Clinlytics
HomeTermsPrivacyHIPAABAA
© 2026 Clinlytics LLC · EIN 41-5059229
HomeTerms of ServicePrivacy PolicyContact
Privacy

Privacy Policy

How Clinlytics collects, uses, discloses, and protects information across our website, platform, and related services.

Clinlytics LLC  ·  Effective September 1, 2026

Clinlytics LLC (“Clinlytics,” “we,” “us,” or “our”) provides a business-to-business software-as-a-service platform for ABA therapy clinics. This Privacy Policy explains how Clinlytics collects, uses, discloses, and otherwise processes personal information in connection with our website, platform, and related services (collectively, the “Services”).

This Privacy Policy is intended primarily for clinic representatives, workforce members, prospective customers, website visitors, and other individuals who interact directly with Clinlytics. When Clinlytics processes Protected Health Information (“PHI”) on behalf of a clinic or other HIPAA-regulated organization, Clinlytics acts as a business associate as applicable, and that PHI is governed by the applicable Business Associate Agreement (“BAA”), the HIPAA Rules, and the instructions of the organization that provided the information. This Privacy Policy does not replace a clinic’s own HIPAA Notice of Privacy Practices.

Table of Contents
  1. Information We Collect
  2. Protected Health Information & HIPAA
  3. How We Use Information
  4. How We Disclose Information
  5. Third-Party Service Providers
  6. Cookies & Similar Technologies
  7. Data Retention
  8. Security
  9. Individual Privacy Choices & Rights
  10. Children
  11. International Processing
  12. Links & Third-Party Services
  13. Changes to This Privacy Policy
  14. Contact Us

1. Information We Collect

Depending on how the Services are used, we may collect or process the following categories of information:

  • Account and business contact information, such as names, business contact details, clinic affiliation, role, account identifiers, and authentication information.
  • Clinic operational information relating to use of the Services.
  • Client authorization information and insurance authorization units.
  • Billing, claims, and reimbursement-related information entered or maintained through the Services.
  • Scheduling information.
  • Staff and employee credentialing information.
  • Payment and subscription information. Payment-card processing is handled through Stripe; Clinlytics may receive transaction, billing-status, and related account information but does not need to store full payment-card details when processed directly by Stripe.
  • Communications and support information, including information submitted when contacting Clinlytics or using service-related communications.
  • Technical and usage information reasonably generated through use of the Services, such as device, browser, log, authentication, feature-use, and diagnostic information, to the extent collected by the Services or supporting infrastructure.

2. Protected Health Information and HIPAA

Clinlytics is designed to support clinic administrative workflows that may involve PHI. When a HIPAA covered entity or business associate uses Clinlytics to create, receive, maintain, or transmit PHI on its behalf, the applicable BAA governs Clinlytics’s use and disclosure of that PHI. The clinic or other organization remains responsible for its relationship with the individual, its own HIPAA notices and authorizations, and determining the lawfulness of information it submits to the Services.

Individuals seeking to exercise HIPAA rights concerning PHI held by a clinic should generally direct the request to the clinic or organization responsible for the record. Clinlytics will assist the applicable clinic or organization with access, amendment, accounting, and other obligations as required by the BAA and HIPAA Rules.

3. How We Use Information

We may use information, as applicable and subject to the BAA for PHI, to:

  • Provide, operate, maintain, and support the Services, including authorization tracking, denial management, billing intelligence, scheduling, and credentialing functionality.
  • Create and manage accounts, authenticate users, administer subscriptions, and process billing.
  • Communicate about accounts, service activity, onboarding, support, security, and administrative matters.
  • Protect the security, integrity, availability, and lawful use of the Services; detect and investigate suspected fraud, misuse, or security events; and enforce contractual terms.
  • Diagnose technical issues, maintain functionality, and improve the Services using information that we are legally and contractually permitted to use.
  • Comply with applicable law, regulation, legal process, and lawful governmental requests, and establish, exercise, or defend legal claims.
  • Create and use de-identified or aggregated information where permitted by applicable law and contractual obligations. PHI will be de-identified only in accordance with applicable HIPAA requirements before it is treated as non-PHI for these purposes.

4. How We Disclose Information

We may disclose information in the following circumstances, subject to applicable law and the BAA where PHI is involved:

  • Service providers and subprocessors. We use providers that help operate the Services, including Supabase for database and backend functionality, Stripe for payments, and Resend for email communications. These providers may process information only as necessary for the services they provide to us and subject to applicable contractual and legal requirements.
  • Customer-directed disclosures. We may disclose information at the direction of the clinic or organization that controls the relevant account or data.
  • Legal and safety purposes. We may disclose information when required by law or when reasonably necessary to protect rights, safety, systems, property, or the integrity of the Services, consistent with applicable law.
  • Business transactions. Information may be disclosed in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business or assets, subject to applicable confidentiality, HIPAA, and other legal requirements.

Clinlytics does not sell PHI. Clinlytics will not use or disclose PHI for purposes prohibited by HIPAA or the applicable BAA.

5. Third-Party Service Providers

Our current identified providers include:

ProviderPurpose
SupabaseDatabase and backend services
StripePayment processing
ResendService-related email communications

Our service-provider relationships may change as the Services evolve. When a provider creates, receives, maintains, or transmits PHI on our behalf, we will address the relationship as required by applicable HIPAA business-associate requirements before using that provider for PHI.

6. Cookies and Similar Technologies

The website or platform may use cookies, local storage, or similar technologies that are necessary for authentication, security, session management, preferences, and operation of the Services. We will not describe optional advertising, analytics, or tracking technologies as being in use unless and until they are actually implemented. Browser settings may allow users to control certain cookies, although disabling necessary technologies may affect Service functionality.

7. Data Retention

We retain information for as long as reasonably necessary to provide the Services, administer the business relationship, maintain security and business records, comply with legal and contractual obligations, resolve disputes, and enforce agreements. Retention of PHI is governed by the applicable BAA, customer instructions, technical feasibility, and applicable law. Upon termination of a BAA, PHI will be returned or destroyed when feasible as required by the BAA; where return or destruction is infeasible, the protections applicable to retained PHI will continue for as long as the information is retained.

8. Security

Clinlytics maintains administrative, technical, and organizational safeguards designed to protect information appropriate to its sensitivity and to the nature of the Services. Where Clinlytics handles ePHI as a business associate, Clinlytics is subject to applicable HIPAA Security Rule requirements. No method of electronic transmission, storage, or security is guaranteed to be completely secure, and we do not represent that any system is immune from all threats.

9. Individual Privacy Choices and Rights

Depending on applicable law and the nature of the relationship with Clinlytics, an individual may have rights concerning personal information, which may include rights to request access, correction, deletion, or information about certain processing. These rights may be subject to statutory exceptions and verification requirements.

For personal information controlled by a clinic or other Customer, requests should be directed to that organization. For PHI, HIPAA rights are generally exercised through the covered entity responsible for the record. Clinlytics will provide assistance to the applicable organization where required by law or contract.

10. Children

The Clinlytics Services are business tools intended for use by clinics and their authorized workforce members. They are not directed to children for independent consumer use. A clinic may maintain information relating to pediatric patients as part of its provision of ABA therapy services; when Clinlytics processes such information on behalf of the clinic, it does so under the clinic’s instructions and applicable contractual and legal requirements, including the BAA where the information is PHI.

11. International Processing

Clinlytics is a United States business serving business customers. This Privacy Policy does not represent that information will be processed exclusively in any particular state or location. If cross-border processing becomes applicable, Clinlytics will address any legally required transfer or processing safeguards before representing that a particular transfer mechanism applies.

12. Links and Third-Party Services

The Services may contain links to or integrations with third-party services. Clinlytics is not responsible for the independent privacy practices of third parties acting outside Clinlytics’s instructions. Customers and users should review applicable third-party terms and privacy notices where appropriate.

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in law, technology, the Services, or our information practices. When we make material changes, we will update the effective date and provide additional notice when reasonably appropriate or legally required. We will not use a policy update to retroactively authorize a materially different use of PHI that is prohibited by an applicable BAA or the HIPAA Rules.

14. Contact Us

Questions or requests concerning this Privacy Policy may be directed to Clinlytics through the contact methods made available on our website or by mail at:

  • Clinlytics LLC
  • 909 Eagles Landing Pkwy, Ste 440 #2249, Stockbridge, GA
  • Website: clinlyticsonline.com