Legal

Privacy Policy

Last updated: August 11, 2026

This Privacy Policy describes how ReMyLL, LLC (“ARIA,” “we,” “us”) collects, uses, discloses, and protects information when individuals visit our websites or use the ARIA HOTLINE® reporting platform (the “Service”). It has four parts: Part A covers visitors to our public website, Part B covers reporters and customer personnel using the platform, Part C describes how we handle and secure data, and Part D sets out state privacy rights and how to exercise them. Terms defined in our service terms and, for enrolled customers, in the service agreement accepted during account activation (including “Customer” and “Customer Data”) carry the same meaning here.

Part A

Website privacy

Applies to visitors of ariahotline.com and related public-facing pages.

A1. Information we collect

  • Contact information submitted through forms
  • Email addresses for inquiries
  • Website analytics (browser type, pages visited, timestamps)
  • Cookies used for basic site functionality

We do not sell personal information.

A2. How we use website information

To respond to inquiries, improve site performance, maintain security, and provide product information.

A3. Sharing website information

We may share website information with service providers supporting site operations, and with legal authorities when required by binding legal process. We do not share website information for advertising.

A4. Cookies and analytics

Strictly necessary cookies keep the site and the Client Admin Portal working. Privacy-focused analytics run only if you select “Accept analytics” on the cookie banner; if you decline or make no choice, no analytics script loads and no analytics cookie is set. We do not use advertising cookies, social media or advertising pixels, session replay, or fingerprinting, and no cookies or analytics run on the reporter portal or on anonymous reporting sessions. We honor Global Privacy Control signals. See the Cookie Policy for detail.

A5. Website chat assistant

The ARIA Assistant chat on this website is answered by artificial intelligence. Messages you send are transmitted to a third-party AI service provider to generate a response, and a notice to that effect appears in the chat window before you send. The chat is not confidential, is not monitored in real time, and must not be used to submit a report or to share personal, health, or identifying information. Chat content is not used to train AI models. If you need to make a report, use your organization's reporting line.

Part B

Product & service privacy

Applies to reporters and Customer personnel using the ARIA HOTLINE® platform.

B1. Information we collect through the Service

Reporter-provided: narrative descriptions; dates, locations, and individuals involved; attachments (documents, images, audio); and follow-up messages. Reporters may remain anonymous.

Customer-provided: organization details; reviewer names, roles, and contact information; billing information; and configuration settings.

Collected automatically (authorized reviewers only): log data, browser and device information, authentication events, and error logs.

For anonymous reports, we do not collect: IP addresses, device fingerprints, network identifiers, employee IDs, or geolocation metadata, and we do not attempt to infer identity.

B2. How we use Service information

To provide and operate the Service, generate AI-assisted summaries and classification drafts, maintain audit logs, support Customer's case management, improve reliability and security, and comply with legal obligations.

We do not sell personal information or use Customer Data for advertising.

B3. How we share Service information

With Customer:Customer's authorized reviewers access Customer Data according to Customer's permissions. Customer manages those permissions, as described in the Terms of Use.

With subprocessors: vetted providers for hosting, telephony, payment processing, support tooling, and logging and monitoring. We maintain a current subprocessor list.

Legal process: we may disclose information only when required by applicable law or binding legal process. We cannot disclose identifying information for anonymous reports because such information is not collected.

Business transactions: Customer Data remains subject to this Policy in the event of a merger or acquisition.

B4. Data retention

Customer Data is retained for the duration of Customer's subscription, with case data retained for the 6-year period included in Customer's plan (or as extended by agreement). Following termination and the export window described in the customer service agreement, ARIA deletes Customer Data and does not retain it, unless ARIA receives direct written notice of a litigation hold requiring preservation of specified data. Upon termination, Customer may export its data for 30 days. Afterward, Customer Data is deleted except where retention is legally required.

B5. Your rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information. For reports submitted through a Customer's program, ARIA processes data on the Customer's behalf; requests are directed to the Customer, and we support the Customer in fulfilling them. Website inquiries, and the state-law rights described in Part D, can be raised through contact us.

B6. Children's privacy

The Service is not intended for children under 16.

Part C

Data handling & security

The administrative, technical, and physical controls that protect Customer Data.

C1. Data categories and ownership

Customer Data (reports, case files, attachments, audit logs) belongs to Customer. Operational data (logs, metrics, diagnostics) and administrative data (account and billing details) support the operation of the Service. ARIA processes Customer Data solely to provide and support the Service; AI-generated outputs are drafts requiring Customer review.

C2. Storage and residency

Customer Data is encrypted in transit and at rest, hosted in the United States by default with an optional Canadian residency configuration, and backed up securely with controlled retention.

C3. Access controls

ARIA enforces role-based access, least-privilege principles, multi-factor authentication for ARIA personnel, logged administrative actions, and regular access reviews. Customer controls its own reviewer permissions.

C4. Subprocessor management

ARIA maintains a current subprocessor list, conducts due diligence before engagement, requires contractual safeguards, and monitors performance.

C5. Secure development and transmission

ARIA follows secure development practices including code review, dependency management, vulnerability scanning, change-management controls, and environment segregation. All data transmitted between Customer, reporters, and ARIA systems is encrypted.

