Privacy Policy

Last Updated: April 16, 2026

1. Introduction

One Clinical Engine Inc. d/b/a OneDash ("Company," "we," or "our") respects your privacy and is committed to protecting it through our compliance with this policy.

OneDash develops, operates, and distributes a Software-as-a-Service ("SaaS") platform that enables health plans, payers, and care management organizations to identify and close care gaps, automate member outreach, and improve quality outcomes. The platform, together with its associated tools, dashboards, APIs, automated communication workflows, and data analytics services, is collectively referred to as the "Service."

This policy describes the types of information we may collect from you or that you may provide when you visit our website at onedashengine.com, access our web-based platform, interact with our application programming interface ("API"), or use our SaaS offerings. It also explains our practices for collecting, using, maintaining, protecting, and disclosing that information.

Capitalized terms used herein without definition will have the same meanings as defined in the Terms of Service and any applicable Master Services Agreement, SaaS Agreement, or Business Associate Agreement ("BAA") executed with us.

A note on health plan member data: OneDash's platform is used by health plan customers to manage and engage their members. Where OneDash processes Protected Health Information ("PHI") about health plan members on behalf of a health plan customer, that processing is governed by a Business Associate Agreement between OneDash and the applicable customer, and by the health plan's own privacy notices to its members — not by this Privacy Policy. This Privacy Policy primarily governs information collected from and about our business customers, their authorized platform users, and visitors to our website.

OneDash acts solely as a service provider to its customers and does not independently determine the purposes or means of processing member data. For personal information of platform users, OneDash acts as a business providing services to its customers. For PHI, OneDash acts as a Business Associate as defined under HIPAA. Except where otherwise expressly stated, OneDash processes data solely on behalf of its customers and in accordance with their instructions.

2. Scope of This Policy

This Privacy Policy applies to all products and services offered by One Clinical Engine Inc. d/b/a OneDash ("Company"), including the OneDash platform, website at onedashengine.com, APIs, and any associated tools or services (collectively, the "Services").

This Privacy Policy governs information collected from and about:

  • Platform users — employees, administrators, care managers, and other authorized users of health plan customers who access and use the OneDash platform
  • Website visitors — individuals who visit our website
  • Prospective customers — individuals who inquire about or request a demo of our Services

This Privacy Policy does not govern the processing of health plan member data (including Protected Health Information) that OneDash handles on behalf of its health plan customers. That processing is conducted under the terms of a Business Associate Agreement ("BAA") executed between OneDash and each applicable customer, and is subject to the health plan's own privacy notices to its members.

3. Children Under 13

The Service is intended solely for use by business professionals and is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected personal information from a child under 13, we will promptly delete that information.

If you believe we may have any information from or about a child under 13, please contact us at:

One Clinical Engine Inc. d/b/a OneDash 

1444 I St NW, Suite 600 

Washington, DC 20005 

privacy@onedashengine.com

California residents under 16 years of age may have additional rights regarding the collection and sale of their personal information. Please see the California Privacy Rights section of this policy for more information.

4. Information We Collect About You and How We Collect It

We collect several types of information from and about users of our Service. The categories below describe what we collect, from whom, and for what purpose.

1. Platform User Account Information

When an authorized user registers for or accesses the OneDash platform on behalf of a health plan customer, we may collect:

  • Name, job title, and professional contact details (email address, phone number)
  • Username, password, and account security information
  • Organization name and your role within that organization
  • Communications and correspondence with our team, including support requests

2. Customer Organization Information

At the business account level, we collect information about our health plan customers, including:

  • Organization name, billing address, and contact details
  • Contracting and billing information as set out in applicable Statements of Work or Master Services Agreements

3. Platform Usage Data

As you use the OneDash platform, we automatically collect information about how you interact with the Service, including:

  • Dashboard and report activity, workflow configurations, and feature usage
  • Log data, IP addresses, browser type, operating system, and device information
  • Session duration, page views, and navigation patterns within the platform
  • Search queries entered within the Service

4. AI CoPilot & Automated Feature Inputs

Where you interact with AI-powered features within the platform, we may collect:

  • Inputs, prompts, and queries submitted to AI features
  • Outputs generated and any feedback or ratings provided
  • Anonymized usage data used to monitor and improve AI feature performance

For important guidance on what information should not be submitted into AI features, including PHI restrictions, please see the AI Features section of this policy.

