ABANOTES LLC
PRIVACY POLICY
Version 1.0\
Status: Reviewed\
Owner: ABANotes LLC\
Proposed Effective Date: 08/03/2026\
Last Updated: July 31, 2026
Document Control
| Field | Information |
|---|---|
| Document | ABANotes Privacy Policy |
| Version | 1.0 |
| Owner | ABANotes LLC |
| State of Organization | Florida |
| Primary Website | https://abanotes.ai |
| Development Website | https://abanotes.com |
| Products Covered | ABANotes web services and My ABANotes mobile applications |
| Classification | Public |
| Status | Reviewed |
Revision History
| Version | Date | Description | Approval Status |
|---|---|---|---|
| 1.0 | August 3, 2026 | Initial comprehensive Privacy Policy reviewed | Reviewed |
Table of Contents
- Scope and Overview\
- Roles and Relationship to Healthcare Providers\
- Definitions\
- Information We Collect\
- Sources of Information\
- How We Use Information\
- Artificial Intelligence and Human Review\
- Cookies and Similar Technologies\
- My ABANotes Mobile Applications\
- Electronic Signatures and Approvals\
- How We Disclose Information\
- Subprocessors and Service Providers\
- No Sale, Advertising Use, or Cross-Context Tracking\
- Customer and Authorized User Responsibilities\
- Data Retention and Deletion\
- Security\
- Individual Privacy Rights and Requests\
- California Privacy Disclosures\
- Other U.S. State Privacy Laws\
- Children's Privacy\
- International Use and Transfers\
- Third-Party Services and Links\
- Changes to This Policy\
- Relationship to Other ABANotes Documents\
- Contact Us and Complaints
1. Scope and Overview
ABANotes LLC ("ABANotes," "we," "us," or "our") provides a
cloud-based healthcare software platform for Applied Behavior Analysis
and related behavioral-health providers. The platform includes clinical
documentation, assessments and reassessments, scheduling, behavior-data
tracking, protocol-modification documentation, caregiver-training
documentation, supervision documentation, authorization tracking, staff
and client management, billing support, reports, document storage,
electronic signatures, and AI-assisted drafting.
This Privacy Policy ("Policy") explains how ABANotes collects, uses,
discloses, stores, protects, retains, and deletes Personal Information
through:
- https://abanotes.ai and ABANotes-controlled pages that link to this
Policy; - the ABANotes hosted web application;
- the development website at https://abanotes.com, to the extent it
collects Personal Information; - the My ABANotes applications for iOS and Android; and
- related support, security, account-administration, and business
communications.
This Policy applies to information ABANotes processes in its own
capacity and to information it processes for customer organizations. It
is a public disclosure and is not a substitute for the Master
Subscription Agreement, Business Associate Agreement, or other contract
between ABANotes and a customer.
This Policy does not apply to a customer's independent privacy
practices, websites, systems, or handling of information outside the
Services. A customer organization may provide additional privacy notices
that apply to its patients, clients, caregivers, workforce, or other
individuals.
2. Roles and Relationship to Healthcare Providers
2.1 Customer Data
ABA agencies, behavioral-health providers, healthcare organizations, and
other subscribing entities ("Customers") determine why and how
Customer Data is entered into and used through the Services. For
Customer Data, the Customer ordinarily acts as the responsible
healthcare provider, covered entity, business associate, controller, or
business, as applicable. ABANotes ordinarily acts as the Customer's
business associate, subcontractor business associate, processor, service
provider, or contractor.
ABANotes processes Customer Data to provide the Services and as
instructed or authorized by the Customer, the applicable agreements, and
law. If you use ABANotes through an employer, provider, agency, or
caregiver account, that organization generally controls your account and
the records maintained in its tenant.
2.2 Protected Health Information
When ABANotes creates, receives, maintains, or transmits Protected
Health Information ("PHI") for a Customer subject to the Health
Insurance Portability and Accountability Act ("HIPAA"), the executed
Business Associate Agreement ("BAA") governs ABANotes' HIPAA duties.
If this Policy conflicts with an executed BAA regarding PHI, HIPAA
duties, Security Incidents involving PHI, or Breach notification, the
BAA controls.
This Policy is not a healthcare provider's HIPAA Notice of Privacy
Practices. HIPAA does not generally require a business associate to
issue its own Notice of Privacy Practices. Individuals seeking to
exercise HIPAA rights concerning records maintained by a healthcare
provider should ordinarily contact that provider directly.
2.3 Information Controlled Directly by ABANotes
ABANotes may independently control limited information used for its own
business operations, such as website inquiries, prospective-customer
contacts, contract and billing contacts, support communications,
security records, and information about ABANotes' direct business
relationships. This Policy applies to that processing subject to
applicable law.
3. Definitions
For this Policy:
"Authorized User" means an individual whom a Customer authorizes to
access the Services, including an owner, manager, BCBA, BCaBA, RBT,
caregiver, administrator, billing user, or other designated user.
"Customer Data" means information submitted to, stored in, generated
through, or processed in connection with the Services on behalf of a
Customer, including PHI and AI Output retained in the Customer's tenant.
"Personal Information" means information that identifies, relates
to, describes, is reasonably capable of being associated with, or could
reasonably be linked to an individual or household. The term includes
"personal data" and similar terms under applicable privacy laws, but
does not include information excluded by law, such as properly
deidentified or publicly available information where applicable.
"Process" or "Processing" means any operation performed on
information, including collection, access, use, storage, transmission,
disclosure, analysis, retention, or deletion.
"Services" means the ABANotes web platform, My ABANotes mobile
applications, and related hosted features, support, and functionality
provided by ABANotes.
"Subprocessor" means a service provider engaged by ABANotes to
process Customer Data in support of the Services.
4. Information We Collect
The information collected depends on the Customer's configuration, the
user's role, the features used, and the information that the Customer or
user chooses to provide.
4.1 Account, Identity, and Contact Information
We may collect:
- name, email address, telephone number, mailing or business address,
preferred language, and organization; - username, role, agency or tenant affiliation, user and account
identifiers, and account status; - passwords in protected form, password-reset information, session
identifiers, authentication records, and other security credentials; - job title, professional role, credentials, certifications, license
information, NPI, Medicaid enrollment or provider identifiers, CAQH
information, employment or hire information, and related expiration
dates; - business contacts, contract contacts, billing contacts, and support
contacts; and - information used to provision, administer, secure, suspend, or close
an account.
Depending on a Customer's workforce-management configuration, Customer
Data may also include tax or workforce identifiers and documents.
Customers must collect and enter only information that is lawful,
relevant, and reasonably necessary.
4.2 Client, Caregiver, Clinical, and Healthcare Information
Customers and Authorized Users may submit highly sensitive information,
including:
- client or patient names, dates of birth, sex or gender information,
contact information, addresses, preferred language, and caregiver or
family relationships; - diagnoses, diagnosis codes, physician and referral information,
medical history, clinical observations, functional assessments,
reassessments, treatment plans, behavior plans, progress data, and
outcome data; - session schedules, service locations, attendance, participants,
service codes, units, clinician assignments, supervision records,
and visit documentation; - behavior-reduction data, skill-acquisition data, caregiver-training
data, protocol modifications, incident or safety information, and
narrative notes; - payer, insurance, Medicaid, authorization, billing-support, and
service-utilization information; - electronic signatures, signer names, approvals, consent records,
signed timestamps, signature images or data, and related audit
evidence; - uploaded documents, images, reports, credentials, forms,
correspondence, and exported records; and - AI Input and AI Output associated with requested documentation
workflows.
This information may constitute PHI, medical information, sensitive
Personal Information, or another legally protected category.
4.3 Technical, Device, Usage, and Security Information
When a person accesses the Services, we or our service providers may
automatically collect:
- IP address, browser type and version, operating system, device type,
application version, language, and general network information; - device or application identifiers that are necessary for
authentication, security, notifications, diagnostics, or service
operation; - login, logout, access-attempt, session, authentication, and
account-security information; - pages, screens, features, buttons, records, and workflows accessed
or used; timestamps; referring pages; and performance information; - crash reports, error messages, application logs, diagnostic data,
and support-related technical information; - audit events, which may include record creation, viewing,
modification, deletion, export, signature, permission, role, and
administrative changes; and - cookie and similar-technology information described in Section 8.
We may derive approximate geographic information from an IP address for
security, fraud prevention, localization, or legal compliance. This is
different from collecting a device's precise GPS location.
4.4 Communications and Support Information
We collect information when a person contacts sales, privacy, security,
legal, billing, or support; submits a form; reports an incident;
participates in training; or otherwise communicates with ABANotes. This
may include message contents, attachments, contact details, support
history, troubleshooting information, and call or meeting notes.
Do not send passwords, authentication secrets, or unnecessary PHI
through ordinary email or public web forms.
4.5 Transaction and Subscription Information
We may collect organization billing details, subscription plan, Order
Form information, invoices, payment status, tax information, and related
transaction records. If payment processing is provided by a third-party
processor, that processor may collect payment-card or bank information
under its own terms. ABANotes should disclose the current payment
processor in the Subprocessor List before enabling such processing.
4.6 Information We Create or Derive
We may create account-status information, security risk indicators,
service metrics, audit records, support classifications, and aggregated
or deidentified analytics. We may use aggregated or deidentified
information only in a form that is not reasonably capable of identifying
a Customer, user, client, patient, or caregiver and does not expose PHI.
