Privacy Policy

Last updated: July 2026

1. Scope

This Privacy Policy explains how Sirr handles information across its pathology research service, Sirr Voice, and related websites, applications, and support services. The information we process depends on the product features you or your organization choose to use.

2. Information We Collect

We may collect information that you, your organization, or an authorized administrator provides, including:

  • Account Information: Name, email address, phone number, authentication identifiers, organization, role, and account settings
  • Pathology Content: Pathology slide images and related information you upload for research analysis
  • Voice Content: Microphone or call audio, transcripts, messages, language selections, structured call data, workflow results, and handoff details when Sirr Voice is used
  • Configuration and Audit Data: Agent instructions, approved tools, safety and escalation settings, administrator actions, acknowledgments, and service activity
  • Usage and Device Data: How you interact with the service, browser and device information, timestamps, diagnostics, and security logs
  • Transaction and Support Information: Payment information processed by third-party payment processors and information you provide when requesting support

3. How We Use Information

  • Provide, maintain, secure, and improve Sirr products and services
  • Authenticate users and apply organization, administrator, and access controls
  • Process research analyses and return requested results
  • Recognize speech, generate transcripts and spoken responses, structure messages, route approved workflows, and support transfer to authorized people
  • Run customer-approved integrations and tools, subject to configured permissions and safeguards
  • Monitor reliability, investigate misuse, maintain audit records, and respond to support requests
  • Process transactions and send service-related communications

4. Microphone and Voice Processing

Sirr Voice accesses microphone audio only after a user starts a voice session and grants the applicable browser or device permission. Audio may be streamed to speech, language, and voice services to provide the requested interaction. Depending on the enabled workflow, transcripts and structured call data may be made available to authorized users or included in a human handoff. Users can end a session or revoke microphone permission through their browser or device controls.

5. Service Providers and Disclosures

We may use service providers and subprocessors for cloud hosting, authentication, databases, security, payment processing, speech recognition, language-model processing, text-to-speech, communications, and customer support. They process information as needed to provide their services to Sirr, subject to the applicable agreements and configured controls. We may also disclose information to your organization and its authorized administrators or handoff recipients, when required by law, or to protect rights, safety, and service integrity. We do not sell personal data.

6. Data Storage and Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls and security measures appropriate to the service configuration. No transmission or storage system is completely secure, and users and administrators are responsible for protecting account credentials, granting appropriate permissions, and configuring integrations and handoff recipients carefully.

7. Retention and Deletion

Retention depends on the type of information, product configuration, customer instructions, applicable agreements, security needs, and legal obligations. We retain information only as reasonably necessary for those purposes. Authorized users or organizations may request deletion through available account controls or Sirr's published support channels. Some information may be retained where required for security, dispute resolution, legal compliance, or enforcement of agreements. Service providers may apply their own retention and deletion terms consistent with their agreements with Sirr.

8. Product-Specific Data Boundaries

Pathology research service: Do not upload images containing personally identifiable patient information. Uploaded content must be de-identified in accordance with applicable requirements. The service remains subject to the research-use limitations in our Terms of Service.

Sirr Voice evaluation: Current access is invite-only and limited to synthetic or fictional information. Do not submit protected health information or other real patient information during the evaluation. A registration checkbox or in-app acknowledgment is not a Business Associate Agreement and does not authorize the use of protected health information. Any required BAA must be separately reviewed, signed, and accompanied by an approved service configuration before such use is enabled.

9. Human Handoffs

When an organization enables a handoff workflow, Sirr Voice may send a transcript, structured summary, contact details, or other relevant information to the recipient selected by that organization. The organization is responsible for choosing authorized recipients, maintaining working handoff channels, and limiting the information shared to what is appropriate for the workflow.

10. Your Choices and Rights

Depending on your location and relationship with Sirr, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. If your account is managed by an organization, requests may need to be directed to that organization as the controller or account administrator. We may verify your identity and authority before completing a request.