Privacy Policy
Privacy Policy
Effective Date
August 27, 2026
Last Updated
August 27, 2026
Arriba Data Systems doing business as Arriba (“Arriba,” “we,” “us,” or “our”) respects the privacy and security of information entrusted to us. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit our websites, access or use Arriba Portal, interact with our applications or integrations, communicate with us, request support, or otherwise use services provided by Arriba (collectively, the “Services”).
Our Privacy Commitments
Arriba does not sell Customer Data or Personal Information. Arriba does not share Customer Data or Personal Information for advertising. Arriba does not use Customer Data, Protected Health Information (“PHI”), claims information, medical information, or other Customer-provided data to train publicly available or general-purpose artificial intelligence models.
We process Customer Data only as necessary to provide and secure our Services, perform activities authorized by our Customers, meet contractual obligations, and comply with applicable law.
1. Scope of This Privacy Policy
This Privacy Policy applies to Personal Information processed by Arriba in connection with our websites, software platform, applications, integrations, and related Services.
Arriba primarily provides Services to businesses and organizations, including employers, insurers, third-party administrators, utilization review organizations, medical management organizations, healthcare organizations, governmental entities, and other entities (“Customers”).
In many circumstances, Arriba processes information on behalf of a Customer. In those circumstances, the Customer determines why and how the information is processed, and Arriba processes the information pursuant to our agreement with that Customer. This distinction is particularly important for medical, claims, and other information processed through Arriba Portal.
2. Information We Collect
The information we collect depends on how you interact with Arriba and the Services you use. We may collect or process the following categories of information.
Account and Identity Information
-
name
-
username
-
email address
-
telephone number
-
job title
-
employer or organization
-
department
-
professional role
-
user identifier
-
authentication information
-
account permissions and roles
Customer and Business Information
-
organization names
-
contact information
-
customer identifiers
-
employer information
-
payer information
-
provider information
-
billing contacts
-
contract-related information
-
account configuration information
Claims and Case Information
-
claimant names
-
claim numbers
-
dates of injury
-
dates of birth
-
employer information
-
adjuster information
-
attorney information
-
provider information
-
claim status
-
jurisdiction information
-
referral information
-
treatment requests
-
case management information
-
other information associated with a claim or case
Medical and Health Information
-
medical records
-
diagnoses
-
treatment requests
-
medications
-
procedures
-
treatment history
-
physician information
-
clinical documentation
-
utilization review information
-
medical case management information
-
other health-related information
Financial and Billing Information
-
invoice information
-
billing identifiers
-
amounts
-
payment status
-
service charges
-
accounting references
-
customer billing information
-
information exchanged with authorized accounting integrations
Documents and Communications
-
medical records
-
referral forms
-
reports
-
correspondence
-
emails
-
attachments
-
uploaded documents
-
fax-related information
-
notes
-
task information
-
workflow communications
Support Information
-
name and contact information
-
organization
-
support request and communications
-
diagnostic information
-
screenshots or documents you provide
-
information necessary to troubleshoot the issue
Device and Technical Information
-
IP address
-
browser type
-
operating system
-
device information
-
date and time of access
-
authentication activity
-
session information
-
pages or features accessed
-
application events
-
referring pages
-
error information
-
network and security information
Audit and Activity Information
-
login and logout activity
-
records accessed
-
records created or modified
-
workflow actions
-
assignments
-
approvals
-
document activity
-
communications
-
timestamps
-
user identifiers
-
other actions necessary for security, auditing, compliance, and system administration
Some medical and health information processed through the Services may constitute Protected Health Information (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”).
3. How We Collect Information
Directly From You
For example, when you create or use an account, contact us, request a demonstration, submit a form, upload a document, communicate with support, or otherwise provide information to us.
From Our Customers
Customers may provide information to Arriba in order to use the Services, including user account information, claimant or patient information, claims information, referral information, medical records, provider information, and other information necessary to perform the Services.
From Authorized Integrations
Arriba may receive information from third-party systems that a Customer has authorized Arriba to access, including claims administration systems, accounting systems, identity providers, medical information systems, document management systems, electronic data interchange services, communication systems, and other Customer-authorized services.
Automatically
Certain technical and usage information may be collected automatically through servers, logs, cookies, security systems, and similar technologies.
4. How We Use Information
We may use information to:
-
provide and operate Arriba Portal and related Services;
-
process referrals and support utilization review, case management, treatment request, document, communication, reporting, billing, and other Customer-authorized workflows;
-
authenticate users, manage sessions, enforce role-based access controls, and prevent unauthorized access;
-
provide technical and customer support;
-
maintain security, investigate incidents, detect suspicious activity, prevent fraud, and maintain audit records;
-
monitor, maintain, troubleshoot, and improve the reliability and functionality of our Services;
-
perform Customer-authorized integrations and data exchanges;
-
comply with contractual obligations, applicable law, legal process, and regulatory requirements; and
-
protect the legal rights, security, and safety of Arriba, our Customers, users, and others.
5. Protected Health Information and HIPAA
Arriba may provide Services to organizations that are Covered Entities or Business Associates under HIPAA. When Arriba creates, receives, maintains, or transmits PHI on behalf of a Customer in a manner subject to HIPAA, Arriba processes that information in accordance with applicable HIPAA requirements, the applicable Business Associate Agreement (“BAA”), our contractual obligations, and applicable security and privacy requirements.
The applicable BAA governs Arriba’s permitted uses and disclosures of PHI.
Arriba Is Generally Not the Source of Your HIPAA Notice of Privacy Practices
Arriba typically provides technology and services on behalf of insurers, employers, healthcare organizations, utilization review organizations, medical management organizations, and other Customers. If you are an individual seeking to access or correct your medical information, obtain a copy of records, request an accounting of disclosures, restrict a disclosure, or exercise another HIPAA right, you should generally contact the organization responsible for your claim, medical care, health plan, or other applicable record. Arriba will cooperate with its Customers as required by applicable law and the applicable BAA.
6. Workers’ Compensation Information
The Services may process information in connection with workers’ compensation claims and related medical management activities. Such information may be used and disclosed as authorized by applicable workers’ compensation laws, healthcare privacy laws, contractual requirements, and Customer instructions.
Arriba does not independently determine a claimant’s eligibility for benefits or make medical treatment decisions solely because information is processed through Arriba Portal.
7. Artificial Intelligence and Automated Processing
Certain Arriba Services may use artificial intelligence, machine learning, natural-language processing, optical character recognition, document understanding, search, summarization, or other automated technologies (“AI Features”). Depending on the feature, these technologies may assist with document classification, extraction and organization of information, summarization, search and retrieval, identification of potentially missing or inconsistent information, preparation of draft content, quality-assurance assistance, and workflow automation.
Information processed by AI Features remains subject to applicable Customer agreements, privacy requirements, security controls, and access restrictions. AI Features are intended to assist authorized users and are not intended, by themselves, to replace required clinical or professional judgment.
Customer Data Is Not Used to Train Public AI Models
Arriba does not use Customer Data, PHI, claims information, medical information, confidential Customer information, or other Customer-provided data to train publicly available or general-purpose artificial intelligence models.
Where Arriba uses third-party artificial intelligence or machine-learning services to provide an authorized feature, Arriba requires Customer Data to be processed only as necessary to provide that functionality and subject to appropriate contractual, privacy, and security protections.
8. How We Disclose Information
Arriba does not sell Customer Data or Personal Information and does not disclose Customer Data or Personal Information to third parties for advertising or cross-context behavioral advertising. Arriba discloses information only as reasonably necessary to provide and secure the Services, fulfill Customer-authorized activities, comply with contractual obligations, or satisfy applicable legal requirements.
To the Customer That Provides Your Access
If your Arriba account is provided by an employer or other Customer, that Customer may access information associated with your account and activity consistent with its permissions, contractual rights, and applicable law.
Service Providers and Subprocessors
Arriba may use service providers and subprocessors to support operation of the Services, including providers of cloud infrastructure and hosting, data storage, cybersecurity, system monitoring, application performance management, communications, email delivery, document processing, customer support, identity and authentication, backup and disaster recovery, and related technology services.
These organizations process information on Arriba’s behalf only as necessary to provide their contracted services and are subject to appropriate confidentiality, privacy, security, and contractual requirements. They are not authorized by Arriba to sell Customer Data or use Customer Data for their own advertising purposes. Where a service provider creates, receives, maintains, or transmits PHI on Arriba’s behalf, Arriba enters into appropriate Business Associate arrangements when required by HIPAA.
Customer-Authorized Integrations
Arriba may transmit information to third-party systems when a Customer has specifically authorized an integration or data exchange. Examples may include claims administration systems, accounting platforms, identity providers, communication services, medical guideline systems, document services, electronic data interchange providers, and other Customer-authorized systems. Such disclosure occurs only to provide functionality requested or authorized by the Customer.
Legal Requirements
Arriba may disclose information when reasonably necessary to comply with applicable law or valid legal process, respond to governmental or regulatory authorities, investigate fraud or illegal activity, protect the security and integrity of the Services, protect rights or safety, or establish, exercise, or defend legal claims.
Business Transactions
Information may be transferred as part of a merger, acquisition, financing, corporate reorganization, sale of assets, or change in control. Any successor remains subject to applicable legal and contractual requirements governing protected Customer information.
9. We Do Not Sell or Share Personal Information for Advertising
Arriba does not sell Personal Information or Customer Data.
