mechanisms, adequacy decisions, risk assessments, or other legally recognized safeguards.

Customer data will be processed in accordance with applicable contractual data-location and transfer requirements.

13. Data Retention

Intrinsic Imaging retains personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected and to satisfy applicable legal, regulatory, clinical, contractual, security, quality, and recordkeeping obligations.

Retention periods may depend on the nature and sensitivity of the information; customer instructions and contractual requirements; clinical-study or research requirements; legal and regulatory requirements; applicable limitation periods; security and fraud-prevention needs; and legitimate business and operational requirements.

At the end of the applicable retention period, information is securely deleted, destroyed, anonymized, or returned in accordance with applicable requirements.

Where Intrinsic Imaging processes information solely on behalf of a customer, retention and deletion are governed by the customer's instructions and applicable contractual and legal requirements.

14. Secure Deletion and Return of Information

Upon termination or expiration of Services, Intrinsic Imaging will return or securely delete customer personal information as required by the applicable agreement, documented customer instructions, and law.

Deletion processes are designed to make information inaccessible or irrecoverable using methods appropriate to the relevant technology and sensitivity of the information.

Information may remain temporarily within secure backup systems until it is overwritten or deleted according to established backup-retention procedures, unless applicable requirements dictate otherwise.

15. Information Security and Privacy Incidents

Intrinsic Imaging maintains processes for identifying, investigating, containing, documenting, remediating, and recovering from suspected or confirmed information-security and privacy incidents.

Where an incident involving personal information triggers notification requirements, Intrinsic Imaging will provide notifications to affected customers, individuals, regulators, or other parties in accordance with applicable law and contractual obligations.

When Intrinsic Imaging processes information on behalf of a customer, we will provide information reasonably necessary to assist the customer in evaluating and responding to an incident, subject to applicable contractual and legal requirements.

16. Government and Law-Enforcement Requests

Intrinsic Imaging will not disclose customer personal information to governmental or law-enforcement authorities except where authorized or required by applicable law.

Where legally permitted and appropriate, we may notify the affected customer before responding to a request and may challenge requests that we reasonably believe are invalid, excessive, or unlawful.

We seek to limit disclosures to information legally required by a valid request.

17. Individual Privacy Rights

Depending on an individual's location, relationship with Intrinsic Imaging, and applicable law, individuals may have rights concerning their personal information, including rights to request access, correction, deletion, restriction, or portability; object to certain processing; withdraw consent where processing is based on consent; and submit a complaint to an appropriate supervisory or regulatory authority.

These rights are subject to applicable legal limitations and exceptions.

Where Intrinsic Imaging processes personal information solely on behalf of a customer, individuals should ordinarily submit requests directly to that customer. Intrinsic Imaging will provide reasonable assistance to customers in responding to valid requests where required by applicable law or contract.

Intrinsic Imaging will not discriminate against an individual for exercising a privacy right protected by applicable law.

18. Protected Health Information and HIPAA

Where Intrinsic Imaging receives or processes Protected Health Information as a business associate under HIPAA, such information will be handled in accordance with applicable HIPAA requirements and the governing Business Associate Agreement.

Where another HIPAA-specific privacy notice or Notice of Privacy Practices applies, that notice may contain additional information concerning the use and disclosure of Protected Health Information and applicable individual rights.

If a conflict exists between this Privacy Policy and a legally required HIPAA notice or applicable Business Associate Agreement, the legally controlling requirement will govern to the extent of the conflict.

19. Clinical-Trial and Research Data

Intrinsic Imaging may process personal information in connection with clinical trials, research studies, medical imaging, and related activities.

Depending on the engagement, the sponsor, healthcare institution, investigator, or other organization may determine the purposes and means of processing. Intrinsic Imaging may act as a processor, service provider, business associate, or other contracted party.

Where practicable and appropriate, clinical-trial and research information may be coded, pseudonymized, de-identified, or otherwise separated from directly identifying information.

Applicable study protocols, informed-consent documentation, contracts, regulatory requirements, and customer instructions may establish additional requirements concerning such information.

20. Cookies and Similar Technologies

Our websites and online Services may use cookies, log files, and similar technologies necessary for functionality, authentication, security, performance, preferences, and authorized analytics.

Where required by applicable law, we provide appropriate notice and obtain consent before using non-essential cookies or similar technologies.

Additional information may be provided through a separate Cookie Notice or consent-management interface.

21. Children's Information

Our Services are not generally directed toward children for independent consumer use.

Personal information relating to minors may nevertheless be processed in connection with authorized healthcare, clinical-trial, research, or customer services. In such circumstances, the information will be processed pursuant to applicable legal, contractual, consent, authorization, and research requirements.

22. Employee Confidentiality and Training

Personnel with access to personal information are subject to confidentiality and information-security obligations appropriate to their roles.

Intrinsic Imaging provides privacy and information-security awareness and training appropriate to personnel responsibilities and periodically reinforces those requirements.

Access to sensitive information is limited according to business need and applicable authorization.

23. Privacy by Design and Security by Design

Intrinsic Imaging considers privacy and information-security requirements throughout relevant system, service, and process lifecycles.

Depending on the nature and risk of the processing, this may include data-minimization measures; access-control design; encryption and pseudonymization; secure development practices; risk and privacy assessments; logging and monitoring; retention and deletion requirements; vendor and subprocessor reviews; and testing of relevant security controls.

24. Accountability and Governance

Intrinsic Imaging maintains governance processes designed to support compliance with applicable privacy, information-security, contractual, and regulatory requirements.

These processes may include documented policies and procedures, defined security and privacy responsibilities, risk assessments, internal reviews, management oversight, incident management, vendor oversight, employee training, corrective actions, and continual improvement.

Intrinsic Imaging periodically reviews its privacy and information-security practices and updates them as necessary to address changes in technology, risk, business operations, contractual requirements, and applicable law.

25. Audits and Assurance

Intrinsic Imaging may conduct or obtain security assessments, internal audits, independent assessments, vulnerability testing, penetration testing, risk assessments, and other assurance activities appropriate to the Services and associated risks.

Where required by contract, applicable assurance information may be made available to eligible customers subject to appropriate confidentiality, security, and nondisclosure restrictions.

Nothing in this Privacy Policy should be interpreted as representing that Intrinsic Imaging holds a particular certification unless the certification has been formally issued by an accredited certification body and remains valid.

26. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our Services, processing practices, legal or regulatory requirements, security practices, or other operational considerations.

Where required by applicable law or contract, Intrinsic Imaging will provide appropriate notice of material changes to this Privacy Policy.

27. Contact Information

Questions, concerns, privacy requests, or complaints concerning this Privacy Policy or Intrinsic Imaging's processing of personal information may be directed to:

Todd JoronPresident & CEOIntrinsic Imaging, LLC580 Main Street, Suite 210
Bolton, MA 01740
United States
Email: Privacy@IntrinsicImaging.comTelephone: +1-978-428-9410

Individuals may also contact the appropriate data-protection, healthcare, or regulatory authority where applicable.

Document Control

Document Owner
Todd Joron, President & CEO
Approved By
Todd Joron, President & CEO
Version
1.0
Effective Date
October 1, 2026
Review Frequency
At least annually and following material changes to applicable requirements, processing activities, or information-security risks.