Privacy Policy
What we collect through the marketing site and pilot workspace, the anonymous aggregate analytics posture we hold ourselves to, and the rights you have over your information.
Last updated: July 28, 2026
1. Scope of this policy
This Privacy Policy describes how Marsa Health (“we”, “us”) handles personal information collected through the marsahealth.com website, including the demo-request and contact forms, blog, calculators, and other public pages (the “Site”), and the account information of people our customers ask us to provision for the Marsa Health workspace.
It does not cover the operational data our customers process in production deployments of the Marsa Health workspace. That data is governed by the customer’s agreement with us, including a business associate agreement where protected health information is involved; the customer controls that data and we process it only on the customer’s behalf.
2. Information we collect
We collect information you choose to give us through the Site, and account information for provisioned workspace users:
- Demo and contact requests — your work email, organization name, role, how you heard about us, and the business details you include about your operation (for example, team size or the workflows you want to see).
- Email correspondence — the contents of messages you send us and the address you send them from.
- Workspace accounts — for pilot organizations, the name, work email, organization membership, and sign-in records of users the organization asks us to provision. There is no self-service signup.
The Site is not a channel for patient data. Our forms instruct visitors not to enter patient data or protected health information, and we ask that you never submit PHI through the marketing site.
3. Consumer health data
Although our Site is about behavioral-health operations, we do not collect consumer health data about Site visitors. Reading a guide or using a calculator is not linked to your identity in our records — our analytics are the anonymous daily aggregates described in Section 4 — and we do not draw inferences about any visitor’s health, treatment, or interest in care. The information our forms request is business information about an organization, not information about an individual’s health.
If that ever changes, health-data privacy laws such as Washington’s My Health My Data Act require separate notice and consent, and we would provide both before collecting any such data. For clarity on HIPAA: information you submit through the Site is not protected health information, and we handle PHI only inside production customer deployments under a business associate agreement, as described in our Terms of Service.
4. Site analytics
Our content analytics are deliberately minimal. We record anonymous, daily aggregate counts of page activity — enough to know which guides and tools are useful. We do not assign visitor identifiers, do not use advertising cookies, do not collect IP addresses in analytics records, and do not track visitors across other sites.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
5. Cookies and device storage
The Site uses no analytics or advertising cookies. The only cookies we set are strictly necessary ones: a session cookie and a security (CSRF) cookie used to keep provisioned workspace users signed in. If you never sign in, the Site works without any cookie that identifies you.
We use your browser’s local or session storage for a few interface preferences — for example, remembering that you dismissed an announcement, completed a demo-workspace onboarding card, or already saw the logo’s introductory draw. These values are non-identifying labels and never leave your device.
Because the Site does not track visitors or sell or share personal information, there is nothing for browser opt-out signals such as Global Privacy Control or Do Not Track to switch off; we treat visitors who send those signals the same as everyone else — untracked.
6. How we use information
We use the information described above to:
- respond to demo requests and route your inquiry to the right person;
- communicate with you about the Service, including scheduling and follow-up you have asked for;
- provision, secure, and support workspace accounts our customers ask us to create;
- understand which Site content is useful, using the aggregate analytics described in Section 4;
- operate, secure, and improve the Site;
- comply with legal obligations and enforce our terms.
7. How we share information
We share personal information only with:
- Service providers that host our infrastructure, deliver form submissions and email, or otherwise help us operate the Site and respond to inquiries, under terms that limit their use of the information to providing services to us;
- Professional advisers and authorities where required by law, to protect our rights, or in connection with a corporate transaction, with notice where legally permitted.
We do not sell personal information and have not done so.
8. Data retention
Demo requests are not stored in our application database or function logs. Our form-delivery provider temporarily stores submissions while delivering them to our operator mailbox (currently 30 days on its free plan or one year on its Pro plan). We keep the resulting correspondence only as long as needed to handle your inquiry and maintain our business relationship. If no active relationship develops, our mailbox retention rule deletes inquiry records no later than twenty-four months after our last interaction with you, except where a longer period is required for legal, accounting, or audit purposes.
Workspace account records are kept for the life of the account and for a limited period afterward to meet the customer’s export rights and our legal obligations. Aggregate analytics contain no personal information and may be retained indefinitely. You may request deletion at any time as described in Section 10.
9. Security
We protect information in transit with encryption and limit access to the systems that store inquiry data to the people who need it to respond to you. Our broader security posture — access controls, audit history, retention, and incident response — is described on the security page. No method of transmission or storage is perfectly secure, but we work to protect the information you share with us.
10. Your rights and choices
You can ask us to access, correct, or delete the personal information we hold about you, or to stop contacting you, by emailing team@buildalytic.com. We will take reasonable steps to verify your request — normally by corresponding with the email address on file — and respond within the time required by applicable law. Where local law allows an authorized agent to act for you, or gives you the right to appeal a decision we make on your request, we honor those processes too.
Depending on where you live, you may have additional rights. California residents may request disclosure of the categories of personal information we collect (for the Site, these are identifiers and professional information you provide, used for the purposes in Section 6), request deletion or correction, and are entitled not to be discriminated against for exercising those rights; we do not sell or share personal information as those terms are defined in the CCPA/CPRA. Residents of other U.S. states with comprehensive privacy laws have similar access, correction, deletion, and portability rights. Residents of the European Economic Area and the United Kingdom may also have rights to restrict or object to processing, to data portability, and to lodge a complaint with a supervisory authority; where GDPR-style laws apply, we process the information described in this policy to perform contracts, pursue legitimate interests such as responding to business inquiries, and comply with law.
11. Children
The Site is a business-to-business service directed at healthcare organizations. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
12. International transfers
We are based in the United States and process information there. If you access the Site from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction. Where required, we use appropriate safeguards for such transfers.
13. Changes to this policy
We may update this policy as the Site and the Service evolve. When we do, we will revise the “Last updated” date above, and for material changes we will provide more prominent notice, such as a note on this page or an email where we have an address for you.
14. Contact
Privacy questions and requests can be sent to team@buildalytic.com or through the contact page.