CodaPath Privacy Policy

Effective date: [INSERT EFFECTIVE DATE]

This Privacy Policy includes CodaPath’s Washington Consumer Health Data Privacy Notice. It explains how CodaPath LLC (“CodaPath,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information through codapath.net, our public marketing website, the authenticated clinician application, client-portal functions, and related communications and support (collectively, the “Service”).

This policy should be read with the CodaPath Clinician Terms of Service and any separate Client Portal Terms. It does not replace any privacy notice or consent that a clinician, clinic, school, employer, or other organization is independently required to provide.

1. Scope and our privacy roles

This policy applies to individual clinician subscribers, website visitors, adults who access the client portal, and people who contact CodaPath. The individual subscription is intended for clinicians, not for independent use by children. Organization use is governed by a separate written license and may be subject to additional privacy terms.

CodaPath determines how clinician account, billing, website, support, and security information is handled for its own business purposes. For coded client information entered by a clinician, the clinician generally selects the information and directs its use through the Service, and CodaPath processes it to provide the requested functionality. Our legal role may vary by data, relationship, and applicable law.

CodaPath is not a healthcare provider and the individual subscription is not an electronic health record. It is designed for coded, non-identifying information and is not intended or authorized to receive protected health information (“PHI”). CodaPath does not enter into a HIPAA business associate agreement for individual subscriptions. This policy is not a HIPAA Notice of Privacy Practices.

2. Information we collect

We collect only the information described below, subject to the configuration and bracketed confirmations that must be completed before publication.

3. Client information the Service is designed not to collect

CodaPath does not request or provide fields for client names, initials, schools, email addresses, dates of birth, street addresses, telephone numbers, diagnoses, medical-record numbers, health-plan numbers, or a key that maps a client code to a person. CodaPath does not store clinician narrative journal notes. The Service uses structured fields and technical controls designed to prevent prohibited identifiable information from being submitted or uploaded.

A random client code is not derived from client information. Any external mapping between a client code and a person must remain outside CodaPath and under the clinician’s control. Users must not place identifying information in goals, titles, filenames, metadata, screenshots, support messages, or other fields.

The Service stores session dates. Users must not combine a date with information that identifies or reasonably permits identification of a client. Whether information is “personal information,” “consumer health data,” “PHI,” or deidentified is determined by applicable law and the surrounding facts, not by this policy alone.

4. Sources of information

5. How we use information

CodaPath does not use identifiable Subscriber Content or coded client data to train public or third-party artificial-intelligence models. [CONFIRM WHETHER ANY PRIVATE AI FEATURE OR VENDOR PROCESSES SERVICE DATA; IF NONE, STATE “NO AI FEATURE OR VENDOR PROCESSES SERVICE DATA.”]

6. How we disclose information

We may disclose information only as described below. “Disclose” and “share” in this general section are used in their ordinary sense; laws may define “share,” “sale,” or similar terms differently.

Service-provider register to complete

No sale, targeted advertising, or model training

CodaPath does not sell personal information or consumer health data. CodaPath does not share personal information for cross-context behavioral advertising or use coded client data for targeted advertising. CodaPath does not allow advertising networks to collect data in authenticated areas. CodaPath does not use identifiable Subscriber Content or coded client data to train public or third-party AI models. [COUNSEL/ENGINEERING: CONFIRM THESE STATEMENTS AGAINST ALL CURRENT VENDORS, SDKs, PIXELS, AND CONTRACTS.]

7. Cookies and online tracking

The public marketing website is hosted on Wix. Wix and [IDENTIFY OTHER MARKETING-SITE PROVIDERS] may place cookies or use similar technology to provide the site, maintain security, remember choices, and [DESCRIBE ANALYTICS, IF USED]. The authenticated CodaPath application is hosted separately from Wix.

CodaPath does not use advertising pixels or session-replay tools in authenticated areas. [CONFIRM WHETHER FIRST-PARTY OR PRODUCT ANALYTICS OPERATE AFTER LOGIN. IF YES, IDENTIFY THE PROVIDER, DATA, PURPOSE, RETENTION, AND OPT-OUT.]

You can adjust browser settings and, where available, use our cookie controls at [COOKIE SETTINGS LINK]. Blocking essential cookies may prevent parts of the Service from working.

California Do Not Track disclosure. Some browsers offer a “Do Not Track” signal. Because there is no uniform industry response, our Service [DOES / DOES NOT] respond to that signal. We honor legally required opt-out preference signals, such as Global Privacy Control, where they apply. Because CodaPath does not sell personal information or use it for cross-context behavioral advertising, such a signal generally does not change those practices. [CONFIRM TECHNICAL HANDLING BEFORE PUBLICATION.]

