Privacy & Usage Policy

Last updated August 28, 2026

1. What we collect

  • Staff accounts: name, email, role and organization membership.
  • Client records: the identity, contact, evaluation, invoice and document data your organization enters or that clients submit through the intake and portal links.
  • Operational data: notifications, audit log entries, chat messages and timestamps needed to run the workflow.

2. How we use it

Data is used only to operate the Service for your organization: managing cases, deadlines, payroll, invoices and communications. We do not sell data and we do not use client records for advertising or for training external models.

3. Access control

  • Every record belongs to a single organization and is isolated at the database level.
  • Case managers and therapists see only the cases assigned to them.
  • Payroll is visible only to the staff member it belongs to and the organization owner.
  • Invoices are restricted to owners and explicitly authorized staff.
  • Uploaded files are served through short-lived signed links.

4. Automated notifications

Deadline, ticket, workflow and payroll reminders are sent by email, in-app notification and team chat. Recipients are limited to the people involved in the case and the leadership of the same organization. Each user can adjust channels and timing in Notifications settings.

5. Sub-processors

We rely on infrastructure providers for hosting and database storage, an email delivery provider for transactional messages, and an SMS provider when SMS notifications are enabled. These providers process data only to deliver those functions.

6. Retention and deletion

Records are kept while the organization’s account is active. After termination, data can be exported for 30 days and is then deleted. Owners may request deletion of specific client records at any time, subject to legal retention duties that apply to the organization.

7. Client rights

Clients can request access to, correction of or deletion of their information by contacting the organization handling their case. That organization is responsible for responding; we assist as processor.

8. Acceptable usage

Users must not attempt to view records outside their assignment, share credentials, or export client data to unmanaged devices or services. Access attempts and record changes are written to an append-only audit log.

9. Contact

Privacy questions and data requests: info@rebhumanservices.org.