Privacy Policy

Last updated: September 23, 2019

KLAS Research, LLC, is referred to in this Privacy Notice as "KLAS" or by first person pronouns such as "we," "us," "our," etc.

Contact Information

KLAS will control the use of your personal data, which it collects on this website. You may contact KLAS at:

Personal Data We Collect and Purposes for which We Use It

We collect and process personal data to facilitate our legitimate business interests. These interests include providing our products and services to you, communicating additional information to you regarding our products and services, and conducting other activities associated with managing our business.

When we process your personal data to facilitate our business interests, we balance any potential impact on you (both positive and negative) and your rights under data protection laws.

You are not required to provide us with any personal data we may request. However, if the requested information is necessary for us to provide any product, service, or information requested by you, or to participate in surveys or interviews, we will be unable to fulfill your request.

The following are examples of personal data we may collect and use:

Personal data required for the provision of products and services

To provide you with information regarding our products and services and to enable you to use and procure them, we may collect personal data, including but not limited to your name, telephone number, address, and email address. If you wish to participate in our surveys, interviews, or other research initiatives, the same contact information may also be used to communicate with you in connection with those activities. Personal data collected is stored on servers located in the United States of America.

KLAS conducts two primary research initiatives:

  1. Vendor performance feedback (traditional model): Your survey responses will be aggregated with those of other survey participants and the aggregate results are shared anonymously with those who have access to KLAS’ research.
  2. Clinician user feedback (Arch Collaborative): Your survey responses will be aggregated with those of other survey participants and the aggregate results will be shared anonymously with your employer and other report recipients. If your employer has commissioned the survey, your individual (i.e., non-aggregated) survey responses will also be shared with your employer (if you choose to share such responses with your employer).

To enable you to interact with our websites and online products and services, we may also collect passwords, password hints, and similar security information needed for authentication and account access.

To enable purchases of products and services, we collect data necessary to processing payments. Such information may include a credit card number and the associated security code if that is your chosen method of payment.

We may also request and collect other data from you via forms on our websites. In each case, you will know what personal data you provide to us because you actively and voluntarily provide it.

Information collected via cookies

Our websites and services use “cookies.” Cookies are small text files that websites transfer to your computer’s hard drive. We may use cookies to measure traffic patterns, personalize content, control security, and help us make our websites more useful. The cookies we use may identify your OS version, browser, and internet specifications. You have the choice to accept cookies, reject cookies, or be notified when a site sets a cookie by configuring your browser preferences.

KLAS stores the following required cookies on a user’s machine:

.AspNetCore.Session An encrypted id required to maintain your logged in status from page to page.
KLASLoginWebUserIdCookie   An encrypted id required to maintain your logged in status from session to session.

We use tools of the following third-party vendors, who may also set cookies:

  • Google (metrics for general web-traffic analytics)

The vendors above are the only companies with whom we share information gathered from cookies. We do not use that information to market to users outside of the KLAS website. If you are uncomfortable enabling cookies on our site, you may turn them off. The cookies make the user experience more convenient but are not necessary.

Information automatically collected and stored in log files

Our websites may automatically gather and store certain information in log files, including, but not limited to, your IP Address, browser type, internet service provider, referring/exiting pages, operating system, date/time stamp, and clickstream data.

When necessary, we also use personal data to:

  • protect against, prevent, and manage the risk of exposure to fraud, legal claims, and liabilities;
  • respond to your inquiries and requests;
  • process and manage opt-out or unsubscribe requests;
  • comply with applicable laws, regulations, codes, and industry standards and practices;
  • create and send communications to you;
  • respond to subpoenas or orders of a court or government agency; and
  • establish, exercise, or defend legal claims, including, but not limited to, to protect KLAS's rights and/or property.
How We Share Personal Data

Your personal data will be accessible by our employees who require access in order to further our business interests as described above.

