DRAFT — requires legal review before publication

Privacy policy

Effective [EFFECTIVE DATE] · Last updated [LAST UPDATED DATE] · Version 0.1 (draft)

This describes how ClientCentric handles information collected through the ClientCentric public website and interactive demo. It is not a HIPAA Notice of Privacy Practices.

1. Scope

This policy covers the ClientCentric public website, the interactive public demo, the book-a-walkthrough form, and communications with us.

It does not cover an agency's live ClientCentric portal. Information held there is processed for that agency under its customer agreement, data-processing terms, and Business Associate Agreement where applicable. If you are a client, representative or employee of an agency that uses ClientCentric, that agency is the right first point of contact about your records.

2. Information collected through the public website

If you submit the walkthrough form we collect what you provide:

  • Your name and work email
  • Phone number, if you give one
  • Agency name, and website if you give one
  • Approximate number of active clients and staff
  • Services provided, and current systems if you tell us
  • Any operational challenge you choose to describe
  • Preferred contact time, if you give one
  • Your confirmation that we may contact you
  • Subsequent communications with us

3. Information collected automatically

Our hosting infrastructure records ordinary technical information as part of serving and securing the site — including IP address, browser and device information, and request logs. These are used to operate the service, diagnose faults and prevent abuse.

[APPROVED ANALYTICS PROVIDERS] — analytics are not enabled until a provider is approved. When one is, it will be privacy-preserving, it will be named here, and it will be disabled on demo routes.

4. What the public demo does not collect

The interactive demo holds no real information and sends nothing anywhere. Each statement below is a property of how it is built, not a policy applied on top of it:

  • Every client, staff member, visit, note and document in the demo is fictional
  • Demo changes exist only in your browser's memory and are never sent to a server
  • Refreshing the page discards them and restores the original data
  • No demo action sends email, SMS, an invitation, or a signature request
  • No demo action contacts HHAeXchange or any other external system
  • Your real location is never requested; clocking is simulated and labelled as such
  • Portal Help answers from a table shipped with the page — what you type there does not leave your browser, is not logged, and is not captured by analytics
  • No demo record is written to local storage or cookies

5. Sources of information

Directly from you, when you submit the form or contact us. Automatically from your browser, as described above. From a scheduling provider, if and when one is configured — [APPROVED SUBPROCESSORS].

6. How information is used

To operate the website and demo; to respond to walkthrough requests and arrange them; to provide information you ask for; to prevent abuse and secure the service; to diagnose technical problems; to improve public usability; and to meet legal obligations.

7. Cookies and analytics

The site uses one browser storage value on the demo: which view — administrator or staff — you selected. It is stored per browser tab, holds nothing about you, and exists so that refreshing while exploring the staff view does not silently switch you to an administrator.

We do not use advertising pixels, cross-site behavioural advertising, session replay, keystroke recording, or form-content capture. We do not capture the text of Portal Help questions.

8. Disclosure and service providers

We do not sell personal information, and we do not use information from the public site for targeted advertising.

Information is necessarily processed by the infrastructure providers that host and secure the site, and by an email provider when we reply to you. Categories: hosting, email delivery, scheduling, security, and professional advisers. Named providers: [APPROVED SUBPROCESSORS]. We may also disclose information where required by law, or in connection with a business transaction.

9. Customer agency data and protected health information

Agencies using ClientCentric control their own records and user relationships. We process that data according to the agreements in place with them, and PHI-related responsibilities are additionally governed by applicable Business Associate Agreements.

We do not use customer protected health information for advertising, and we do not train public AI models on it.

If you want access to, or correction of, records an agency holds about you, contact that agency — subject to the governing agreement and applicable law. This policy is not a substitute for an agency's own privacy notices or legal obligations, and it is not a HIPAA Notice of Privacy Practices.

10. Retention

Walkthrough enquiries are retained for [RETENTION PERIOD — TO BE SET WITH COUNSEL] and then deleted or anonymised. Security and request logs are retained for [LOG RETENTION PERIOD — TO BE SET WITH COUNSEL].

Demo state is not retained at all: it exists in your browser's memory and ends when you refresh or close the tab.

Retention of records inside a customer agency's portal is governed separately by that agency's agreement, its policies and applicable law — including Minnesota's five-year retention requirement for licensed providers.

11. Security

We use layered controls: access controls, multi-factor authentication for privileged access, encryption in transit, rate-limited endpoints, security logging, private file delivery, and vulnerability management. Infrastructure is BAA-backed where it processes customer data.

No internet-connected system can guarantee absolute security, and we do not claim otherwise.

12. Your privacy rights

Depending on where you live and the circumstances, you may have rights to access, correct or delete information, to obtain a copy, to appeal a decision, to opt out of marketing, and to exercise choices about cookies or analytics.

Which rights apply depends on your jurisdiction, our role in relation to the data, applicable exemptions, and the type of information involved. Minnesota's Consumer Data Privacy Act has been in effect since 31 July 2025; its applicability and exemptions are being assessed with counsel rather than assumed.

To make a request, contact contact@clientcentric.org. We may need to verify your identity.

13. Children

The public website and the business demo are not directed to children under 13. They are intended for agency owners, administrators and professionals. Access to a live client portal is handled separately through customer agreements and agency policy.

14. Where information is processed

The site and demo are hosted in the United States. [INTERNATIONAL TRANSFER LANGUAGE — only to be added if infrastructure outside the United States is actually used.]

15. Changes to this policy

We may update this policy. The effective and last-updated dates at the top change when we do, and material changes will be indicated on this page.

16. Contact

ClientCentric · contact@clientcentric.org