Brandt VX
Start a conversation

VX Privacy

VX Privacy Notice

VX is provided to client organizations, not the general public. This notice explains what the application collects about you as a user, and how the data your organization entrusts to us is handled.

One session cookie · No trackers · Nothing sold

01 · Your account

What VX stores about you.

VX stores the account information your organization provides or you enter: your name, call sign, email address, and authentication data, including multi-factor authentication settings. We use it to operate your account and secure the application, and nothing else. No marketing, no mailing lists, nothing sold, ever.

02 · Cookies and maps

One cookie, no trackers.

VX sets one cookie: the session cookie that keeps you signed in. It expires when you close your browser, and sessions end automatically after 30 minutes of inactivity. There are no advertising trackers and no third-party analytics.

VX’s maps are provided by Mapbox; when maps load, your browser requests map data from Mapbox’s servers, which receive standard request information such as your IP address. We send Mapbox nothing about you.

03 · Activity records

Logs that keep the system honest.

Like any system handling regulated data, VX keeps operational logs: sign-ins, failed sign-in attempts, and administrative changes to the database. These records exist for security and accountability and are retained under our data management policy.

04 · Your organization’s data

Processed on its behalf, governed by agreement.

The operational data in VX, including any protected health information, belongs to the client organization and is processed on its behalf. Where that data includes PHI, Brandt VX, LLC acts as a business associate under a business associate agreement, and that agreement and HIPAA govern its use, disclosure, and protection. Requests about individual records (access, amendment) should go to your organization, which directs how its data is handled; we support those requests under the applicable agreement.

05 · Protection

Where it lives and how it’s protected.

VX runs on Amazon Web Services in the United States, under a business associate agreement with AWS. Data is encrypted in transit and at rest, access is limited to authorized personnel, and database activity is logged. Our compliance posture (HIPAA and SOC 2) is monitored continuously and published at trust.brandtvx.com.

06 · End of access

The agreement always governs.

When access ends, accounts are disabled promptly. Anything that remains is bound by the client agreement and, for PHI, the business associate agreement: data is kept, returned, or destroyed only as those agreements require, and is never put to any use they do not permit.

07 · Changes and contact

Ask us directly.

We may revise this notice by posting a new version here with a new revision date. Questions: info@brandtvx.com, and a person will answer.

Last revised: August 17, 2026.