5. Communications Data

We collect information when you communicate with us, including:

  • Emails, support tickets, and chat communications with our team
  • Responses to surveys or feedback requests
  • Information provided when requesting a demo or during onboarding

A note on health plan member data: OneDash's platform ingests and processes health plan member data — including claims, lab results, EHR data, pharmacy records, social determinants of health, and other health-related information — on behalf of our health plan customers. This data is provided to OneDash by the customer and is processed solely under the terms of the applicable Business Associate Agreement. It is not collected by OneDash directly from members and is not governed by this section of the Privacy Policy.

5. How We Collect Information

We collect information about you in the following ways:

1. Directly From You

We collect information you provide directly when you register for an account, contact our support team, respond to surveys, request a demo, or otherwise communicate with us.

2. Automatically Through the Service

As you navigate and interact with our Service — both the public website and the OneDash platform — we use automatic data collection technologies to collect certain information about your device, browsing actions, and usage patterns, including:

  • IP address, browser type, operating system, and device information
  • Pages visited, features accessed, and navigation patterns within the platform
  • Session duration, timestamps, and log data
  • Session management data used to maintain your authenticated session and keep you securely logged in

The technologies we use for automatic data collection include:

  • Cookies — Small files placed on your device that help us maintain your session, remember your preferences, and understand how the Service is used. You may configure your browser to refuse cookies, though doing so may affect your ability to access certain parts of the Service.
  • Web Beacons — Small electronic files (also known as clear gifs or pixel tags) embedded in pages or emails that help us track page visits, email opens, and general usage statistics.
  • Analytics Tools — We use internal analytics and monitoring tools, and may use limited third-party service providers, to understand platform usage and improve the Service. These tools may collect information about your interactions with the platform in aggregated or de-identified form.

Cookies and tracking technologies on the OneDash platform are used primarily for authentication, security, and service improvement purposes — not for advertising or behavioral tracking across third-party websites.

3. From Third Parties

We may receive information about your organization or your account from third parties, such as from our health plan customers when they set up authorized user accounts on your behalf.

6. How We Use Your Information

We use the information we collect for the following purposes:

1. To Provide and Operate the Service

  • To create and manage your platform account and authorized user access
  • To deliver the features, tools, dashboards, and workflows that make up the OneDash platform
  • To process and respond to support requests and communications
  • To fulfill our obligations under applicable Statements of Work and Master Services Agreements

2. To Improve and Develop the Service

  • To monitor platform performance, diagnose technical issues, and maintain service reliability
  • To analyze how the platform is used in order to improve existing features and develop new ones
  • To conduct internal research and testing
  • To improve the AI-powered features within the platform, including the AI CoPilot, using anonymized or aggregated usage data
  • We do not use one customer's data to benchmark, train models, or generate insights in a manner that identifies or exposes another customer's data

3. To Communicate With You

  • To send you account-related notices, including security alerts, platform updates, and changes to our terms or policies
  • To respond to your inquiries, feedback, and support requests
  • To send product updates, service announcements, and other business-related communications to platform users. These communications are sent in a professional context and are not consumer marketing communications or mobile messaging campaigns.

4. To Send Automated Member Outreach on Behalf of Customers

OneDash's platform enables health plan customers to conduct automated outreach to their members — including SMS messages, calls, and other communications — as part of care gap closure workflows and quality improvement programs. Where OneDash sends such communications, it does so strictly on behalf of and under the direction of the applicable health plan customer. Health plan customers are responsible for ensuring that their members have provided appropriate consent to receive such communications, and for the content and legality of communications sent through the platform. OneDash does not independently verify the sufficiency of consents obtained by customers and does not use member contact information for its own marketing purposes.

Mobile opt-in data and consent obtained in connection with member outreach programs is used solely to deliver the communications authorized by the applicable health plan customer and will not be shared with any third party for marketing or promotional purposes.

5. To Produce Analytics and Reporting

  • To generate the dashboards, reports, and population-level insights that are core to the Service
  • To produce aggregated or de-identified analytics that may be used to improve the Service, in a manner that does not identify any individual member or customer

6. For Security and Fraud Prevention

  • To protect the security and integrity of the platform and its users
  • To detect, investigate, and prevent unauthorized access, fraud, and other harmful activity
  • To enforce our Terms of Service and other applicable agreements

7. To Comply With Legal Obligations

  • To comply with applicable laws, regulations, and legal processes
  • To respond to lawful requests from government authorities or courts
  • To exercise or defend our legal rights

8. For Any Other Purpose With Your Consent

We may use your information for other purposes not listed above where we have obtained your consent to do so.