5. Sources of Information
We obtain information from:
- Customers and their owners, administrators, workforce members,
contractors, and representatives; - Authorized Users, including clinicians, RBTs, caregivers, and
administrative or billing staff; - individuals who contact ABANotes or visit our websites;
- devices, browsers, mobile operating systems, and the Services during
use; - integrations, vendors, or service providers authorized by ABANotes
or a Customer; - public or professional sources when needed to verify business or
professional information; and - information generated through use of the Services, including audit
events and AI Output.
Customers are responsible for ensuring they have authority to provide
Personal Information to ABANotes and for delivering any notice or
obtaining any authorization or consent required for their collection and
use.
6. How We Use Information
Subject to the applicable Customer agreement and law, ABANotes uses
information to:
- provide, host, configure, maintain, and support the Services;
- authenticate users, maintain sessions, administer roles and
permissions, and manage accounts; - enable clinical, scheduling, assessment, supervision, caregiver,
authorization, reporting, billing-support, document, and signature
workflows; - process Customer-authorized AI-assisted drafting requests;
- store, transmit, back up, restore, export, and delete Customer Data;
- communicate about accounts, support requests, security matters,
service changes, transactions, and legal notices; - monitor availability, diagnose errors, maintain performance, develop
fixes, and improve supported features; - protect confidentiality, integrity, and availability; prevent
misuse; investigate suspicious activity; and respond to security
incidents; - maintain audit trails and evidence of account activity, approvals,
and electronic transactions; - enforce agreements, Acceptable Use requirements, and Customer
instructions; - comply with law, legal process, regulatory requests, professional
obligations, and valid governmental demands; - establish, exercise, or defend legal claims and manage business
risk; - perform accounting, billing, contracting, vendor management,
compliance, and internal administration; and - create and analyze aggregated or properly deidentified service
information consistent with the MSA and BAA.
Where a privacy law requires a legal basis, ABANotes relies, as
applicable, on performance of a contract, legitimate interests in
operating and securing the Services, compliance with legal obligations,
consent, or the Customer's lawful instructions. Customers determine the
legal basis for their own processing of Customer Data.
7. Artificial Intelligence and Human Review
7.1 Assistive Drafting
ABANotes provides AI-assisted drafting features. AI may process
Customer-authorized information to generate draft narratives, summaries,
or related content for the specific workflow requested by an Authorized
User. AI is assistive technology and does not replace professional
judgment, clinical assessment, diagnosis, treatment planning,
supervision, coding, billing review, or payer-compliance review.
7.2 AI Providers
ABANotes may use approved AI providers identified in the then-current
Subprocessor List, including providers such as OpenAI and Anthropic.
Providers and models may change as the Services evolve, subject to the
MSA, BAA, Subprocessor List, and applicable law.
When AI Input contains PHI, ABANotes will use only configurations
approved for the applicable PHI workflow and subject to required
contractual protections. Customer-authorized information is sent only as
necessary to provide the requested AI functionality.
7.3 No General-Purpose Model Training Without Written Authorization
ABANotes does not authorize PHI or other Customer Data submitted through
approved AI workflows to be used to train publicly available or
general-purpose AI models. ABANotes will not use or permit such training
without the Customer's explicit written authorization and any additional
authorization or legal basis required by law. This restriction does not
prohibit service operation, abuse monitoring, or security processing
that is permitted by the applicable agreement and approved
configuration.
7.4 Customer Ownership and Mandatory Review
AI Output generated through or in connection with the Services remains
Customer Data. It is draft content until reviewed and approved by an
appropriately qualified Authorized User. Before AI Output is signed,
submitted, billed, relied upon, or incorporated into a designated
medical or clinical record, the Customer must require a qualified human
to independently verify every material factual statement and assess
clinical accuracy, completeness, medical necessity, payer requirements,
coding, internal policy, and applicable professional standards.
AI Output may be incomplete, inaccurate, biased, inconsistent, or
unsupported by the underlying record. Customers and Authorized Users
must not assume that a fluent or plausible response is correct.
Additional requirements appear in the AI Use & Human Oversight
Policy, MSA, and BAA.
8. Cookies and Similar Technologies
8.1 Essential, Authentication, and Session Technologies
ABANotes uses cookies, local storage, tokens, or similar technologies
that are necessary to:
- authenticate users and maintain secure sessions;
- route users to the correct Customer tenant and role-based
experience; - remember security, session, and limited interface settings;
- protect against fraud, misuse, and unauthorized access; and
- maintain core website and application functionality.
Disabling these technologies may prevent login or cause parts of the
Services to function incorrectly.