8. Coded client data and HIPAA

The individual CodaPath Service is designed for coded information and is not intended or authorized to receive PHI. It does not collect the client identifiers listed in Section 3, a re-identification key, diagnoses, or narrative clinical notes. The Service’s acceptance of structured data or session dates is not a representation that a clinician’s particular use satisfies a HIPAA deidentification method or an employer’s policies.

A clinician remains responsible for deciding whether information may lawfully be entered, maintaining any external mapping separately, obtaining required permissions, and keeping any official medical, educational, or employment record in the required system. If a user believes prohibited information was submitted, the user should use the available removal feature and contact [PRIVACY EMAIL] without repeating the prohibited information in the message.

9. Washington Consumer Health Data Privacy Notice

This section provides the disclosures required by Washington’s My Health My Data Act when the Act applies. To be conservative, CodaPath treats coded client tracking data as consumer health data if it is linked or reasonably linkable to a consumer under applicable law. Information that meets a statutory deidentification standard may fall outside that definition.

Consumer health data we may collect

Sources and purposes

Sources are the clinician subscriber, the clinician’s use of CodaPath, an adult client-portal visitor’s entry of a random code, and the Service’s operation of requested functions. We collect and use this information only to provide requested tracking, visualization, export, approved-summary, material-sharing, client-portal, support, security, and compliance functions; to maintain the Service; and for other purposes disclosed here or separately authorized as required by law.

Consumer health data we share and the recipients

CodaPath may share the categories above only as necessary to provide a requested product or service, at a clinician’s direction, with valid consent where required, or as otherwise permitted by law. Categories of recipients may include application hosting and database providers; security or error-monitoring providers that are configured to receive such data; the clinician and recipients the clinician authorizes through a client code or export; legal or safety recipients where permitted; and a successor in a qualifying business transaction.

Specific third parties and affiliates that may receive consumer health data: [LIST THE LEGAL NAME AND ACTIVE CONTACT METHOD FOR EACH THIRD PARTY OR AFFILIATE THAT ACTUALLY RECEIVES CONSUMER HEALTH DATA. IF NONE IN A CATEGORY, STATE “NONE.” AT MINIMUM, CONFIRM THE APPLICATION HOSTING/DATABASE PROVIDER. DO NOT LIST WIX OR STRIPE HERE UNLESS THEY ACTUALLY RECEIVE CONSUMER HEALTH DATA.]

CodaPath does not sell consumer health data. CodaPath does not use consumer health data for targeted advertising or geofencing around healthcare facilities. We do not attempt to reidentify data that has been deidentified under applicable law, and we require recipients of deidentified data to maintain it in deidentified form where legally required.

Washington rights and how to exercise them

Subject to the Act and applicable exceptions, a Washington consumer may request to:

Submit a request through [SECURE PRIVACY REQUEST WEBFORM OR EMAIL] or, if you have a clinician account, through [IN-ACCOUNT REQUEST METHOD]. A person does not need to create a new account to make a request. We may request information reasonably necessary to authenticate the request. Do not send a client’s name, diagnosis, or other health details. For a portal record, provide the random client code and [DESCRIBE THE SAFE VERIFICATION PROCESS].

Where CodaPath processes coded client data solely on a clinician’s behalf, the clinician may be the appropriate party to receive and authenticate the request. CodaPath may direct the request to that clinician or assist the clinician as required by law. Because CodaPath does not hold the external identity-to-code mapping, it may be unable to connect a named person to a coded record without the code and appropriate verification.

We will respond without undue delay and within the period required by law, generally within 45 days under the Washington Act, subject to one permitted 45-day extension. Information is provided without charge up to twice annually unless a request is manifestly unfounded, excessive, or repetitive as defined by law.

If we deny a request, you may appeal through [APPEAL WEBFORM OR PRIVACY EMAIL WITH SUBJECT “PRIVACY APPEAL”]. We will respond within the period required by law and explain our decision. If the appeal is denied, you may contact the Washington State Attorney General at https://www.atg.wa.gov/file-complaint.

For a verified Washington deletion request, deletion from archived or backup systems may be delayed until those systems are restored, but not longer than six months after authentication where the Act applies, unless another legal exception permits retention.