7. Disclosure of Your Information

We do not sell, rent, or monetize your personal information to third parties. We may disclose aggregated or de-identified information that does not identify any individual user or organization without restriction.

For purposes of this policy, "affiliates" means entities under common ownership or control with OneDash.

We may disclose personal information that we collect or that you provide in the following circumstances:

1. Service Providers and Subprocessors

We share information with third-party vendors and service providers that support the operation and delivery of the Service, including cloud infrastructure providers, analytics tools, customer support platforms, and communication delivery services. These third parties are contractually required to keep your information confidential and to use it only for the purposes for which we disclose it to them. A current list of subprocessors is available upon request.

2. AI Feature Providers

Where you interact with AI-powered features within the platform, your inputs may be processed by third-party LLM providers engaged by OneDash. We do not share personally identifiable account information — such as your name, username, or email address — with these providers. Where AI Features are used in connection with PHI, such processing will occur only where expressly permitted under an applicable BAA and subject to appropriate safeguards.

3. At the Direction of Health Plan Customers

OneDash processes and shares member data strictly at the direction of and on behalf of its health plan customers, under the terms of applicable Business Associate Agreements. Such sharing is governed by the BAA and the health plan customer's own obligations, not by this Privacy Policy.

4. Mobile Opt-In Data — No Third Party Sharing

Mobile opt-in data and phone numbers will not be shared with third parties or affiliates for marketing or promotional purposes.

Mobile opt-in data and phone numbers collected for SMS purposes are not shared with any third party for marketing or promotional purposes. Mobile opt-in data and consent collected in connection with member outreach programs conducted through the OneDash platform is used solely to deliver the communications authorized by the applicable health plan customer. This data is not sold, rented, or disclosed to any third party for their own marketing use under any circumstances.

5. Business Transfers

In the event of a merger, acquisition, reorganization, dissolution, or sale of all or part of One Clinical Engine Inc.'s assets, personal information held by OneDash may be transferred to the successor entity as part of that transaction. We will notify affected users of any such transfer and any material changes to how their information is handled.

6. Legal Compliance and Safety

We may disclose your information where required to do so by law or in response to valid legal process, including court orders, subpoenas, or government requests. We may also disclose information where we reasonably believe disclosure is necessary to protect the rights, property, or safety of OneDash, our customers, or others, or to detect and prevent fraud or security incidents.

7. With Your Consent

We may share your information for purposes not described above where we have obtained your consent to do so.

8. AI Features

The OneDash platform includes features powered by artificial intelligence ("AI Features"), including but not limited to the AI CoPilot, which assists care teams with medication intelligence, therapy management guidance, care gap identification, and clinical decision support.

How AI Features Work

AI Features process the inputs you submit and return machine-generated outputs. To generate these responses, your inputs may be transmitted to third-party LLM providers engaged by OneDash. We do not share your account information — such as your name, username, email address, or organization — with these providers. Where AI Features are used in connection with PHI, such processing will occur only where expressly permitted under an applicable BAA and subject to appropriate safeguards.

What Not to Submit

Unless your organization has executed a Business Associate Agreement ("BAA") with OneDash that expressly covers AI feature usage, please do not submit Protected Health Information ("PHI") — including member names, dates of birth, member IDs, diagnosis codes, or other individually identifiable health information — into AI Features. If you are unsure whether your organization's BAA covers AI feature usage, please contact your OneDash account manager or our privacy team at privacy@onedashengine.com.

AI Feature Outputs

Outputs generated by AI Features are machine-generated and may not always be accurate, complete, or up to date. All clinical recommendations or guidance produced by AI Features should be reviewed by a qualified healthcare professional before being acted upon. OneDash does not warrant the accuracy of AI-generated outputs and is not liable for decisions made in reliance on them.

9. HIPAA & Protected Health Information

OneDash's Role Under HIPAA

OneDash operates as a Business Associate (as defined under the Health Insurance Portability and Accountability Act of 1996, "HIPAA") to its health plan customers, which are Covered Entities under HIPAA. In this capacity, OneDash processes Protected Health Information ("PHI") on behalf of and under the direction of those customers, solely as permitted by the applicable Business Associate Agreement ("BAA") and consistent with HIPAA and its implementing regulations.

