Orva Product: End User License Agreement

Effective Date: April 22, 2025
Last Updated: May 20, 2025

This End User License Agreement (“EULA”) governs your access to and use of Orva, a perioperative voice assistant platform developed by RAIN Technology, Inc. (for U.S. users) and RAIN Technology ME LTD (for UAE users), collectively referred to as “RAIN,” “we,” “us,” or “our.”

By accessing or using the Orva platform, you (“User”) agree to comply with the terms and conditions applicable to your jurisdiction.

Regional Applicability

Users are subject to the version of this EULA corresponding to their jurisdiction:

  • UAE-based users: Governed by UAE EULA, UAE Federal Law No. 45 of 2021, ADHICS, and UAE data localization laws.

  • U.S.-based users: Governed by U.S. EULA, HIPAA, and applicable state/federal data privacy laws.

Key Definitions

  • Voice Data: Audio recordings, commands, or speech interactions captured by Orva, including any associated metadata (e.g., timestamps, device ID, user ID).

  • Personal Data: Any data identifying or relating to an identifiable individual, including medical identifiers, voiceprints, or timestamps linked to care.

  • De-identification: A data processing method that removes identifiers in compliance with HIPAA or UAE PDPL, rendering data non-attributable to individuals.

  • PHI (Protected Health Information): Health-related personal data as defined by HIPAA or equivalent local law.

  • EHR (Electronic Health Record): A digital clinical documentation system that may be integrated with Orva for workflow automation.

  • Consent: Voluntary agreement by the User or healthcare entity to allow data collection and processing for defined purposes.

EULA — Orva (UAE Version)

Applies to users located in the United Arab Emirates

1. Introduction

This End User License Agreement (“EULA”) is a binding legal agreement between you (“User,” “you,” or “your”) and RAIN Technology ME LTD, a company organized and existing under the laws of the United Arab Emirates, with its principal office located at Level 14, Al Sarab Tower, ADGM Square, Al Maryah Island, Abu Dhabi, UAE (“RAIN Technology,” “we,” “our,” or “us”). This EULA governs your access to and use of Orva, a clinical-grade, voice-activated software platform designed to operate on smart healthcare devices, including but not limited to Android tablets, wearable headsets, and clinical display TVs, within licensed surgical and procedural healthcare environments in the UAE.

By installing, accessing, or using the Orva software (“Software”), you agree to be legally bound by the terms of this EULA, in addition to all applicable terms outlined in the Orva Terms of Service (ToS) and Privacy Policy. If you do not agree to all the terms of this EULA, you are not authorized to access or use the Orva Software, and you must cease use and uninstall it immediately.

This Software is expressly licensed—not sold—and is made available exclusively for institutional clinical use by authorized healthcare providers and personnel. It may only be used in compliance with the laws and data protection frameworks of the United Arab Emirates, including the Abu Dhabi Healthcare Information and Cyber Security Standard (ADHICS v2), UAE Federal Decree Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), and other regulations set forth by the Department of Health – Abu Dhabi (DOH) and the Ministry of Health and Prevention (MOHAP).

RAIN Technology ME LTD retains all ownership, intellectual property rights, and proprietary interests in the Orva Software. This EULA grants you a limited, non-exclusive, non-transferable, and revocable license to use the Software solely for clinical and healthcare operational purposes, subject to the restrictions outlined herein. Any use of the Software outside the authorized scope, including commercial exploitation, reverse engineering, or use in non-clinical environments, is strictly prohibited and may constitute a violation of civil or criminal law.

By accepting this EULA, you represent and warrant that you are an authorized healthcare provider, administrator, or user operating under the authority of a licensed UAE healthcare facility and that you will use the Software solely within the bounds of clinical and regulatory guidelines.

2. Scope of License

Subject to your continued compliance with this EULA and all applicable laws and regulations, RAIN Technology ME LTD hereby grants you a limited, non-exclusive, non-transferable, non-sublicensable, and revocable license to install, access, and use the Orva Software solely for its intended clinical and operational purposes within a licensed healthcare institution operating under the jurisdiction of the United Arab Emirates.

This license is expressly conditioned upon the following limitations:

  • Institutional Use Only: The Software may only be used on devices owned or managed by your licensed healthcare facility. Personal or consumer use is strictly prohibited.
  • Regulatory Compliance: Use of the Software must fully comply with all applicable UAE laws and regulations, including but not limited to the Abu Dhabi Department of Health (DoH) requirements, the Abu Dhabi Healthcare Information and Cyber Security (ADHICS v2) standard, and the UAE Personal Data Protection Law (Federal Decree Law No. 45 of 2021).
  • Clinical and Operational Purpose: The Software is licensed exclusively for healthcare-related use cases, such as intraoperative workflow support, clinical documentation, and analytics for improving care quality and efficiency. Any non-clinical or commercial use of the Software is unauthorized.
  • No Redistribution or Derivative Use: You may not copy, distribute, sublicense, rent, lease, or make the Software available to third parties outside your organization.
  • Prohibited Activities: You are expressly forbidden from attempting to reverse engineer, decompile, disassemble, modify, adapt, translate, or create derivative works based on the Software, its components, or underlying code. Any such actions are considered a breach of this agreement and may result in legal action and license termination.

RAIN Technology ME LTD reserves all rights not expressly granted to you under this EULA. No license or right is granted to use RAIN’s trademarks, trade secrets, patents, or other intellectual property except as explicitly permitted herein.

3. Voice & Audio Data Collection

As part of its core functionality, Orva may capture voice inputs and user commands initiated by a predefined wake-word trigger (“Hey Orva”). This voice-enabled interaction is designed to support clinical workflow automation, reduce manual documentation burden, and facilitate safe, hands-free operation in surgical environments.

Purposes of Collection

  • Voice data collected after wake-word activation may be used for the following limited and lawful purposes:
  • Improving System Accuracy: To enhance Orva’s speech recognition engine and improve real-time response reliability across varied clinical scenarios.
  • Accent Adaptation: To increase comprehension and transcription accuracy for regional English dialects and healthcare terminology commonly used in UAE settings.
  • Feature Optimization: To ensure the platform delivers relevant, context-aware responses that align with surgical workflows and patient safety priorities.

Privacy & Safeguards

All voice samples used for system learning are:

  • Captured only after wake-word activation, ensuring user intent and minimizing incidental collection.
  • Irreversibly de-identified before being used for AI model training or performance testing. Once de-identified, voice data cannot be linked back to any individual, user account, or healthcare encounter.
  • Encrypted at rest using AES-256 encryption and stored in secure, UAE-based environments in accordance with ADHICS standards.
  • Access-controlled using strict, role-based permissions limited to authorized RAIN Technology ME LTD personnel.
  • Audited through periodic internal reviews and third-party assessments to validate compliance with the UAE Personal Data Protection Law (PDPL) and Abu Dhabi Healthcare Information and Cyber Security Standard (ADHICS v2).

No voice data—whether raw or de-identified—is used for advertising, profiling, or sold to external entities under any circumstances.

4. User Consent and Data Use

RAIN Technology ME LTD processes personal and clinical data within the Orva platform in accordance with the UAE Personal Data Protection Law (Federal Decree Law No. 45 of 2021) (“PDPL”), the Abu Dhabi Healthcare Information and Cyber Security Standard (ADHICS v2), and relevant guidance issued by the Department of Health – Abu Dhabi (DoH).

Primary Lawful Basis – Direct Clinical Use

Pursuant to PDPL Article 4(1)(b), the collection and processing of personal data—including voice recordings and session metadata—is considered lawful when necessary for the provision of healthcare or treatment, without requiring additional patient consent. Orva’s use in surgical environments for real-time documentation, workflow support, and clinical safety alerts falls under this provision.

Secondary Uses – Model Training & Analytics

For purposes beyond direct care, such as AI model refinement, feature development, or clinical workflow benchmarking, Orva relies on one of the following lawful bases:

  • PDPL Article 4(1)(a) – Explicit consent: Consent is obtained from patients during the facility’s general consent process, and such consent must be documented by the healthcare institution.
  • PDPL Article 4(11) – Anonymization: If personal identifiers are irreversibly de-identified, the processing may occur without consent, provided the data cannot be re-associated with any individual.

RAIN Technology ensures that all data used for secondary purposes undergoes rigorous de-identification processes in accordance with ADHICS and industry best practices.

