Privacy Policy
Taxo.ai, Inc.
Effective Date:
February 27, 2026
Last Updated:
March 2, 2026
IMPORTANT NOTICE REGARDING HEALTHCARE DATA: This Privacy Policy governs how Taxo.ai, Inc. (“Taxo,” “we,” “us,” or “our”) collects, uses, and discloses personal data in its capacity as a data Controller—for example, when you visit our website, interact with our marketing materials, or engage in business transactions with us. This Policy does NOT apply to Protected Health Information (“PHI”) or patient data processed through our products and Services on behalf of healthcare practice customers. When we process PHI on behalf of our customers, we do so as a Business Associate under the Health Insurance Portability and Accountability Act (“HIPAA”) and applicable state health privacy laws, pursuant to Business Associate Agreements (“BAAs”) with each customer. If you are a patient and have questions about how your healthcare provider uses your data, please contact your healthcare provider directly.
This Policy also does not apply to personal data about current and former Taxo.ai, Inc. employees, job candidates, or contractors and agents acting in similar roles.
1. Definitions
The following terms have the meanings set forth below when used in this Privacy Policy. These definitions apply regardless of whether the terms appear in singular or plural form.
“Digital Properties” means the Taxo website (https://taxo.ai), our branded social media pages, and other websites or online properties that we operate or control.
“Device” means any device that can access the Digital Properties, such as a computer, mobile phone, or digital tablet.
“Personal Data” means any information that relates to an identified or identifiable natural person, as defined under applicable data protection laws.
“Service(s)” refers to the products, software, and services provided by Taxo.ai, Inc. to its customers, including its AI-powered front desk and patient communication solutions.
“Service Provider” means any natural or legal person who processes data on behalf of Taxo.ai, Inc., including third-party companies or individuals engaged to facilitate or support the Services or Digital Properties.
“You” (or “your”) means the individual accessing or using the Digital Properties, or the company or other legal entity on behalf of which such individual is acting.
If you are located in the European Economic Area (“EEA”), Switzerland, or the United Kingdom (“U.K.”), please refer to Section 11 for additional information about the specific entity or entities acting as a controller of your personal data.
This Policy applies when you:
• Visit or interact with our Digital Properties;
• Register for or participate in our webinars, events, programs, demonstrations, or promotional activities;
• Request a product demonstration or submit inquiries through our website;
• Interact with us in person, such as at trade shows, conferences, or our offices; or
• Inquire about or engage in commercial transactions with us.
2. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of material changes by posting the updated Privacy Policy on this page and updating the “Last Updated” date above.
For material changes that significantly affect how we process your personal data, we will provide additional notice via email and/or a prominent notice on our Digital Properties prior to the change becoming effective.
We encourage you to review this Privacy Policy periodically. Your continued use of our Digital Properties after the posting of changes constitutes your acknowledgment of such changes.
3. Personal Data We Collect and Disclose
The following table describes the categories of personal data we collect and the parties to whom we may disclose such data. For California residents: this table includes parties to whom we disclose personal data for a business or commercial purpose, as defined by California law.
Categories of Personal Data Collected | Disclosures of Personal Data |
|---|---|
Identifiers, such as your name, email address, postal address, phone number, job title, company name, and device identifiers (e.g., IP address, browser type, and operating system). |
|
Commercial Information, such as purchasing history, transaction records, product or service preferences, and billing information. |
|
Internet or Other Electronic Network Activity Information, such as browsing history, search history, device information, browser type, referring/exit pages, and information regarding your interactions with our Digital Properties, emails, and advertisements. |
|
Geolocation Information, such as approximate location derived from your IP address or information you voluntarily provide (e.g., city and state in a webform). You may control collection of precise location data through your device settings. |
|
Audio, Electronic, Visual, and Similar Information, such as recordings of interactions with our sales, support, or customer success teams (e.g., for quality assurance or training purposes, in accordance with applicable law); or customer support chat and messaging logs. |
|
Professional or Employment-Related Information, such as your job title, employer, professional experience, and business contact details. |
|
Inferences, such as preferences, interests, and marketing segments derived from the categories above. |
|
In addition to the above, we may disclose your personal data: (a) to respond to lawful requests by law enforcement or other government authorities, including to meet national security requirements; (b) to enforce our agreements and policies; (c) to protect the rights, property, or safety of Taxo.ai, Inc., our users, or third parties; or (d) in de-identified, anonymized, or aggregated form to third parties for any lawful purpose.
