Privacy Policy (Draft)
Last updated: July 2026 · Status: draft for legal review
1. Who we are
ABARecords is an electronic medical record (EMR) platform for Applied Behavior Analysis providers. Each provider organization (a "tenant") uses ABARecords to run its own clinical operations.
2. Whose data it is
All clinical and operational data entered into ABARecords belongs to the tenant that entered it. ABARecords acts as a data processor / service provider: we store and process data solely to deliver the service to that tenant. We do not own tenant data, we do not sell it, we do not use it for advertising, and we do not share it across tenants. When a tenant leaves, its data is exported and deleted per the service agreement.
3. What we collect
- Account data: names, work emails and credentials of staff users, for authentication and role-based access.
- Tenant clinical data: records the tenant creates (clients, sessions, notes, plans, assessments). Protected Health Information is handled under HIPAA and the BAA.
- Technical data: security logs (logins, IP, device) kept for auditing and required by HIPAA's Security Rule.
4. How we protect it
Multi-tenant isolation on every record, role-based access control, full audit trail of access and changes, encrypted transport, and least-privilege operations. Public pages (like the login) never expose client data.
5. Your rights
Patients and caregivers exercise their privacy rights (access, amendment, accounting of disclosures) directly with their provider organization, which controls the records. We support tenants in fulfilling those requests.
6. Contact
Privacy questions: contact your organization's administrator, or the platform operator through the support center.