Effective Date: September 20, 2026

This Privacy Policy describes how DevicePath Network (“DevicePath,” “we,” “us”) handles information you provide, information generated through your use of the Platform, and information that may be made public through optional Platform features. Read it together with our Terms of Service. If these documents conflict about how information is handled, this Privacy Policy controls.

Information we collect

We collect the details you provide when creating an account or submitting a request: name, organization, business email, phone number (if provided) and the content of your inquiry. If you sign in with Google, we receive basic account identifiers from that provider. Company and product listing information you publish is collected and displayed publicly.

If you create a Professional Profile, we collect the fields you choose to complete: name, job title, professional role, headline, professional summary, territory and coverage information, medical specialties, certifications and company affiliation data. This information is stored as part of your account and is not made public unless you actively publish and, where applicable, enable discoverability for your Professional Profile.

We also keep a record of your agreement to our Terms of Service, consisting of your account identifier, the Terms version accepted and the acceptance timestamp. Each accepted version is stored as its own record, so earlier acceptances are preserved rather than overwritten. Where you accept the Terms while submitting a business inquiry, the accepted version and timestamp are also stored with that inquiry. We do not store IP addresses or device fingerprints as part of that acceptance record.

How we use it

Account information is used to sign you in and show your dashboard. Inquiry details are shared only with the company you contacted so they can respond to your request. Listing information is published in our public directories and may appear in search engines.

Professional Profile information is used to populate your profile editor and, where you have published and made your profile discoverable, your public profile page. Affiliation data is used to display confirmed company relationships on your public profile if you have enabled them for public display.

Introduction request data—the request message, the identities of the requester and recipient and the outcome—is used to operate the introduction feature and to notify both parties of request activity. In-app notification data is used solely to populate the notification feed in your account and is accessible only to you and, where legally required or permitted, to DevicePath administrators.

Professional profiles: what is and is not public

Creating an account does not automatically make any personal or professional information public. Company Listings are published only when you actively publish them. Professional Profiles are created in draft status and are not visible to other users or the public until you set the profile to Published.

For Procurement Partners (individual buyer-side users): a Published Professional Profile is not discoverable by Solution Providers and does not receive a public-facing profile page unless you separately enable the discoverability setting in the Professional Profile editor. Enabling discoverability is an affirmative opt-in step that is distinct from publishing the profile. You can disable it at any time.

When a Procurement Partner enables discoverability on a Published profile, a public profile page is created that displays the following information: name, job title, professional role, headline, coverage area, territory states, medical specialties, certifications, and any affiliations you have marked for public display. Your email address and phone number are never displayed on the public profile page.

For Solution Providers (seller-side users): a Published Professional Profile is included in the Platform’s professional directory and discovery features, representing the individual in connection with the companies they are affiliated with.

Search engine indexing. When a Professional Profile is published and discoverable, the profile page is included in the Platform’s sitemap and may be crawled and indexed by public search engines. The publicly displayed fields described above—not your email address, phone number or private account data—can then appear in search results and may be retained in search-engine caches outside DevicePath’s direct control.

If you disable discoverability or delete your Professional Profile, your page will be removed from the Platform. Search engines and other third parties that previously crawled or indexed your public page may retain copies for an additional period. Removal from third-party caches and search indexes is controlled by those third parties, not by DevicePath. Submitting removal requests directly to search engines may accelerate the process.

Company affiliations

A Procurement Partner or Solution Provider may request an affiliation between their Professional Profile and a Company Listing. The request message and the requester’s identity are shared with the Company to allow it to approve or deny the request. An approved affiliation is visible in the professional’s profile editor. It appears on the public profile page only if the professional has enabled it for public display. DevicePath does not independently verify employment status, purchasing authority, representation authority or credentials as part of the affiliation process.

Profile view tracking

When a signed-in user views a Solution Provider's or Procurement Organization's public company profile page, we record that visit. Company owners do not receive a record when viewing their own listing.

We use this two ways. An aggregate view count reflects total visits from signed-in and signed-out users alike and does not identify anyone. Separately, Solution Provider accounts currently see a list of signed-in visitors from the trailing 30 days — each visitor's name, organization and job title, as recorded on their account, along with their most recent visit date. Signed-out visits are never identified. Procurement Organization listings accumulate the same underlying visit records, but do not yet have a dashboard view of identified visitors.

Business inquiries

When you submit a business inquiry to a Company Listing, the inquiry—including your name, organization, contact information and message—is shared with the company you contacted so they can respond. Inquiries generate an email notification to the receiving company. Inquiry records are retained in association with both the submitting account and the receiving company’s account. Access controls restrict inquiry records to the buyer who submitted them and the company that received them. Inquiries are directed at Company Listings and are a distinct mechanism from Introduction Requests.

Introduction requests and contact exchange

Introduction Requests are separate from business inquiries. A Solution Provider may send an Introduction Request to a discoverable Procurement Partner. The request message and the requester’s identity (name and company) are shared with the Procurement Partner so they can evaluate and respond to the request. Submitting an Introduction Request does not itself release either party’s email address or phone number.

When the Procurement Partner affirmatively accepts an Introduction Request, the Platform releases to each party the other party’s name, company name, email address and phone number (if the other party has provided one). This contact exchange does not release passwords, payment information, inquiry history or any other account data.

Contact information received through an accepted introduction may be used for the professional purpose of the introduction and for follow-on professional communications reasonably arising from it. It may not be used to add the other party to bulk marketing lists, email broadcasts or advertising campaigns without separate consent from that party; to sell, share, resell, trade, compile or distribute that contact information to any third party; or to conduct abusive, harassing or repetitive unsolicited outreach unrelated to the introduction. This restriction applies to both parties. See also Terms of Service Section 11.7.

Introduction records—the request, the decision and the timestamp—are retained in association with both parties’ accounts and are accessible to DevicePath administrators for moderation and abuse-prevention purposes.

Cookies, analytics and advertising technology

We use strictly necessary cookies and local browser storage to keep you signed in. We use the Meta pixel across the site to measure traffic and the effectiveness of our marketing, which allows Meta to receive information about pages you view on DevicePath Network and to set or read its own cookies. Meta’s use of that information is governed by its own policies.

If you use the “Schedule a Conversation” button, we embed Cal.com’s scheduling widget directly on the page. Cal.com processes the name, email address and any other information you provide in order to book the call, and may set its own cookies as part of operating the scheduling widget. Cal.com’s use of that information is governed by its own policies.

Service providers

We rely on third-party providers to operate the platform, including hosting and database infrastructure, authentication (including Google sign-in), email delivery, scheduling, analytics and advertising technology, and AI providers used to draft or summarize company listing information from public websites. These providers process information on our behalf or under their own terms as applicable. Standard server and security logs are generated as part of hosting.

Patient information

DevicePath Network is a business-to-business platform. Do not submit protected health information or patient-identifiable information. DevicePath Network is not designed or offered as a patient-record system, we do not describe it as HIPAA compliant, and ordinary use of the platform is not intended to involve protected health information. Using the platform does not create a Business Associate relationship or a Business Associate Agreement.

Your choices

You can update the information in your account, company profile or Professional Profile at any time through your account settings and profile editors. You can set your Professional Profile to Draft or Hidden to remove it from public view on the Platform without deleting it. Procurement Partners can disable discoverability at any time to prevent new Introduction Requests and remove the public profile page from the Platform.

You can delete your account through account settings. Deletion removes your account access, unpublishes Company Listings you control and removes your Professional Profile from the Platform. It does not immediately remove copies of your public profile that search engines or other third parties have already indexed or cached. Introduction records, inquiry records, affiliation records, notification records and other system records are not immediately erased on deletion and may be retained as described below.

Data protection and retention

We do not sell personal information. Access controls restrict inquiry records to the buyer who submitted them and the company that received them. Introduction records are restricted to the parties to the introduction and to DevicePath administrators for moderation purposes. If you delete your account, your access ends and listings you control are unpublished; immediate erasure of every copy is not possible. Some information may remain for a reasonable period in backups, audit logs, security records, fraud-prevention records, legal-compliance records, dispute records and records we need to enforce our agreements, subject to applicable law and our actual retention practices. We do not retain that information indefinitely where we no longer have a legitimate need for it.

Contact

Questions about this policy? Reach us through the contact page and we will respond promptly. See also our Terms of Service.