OneDash is not itself a Covered Entity and does not have a direct HIPAA relationship with health plan members whose data flows through the platform. OneDash primarily acts as a service provider and processes data in accordance with customer instructions.

Business Associate Agreements

Before processing any PHI on behalf of a health plan customer, OneDash requires that customer to execute a BAA with OneDash. The BAA governs the permitted uses and disclosures of PHI, security obligations, breach notification procedures, and data return or destruction upon termination of the customer relationship. If you are a health plan customer and have not yet executed a BAA with OneDash, please contact us at privacy@onedashengine.com before submitting any PHI to the platform.

Security Safeguards

OneDash implements administrative, physical, and technical safeguards designed to protect PHI against unauthorized access, use, disclosure, alteration, and destruction, in accordance with the HIPAA Security Rule. These safeguards are detailed in our security documentation, which is available to customers upon request.

Breach Notification

In the event of a breach of unsecured PHI, OneDash will notify the applicable health plan customer in accordance with the breach notification requirements of HIPAA and the terms of the applicable BAA. The health plan customer is responsible for notifying affected members and, where required, the U.S. Department of Health and Human Services.

Member Rights Under HIPAA

Health plan members whose PHI is processed through the OneDash platform should direct any requests to exercise their HIPAA rights — including rights to access, amend, or restrict the use of their PHI — to the applicable health plan, not to OneDash. OneDash will cooperate with health plan customers in responding to such requests as required by the applicable BAA and HIPAA.

Scope

This section applies only to PHI processed by OneDash on behalf of its health plan customers. Information collected from platform users — such as account data and usage analytics — is not PHI and is governed by the other sections of this Privacy Policy.

10. SMS and Electronic Communications

Overview

OneDash's platform enables health plan customers to conduct automated outreach to their members via SMS messages, calls, and other electronic communications as part of care gap closure workflows, medication adherence programs, and quality improvement initiatives. OneDash sends these communications as a platform service provider acting on behalf of and under the direction of its health plan customers.

Member Communications Sent on Behalf of Health Plan Customers

Where OneDash sends SMS messages or other automated communications to health plan members on behalf of a health plan customer, the following applies:

  • Messages may include care gap reminders, medication adherence outreach, appointment notifications, health program enrollment invitations, and other care management communications authorized by the health plan customer
  • Message frequency will vary depending on the health plan customer's program configuration and the member's care needs
  • Standard message and data rates may apply
  • Members may opt out of SMS communications at any time by replying STOP to any message. Members may reply HELP for assistance
  • Health plan customers are responsible for obtaining all necessary consents from their members prior to initiating any outreach through the OneDash platform, in compliance with the Telephone Consumer Protection Act ("TCPA") and all other applicable laws and regulations. Customers are responsible for the content and legality of communications sent through the platform
  • OneDash does not independently verify the sufficiency of consents obtained by customers and disclaims responsibility for customers' compliance with applicable communication laws, including the TCPA
  • OneDash does not send unsolicited marketing messages to health plan members and does not use member contact information for OneDash's own marketing purposes

Mobile Opt-In Data — No Third Party Sharing

Mobile opt-in data and phone numbers collected for SMS purposes are not shared with any third party for marketing or promotional purposes. Mobile opt-in information and consent data collected in connection with member outreach programs conducted through the OneDash platform is used solely to deliver the communications authorized by the applicable health plan customer. This information will not be sold, rented, or disclosed to any third party for marketing or promotional purposes under any circumstances.

Platform User Communications

OneDash may send electronic communications to authorized platform users — such as health plan employees and care managers — regarding their use of the Service, including account notifications, product updates, security alerts, and support communications. These communications are sent in a business context and are not consumer marketing communications or mobile messaging campaigns. Platform users may opt out of non-essential communications by contacting us at privacy@onedashengine.com. Opting out of essential account and security notifications is not available while your account remains active.

TCPA Compliance

OneDash designs its platform to support compliance with the Telephone Consumer Protection Act ("TCPA") in the operation of its automated communication features. Health plan customers using OneDash's outreach capabilities are independently responsible for ensuring their use of the platform complies with TCPA and any applicable state laws governing automated communications.

Contact

For questions about communications sent through the OneDash platform, please contact us at privacy@onedashengine.com.

