Privacy Policy
Last updated: September 17, 2026
16 Bit Inc. (
"16 Bit",
"we", or
"us") is a Canadian medical AI company headquartered in Toronto, Ontario. We develop software medical devices, including Rho and Physis, that healthcare professionals use to reveal information in routine medical images. This Privacy Policy explains how we handle personal information about the people we interact with. It applies to our websites (including
16bit.ai), our cloud-based Services as defined in our Terms of Service (including Rho Direct, the Rho Direct API, and Physis), and our business relationships with customers, distributors, partners, and prospective customers.
The most important thing to know
This policy is about information relating to
you: our users, customers, business contacts, and website visitors. It is not about your patients.Our cloud-based products are designed so that identifiable patient information does not reach 16 Bit. Where a healthcare facility gives us access to patient information so that we can support software installed at the facility, we act as the facility's service provider under contract, and the facility's own privacy notice governs. Section 2 explains this in more detail.
1. Who This Policy Covers
We collect personal information about:
• Users: individuals who create accounts or use our Services through a web application, an API, or software we provide for installation in their environment, including Authorized Users of organizational accounts.
• Business contacts: personnel of our customers, distributors and resellers, suppliers, partners, prospective customers, and research collaborators.
• Website visitors and people who contact us, subscribe to updates, or attend our events or webinars.
• Job applicants.
2. Patient Information and Our Role
2.1 Cloud Services (Rho Direct, the Rho Direct API, Physis).
These Services are designed so that identifiable patient information does not reach 16 Bit. In the Rho Direct web application, identifiers are removed or encrypted in your browser before upload, using a key that only you hold; 16 Bit receives de-identified image data and results, together with encrypted identifiers that it cannot read. The de-identified status of the data 16 Bit receives through the web application is supported by an independent expert determination under the HIPAA de-identification standard. Where a Service is accessed through its API, or through a component installed in your environment, de-identification takes place in your systems before anything is sent to us, and the mapping between our correlation tokens and your patients stays with you. In Physis, deidentified images and non-identifying values such as age, sex, the result, and any notes you enter are retained. We do not attempt to re-identify anyone from this data. If identifiable information reaches us because in-product instructions or the API documentation were not followed, we delete it in accordance with our internal procedures upon discovery.
2.2 Software Installed at Healthcare Facilities (Rho Enterprise)
Patient data processed by Rho Enterprise remains within the facility's own infrastructure. 16 Bit personnel may access that data only when the facility authorizes it for technical support, and only to the extent necessary. In that limited case we act as the facility's service provider, agent, business associate, or data processor (depending on the jurisdiction) under a written agreement with the facility. The facility remains responsible for the patient data, and its own privacy notice governs. Patients with questions or requests about their information should contact the facility.
2.3 Other
Our internal safeguards for any patient information we may encounter are set out in our Data Privacy and Security procedures, which form part of our ISO 13485 quality management system.
3. Information We Collect
Account and profile information
Name, email address, organization, role or profession, country, language preference, account settings, and the Region assigned to your account (Section 5).
From you, when you register or update your account.
Billing and transaction information
Billing name and address, purchase history, Credits balance or subscription plan and status, currency, the card type, issuing country, and last four digits of your payment card, and tax identifiers. Full payment card details are collected and held by our payment processor, not by us.
From you and from our payment processor.
Usage and technical information
Log data such as IP address, browser and device type, operating system, pages and features used, and dates and times of access; API call logs; account-level activity such as the number of analyses run and their outcomes; error reports; product analytics collected under a pseudonymous identifier; and, for software installed at customer facilities, operational data such as software version, analysis counts, and error logs. None of this is designed to include patient identifiers.
Automatically, when you use our websites and Services.
Support requests and correspondence, feedback, survey responses, event and webinar registrations, and records of complaints or safety reports (which medical device regulations may require us to keep).
From you, when you contact us.
Business contact information
Name, job title, employer, work email and phone number, professional profile information, records of meetings and correspondence, and contract-related details.
From you, your employer, our distributors and resellers, publicly available sources such as professional networking sites and institutional websites, and business contact databases and lead-generation services.
CV, cover letter, and information you provide in an application.
