Privacy Policy
At a Glance
- We collect your name, email, and other information you provide through our website forms.
- We use Google Analytics and HubSpot to understand how our website is used.
- We do not sell your personal information to anyone, ever.
- You have rights under California law to access, delete, and correct your information.
- If you have questions, email us at nicholas.demetriades@alstenimedical.com.
1. Who We Are
Alsteni Medical, Inc. is a Delaware C-Corporation headquartered in Los Angeles, California. We are developing an investigational medical device — the Alsteni System — which is not yet cleared by the FDA and is not available for sale or clinical use.
This Privacy Policy explains how we collect, use, and protect your information when you visit our website at alstenimedical.com or interact with us through our online forms.
Regulatory notice: The Alsteni System is an investigational device under development. It has not been cleared or approved by the U.S. Food and Drug Administration. No product described on this website is available for sale, and no information on this website should be construed as a claim of safety or effectiveness for any investigational device.
2. Information We Collect
Information You Provide Directly
When you fill out a form on our website, you may provide:
- Name
- Email address
- Institutional or organizational affiliation
- Professional role or medical specialty
- Whether you are interested in learning about our clinical study
- Free-text messages or questions
You are never required to provide this information. If you choose not to, you can still browse our website freely.
Information Collected Automatically
When you visit our website, certain information is collected automatically through cookies and similar technologies:
- IP address (used to approximate geographic location; not stored in full by Google Analytics)
- Device type, operating system, and browser information
- Pages you visit on our website and how long you spend on them
- The website or link that referred you to us
- Clicks, scrolls, and other interactions with our website
This information is collected by two services we use: Google Analytics 4 and HubSpot. We describe each in detail in Section 5.
Information From Third Parties
We do not currently purchase personal information from data brokers or other third-party sources. HubSpot, our customer relationship management platform, may enrich contact records with publicly available business information (such as company name and size) when you submit a form.
3. How We Use Your Information
| Purpose | Information Used |
|---|---|
| Responding to your inquiries | Name, email, message content |
| Sending company updates (when you opt in) | Name, email |
| Tracking interest in our clinical study | Name, email, institutional affiliation, specialty, study interest |
| Investor relations communications | Name, email, firm/affiliation, role |
| Analyzing website traffic and usage patterns | IP address, device info, browsing behavior (via GA4, HubSpot) |
| Improving website functionality and content | Browsing behavior, session data |
We do not use your information for any purpose other than those listed above. We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
4. How We Share Your Information
We do not sell your personal information. We have not sold personal information in the preceding 12 months, and we have no plans to do so.
We share information with the following categories of service providers, solely for the purposes described above:
| Provider | Data Shared | Purpose |
|---|---|---|
| HubSpot | Form submissions, IP address, browsing behavior, email interactions | CRM, email communications, website analytics |
| Google (Analytics 4) | IP address (anonymized), device info, browsing behavior | Website traffic analysis |
We may also disclose your information if required by law, court order, or government request, or to protect our legal rights.
5. Cookies and Tracking Technologies
Our website uses cookies and similar technologies. A cookie is a small text file stored on your device by your web browser. We use cookies for website functionality, analytics, and advertising measurement.
Google Analytics 4
| Cookie | Purpose | Duration |
|---|---|---|
_ga | Distinguishes unique visitors | 2 years |
_ga_[container-id] | Maintains session state | 2 years |
Google Analytics helps us understand how visitors use our website. Google may use this data in accordance with its own privacy policy. You can opt out by installing the Google Analytics Opt-Out Browser Add-On.
HubSpot
| Cookie | Purpose | Duration |
|---|---|---|
__hstc | Main visitor tracking (domain, timestamps, session count) | 6 months |
hubspotutk | Visitor identity (links form submissions to browsing history) | 6 months |
__hssc | Session tracking | 30 minutes |
__hssrc | Detects new browser sessions | Session |
__hs_opt_out | Records cookie consent preferences | 6 months |
__hs_cookie_cat_pref | Records consented cookie categories | 6 months |
HubSpot is our customer relationship management platform. It helps us manage communications and understand how visitors interact with our website. When you submit a form, HubSpot links your form submission to your previous browsing activity on our site.
Managing Cookies
You can manage cookies through:
- Our cookie consent banner, which appears when you first visit our website
- Your browser settings (most browsers allow you to block or delete cookies)
- The Global Privacy Control (GPC) signal in your browser, which we honor as an opt-out request
Blocking all cookies may affect your experience on our website, but you will still be able to browse and read all content.
6. How Long We Keep Your Information
| Data Category | Retention Period | Reason |
|---|---|---|
| Contact information and CRM records | Duration of relationship + 3 years | Business communications |
| Clinical study interest records | 5 years after collection | Anticipated regulatory recordkeeping requirements |
| Investor inquiry records | Duration of relationship + 3 years | Securities law recordkeeping |
| Website analytics (Google Analytics) | 14 months | GA4 default retention setting |
| HubSpot browsing data | Duration of account | CRM platform default |
| Cookie data | Per cookie durations above | Varies by cookie |
When the retention period expires, we delete or anonymize your information. You can request deletion at any time (see Section 7).
7. Your Privacy Rights
California Residents
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), California residents have the following rights:
- Right to Know: You can request a copy of the personal information we have collected about you in the past 12 months, including the categories of information, the sources, the purposes, and any third parties we shared it with.
- Right to Delete: You can request that we delete the personal information we have collected about you, subject to certain legal exceptions.
- Right to Correct: You can request that we correct inaccurate personal information we maintain about you.
- Right to Opt Out of Sharing: You can opt out of the sharing of your personal information for cross-context behavioral advertising. You can do this by enabling Global Privacy Control (GPC) in your browser, or emailing us.
- Right to Limit Use of Sensitive Personal Information: If we collect sensitive personal information (such as information about your health or medical conditions), you can request that we limit its use to what is necessary for the purposes for which it was collected.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
Verification: To protect your information, we will verify your identity before fulfilling a request. We may ask you to confirm information you previously provided to us.
Authorized agents: You can designate an authorized agent to submit a request on your behalf. We may require proof of the agent’s authorization and verify your identity directly.
Visitors Outside the United States
Our website is accessible worldwide. If you are visiting from outside the United States — including from the European Economic Area (EEA), United Kingdom, or Switzerland — please be aware that your information will be transferred to and processed in the United States, where our servers and service providers are located.
Legal basis for processing (EEA/UK visitors): We process your information based on your consent (for marketing communications and non-essential cookies), our legitimate interests (for website analytics and security), and contractual necessity (when responding to your inquiries).
Data transfer safeguards: Our service providers (HubSpot and Google) participate in the EU-U.S. Data Privacy Framework and/or maintain Standard Contractual Clauses approved by the European Commission.
Additional rights: EEA, UK, and Swiss residents may also have the right to access, rectify, erase, restrict processing, object to processing, and request portability of their personal data. You may also lodge a complaint with your local data protection authority. To exercise these rights, email nicholas.demetriades@alstenimedical.com.
8. Health Information
We are a medical device company, and some visitors to our website may be patients, caregivers, or healthcare professionals interested in our technology or clinical research.
What we collect: If you indicate interest in our clinical study through our website forms, that indication — combined with any information about your medical condition that you choose to share — may constitute health-related information.
How we treat it: We treat all health-related information with heightened care. We use it only to communicate with you about our clinical study or to respond to your inquiries. We do not share health-related information with advertisers, data brokers, or any other third parties for marketing purposes.
What we are not: Alsteni Medical is not a healthcare provider, health plan, or healthcare clearinghouse. Our website is not a patient portal and does not provide medical advice, diagnosis, or treatment. Information collected through our website forms is not Protected Health Information (PHI) under HIPAA.
The content on this website does not constitute medical device labeling, advertising for an approved product, or a solicitation for the sale of a medical device.
Information you provide regarding interest in our clinical study is collected solely for the purpose of future communications about study enrollment opportunities. Submission of any form on this website does not constitute enrollment in a clinical trial, create a patient-provider relationship, or guarantee future access to any investigational device.
Your rights: If you have shared health-related information with us and would like it deleted, email nicholas.demetriades@alstenimedical.com and we will delete it within 30 days.
9. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your information from unauthorized access, use, or disclosure. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls limiting who within our organization can view your information
- Use of service providers (HubSpot, Google) that maintain SOC 2 Type 2 compliance
- Regular review of our data handling practices
No method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee its absolute security.
10. Children’s Privacy
Our website is not directed to individuals under the age of 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, please contact us at nicholas.demetriades@alstenimedical.com.
11. Third-Party Links
Our website may contain links to third-party websites, such as published research articles, social media profiles, or service provider websites. We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policy of any website you visit.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you by email or through a banner on our website.
We encourage you to review this policy periodically.
13. Contact Us
If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us at: