Section 1Introduction and Scope
1.1Who We Are
Beema Technologies Limited Company (“Beema Technologies”), a Texas limited liability company (Texas Secretary of State File Number: 805958746, effective April 1, 2025), operates the Voxelion platform, accessible at voxelion.ai. Voxelion is a perceptual data integrity engine offering two core products: Voxelion Health, a 3D DICOM medical imaging deduplication solution, and Voxelion Drive, a LiDAR and multi-sensor autonomous vehicle perception data deduplication solution. Throughout this Privacy Policy, references to “Voxelion,” “we,” “us,” or “our” refer collectively to Beema Technologies Limited Company and its products and services.
1.2What This Policy Covers
This Privacy Policy describes how Voxelion collects, uses, stores, processes, transfers, and protects information when you: (a) access or browse our website at voxelion.ai; (b) use our application programming interface (API), software development kit (SDK), or platform services; or (c) communicate or interact with us in any capacity. This Policy applies to all users globally, including individual developers, enterprise customers, and business partners.
1.3Global Applicability
Voxelion serves customers across multiple jurisdictions worldwide. This Privacy Policy is designed to satisfy the requirements of applicable data protection laws, including but not limited to:
- The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations at 45 CFR Parts 160 and 164;
- The European Union General Data Protection Regulation (EU) 2016/679 (GDPR);
- The California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA);
- The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024; and
- Other applicable national, state, and regional data protection and privacy laws.
Where applicable law in a particular jurisdiction imposes requirements more stringent than those stated in this Policy, Voxelion will comply with the more stringent standard with respect to residents of that jurisdiction.
1.4Acceptance
Section 3How We Use Information
3.1Service Delivery
We use collected information to provision and maintain API access and platform services; calculate and process billing based on the volume of data processed (in GB); maintain account records and user preferences; authenticate users and enforce access controls; and deliver technical support and respond to inquiries.
3.2Product Improvement
Aggregated and anonymized usage metrics may be used internally to improve product performance, prioritize engineering features, identify and resolve technical issues, and enhance overall platform reliability. No individual customer data — and no customer spatial, imaging, or sensor data — is used for product training, model development, or algorithm improvement without the customer’s explicit prior written consent.
3.3Communications
We use contact information to send: transactional and service notifications (e.g., account confirmations, API status alerts); security advisories; billing summaries and invoices; product update announcements; and responses to direct inquiries. Marketing or promotional communications are strictly opt-in and will not be sent absent your express consent. You may withdraw consent for marketing communications at any time by following the unsubscribe instructions included in each communication or by contacting privacy@voxelion.ai.
3.4Legal Compliance and Security
We use and disclose information as necessary to comply with applicable law and regulatory requirements; respond to valid legal process (e.g., subpoenas, court orders); enforce our Terms of Service and other agreements; investigate, detect, and prevent fraud, abuse, or unauthorized access; and protect the security, integrity, and availability of our platform and the rights and safety of our users and the public.
3.5Billing and Financial Administration
Usage data is used to calculate charges under applicable service tiers (including, for example, the Infrastructure Growth tier at $0.015 per GB of data processed), generate invoices, manage enterprise contract billing, and maintain financial records required for tax and regulatory compliance.
Section 4HIPAA Compliance and Protected Health Information
4.1HIPAA Applicability
Voxelion Health is used by healthcare providers, radiology AI developers, health systems, and medical technology companies who may qualify as Covered Entities or Business Associates under HIPAA. Where Voxelion processes or could access PHI on behalf of a Covered Entity or Business Associate — even if only incidentally — Beema Technologies Limited Company acts as a Business Associate as defined under 45 CFR §160.103, and assumes all applicable obligations thereunder.
4.2Business Associate Agreements (BAA)
Mandatory Requirement — No Exceptions
Consistent with 45 CFR §164.308(b) and §164.502(e), Beema Technologies Limited Company will enter into a fully executed Business Associate Agreement (BAA) with any Covered Entity or Business Associate customer whose use of Voxelion Health involves or could potentially involve access to PHI, prior to the commencement of any processing. No real patient health data may be processed through any Voxelion system until a fully executed BAA is in place. This requirement admits of no exceptions, waivers, or informal workarounds.
4.3Technical and Administrative Safeguards for Health Data
Voxelion implements the following safeguards in connection with health-adjacent workloads:
- Encryption in Transit: All data transmitted to or processed by Voxelion systems is encrypted using TLS 1.2 or higher.
- Encryption at Rest: All data stored within Voxelion infrastructure is encrypted using AES-256.
- Access Control: Access to systems that may interface with health data is governed by role-based access control (RBAC) with mandatory multi-factor authentication (MFA) for all internal users.
- Audit Logging: Comprehensive audit logs are maintained of all access events, system interactions, and processing activities relating to health workloads.
- Minimum Necessary Standard: Access to health-adjacent systems is limited to personnel with a documented, legitimate operational need.