Arriba does not share Personal Information or Customer Data for cross-context behavioral advertising, targeted advertising, or third-party marketing.
Arriba does not:
-
sell claims information;
-
sell medical information;
-
sell Protected Health Information;
-
sell Customer Data;
-
provide Customer Data to data brokers;
-
use Customer Data for third-party advertising;
-
share Customer Data with advertisers; or
-
permit service providers to use Customer Data for their own advertising purposes.
For purposes of the California Consumer Privacy Act (“CCPA”), Arriba does not “sell” or “share” Personal Information as those terms relate to the sale of Personal Information or sharing for cross-context behavioral advertising. Limited disclosure to service providers, subprocessors, Customer-authorized integrations, or governmental authorities as described in this Privacy Policy is not undertaken for advertising or commercial sale of Personal Information.
10. Cookies and Similar Technologies
Our public websites and Services may use cookies and similar technologies for authentication, maintaining sessions, remembering user preferences, security, fraud prevention, application functionality, performance monitoring, analytics, and troubleshooting.
Some cookies are necessary for the operation and security of the Services. Where required by applicable law, we provide appropriate choices concerning non-essential cookies or similar tracking technologies. You may also be able to configure your browser to restrict cookies, although disabling certain cookies may affect the operation of some Services.
11. Do Not Track and Global Privacy Control
Some browsers provide “Do Not Track” signals. Because there is not a universally accepted technical standard for responding to traditional browser Do Not Track signals, our Services may not respond to those signals in every circumstance.
Where applicable law requires recognition of legally valid opt-out preference signals, such as Global Privacy Control (“GPC”), Arriba will process supported signals as required by applicable law.
12. Information Security
Arriba uses administrative, technical, and organizational safeguards designed to protect Personal Information and Customer Data. Depending on the applicable Services, these safeguards may include:
-
encryption of data in transit;
-
encryption of data at rest where appropriate;
-
access controls and role-based authorization;
-
multi-factor authentication;
-
network and application security controls;
-
tenant separation;
-
security monitoring and audit logging;
-
vulnerability management;
-
backup and recovery procedures;
-
incident response procedures; and
-
employee and contractor confidentiality requirements.
No information system can be guaranteed to be completely secure. Users are responsible for maintaining appropriate security over their account credentials and devices. If you believe your Arriba account or information has been compromised, contact it@arribadtasys.com.
13. Data Retention
We retain information for only as long as reasonably necessary for the purposes for which it was collected or as required by Customer agreements, legal requirements, regulatory obligations, contractual obligations, security requirements, dispute resolution, audit requirements, or legitimate business requirements.
Different categories of information may have different retention periods. Customer Data may be retained according to retention requirements established by the Customer and the applicable agreement with Arriba. Certain information may remain in backups, archives, audit logs, security records, billing records, or legally required records after active use has ended. Where information is subject to a legal hold or other preservation requirement, it may be retained for the duration of that requirement.
14. De-Identified and Aggregated Information
Arriba may create aggregated or de-identified information that is not reasonably capable of identifying an individual. We may use this information for service improvement, system performance analysis, security, analytics, product development, and business planning. Where applicable law requires it, Arriba will maintain de-identified information in de-identified form and will not attempt to reidentify it except as permitted by law.
15. Your Privacy Choices
Depending on the circumstances and applicable law, you may have the right to request access to certain Personal Information, request correction of inaccurate Personal Information, request deletion of certain Personal Information, obtain information regarding how Personal Information is used and categories of recipients, object to or restrict certain processing, withdraw consent where processing is based on consent, or exercise other privacy rights provided by applicable law.
Not all rights apply in all circumstances. For information maintained by Arriba on behalf of one of our Customers, we may refer your request to the applicable Customer because that organization controls the information. This is particularly likely for claims, medical, employment, and other Customer-provided information.
16. California Privacy Rights
This section applies to California residents to the extent the CCPA, as amended by the California Privacy Rights Act, applies to the Personal Information involved. Subject to applicable exceptions, California residents may have the following rights.
Right to Know
Request information regarding categories of Personal Information collected, categories of sources, purposes for collecting or using the information, categories of third parties to whom information is disclosed, and specific pieces of Personal Information collected about you.
Right to Delete
Request deletion of certain Personal Information, subject to applicable exceptions.
Right to Correct
Request correction of inaccurate Personal Information.
Right to Opt Out of Sale or Sharing
California residents have the right to opt out of the sale of Personal Information or sharing of Personal Information for cross-context behavioral advertising where a business engages in such activities. Arriba does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising. Accordingly, Arriba does not currently engage in activities requiring users to opt out of the sale or sharing of Personal Information for advertising purposes.
