Privacy Policy

Last updated: January 15, 2022

This Privacy Policy describes how Clistahr Technologies, Inc. ("Clistahr", "We", "Us", "Our") collects, uses, and discloses information when You use the Service, and explains Your privacy rights and how the law protects You.

We collect, use, and disclose information as described in this Privacy Policy and, where required by applicable law, only where We have a valid legal basis to do so, including Your consent where consent is required.

Important: Our Two Different Roles

Please read this section first. It determines which parts of this Privacy Policy apply to You.

Clistahr provides software to home health agencies, skilled nursing organizations, and similar healthcare providers ("Agencies"). We do not deliver healthcare. Depending on the information involved, We act in one of two capacities:

  • 1. As a controller of Our Own Data. When You visit Our Website, contact Us, request a demo, subscribe to Our communications, apply for a job with Us, or administer Your Agency's commercial relationship with Us, We decide how that information is used. This Privacy Policy governs that information in full.

  • 2. As a Business Associate processing Agency Data. When an Agency uses the Service to document patient care, manage its workforce, or run its operations, the Agency — not Clistahr — decides what information is collected and how it is used. Clistahr processes that information solely on the Agency's behalf and only as permitted by Our written agreement with the Agency, including a Business Associate Agreement ("BAA") executed under HIPAA.

Agency Data is not governed by the commercial provisions of this Privacy Policy. We do not use Agency Data for Our own marketing, do not sell or share it, do not use it to build profiles, and do not use it for purposes other than providing the Service, as required by law, and as otherwise permitted by the applicable BAA.

If You are a patient, a client of an Agency, or a member of an Agency's workforce and You want to access, correct, or delete records held in the Service, contact Your Agency, not Clistahr. The Agency is the entity legally responsible for responding, and it decides what records must be retained. Where an Agency directs Us to act on such a request, We assist the Agency. If You contact Us directly about Agency Data, We will refer You to the relevant Agency and, where required, notify that Agency of Your request.

Sections marked [Own Data only] apply only to information in category 1 above.

Interpretation and Definitions

Interpretation

The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for You to access Our Service or parts of Our Service.

  • Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.

  • Agency means a home health agency, skilled nursing organization, or other healthcare provider organization that licenses the Service and maintains a tenant within it. An Agency is typically a Covered Entity under HIPAA.

  • Agency Data means all information that an Agency, or a Platform User acting for an Agency, submits to, or that is generated within, the Agency's tenant in the Service. Agency Data includes patient and client records, clinical documentation, visit and scheduling records, electronic visit verification data, and Agency workforce records.

  • Application refers to Clistahr, the software program provided by the Company, including its web and mobile interfaces.

  • Business, for the purposes of the CCPA/CPRA, refers to the Company as the legal entity that collects Consumers' personal information, or on behalf of which such information is collected, and that alone, or jointly with others, determines the purposes and means of the processing of Consumers' personal information, and that does business in the State of California. Where Clistahr acts as a Business Associate or Service Provider processing Agency Data, Clistahr is not the "Business" with respect to that information.

  • Business Associate and Covered Entity have the meanings given in HIPAA. Clistahr is a Business Associate of each Agency.

  • Business Associate Agreement (BAA) means the written agreement required by 45 CFR 164.504(e) between Clistahr and an Agency governing Clistahr's handling of Protected Health Information.

  • CCPA and/or CPRA refers to the California Consumer Privacy Act as amended by the California Privacy Rights Act of 2020.

  • Company (referred to as either "the Company", "We", "Us" or "Our" in this Privacy Policy) refers to Clistahr Technologies, Inc., 6851 Oak Hall Lane, Suite 119, Columbia, MD 21045.

  • Consumer, for the purpose of the CCPA/CPRA, means a natural person who is a California resident. A resident, as defined in the law, includes (1) every individual who is in the State of California for other than a temporary or transitory purpose, and (2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose.

  • Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website, among its many uses.

  • Country/State refers to: Maryland, United States.

  • Device means any device that can access the Service, such as a computer, a cell phone or a digital tablet.

  • Do Not Track (DNT) is a concept promoted by U.S. regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism allowing Internet users to control the tracking of their online activities across websites.

  • HIPAA means the Health Insurance Portability and Accountability Act of 1996, as amended, including the HITECH Act and their implementing regulations.

  • Our Own Data means information for which Clistahr determines the purposes and means of processing, including Website visitor data, prospect and marketing contacts, Agency administrative and billing contacts, support correspondence with Us, and job applicant data.

  • Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual.

    For the purposes of the CCPA/CPRA, Personal Data means any information that identifies, relates to, describes or is capable of being associated with, or could reasonably be linked, directly or indirectly, with You.

    We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.

  • Platform User means an individual who accesses the Service under an Agency's tenant, such as clinical, administrative, or field staff, or an auditor authorized by the Agency.

  • Protected Health Information (PHI) and Electronic Protected Health Information (ePHI) have the meanings given in HIPAA.

  • Service refers to the Application or the Website or both.

  • Service Provider means any natural or legal person who processes data on behalf of the Company, including third-party companies employed by the Company to facilitate the Service, to provide the Service on Our behalf, to perform services related to the Service, or to assist Us in analyzing how the Service is used. Where a Service Provider may access ePHI, We execute a Business Associate Agreement with that Service Provider.

  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

  • User means any individual who accesses or uses the Service, including Visitors and Platform Users.

  • Visitor means an individual who visits the Website without accessing an Agency tenant.

  • Website refers to Clistahr, accessible from https://clistahr.com.

  • You means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Collecting and Using Your Personal Information

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Phone number
  • Address, State, Province, ZIP/Postal code, City
  • Job title, role, and the Agency You are associated with
  • Account credentials and authentication records

Agency Data Processed on Behalf of Agencies

When an Agency uses the Service, the Service processes information the Agency chooses to enter or generate. Depending on the Agency's configuration, this may include:

  • Patient and client identifiers, contact details, and addresses
  • Clinical documentation, care plans, assessments, orders, and progress notes
  • Visit records, scheduling data, and electronic visit verification data, including device location captured at clock-in and clock-out (see "Location Information")
  • Agency workforce records, including applicant information, employment and credentialing history, licenses and certifications, in-service training and quiz results, leave requests, timecards, and contractor agreements
  • Documents, photographs, and files uploaded by Platform Users

Clistahr collects this information only as an extension of the Agency's own systems. The Agency determines what is collected, who may access it, how long it is kept, and when it is deleted.

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of Our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including the type of mobile device You use, Your mobile device's unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

Usage Data generated inside an Agency tenant — including application audit records showing which Platform User viewed or changed which record, and when — is Agency Data. It exists because HIPAA requires it, it is made available to the Agency, and it is retained under the Agency's instructions and Our legal obligations rather than under the retention periods in the "Retention" section below.

Location Information

The mobile interface of the Service supports electronic visit verification. With Your prior permission, when a Platform User clocks in or out of a visit, the Application captures the Device's location and compares it against the service address recorded by the Agency, within a radius the Agency configures.

  • Location is captured in connection with visit events, for the purpose of verifying that a scheduled visit occurred at the correct place and time.
  • The resulting records are Agency Data. They are provided to the Agency, which uses them for compliance, payroll, and payer reporting.
  • Clistahr does not use location data for advertising, does not sell or share it, and does not use it to track Platform Users outside visit events.
  • You can disable location access at any time through Your Device settings. Doing so may prevent the visit verification features from working, and Your Agency may require it as a condition of using the Application for work.

Camera and Photo Library

With Your prior permission, the Application may access Your Device's camera and photo library so that You can attach documents, wound photographs, signatures, or similar materials to a record. Material You attach is uploaded to the Service and becomes Agency Data. You can enable or disable this access at any time through Your Device settings.

Tracking Technologies and Cookies

We use tracking technologies (such as cookies) on Our Website and, in a limited way, within the Service. The technologies We use may include:

  • Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of Our Service.

  • Web Beacons. Certain sections of Our Website may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages and for other related website statistics.

  • Email Tracking Technologies. Our marketing emails may contain similar technologies that tell Us whether an email has been opened or a link within it has been clicked. We use this to measure the performance of Our email communications, to maintain deliverability, and to understand which content is of interest to You. You can prevent most email tracking by configuring Your email client to block the automatic loading of remote images, and You may opt out of marketing emails entirely by using the unsubscribe link in any marketing email We send. Operational and security emails required to deliver the Service do not carry marketing tracking.

We do not use advertising cookies, cross-context behavioral advertising technologies, or third-party analytics that receive Agency Data inside the authenticated Service. Tracking technologies described in this section apply principally to Our public Website.

Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.

Where required by law, We use non-essential cookies only with Your consent. You can withdraw or change Your consent at any time using Our cookie preferences tool (if available) or through Your browser or device settings. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.

We use both Session and Persistent Cookies for the purposes set out below:

  • Necessary / Essential Cookies

    Type: Session Cookies. Administered by: Us.

    Purpose: Essential to provide You with services available through the Website and the Service and to enable You to use their features. They authenticate users, maintain session state, enforce session timeouts, and help prevent fraudulent use of accounts. Without these Cookies, the services You have asked for cannot be provided.

  • Cookie Notice Acceptance Cookies

    Type: Persistent Cookies. Administered by: Us.

    Purpose: Record whether users have accepted the use of cookies and the consent choices You have made, so that We can honor those choices on future visits.

  • Functionality Cookies

    Type: Persistent Cookies. Administered by: Us.

    Purpose: Remember choices You make, such as Your login details or language preference, so You do not have to re-enter preferences each time.

Use of Your Personal Data

Our Own Data [Own Data only]

The Company may use Our Own Data for the following purposes:

  • To provide and maintain Our Service, including to monitor its usage, availability, and performance.

  • To manage Your Account and Your registration as a user of the Service.

  • For the performance of a contract with You or with the Agency You represent.

  • To contact You by email, telephone, SMS, or push notification regarding updates, service changes, security notices, and other communications related to the functionality of the Service.

  • To provide You with news and information about Our products, services, and events. We send marketing communications only where permitted by applicable law. Where prior consent is required, We send them only with Your consent; otherwise We may send them until You opt out. You may opt out at any time using the unsubscribe link in any marketing email or by contacting Us.

  • To manage Your requests and provide customer support.

  • For security and fraud prevention, including detecting, investigating, and responding to security incidents and misuse.

  • To comply with legal obligations and to establish, exercise, or defend legal claims.

  • For business transfers, to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets.

  • For product improvement and analysis, including identifying usage trends and evaluating the effectiveness of Our communications.

Agency Data

We use Agency Data only to:

  • Provide, maintain, secure, and support the Service for the Agency
  • Perform the functions the Agency or its Platform Users initiate within the Service
  • Prevent, detect, and respond to security incidents, fraud, and illegal activity affecting the Service
  • Meet Our obligations under the BAA and applicable law, including required audit logging and breach notification

We do not use Agency Data to market to patients or to Platform Users, to build advertising profiles, or to train systems for purposes unrelated to the Agency's use of the Service, except where a use is expressly permitted by the BAA and applicable law — for example, using de-identified information created in accordance with 45 CFR 164.514 for the proper management and administration of the Service. De-identified information is not re-identified and is not treated as Personal Data.

Agency Data is not among the assets We would use or transfer for the business-transfer purpose described above except in accordance with the BAA and applicable law. Any successor entity assumes the same obligations, and the Agency retains its rights under its agreement with Us.

Disclosure of Your Personal Data

We may share information in the following situations:

  • With Service Providers: To host, operate, monitor, secure, and support the Service and to communicate with You. Where a Service Provider may access ePHI, We execute a Business Associate Agreement before any access is granted, and its use of the information is limited to the contracted service.
  • With the Agency: Agency Data is made available to the Agency that controls the tenant, including its authorized administrators and auditors.
  • With Affiliates: We may share Our Own Data with Our Affiliates, who are required to honor this Privacy Policy. Agency Data is shared with an Affiliate only where the Affiliate acts as Our subcontractor under the BAA.
  • For business transfers: In connection with any merger, sale of Company assets, financing, or acquisition, subject to the limitation stated above for Agency Data. We will provide notice before Our Own Data becomes subject to a different Privacy Policy.
  • For legal reasons: Where required by law or in response to valid requests by public authorities. Requests for PHI are handled in accordance with HIPAA and the BAA, which generally require Us to notify the Agency of the request unless prohibited by law.
  • With Your consent: For any other purpose with Your consent.

Categories of Service Providers

  • Cloud hosting and infrastructure: Amazon Web Services, Inc. (United States regions). AWS hosts the Service, including storage, compute, backup, and logging infrastructure. A Business Associate Addendum is in place. See https://aws.amazon.com/compliance/data-privacy/.
  • Transactional and marketing email: AWS Simple Email Service (SES). See https://docs.aws.amazon.com/ses/latest/dg/data-protection.html.
  • SMS delivery: AWS End User Messaging. See https://docs.aws.amazon.com/sms-voice/latest/userguide/data-protection.html.
  • Electronic Signatures: BoldSign. See https://boldsign.com/legalcenter/.

A current list of the Service Providers that may process Agency Data is available to Agencies on request.

Text Messages Privacy Notice

You may receive text (SMS) messages from Us. We collect and store the information You provide in connection with text messaging, such as Your phone number, the date and method of Your consent, and message delivery information.

No mobile information will be shared with or sold to third parties or affiliates for marketing or promotional purposes. The phone numbers and consent records We collect for texting are never shared with anyone for any purpose, except the Service Providers that technically have to handle them to deliver the messages.

We treat two categories of messages separately:

  • Operational and security messages, such as one-time passcodes, authentication messages, security alerts, account notifications, and messages related to Your work in an Agency tenant. These are part of the Service. Opting out may prevent You from signing in or receiving required notifications.
  • Marketing messages, such as promotional offers and product announcements. These require separate opt-in consent, which is never a condition of purchase or of using the Service, and which You may withdraw at any time without affecting operational messages.

Reply STOP to opt out. Reply HELP for support. Message and data rates may apply. Messaging frequency may vary. Carriers are not liable for delayed or undelivered messages.

Retention of Your Personal Data

Our Own Data [Own Data only]

We retain Our Own Data only for as long as necessary for the purposes set out in this Privacy Policy, and to comply with Our legal obligations, resolve disputes, and enforce Our agreements. Where possible We apply shorter periods or reduce identifiability by deleting, aggregating, or anonymizing data. The periods below are maximums; We may delete or anonymize sooner.

  • Account information

    • Administrative and billing contact accounts: for the duration of the relationship plus up to 24 months after closure, to handle post-termination issues and disputes.
  • Customer support data

    • Support tickets and correspondence with Us: up to 24 months from closure.
    • Chat transcripts: up to 24 months for quality assurance and training.
  • Website usage data

    • Website analytics data (cookies, IP addresses, device identifiers): up to 24 months from collection.
    • Website server logs: up to 24 months for security monitoring and troubleshooting.
  • Marketing data

    • Email marketing: until You unsubscribe, or up to 24 months from Your last engagement, whichever comes first.

Agency Data

The retention periods above do not apply to Agency Data. Agencies are subject to federal and state recordkeeping requirements that commonly require clinical and employment records to be retained for many years, and HIPAA requires certain security and audit documentation to be retained for six years. Accordingly:

  • We retain Agency Data for the term of Our agreement with the Agency and in accordance with the Agency's instructions.
  • Application audit records showing access to and changes in ePHI are retained for at least six years, as required by 45 CFR 164.316(b)(2).
  • On termination, We provide the Agency an export of its data in the agreed format and then return or destroy remaining Agency Data in accordance with the BAA, unless retention is required by law. Residual copies may persist in encrypted backups until they expire under Our standard backup schedule; those backups are not restored except for disaster recovery, security, or legal compliance.
  • Data subject to a legal hold, litigation, investigation, or preservation notice is retained until the hold is released.

Individuals seeking deletion of records held in an Agency tenant must direct the request to the Agency.

Deletion and Correction of Your Personal Data

[Own Data only] You may update, amend, or delete information You provided to Us at any time by signing in to Your Account and visiting the settings that allow You to manage Your information, or by contacting Us. We may need to retain certain information where We have a legal obligation or other lawful basis to do so.

Requests concerning Agency Data — patient records, clinical documentation, visit and location records, or Agency workforce records — must be directed to the Agency. Clistahr cannot lawfully delete or alter those records on an individual's instruction, because the Agency, not Clistahr, is responsible for the integrity and retention of its own records. We will act on the Agency's documented instruction and will assist the Agency in fulfilling requests it receives.

Transfer of Your Personal Data

The Service is intended for use in the United States, and information processed through the Service is stored and processed in the United States. Your information may be transferred to and maintained on computers located outside of Your state, province, or country, where data protection laws may differ.

Where required by applicable law, We ensure that international transfers are subject to appropriate safeguards. The Company will take all steps reasonably necessary to ensure Your data is treated securely and in accordance with this Privacy Policy.

Security of Your Personal Data

We maintain an information security program with administrative, physical, and technical safeguards designed to meet the requirements of the HIPAA Security Rule, including encryption of data in transit and at rest, role-based access control, tenant isolation, mandatory multi-factor authentication for privileged access, audit logging, workforce security training, and documented incident response.

No method of transmission over the Internet, or method of electronic storage, is 100% secure. While We strive to use commercially reasonable means to protect Your information, We cannot guarantee its absolute security.

If a breach of unsecured PHI occurs, We notify the affected Agency in accordance with HIPAA and the BAA. The Agency, as Covered Entity, is responsible for notifying affected individuals, the U.S. Department of Health and Human Services, and the media where required, and We cooperate fully in that process.

CCPA/CPRA Privacy Notice (California Privacy Rights)

This section supplements the information in Our Privacy Policy and applies solely to visitors, users, and others who reside in the State of California.

Scope and HIPAA Exclusion

The CCPA/CPRA does not apply to protected health information collected by a covered entity or business associate governed by HIPAA, or to medical information governed by the California Confidentiality of Medical Information Act (CMIA). Most information held within an Agency tenant falls into these exclusions. Where Clistahr processes personal information on an Agency's behalf that is not excluded, Clistahr acts as a Service Provider under a written contract that limits its use of that information, and the Agency is the Business responsible for responding to Consumer requests.

The disclosures below therefore describe Our practices as a Business with respect to Our Own Data, and identify separately where a category is also processed on an Agency's behalf.

Categories of Personal Information Collected

The following list uses the categories defined in the CCPA/CPRA and reflects information We may have collected from California residents within the last twelve (12) months. Listing a category does not mean every type of information it describes was in fact collected.

  • Category A: Identifiers. Examples: real name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name, driver's license number, passport number, or other similar identifiers.

    Collected: Yes. As a Business (Visitors, prospects, Agency contacts, Platform User account identifiers) and, as a Service Provider, within Agency Data.

  • Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Examples: name, signature, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, financial information, medical information, or health insurance information.

    Collected: Yes. As a Business, contact and account details. Employment, credentialing, education, and medical or health insurance information appear within Agency Data and are collected only as a Service Provider on the Agency's behalf; the medical portion is generally excluded from the CCPA/CPRA under the HIPAA and CMIA exclusions described above.

  • Category C: Protected classification characteristics under California or federal law. Examples: age, race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information.

    Collected: Yes, within Agency Data only. Patient records and Agency workforce records may contain date of birth, sex, medical condition, disability, and similar characteristics where the Agency records them. Clistahr does not collect these characteristics for its own purposes and does not use them to make decisions about any individual. The clinical portion is generally excluded from the CCPA/CPRA under HIPAA and CMIA.

  • Category D: Commercial information. Examples: records of products or services purchased, obtained, or considered, or other purchasing histories or tendencies.

    Collected: Yes, limited. Subscription, licensing, and billing records relating to Agencies and their administrative contacts. We do not collect consumer purchasing histories.

  • Category E: Biometric information. Examples: genetic, physiological, behavioral, and biological characteristics used to extract a template or identifier, such as fingerprints, faceprints, voiceprints, iris or retina scans, keystroke or gait patterns.

    Collected: No. Where a Device uses biometric unlock (such as fingerprint or face unlock) to access the Application, that verification occurs on Your Device and the biometric template is never transmitted to or stored by Us.

  • Category F: Internet or other similar network activity. Examples: browsing history, search history, information on a consumer's interaction with a website or application.

    Collected: Yes. Website analytics as a Business; in-application activity and audit records as a Service Provider within Agency Data.

  • Category G: Geolocation data. Examples: approximate physical location, physical location or movements.

    Collected: Yes. Approximate location derived from IP address as a Business. Precise geolocation is captured by the mobile Application at visit clock-in and clock-out, with permission, as Agency Data on the Agency's behalf. See also Category L.

  • Category H: Sensory data. Examples: audio, electronic, visual, thermal, olfactory, or similar information.

    Collected: Yes. With Your prior permission, pictures and other visual material from Your Device's camera and photo library, and signatures captured in the Service, in order to provide features of the Application. This material is Agency Data.

  • Category I: Professional or employment-related information. Examples: current or past job history or performance evaluations.

    Collected: Yes. The Service includes human resources functionality, and Agency Data may include applicant records, employment history, credentials and licenses, in-service training and quiz results, leave requests, timecards, and contractor agreements. This information is processed as a Service Provider on the Agency's behalf. We also collect professional information about Our own job applicants and workforce as a Business.

  • Category J: Non-public education information (per FERPA, 20 U.S.C. § 1232g, 34 C.F.R. Part 99).

    Collected: No. Training records generated within the Service are employment records, not FERPA education records.

  • Category K: Inferences drawn from other personal information. Examples: a profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

    Collected: No. We do not create profiles about individuals, and We do not use Agency Data to draw inferences about patients or Platform Users.

  • Category L: Sensitive personal information. Examples: government-issued identifying numbers; account log-in credentials in combination with a password or access code; genetic data; neural data; precise geolocation; racial or ethnic origin; religious or philosophical beliefs; union membership; the contents of mail, email, and text messages; biometric data; health data; and sexual orientation or sex life.

    Collected: Yes. Specifically:

    • Account log-in credentials in combination with a password — collected as a Business to authenticate You and secure Your Account.
    • Precise geolocation — collected by the mobile Application at visit clock-in and clock-out, as Agency Data, solely to verify visits.
    • Health data and government-issued identifying numbers — present within Agency Data where the Agency records them; the health portion is generally excluded from the CCPA/CPRA under HIPAA and CMIA.

    We collect, use, and disclose sensitive personal information only for the purposes permitted by the CCPA/CPRA and its implementing regulations, and We do not use sensitive personal information to infer characteristics about You.

Under CCPA/CPRA, Personal Information does not include:

  • Publicly available information, as defined by the statute
  • Deidentified or aggregated consumer information
  • Information excluded from the CCPA/CPRA's scope, such as:
    • Health or medical information covered by HIPAA and the CMIA, or clinical trial data
    • Personal Information covered by certain sector-specific privacy laws, including the FCRA, the GLBA or California FIPA, and the Driver's Privacy Protection Act of 1994

Sources of Personal Information

  • Directly from You. Forms You complete, preferences You express, and information You enter into the Service.
  • Indirectly from You. Observing Your activity on Our Service.
  • Automatically from You. Cookies and similar technologies set on Your Device as You navigate Our Website.
  • From Agencies. Information an Agency or its Platform Users enter about patients, clients, applicants, and workforce members.
  • From Service Providers. Third-party vendors We use to provide the Service.

Use of Personal Information

We may use or disclose Personal Information for "business purposes" or "commercial purposes" as defined under the CCPA/CPRA, including:

  • To operate the Service and provide it to You and to Agencies
  • To provide support and respond to inquiries
  • To fulfill the reason You provided the information
  • To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations
  • For internal administrative and auditing purposes
  • To detect security incidents and protect against malicious, deceptive, fraudulent, or illegal activity
  • Other purposes consistent with the context in which the information was collected, or as disclosed at the time of collection

Personal Information processed on an Agency's behalf is used only to perform the services specified in Our contract with the Agency.

If We decide to collect additional categories of Personal Information, or use collected Personal Information for materially different, unrelated, or incompatible purposes, We will update this Privacy Policy.

Disclosure of Personal Information

In the last twelve (12) months We may have disclosed the following categories of Personal Information for business purposes: A (Identifiers), B (California Customer Records categories), C (Protected classifications, within Agency Data), D (Commercial information), F (Internet or network activity), G (Geolocation data), H (Sensory data), I (Professional or employment-related information), and L (Sensitive personal information).

We disclose these categories to the following categories of recipients:

  • The Agency that controls the tenant in which the information resides, and its authorized users
  • Service Providers and contractors, including Our cloud hosting, email, and communications providers
  • Our Affiliates
  • Professional advisors, and public authorities where required by law

When We disclose Personal Information to a Service Provider or contractor for a business purpose, We enter into a contract that describes the purpose, requires the recipient to keep the information confidential, and prohibits use for any purpose other than the limited and specified purposes stated in the contract. Where ePHI is involved, that contract includes a Business Associate Agreement.

Sale or Sharing of Personal Information

As defined in the CCPA/CPRA, "sell" means disclosing personal information to a third party for valuable consideration, and "share" means disclosing personal information to a third party for cross-context behavioral advertising.

We have not sold or shared Personal Information of California residents in the preceding twelve (12) months, and We do not sell or share Personal Information as those terms are defined in the CCPA/CPRA. We have not sold or shared the personal information of Consumers under 16 years of age. We disclose Personal Information to Service Providers and contractors under written contracts that restrict their use of that information.

We honor opt-out preference signals such as the Global Privacy Control (GPC) where applicable. If Our practices change, We will update this Privacy Policy and provide the required "Do Not Sell or Share My Personal Information" link and opt-out methods.

Retention of Personal Information

We retain California residents' Personal Information for as long as reasonably necessary to achieve the purposes described in this Privacy Policy, taking into account how long We need the information to provide the Service; whether You have requested deletion, subject to applicable exceptions; Our legal, tax, accounting, and regulatory obligations; security and fraud prevention needs; and the periods needed to resolve disputes and enforce Our agreements. Specific periods are described in the "Retention of Your Personal Data" section, including the separate treatment of Agency Data.

Your Rights under the CCPA/CPRA

California residents have the following rights: the right to notice; the right to know and access; the right to correct; the right to delete, subject to exceptions; the right to opt out of sale or sharing; the right to limit the use and disclosure of sensitive personal information; and the right not to be discriminated against for exercising these rights.

Where Clistahr acts as a Service Provider, We will forward Your request to the relevant Agency or direct You to it. The Agency is the Business responsible for responding.

We may deny a deletion request where retaining the information is necessary for Us or Our Service Providers to complete the transaction for which it was collected; detect security incidents or protect against fraudulent or illegal activity; debug and repair errors; exercise free speech or another right provided by law; comply with the California Electronic Communications Privacy Act; engage in public or peer-reviewed research in the public interest with Your prior informed consent; enable internal uses reasonably aligned with consumer expectations; comply with a legal obligation; or make other internal and lawful uses compatible with the context in which You provided the information.

Exercising Your CCPA/CPRA Rights

To exercise Your rights, contact Us using the details in the "Contact Us" section. Only You or an authorized agent acting on Your behalf may make a verifiable request relating to Your Personal Information.

Your request must provide sufficient information to allow Us to reasonably verify that You are the person about whom We collected Personal Information, or an authorized representative, and must describe Your request with enough detail for Us to evaluate and respond to it. We cannot respond if We cannot verify Your identity or authority, or confirm that the information relates to You.

We will not require a verifiable consumer request to opt out of sale or sharing, or to limit the use of sensitive personal information; for those requests We may ask only for information reasonably necessary to identify the Personal Information concerned.

No later than 10 business days after receiving a request to know, delete, or correct, We will confirm receipt and explain how We will process and verify the request. We will respond no later than 45 calendar days after receipt, and may extend once by an additional 45 calendar days where reasonably necessary, notifying You within the initial period and explaining the reason.

Unless You request a longer period, Our response to a request to know will cover the preceding 12 months. You may request information collected on or after January 1, 2022, for a longer period, unless providing it is impossible or requires disproportionate effort. We are not required to retain Personal Information for any specific period.

For data portability requests, We will provide Your personal information in a readily usable format that allows transmission from one entity to another without hindrance.

Limit the Use or Disclosure of My Sensitive Personal Information

California residents have the right to limit the use and disclosure of sensitive personal information to what is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests them.

We collect, use, and disclose sensitive personal information only in ways necessary to provide the Service — authenticating You, securing Your Account, and, where the Agency has enabled it, verifying visits using precise geolocation. We do not use it to infer characteristics. To submit a request to limit, contact Us using the methods in the "Contact Us" section. We will not require You to verify Your identity to submit a request to limit, although We may ask for information reasonably necessary to process it.

Privacy Rights in Other U.S. States

Comprehensive privacy laws are in effect in a number of U.S. states, including Maryland, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others. If You are a resident of a state with such a law, You may have some or all of the rights below, subject to that state's exemptions and thresholds.

Two exemptions matter most here. First, these laws generally exclude protected health information governed by HIPAA, and several exclude covered entities and business associates entirely. Second, where Clistahr acts as a processor for an Agency, the Agency is the controller and is responsible for responding to Your request. We assist the Agency and will refer You to it.

Your Rights

  • Confirm and access. Confirm whether We process Your personal data and obtain a copy.
  • Correct. Correct inaccuracies, taking into account the nature of the data and the purpose of processing. (Not available in Iowa or Utah.)
  • Delete. Delete personal data You provided or that We obtained about You, subject to exemptions.
  • Portability. Obtain a copy in a portable and, to the extent technically feasible, readily usable format.
  • Opt out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects.
  • Sensitive data. In most of these states, We must obtain Your consent before processing sensitive data. In Maryland, the sale of sensitive data is prohibited outright, and collection and processing of sensitive data is limited to what is strictly necessary to provide the requested product or service.
  • Non-discrimination. You will not receive a lesser level of service for exercising these rights.