5. Messaging & Attribution

To ensure operational integrity, clinical accountability, and accurate workflow traceability, Orva systematically logs and attributes all user interactions within the platform—including but not limited to voice commands, button presses, navigation events, and session activities—to the authenticated user account performing the action.

These logs are:

  • Tied to named user accounts provisioned through the Orva Admin Panel and authenticated under role-based access controls
  • Time-stamped and session-bound, ensuring traceability of events within each intraoperative interaction
  • Used to support operational coordination, such as real-time case management, room transitions, or handoffs between clinical staff
  • Instrumental for auditing, incident reconstruction, and quality assurance, especially in environments where multiple users may interact with a single shared device or room-based deployment

All activity logs are classified as Confidential under Orva’s data management policy and are protected using industry-standard encryption and access control mechanisms. Logs are retained in accordance with the healthcare facility’s data retention policy and are not used for performance evaluation or disciplinary purposes unless directed by the institution or required under applicable UAE law.

Orva’s attribution framework aligns with ADHICS v2 requirements for auditability and PDPL mandates for lawful and transparent processing of user-related data in healthcare systems.

6. User Rights under UAE Law

In accordance with the UAE Personal Data Protection Law (Federal Decree Law No. 45 of 2021) and ADHICS v2, individuals whose data is processed via the Orva platform are entitled to exercise specific rights concerning their personal and health-related data. These rights may be subject to institutional policies, medical record retention requirements, and applicable healthcare regulations.

Subject to the clinical context and lawful limitations, you may:

  • Request access to your personal data that has been collected, including voice interactions, session metadata, and account-related activity logs
  • Request rectification of inaccurate or outdated personal data stored by Orva or request erasure of data where appropriate and permissible by law
  • Withdraw consent to the use of your voice data for non-essential, non-clinical purposes such as product improvement or AI model training, provided such data has not already been irreversibly de-identified
  • Object to processing, where the processing is based solely on legitimate interest and does not impact the delivery of medical care
  • Request restriction of processing in situations where a dispute over data accuracy or lawful use exists

How to Submit a Request

Data subject rights requests should be submitted:

  • Through your healthcare provider, which acts as the data controller for all Orva-related patient data, or
  • Directly to RAIN Technology ME LTD by emailing: hello@orvahealth.com

RAIN will acknowledge receipt of your request within five (5) business days and, where applicable, will respond in full within thirty (30) calendar days, in accordance with Article 14 of the UAE PDPL. In certain complex cases or where verification is required, the timeline may be extended by an additional thirty (30) days with prior notice.

RAIN Technology ME LTD reserves the right to request additional information to confirm the identity of the requester or to verify institutional authorization, where applicable.

7. Data Security and Compliance

RAIN Technology ME LTD is committed to safeguarding all personal, clinical, and operational data processed through the Orva platform by implementing a comprehensive, risk-based information security program. This program is designed to meet and exceed the expectations of UAE healthcare regulators and international security frameworks.

Compliance Frameworks

RAIN maintains active compliance with the following standards and regulations:

  • ADHICS v2 – The Abu Dhabi Healthcare Information and Cyber Security Standard, which outlines mandatory security and privacy controls for healthcare technology used within Abu Dhabi, including access management, encryption, monitoring, and incident response.
  • UAE PDPL – RAIN complies with the UAE Personal Data Protection Law regarding data processing, retention, breach notification, and data subject rights.
  • ISO/IEC 27001:2022 – RAIN’s internal security program is certified against the international standard for information security management systems (ISMS), reflecting a systematic approach to managing sensitive data.

Technical and Administrative Safeguards

RAIN implements the following security measures throughout the Orva platform:

  • Encryption of all data at rest and in transit using AES-256 and TLS 1.2 or higher
  • Strict internal access controls, including role-based access, least-privilege enforcement, session monitoring, and routine access reviews
  • Multi-factor authentication (MFA) for privileged access to production environments
  • Regular vulnerability scanning, penetration testing, and security patch management
  • Secure development lifecycle (SDLC) practices to ensure application-level security from design to deployment
  • Data breach response procedures that align with ADHICS and PDPL, including investigation protocols, forensic logging, impact assessments, and regulatory notifications where applicable

All security controls are reviewed at least annually, and RAIN conducts internal audits and third-party assessments to validate ongoing compliance with security standards and legal obligations.

