Privacy Policy.
This Privacy Policy explains how Mulholland, Inc. ("Mulholland," "we," "us," or "our") collects, uses, and protects the personal information we handle for our own purposes: when you visit our websites, contact us or ask for a demo, come to our events, hear from us about our services, manage an account with us, work with us as a vendor or partner, or apply for a job with us. It also explains how we use de-identified data on our own account.
Customer data.
Our customers are businesses. Customer data means the data a customer puts into MarzyOS and the data we handle while performing services for that customer. We handle it on the customer's behalf, under the customer's agreement with us, and this policy does not cover it. Our Customer Data Privacy Notice summarizes how we handle customer data, and the customer's signed agreements govern. Once we de-identify customer data as a customer's agreement allows, the result is no longer customer data, and we use it on our own account as described under "De-identified data" below.
The account details of the people a customer gives access to MarzyOS, such as their names and work email addresses, are customer data too, and we handle them for the customer. The one exception is what we use to administer our own contract and billing relationship with that customer, such as the contact details of the people who manage the customer's account with us, sign its agreements, or receive its invoices. This policy covers that use.
If you are a patient, client, or employee of one of our customers and have a question about your information, please contact that customer. If you contact us, we will refer you to them.
Information we collect.
- Information you provide. When you contact us, ask for a demo, or book a call, we collect your name, email, company, role, and the contents of your message. If you apply for a job, we collect what you send us, such as your résumé.
- Events. When you register for or attend an event we host or take part in, we collect your registration details and any business contact details you share with us.
- Account and billing information. When your company becomes a customer, we collect business contact details for the people who manage its account with us, sign agreements, and handle invoices, and we keep billing and payment records.
- Vendors and partners. We keep business contact details for the people we work with at our vendors and partners.
- Usage data. We collect basic technical information — such as IP address, browser type, and pages visited — to operate and secure our websites.
We get this information from you, from your browser when you use our websites, and from your company when it sets up an account with us or names you as a contact.
How we use information.
- To respond to inquiries, arrange demos, and provide the services you request.
- To administer our contracts and billing with customers, including agreements, invoices, and payments.
- To tell you about our services and events. You can opt out of marketing emails at any time.
- To consider job applications.
- To operate, maintain, secure, and improve our websites and services.
- To meet legal, regulatory, and contractual obligations, and to protect our rights.
We do not sell your personal information, and we do not share it with advertisers or data brokers.
De-identified data.
Where a customer's agreement is on version 1.4 or later of our Master Services Agreement, we may de-identify information we process for that customer and use the resulting de-identified data, alone or combined with de-identified data from other customers and sources, for any lawful purpose, including to improve our services and to develop and train our own AI models. We may sell, license, or otherwise make those models available to others, on their own or as part of our products. As between us and the customer, we own the de-identified data and those models, and we may keep them after the customer's agreement ends; they are not returned or deleted with the customer's data. This applies only to information we first receive or generate on or after the effective date of the Order Form or amendment by which the customer first agrees to one of those versions, never to earlier information or to new information made by reprocessing it. Customers on earlier versions are unaffected.
If we de-identify patient information, we do so only under HIPAA's expert determination method (45 C.F.R. § 164.514(b)(1)), which we use for free text, documents, images, and model inputs and outputs, or, for structured data fields only, its safe harbor method (45 C.F.R. § 164.514(b)(2)). We may sell, license, or otherwise disclose de-identified patient information, derived from patient information, as part of models we make available to others.
We maintain and use de-identified data only in de-identified form, and we will not attempt to re-identify it. We do not sell or license the de-identified data itself as a dataset. We disclose record-level de-identified data only as part of a model, to service providers acting for us, to a successor to our business, or where the law requires, and we require anyone who receives it, or a model built with it, from us to agree in writing to keep it de-identified, not to attempt to re-identify it, and not to sell it.
How we share information.
We share personal information with service providers that help us run our websites and our business, such as hosting, email, e-signature, and invoicing and payment providers. We may also share it with our professional advisers, with a successor if we are involved in a merger, acquisition, or sale of assets, and where the law requires or to protect our rights. We share de-identified data, and models built with it, only as described above.
Some of our pages, including blog posts, show YouTube videos or video thumbnails. When one loads, your browser connects to YouTube, which receives information about your visit, such as your IP address, under its own privacy policy. We embed videos in YouTube's privacy-enhanced mode.
YouTube may use what it receives as its own privacy policy describes. No other company collects personal information about your activity over time and across websites through ours, and we do not track you across other websites. Our websites do not respond differently to browser Do Not Track signals.
Security.
We use reasonable safeguards designed to protect the personal information we hold. No method of transmission or storage is completely secure. How we protect customer data is described in our Customer Data Privacy Notice and on our Security page.
Data retention.
We keep personal information only as long as we need it for the purposes above, such as for the length of our relationship with you or your company, and as needed to meet our legal, tax, and accounting obligations. Retention and deletion of customer data are governed by the customer's agreement, as our Customer Data Privacy Notice describes.
Your rights.
Depending on where you are located, you may have rights to access, correct, delete, or restrict the processing of your personal information. To exercise these rights, contact us using the details below and we will respond in accordance with applicable law. We will not discriminate against you for exercising them. If your request is about information in customer data, we will refer you to the customer and help it respond as its agreement with us requires. If you live in California, you can use those details for any question or request about your personal information.
Changes to this policy.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be communicated where appropriate.
Contact.
Privacy questions or requests: privacy@mulholland.ai. Security matters: security@mulholland.ai. By mail: Mulholland, Inc., 3400 W Riverside Dr, Ste 250, Burbank, CA 91505.