8.2 Preference Technologies
We may use preference cookies or local storage to remember choices such
as language, display, workflow, or consent preferences. These
technologies do not authorize a user to bypass Customer-controlled
permissions.
8.3 Performance and Analytics Technologies
As of the Last Updated date, the reviewed ABANotes web application
source did not show third-party advertising analytics or cross-site
tracking technology. ABANotes may use limited first-party or
service-provider performance and analytics technologies to understand
reliability, diagnose errors, measure feature use, and improve the
Services. If ABANotes introduces nonessential analytics, it will update
this Policy and any required consent or cookie controls before or when
the technology is deployed.
8.4 No Advertising Cookies
ABANotes does not use advertising cookies to serve behaviorally targeted
advertisements and does not use PHI for advertising. ABANotes does not
permit third-party advertising networks to track users through the
Services for cross-context behavioral advertising.
8.5 Browser Controls
Users can control cookies through browser or device settings. Essential
technologies cannot always be disabled while continuing to use
authenticated Services. Where applicable law requires consent for
nonessential technologies, ABANotes will provide an appropriate choice
mechanism.
9. My ABANotes Mobile Applications
This Policy applies to My ABANotes for iOS and Android. Mobile
collection depends on the release build, operating system, enabled
features, Customer configuration, and permissions a user grants.
9.1 Camera and Photo or File Access
The application may request camera, photo-library, or file access when a
user chooses to photograph, scan, select, upload, attach, or manage an
authorized document or image. Access is feature-triggered and should be
limited to the content the user selects or captures. Users may deny or
revoke permission in device settings, although the related upload or
capture feature may not function.
9.2 Notifications
The application may request notification permission to deliver
Customer-authorized service reminders, workflow alerts, security
notices, signature or document status, schedule information, or similar
operational communications. Notification content may be visible on a
locked screen depending on device settings. Customers and users should
configure notification previews to protect confidential information and
PHI.
9.3 Microphone
My ABANotes does not intend to access or collect microphone audio unless
ABANotes introduces and clearly discloses an audio-dependent feature and
the user grants operating-system permission. Denying microphone access
would affect only such a feature.
9.4 Location
My ABANotes does not intend to collect precise GPS location unless
ABANotes introduces and clearly discloses a location-dependent feature
and the user grants permission. Service-location information entered
into a schedule or clinical record is Customer Data and is different
from device geolocation. Approximate location may be inferred from IP
address for security or service operation as described in Section 4.3.
9.5 Biometric Authentication
If My ABANotes offers Face ID, Touch ID, fingerprint, or another
device-based biometric login option, biometric matching is performed by
the device operating system. ABANotes does not receive or store the
user's underlying biometric template; it receives only the
authentication result or token needed to unlock the application. Users
may disable biometric access and use an available alternative
authentication method.
9.6 Mobile Diagnostics and Identifiers
The application and its operating-system or infrastructure providers may
process application version, device type, operating-system version,
crash or error information, notification token, security identifiers,
and similar diagnostics needed to operate, secure, and troubleshoot the
application. ABANotes does not use these identifiers for cross-app
advertising or tracking.
9.7 App-Store Disclosures
ABANotes will maintain Apple App Privacy and Google Play Data safety
disclosures that reflect the current production builds and integrated
third-party code. If an app-store disclosure conflicts with this Policy,
ABANotes should investigate and correct the inaccurate disclosure;
neither statement expands ABANotes' contractual authority to process
Customer Data.
10. Electronic Signatures and Approvals
The Services may enable electronic caregiver signatures, clinician
signatures, approvals, acknowledgments, and consents. To support the
integrity and evidentiary value of an electronic transaction, ABANotes
may process:
- the signer's name, role, account, and Customer affiliation;
- the signature image, drawn signature data, typed-signature
selection, or other signature representation; - the document, form, or content presented to the signer, including
version or snapshot; - the date and time of signing or approval;
- IP address, user agent, device or session information, and
authentication evidence; - consent or approval status and related audit events; and
- later modifications, revocations, or administrative actions where
supported.
These records are retained with the associated Customer Data according
to the applicable agreement, Customer instructions, legal obligations,
and Data Retention and Destruction Policy.
The electronic-signature features are intended to support transactions
under the federal Electronic Signatures in Global and National Commerce
Act and applicable state electronic-transaction laws, including
Florida's Electronic Signature Act and Uniform Electronic Transaction
Act. ABANotes does not determine whether a particular document may
lawfully be signed electronically, whether a signer has authority, or
whether a Customer's workflow satisfies a payer, clinical, consent,
recordkeeping, or legal requirement. The Customer is responsible for
those determinations.
11. How We Disclose Information
ABANotes may disclose information in the following circumstances.
