MAX MERGE SOFTWARE INC. — Privacy Notice

Effective Date: June 11, 2026

This Privacy Notice describes how MAX MERGE SOFTWARE INC., doing business as MAXMRJ ("MAX," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you use www.maxmrj.com, the MaxMerge web platform, the MaxAlly mobile application, and related services (collectively, the "Services"). It applies to:

  • Facility Users — healthcare facilities and their staff (e.g., discharge coordinators) using the platform to coordinate post-discharge referrals;
  • Provider Users — community providers (home health, hospice, home care, assisted living, DME, transport, and others) receiving and managing referrals;
  • Consumer Users — individuals, family members, and caregivers using the MaxAlly mobile application;
  • Visitors — anyone browsing our public websites.

This Privacy Notice is incorporated into our Terms and Conditions. Capitalized terms not defined here have the meanings given in the Terms.

Part I — General Privacy Notice

1. Important: How HIPAA Applies (and When This Notice Does Not)

When MAX creates, receives, maintains, or transmits Protected Health Information ("PHI") on behalf of a healthcare facility or provider that is a HIPAA Covered Entity or Business Associate, MAX acts as a Business Associate, and that PHI is governed by HIPAA and the applicable Business Associate Agreement ("BAA") — not by this Privacy Notice. Patients' rights with respect to that PHI (including access and amendment) are exercised through the patient's healthcare facility or provider, and questions about a facility's or provider's privacy practices should be directed to that organization's own Notice of Privacy Practices.

This Privacy Notice governs personal information that MAX collects outside its Business Associate role — including information collected directly from Consumer Users through MaxAlly, account and billing information for all users, and website visitor data. If there is any conflict between this Notice and an applicable BAA with respect to PHI, the BAA controls.

Where an organization operates multiple facilities that are separate HIPAA Covered Entities, the BAA applies with respect to each such Covered Entity (whether accepted at the organization level or per facility), and PHI is accessible across facilities within an organization only as permitted by HIPAA and the applicable BAA(s). The BAA is accepted through the Platform at first login, immediately following acceptance of the Terms and Conditions.

2. Information We Collect

(a) Information you provide:

  • Account and registration data — name, email address, phone number, password, role, organization and facility or location affiliation, professional license information (Providers);
  • Profile and referral data (Facility and Provider Users) — provider service types, coverage areas, availability, languages, insurance plans accepted, rates, and referral details, which may include patient information handled per Section 1;
  • Consumer care information (MaxAlly) — information you choose to provide about yourself or a patient you are authorized to assist, including check-in and follow-up survey responses, care-related questions, and information about care needs and recovery (see Part II — this is Consumer Health Data);
  • Documents — files you upload, such as discharge instructions or care documents (see Part II where uploaded by Consumers);
  • AI Feature inputs — questions and content you submit to AI features, and the outputs generated;
  • Communications — messages sent through the platform, support requests, reviews, and feedback;
  • Payment data — processed by Stripe, Inc. (web platform) or the Apple App Store / Google Play (mobile). MAX does not store full payment card numbers.

(b) Information collected automatically:

  • Device and technical data — IP address, device identifiers, operating system, browser type, app version, crash reports;
  • Usage data — pages and screens viewed, features used, links clicked, time spent, referring URLs;
  • Approximate location inferred from IP address. Precise geolocation is collected only with your separate, affirmative in-app consent, which you may revoke at any time in your device settings;
  • Cookies and similar technologies on our public websites (see Section 7).

(c) Information from other sources:

  • From Facility Users — contact information for patients or caregivers enrolled to receive check-ins or MaxAlly invitations (the facility is responsible for obtaining required consents, as described in the Terms);
  • From a Sponsor (a facility, health plan, or employer paying for your access) — your name and contact information needed to provision sponsored access;
  • From verification and screening services, where applicable to Provider onboarding.

3. How We Use Personal Information

  • To provide, maintain, secure, and improve the Services, including referral coordination, check-ins and follow-up surveys, document features, and AI features;
  • To create and manage accounts, authenticate users, and provide customer support;
  • To process payments and manage subscriptions, trials, and sponsored access;
  • To send service communications (confirmations, check-ins, alerts, security and legal notices) consistent with the consents described in the Terms;
  • To send marketing communications about our own services, which you may opt out of at any time (we do not use Consumer Health Data for marketing without your separate consent — see Part II);
  • To detect, prevent, and address fraud, abuse, security incidents, and technical issues;
  • To comply with legal obligations and enforce our Terms;
  • To create de-identified and/or aggregated data that does not identify you, which we may use for any lawful business purpose, including improving the Services and developing, training, and improving our AI features and models. We commit not to attempt to re-identify de-identified data.