8. Privacy Policy

This EULA incorporates the Orva Privacy Policy (UAE version), which provides detailed information on:

  • Purpose of data collection

  • Retention periods

  • Data controller responsibilities

9. System Integration

Orva may be configured to interface with hospital systems, including EHRs and scheduling tools. Integration will be scoped to the minimum necessary access and adhere to UAE-specific regulatory requirements.

10. Termination

RAIN Technology ME LTD reserves the right to suspend or terminate this End User License Agreement (EULA) and your associated access to the Orva Software at any time, with or without prior notice, under any of the following conditions:

  • Breach of Terms: You violate or fail to comply with any provision of this EULA, including misuse of the Software, unauthorized data access, or non-compliance with institutional security policies.
  • Institutional Termination: The contractual relationship between RAIN Technology ME LTD and your healthcare institution (the data controller or licensee) is terminated, suspended, or expires.
  • Legal or Regulatory Mandate: Applicable UAE laws, governmental orders, or regulatory directives (including but not limited to PDPL, ADHICS, or MOHAP rulings) require revocation, suspension, or modification of license access.
  • Security Risk: Continued use of the Software poses, in RAIN’s reasonable judgment, a material risk to patient safety, data integrity, system security, or public health.

Upon termination, the following terms shall immediately apply:

  • All rights granted to the user under this EULA shall cease
  • You must immediately discontinue use of the Software and uninstall it from any authorized devices
  • RAIN may remotely disable or restrict access to the Software without liability
  • Any ongoing obligations related to data confidentiality, intellectual property, and lawful use shall survive termination

RAIN Technology ME LTD is not liable for any disruption to clinical workflows or operations resulting from license termination when such termination is the result of breach, institutional disengagement, or legal mandate.

12. Governing Law

This EULA is governed by the laws of the United Arab Emirates, and disputes shall be resolved through the courts of Abu Dhabi.

13. Contact

RAIN Technology ME LTD
Level 14, Al Sarab Tower
ADGM Square, Al Maryah Island
Abu Dhabi, UAE
Email: hello@orvahealth.com

EULA — Orva (U.S. Version)

Applies to users located in the United States

1. Introduction

This End User License Agreement (“EULA”) is a binding legal agreement between you (“User,” “you,” or “your”) and RAIN Technology, Inc., a Delaware corporation with its principal office located at 5526 W 13400 S #60, Herriman, UT 84096 (“RAIN,” “we,” “our,” or “us”). This EULA governs your installation, access, and use of Orva, a voice-driven software platform designed to support surgical and clinical workflows through hands-free interaction.

Orva is intended exclusively for professional use by healthcare providers, administrators, and clinical staff operating within licensed healthcare facilities in the United States. The platform is delivered through Android-based devices, including tablets, smart TVs, and wearable headsets, and is designed to assist with intraoperative workflow management, documentation, and patient safety coordination.

By installing, accessing, or using the Orva software (“Software”), you acknowledge that you have read, understood, and agree to be legally bound by the terms of this EULA, along with the Orva Terms of Service (ToS), Privacy Policy, and any applicable Business Associate Agreement (BAA) between RAIN and your healthcare organization. If you do not agree to the terms of this EULA, you are not authorized to use the Software, and you must immediately uninstall and discontinue all use.

This Software is licensed, not sold, and remains the intellectual property of RAIN Technology, Inc. Your license is limited, non-exclusive, non-transferable, non-sublicensable, and revocable, and it permits use of the Software solely in accordance with this EULA and applicable U.S. federal and state privacy and healthcare laws, including:

Health Insurance Portability and Accountability Act of 1996 (HIPAA)

Health Information Technology for Economic and Clinical Health (HITECH) Act

California Consumer Privacy Act (CCPA/CPRA) and similar state-specific laws, where applicable

The Orva platform is not a medical device, diagnostic system, or substitute for professional medical judgment. You acknowledge and agree that Orva is a clinical support tool intended to assist—not replace—human decision-making in patient care.

2. Scope of License

Subject to your continued compliance with this EULA, the Orva Terms of Service, applicable Business Associate Agreements (BAAs), and all relevant federal and state laws, RAIN Technology, Inc. hereby grants you a limited, non-exclusive, non-transferable, non-sublicensable, and revocable license to access and use the Orva Software solely for internal clinical and operational purposes within your licensed healthcare organization in the United States.

This license is conditioned on the following limitations and obligations:

  • Institutional Use Only: The Software may only be used by authorized personnel within a licensed healthcare provider organization and may not be used for personal, consumer, or non-clinical purposes.
  • Regulatory Compliance: Use of the Software must comply with all applicable U.S. laws, including but not limited to:
    • HIPAA (Health Insurance Portability and Accountability Act of 1996)
    • HITECH Act (Health Information Technology for Economic and Clinical Health Act)
    • State-specific privacy laws, including the California Consumer Privacy Act (CCPA/CPRA), where applicable
  • Permitted Use: The Software is licensed solely to support authorized clinical workflows, surgical documentation, and healthcare operations.
  • Prohibited Use: You may not:
    • Copy, distribute, sublicense, sell, or commercially exploit the Software
    • Modify, reverse engineer, decompile, or disassemble any part of the Software
    • Use the Software outside the scope defined in this EULA or any applicable BAA
  • No Ownership Transfer: This license does not convey to you any ownership rights in the Software or related intellectual property. All rights not expressly granted herein are reserved by RAIN Technology, Inc.

RAIN may monitor system usage for compliance and security purposes and reserves the right to suspend or terminate access if the Software is used outside of these terms or in violation of any applicable law or agreement.

3. Voice & Audio Data Collection

As part of its core functionality, Orva captures voice inputs and spoken commands triggered by a designated wake word (e.g., “Hey Orva”). This feature is designed to enable hands-free interaction during surgical procedures and clinical workflows, enhancing efficiency, safety, and documentation accuracy.

Purposes of Collection

  • Voice and audio interactions may be collected and processed for the following lawful and operational purposes:
  • Improving Natural Language Understanding (NLU): To enhance the system’s ability to interpret clinical language and respond accurately across diverse accents and medical contexts.
  • Advancing Workflow Safety and Precision: To ensure that Orva reliably executes voice-activated tasks within time-sensitive and high-risk clinical environments.
  • Supporting Operational Reliability: To reduce transcription errors, minimize misinterpretations, and streamline surgical documentation through contextual audio parsing.

Privacy and Security Safeguards

RAIN Technology, Inc. employs strict safeguards to ensure the secure and compliant processing of voice data:

  • Voice samples are only captured post wake-word activation, ensuring user intent and minimizing inadvertent collection.
  • No raw voice data is used for training until it has been irreversibly de-identified, in accordance with HIPAA de-identification standards (45 CFR § 164.514(b)).
  • De-identified data is encrypted at rest using AES-256 encryption and stored in HIPAA-compliant environments.
  • Access is limited to designated RAIN engineers and machine learning specialists, governed by strict role-based access controls and documented access logs.
  • All AI training activities are logged, and RAIN undergoes periodic third-party audits to validate compliance with HIPAA and security best practices.

RAIN does not use voice data for advertising, commercial profiling, or any non-clinical purpose. Data is never sold or disclosed to third parties unless required by law or explicitly authorized under a Business Associate Agreement.

4. User Consent & Data Use

By accessing and using the Orva platform, you acknowledge and consent to the collection, processing, and secure storage of personal data—including voice interactions and system metadata—as required for clinical operations, product functionality, and permitted secondary uses under applicable U.S. law.

Minimum Necessary Standard

All collection and handling of Protected Health Information (PHI) by RAIN Technology, Inc. adheres strictly to the “minimum necessary” standard as outlined in the HIPAA Privacy Rule (45 CFR §164.502(b)). PHI is accessed, used, and disclosed only to the extent necessary to fulfill the intended clinical or operational purpose.

  • Any use of PHI for non-essential activities—such as data analytics, benchmarking, or natural language model training—occurs only after the data has been irreversibly de-identified in accordance with HIPAA de-identification standards, or

  • With explicit authorization from the healthcare provider, as defined under a valid and executed Business Associate Agreement (BAA).

Scope of User Consent

By using the Orva Software, you expressly consent to the following:

  • Capture and processing of voice commands and clinical interactions initiated by wake-word activation for the purpose of enabling product functionality and improving voice recognition accuracy.

  • Secure storage and transmission of PHI and session metadata using HIPAA-compliant infrastructure, including end-to-end encryption (TLS 1.2/1.3 in transit, AES-256 at rest), access control enforcement, and continuous security monitoring.

  • International data transfers, where applicable, may only occur when:

    • Data has been fully anonymized and no longer constitutes PHI under HIPAA, or

    • Such transfers are governed by valid contractual mechanisms, including Standard Contractual Clauses (SCCs), data processing agreements, or healthcare provider-approved transfer arrangements.

RAIN does not use, disclose, or retain data beyond what is required for the delivery and support of the Orva platform, except as otherwise permitted by law or contractual agreement.

5. Attribution & Operational Logging

To promote clinical accountability, support operational transparency, and ensure compliance with healthcare data regulations, Orva automatically logs and attributes all user interactions within the platform to the authenticated account associated with the session.

Scope of Logging

The following types of activity are logged by the system:

  • Voice commands and interactions initiated via wake-word activation

  • Button presses, screen interactions, and feature usage

  • Session metadata including device ID, user role, timestamp, and room ID

  • Configuration changes, access events, and user logins/logouts

Each recorded action is tied to the verified user account authenticated through the Orva Admin Panel. Logs are tamper-resistant and include time-stamped entries for auditability and historical traceability.

Retention & Access

  • Audit logs are retained for a minimum of six (6) years in accordance with the HIPAA Security Rule (45 CFR §164.316(b)(2)(i)), which governs documentation and audit trail retention in healthcare systems.

  • Logs are stored in encrypted, access-controlled environments and are made accessible to the healthcare provider upon request, including for compliance audits, investigations, or incident response.

  • Access to operational logs by RAIN Technology, Inc. personnel is restricted to authorized engineering or compliance staff under documented role-based access controls.

RAIN does not use operational logs for employee or clinician performance evaluation. Logs are strictly maintained to uphold the integrity of the system, ensure accurate attribution, and support clinical governance.

6. Your Rights Under U.S. Law

As a user of the Orva platform or a data subject whose information may be processed through clinical use of the Software, you are entitled to certain rights under applicable U.S. data protection laws, including the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and state-level laws such as the California Consumer Privacy Act (CCPA/CPRA), where applicable.

Subject to verification of identity, institutional policy, and applicable exceptions under law, you may exercise the following rights:

Access

You may request a copy of your personal data, including PHI or system-attributed activity, that has been collected or maintained through Orva.

Correction

You may request that inaccurate or incomplete personal data be corrected, in accordance with HIPAA’s Right to Amend under 45 CFR §164.526.

Withdrawal of Consent

You may withdraw your consent for the use of your voice data for non-essential purposes, such as system training or enhancement, provided that the data has not already been de-identified or is not required for clinical or operational integrity.

Deletion (Where Applicable)

You may request deletion of personal data not required to be retained under HIPAA or other regulatory obligations. Deletion requests are evaluated on a case-by-case basis and must not conflict with medical record retention or legal hold requirements.

How to Submit a Request

Requests should be submitted through one of the following channels:

  • Via your healthcare provider or institution, which serves as the primary data controller under HIPAA, or

  • Directly to RAIN Technology, Inc. at hello@orvahealth.com

All requests will be:

  • Acknowledged within five (5) business days, and

  • Fulfilled within thirty (30) calendar days, unless an extension is lawfully required or justified under HIPAA or CCPA guidelines

RAIN Technology, Inc. reserves the right to request additional information to verify your identity or authority before processing any request and may refer certain requests to your healthcare provider for fulfillment where appropriate.

7. Security & Compliance

RAIN Technology, Inc. implements a multi-layered security program to ensure the confidentiality, integrity, and availability of all personal and protected health information (PHI) processed by the Orva platform. This program aligns with U.S. healthcare regulatory requirements and internationally recognized security standards.

Regulatory Compliance

RAIN complies with the following frameworks:

  • HIPAA Security Rule (45 CFR §§164.302–318) – Security protocols are designed to safeguard electronic PHI (ePHI) through administrative, physical, and technical controls as required under HIPAA.

  • HITECH Act – Breach notification and enhanced privacy enforcement mechanisms are incorporated into our incident response framework.

  • ISO/IEC 27001:2013 – RAIN’s internal information security management system (ISMS) is certified against this global standard, reflecting a risk-based, continuous-improvement approach to data protection.

Security Measures

RAIN applies the following safeguards to protect Orva data and infrastructure:

  • End-to-end encryption of all PHI, using AES-256 at rest and TLS 1.2 or higher in transit

  • Role-based access controls with session logging and multifactor authentication for sensitive operations

  • Continuous vulnerability scanning and penetration testing, along with patch management and secure configuration baselines

  • Network segmentation and secure cloud hosting in HIPAA-compliant environments with regular auditing and monitoring

Logging & Retention

  • Technical and audit logs (e.g., access logs, system actions, session metadata) are retained for a minimum of six (6) years, consistent with the HIPAA Security Rule’s documentation retention requirements (45 CFR §164.316(b)(2)(i)).

  • De-identified training data used for AI and natural language model enhancement is retained for up to five (5) years, unless otherwise governed by contractual or regulatory requirements.

All security controls are reviewed at least annually, and independent assessments are conducted periodically to validate effectiveness and compliance.

8. Privacy Policy

This EULA incorporates the Orva Privacy Policy (U.S. version). Users are encouraged to review it for full transparency on data handling, retention, and transfer practices.

9. System Integration

Orva may interface with third-party applications (e.g., EHR platforms), but only under HIPAA-compliant architecture and Business Associate Agreements (BAAs), as required.

10. Termination

RAIN Technology, Inc. reserves the right to suspend or terminate your license to use the Orva Software at any time, with or without prior notice, under any of the following conditions:

  • Breach of Agreement: You violate any term of this EULA, the associated Terms of Service, or any relevant data protection law, including but not limited to unauthorized access, misuse of data, or circumvention of security controls.

  • Institutional Disengagement: The healthcare provider or institution with which your user account is associated terminates, lapses, or opts not to renew its Orva subscription or Business Associate Agreement (BAA) with RAIN Technology, Inc.

  • Legal or Regulatory Requirement: A court order, regulatory directive, or applicable law mandates the suspension or revocation of software access, such as in the case of a data breach investigation, sanction, or statutory change.

Effect of Termination

Upon termination:

  • All rights granted under this license will immediately cease.

  • You must discontinue all use of the Software, and RAIN may disable access remotely.

  • Any associated data, access logs, or account metadata may continue to be retained in accordance with HIPAA, HITECH, or other applicable legal retention obligations.

  • Terms related to data security, confidentiality, limitations of liability, and compliance will survive termination of this agreement.

RAIN Technology, Inc. will not be liable for any loss of access, operational disruption, or data resulting from the lawful enforcement of termination provisions as defined herein.

12. Governing Law

This End User License Agreement (EULA) shall be governed by and construed in accordance with the laws of the State of Delaware, United States of America, without regard to its conflict-of-law principles or provisions that would result in the application of the laws of another jurisdiction.

Dispute Resolution Process

In the event of any dispute, claim, or controversy arising out of or relating to this EULA, the Orva Software, or your use thereof, the parties agree to the following dispute resolution process:

  1. Good-Faith Negotiation – The parties shall attempt in good faith to resolve any such dispute promptly through informal discussions between authorized representatives.

  2. Non-Binding Mediation – If the dispute is not resolved within thirty (30) days, the matter shall be submitted to non-binding mediation, to be conducted by a mutually agreed-upon mediator located in Wilmington, Delaware.

  3. Binding Arbitration – If mediation fails to resolve the matter, the dispute shall be finally resolved by binding arbitration administered by the American Arbitration Association (AAA) in accordance with its Commercial Arbitration Rules, with proceedings held in Wilmington, Delaware. The arbitration shall be conducted before a single arbitrator and judgment on the award rendered by the arbitrator may be entered in any court of competent jurisdiction.

Exclusions

Notwithstanding the foregoing, either party may seek:

  • Temporary or preliminary injunctive relief in a court of competent jurisdiction to prevent unauthorized use or disclosure of confidential information or intellectual property

  • Enforcement of a settlement agreement or arbitration award

Each party shall bear its own legal fees and costs unless otherwise determined by the arbitrator or agreed in writing.

13. Contact

RAIN Technology, Inc.
5526 W 13400 S #60
Herriman, UT 84096
Email: hello@orvahealth.com