Privacy Policy
Effective Date: April 3, 2026
1. Introduction
Welcome to CareLog, operated by CareLog Inc. ("CareLog", "we", "us", or "our"). We provide an AI-powered care intelligence platform for senior living communities. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, and related services (collectively, the "Service").
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Resident Data: Health records, care notes, and other sensitive information pertaining to residents of a Facility.
- PHI: Protected Health Information as defined under applicable healthcare laws (e.g., HIPAA).
- Controller: The entity that determines the purposes and means of processing Personal Data (typically the Facility).
- Processor: The entity which processes Personal Data on behalf of the Controller (CareLog).
- User: Any authorized individual accessing the Service, including facility staff and family members.
- Facility: The residential care home or healthcare organization subscribing to the Service.
3. Information We Collect
We collect several categories of information to provide and improve our Service:
- a) Account Information: Name, email address, phone number, job title, and facility details collected during registration.
- b) Resident and Care Data: Health records, care notes, medication logs, incident reports, photos, vitals, behavioral data, and dementia tracking metrics. This data is strictly entered by authorized Facility staff.
- c) Family Portal Data: Messages, visit requests, care goals, and interactions submitted through the family communication portal.
- d) Usage and Technical Data: IP addresses, browser types, device information, session logs, and feature usage analytics.
- e) Payment Data: Billing information processed securely by our payment processor (Stripe). CareLog does not store full credit card numbers.
- f) Communications: Support requests, emails, and feedback provided directly to us.
4. Legal Basis for Processing
We process your data based on the following legal grounds:
- a) Consent: When you explicitly agree to specific processing activities.
- b) Contract Performance: To fulfill our obligations under the Terms of Service with the Facility.
- c) Legitimate Interest: For improving our Service, ensuring security, and conducting necessary analytics.
- d) Legal Obligation: To comply with applicable laws, regulations, or legal processes.
5. How We Use Information
We utilize the collected information to:
- a) Operate, maintain, and provide the features of the Service.
- b) Facilitate care coordination and resident monitoring.
- c) Enable secure family communication and updates.
- d) Process billing and administrative transactions.
- e) Analyze Service usage to improve functionality and user experience.
- f) Ensure platform security, investigate fraud, and enforce our terms.
- g) Power AI-assisted features (e.g., care plan generation, schedule optimization, voice transcription), processed server-side.
6. AI and Automated Processing
CareLog incorporates artificial intelligence to assist with schedule generation, care plan suggestions, and voice transcription.
- a) No Training on User Data: Your Personal Data and Resident Data are NEVER used to train our or third-party AI models.
- b) Human Oversight: All AI-generated outputs are suggestions. Users maintain full control and can request human review or modify any automated suggestions.
7. Data Sharing
We do not sell your Personal Data or Resident Data. We only share information with:
- a) Third-Party Processors: Trusted service providers essential to operating the Service (e.g., hosting providers, Stripe for payments, Resend for email, Cloudinary for media, OpenAI/Google for strict API-based AI processing without data retention).
- b) Legal Requirements: If required by law, court order, or to protect the rights, property, or safety of CareLog, our Users, or the public.
8. Data Ownership
The Facility retains full ownership of all Resident Data entered into CareLog. We act strictly as a Data Processor.
- a) Export: Upon termination, the Facility can export all data in a standard format.
- b) Deletion: Data is permanently deleted within 90 days of account closure unless legal obligations require further retention.
9. Data Security
We implement robust, industry-standard security measures, including:
- a) Encryption in transit (TLS 1.2+) and at rest (AES-256).
- b) Strict role-based access controls (RBAC) and session management.
- c) Comprehensive audit logging for all PHI access and modifications.
- d) Regular security reviews and vulnerability assessments aligned with SOC2 principles.
10. Data Retention
We retain data according to the following schedules:
- a) Account Data: Retained while the account is active, plus 90 days.
- b) Resident Care Data: Retained per the Facility's configured retention policy.
- c) Audit Logs and Incident Reports: Retained for a minimum of 7 years to support compliance.
- d) Billing Records: Retained as required by applicable tax laws.
11. Your Rights
Depending on your jurisdiction, you have the right to access, rectify, erase, restrict, port, or object to the processing of your Personal Data, and to withdraw consent.
- a) Facility Staff and Families: Please direct data requests to your Facility Administrator, who manages the data.
- b) Direct Requests: You may also contact support@carelog.co. We will respond within 30 days.
12. Children's Privacy
The Service is not directed at children under the age of 13. Any Resident Data concerning minors is collected and managed strictly under the legal authority and consent obtained by the Facility.
13. International Data Transfers
CareLog primarily processes data in the United States. For international users, we ensure appropriate safeguards (such as Standard Contractual Clauses) are in place to protect your data across borders.
14. Cookies and Tracking
We use essential cookies necessary for authentication and session management. We do not use third-party advertising cookies. Analytics tracking is only enabled with your explicit consent.
15. HIPAA Considerations
CareLog is designed to support Facility compliance with the Health Insurance Portability and Accountability Act (HIPAA) and similar healthcare regulations.
- a) Business Associate Agreement (BAA): Available upon request for covered entities.
- b) Facility Responsibility: The Facility remains ultimately responsible for ensuring their use of CareLog meets their specific legal and regulatory obligations.
16. Changes to This Policy
We may update this Privacy Policy periodically. We will provide at least 30 days' notice for material changes via email and in-app notifications before they take effect.
17. Contact Us
If you have any questions or concerns regarding this Privacy Policy, please contact our Data Protection Officer at:
- Email: privacy@carelog.co
- Support: support@carelog.co