4. How We Process Personal Data
We process your personal data for the following purposes and on the following legal bases:
Purpose of Processing | Lawful Basis |
To provide our Digital Properties and respond to inquiries, including operating, maintaining, and improving our website; processing demo requests and contact form submissions; communicating with you regarding your inquiries; and providing customer support. | Legitimate interests; Contract performance; Legal obligations |
For our own business purposes, including maintaining business records; conducting internal reporting and analytics; collecting payments; performing accounting functions; performing IT security management; evaluating and improving our business, Services, and Digital Properties; and developing new products and features. | Legitimate interests; Legal obligations |
For legal, safety, or security reasons, including complying with legal requirements; establishing, exercising, or defending legal claims; protecting the safety, security, and integrity of our property and rights; investigating policy violations; and detecting, preventing, and responding to security incidents, fraud, or other malicious or illegal activity. | Legitimate interests; Legal obligations; Public interest |
For marketing, including sending you marketing and promotional communications about our Services (via email, phone, or other channels); facilitating your participation in events, webinars, or programs; publishing testimonials or case studies (with your consent); and assessing advertising effectiveness. You may opt out of marketing communications at any time by clicking the “unsubscribe” link in our emails or contacting us at privacy@taxo.ai. | Consent (where required by law); Legitimate interests |
To fulfill referral requests, including using information you provide (such as a contact’s name, email, title, and company) to reach out on your behalf. You must only provide others’ personal data if you have their consent. | Consent (where required by law); Legitimate interests |
For corporate transactions, such as in connection with mergers, acquisitions, reorganizations, divestitures, bankruptcy, or other corporate events. | Legitimate interests; Legal obligations |
When you have voluntarily consented to have your personal data processed for a specific purpose. | Consent |
Taxo.ai, Inc. will honor data subject rights to the extent required by applicable law. You may have the right to access, correct, update, and, in some cases, request deletion of your personal data (subject to legal exceptions). You may submit a request by emailing privacy@taxo.ai. Taxo.ai, Inc. uses a limited number of third-party service providers to assist in processing data. These providers support site features, database monitoring, data transmission, and storage. They may process or store personal data while providing their services. Taxo.ai, Inc. maintains contracts restricting their access, use, and disclosure of personal data in compliance with applicable data protection laws, including GDPR where applicable.
5. Sources of Personal Data
• Information you provide directly, including when you complete forms on our Digital Properties, request a demo, register for events, contact our sales or support teams, or visit our offices.
• Information collected from your employer, colleagues, or business contacts, including information about representatives of our current, prospective, or former customers, suppliers, investors, and business partners. We may also receive your information through referrals.
• Information automatically collected, including technical information about your interactions with our Digital Properties (such as IP address, browser type, pages visited, and time spent). See Section 6 and our Cookie Policy for more information.
• Information from public sources, including public records, social media profiles, and professional networking sites.
• Information from third parties, including data enrichment providers, marketing partners, social media platforms, and analytics services.
We may combine information from these various sources and use or disclose it for the purposes described in this Policy.
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies (such as pixels, web beacons, and local storage) on our Digital Properties. These technologies help us analyze site usage, enhance navigation, personalize your experience, and support our marketing efforts. For detailed information about the types of cookies we use, how you can manage your cookie preferences, and your choices regarding tracking technologies, please refer to our Cookie Policy, available on our website.
Our Digital Properties feature a cookie consent banner that allows you to manage your preferences across three categories: Strictly Necessary cookies (which cannot be disabled), Analytics cookies, and Marketing cookies. You may update your preferences at any time by accessing the cookie settings on our website.
Some browsers offer a “Do Not Track” (DNT) signal. We will honor Global Privacy Control (GPC) signals to the extent required by applicable law.
7. Security and Retention
Taxo.ai, Inc. maintains appropriate technical and organizational security measures designed to protect your personal data against accidental or unlawful destruction, loss, disclosure, alteration, or unauthorized access. While no method of transmission over the internet or electronic storage is 100% secure, we strive to use commercially reasonable means to protect your personal data.
Your personal data will generally be retained as long as necessary to fulfill the purposes for which it was collected, including to comply with legal, accounting, or reporting obligations. When determining retention periods, we consider the nature and sensitivity of the data, the purposes of processing, applicable legal requirements, and our legitimate business interests.
When we have no ongoing legitimate business need or legal basis to process your personal data, we will delete, anonymize, or aggregate it. If deletion is not immediately possible (for example, because the data resides in backup archives), we will securely store and isolate the data until deletion can be completed. For questions about retention periods applicable to your situation, please contact us at privacy@taxo.ai.
8. Children’s Privacy
Our Digital Properties and Services are not directed to children under the age of 16 (or such higher age as may be required by applicable law), and we do not knowingly collect personal data directly from children through our website. If you are a parent or guardian and believe that a child has provided personal data to us, please contact us at privacy@taxo.ai, and we will take steps to delete such information.
Note: This section pertains to data collected through our Digital Properties (website). To the extent that Taxo’s products process data relating to minors on behalf of healthcare practice customers, such processing is governed by HIPAA, applicable BAAs, and each healthcare practice’s own privacy notices.
9. External Links
Our Digital Properties may contain links to external websites or services operated by third parties. We do not control and are not responsible for the privacy practices, content, or data collection policies of such third-party sites. We encourage you to review the privacy policies of any external sites you visit.
10. Supplemental Terms for California Residents
Pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), this Section 10 applies to personal data collected about California residents where Taxo.ai, Inc. acts as a “business” (as defined by the CCPA). This section supplements the rest of this Policy and does not apply to current or former employees, applicants, contractors, or agents.
Additional Data Processing Disclosures
The table below provides the categories of personal data we have sold, shared, or disclosed to third parties, as defined by the CCPA.
Categories of Personal Data | Third Parties to Whom Data Is “Sold or Shared” (CCPA) |
Identifiers (name, email, IP address, device identifiers) | • Companies operating cookies and tracking technologies (e.g., analytics providers), when you enable such cookies via our cookie banner • Business partners with whom we jointly market or sell our Services |
Commercial information | Not applicable |
Internet or electronic network activity information | Companies operating cookies and tracking technologies, when you enable such cookies via our cookie banner |
Geolocation information | Companies operating cookies and tracking technologies, when you enable such cookies via our cookie banner |
Audio, electronic, visual, and similar information | Not applicable |
Professional or employment-related information | Not applicable |
Inferences | Not applicable |
Although we have not “sold” or “shared” personal data for monetary consideration in the past 12 months, we engage in certain practices involving third-party tracking technologies on our Digital Properties that may constitute a “sale” or “sharing” as defined under the CCPA. We do not knowingly sell or share personal data of minors under the age of 16.
We do not collect or process “sensitive personal information,” as defined by the CCPA, for the purpose of inferring characteristics about you. Taxo.ai, Inc. only uses sensitive personal information consistent with the exceptions to the right to limit sensitive personal information under the CCPA.
Your California Privacy Rights
Subject to legal limitations, California residents may have the following rights:
Right to Know. You may request information about the categories and specific pieces of personal data we have collected, the sources of collection, the purposes for collecting, and the third parties with whom we have disclosed your personal data.
Right to Delete. You may request deletion of personal data we have collected from you, subject to certain exceptions.
Right to Correct. You may request correction of inaccurate personal data that we maintain about you.
Right to Opt Out of Sale or Sharing. You may direct us to stop “selling” or “sharing” your personal data as those terms are defined under the CCPA.
Right to Non-Discrimination. We will not discriminate against you for exercising any of these rights.
To exercise any of these rights, please email privacy@taxo.ai.
