This Privacy Statement describes how Maxeta Technologies, Inc. (“Maxeta,” “we,” “us,” or “our”) processes personal information and other data in connection with Maxeta-hosted deployments of the RadSurv software application (“RadSurv” or the “Service”).
Maxeta’s processing of personal information through the maxetatech.com website, marketing activities, and other corporate functions is described in the Maxeta Privacy Statement. Use of RadSurv is also governed by the RadSurv Terms of Service, which controls the contractual relationship between Maxeta and the customer organization that subscribes to the Service (“Customer”).
1.Roles and Responsibilities
For most personal information processed through RadSurv — including data about Customer’s personnel, contractors, and survey subjects — Customer is the data controller and Maxeta acts as a data processor (or, under U.S. state privacy laws, as a service provider) on Customer’s behalf. Maxeta processes this information only to provide, secure, support, and improve the Service for Customer, and in accordance with the Terms of Service and any applicable data processing terms.
Maxeta acts as an independent controller only for limited categories of information that Maxeta determines the purposes and means of processing, such as service account administration, billing, and security logs maintained for Maxeta’s own operational and legal purposes.
2.Information We Process
Authentication and Identity Data
When Customer enables single sign-on through an identity provider such as Microsoft Entra ID, Maxeta receives identity attributes necessary to authenticate users and provision role-based access. These typically include the user’s name, work email address, Entra object identifier, tenant identifier, and group or role assignments used to map permissions within RadSurv. Maxeta does not receive passwords or other authentication secrets.
Customer Data
“Customer Data” is defined in the Terms of Service and includes survey data, map and template configuration, dose and contamination measurements, postings, equipment locations, briefing records, peer review records, generated reports, and any other content submitted by Customer or its authorized users to RadSurv. Customer Data may include personal information about Customer’s personnel and, depending on Customer’s use, information that Customer treats as sensitive under its own policies or applicable regulatory requirements.
Service Usage and Security Data
Maxeta automatically collects information generated by use of RadSurv, including authentication events, application audit logs, IP addresses, browser and device information, timestamps, feature usage, and error and performance telemetry. This information is used to operate, secure, monitor, support, and improve the Service.
Communications
When a Customer representative contacts Maxeta for support or other purposes, we process the contents of those communications and associated contact information to respond and to maintain support records.
3.How We Use Information
Maxeta uses the information described in Section 2 to:
- Provide, operate, and deliver RadSurv to Customer and its authorized users.
- Authenticate users, provision and manage access, and enforce role-based permissions.
- Monitor and secure the Service, including detecting and responding to security events, abuse, and unauthorized access.
- Diagnose and resolve technical issues and provide customer support.
- Maintain audit trails, logs, and records of activity within RadSurv.
- Improve the Service, including its performance, reliability, features, and user experience.
- Comply with legal obligations, respond to lawful requests, and enforce the Terms of Service.
Identity data and Customer Data processed through RadSurv are not used for advertising, sold to third parties, used to train artificial intelligence or machine learning models for any purpose other than serving Customer, or combined with marketing data collected through Maxeta’s corporate website or marketing channels.
4.Tenant Isolation
Each Customer is provisioned with a dedicated application instance and database. Customer Data is not commingled across tenants. Maxeta personnel access a Customer’s tenant only when necessary to provide, secure, or support the Service, and such access is logged and subject to internal controls.
5.Hosting and Subprocessors
RadSurv is hosted in commercial cloud infrastructure located in the United States. Maxeta engages a limited number of subprocessors that provide cloud infrastructure, monitoring, security, and operational services necessary to deliver RadSurv. Maxeta maintains a current list of RadSurv subprocessors and will provide it to Customer on request. Maxeta requires its subprocessors to maintain security and confidentiality protections appropriate to the data they process.
6.Security and Compliance
Maxeta maintains a formal information security program that includes administrative, technical, and physical safeguards designed to protect personal information and Customer Data against unauthorized access, disclosure, alteration, and destruction. These safeguards include encryption of data in transit, encryption of data at rest, access controls, logging and monitoring, vulnerability management, and personnel training.
Maxeta is pursuing SOC 2 Type II certification. Once issued, the report will be available to Customer under a non-disclosure agreement on reasonable request.
No method of transmission or storage is completely secure, and Maxeta cannot guarantee absolute security. Incident notification and other contractual security commitments are governed by the Terms of Service and any applicable Order.
7.Data Retention and Deletion
Customer Data is retained for the term of the applicable Order. Upon termination or expiration of the Order, Maxeta will make Customer Data available for export in accordance with the Terms of Service and will thereafter delete Customer Data from production systems in the ordinary course of business. Backup copies are retained for a limited period in accordance with Maxeta’s backup retention practices and are deleted on a rolling basis.
Service usage and security data, including audit logs, are retained for the period necessary to support security monitoring, incident response, troubleshooting, and applicable legal and regulatory obligations.
8.Individual Rights and Requests
Depending on the jurisdiction in which they reside, individuals whose personal information is processed through RadSurv may have rights to access, correct, delete, restrict, or object to the processing of their personal information, or to data portability.
Because Maxeta processes most personal information in RadSurv on behalf of Customer as a processor or service provider, individuals should generally direct requests to exercise these rights to Customer, which controls how the information is collected and used within its tenant. Maxeta will assist Customer in responding to such requests as required by applicable law and the Terms of Service.
Individuals may also contact Maxeta directly using the contact information in Section 12. Maxeta will route the request to the relevant Customer where appropriate, and will respond directly with respect to any information for which Maxeta is the controller.
9.International Data Transfers
RadSurv is operated from the United States. If Customer or its authorized users access RadSurv from outside the United States, information processed through the Service will be transferred to and processed in the United States, which may have data protection laws different from those of the user’s country of residence. Where required by applicable law, Maxeta relies on appropriate safeguards for international transfers and will enter into supplementary contractual terms with Customer as necessary.
10.Children’s Privacy
RadSurv is an enterprise application intended for use by Customer’s authorized personnel in occupational settings. RadSurv is not directed to children, and Maxeta does not knowingly collect personal information from children through the Service.
11.Changes to This Privacy Statement
Maxeta may update this Privacy Statement from time to time. If Maxeta makes material changes, Maxeta will provide reasonable advance notice to Customer, including by posting the updated Privacy Statement at the URL where this Privacy Statement is hosted, by notice within RadSurv, or by email to Customer’s designated contact. The “Effective Date” above will reflect the date of the most recent update.
12.Contact Information
Questions about this Privacy Statement, requests relating to personal information processed in connection with RadSurv, or other privacy-related inquiries should be directed to: