Privacy policy
L37 Innovations Inc. (“L37”, “we”, “us”, “our”) is a Delaware corporation providing Physical AI and Clinical AI solutions for healthcare, pharmaceutical, and life sciences organizations, through our website at www.l37.co (the “Site”) and our products and services (collectively, the “Services”).
This Privacy Policy explains how we collect, use, share, and protect Personal Information — any information relating to an identified or identifiable individual — when you visit our Site, interact with us, or use our Services.
L37 acts in two distinct roles. For information collected through the Site and in the course of our business relationships (for example, contact details of client representatives), L37 is the data controller. For clinical and operational data processed within our Services on behalf of hospitals, health systems, and other enterprise clients, L37 acts as a data processor — or service provider / business associate, as applicable — under a written agreement with that client. In those cases the client's own privacy notice governs, and this Policy applies only to the extent L37 determines the purposes and means of processing.
If you do not agree with this Privacy Policy, please do not use the Site or submit Personal Information to us.
Information we collect through the Site
Contact information such as your name, business email address, phone number, employer, job title, and country, when you contact us, request a briefing, or subscribe to communications;
Communications, including the content of messages you send us, questions, feedback, and responses to surveys;
Event and meeting information, such as registration details for demonstrations, webinars, and briefings;
Usage information, including pages visited, features used, date and time of access, IP address, browser type, operating system, device identifiers, and referring domain, collected through cookies and similar technologies;
Recruitment information, such as CVs and related details, if you apply to work with us.
We do not collect Personal Information from the Site for advertising resale, and we do not sell Personal Information.
Data processed within our Services
Our Services operate inside clinical and operational environments. Depending on the deployment, they may process:
Operational telemetry from robots and connected hospital assets, such as location, task status, and sensor readings;
Voice and video data captured by assistive robots and devices, including speech processed for transcription and interaction;
Clinical and patient data made available by the client within its systems and processed under the client's instructions;
Simulation and digital twin data describing facilities, equipment, and workflows.
This data is processed on behalf of, and under the documented instructions of, our clients, under contracts that include data processing terms and — where applicable in the United States — business associate agreements. Our clients are responsible for the lawfulness of the underlying data and for obtaining any required patient consents.
How we use Personal Information
Providing and operating the Site and Services, and performing our contracts;
Responding to inquiries and managing our business relationships;
Sending administrative and service communications, such as confirmations, technical notices, and updates;
Sending marketing communications about our Services, with your consent where required — you can opt out at any time;
Improving and securing our Site and Services, including analytics, monitoring, fraud prevention, and enforcement of our terms;
Complying with legal obligations and responding to lawful requests.
Where the GDPR or similar laws apply, we process Personal Information on the following legal bases: performance of a contract; our legitimate interests; your consent; and compliance with legal obligations.
Cookies and analytics
We use cookies and similar technologies for authentication, preferences, security, and analytics. You can control cookies through your browser settings and, where required by law, through the consent manager presented when you first visit the Site. For more information, see our Cookie Notice.
How we share Personal Information
Service providers supporting our operations — including cloud hosting and infrastructure, identity and access management, payment processing, communications, customer relationship management, and analytics — under data processing agreements;
L37 business units in the United States, France, Kazakhstan, and Kenya, for the purposes described in this Policy;
Professional advisers, such as lawyers, auditors, and insurers, under confidentiality obligations;
Counterparties and advisers in a merger, acquisition, financing, reorganization, or sale of assets, with appropriate safeguards during diligence;
Public authorities, courts, or regulators where required by law, to comply with legal process, or to protect rights, safety, and property.
We do not sell Personal Information, and we do not share it for cross-context behavioral advertising.
International data transfers
L37 operates internationally. Where Personal Information is transferred across borders — including to the United States — we implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses, or we rely on adequacy decisions or other lawful transfer mechanisms. Copies of the applicable safeguards are available on request.
Regional disclosures
European Economic Area and United Kingdom
If you are in the EEA or the UK, you have the following rights regarding Personal Information for which L37 is the controller, subject to the conditions of the GDPR and UK GDPR:
To be informed about, and to access, the Personal Information we hold about you;
To rectify inaccurate or incomplete Personal Information;
To erasure and to restriction of processing, under certain circumstances;
To data portability, under certain circumstances;
To object to processing based on legitimate interests, and to direct marketing at any time;
To withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
To lodge a complaint with your supervisory authority.
United States
Where L37 processes protected health information for covered entities or other business associates, it does so as a business associate under written business associate agreements pursuant to HIPAA. California residents and residents of other states with comprehensive privacy laws may have additional rights, including the right to know, correct, delete, and opt out of certain sales or sharing. To exercise these rights, contact us at info@l37.co.
France
Personal health data processed in connection with deployments in France is hosted by HDS-certified providers and processed in accordance with the GDPR and applicable guidance of the CNIL.
Kenya
Personal Information relating to individuals in Kenya is processed in accordance with the Data Protection Act, 2019, including rights of access, correction, and deletion. Complaints may be addressed to the Office of the Data Protection Commissioner.
Kazakhstan
Personal Information relating to individuals in Kazakhstan is processed in accordance with the Law of the Republic of Kazakhstan “On Personal Data and Their Protection”, including its consent and cross-border transfer requirements.
AI and automated decision-making
Our Services include agentic AI and Physical AI systems. L37 designs these systems for human oversight: they support clinical and operational decisions, but they do not make solely automated decisions that produce legal or similarly significant effects on individuals without human review.
Our AI systems record their actions in auditable logs, and we maintain explainability and guardrail mechanisms appropriate to the risk of each deployment. Where laws such as the GDPR or the EU AI Act require additional disclosures or impact assessments, we provide them in the relevant contractual documentation.
Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, multi-factor authentication, audit logging, network isolation, and regular security assessments. No system is completely secure; if you believe your interaction with us has been compromised, please contact us immediately at info@l37.co.
Data retention
We retain Personal Information for as long as necessary for the purposes described in this Policy, to comply with legal and contractual obligations — including medical record retention rules applicable to our healthcare clients — and to resolve disputes and enforce our agreements. When retention periods expire, we delete or anonymize Personal Information securely.
Children
Our Site and Services are intended for business users and are not directed to children. We do not knowingly collect Personal Information from children through the Site. Where our Services process paediatric patient data, that data is processed on behalf of and under the instructions of our healthcare clients, who are responsible for the applicable consents and disclosures.
Your choices and rights
You may request access to, correction of, or deletion of your Personal Information, or exercise the other rights described in this Policy, by contacting info@l37.co. We verify requests before acting on them and respond within the timeframes required by applicable law. You will not be discriminated against for exercising your rights.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and revise the “Date of last revision” below, and where required by law we will provide additional notice. Your continued use of the Site after the effective date of the updated Policy constitutes your acceptance of the changes.
Contact us
If you have questions or concerns about this Privacy Policy or L37's privacy practices, contact us at:
L37 Innovations Inc.
Attention: Privacy
200 Continental Drive, Suite 401,
Newark, DE 19713, USA
+1 (740) 272-5256
Date of last revision: June 12, 2026