Legal

Privacy notice

Last updated 29 September 2026.

This notice describes how the product and this website behave today. For a customer, the governing terms are the executed agreement and its data processing addendum; this page explains our practice and is not itself the contract.

1. Who we are

Adelo Health, LLC builds two products. Adelo CRM is field sales software for commercial teams that call on physician offices. Adelo Drive records business mileage and prices it for reimbursement; it is sold on its own and also works alongside the CRM. In this notice “we” and “us” mean Adelo Health, LLC, the entity that operates adelotechnologies.com and both applications and that is the data controller named below. Adelo Workforce (getadelo.com), Adelo Consulting (adeloconsulting.com) and Adelo Docs (adelodocs.com) are sibling brands of the same entity; this notice covers Adelo CRM, Adelo Drive and this website.

For data inside the product — your reps, your imported target files, your activity records — your organization is the controller and we are the processor: we handle it on your instructions under your agreement. For data you give us through this website, we are the controller.

2. What we do not collect

Adelo CRM is scoped to exclude protected health information. It holds provider-level commercial data — the contents of a vendor target file — plus your own reps’ activity and routes. It is not a clinical system, holds no patient record, and no field in it is designed to accept a patient identifier, diagnosis, encounter or result. Because it does not receive or maintain PHI on your behalf, it does not act as a HIPAA business associate and no business associate agreement is required. See the security overview for the fuller statement.

We do not sell personal data, we do not rent or broker it, and we do not share it for anyone else’s advertising. We have no advertising business.

3. This website

Page views

We record page views first-party, using our own endpoint. There are no third-party analytics SDKs on this site — no Google Analytics, no advertising pixels, no session recorders, no cross-site identifiers and no fingerprinting.

The only identifier is a random UUID stored in a first-party cookie named adelo_aid, which lets us count returning visits without knowing who you are. It expires after one year and you can clear it at any time.

If your browser sends a Do Not Track header or a Global Privacy Control signal, tracking is skipped entirely. No request is made, no cookie is written, and no page view is recorded. This is checked before anything else happens, both in the browser and again at our endpoint.

Cookies we set

  • adelo_aid — random visitor identifier, one year, first-party. Not set when DNT or GPC is present.
  • adelo_utm — first-touch campaign parameters, thirty days, so a demo request made three pages later still carries its source. Not set when DNT or GPC is present.
  • adelo-theme — stored in local storage, not a cookie. Remembers whether you chose the light or dark theme. Never transmitted.

We set no advertising, retargeting or third-party cookies of any kind.

Forms

When you submit a demo request or contact form we collect what you type — name, work email, organization, role, job title, the size of your field team and target file if you give them, phone if you give it, and your message — together with the page you submitted from, the referring page, campaign parameters, your IP address and your browser user-agent string.

We use it to respond to your request and to keep a record of the conversation in our own CRM. It is not sold and is not loaded into an advertising platform. If it is not a fit, we will say so and stop contacting you.

4. The products

Adelo CRM

Inside Adelo CRM we process, on your organization’s instructions: the contents of the territory files you import (NPI, provider name, specialty, practice, address, and the vendor’s ranking and volume columns); the objects derived from them (practices, providers, tiers, zones, planned days, routes, stops, tasks and opportunities); logged calls and notes written by your users; your users’ own names, work email and role; and, for a user who adds one, the home their field days start from.

Adelo CRM does not track the location of your people. Routing operates on the coordinates of physician offices. In the CRM there is no background location collection, no continuous location history for any rep, and no geofence. A rep can choose to start a day from where they are standing; that position is read once, while the app is open, to order that day’s calls, and it is kept only if the rep chooses to depart from it, as that one day’s starting point. A rep can also save where their days start: a home address they type, or the spot they are standing on when they choose to save it. Only that rep can read their home, and they can change or remove it at any time; a saved day’s map shows where that day starts to the people who can see the day. A logged call records that a rep says they visited a practice on a date, and is stored as exactly that. Adelo Drive is a different product with a different answer, set out below — it records drives, and it is the only place in anything we build that does.