C6. Incident response and continuity

ARIA maintains an incident response program covering detection, containment, remediation, Customer notification where required, and post-incident review, alongside redundant infrastructure, backup and restoration procedures, and disaster recovery and business continuity plans.

C7. Customer responsibilities

Customer is responsible for reviewer access management, credential security, reviewing AI-generated drafts, and compliance with applicable laws, as set out in the ARIA Terms of Service accepted during account activation. That agreement's prohibitions, including attempting to identify anonymous reporters, retaliation, circumventing security controls, and unlawful use, apply equally here.

C8. Legal compliance

ARIA complies with applicable U.S. privacy and data protection laws. ARIA does not represent compliance with any specific certification unless agreed in writing.

Part D

State privacy rights

Rights available to residents of states with comprehensive privacy laws, and how to exercise them.

D1. Our role

For information collected through our public website, ARIA is the business or controller. For Customer Data submitted through the reporting platform, ARIA is a service provider or processor acting on the Customer's documented instructions; requests about a report should be directed to the organization that operates the reporting program, and we assist that organization in responding.

D2. Categories of information collected through our website

In the twelve months preceding the date above, we collect the following categories from website visitors. We collect no other statutory categories.

IdentifiersName, work email address, organization name, and telephone number where you provide one.
Commercial informationProducts or plans inquired about, demonstrations requested, and enrollment details.
Internet activityPages visited, referring source, browser and device type, and timestamps, collected only if you accept analytics.
InferencesNone. We build no profiles and perform no profiling that produces legal or similarly significant effects.
Sensitive informationNone collected through our website. Do not submit health or other sensitive information through a website form or the chat assistant.

Sources: you, directly. Business purposes: responding to inquiries, providing and billing for the Service, site security and performance, and legal compliance. Categories of recipients: service providers for hosting, email delivery, scheduling, payment processing, and analytics, each bound by contract to use the information only for us. Retention: inquiry records are kept for up to twenty-four months after last contact unless an account is opened, in which case Customer records follow the retention terms in B4.

D3. We do not sell or share personal information

ARIA does not sell personal information, and does not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding twelve months, including with respect to consumers under sixteen. We run no advertising or social media pixels, so there is no opt-out to offer. We also do not use or disclose sensitive personal information for purposes requiring a right to limit.

D4. Your rights

Depending on your state of residence, you may have the right to:

Know and accessConfirm whether we process your personal information and obtain a copy, including the categories, sources, purposes, and recipients.
CorrectCorrect inaccurate personal information we hold about you.
DeleteRequest deletion, subject to exceptions such as security, legal obligations, and the completion of a transaction you requested.
PortabilityReceive a copy in a portable, readily usable format where technically feasible.
Opt outOpt out of sale, sharing, targeted advertising, and profiling with legal or similarly significant effects. We conduct none of these activities.
Non-discriminationExercise any right without denial of service, different pricing, or a different level of quality.

California residents may also request the information described in California Civil Code section 1798.83. Nevada residents may submit an opt-out of the sale of covered information; we do not engage in such sales.

D5. How to exercise a right, and how we verify it

Submit a request through our contact page or by writing to ReMyLL, LLC, 625 Kenmoor Ave SE, Suite 350, Grand Rapids, MI 49546. Tell us which right you are exercising and the state you reside in.

We verify your request by matching the information you provide against our records, typically the email address used to contact us. We may ask for additional information where a request concerns sensitive records, and we do not use verification information for any other purpose. An authorized agent may submit a request with written permission signed by you, and we may still contact you to confirm.

We respond within forty-five calendar days, and may extend once by an additional forty-five days where reasonably necessary, with notice to you. There is no fee unless a request is manifestly unfounded or excessive.

D6. Appeals

If we decline your request, we will explain why. You may appeal that decision within a reasonable period by replying to our response or writing to the address above with the word Appeal in your message. We will respond in writing within forty-five days, and if we deny the appeal, we will provide a method to contact your state Attorney General.

D7. Universal opt-out signals

We honor the Global Privacy Control and comparable universal opt-out mechanisms. A browser that transmits such a signal is treated as declining analytics, and no analytics script loads and no analytics cookie is set, even if consent was previously given on that browser.

D8. Consumer health data

ARIA is not a healthcare provider and does not collect consumer health data through this website. The reporting platform is a compliance reporting system, not a medical records system; health-related details may appear incidentally within the content of a report submitted to an organization that operates a reporting program. That content is processed on that organization's instructions, is not sold, is never used for advertising, and is subject to the Business Associate Agreement where the organization is regulated under HIPAA. We do not collect precise geolocation, and we do not infer health status from website activity.

D9. Notice at collection

Each form on this website states, at the point of collection, what we will do with the information and links to this Policy. Our forms are not reporting channels; report details and personal health information should not be submitted through them.

Changes and contact

Material changes to this Policy will be posted here with an updated date and communicated to Customer administrators. Questions: ReMyLL, LLC, 625 Kenmoor Ave SE, Suite 350, Grand Rapids, MI 49546, United States · contact us.