Right to Limit Use of Sensitive Personal Information
Where applicable, California residents may have the right to limit certain uses or disclosures of Sensitive Personal Information. Arriba processes Sensitive Personal Information only as reasonably necessary to provide, secure, administer, or support Customer-authorized Services or as otherwise permitted by applicable law. Arriba does not use Sensitive Personal Information to infer characteristics about individuals for advertising purposes.
Right to Non-Discrimination
Arriba will not unlawfully discriminate against an individual for exercising an applicable privacy right.
17. Categories of Personal Information Under California Law
Depending on how you interact with Arriba, we may process categories of Personal Information such as the following. Arriba does not necessarily collect every category from every individual.
Category
Examples
Primary Purpose
Identifiers
Name, email, user ID, IP address
Accounts, authentication, communication
Customer records
Contact and business information
Customer administration
Protected classifications
Information contained in Customer records where applicable
Providing Customer-authorized Services
Commercial information
Customer and billing information
Administration and billing
Internet or electronic activity
Logins, system activity, browser and device information
Security, functionality and auditing
Professional information
Employer, job title, role
User administration
Sensitive Personal Information
Health information, account credentials, and other sensitive information where applicable
Providing Customer-authorized Services
Medical information
Records, diagnoses, and treatment information
Utilization review, case management, and related Services
Employment-related information
Employer and work-related claim information
Workers’ compensation and case workflows
Inferences
Limited system-generated classifications or workflow indicators
Providing and improving Services
18. Sources of Personal Information
We may obtain Personal Information from you, our Customers, your employer, insurers, third-party administrators, healthcare providers, utilization review organizations, case management organizations, authorized integrations, claims administration systems, service providers, and information generated through use of the Services.
19. California Privacy Requests
To submit an applicable privacy request, contact us using the methods below. We may need to verify your identity before processing certain requests. Authorized agents may submit requests where permitted by law, but we may require evidence of the agent’s authority and verification of the applicable individual. If the information is controlled by one of our Customers, we may direct you to that Customer or assist the Customer in responding to your request.
-
Email: it@arribadatasys.com
-
Mail: Arriba Data SystemsAttn: Privacy, 12532 Quail Meadow, Auburn, CA 95603
20. Personal Information Relating to Claims and Medical Records
If you are a claimant, patient, injured worker, or other individual whose information appears in Arriba Portal because one of our Customers uses the Services, Arriba may not be the organization responsible for independently responding to your privacy request. Information may have been provided to Arriba by your employer, insurance carrier, claims administrator, healthcare provider, utilization review organization, case management organization, or another organization involved in administering your claim or care.
In these circumstances, you should generally direct requests concerning the underlying claim or medical record to the organization responsible for that record. Arriba will assist its Customers with appropriate privacy requests as required by applicable law and our contractual obligations.
21. Children’s Privacy
Arriba’s websites and Services are intended for business and professional use and are not directed to children. We do not knowingly solicit Personal Information directly from children under 13 through our public websites.
Information concerning minors may appear in Customer-provided records where necessary for legitimate healthcare, claims, insurance, or other authorized business purposes. Such information is processed on behalf of the applicable Customer and subject to applicable contractual and legal requirements.
22. Third-Party Websites and Services
Our websites and Services may contain links to or integrations with third-party websites and services. Arriba does not control the privacy practices of independent third parties. You should review the privacy policies applicable to those services before providing information directly to them.
23. Business-to-Business Users
If you interact with Arriba on behalf of a business or organization, we may use your business contact information to manage our business relationship, communicate about our Services, provide demonstrations, provide support, administer contracts, respond to inquiries, and provide information concerning relevant Arriba Services. You may request that we stop sending non-transactional marketing communications by following the unsubscribe instructions provided in those communications.
24. Email Communications
We may send transactional communications necessary to provide the Services, including security notifications, account messages, workflow notifications, support communications, service announcements, and administrative communications. Transactional communications may not provide an unsubscribe option where they are necessary to operate or secure your account. Marketing communications, where applicable, will provide appropriate unsubscribe options.
25. International Users
Arriba primarily provides Services from the United States. If information is transferred from another country to the United States, it may be processed in the United States and other locations where Arriba or its authorized service providers operate. Where required, Arriba uses appropriate contractual, organizational, and technical measures for international transfers of Personal Information.
26. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to our Services, privacy practices, technology, legal requirements, integrations, or business operations. When we make changes, we will update the “Last Updated” date at the beginning of this Policy. Where required by applicable law, we may provide additional notice regarding material changes. We encourage you to review this Privacy Policy periodically.
27. Contact Us
If you have questions about this Privacy Policy or Arriba’s privacy practices, contact:
Organization
Arriba Data Systems, d/b/a Arriba
Attention
Privacy
Address
-
12532 Quail Meadow
City/State/ZIP
Auburn, CA 95603
Website
Arribadatasys.com
Privacy
Security / Support
it@arribadatasys.com | support@arribadatsys.com
