BT Global Solutions LLC ("we", "us", or "our") operates the Vela AI mobile application (the "App"), an ambient clinical documentation tool used by healthcare providers in urgent care and aesthetic medicine settings. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Healthcare context. Vela AI is intended for use by licensed clinicians and their authorized staff. The App processes audio recordings of clinical encounters and generates draft documentation. Your audio recordings and clinical data are processed by Amazon Web Services (AWS), including AWS HealthScribe for clinical documentation. AWS is HIPAA-eligible and data is processed in accordance with our Business Associate Agreement. We act as a Business Associate under HIPAA when handling Protected Health Information (PHI) on behalf of covered entities under a signed Business Associate Agreement (BAA).
1. Information We Collect
Account information
Name, email address, and organization affiliation provided during sign-up or invitation.
Authentication credentials and access codes used to sign in to the App.
Audio and clinical content
Audio recordings of clinical encounters that you explicitly start within the App. Audio recordings are transmitted to Amazon Web Services (AWS), specifically AWS HealthScribe, for transcription and clinical documentation, and are deleted after processing.
Generated transcripts, SOAP notes, and clinical summaries produced from those recordings.
Encounter metadata such as date, duration, and patient identifier you assign.
Device and usage data
Device model, operating system version, and App version used for diagnostics.
Crash reports and error logs that help us identify and fix problems.
Basic usage analytics (e.g., screens visited, feature usage) used to improve the App.
2. How We Use Information
To provide the core service: transcribing audio and generating clinical documentation.
To authenticate users and protect account security.
To diagnose, troubleshoot, and improve the reliability and quality of the App.
To comply with our legal obligations and contractual commitments to healthcare organizations.
We do not sell personal information or PHI. We do not use PHI to train general-purpose AI models. We do not show advertising in the App.
3. Recording Consent
You are responsible for obtaining any consent required by applicable law, your organization's policies, and professional ethics before recording any clinical encounter. The App provides clear visual indicators while recording is active.
4. Service Providers
We use the following service providers to operate the App. Each is bound by contractual confidentiality and data protection obligations, including a Business Associate Agreement where PHI is involved:
Amazon Web Services (AWS), including AWS HealthScribe — AWS is the third-party processor of your clinical data. We send your audio recordings of clinical encounters and the resulting clinical notes to AWS HealthScribe, which uses them to generate clinical documentation (transcription, structured notes, and clinical summaries). AWS is HIPAA-eligible; data is encrypted in transit and at rest, processed in accordance with our Business Associate Agreement with AWS, and deleted after processing. Your data is not used to train general-purpose AI models.
AWS cloud hosting and storage — provides the secure infrastructure on which our backend service and your account data run.
5. Data Retention
Audio recordings, transcripts, and generated notes are retained for the period required by your healthcare organization's data retention policy and applicable law. You or your organization administrator may request deletion of specific encounters or your entire account at any time. Backups are purged on a rolling 30-day cycle after deletion.
6. Security
All data is encrypted in transit using TLS 1.2 or higher.
Data at rest is encrypted using AES-256.
Access to production systems is limited to authorized personnel and audited.
We follow the HIPAA Security Rule's administrative, physical, and technical safeguards.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
Access the personal information we hold about you.
Request correction or deletion of your personal information.
Request a copy of your data in a portable format.
Withdraw consent or object to specific processing activities.
For PHI held on behalf of a covered entity, requests should be directed to that healthcare organization, which is the data controller. We will support those requests as Business Associate.
8. Children
The App is not directed to individuals under 13 and we do not knowingly collect personal information directly from children. The App may, however, be used by clinicians treating pediatric patients; in that case, the patient's information is handled as PHI under the controlling healthcare organization's authority.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the App and, where appropriate, by email. The "Effective" date at the top of this page reflects the most recent revision.
10. Contact Us
Questions, requests, or concerns about this Privacy Policy can be sent to: