Privacy
Privacy Policy
What we collect, why, how long we keep it, and what you can ask for.
What we collect
When you create an account or run a Risk Analysis we collect your name, work email, practice name, vertical, primary state, and the answers you provide to our questionnaires. When you submit intake we also collect your staff roster (name, work email, role), vendor list, and a baseline attestation. If you upload a logo we store it in a private Supabase Storage bucket.
Why we collect it
To generate your HIPAA compliance pack, your BAAs, your Audit Pack, and your training assignments. To deliver email and Slack notifications to your designated contacts. To meet our 72-hour deployment SLA and our written guarantee. We do not sell, rent, or trade your data, ever.
Who can see it
Your data is row-level-secured by your customer_id. Authenticated users see only their own practice. Our service role is used by trusted server-side processes (Stripe webhooks, the provisioning runner, scheduled jobs). We do not give individual Honest Comply employees portal access to customer data without a documented support reason.
How long we keep it
For the life of your subscription, plus six years after termination to satisfy HIPAA documentation retention (45 CFR 164.530(j)(2)). You may request deletion of marketing data at any time. Audit-defensible training completion records and immutable audit logs are retained for the full six-year window even after deletion requests.
Your rights
Email privacy@honestcomply.com to request a copy of your data, deletion of marketing data, or to ask us to stop processing your data for a specific purpose. We respond within 30 days. If you are in California you have CPRA rights; if you are in Europe you have GDPR rights; the same email serves both.