How to Opt Out of Sale or Sharing
To fully exercise your Right to Opt Out:
1. Submit an opt-out request by emailing privacy@taxo.ai; and
2. Disable analytics and marketing cookies via the cookie preference settings on our website. You must complete this step on each browser and device you use.
We will honor Global Privacy Control (GPC) signals to the extent required by California law.
Verification and Authorized Agents
To process your request, we may need to verify your identity. We may request information such as your name and email address. For Specific Pieces requests, we may require a signed declaration under penalty of perjury. Authorized agents may submit requests on your behalf by emailing privacy@taxo.ai and providing written authorization from the data subject. We reserve the right to verify the individual’s identity directly.
Response Timing
We will process opt-out requests within 15 business days. We will respond to other requests within 45 days, with an extension of up to 90 days if we notify you of the need for additional time.
11. Supplemental Information for the EEA, Switzerland, and the U.K.
The following terms supplement this Policy with respect to personal data of individuals located in the EEA, Switzerland, and the U.K. In the event of any conflict between this section and the rest of the Policy, this section shall govern with respect to EEA, Swiss, and U.K. personal data.
Data Controller
The data controller is Taxo.ai, Inc., located at 169 Madison Ave STE 80892, New York, NY 10016, unless we specifically inform you otherwise.
Legal Basis for Processing
Please see Section 4 for the legal bases on which we rely for the collection, processing, and use of personal data.
Your Data Protection Rights
Under applicable data protection laws, you may have the following rights:
Right of Access. You may obtain confirmation of whether we process your personal data and request a copy of such data.
Right to Data Portability. You may receive your personal data in a structured, commonly-used, machine-readable format and transmit it to another controller, where processing is based on consent or contract and carried out by automated means.
Right to Rectification. You may request correction of inaccurate personal data and completion of incomplete data.
Right to Object. You may object to the processing of your personal data in certain circumstances, including processing based on legitimate interests or for direct marketing.
Right to Restrict Processing. You may request that we restrict processing of your personal data in certain circumstances.
Right to Erasure. You may request deletion of your personal data in certain circumstances.
Right to Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.
Right to Withdraw Consent. Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
Right Regarding Automated Decision-Making. We do not currently engage in automated decision-making as described in Article 22(1) and (4) of the GDPR. Should this change, we will inform you and provide the right to human intervention and to contest the decision.
To exercise any of these rights, please contact us at privacy@taxo.ai. We may decline certain requests where permitted by law, such as where fulfilling the request would infringe another person’s rights.
International Transfers of Personal Data
Due to our operations in the United States, personal data collected from individuals in the EEA, Switzerland, or the U.K. may be transferred to the United States or other countries that may not provide an equivalent level of data protection. Such transfers are made using valid data transfer mechanisms, including EU Standard Contractual Clauses (“SCCs”) and/or the U.K. International Data Transfer Addendum, approved codes of conduct, or other mechanisms approved by the relevant authorities. Please contact us at privacy@taxo.ai if you wish to receive further information about international data transfers or a copy of the relevant transfer mechanism.
12. Supplemental Information for Other Regions
Australia: Personal data processed by Taxo.ai, Inc. as described in this Policy is handled in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) via oaic.gov.au.
Canada: Personal data as defined under the Personal Information Protection and Electronic Documents Act (“PIPEDA”) will be processed by Taxo.ai, Inc. in accordance with PIPEDA.
Nevada: We do not currently sell personal data as defined under Nevada law. Nevada residents may email privacy@taxo.ai to exercise opt-out rights under Nevada Revised Statutes §603A et seq.
United Kingdom: Personal data is processed in accordance with Taxo.ai, Inc.’s obligations under the UK Data Protection Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (“U.K. GDPR”).
16. Contact Information
If you have questions, concerns, or complaints regarding this Policy or our privacy practices, please contact us:
Email: hello@taxo.ai
Mail: Taxo.ai, Inc., 169 Madison Ave STE 80892, New York, NY 10016
Website: https://www.taxo.ai
© 2026 Taxo.ai, Inc.. All rights reserved.