Privacy Policy

Last updated: May 12, 2026

1. Introduction

Immaculate.Care ("Company," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your information when using our platform.

2. Information We Collect

We collect information you provide directly to us, such as:

  • Account registration information (name, email, facility information)
  • Care recipient medical data (health logs, vitals, medications, health predictions)
  • Staff and caregiver information (including wellness and burnout scores)
  • Family and advocate information (for engagement and matching)
  • Financial data (costs, billing, labor optimization)
  • Usage data and logs (for compliance and quality improvement)
  • Communication records (messages, alerts, notifications)
  • Photographs and documentation (uploaded with consent)

3. HIPAA Compliance

Immaculate.Care complies with the Health Insurance Portability and Accountability Act (HIPAA). We maintain appropriate safeguards for Protected Health Information (PHI) including:

  • Encryption of data at rest and in transit
  • Access controls and authentication
  • Comprehensive audit logging
  • Business Associate Agreements (BAA) for covered entities

4. How We Use Your Information

We use collected information to:

  • Provide and maintain our services
  • Improve care delivery and outcomes through analytics
  • Generate predictive health alerts to prevent hospitalizations
  • Facilitate volunteer advocate matching for resident engagement
  • Monitor caregiver wellness to prevent burnout
  • Optimize schedules fairly while reducing costs
  • Track and prevent incidents before they occur
  • Provide cost transparency and financial reporting
  • Send alerts and notifications based on resident and staff needs
  • Support compliance with HIPAA, CMS, and regulatory requirements
  • Enhance platform functionality and user experience

5. Data Sharing

We do not share your personal information with third parties except:

  • With authorized care team members (nurses, doctors, supervisors)
  • Family members with explicit resident/guardian consent
  • Volunteer advocates matched to residents (limited to relevant information)
  • Legal and regulatory compliance requirements (law enforcement, health agencies)
  • Business partners under Business Associate Agreements (payment processors, email providers, hosting providers)
  • Healthcare providers with proper authorization for continuity of care
  • We NEVER sell personal or health information to third parties
  • We NEVER use health data for marketing without explicit opt-in consent

6. Data Retention

We retain personal information for as long as necessary to provide services and comply with legal obligations. HIPAA-covered entities may retain medical records per regulatory requirements (typically 6+ years).

7. Your Rights

You have the right to:

  • Access your information
  • Request corrections to your data
  • Request deletion (subject to legal holds)
  • Opt-out of non-essential communications
  • Export your data in standard formats

8. Security Measures

We implement industry-standard security measures including:

  • AES-256 encryption for sensitive data
  • TLS 1.3 for data in transit
  • Regular security audits and penetration testing
  • Multi-factor authentication
  • Role-based access controls

9. Third-Party Services

We use the following third-party services under Data Processing Agreements:

  • AWS (Cloud hosting) - encrypted data centers
  • SendGrid (Email delivery) - HIPAA-compliant email
  • Stripe (Payment processing) - PCI DSS Level 1 certified
  • All vendors sign Business Associate Agreements committing to HIPAA compliance

10. Data Deletion & Privacy Requests

You can request:

  • Access to your personal and health information
  • Correction of inaccurate data
  • Deletion of your account and related data (with legal hold exceptions)
  • Export of your data in standard formats
  • Opt-out from non-essential communications
  • Withdrawal of consent for data processing

Requests are typically processed within 30 days. We may retain data longer if required by law.

11. Children's Privacy

Immaculate.Care is not intended for children under 13. We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information and terminate the child's account.

12. International Data Transfers

Your information may be stored and processed in the United States. By using Immaculate.Care, you consent to the transfer of your information to the United States, where privacy laws may differ from your home country.

13. Privacy Policy Changes

We may update this Privacy Policy periodically. We will notify you of significant changes via email or by posting the updated policy on our website. Your continued use of Immaculate.Care after changes constitutes your acceptance of the updated policy.

14. Contact Us

For privacy questions, to exercise your rights, or to report a privacy violation, contact:

Privacy Officer
Immaculate.Care
Email: richy@immaculate.care
Phone: 1-800-CARE-NOW
Response time: Within 5 business days