NPI Shield LLC – Enterprise Privacy Policy

Effective Date: 2026
This Privacy Policy governs how NPI Shield LLC (‘Company’) collects, uses, and protects information
related to its services.

1. Scope

This policy applies to all users of the NPI Shield platform, including web and mobile applications.

2. Information Collected

We collect account data, technical usage data, and non-PHI signals associated with NPI monitoring.
We do not collect protected health information (PHI) unless explicitly agreed via BAA.

3. Data Sources

Data may be obtained from public registries, authorized third-party integrations, and user-provided
information.

4. Use of Information

Information is used to deliver alerts, improve system functionality, ensure compliance, and
communicate with users.

5. Legal Basis

Processing is based on user consent, contractual necessity, and legitimate business interests.

6. Data Sharing

We do not sell personal data. Information may be shared with service providers, partners, or authorities
as required by law.

7. Security Measures

We implement administrative, technical, and physical safeguards aligned with industry standards,
including encryption and access controls.

8. Data Retention

Data is retained only as long as necessary for operational, legal, and regulatory purposes.

9. User Rights

Users may request access, correction, deletion, or restriction of their data, subject to applicable law purposes.

10. Compliance

We align with applicable privacy laws including HIPAA (where applicable), and U.S. data protection
standards.

11. Updates

This policy may be updated periodically. Continued use of services constitutes acceptance.

12. Contact

For inquiries: support@npi-shield.net