We do not knowingly collect sensitive personal information about you (such as health information, racial or ethnic origin, or biometric data), other than payment information as described above. Please do not send us sensitive information about yourself unless we ask for it.
4. Cookies and Similar Technologies
Our websites and Services use cookies and similar technologies that are strictly necessary for them to function, such as keeping you signed in and protecting against fraud. We also use Google Analytics, which sets cookies to help us understand how our websites are used. We do not use advertising cookies, and we do not deploy customer relationship management tracking scripts on our public websites. You can control cookies through your browser settings; disabling necessary cookies may prevent the Services from working. Our websites may link to third-party sites whose privacy practices we do not control.
5. How We Use Personal Information
Legal basis (where required)
Creating and managing accounts, authenticating users, processing analyses, maintaining case history, providing support.
Performance of a contract.
Billing and account Region
Processing purchases and subscriptions, invoicing, tax compliance, preventing fraud, and determining your account's Region from the issuing country of your payment method. Your Region sets your pricing and whether the Service is used clinically or for Non-Clinical Use, as described in our Terms of Service.
Contract; legal obligation.
Monitoring for unauthorized access, investigating incidents, enforcing our Terms of Service.
Legitimate interests (protecting our users and Services).
Improving our products and Services
Analyzing account-level usage and operational data to understand how features are used, diagnosing errors, planning improvements.
Medical device regulatory obligations
Recording and investigating complaints and safety reports, post-market surveillance, maintaining distribution records, communicating field safety notices.
Managing business relationships
Communicating with customers, distributors, suppliers, and partners; managing contracts, orders, and revenue reporting.
Contract; legitimate interests.
Sending information about our products, publications, and events to healthcare professionals and organizations; inviting prospective customers to speak with us.
Consent where required by law (including Canada's anti-spam legislation); otherwise legitimate interests.
Legitimate interests; consent.
Responding to lawful requests, meeting record-keeping obligations, establishing or defending legal claims.
Legal obligation; legitimate interests.
Automated decision-making. We do not make decisions about you that have legal or similarly significant effects based solely on automated processing. Our Services produce outputs about patients for review by qualified healthcare professionals, who make all clinical decisions.
6. How We Share Personal Information
We do not sell personal information, and we do not share it for advertising. We share it only as follows:
Service providers that process personal information on our behalf and under contract, including cloud hosting (Amazon Web Services, United States regions); productivity, email, and document tools (Google Workspace); payment processing; customer relationship management (HubSpot); product analytics (Mixpanel); email outreach; and source code and development infrastructure (GitHub). These providers may access personal information only to perform services for us.
Distributors and resellers, where you are a customer of, or were introduced to us by, one of our authorized distributors or resellers, we share business contact and account information with them as needed to manage the relationship, and they share information with us for the same purpose. Our distributors are independent organizations responsible for their own privacy practices.
Regulators and authorities, where required by medical device, tax, or other laws, including complaint and safety reports that may include the reporter's contact details.
Professional advisers, such as lawyers, auditors, and insurers, under confidentiality obligations.
Corporate transactions. If 16 Bit is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy.
With your consent or at your direction.
7. International Transfers
16 Bit is located in Canada. Our service providers process personal information in the United States, and some in Canada. If you are outside these countries, your personal information will be transferred to and processed in them, where privacy laws may differ from those of your country.
European Economic Area, United Kingdom, and Switzerland. Transfers to 16 Bit in Canada are covered by the European Commission's adequacy decision for Canadian organizations subject to PIPEDA and the equivalent United Kingdom and Swiss recognition. For transfers to our United States service providers, we rely on the European Commission's Standard Contractual Clauses incorporated in each provider's data processing agreement and, where the provider is certified, on the EU-U.S. Data Privacy Framework and its UK and Swiss extensions.
Australia, Singapore, Vietnam, and other jurisdictions. We take reasonable steps, including contractual protections, to ensure that overseas recipients handle personal information in a manner consistent with this policy and applicable law.
You can ask us for more information about transfer safeguards using the contact details in Section 12.
