1. Who is responsible for your data
The data controller for HL7 Workbench is Saga IT, LLC, a Florida limited liability company based in West Palm Beach, Florida, United States. You can reach us about privacy at customer-support@saga-it.com.
HL7 Workbench is provided from the United States and is not currently directed at individuals in the European Union, the EEA, or the United Kingdom: we do not target those regions, offer local pricing, or localise the service for them. We have accordingly not appointed a representative under Article 27 of the GDPR or of the UK GDPR. Should we begin offering the service to individuals in those regions, we will appoint a representative for each and name it here, with contact details, before we do so.
2. Message content stays in your browser
Parsing, validation, building, and analysis of HL7 messages happen entirely in your browser. Your messages are not uploaded to, processed by, or stored on our servers, and they are never used to train models.
When terminology validation is enabled (it is by default — you can turn it off in Terminology settings, or use Offline Mode), the individual vocabulary codes being checked — the code, its code system, and its display label — are sent to our terminology service as lookup queries. These lookups are answered transiently and are excluded from our request logs and traces.
If you enable message persistence, messages are stored encrypted in your own browser storage on your device. Clearing your browser data removes them.
Because your messages never reach us, we cannot recover them for you, and we cannot disclose them to anyone else.
3. Information we collect
Account information: the identifier, email address, and display name supplied by the sign-in provider you choose, plus your account tier and the version of the Terms of Service you accepted and when. An email address is required to create an account; without one we cannot provide the service.
Settings and saved work: your interface preferences and any conformance profiles you choose to save to your account.
Technical metadata: for each request, your IP address, the request path and method, a timestamp, the response status and timing, a build identifier, and a licence identifier; for signed-in requests, your account identifier is attached to the log line. Aggregate analytics events additionally record approximate country and device/browser type, derived at our edge and not linked to your account.
Product analytics: a fixed set of events describing which pages you visit and which tools you use — for example parsing, validating, or exporting — together with your account tier. These events are drawn from a closed list and cannot contain free text or anything derived from your message content.
Payment information (Pro plan, when available): if you subscribe to a paid plan, our payment processor collects and processes your payment details directly; we receive only limited billing metadata such as your plan, status, and the last four digits of a card. We do not store full card numbers.
4. Why we use it, and our legal basis
We use this information to create and authenticate your account and keep you signed in; to sync your settings across your devices; to provide and, when available, bill the paid plan; to operate, secure, and troubleshoot the service and prevent abuse or unauthorised copying; to understand which features are used so we can improve them; and to meet our legal obligations.
Where the law (including the EU and UK GDPR) requires a legal basis, we rely on: performance of our contract with you (Article 6(1)(b)) to create and run your account and to provide and bill the service; our legitimate interests (Article 6(1)(f)) to secure the service, prevent abuse and unauthorised copying, and understand and improve product usage; your consent (Article 6(1)(a)) for any non-essential cookies or optional marketing; and compliance with a legal obligation (Article 6(1)(c)) where one applies. We do not make decisions about you that produce legal or similarly significant effects solely by automated means.
5. Third-party sign-in
You can sign in with Google, Microsoft, or GitHub. Doing so shares your name and email address with us, subject to that provider’s consent screen and privacy policy. We never receive your password. You can also register directly with an email address and password; that password is stored only as a secure hash by our own sign-in service and never in plain text.
Authentication is handled by our own identity service. We do not store passwords for accounts created through a third-party provider.
6. Who we share it with
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
We share it only with service providers who host and operate the service on our behalf, under contracts that limit their use of it to providing services to us. These are: cloud hosting and infrastructure; content-delivery and security; transactional email; and, when the Pro plan launches, a payment processor. We also disclose information where we are legally required to, or where necessary to establish, exercise, or defend legal claims.
7. International data transfers
The service is operated using infrastructure located in the United States. If you are in the European Union, the EEA, the United Kingdom, or elsewhere outside the United States, your account information and technical metadata are transferred to and processed in the United States.
As stated in section 1, the service is not directed at individuals in the European Union, the EEA, or the United Kingdom, and we do not currently rely on a transfer mechanism for those regions. Should we begin offering the service there, we will put appropriate safeguards in place before we do — the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) for transfers from the EU/EEA, and the UK International Data Transfer Agreement or the UK Addendum to those clauses for transfers from the United Kingdom, together with a transfer risk assessment — and describe them here. We do not rely on the EU-US Data Privacy Framework.
8. How long we keep it
Account information, settings, and saved profiles are kept while your account is open, and deleted within 30 days of account closure except where we must retain records to meet a legal obligation.
Technical metadata and analytics events are kept for up to 12 months, then deleted or aggregated so they no longer identify you. Records that prove your acceptance of these terms and, for paid plans, your consent to recurring charges are kept as long as the law requires.
9. Security
We use encryption in transit, encryption at rest for stored account data, and access controls that limit staff access to what their role requires. Locally persisted messages are encrypted in your browser with a key held on your device.
No service can promise perfect security, but we will notify you and any regulator as the law requires if a breach affects your information.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent where we rely on it. Under the EU and UK GDPR these are the rights of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent.
You can exercise these rights, including deletion of your account and its data, by contacting customer-support@saga-it.com. We respond free of charge and within one month; if a request is complex or numerous we may extend that by up to two further months and will tell you within the first month if we do. We may need to verify your identity first.
If you are in the EU/EEA you may complain to your national data-protection authority; if you are in the UK you may complain to the Information Commissioner’s Office (ico.org.uk).
11. Your US state privacy rights
If you are a US resident of a state with a comprehensive privacy law (such as California, Colorado, Connecticut, Virginia, and others), you may have rights to know, access, correct, delete, and obtain a copy of your personal information, and to appeal a decision on your request. Contact customer-support@saga-it.com to exercise them; where the law provides an appeal, we will explain how.
We do not "sell" your personal information and we do not "share" it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, so we do not offer a "Do Not Sell or Share" mechanism; because we do not sell or share personal information, opt-out preference signals such as Global Privacy Control do not change any processing we perform. For the same reason we do not respond to browser 'Do Not Track' signals — there is no cross-site tracking for such a signal to switch off. We do not discriminate against you for exercising your rights.
12. Children
HL7 Workbench is a professional tool and is not directed to children. We do not knowingly collect personal information from anyone below the age of digital consent that applies where they live (which ranges from 13 to 16 in the EU, and is 13 under US law). If you believe a child has provided us information, contact us and we will delete it.
13. Cookies and similar technologies
We use cookies and browser storage that are necessary to run the service: to keep you signed in, to remember your settings, and to protect against abuse. We do not use advertising or cross-site tracking cookies. Any non-essential cookie would be used only with your consent.
14. Changes and contact
We may update this policy; each version carries a publication date, and material changes are notified in the application.
Questions, requests, and complaints can be sent to Saga IT, LLC at customer-support@saga-it.com.