"Disclosure" in this section does not mean that ABANotes sells
information.
11.1 Customer Organizations and Authorized Users
We disclose Customer Data within the Customer's tenant according to
configured roles, permissions, client or team assignments, workflows,
and Customer instructions. Customer administrators may access and manage
Authorized User accounts and Customer Data. Depending on role and
configuration, information may be available to owners, managers,
clinicians, RBTs, caregivers, administrative staff, billing staff, or
other Customer-authorized persons.
11.2 Subprocessors and Service Providers
We disclose information to approved providers that support hosting,
storage, backups, security, AI processing, email, communications,
document handling, support, diagnostics, and other service functions.
These providers may include cloud infrastructure providers, AI providers
such as OpenAI and Anthropic, and Zoho for email-related services, as
identified in the Subprocessor List. They may process information only
for authorized services and under applicable contractual restrictions.
11.3 Customer-Directed Disclosures and Integrations
We disclose information when a Customer or Authorized User directs an
export, report, email, download, integration, signature workflow, or
transmission. Customers are responsible for destination security,
recipient authority, minimum-necessary decisions, and subsequent use
outside ABANotes-controlled systems.
11.4 Professional Advisers and Business Operations
We may disclose information to attorneys, auditors, insurers,
accountants, consultants, and other professional advisers who need it to
provide services, protect legal rights, manage risk, or support
compliance. PHI will be disclosed only as permitted by the BAA and law.
11.5 Legal Compliance, Safety, and Protection of Rights
We may disclose information when we reasonably believe disclosure is
required by law, regulation, subpoena, court order, or valid
governmental request; is necessary to cooperate with regulators or law
enforcement; or is appropriate to protect rights, safety, security,
property, or the integrity of the Services. We will apply applicable
contractual and legal safeguards and, when permitted, notify the
Customer.
11.6 Business Transfers
Information may be disclosed in connection with a proposed or completed
merger, financing, acquisition, reorganization, sale of assets,
bankruptcy, or similar business transaction. Any successor remains
subject to applicable law, contracts, and BAA obligations for PHI. Where
required, we will provide notice or obtain consent.
11.7 With Consent or Authorization
We may disclose information for another purpose when the individual,
Customer, or other legally authorized person provides valid consent,
direction, or authorization.
12. Subprocessors and Service Providers
ABANotes uses approved Subprocessors to provide parts of the Services.
Categories may include:
- cloud infrastructure, database, storage, backup, and
content-delivery providers; - AI model and AI infrastructure providers;
- email and service-communication providers;
- security, monitoring, logging, diagnostics, and incident-response
providers; - document generation, electronic-signature support, and
file-processing providers; - customer support and business-operation providers; and
- payment or billing providers, if enabled.
Examples include Amazon Web Services, OpenAI, Anthropic, and Zoho. The
authoritative, current list is the ABANotes Subprocessor List.
ABANotes may add, replace, or remove Subprocessors in accordance with
the MSA, BAA, Subprocessor List, and applicable law. Subprocessors that
create, receive, maintain, or transmit PHI must be subject to
appropriate downstream business-associate protections before processing
PHI.
13. No Sale, Advertising Use, or Cross-Context Tracking
ABANotes does not:
- sell Personal Information or PHI for monetary or other valuable
consideration; - share Personal Information for cross-context behavioral advertising;
- use or disclose PHI for advertising;
- use Customer Data to build advertising profiles;
- permit advertising networks to track users across unrelated
applications or websites through the Services; or - use Customer Data to train publicly available or general-purpose AI
models without the explicit written authorization and legal
permissions described in Section 7.3.
ABANotes does not offer financial incentives in exchange for Personal
Information. If these practices change, ABANotes will update its
disclosures and provide any rights, notices, consent, or opt-out
mechanisms required by law before the new practice begins.
14. Customer and Authorized User Responsibilities
Customers determine and are responsible for:
- the purposes and lawful basis for processing Customer Data;
- notices, authorizations, consents, and permissions required from
clients, patients, caregivers, workforce members, or others; - HIPAA compliance and execution of a BAA before PHI processing
begins; - minimum-necessary determinations and limits on information entered
or disclosed; - user provisioning, role assignment, client or team assignment,
access review, and prompt deactivation of former users; - workforce screening, training, supervision, sanctions, and
professional licensing; - the accuracy, completeness, relevance, and lawfulness of Customer
Data; - clinical decisions, medical necessity, payer requirements, coding,
billing, and human review of AI Output; - security of endpoints, mobile devices, credentials, networks,
printed records, exports, downloads, and systems outside ABANotes'
control; and - responding to privacy-rights requests for records the Customer
controls, with ABANotes' assistance where required by contract or
law.