We do not use your data to train models. The planning pipeline is deterministic arithmetic with published weights, not a learned model, so there is nothing in it that would benefit from your data even if we wanted to.

Messages between colleagues

Adelo CRM includes messaging inside a single organization’s workspace. We process the text of those messages, the identity of who wrote each one, and when. There is no public surface of any kind: no feed, no discovery, no profile page, no way to reach anyone outside your own organization, and no way to join without an invitation from an administrator of that organization. Row-level security in PostgreSQL enforces the boundary — a signed-in user of one company cannot read a message belonging to another, and a member of one private channel cannot read another, regardless of seniority.

The author’s name is stored on the message rather than looked up when it is read. That is deliberate: a thread where half the messages say “Unknown” after somebody leaves the company is not a record of what was said. A message can be withdrawn by the person who wrote it at any time, and a manager or administrator can withdraw anything posted in a shared channel. Direct messages between two people are outside a manager’s reach; the sender alone can withdraw one.

Photographs attached to messages

A user can attach a picture to a message — in practice a requisition that came back filled in wrong, a label on a fridge, a courier placard on a door. Images are stored in a private bucket scoped to the organization that posted them, capped at 12 MB, and served only to signed-in members of that same organization through URLs that are signed and expire within the hour. They are never public, never used for anything but showing the message they belong to, and never used for advertising, analytics, personalization or model training. We access the camera or photo library only at the moment you choose a picture to attach, and only with the permission iOS asks you for.

Dictation does not send us audio. Speech-to-text runs on Apple’s own on-device speech recognition through the system’s Web Speech bridge. The app receives the transcribed text; it never receives, records, transmits or stores the recording. There is nothing for us to declare because nothing reaches us.

Adelo Drive

Adelo Drive exists because of one rule. A mileage reimbursement stays tax-free only if the record behind it carries four things — how far, what date, where to, and what for (Reg. §1.274-5T). Without them the money an employer pays a driver becomes taxable wages on the driver’s W-2. Everything the product records is one of those four, and nothing it records is anything else.

A driver may enter drives by hand, in which case no location is read at any point. Reimbursement never depends on automatic capture, and we say so on the screen where a driver decides.

Automatic drive capture

Adelo Drive can record drives in the background, and only after the driver switches it on themselves. Nothing in the product turns it on: not an administrator, not their employer, not us. Four conditions must all hold before a single drive is recorded, and they are enforced in the database rather than by the screens — an insert that does not satisfy them is refused, not filtered:

  • Consent. The driver has read the disclosure and agreed to it, and we store which version of the text they were shown. Rewording it without issuing a new version would leave a record saying somebody agreed to sentences they never saw.
  • The switch is on. The driver owns it and can turn it off at any moment, for a couple of hours or for good.
  • It is inside their own hours. The driver sets the days and times. Outside that window nothing is captured, unless the driver has separately chosen to allow it.
  • No pause is running. A pause expires by itself, because a pause you have to remember to undo becomes a month of missing mileage.

What a recorded drive contains: when it started and ended, where it started and ended, and how far it was. That is the whole list. There is no route line, no speed, no breadcrumb trail, and no live position — not withheld from a screen, but absent from the database. There is no column in the product that could hold a movement trail, and the migration that created these tables asserts that no such column has appeared before it will apply.

What the employer sees, and what they never see

An employer sees a drive only after the driver has classified it as business or as commute, and a business drive only once the driver has written what it was for. Until the driver decides, a captured drive is visible to that driver and to nobody else — not their manager, not an administrator, not the owner of the account. That is not a setting; row-level security in PostgreSQL permits exactly one reader, and no policy granting any other role exists on the table.

A drive the driver marks personal is deleted where it stands: the places and the coordinates are removed at that moment, and what remains is a tombstone recording that a drive existed and was discarded. We keep that much so that “my August is missing” is an answerable question, and nothing about where the car went. A drive taken while the switch is off is never recorded at all — it does not reach us, so it cannot reach them.

We do not use any of this to locate a person. Not for the employer, not for us. Drive capture is not a workforce-monitoring feature and it is not offered as one; a company that wants to know where its people are will not find it here.

Reimbursement programs

Where an organization runs a fixed and variable rate (FAVR) program, the fixed half of the allowance is priced on the postal code where the driver’s car is kept overnight, because that is what vehicle insurance is priced on. We hold that postal code, the vehicle’s details, and — where the program requires proof of the insurance it is reimbursing — the documents the driver uploads. A driver’s home address is not exposed to their manager, and the vehicle identification number and plate of a personally owned car are not either.

5. Legal bases

  • Contract — providing the product to your organization and responding to a request you made.
  • Legitimate interests — securing the service, preventing abuse, and first-party measurement of our own website where you have not objected. Where you signal DNT or GPC we treat that as an objection and stop.
  • Consent — marketing email, which you give explicitly and can withdraw in one click.
  • Legal obligation — where we must retain or disclose something by law.

6. Retention

  • Website page-view records: 24 months, then deleted.
  • Form submissions and CRM records: for the duration of the relationship and 24 months after last contact, unless you ask us to delete them sooner.
  • Customer product data, including imported target files: for the term of your agreement, then deleted or returned per that agreement.
  • Security and operational logs: 12 months.
  • Captured drives and mileage records: for the term of your agreement, then deleted or returned with the rest of your product data. Note the two exceptions that run shorter. A drive a driver marks personal has its places and coordinates removed at the moment they mark it, not at the end of a retention period. And a drive taken while capture is switched off has no retention period because it is never recorded: it does not leave the phone.
  • Consent records: for as long as the driver is on the program and six years after, because the record of who agreed to what, and to which version of the text, is the evidence that the capture was permitted. Withdrawing consent stops capture at once and does not erase the fact that it was given and withdrawn.
  • Insurance and vehicle documents uploaded for a FAVR program: for the term of your agreement plus the period your own tax records require, since they substantiate the allowance that was paid.
  • Messages between colleagues and any photographs attached to them: for the term of your agreement, then deleted with the rest of your product data. A message withdrawn by its author, a manager or an administrator is removed from every view immediately.

7. Subprocessors

We use third parties for cloud infrastructure, managed database and authentication, account email (sign-in confirmation and password reset), and the road geometry and map tiles behind the planner’s map — the last of which receive coordinates only, never a provider, practice or user record. A distance-matrix provider is involved only if you configure one, and is billed on your own account. Data is stored in the United States.

The current named list, with locations and purposes, is provided under the data processing agreement and on request to security@adelohealth.com.

8. Your rights

Subject to your jurisdiction, you may request access to your personal data, correction of it, deletion of it, a portable copy of it, restriction of processing, or object to processing. You may withdraw consent to marketing at any time.

If you are an employee of a customer, ask us and we will help — but for data held under your employer’s instructions we will normally need to route the request through them, because they are the controller.

Requests go to hello@adelohealth.com. We aim to respond within thirty days and will tell you if we need longer.

9. Security

Authentication runs on a managed provider. Access is role- and territory-scoped. Tenant isolation is enforced with Postgres row-level security attached to the tables themselves, so an application-code mistake cannot leak another tenant’s rows. Traffic is encrypted in transit.

We hold no SOC 2 report, no HITRUST certification and no ISO 27001 certification, and no independent penetration test has been performed. The security page states plainly what is and is not in place.

10. Children

Adelo CRM is a workplace product intended for people in employment. It is not directed to children and we do not knowingly collect data from anyone under 16.

11. Changes

We will update the date at the top when this changes. For material changes affecting customers we will give notice through the product or by email before they take effect.

12. Contact

Privacy requests: hello@adelohealth.com. Security: security@adelohealth.com. Anything else: hello@adelohealth.com.

See also the terms of service.