Privacy policy
Effective August 24, 2026 · Last updated August 24, 2026
This describes how ClientCentric handles information collected through the ClientCentric public website and interactive demo. It is not a HIPAA Notice of Privacy Practices.
1. Scope
This policy covers the ClientCentric public website, the interactive public demo, the book-a-walkthrough form, and communications with us.
It does not cover an agency's live ClientCentric portal. Information held there is processed for that agency under its customer agreement, data-processing terms, and Business Associate Agreement where applicable. If you are a client, representative or employee of an agency that uses ClientCentric, that agency is the right first point of contact about your records.
2. Information collected through the public website
If you submit the walkthrough form we collect what you provide:
- Your name and work email
- Phone number, if you give one
- Agency name, and website if you give one
- Approximate number of active clients and staff
- Services provided, and current systems if you tell us
- Any operational challenge you choose to describe
- Preferred contact time, if you give one
- Your confirmation that we may contact you
- Subsequent communications with us
3. Information collected automatically
Our hosting infrastructure records ordinary technical information as part of serving and securing the site — including IP address, browser and device information, and request logs. These are used to operate the service, diagnose faults and prevent abuse.
We do not use third-party analytics on this site. If we ever adopt an analytics provider, it will be privacy-preserving, it will be named in this policy before it is enabled, and it will be disabled on demo routes.
4. What the public demo does not collect
The interactive demo holds no real information and sends nothing anywhere. Each statement below is a property of how it is built, not a policy applied on top of it:
- Every client, staff member, visit, note and document in the demo is fictional
- Demo changes exist only in your browser's memory and are never sent to a server
- Refreshing the page discards them and restores the original data
- No demo action sends email, SMS, an invitation, or a signature request
- No demo action contacts HHAeXchange or any other external system
- Your real location is never requested; clocking is simulated and labelled as such
- Portal Help answers from a table shipped with the page — what you type there does not leave your browser, is not logged, and is not captured by analytics
- No demo record is written to local storage or cookies
5. Sources of information
Directly from you, when you submit the walkthrough form or contact us. Automatically from your browser, as described above. And from our scheduling provider, Calendly: the walkthrough form submits your details straight into the booking you create there — this website's own servers do not store the form's contents.
6. How information is used
To operate the website and demo; to respond to walkthrough requests and arrange them; to provide information you ask for; to prevent abuse and secure the service; to diagnose technical problems; to improve public usability; and to meet legal obligations.
7. Cookies and analytics
We set no cookies ourselves. The site uses two per-tab browser storage values: on the demo, which view — administrator or staff — you selected, so that refreshing while exploring the staff view does not silently switch you to an administrator; and on marketing pages, the campaign tags and landing page you arrived with, if any, so that a walkthrough you choose to book records how you found us. Both hold nothing beyond that, are sent nowhere except into a booking you create, and end when the tab closes. If you open the scheduling step, Calendly's embedded page operates under Calendly's own privacy policy.
We do not use advertising pixels, cross-site behavioural advertising, session replay, keystroke recording, or form-content capture. We do not capture the text of Portal Help questions.
8. Disclosure and service providers
We do not sell personal information, and we do not use information from the public site for targeted advertising.
Information is necessarily processed by the service providers that operate the site and our communications: Amazon Web Services (hosting), Calendly (scheduling), Cloudflare (DNS and inbound email routing), and Google (email correspondence) — plus, where needed, professional advisers. If these providers change, this policy will be updated. We may also disclose information where required by law, or in connection with a business transaction.
9. Customer agency data and protected health information
Agencies using ClientCentric control their own records and user relationships. We process that data according to the agreements in place with them, and PHI-related responsibilities are additionally governed by applicable Business Associate Agreements.
We do not use customer protected health information for advertising, and we do not train public AI models on it.
If you want access to, or correction of, records an agency holds about you, contact that agency — subject to the governing agreement and applicable law. This policy is not a substitute for an agency's own privacy notices or legal obligations, and it is not a HIPAA Notice of Privacy Practices.
10. Retention
Walkthrough enquiries and related correspondence are kept while we are in contact with you and for no longer than 24 months after our last interaction, then deleted or anonymised — unless a customer relationship begins, in which case the customer agreement governs, or the law requires a longer period. Security and request logs rotate on a rolling basis and are kept no longer than 12 months.
Demo state is not retained at all: it exists in your browser's memory and ends when you refresh or close the tab.
Retention of records inside a customer agency's portal is governed separately by that agency's agreement, its policies and applicable law — including Minnesota's five-year retention requirement for licensed providers.
11. Security
We use layered controls: access controls, encryption in transit, rate limiting on public write endpoints, security logging, and private file delivery. Two-factor enrollment ships with the operational portal before any client data is stored. Infrastructure is BAA-ready: single-region hosting, TLS everywhere, and no PHI processed until a BAA is in place with the customer.
No internet-connected system can guarantee absolute security, and we do not claim otherwise.
12. Your privacy rights
Depending on where you live and the circumstances, you may have rights to access, correct or delete information, to obtain a copy, to appeal a decision, to opt out of marketing, and to exercise choices about cookies or analytics.
Which rights apply depends on your jurisdiction, our role in relation to the data, applicable exemptions, and the type of information involved. Minnesota's Consumer Data Privacy Act has been in effect since 31 July 2025; where it or another state privacy law applies to information we hold about you, you can exercise the rights it grants using the contact below, and we will honour them as the law requires.
To make a request, contact contact@clientcentric.org. We may need to verify your identity.
13. Children
The public website and the business demo are not directed to children under 13. They are intended for agency owners, administrators and professionals. Access to a live client portal is handled separately through customer agreements and agency policy.
14. Where information is processed
The site and demo are hosted in the United States. If you access them from outside the United States, your information is processed in the United States, where privacy laws may differ from those of your jurisdiction.
15. Changes to this policy
We may update this policy. The effective and last-updated dates at the top change when we do, and material changes will be indicated on this page.
16. Contact
ClientCentric · contact@clientcentric.org