8. How Long We Keep Personal Information
We keep personal information for as long as your account or business relationship with us is active and, after that, for as long as it is needed for the purposes described in this policy. Because we manufacture regulated medical devices, much of the information we hold about users and customers forms part of records that medical device regulations require us to keep for at least 10 years after the last unit of the relevant product is released (and longer where a regulator requires it). Other legal obligations, such as tax law, set their own periods. We review the information we hold periodically and delete or anonymize information that no longer serves a purpose or is no longer required. You may ask us to delete your information at any time (Section 10); we will do so unless a legal obligation requires us to keep it, in which case we will tell you.
In practice:
Account, support, and usage information relating to a medical device: retained as part of our device records for at least 10 years after the last release of the relevant product, so that we can meet traceability, complaint-handling, and post-market surveillance obligations.
Billing and tax records: at least 7 years, as required by tax law.
Business contact information: for the duration of the relationship and as long as needed afterwards to manage contracts, records, and follow-up, or until you ask us to stop.
Marketing contacts: until you unsubscribe or object, after which we keep only what is needed to honour your choice.
Recruitment information: 2 years after the process ends, unless you ask us to delete it sooner or agree to a longer period.
9. How We Protect Personal Information
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit and at rest, multi-factor authentication for our systems, least-privilege access controls with periodic access reviews, staff privacy and security training, vendor security assessments, and a documented incident response process with defined notification timelines. Our safeguards are maintained under our ISO 13485 quality management system and reviewed at least annually. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights and Choices
Depending on where you live, you may have the right to: access the personal information we hold about you; have it corrected; have it deleted; receive it in a portable format; object to or restrict certain processing; withdraw consent where processing is based on consent; and complain to a privacy regulator. You may exercise these rights, or ask questions, by contacting us at
privacy@16bit.ai. We may need to verify your identity. We will respond within 30 days, or within any shorter period required by law, and we will not treat you differently for exercising your rights.
Marketing. You can unsubscribe from marketing emails using the link in each email or by contacting us. We will continue to send service-related messages, such as security notices, billing confirmations, and regulatory communications, where necessary.
Regional notes:
Canada. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws, including Quebec's Act respecting the protection of personal information in the private sector. Our Privacy Officer is identified in Section 12. You may complain to the Office of the Privacy Commissioner of Canada or to your provincial commissioner. Residents of Quebec may also ask us to stop disseminating their information or to de-index it, and to provide computerized personal information in a structured, commonly used format.
European Economic Area and United Kingdom. We process personal information under the legal bases identified in Section 5. Where we rely on legitimate interests, you may object. We have appointed a Data Protection Officer and an EU representative under Article 27 GDPR (Section 12). You may complain to your local supervisory authority.
United States. We do not sell personal information or share it for cross-context behavioural advertising, and we do not use it for profiling that produces legal or similarly significant effects. Residents of states with comprehensive privacy laws may have rights of access, correction, deletion, and portability, which you may exercise as described above.
Australia. We handle personal information in accordance with the Australian Privacy Principles. You may complain to us first and, if unresolved, to the Office of the Australian Information Commissioner.
Singapore. We comply with the Personal Data Protection Act 2012. Our Data Protection Officer can be contacted as set out in Section 12.
Vietnam and other jurisdictions. You may have rights under local data protection law, which you may exercise by contacting us.
11. Children
Our websites and Services are directed to healthcare professionals and organizations and are not intended for anyone under 18. We do not knowingly collect personal information from children. Physis processes paediatric images on behalf of healthcare professionals; that is patient information governed by Section 2, and no identifying information is stored.
12. Contact Us
16 Bit Inc. 20 Bay St, 11th Floor, Toronto, Ontario, M5J 2N8, Canada
Privacy inquiries and rights requests: privacy@16bit.ai
Privacy Officer and Data Protection Officer: Dr. Alexander Bilbily, privacy@16bit.ai
EU Representative (Article 27 GDPR): Euverify Ltd, Unit 3D, North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland.
Email: gdpr@euverify.com
UK Representative: Euverify Ltd, (UK) 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom.
Email: gdpr@euverify.com
13. Changes to this policy
We may update this policy from time to time. We will post the updated version on our website with a new effective date and, for material changes, notify account holders by email or in-product before the changes take effect. Previous versions are available on request.