Privacy Policy
Last updated: 12 August 2026
MagicIntel provides Independent Dispute Resolution (IDR) services to healthcare providers. This policy explains what personal information we collect through magicintel.ai, why we collect it, who it is shared with, and the choices you have.
It covers this website and the email address published on it. It does not cover the handling of claim data under a signed services agreement — that is governed by that agreement and, where protected health information is involved, by a Business Associate Agreement executed before any such data is received.
The short version
We collect the business contact details you choose to send us and the details of your billing operation that let us prepare an audit. We use them to reply to you and to prepare that audit. We do not sell them, we do not buy contact lists, and we do not want patient information through this website.
What we collect
Information you give us. When you request an audit, our form asks for your name, email address and phone number. If we then correspond — by email, or by phone if you have asked us to call — we hold whatever you choose to tell us about your organization and your billing operation, such as your role, your specialty, your payer mix, the states you bill in, and how IDR is handled today.
Information collected automatically. Our hosting provider records standard web server logs for every request: IP address, browser and device type, the page requested, referring page, and the time of the request. These are used to operate and secure the site.
What we do not collect. This website sets no cookies of its own and runs no advertising, tracking or analytics scripts. We do not build profiles of visitors, and we do not track you across other websites. Our form provider sets cookies necessary to operate the form once you open it; see "Who we share it with" below.
Patient information. We do not ask for, and ask that you never send us, protected health information through this website, its form, or unencrypted email. Any audit produced before an engagement is based on public data and, if you choose, aggregate figures containing no patient-identifiable information. If PHI reaches us unsolicited, we will delete it and tell you.
Why we use it, and on what basis
| What we do | Why |
|---|---|
| Reply to your enquiry and prepare the audit you asked for | To take steps you have requested |
| Follow up about the audit, and about a possible pilot | Our legitimate interest in pursuing business you initiated |
| Keep records of who we have spoken to and what was agreed | Our legitimate interest in running the business, and legal record-keeping |
| Operate, secure and troubleshoot the website | Our legitimate interest in a functioning, secure service |
Where the UK or EU GDPR applies, the legal bases are those stated above: Article 6(1)(b) for steps taken at your request and Article 6(1)(f) for our legitimate interests. You can object to processing based on legitimate interests at any time — see "Your choices".
We do not use your information for automated decision-making that produces legal or similarly significant effects.
Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We share it only with service providers who process it on our instructions:
- Netlify — website hosting and server logs.
- Tally — the audit request form. Submissions are collected and stored by Tally and forwarded to us.
- Our email provider — correspondence sent to and from
hello@magicintel.ai.
Each is bound to use the information only to provide its service to us. We may also disclose information where we are legally required to, or to establish or defend legal claims. If the business is ever sold or merged, information may transfer as part of that transaction; you would be told before it became subject to a materially different policy.
Where it is held
We operate from the United States and our service providers store information in the United States. If you contact us from outside the United States, your information will be transferred there. Where the UK or EU GDPR applies, we rely on the European Commission's Standard Contractual Clauses, or an equivalent approved mechanism, for those transfers.
How long we keep it
We keep enquiry and correspondence records for 24 months after our last contact with you, unless you ask us to delete them sooner or we need them longer to meet a legal obligation or to establish or defend a legal claim. Server logs are retained for a short operational period and then discarded. Information held under a signed services agreement is retained according to that agreement.
How we protect it
Traffic to this website is encrypted in transit using TLS. Access to enquiry data is limited to the people who need it to respond to you, through accounts that require multi-factor authentication. No system is perfectly secure, and we do not claim otherwise; if a breach affects your information and the law requires it, we will notify you and the relevant regulator.
Your choices
Wherever you are, you can ask us to:
- tell you what personal information we hold about you and give you a copy;
- correct it if it is wrong;
- delete it;
- stop using it for follow-up contact.
Email hello@magicintel.ai and we will respond within 30 days. We may need to confirm your identity before acting. You will never be charged or treated differently for exercising these rights.
If you are in California. The CCPA, as amended, gives you the rights above, plus the right to know the categories of personal information collected, the purposes, and the categories of third parties it is disclosed to — all set out in this policy. In the preceding twelve months we have collected identifiers and professional or employment-related information, as described above. We have not sold personal information and have not shared it for cross-context behavioural advertising, and we do not do so now. We do not knowingly collect the sensitive personal information categories the CCPA defines. You may use an authorised agent to make a request.
If you are in the UK or EEA. In addition to the rights above you may request restriction of processing, object to processing based on legitimate interests, request your information in a portable format, and lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk.
Children
This website is intended for people acting in a professional capacity. It is not directed to children, and we do not knowingly collect information from anyone under 16.
Changes
If we change this policy we will update the date at the top. If the change is material — for example, a new category of information or a new purpose — we will say so prominently on this page before it takes effect.
Contact
Questions, requests, or complaints about this policy or your information:
MagicIntel Email: hello@magicintel.ai 2261 Market Street, San Francisco, CA 94114