This week: Summer's-End Setup ยท Defender $399 โ†’ $299Live in 72 hoursZero sales callsBacked by a written refundThis week: Summer's-End Setup ยท Defender $399 โ†’ $299Live in 72 hoursZero sales callsBacked by a written refundThis week: Summer's-End Setup ยท Defender $399 โ†’ $299Live in 72 hoursZero sales callsBacked by a written refund
Honest Comply

Privacy

Privacy Policy

What we collect, why, how long we keep it, and what you can ask for.

What we collect

When you create an account or run a Risk Analysis we collect your name, work email, practice name, vertical, primary state, and the answers you provide to our questionnaires. When you submit intake we also collect your staff roster (name, work email, role), vendor list, and a baseline attestation. If you upload a logo we store it in a private Supabase Storage bucket.

Why we collect it

To generate your HIPAA compliance pack, your BAAs, your Audit Pack, and your training assignments. To deliver email and Slack notifications to your designated contacts. To meet our 72-hour deployment SLA and our written guarantee. We do not sell, rent, or trade your data, ever.

Who can see it

Your data is row-level-secured by your customer_id. Authenticated users see only their own practice. Our service role is used by trusted server-side processes (Stripe webhooks, the provisioning runner, scheduled jobs). We do not give individual Honest Comply employees portal access to customer data without a documented support reason.

How long we keep it

For the life of your subscription, plus six years after termination to satisfy HIPAA documentation retention (45 CFR 164.530(j)(2)). You may request deletion of marketing data at any time. Audit-defensible training completion records and immutable audit logs are retained for the full six-year window even after deletion requests.

Your rights

Email privacy@honestcomply.com to request a copy of your data, deletion of marketing data, or to ask us to stop processing your data for a specific purpose. We respond within 30 days. If you are in California you have CPRA rights; if you are in Europe you have GDPR rights; the same email serves both.