AI Features. Inputs to and outputs from AI features are used to provide the feature, for safety review and abuse prevention, and to improve service quality. We may use de-identified (anonymized) data to develop, train, and improve our AI features and models; once data is de-identified it no longer identifies you, and we commit not to attempt to re-identify it. We do not use identifiable Consumer Health Data to train generalized AI models without your separate, affirmative consent. AI outputs are informational decision support only, as described in the Terms.

4. How We Disclose Personal Information

We disclose personal information only as follows:

  • Within your care coordination circle, at your direction or as part of the Service — e.g., a referral sent by a Facility User is visible to the selected Provider Users; a Consumer User can see which provider was finalized for their patient; messages are visible to their recipients;
  • Within your organization — if your account is provisioned under an organization (for example, a multi-facility operator or a multi-location provider), your account information, usage data, and the content you create in the Services are visible to your organization's administrators and to other authorized users according to the permissions your organization configures; access to patient-related information across facilities or locations is controlled by organization-level permissions and the applicable BAA(s) (Section 1);
  • Service providers (processors) — vendors that host, secure, and support the Services (cloud hosting, communications delivery, payment processing, analytics as limited by Section 7, AI infrastructure), bound by contracts limiting their use of your information to providing services to us;
  • Sponsors — if your access is sponsored, we may confirm to the Sponsor whether sponsored accounts are active and provide aggregate usage statistics. We do not disclose a Consumer User's individual survey responses, AI conversations, documents, or other Consumer Health Data to a Sponsor without the Consumer's separate, affirmative consent or as otherwise required by law;
  • Legal and safety — to comply with law, legal process, or governmental request; to enforce our Terms; or to protect the rights, property, or safety of MAX, our users, or the public;
  • Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to this Notice's commitments;
  • With your consent — for any other purpose disclosed to you at the time.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not disclose Consumer Health Data to third parties for their own marketing or advertising purposes.

5. Data Retention

We retain personal information for as long as your account is active or as needed to provide the Services, then for the period needed to comply with legal, audit, tax, and security obligations, resolve disputes, and enforce agreements. PHI is retained and destroyed per the applicable BAA. Consumer Health Data is retained per Part II. When retention ends, we delete or de-identify the information.

6. Data Security

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit (TLS) and at rest (AES-256), access controls and role-based permissions, audit logging, and PCI-DSS-compliant payment processing through our payment processors. No method of transmission or storage is 100% secure; we cannot guarantee absolute security. If a breach of unsecured information occurs, we will notify affected individuals and regulators as required by applicable law, including HIPAA/HITECH (via the affected Covered Entity where we act as Business Associate) and the FTC Health Breach Notification Rule for consumer health records.

7. Cookies, Analytics, and Tracking

Our public websites use essential cookies and analytics cookies (e.g., Google Analytics) to understand site usage. You can control cookies through your browser and opt out of analytics via the Google Analytics opt-out tool.

Inside the logged-in platform and the MaxAlly application, we do not use third-party advertising trackers, advertising SDKs, or social media pixels, and we do not disclose health information to advertising or social media platforms. Analytics within the Services are limited to first-party or processor-bound product analytics used to operate and improve the Services.

Global Privacy Control. We honor Global Privacy Control (GPC) signals from your browser as a valid opt-out of sale/sharing where required by law. Other "Do Not Track" signals are not currently recognized by industry standard; we treat them the same as GPC where technically feasible.

8. Your Privacy Rights

(a) All users. You may access and update your account information in your settings, opt out of marketing emails (unsubscribe link) and texts (reply STOP), and delete your account as described in the Terms.

(b) State privacy rights (including California). Depending on your state of residence (including California, Colorado, Connecticut, Virginia, Texas, Oregon, and others), you may have the right to:

  • Know/Access — confirm whether we process your personal information and obtain a copy;
  • Delete — request deletion of personal information we hold about you;
  • Correct — request correction of inaccurate personal information;
  • Portability — obtain your information in a portable format;
  • Opt out — of sale, sharing for cross-context behavioral advertising, and certain profiling (we do not engage in these);
  • Limit use of sensitive personal information — we use sensitive personal information only for the purposes permitted without a right-to-limit notice under the CPRA (providing the services you request, security, and legal compliance);
  • Non-discrimination — we will not discriminate against you for exercising your rights.

To exercise rights, email info@maxmrj.com with the subject "Privacy Request," or write to the address in Section 12. We will verify your identity (typically by confirming control of the email or phone number on the account) and respond within the time required by law. Authorized agents may submit requests with proof of authorization. If we deny a request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state Attorney General.

Note: rights with respect to PHI we hold as a Business Associate must be exercised through your healthcare facility or provider (Section 1). Rights with respect to Consumer Health Data are described in Part II. California's "Shine the Light" (Civil Code § 1798.83): we do not disclose personal information to third parties for their direct marketing purposes.

9. Children's Privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13; if we learn we have, we will delete it. Users must be at least 18 to register. Information about minor patients handled for facilities is processed as PHI under Section 1; consumer-facing communications for minor patients are directed only to a parent, legal guardian, or authorized adult caregiver, as required by the Terms.

10. International Users

The Services are operated from the United States and intended for users in the United States. If you access the Services from elsewhere, you understand your information will be processed in the U.S.

11. Changes to This Notice

We will post changes to this Notice with a new effective date and, for material changes, provide notice through the Services or by email. Material changes affecting our treatment of previously collected health or other personal information will not apply retroactively without your consent where required by law.

12. Contact Us

MAX MERGE SOFTWARE INC. — Attention: Privacy Compliance
254 Chapman Rd, Ste 208 #21666, Newark, DE 19702
Email: info@maxmrj.com (subject: "Privacy Request")

Part II — Consumer Health Data Privacy Policy

This Part applies to "consumer health data" as defined by the Washington My Health My Data Act, Nevada SB 370, and similar laws — personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. It applies to data collected from Consumer Users through MaxAlly and consumer-facing check-ins and surveys, to the extent not governed by HIPAA (see Part I, Section 1). Where this Part conflicts with Part I as to consumer health data, this Part controls. This Consumer Health Data Privacy Policy is also published at its own prominently linked URL (maxmrj.com/legal/consumer-health-data-privacy/).

A. Consumer Health Data We Collect

  • Check-in and follow-up survey responses (e.g., symptoms, medication adherence, falls, mobility, recovery progress);
  • Care-related information you provide about yourself or a patient you are authorized to assist, including through AI question-and-answer features;
  • Care documents you upload (e.g., discharge instructions, care plans);
  • Information about care services coordinated for a patient (e.g., which provider was finalized);
  • Precise location, only if you separately consent in-app;
  • Inferences drawn from the above to provide the Services (e.g., flagging a survey response for follow-up).

Sources: you; a facility that enrolls you or your patient (with required consents); documents you upload.

B. Why We Collect and Use It

We collect and use consumer health data only: (1) to provide the products and services you request — care coordination, check-ins, document features, decision support, and safety escalations; (2) for security, fraud prevention, and legal compliance; and (3) with your separate, affirmative consent, for any other disclosed purpose. We do not use consumer health data for advertising.

C. Sharing of Consumer Health Data

We share consumer health data only with: (1) processors bound by contract to use it solely to provide services to us; (2) your care coordination circle as part of the Service you request; (3) recipients you direct us to share with; (4) legal/safety recipients as required by law. We do not sell consumer health data, and no sale will occur without the separate, signed authorization required by applicable law (which is revocable). We do not share consumer health data with Sponsors except as stated in Part I, Section 4.

D. Your Rights

Subject to applicable law (including the Washington My Health My Data Act for Washington residents and others within its scope), you have the right to:

  • Confirm and access the consumer health data we hold about you, including a list of third parties and affiliates with whom we have shared it;
  • Withdraw consent to our collection and sharing of your consumer health data;
  • Delete your consumer health data, including from backups (on backup-cycle timing) and with notice to processors;
  • Appeal a refusal, and contact the Washington Attorney General (or your state's Attorney General) if your appeal is unsuccessful.

Exercise these rights via info@maxmrj.com, subject "Health Data Request." We will verify your identity and respond within the time required by law. Deleting consumer health data may disable core MaxAlly features; we will tell you before completing the request.

E. Consent

Where required by law, we collect consumer health data only after presenting a separate, affirmative consent that describes the categories collected, purposes, and sharing — not bundled with these Terms or general account sign-up — and we obtain separate authorization before any sharing beyond what is necessary to provide the Services you request.

MAX MERGE SOFTWARE INC. © 2026. Terms and Conditions | Privacy Notice