Set out below: what becomes of information Fortify 24x7 receives through this storefront, plus information the security layers throw off once they are switched on. The aim was a page somebody could actually get through, so each family of lines is described by what it genuinely touches rather than by the category heading it might sit under.
This issue: 25 August 2026Patient Data Armor is a trading brand. The company answerable for everything set out here is Fortify 24x7, and wherever this page says we, that is who it means.
Send a question about any of it to support@patientdataarmor.com and somebody who works here will write back.
Three items, all of them small, none of them shared with anybody.
There is no tracking on this storefront. No advertising network loads, no visitor profile is assembled, and no third party analytics package runs on any page of it.
Payment runs on Stripe infrastructure. The number embossed on your card, the expiry beside it and the verification digits never pass through this website, are never shown to anybody at Fortify 24x7, and are never written into a system we operate.
Stripe hands back the short set of facts an account needs to exist: the address that bought, the practice name entered at checkout, the lines chosen with their counts, whether the subscription presently stands in good order, and two identifiers Stripe uses internally.
Running these services across enrolled systems means handling whatever those systems emit. Which categories apply to you depends entirely on which lines you hold.
None of that gets repurposed. It is handled to run what you are paying for. Nothing is ever sold on, and nothing is ever used to build or improve something we sell to somebody else. Treat that as a commitment rather than a description of present practice we might quietly revise.
A case carries its subject line, whatever you typed, the notes engineers add afterwards, and any attachments. All of it lives inside the service management platform we run, which keeps the record fastened to the problem it belongs to.
Delivering a managed service means standing on platforms other people built. Each is bound by contract to handle data only for the purpose we engaged it for. They are named below, because reading their notices yourself beats taking our word for it.
Nobody outside that list receives anything unless a law obliges us to hand it over. It is not sold, and it never travels to anyone assembling advertising profiles.
Account and billing records stay while a subscription is alive, and afterwards for as long as the tax code and ordinary bookkeeping require. Telemetry follows the retention its own line specifies, which the plating sheet states or scoping agrees. Duplicates follow whichever schedule you selected.
When an account closes we write to you naming what is being destroyed and the date it happens. Destruction timing for duplicates depends on the platform storing them, so you receive a real date for your own configuration instead of a paragraph of comfort.
Where you live decides which rights apply to you. Access, correction, deletion and objection are the four that come up most. Ask for any of them and we will go through it alongside you. Asking is free and carries no consequence.
Where material sits with us because we serve a business, employees of that business should begin with their own employer, and helping that employer respond is something we will do.
Delivering these services puts Fortify 24x7 in contact with protected health information held on the systems you enroll. Where the relationship calls for it we enter into a business associate agreement, and that document then governs use, safeguarding and reporting ahead of anything written on this page.
Two consequences worth stating outright. Protected health information is handled only to deliver what you bought and only as far as that agreement permits. And your own duties as a covered entity or business associate do not move: risk analysis, policy, workforce training, patient rights requests and any decision about notification stay where they are.
Access into a customer environment is granted for the piece of work that needs it. Our own accounts require a second factor. Actions taken inside a tenant are recorded. Three sentences describing practice, and not one of them a guarantee that nothing can ever fail. A provider prepared to hand you that guarantee is telling you something untrue.
Whenever this notice changes, so does the issue date printed above it. Where a revision alters the handling of information already in our possession, we write to account holders instead of leaving anybody to notice on their own.