11. Do Not Track

Some web browsers have a "Do Not Track" ("DNT") feature that signals to websites that you do not want your online activity tracked. Currently there is no universally accepted standard for how websites should respond to DNT signals, and OneDash does not alter its data collection or use practices in response to DNT signals from your browser.

If a standard for DNT compliance is adopted in the future, we will update this policy accordingly.

For information about how to limit data collection through cookies and tracking technologies, please see the How We Collect Information section of this policy.

12. Your Choices and Controls

We provide you with the following controls over your information:

Cookies and Tracking Technologies

You can configure your browser to refuse all or some cookies, or to alert you when cookies are being sent. Please note that disabling cookies may affect your ability to access or use certain features of the OneDash platform. For more information see the How We Collect Information section of this policy.

Product and Service Communications

OneDash may send communications to platform users regarding product updates, service announcements, and other business-related matters. These communications are sent in a professional context and are not consumer marketing communications. OneDash does not use personal information to conduct marketing outreach to health plan members.

If you do not wish to receive product updates or service-related communications from OneDash, you may opt out by:

Please note that opting out does not apply to essential service communications such as account notifications, security alerts, platform updates, or communications required under our agreements with your organization. These will continue for as long as your account is active.

SMS Communications

For information about opting out of SMS communications sent through the OneDash platform, please see the SMS and Electronic Communications section of this policy.

California Residents

California residents may have additional privacy rights and choices under the California Consumer Privacy Act. Please see the California Privacy Rights section of this policy for more information.

Nevada Residents

Nevada residents who wish to exercise sale opt-out rights under Nevada Revised Statutes Chapter 603A may submit a request to privacy@onedashengine.com. OneDash does not currently sell personal information in a manner that triggers that statute's opt-out requirements.

13. Accessing and Correcting Your Information

If you are an authorized platform user and wish to review, correct, or delete the personal information OneDash holds about you, you may submit a request by contacting us at privacy@onedashengine.com. We will respond to your request within a reasonable timeframe.

We may decline a request to change information if we believe the change would violate any applicable law or cause the information to be inaccurate. In some cases, deletion of your personal information may require deletion of your user account.

California Residents

California residents may have additional rights regarding their personal information under the California Consumer Privacy Act. Please see the California Privacy Rights section of this policy for more information.

14. Data Security and Retention

Our Security Measures

OneDash implements administrative, physical, and technical safeguards designed to protect the information we collect and maintain against unauthorized access, use, disclosure, alteration, and destruction. These measures include encryption of data in transit and at rest, access controls and authentication requirements, regular security assessments and monitoring, and contractual security obligations imposed on our third-party service providers and subprocessors.

We maintain a security program designed to meet the requirements of applicable laws and regulations, including HIPAA where applicable. Customers may request additional information about our security practices and documentation by contacting us at privacy@onedashengine.com.

Data Retention

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, to provide our Services, and to comply with our legal obligations. Our general retention principles are:

  • Platform user account data is retained for the duration of the customer relationship and for a reasonable period thereafter to fulfill legal, contractual, and compliance obligations
  • Usage and log data is retained for as long as necessary for security monitoring, performance analysis, and service improvement purposes
  • Communications and support data is retained as needed to resolve issues and maintain service records
  • PHI processed on behalf of health plan customers is retained and destroyed in accordance with the terms of the applicable Business Associate Agreement
  • Backup copies of data may persist for a limited period beyond deletion of primary records in accordance with our standard backup and disaster recovery practices
  • We may retain certain information for longer periods where required by law, regulation, or legal process

Upon termination of a customer relationship, customer data will be handled in accordance with the applicable Statement of Work, Master Services Agreement, and Business Associate Agreement.

Your Responsibilities

The security of your account also depends on you. You are responsible for maintaining the confidentiality of your login credentials and for ensuring that unauthorized individuals do not access your account. You agree to notify us immediately at privacy@onedashengine.com if you become aware of any unauthorized access to or use of your account.

Limitations

While we work hard to protect your information, no security measures are perfect or impenetrable and no method of data transmission over the internet can be guaranteed to be completely secure. We cannot guarantee the absolute security of information transmitted to or through the Service, and any such transmission is at your own risk.

Breach Notification

In the event of a security incident affecting non-PHI personal information of platform users, OneDash will notify affected users in accordance with applicable data breach notification laws. For PHI breach notification, please see the HIPAA & Protected Health Information section of this policy.