We may share your personal data with contracted service providers to enable them to provide our products and services to you, for customer support, marketing, technical operations, and account management purposes; and to perform other activities described in this Privacy Notice. We do not share, sell, rent, or trade any personal data with third parties for any promotional purposes unrelated to our business or to our own products and services.

Contractors and service providers are authorized to use and disclose personal data only as necessary to perform and provide the particular services for which they were engaged and only in accordance with this Privacy Notice. Examples of services which may give contractors or service providers access to personal data include:

  • hosting our websites;
  • hosting our email server;
  • processing your payments;
  • maintaining, enhancing, or adding to the functionality of our websites;
  • processing and fulfilling orders
  • collecting web analytics data; and
  • enabling us to send you email or perform other administrative services.

We may share personal data with other parties, including the following:

  • governmental authorities pursuant to applicable laws or court processes or as we reasonably deem necessary to prevent harm, financial loss, fraud, or illegal activity;
  • the successor in interest to all or a portion of our business or assets, provided that, should such a transfer occur, we will require such successor to agree in writing to use, protect, and maintain the security, integrity, and confidentiality of the transferred personal data in accordance with this Privacy Policy; and
  • others pursuant to consent obtained from you.
Criteria and Time Period for Retaining Personal Data

We retain your personal data for a reasonable period of time to fulfill the processing purposes mentioned above. We delete personal data when it is no longer necessary for such purposes.

Certain Rights Available to Persons in the European Economic Area

If you are located in the European Economic Area, you may have the following rights, which may be subject to limitation:

  • Right to access, rectify or erase your personal data;
  • Right to restrict the processing of your personal data;
  • Right to obtain copies of your personal data held by us for the purpose of transferring it to yourself or another party specified by you;
  • Right to object to the processing of your personal data; and
  • Right to not be subject to automated decision-making.

To exercise any of these rights, you may contact us as described above. Our obligations with respect to the foregoing objections and requests are governed by applicable laws and regulations.

You also have the right to lodge a complaint regarding our processing of your personal data with any applicable supervisory authority.

California Residents

Under California’s “Shine the Light” law, California residents may request certain information regarding our disclosure of personal data to third parties for their direct marketing purposes. To make such request, you may contact us as described above.

Security Measures and How We Store Personal Data

Personal data is stored on servers and systems that are owned and managed by us or by contractors engaged by us.

We maintain appropriate technical, administrative, and physical safeguards to protect personal data we receive or collect. We review, monitor, and evaluate our privacy practices and protection systems on a regular basis. Transmission of personal data is protected by SSL encryption when it is exchanged between your web browser and our websites.

Notwithstanding the foregoing measures, transmissions over the internet or a mobile network are not 100% secure, and we do not guarantee the security of transmissions. We are not responsible for any errors by individuals in submitting personal data to KLAS.

Anonymized Data

We may use, transfer, sell, and share aggregated, anonymized data, which does not include any personal data.

Survey and Interview Data

Our goal is to have longstanding relationships with healthcare professionals. KLAS reports survey and interview responses obtained from providers anonymously to ensure that they can speak freely, safely, and with candor. All reports undergo thorough screening to maintain provider anonymity. The only information publicly associated with your responses is job level and organization size.


We do not knowingly market our products or services to, and do not solicit or collect information from, children under the age of 16. We may ask users for their age to ensure that we are not collecting information from children under age 16 or to identify when additional steps may be necessary in connection with information collected from persons who have not reached the age of maturity in the jurisdiction in which they reside. If we learn that we have collected personal data from a child under age 16 without parental consent, we will delete that information. If you believe that we might have personal data from or about a child under 16, please contact us as described above.

Changes to This Privacy Policy

This Privacy Notice may be updated from time to time to remain consistent with the requirements of any applicable laws. We will post the revised version on our website and update the “last updated” date above to reflect the date of the changes.

Make a Difference

Join the KLAS Community to stand with other healthcare professionals by driving change within the industry.

Join Us