Authorized Users must keep credentials confidential, use only their own
accounts, follow Customer policies, limit access to authorized purposes,
protect displayed and exported information, and promptly report
suspected misuse or compromise.
15. Data Retention and Deletion
15.1 Retention Criteria
Retention periods vary according to:
- the MSA, BAA, Order Form, and Customer instructions;
- the duration of the Customer relationship and account;
- healthcare, payer, licensing, tax, employment, and recordkeeping
requirements; - legal, regulatory, audit, security, fraud-prevention, and
dispute-resolution needs; - litigation holds, subpoenas, investigations, and preservation
duties; and - the nature and sensitivity of the information and the purposes for
processing it.
The Data Retention and Destruction Policy and any applicable
retention schedule provide additional operational detail. Customers are
responsible for selecting and applying retention periods to Customer
Data when the Services provide configuration options and for exporting
records they must preserve.
15.2 Account Closure and Customer Data Return
Upon termination or account closure, access, export, return, retention,
and deletion of Customer Data are governed by the MSA, BAA, Data
Retention and Destruction Policy, Order Form, Customer instructions, and
law. A request to close an individual Authorized User account does not
automatically delete clinical or organizational records that belong to
the Customer or must be retained.
15.3 Backups and Residual Copies
Secure backup media are retained according to ABANotes' documented
backup lifecycle and are not routinely restored except for disaster
recovery, business continuity, security, legal necessity, or validated
restoration testing. Deleted information may remain in encrypted or
otherwise protected backups until overwritten or expired in the ordinary
backup cycle. While retained, residual copies remain protected and are
not returned to ordinary production use except as necessary for an
authorized restoration or legal purpose.
15.4 Secure Deletion
When deletion is required and feasible, ABANotes uses deletion or
destruction methods reasonable and appropriate to the media, data
sensitivity, system architecture, contractual obligations, and
applicable law. ABANotes may retain limited records necessary to
document deletion, comply with law, resolve disputes, prevent fraud, or
enforce agreements.
16. Security
ABANotes maintains administrative, technical, and physical safeguards
reasonably and appropriately designed to protect the confidentiality,
integrity, and availability of information. Depending on the system and
risk, safeguards may include:
- encryption in transit and at rest;
- authentication, session management, password controls, and
role-based access; - logical tenant isolation and Customer-scoped access controls;
- audit, activity, security, and system logging;
- backups, restoration procedures, business continuity, and disaster
recovery planning; - vulnerability, configuration, change, and vendor-risk management;
- access authorization, workforce confidentiality, training, and
incident-response procedures; and - controls appropriate to cloud infrastructure, ABANotes-controlled
devices, facilities, and media.
No system, transmission, or storage method is completely secure.
ABANotes does not guarantee absolute security, uninterrupted
availability, or that every attempted attack will be prevented.
Customers and users share responsibility for security as described in
Section 14, the MSA, BAA, and Security Overview.
Report suspected security issues promptly to security@abanotes.ai.
Do not include passwords, secret keys, or unnecessary PHI in an initial
email. Incident and Breach duties involving PHI are governed by the BAA
and the Incident Response & Breach Notification Policy.
17. Individual Privacy Rights and Requests
Depending on the law, the type of information, applicable exemptions,
and ABANotes' role, an individual may have rights to:
- request access to or a copy of Personal Information;
- request correction of inaccurate Personal Information;
- request deletion of Personal Information;
- request restriction of or object to certain processing;
- request data portability, where applicable;
- withdraw consent for future processing where consent is the legal
basis; - close an individual account;
- appeal a denied request where applicable; and
- submit a complaint without unlawful discrimination or retaliation.
17.1 Requests Concerning Customer-Controlled Records
If your information was submitted by or on behalf of an ABA agency,
healthcare provider, employer, or other Customer, contact that Customer
first. ABANotes generally cannot alter or delete Customer-controlled
clinical, employment, billing, signature, or healthcare records without
the Customer's instruction. ABANotes will assist the Customer as
required by the MSA, BAA, or applicable law.
17.2 Requests to ABANotes
Requests may be submitted to privacy@abanotes.ai. Include your name,
contact information, relationship to ABANotes or the relevant Customer,
the right requested, and enough detail to identify the information. Do
not send unnecessary medical details or credentials by email.
ABANotes may verify identity and authority before acting. Verification
may require account authentication, confirmation through a known contact
method, or documentation of authority. An authorized agent may submit a
request where permitted by law, but ABANotes may require proof of
authorization and direct identity verification.
ABANotes may deny or limit a request when permitted or required by law,
including when information must be retained for healthcare records,
legal compliance, security, fraud prevention, claims, litigation holds,
or the rights of others. ABANotes will explain a denial and any
available appeal or complaint route when required.