We do not sell personal data, do not process personal data for targeted advertising, and do not engage in profiling that produces legal or similarly significant effects. Accordingly, no opt-out is currently required, but You may still contact Us to confirm this. We honor universal opt-out mechanisms, including the Global Privacy Control, where the applicable state law requires it.

Maryland Residents

The Maryland Online Data Privacy Act imposes stricter limits than most state laws. Consistent with those requirements, We collect only the personal data that is reasonably necessary and proportionate to provide or maintain the Service; We do not sell sensitive data or precise geolocation data under any circumstance; We do not sell the personal data of a consumer We know or should know is under 18; and We do not process sensitive data beyond what is strictly necessary to provide a product or service the consumer requested.

How to Submit a Request and Appeal

Submit a request using the details in the "Contact Us" section, identifying the state in which You reside. We will respond within 45 days, and may extend once by an additional 45 days where reasonably necessary, notifying You of the extension and the reason within the initial period.

If We decline to act on Your request, We will tell You why and how to appeal. To appeal, reply to Our decision or contact Us with the subject line "Privacy Request Appeal." We will respond to an appeal in writing within 45 days (60 days in some states), explaining the reasons for Our decision. If Your appeal is denied, You may contact Your state Attorney General to submit a complaint.

"Do Not Track" Policy as Required by CalOPPA

Our Service does not respond to Do Not Track browser signals. We do honor the Global Privacy Control where applicable, as described above.

Some third-party websites do keep track of Your browsing activities. If You visit such websites, You can set Your preferences in Your web browser to inform them that You do not want to be tracked.

Your California Privacy Rights (Shine the Light)

Under California Civil Code § 1798.83, California residents with an established business relationship with Us may request information once a year about the sharing of their Personal Data with third parties for those third parties' direct marketing purposes.

We do not disclose California customers' Personal Information to third parties for those third parties' own direct marketing purposes.

California Privacy Rights for Minor Users (Cal. Bus. & Prof. Code § 22581)

California residents under the age of 18 who are registered users of online sites, services, or applications may request removal of content or information they have publicly posted. To request removal, contact Us using the information below and include the email address associated with Your Account. Your request does not guarantee complete removal, and the law may not permit or require removal in certain circumstances.

Children's and Minors' Privacy

The Website and the registration functions of the Service are not directed to individuals under the age of 16, and We do not knowingly collect Personal Information directly from anyone under 16 in that context. If You are a parent or guardian and believe Your child has provided Us with Personal Information in that context, please contact Us and We will take steps to remove it as soon as reasonably possible.

This does not apply to Agency Data. Agencies may provide care to minors, and their records may therefore contain information about minor patients. That information is entered by the Agency under its own legal authority and its own notice of privacy practices, and Clistahr processes it solely on the Agency's behalf. Questions about a minor's records in the Service should be directed to the Agency.

Where a law applicable to a User sets an age higher than 16 for consent to processing, and We rely on consent, We may require the consent of that User's parent or guardian.

Links to Other Websites

Our Service may contain links to other websites that are not operated by Us. If You click a third-party link, You will be directed to that third party's site. We strongly advise You to review the privacy policy of every site You visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top.

Where the change is material, We will let You know by email and/or a prominent notice on Our Service before it becomes effective. Changes to Our handling of Agency Data are additionally governed by Our agreements with Agencies.

You are advised to review this Privacy Policy periodically. Changes are effective when posted on this page.

Contact Us

If You have questions about this Privacy Policy or wish to exercise a privacy right, You can contact Us:

  • By email: contact@clistahr.com

  • By using our request form: https://clistahr.com

  • By phone: +1 240-232-7966

  • By mail: Clistahr Technologies, Inc., Attn: Privacy, 6851 Oak Hall Lane, Suite 119, Columbia, MD 21045, United States

If Your question concerns a patient record, a clinical document, a visit record, or an employment record held in an Agency's tenant, please contact that Agency directly. If You are unsure which Agency holds Your information, contact Us and We will try to help You identify the right point of contact.