Legal
Privacy Policy
Last updated: July 14, 2026
1. Introduction
Acuity Behavioral Health, Inc. ("the Company," "we," "us," or "our") operates getacuitybh.com and the Acuity clinical-operations platform -- software built for inpatient behavioral health and psychiatric facilities. This Privacy Policy explains what information we collect through the website and platform, how we use it, and the choices available to you.
Acuity's core service helps inpatient psychiatric units monitor behavioral signals, support staffing decisions, and reduce end-of-shift charting burden for nurses and nursing leadership. In the course of providing that service, we process certain information on behalf of our facility partners as described below.
We are based at 1230 Peachtree Street NE, Suite 1900, Atlanta, GA 30309, and can be reached at [email protected].
2. Information We Collect
2.1 Information You Provide (Website Visitors and Prospects)
When you interact with getacuitybh.com, we collect information you submit directly:
- Contact details (name, email, phone number) submitted through demo request or contact forms;
- Professional context you choose to share (job title, facility name, unit type, EHR environment);
- The content of any messages or questions you send us.
This information is used to respond to inquiries, arrange product demonstrations, and maintain our prospect communications. It is not patient data and is not clinical in nature.
2.2 Information Collected Automatically (Website)
When you visit getacuitybh.com, we automatically collect limited technical information:
- IP address and approximate geographic location (city or region level);
- Browser type, operating system, and device class;
- Pages visited, referring URLs, and time on page;
- Cookie and similar identifiers (see Section 5).
2.3 Protected Health Information (PHI) -- Platform Deployments
Acuity's clinical-operations platform is deployed within the HIPAA-covered environment of our facility partners. In that context, Acuity processes protected health information (PHI) -- including patient identifiers, behavioral observations, acuity data, and shift-level clinical notes -- on behalf of the covered-entity facility. This processing occurs under a signed Business Associate Agreement (BAA) with each facility partner.
PHI processed through the platform is:
- Controlled by the facility partner as the covered entity;
- Used solely to provide and support the contracted clinical-operations service;
- Encrypted in transit (TLS 1.3) and at rest (AES-256);
- Stored exclusively in US-based infrastructure;
- Not used to train, fine-tune, or improve any AI or machine-learning model outside the facility's deployment without the facility's explicit written authorization.
Your facility's HIPAA rights with respect to PHI are governed by your facility's Notice of Privacy Practices as the covered entity. Acuity operates as a business associate, not a covered entity.
2.4 We Do Not Knowingly Collect Children's Data
getacuitybh.com is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
3. How We Use Information
For website visitor and prospect information, we use what we collect to:
- Respond to demo requests, inquiries, and support questions;
- Operate, maintain, and improve the website and platform;
- Send product updates and (with your consent where required) communications about Acuity;
- Detect, investigate, and prevent fraud or abuse;
- Comply with applicable legal obligations.
For PHI processed under a BAA: use is limited strictly to what is necessary to provide the contracted clinical-operations service to the facility partner. Acuity does not use facility PHI for marketing, advertising, or purposes unrelated to the contracted service.
We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.
4. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf (such as hosting infrastructure, email delivery, and analytics) under contractual confidentiality and data-handling terms consistent with this Policy;
- Our facility partners, as necessary to operate and support the platform under the terms of our BAA;
- Governmental authorities or law enforcement, when required by law or to protect rights, safety, or property;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy and applicable law.
We do not sell personal information to third parties.
5. Cookies and Tracking
We use cookies and similar technologies to operate the site, remember preferences, and measure usage. For details and choices, see our Cookie Policy.
6. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, to comply with legal or accounting obligations, and to resolve disputes:
- Website visitor and prospect contact data: retained for up to 36 months of inactivity, then purged from marketing lists. A longer retention period may apply where a facility partnership is active or under active negotiation.
- Server access logs: retained 90 days, then aggregated or deleted.
- PHI processed under a BAA: retention is governed by the terms of the facility BAA and the facility's own retention obligations under HIPAA and applicable state law. Acuity configures data retention windows in accordance with the facility's policy, and provides deletion tools on request to facility administrators.
7. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption in transit, AES-256 encryption at rest, restricted-access databases, role-based access controls, and audit logging for access to patient-linked data fields. No system is perfectly secure; we cannot guarantee absolute security.
For PHI processed under a BAA, Acuity's architecture is designed to align with HIPAA administrative, physical, and technical safeguard requirements. We do not self-certify HIPAA compliance -- that certification does not exist for software vendors in this form. We describe our security design honestly so your compliance and privacy officers can evaluate the controls.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request regarding your personal information on getacuitybh.com or in our prospect communications, email [email protected]. We will respond within the timeframe required by applicable law.
Note: rights requests related to PHI within a deployed facility instance should be directed to that facility as the covered entity under HIPAA. Acuity will cooperate with the facility's response process in accordance with our BAA obligations.
9. Georgia Residents
Georgia does not currently have a comprehensive consumer privacy statute. As a matter of policy, we extend the following baseline rights to all U.S. residents regardless of state of residence.
9.1 Baseline Rights
- Right to Know: request the categories of personal information we have collected about you.
- Right to Delete: request deletion of personal information you have provided.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Marketing: unsubscribe from marketing emails or opt out via the link in each marketing message.
9.2 How to Exercise
Email [email protected] with a description of your request and enough detail for us to verify your identity. We respond within 45 days.
9.3 Sector-Specific Rights
If you are protected by federal sector laws (such as HIPAA), those laws may give you additional rights with respect to data covered by them. PHI rights under HIPAA should be directed to the covered-entity facility, not to Acuity as a business associate.
9.4 California Visitors
If you are a California resident, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell personal information and do not "share" personal information for cross-context behavioral advertising.
To submit a CCPA / CPRA request, email [email protected] with the subject line "California Privacy Request."
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.
11. Contact
Questions, requests, or complaints can be sent to:
Acuity Behavioral Health, Inc.1230 Peachtree Street NE, Suite 1900
Atlanta, GA 30309
Email: [email protected]
Phone: +1 (404) 892-1700