17.3 Account Deletion
Users may request account closure through available in-app or web
account controls, their Customer administrator, or
support@abanotes.ai. Google Play and other platform requirements may
require a clear account-deletion request method. Account closure ends
access but does not necessarily delete Customer-controlled records or
information subject to lawful retention.
18. California Privacy Disclosures
This section applies only to the extent the California Consumer Privacy
Act, as amended by the California Privacy Rights Act ("CCPA"),
applies to ABANotes and the relevant information.
18.1 Categories Collected and Purposes
During the preceding 12 months, ABANotes may have collected the
following CCPA categories, depending on use of the Services:
| CCPA Category | Examples | Business or Commercial Purposes | Categories of Recipients |
|---|---|---|---|
| Identifiers | Name, email, phone, address, IP address, account and professional identifiers | Provide accounts and Services; authentication; support; security; contracting | Customer and Authorized Users; infrastructure, email, security, and support providers |
| Customer records information | Contact, employment, professional, insurance, provider, and account information | Customer administration; workforce and clinical workflows; support | Customer and Authorized Users; approved service providers |
| Protected classifications | Age or date of birth, sex or gender, disability or health-related information where entered | Customer-directed healthcare and workforce workflows | Customer and Authorized Users; approved PHI-handling providers |
| Commercial information | Subscription, transaction, invoice, service, and authorization information | Contracting, billing, service administration, and reporting | Customer; billing, accounting, and service providers |
| Internet or electronic activity | Login, audit, session, device, browser, usage, and diagnostic information | Operate, secure, troubleshoot, and improve Services | Infrastructure, security, diagnostics, and support providers |
| Geolocation data | Approximate location inferred from IP; service location entered in records | Security, localization, scheduling, and Customer-directed documentation | Customer and Authorized Users; infrastructure and security providers |
| Professional or employment information | Role, employer, license, credentials, NPI, certification, training, and supervision data | User authorization, workforce management, credential tracking, supervision | Customer and Authorized Users; approved service providers |
| Education information | Training, certification, competency, or education records entered by Customer | Workforce qualification and compliance workflows | Customer and Authorized Users |
| Sensitive Personal Information | Account credentials, health information, precise identifiers, signature data, government or provider identifiers, and contents of certain communications | Authentication, healthcare Services, signatures, compliance, and security | Customer and Authorized Users; approved providers as necessary |
| Inferences | Security indicators, account or usage classifications | Security, fraud prevention, support, and service administration | Customer where applicable; security and support providers |
Sources are described in Section 5. Purposes are described more fully in
Section 6. Retention is described in Section 15.
18.2 California Rights
Subject to applicability and exceptions, California residents may
request to know, access, correct, or delete Personal Information and may
obtain information about categories, sources, purposes, and recipients.
They may also opt out of sale or sharing and limit certain uses or
disclosures of Sensitive Personal Information where those practices
occur.
ABANotes does not sell Personal Information or share it for
cross-context behavioral advertising and does not use Sensitive Personal
Information to infer characteristics beyond purposes permitted without a
right to limit. Therefore, ABANotes does not currently provide a "Do Not
Sell or Share My Personal Information" link. If its practices change,
ABANotes will provide required mechanisms before the change begins.
ABANotes will not unlawfully discriminate against a person for
exercising a CCPA right.
18.3 HIPAA and Other Exemptions
The CCPA contains exemptions for certain medical information and PHI
governed by specified healthcare privacy laws, and for certain entities
or data practices. These exemptions do not necessarily apply to every
piece of information ABANotes processes. ABANotes will assess each
request and exemption based on the applicable information and its role
and will not treat all account, workforce, website, or business-contact
information as automatically exempt merely because ABANotes serves
healthcare Customers.
19. Other U.S. State Privacy Laws
Residents of other states may have rights similar to those described in
Section 17, depending on the applicable law and exemptions. State
comprehensive privacy laws commonly apply based on thresholds, entity
status, data type, and processing purpose. HIPAA-regulated PHI or
healthcare entities may be exempt in whole or in part under some state
laws, while other information may remain covered.
ABANotes does not overstate the applicability of any state law. It will
evaluate requests based on the requester's state, the information
involved, ABANotes' role, statutory thresholds, Customer instructions,
and applicable exemptions. Where a state law provides an appeal right, a
requester may appeal by replying to the decision or writing to
privacy@abanotes.ai with "Privacy Appeal" in the subject line. If an
appeal is denied, ABANotes will provide any regulator complaint
information required by law.
State health-data, biometric, employment, breach-notification, and
electronic-transaction laws may impose duties separate from
comprehensive consumer privacy laws. Customers remain responsible for
laws applicable to their healthcare and employment activities.