Privacy Officer and Oversight

OneDash has designated a Privacy Officer responsible for overseeing our privacy and data security program, including:

  • Regularly reviewing and updating our privacy policies and practices to ensure compliance with applicable laws and regulations
  • Overseeing employee training on data privacy and security
  • Conducting or commissioning periodic audits of our privacy and security measures
  • Serving as the primary point of contact for privacy-related inquiries, complaints, and requests

Any violations of this Privacy Policy by our employees or service providers will be taken seriously and may result in disciplinary action up to and including termination of employment or contract. To report a privacy or security concern, please contact our Privacy Officer at privacy@onedashengine.com.

15. California Privacy Rights

Privacy Rights Under the California Consumer Privacy Act ("CCPA") as Amended by the California Privacy Rights Act ("CPRA")

If you are a California resident, California law provides you with certain rights regarding your personal information. This section describes those rights and how to exercise them.

This section applies to personal information OneDash collects from platform users, authorized account contacts, and website visitors who are California residents. It does not apply to health plan member data processed by OneDash under a Business Associate Agreement, which is governed by HIPAA and the applicable health plan's own privacy notices.

Categories of Personal Information We Collect

As described in this Privacy Policy, we collect the following categories of personal information from platform users and website visitors:

  • Identifiers such as name, email address, phone number, and IP address
  • Professional or employment-related information such as job title and organization name
  • Internet or other network activity such as platform usage data, log data, and browser information
  • Inference data derived from usage patterns to understand how the Service is used
  • Communications data such as support requests and correspondence

We do not sell, rent, or monetize personal information and have not done so in the preceding 12 months.

Your Privacy Rights

As a California resident you have the following rights with respect to your personal information:

  • Right to Know — You have the right to request details about the personal information we have collected about you, including the categories of information, the sources, the business purposes for collection, and the categories of third parties with whom we have shared it
  • Right to Access — You have the right to request a copy of the specific personal information we have collected about you
  • Right to Correct — You have the right to request that we correct inaccurate personal information we hold about you
  • Right to Delete — You have the right to request deletion of personal information we have collected about you, subject to certain exceptions under applicable law
  • Right to Opt Out of Sale or Sharing — You have the right to opt out of the sale or sharing of your personal information. OneDash does not sell, rent, or monetize personal information or share it for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information — To the extent OneDash collects sensitive personal information as defined under the CPRA, you have the right to limit its use to purposes permitted by law
  • Right to Non-Discrimination — We will not discriminate against you for exercising any of the rights described above

Exercising Your Rights

To exercise any of the rights described above, you or your authorized agent may submit a request by:

  • Emailing us at privacy@onedashengine.com
  • Writing to us at One Clinical Engine Inc. d/b/a OneDash, 1444 I St NW, Suite 600, Washington, DC 20005

Your request must provide sufficient information for us to verify your identity and describe your request in enough detail for us to understand, evaluate, and respond to it. We will respond to verified requests within 45 days of receipt. If we require additional time we will notify you of the reason and the extension period, up to an additional 45 days where permitted by law.

We will not charge a fee for processing your request unless it is excessive, repetitive, or manifestly unfounded. If a fee applies we will notify you before completing your request.

You may authorize an agent to submit a request on your behalf by providing the agent with written permission to do so. We may request a copy of that written permission when the agent submits the request.

16. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time. Any material changes that affect the collection, use, or disclosure of personal information will be communicated to existing platform users via email and/or through a prominent notice on our website or within the platform prior to the changes taking effect. The date this Privacy Policy was last revised is identified at the top of the page.

Your continued use of the Service following notice of any changes constitutes your acceptance of the updated Privacy Policy. You are responsible for ensuring that OneDash has a current and deliverable email address for you and for periodically reviewing this policy for updates.

Account Termination and Data Retention

If your user account is terminated — whether by you or by OneDash — we will remove your personal account data from the Service in accordance with our data retention practices described in Section 14. We may retain data in aggregated or de-identified form that does not identify you individually.

For health plan customers, the return or destruction of PHI and customer data upon termination of the customer relationship is governed by the terms of the applicable Statement of Work, Master Services Agreement, and Business Associate Agreement.

Contact Information

If you have any questions, comments, or concerns about this Privacy Policy or our privacy practices, please contact us at:

One Clinical Engine Inc. d/b/a OneDash 

1444 I St NW, Suite 600 

Washington, DC 20005 

privacy@onedashengine.com