Clinlytics LLC (“Clinlytics,” “we,” “us,” or “our”) provides a business-to-business software-as-a-service platform for ABA therapy clinics. This Privacy Policy explains how Clinlytics collects, uses, discloses, and otherwise processes personal information in connection with our website, platform, and related services (collectively, the “Services”).
This Privacy Policy is intended primarily for clinic representatives, workforce members, prospective customers, website visitors, and other individuals who interact directly with Clinlytics. When Clinlytics processes Protected Health Information (“PHI”) on behalf of a clinic or other HIPAA-regulated organization, Clinlytics acts as a business associate as applicable, and that PHI is governed by the applicable Business Associate Agreement (“BAA”), the HIPAA Rules, and the instructions of the organization that provided the information. This Privacy Policy does not replace a clinic’s own HIPAA Notice of Privacy Practices.
1. Information We Collect
Depending on how the Services are used, we may collect or process the following categories of information:
- Account and business contact information, such as names, business contact details, clinic affiliation, role, account identifiers, and authentication information.
- Clinic operational information relating to use of the Services.
- Client authorization information and insurance authorization units.
- Billing, claims, and reimbursement-related information entered or maintained through the Services.
- Scheduling information.
- Staff and employee credentialing information.
- Payment and subscription information. Payment-card processing is handled through Stripe; Clinlytics may receive transaction, billing-status, and related account information but does not need to store full payment-card details when processed directly by Stripe.
- Communications and support information, including information submitted when contacting Clinlytics or using service-related communications.
- Technical and usage information reasonably generated through use of the Services, such as device, browser, log, authentication, feature-use, and diagnostic information, to the extent collected by the Services or supporting infrastructure.
2. Protected Health Information and HIPAA
Clinlytics is designed to support clinic administrative workflows that may involve PHI. When a HIPAA covered entity or business associate uses Clinlytics to create, receive, maintain, or transmit PHI on its behalf, the applicable BAA governs Clinlytics’s use and disclosure of that PHI. The clinic or other organization remains responsible for its relationship with the individual, its own HIPAA notices and authorizations, and determining the lawfulness of information it submits to the Services.
Individuals seeking to exercise HIPAA rights concerning PHI held by a clinic should generally direct the request to the clinic or organization responsible for the record. Clinlytics will assist the applicable clinic or organization with access, amendment, accounting, and other obligations as required by the BAA and HIPAA Rules.
3. How We Use Information
We may use information, as applicable and subject to the BAA for PHI, to:
- Provide, operate, maintain, and support the Services, including authorization tracking, denial management, billing intelligence, scheduling, and credentialing functionality.
- Create and manage accounts, authenticate users, administer subscriptions, and process billing.
- Communicate about accounts, service activity, onboarding, support, security, and administrative matters.
- Protect the security, integrity, availability, and lawful use of the Services; detect and investigate suspected fraud, misuse, or security events; and enforce contractual terms.
- Diagnose technical issues, maintain functionality, and improve the Services using information that we are legally and contractually permitted to use.
- Comply with applicable law, regulation, legal process, and lawful governmental requests, and establish, exercise, or defend legal claims.
- Create and use de-identified or aggregated information where permitted by applicable law and contractual obligations. PHI will be de-identified only in accordance with applicable HIPAA requirements before it is treated as non-PHI for these purposes.
5. Third-Party Service Providers
Our current identified providers include:
| Provider | Purpose |
|---|---|
| Supabase | Database and backend services |
| Stripe | Payment processing |
| Resend | Service-related email communications |
Our service-provider relationships may change as the Services evolve. When a provider creates, receives, maintains, or transmits PHI on our behalf, we will address the relationship as required by applicable HIPAA business-associate requirements before using that provider for PHI.
7. Data Retention
We retain information for as long as reasonably necessary to provide the Services, administer the business relationship, maintain security and business records, comply with legal and contractual obligations, resolve disputes, and enforce agreements. Retention of PHI is governed by the applicable BAA, customer instructions, technical feasibility, and applicable law. Upon termination of a BAA, PHI will be returned or destroyed when feasible as required by the BAA; where return or destruction is infeasible, the protections applicable to retained PHI will continue for as long as the information is retained.
8. Security
Clinlytics maintains administrative, technical, and organizational safeguards designed to protect information appropriate to its sensitivity and to the nature of the Services. Where Clinlytics handles ePHI as a business associate, Clinlytics is subject to applicable HIPAA Security Rule requirements. No method of electronic transmission, storage, or security is guaranteed to be completely secure, and we do not represent that any system is immune from all threats.
9. Individual Privacy Choices and Rights
Depending on applicable law and the nature of the relationship with Clinlytics, an individual may have rights concerning personal information, which may include rights to request access, correction, deletion, or information about certain processing. These rights may be subject to statutory exceptions and verification requirements.
For personal information controlled by a clinic or other Customer, requests should be directed to that organization. For PHI, HIPAA rights are generally exercised through the covered entity responsible for the record. Clinlytics will provide assistance to the applicable organization where required by law or contract.
10. Children
The Clinlytics Services are business tools intended for use by clinics and their authorized workforce members. They are not directed to children for independent consumer use. A clinic may maintain information relating to pediatric patients as part of its provision of ABA therapy services; when Clinlytics processes such information on behalf of the clinic, it does so under the clinic’s instructions and applicable contractual and legal requirements, including the BAA where the information is PHI.
11. International Processing
Clinlytics is a United States business serving business customers. This Privacy Policy does not represent that information will be processed exclusively in any particular state or location. If cross-border processing becomes applicable, Clinlytics will address any legally required transfer or processing safeguards before representing that a particular transfer mechanism applies.
12. Links and Third-Party Services
The Services may contain links to or integrations with third-party services. Clinlytics is not responsible for the independent privacy practices of third parties acting outside Clinlytics’s instructions. Customers and users should review applicable third-party terms and privacy notices where appropriate.
13. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in law, technology, the Services, or our information practices. When we make material changes, we will update the effective date and provide additional notice when reasonably appropriate or legally required. We will not use a policy update to retroactively authorize a materially different use of PHI that is prohibited by an applicable BAA or the HIPAA Rules.
14. Contact Us
Questions or requests concerning this Privacy Policy may be directed to Clinlytics through the contact methods made available on our website or by mail at:
- Clinlytics LLC
- 909 Eagles Landing Pkwy, Ste 440 #2249, Stockbridge, GA
- Website: clinlyticsonline.com