20. Children's Privacy
The Services are intended for healthcare organizations, healthcare
professionals, workforce members, and authorized caregivers. They are
not directed to children for independent consumer use, and ABANotes does
not knowingly invite children to create general consumer accounts.
Customers may use the Services to process information about child
clients or patients solely in connection with healthcare,
behavioral-health, caregiver, and administrative services. In that
context, ABANotes processes the information on behalf of the Customer
under the Customer's instructions, the applicable agreements, and law.
The Customer is responsible for parental permission, legal authority,
notices, consents, and any obligations under HIPAA, state minor-consent
laws, or the Children's Online Privacy Protection Act where applicable.
If a parent or guardian believes a child provided Personal Information
directly to ABANotes outside an authorized Customer relationship,
contact privacy@abanotes.ai. ABANotes will investigate and take
appropriate action.
21. International Use and Transfers
The Services are primarily intended for Customers located in the United
States. Information may be processed in the United States and in other
jurisdictions where approved providers operate, as identified or
described in the Subprocessor List.
If ABANotes offers Services involving international processing, it will
use contractual, organizational, or technical safeguards required by
applicable law. Customers must not use the Services in a jurisdiction
where doing so would violate applicable law, an Order Form, export
restrictions, sanctions, or an AI provider's geographic restrictions.
International Customers should consult ABANotes before submitting
regulated health information.
22. Third-Party Services and Links
The Services may contain links to third-party websites, app stores,
integrations, or services. A Customer may also export or transmit
information to third parties it selects. ABANotes does not control the
independent privacy practices of those third parties. Review their
privacy notices before providing information.
An approved Subprocessor processing information for ABANotes is subject
to ABANotes' applicable contractual and vendor-management requirements;
this Section does not reduce those obligations.
23. Changes to This Policy
ABANotes may update this Policy to reflect changes in the Services,
technology, law, subprocessors, or privacy practices. The revised Policy
will identify the new "Last Updated" date and version.
For material changes, ABANotes will provide reasonable notice through
the Services, website, email, Customer administrator, app-store release
information, or another appropriate method before or when the change
takes effect, as required by law. If consent is legally required,
ABANotes will seek it before applying the change to the affected
processing.
Previous versions may be retained for compliance and version-history
purposes. Continued use after the effective date of an updated Policy
does not waive rights that cannot lawfully be waived and does not
independently expand ABANotes' authority under the MSA or BAA.
24. Relationship to Other ABANotes Documents
This Policy should be read with the following documents, as applicable:
- Master Subscription Agreement (MSA): commercial, subscription,
licensing, Customer Data, security, AI, service, and liability
terms; - Business Associate Agreement (BAA): HIPAA duties for PHI,
Security Incidents involving PHI, Breach notification,
individual-rights assistance, and return or destruction; - Terms of Service: terms applicable to website or other users not
governed solely by an executed MSA; - Security Overview: summary of administrative, technical, and
physical safeguards; - Data Retention and Destruction Policy: retention schedules,
backup lifecycle, return, deletion, and destruction procedures; - AI Use & Human Oversight Policy: approved AI use, prohibited
use, provider controls, and mandatory human review; - Incident Response & Breach Notification Policy: incident
identification, escalation, response, cooperation, and notice
procedures; - Subprocessor List: current providers, functions, and processing
locations or categories; - Cookie Policy, if separately published: detailed cookie
inventory and user controls; - Electronic Signature & Consent Policy: signature workflows,
audit evidence, Customer responsibilities, and retention; and - Acceptable Use Policy, Support Policy, Service Level Objectives,
Disaster Recovery Overview, and Business Continuity Summary:
additional operational requirements and commitments.
If this Policy conflicts with an executed agreement, the order of
precedence in that agreement controls. In particular, the BAA controls
for PHI, HIPAA obligations, Security Incidents involving PHI, and Breach
notification.
25. Contact Us and Complaints
ABANotes LLC\
Florida, United States\
Website: https://abanotes.ai
Privacy inquiries and rights requests: privacy@abanotes.ai\
Security reports: security@abanotes.ai\
Technical and account support: support@abanotes.ai\
Legal notices and inquiries: legal@abanotes.ai
If you have a concern about Customer-controlled clinical or healthcare
information, contact the relevant ABA agency, behavioral-health
provider, healthcare organization, or Customer first. You may also
contact ABANotes at the addresses above.
ABANotes will not unlawfully retaliate or discriminate against a person
for submitting a good-faith privacy or security complaint. Individuals
may also have the right to complain to a state attorney general, state
privacy regulator, the California Privacy Protection Agency, the U.S.
Department of Health and Human Services Office for Civil Rights, or
another competent authority, depending on the information and law
involved.
End of ABANotes Privacy Policy --- Version 1.0