4.4No PHI in Development or Testing
Voxelion strictly prohibits the use of real, non-de-identified patient data in development, staging, or testing environments. All internal testing of the Voxelion Health engine uses synthetic datasets or datasets that have been formally de-identified in compliance with 45 CFR §164.514(b). Enterprise customers are contractually required to adhere to the same standard and may not use real PHI in non-production environments without a separately executed agreement and documented safeguards.
4.5HIPAA-Eligible Infrastructure
Voxelion operates exclusively on cloud infrastructure that is certified as HIPAA-eligible. All cloud service providers and infrastructure vendors used in connection with health-adjacent workloads are evaluated for HIPAA eligibility prior to deployment, and standard Business Associate Agreements are in place with all applicable infrastructure providers.
4.6Architectural PHI Protection
As described in Section 2.5, the Voxelion Health engine generates spatial fingerprints from the three-dimensional geometric content of DICOM files without accessing patient metadata fields. This architectural design means PHI is inaccessible to the processing engine even in the theoretical absence of encryption. Voxelion employs both technical controls and administrative safeguards as complementary, defense-in-depth layers of PHI protection — neither layer is considered a substitute for the other.
Section 5Data Sharing and Third Parties
5.1No Sale of Personal Data
Voxelion does not sell, rent, license, or trade personal data to third parties for monetary or other consideration, in any form, for any commercial purpose. This commitment applies universally to all users and jurisdictions and specifically satisfies the opt-out of sale requirements under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
5.2Service Providers
We share data only with carefully vetted third-party service providers that assist in the operation and delivery of our platform. These categories of providers include: PCI-DSS-compliant payment processors; cloud infrastructure and data hosting providers; customer relationship management and support tools; and communication and notification services. All service providers operate under written data processing agreements that require data protection standards at least equivalent to those set forth in this Policy and, where applicable, in applicable law.
5.3Business Transfers
In the event of a merger, acquisition, consolidation, reorganization, or sale of all or substantially all of the assets of Beema Technologies Limited Company, user data may be transferred to the acquiring or successor entity as part of that transaction. In such an event, Voxelion will provide affected users with reasonable advance written notice (no fewer than 30 days prior to any transfer) and will ensure that the acquiring entity is bound by privacy obligations no less protective than those contained in this Policy.
5.4Legal Requirements and Protection of Rights
We may disclose information about you when we have a good-faith belief that such disclosure is: required by applicable law, regulation, or valid legal process (including subpoenas, court orders, or regulatory demands); necessary to protect and enforce our legal rights, contractual agreements, or the security and integrity of our platform; or necessary to protect the health, safety, or rights of our users, employees, or the public.
5.5International Data Transfers
Beema Technologies Limited Company is headquartered in the United States. Where data is transferred from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States or other jurisdictions that may not provide a level of data protection equivalent to that required under applicable law, Voxelion implements appropriate and legally recognized transfer safeguards, including:
- Standard Contractual Clauses (SCCs) as approved by the European Commission (Implementing Decision (EU) 2021/914);
- UK-specific International Data Transfer Agreements (IDTAs) or addenda where applicable; and
- Such other transfer mechanisms as may be recognized and approved by relevant data protection authorities.
Section 6Data Retention
Voxelion retains personal data only for as long as necessary to fulfill the purposes for which it was collected, to perform our contractual obligations, and to comply with applicable legal requirements. The following table summarizes our retention periods:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and Registration Data | Duration of customer relationship + up to 7 years after account closure | Legal, tax, and financial recordkeeping obligations |
| API and Usage Logs (identifiable) | 90 days in identifiable form | Billing verification and debugging |
| API and Usage Logs (aggregated/anonymized) | Up to 3 years after aggregation | Trend analysis and capacity planning |
| Audit Logs (Voxelion Health) | Minimum 6 years | HIPAA record retention — 45 CFR §164.530(j) |
| Billing and Financial Records | 7 years | Tax and financial compliance |
| Communications Records | 3 years | Support continuity and dispute resolution |
6.4Deletion Requests
Upon receipt of a valid and verified deletion request submitted in accordance with Section 7.5, Voxelion will delete or irreversibly anonymize identifiable personal data within thirty (30) calendar days, except to the extent that retention is required by applicable law (including HIPAA record retention requirements), necessary for the resolution of pending disputes, or otherwise subject to a legitimate legal hold.
Section 7Your Rights and Choices
7.1Global Privacy Rights
Depending on your jurisdiction and the applicable law, you may have one or more of the following rights with respect to personal data we hold about you:
- Right of Access: The right to request confirmation of whether we process your personal data and, if so, to obtain a copy.
- Right to Rectification / Correction: The right to request correction of inaccurate or incomplete personal data.
- Right to Erasure / Deletion: The right to request deletion of your personal data, subject to applicable legal retention obligations.
- Right to Restriction: The right to request that we restrict processing of your personal data in certain circumstances.
- Right to Object: The right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
- Right to Data Portability: The right to receive a structured, commonly used, machine-readable copy of personal data you have provided to us.
- Right to Withdraw Consent: Where processing is based solely on consent, the right to withdraw that consent at any time, without affecting the lawfulness of prior processing.
7.2GDPR Rights (EEA Residents)
Residents of the European Economic Area have the full suite of rights enumerated in Articles 15 through 22 of the GDPR. Requests should be submitted to privacy@voxelion.ai. Voxelion will respond within thirty (30) days of receipt of a verified request. Where applicable law permits an extension, and the complexity or volume of requests warrants it, we may extend the response period by up to an additional sixty (60) days, with advance written notice. Where we are unable to fulfill a request in whole or in part, we will provide a reasoned written explanation.
7.3CCPA/CPRA Rights (California Residents)
California residents have the following rights under the CCPA and CPRA:
- Right to Know: The right to know what personal information is collected, used, disclosed, or shared, and for what purposes.
- Right to Delete: The right to request deletion of personal information collected from you, subject to certain exceptions.
- Right to Opt Out of Sale: Voxelion does not sell personal information. No opt-out is required; however, users may confirm this at any time by contacting privacy@voxelion.ai.
- Right to Non-Discrimination: The right not to receive discriminatory treatment for exercising any CCPA/CPRA right.
- Right to Correct: The right to request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: Where applicable, the right to limit the use and disclosure of sensitive personal information.
7.4Texas Residents (TDPSA)
Residents of Texas have rights under the Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, including the rights of access, correction, deletion, portability, and the right to opt out of the processing of personal data for purposes of targeted advertising or profiling. Voxelion does not engage in targeted advertising or profiling as defined under the TDPSA. Requests may be submitted to privacy@voxelion.ai.
7.5Exercising Your Rights
To exercise any of the rights described in this Section, submit a written request to privacy@voxelion.ai with sufficient detail to identify your account and the nature of your request. Voxelion will verify your identity before processing any request that could affect personal data. We will respond within thirty (30) calendar days; complex or high-volume requests may require up to sixty (60) days, with advance notice. We will not charge a fee for reasonable, non-repetitive requests.
Section 8Security
8.1Technical Security Measures
Voxelion implements industry-standard technical security measures, including:
- TLS 1.2 or higher encryption for all data in transit;
- AES-256 encryption for all data at rest within Voxelion infrastructure;
- Role-based access control (RBAC) with mandatory multi-factor authentication (MFA) for all internal system access;
- Regular penetration testing conducted by qualified third-party security firms;
- Ongoing vulnerability assessments and patch management programs; and
Section 10Children’s Privacy
Voxelion’s products and services are directed exclusively to businesses and professional users and are not intended for, marketed to, or designed to be used by individuals under the age of 18. Voxelion does not knowingly collect, solicit, or retain personal data from minors. If Beema Technologies becomes aware that it has inadvertently received personal data from an individual under the age of 18, it will promptly delete that data from its systems and, where applicable, notify any relevant guardian or regulatory authority. If you believe we may have collected data from a minor, please contact privacy@voxelion.ai immediately.
Section 11Changes to This Privacy Policy
Voxelion may update this Privacy Policy periodically to reflect changes in our data practices, technology, legal and regulatory requirements, or business operations. We distinguish between two categories of change:
- Material Changes: Changes that meaningfully affect how we collect, use, or share personal data, or that materially affect user rights, will be communicated to registered users by email no fewer than thirty (30) days prior to the revised policy taking effect. The updated policy will also be posted at voxelion.ai with the revised “Last Updated” date prominently displayed.
- Non-Material Changes: Clarifications, corrections of typographical errors, or changes that do not materially affect user rights may take effect immediately upon posting, with no advance notice required.
The “Last Updated” date displayed in the header of this document reflects the date of the most recent revision. Continued use of Voxelion products or services following the effective date of any revised Privacy Policy constitutes your acceptance of the revised terms. If you do not agree to the revised Policy, you must discontinue use of Voxelion services.
Section 12Contact Information and Supervisory Authorities
12.1Privacy Contact
For all privacy-related inquiries, rights requests, complaints, or questions regarding this Policy or Voxelion’s data practices, please contact:
| Entity | Beema Technologies Limited Company |
|---|---|
| Attention | Privacy Officer |
| Address | Houston, Texas, United States |
| privacy@voxelion.ai | |
| Website | voxelion.ai |
12.2GDPR Supervisory Authority (EEA Residents)
EEA residents who believe that Voxelion’s processing of their personal data violates the GDPR have the right to lodge a complaint with the competent data protection supervisory authority in their EU member state of residence or habitual place of work, in addition to any other administrative or judicial remedy available to them. A directory of EU supervisory authorities is available at edpb.europa.eu.
12.3UK Information Commissioner’s Office (UK Residents)
Residents of the United Kingdom who wish to raise a concern about Voxelion’s data practices may contact the Information Commissioner’s Office (ICO), the UK’s independent data protection regulator. The ICO may be contacted at ico.org.uk or by telephone at +44 303 123 1113.
Voxelion Privacy Policy
Beema Technologies Limited Company | Texas Limited Liability Company | TX Secretary of State File No. 805958746
Houston, Texas, United States | privacy@voxelion.ai | voxelion.ai
Effective April 1, 2025 • Last Updated August 20, 2026
This document is the sole property of Beema Technologies Limited Company. Unauthorized reproduction or distribution is prohibited.