LEGAL
Privacy Policy
Practella is a marketing and patient-engagement platform for chiropractic practices. This policy explains what information we collect, how we use and protect it, and the choices you have.
Practices trust us with their patients' information, and we treat it accordingly: we use it only to run Practella for that practice, and we never sell it.
1. Who is responsible for your information
Practella plays two different roles, and which one applies depends on whose information it is:
- For practices' patient and contact information (the contacts, appointments, messages, form submissions and other records a practice keeps in Practella), the practice is in control. We process that information only on the practice's behalf and under its instructions. Where a practice is a covered entity under HIPAA, we act as its business associate and protect protected health information (PHI) as our Business Associate Agreement with that practice requires. If you're a patient, contact your practice about your information; we'll help them respond.
- For everyone else (people who sign up for or use a Practella account, and visitors to our own website), [Legal entity name] is responsible for the information described in this policy.
2. Information we collect
Account information
When a practice signs up or adds staff, we collect names, work email addresses, a password (stored only as a one-way hash), roles, and practice details such as name, phone, website, address and timezone.
Billing information
Subscriptions are paid through Stripe. Stripe collects and stores card details; we never see or store full card numbers. We keep the Stripe customer and subscription identifiers, plan, status and renewal date.
Practice data
Information practices put into Practella or collect through it: contacts and patients (which can include contact details, date of birth, insurance details, clinical notes and intake answers), appointments, conversations, campaigns, forms and their submissions, media, and social posts. Patients and leads provide some of this directly, for example by submitting a practice's form or booking online.
Usage and security information
To keep accounts secure we record sign-ins and sessions (IP address, browser user agent, times), failed sign-in attempts, and an audit trail of actions taken in the app. We also log the account emails we send (recipient, subject, type, delivery status) but not their contents.
Information from connected services
When a practice connects another service (for example social networks, Google Drive, Dropbox or Stripe), we receive the access tokens and account details needed to use it on the practice's behalf.
3. How we use information
- To provide Practella: running the features each practice uses, such as sending their campaigns, publishing their posts, and taking their bookings.
- To create and secure accounts: verifying email addresses, sending sign-in codes, detecting suspicious activity, and keeping audit trails.
- To bill for subscriptions and measure usage against plan allowances.
- To send account emails such as welcome messages, address confirmations, subscription notices and support replies.
- To provide support, including, when a practice asks for help, viewing its account as its staff would. Those visits are recorded in the practice's audit trail.
- To meet legal obligations and enforce our Terms of Service.
We don't sell personal information, we don't use practice data or PHI for advertising, and we don't use it for any purpose a practice hasn't asked us to, except as the law requires.
5. How we protect information
- Connections to Practella use HTTPS.
- Patients' insurance and clinical details are encrypted in the database with a separate key, and stored credentials for connected services are encrypted as well.
- Sessions sign out automatically after a period of inactivity and expire after a fixed time. Repeated failed sign-ins lock an account temporarily, and two-step verification is available for every user.
- Access to patient records is logged in an audit trail, and staff permissions are limited by role.
- Each practice's data is kept separate from every other practice's.
No system is perfectly secure. If a breach affects your information, we'll notify the affected practices and people as the law and our agreements require.
6. How long we keep information
We keep account and practice data for as long as the practice's account is open. Practices can delete their records in the app at any time. After an account closes, we delete its practice data within [30] days, unless the law requires us to keep it longer or the practice asks us to return it first. Account email logs are deleted after 90 days. Billing records are kept as long as tax and accounting rules require.
7. Cookies and browser storage
Practella keeps your sign-in session and a few display preferences (such as a collapsed sidebar) in your browser's local storage. We don't use advertising cookies. Practices may add Google Analytics to their own landing pages and forms, which uses Google's cookies; see the practice's privacy notice for details.
8. Your choices and rights
- Account users can view and update their profile in Settings, and can ask us to access, correct, export or delete their information by contacting us.
- Patients and leads should contact the practice, which controls their records. You can unsubscribe from a practice's campaign emails with the link in each one, and stop its text messages by replying STOP.
- Depending on where you live, you may have additional rights, such as to know what we hold about you, to have it deleted or corrected, and not to be treated differently for using these rights. We'll respond to verified requests as the law requires.
9. Children
Practella accounts are for businesses and their adult staff. We don't knowingly collect information from children for our own purposes. Practices may keep records about minor patients, which we handle only on the practice's instructions as described above.
10. Changes to this policy
We'll post any changes here and update the effective date. If a change is significant, we'll also tell account owners by email or in the app before it takes effect.
Contact us
Questions about this document? Email our support team, or write to [Legal entity name], [Mailing address].