Cookie Policy

5 Dec 2025

We use cookies and similar technologies to make Burna AI work better for you. This policy explains what cookies are, how we use them, and how you can control them.

What Are Cookies?

Cookies are small text files that websites store on your device when you visit them. They help websites remember your preferences, keep you logged in, and understand how you use the site.

Similar Technologies We Use

  • Local Storage: Stores data on your device for better performance

  • Session Storage: Temporary data storage cleared when you close your browser

Types of Cookies We Use

Essential Cookies (Always Active)

Purpose: Make our website and platform work properly

Legal Basis: Contract performance and legitimate interest

Retention: Session to 12 months

What they do:

  • Keep you logged into your Burna AI account

  • Provide core platform functionality

  • Prevent fraud and ensure security

  • Enable secure data transmission

You cannot opt out of essential cookies without affecting functionality.

Analytics Cookies (Your Choice)

Purpose: Help us understand website usage and improve performance

Legal Basis: Consent

Retention: Up to 14 months

What they do:

  • Track page views and user journeys

  • Measure website performance

  • Identify technical issues

Third parties: Vercel Analytics (privacy-focused, no personal data collection)

Marketing Cookies (Your Choice)

Purpose: Measure marketing campaign effectiveness

Legal Basis: Consent only

Retention: Up to 12 months

What they do:

  • Measure marketing campaign effectiveness

  • Track conversions from our marketing efforts

Third parties: HubSpot (CRM and marketing analytics)

How We Use Cookies

On Our Website

  • Improve performance and user experience

  • Understand which content is most helpful

  • Ensure security and prevent unauthorized access

On Our Platform (CTCAE AI)

  • Maintain secure login sessions

  • Enable clinical documentation features

  • Optimize platform performance

Important: Cookies do NOT access, store, or process any patient health information. All clinical data is handled separately under HIPAA-compliant infrastructure.

Third-Party Services

We work with trusted partners who may set cookies:

Service

Purpose

Privacy Info

HubSpot

Marketing analytics, CRM

HubSpot Privacy

Vercel

Website hosting, analytics

Vercel Privacy

Cloudflare

Security, performance

Cloudflare Privacy

All third parties are bound by data protection agreements.

Your Cookie Choices

Browser Settings

Control cookies directly in your browser:

  • Chrome: Settings → Privacy and Security → Cookies

  • Firefox: Settings → Privacy & Security → Cookies

  • Safari: Preferences → Privacy → Cookies

  • Edge: Settings → Cookies and site permissions

Global Privacy Control

If your browser sends a Global Privacy Control (GPC) signal, we automatically respect that choice and limit non-essential cookies.

Opt-Out Links

Mobile App (iOS)

App Tracking Transparency

Our iOS app respects Apple's App Tracking Transparency (ATT) framework. We do not track you across other companies' apps or websites without your explicit permission.

If you have previously granted or denied tracking permission, you can change this anytime:

Settings → Privacy & Security → Tracking → Burna AI

What Our App Does NOT Do

  • No cross-app or cross-site tracking

  • No device fingerprinting for advertising

  • No sharing of data with data brokers

  • No third-party advertising SDKs

Legal Basis and Rights

GDPR Compliance (EU/EEA/UK)

Legal basis for cookie processing:

Cookie Type

Legal Basis

Essential

Contract performance, legitimate interest

Analytics

Consent

Marketing

Consent

Your rights:

  • Access: Know what cookies collect about you

  • Deletion: Request removal of cookie data

  • Objection: Object to processing

  • Withdrawal: Remove consent anytime

To exercise your rights, contact: contact@burna.ai

Response time: 30 days maximum

CCPA Rights (California)

  • Know: What personal information cookies collect

  • Delete: Request deletion of cookie information

  • Opt-Out: Stop sale/sharing of information

  • Non-Discrimination: Same service regardless of choices

Healthcare Data Protection

HIPAA Compliance

Important: Cookies on our website and app do NOT collect protected health information (PHI).

  • Patient data is processed separately under HIPAA safeguards

  • Marketing cookies never access clinical data

  • Cookie practices do not affect your HIPAA compliance

  • Business Associate Agreements cover all clinical information separately

For Healthcare Organizations

  • Disable non-essential cookies without affecting clinical functionality

  • All patient data protection covered by separate agreements

  • Cookie practices comply with healthcare privacy regulations

Data Retention

Cookie Type

Retention Period

Session Cookies

Deleted when you close your browser

Essential Cookies

Up to 12 months

Analytics Cookies

Up to 14 months

Marketing Cookies

Up to 12 months

Automatic deletion:

  • Scheduled removal at expiration

  • Immediate deletion when you withdraw consent

  • Complete removal when you delete your account

International Transfers

Data may be transferred internationally with appropriate safeguards:

  • Standard Contractual Clauses (SCCs) for EU data transfers

  • Encryption for all data in transit

  • Primary processing: United States

Children's Privacy

Our platform is intended for healthcare professionals and is not directed at individuals under 18. We do not knowingly collect information from children.

Updates to This Policy

When We Update

  • New cookie technologies

  • Legal requirement changes

  • Service provider changes

How We Notify You

  • Updated effective date posted on this page

  • Email notification for material changes

  • 30-day notice for significant updates

Contact Us

For all cookie-related questions or to exercise your privacy rights:

Email: contact@burna.ai

Response time: Within 30 days

Regulatory Contacts

  • EU Users: Your local Data Protection Authority

  • California Users: California Attorney General's Office

  • UK Users: Information Commissioner's Office (ICO)

This Cookie Policy was last updated in January 2026.