Trust & Security
Last updated
SmartChair.AI measures one thing, whether a chair is occupied, and keeps that measurement private, encrypted, and yours. This page sets out how.
What the sensor collects, and what it never can
The sensor is a pressure pad under the seat cushion connected to a small controller. It sends a device identifier, occupied or vacant, the time, and the duration. Nothing else leaves the operatory.
No cameras, no microphones, no patient identifiers. There is no optical or audio component on the device to switch on, so it cannot record a face, a voice, or a name.
Where data lives
The platform runs on Amazon Web Services in the United States. Occupancy data is encrypted in transit and at rest. The dashboard at app.smartchair.ai is delivered through Amazon QuickSight inside the same account boundary.
Who can see it
- Each customer site gets its own credentials. A designated super admin at the customer decides who in the group sees which locations.
- Inside SmartChair.AI, access to customer data is limited to the people who support that customer, and only to the extent their role needs.
- We never sell occupancy data, and we never share one customer's data with another.
Your data is yours
Raw occupancy readings are the customer's property under our customer agreement. You can ask for an export at any time, and we remove your data after the agreement ends on the schedule the agreement sets.
Healthcare
The sensor feed contains no protected health information. Where a customer chooses to share production summaries for reporting, or where a customer otherwise needs it, we sign a Business Associate Agreement and handle that data under HIPAA where applicable.
The website
- Served only over HTTPS, with strict transport security and security headers that block framing and content sniffing.
- Analytics load only after you accept them; see the Privacy Notice.
- The demo form is protected against automated submissions and posts to our own backend, not a third-party form service.
Report a vulnerability
If you believe you have found a security issue in the sensor, the platform, or the website, email [email protected] with enough detail to reproduce it. We acknowledge reports within two business days and do not pursue researchers who act in good faith and give us time to fix the issue.
Security questionnaires
Procurement and IT teams can send vendor questionnaires to [email protected]. We answer them directly, in writing.