10. Data retention

We keep personal information only for as long as reasonably necessary for the purposes described in this policy, including providing the Service, maintaining security, resolving disputes, enforcing agreements, and meeting legal, accounting, and tax obligations. The periods below must be completed before publication and matched to actual system behavior.

Information may be retained longer when reasonably necessary to comply with law, preserve evidence, investigate misuse or a security incident, resolve a dispute, or exercise or defend legal claims. When data is no longer required, we delete, deidentify, or securely dispose of it according to our procedures.

11. Security

CodaPath uses administrative, technical, and physical safeguards designed for the nature of the information and the Service. These include structured fields and input restrictions intended to block prohibited client identifiers; access controls; encryption [IN TRANSIT AND AT REST — CONFIRM]; account authentication [DESCRIBE MFA OR OTHER CONTROLS]; logging and monitoring [CONFIRM]; vendor review; backups; and incident-response procedures [CONFIRM EACH CONTROL BEFORE PUBLICATION].

No method of transmission or storage is completely secure. Clinicians must protect credentials and client codes, use secure devices, revoke codes when access should end, and notify [SECURITY EMAIL] promptly of suspected unauthorized access. Do not include client identity or health details in an incident report.

12. Your privacy rights and choices

Depending on where you live and how the information is processed, you may have rights to know or access personal information, correct inaccuracies, delete information, obtain a portable copy, withdraw consent, restrict or object to processing, opt out of certain sales, targeted advertising, or profiling, and appeal a refusal. CodaPath does not discriminate against a person for exercising an applicable privacy right.

To submit a request, use [SECURE PRIVACY REQUEST METHOD] or email [PRIVACY EMAIL]. We will verify the request in a manner proportionate to its sensitivity. An authorized agent may submit a request where permitted, but we may require proof of authority and direct verification with the consumer. We may deny or limit a request when an exception applies and will explain the decision when required.

Clinician account holders may update [LIST SELF-SERVICE PROFILE FIELDS] through [ACCOUNT SETTINGS PATH], export [DESCRIBE EXPORTABLE DATA] through [EXPORT PATH], cancel a subscription through Account and Billing, and request account deletion through [ACCOUNT DELETION METHOD]. Canceling renewal does not itself delete the account or its data unless the interface expressly says so.

Marketing emails include an unsubscribe method. Account, billing, security, and other service messages are not promotional and may continue while an account or legal obligation remains.

13. California and other state disclosures

The categories of personal information collected, their sources, purposes, and recipient categories are described in Sections 2, 4, 5, and 6. CodaPath does not sell personal information and does not share it for cross-context behavioral advertising. CodaPath does not disclose personal information to third parties for their own direct-marketing use. California residents may use the request methods in Section 12 to ask about or exercise any right that applies to CodaPath’s processing.

California law requires disclosure of whether other parties may collect personally identifiable information about a person’s online activities over time and across different websites. [CONFIRM: OTHER THAN WIX AND THE SPECIFIC COOKIE/ANALYTICS PROVIDERS LISTED IN SECTION 6, CODAPATH DOES NOT PERMIT THIRD PARTIES TO COLLECT SUCH INFORMATION THROUGH THE SERVICE.] See Section 7 for Do Not Track and preference-signal information.

Residents of other states may submit requests through the same method. We will apply the law that governs the request, including any applicable exceptions, verification requirements, and appeal rights.

14. Children and minors

Clinician accounts are for adults age 18 or older. The client portal is intended for access by an adult client, parent, legal guardian, caregiver, or other authorized adult. CodaPath does not knowingly allow a child under 13 to create an account or directly submit personal information. A minor may view clinician-approved material only under the control of an authorized adult or treating professional.

If you believe a child has directly provided personal information contrary to this policy, contact [PRIVACY EMAIL] without including the child’s sensitive information. We will investigate and take appropriate action.

15. United States service and data location

The individual CodaPath Service is offered for use in the United States. Information is processed in [UNITED STATES / LIST OTHER COUNTRIES] by CodaPath and the providers listed in Section 6. If information is transferred across jurisdictions, we use safeguards required by applicable law. [CONFIRM ALL HOSTING, SUPPORT, AND VENDOR PROCESSING LOCATIONS.]

16. Changes to this policy

We may update this policy to reflect changes in the Service, law, or our practices. We will post the updated policy, revise the effective date, and provide additional notice or obtain consent when required. If a change would add a category or purpose for consumer health data that requires prior disclosure and affirmative consent, we will provide that disclosure and obtain consent before the new collection, use, or sharing begins.

Prior versions will be available at [PRIOR-VERSION LINK OR REQUEST METHOD].

17. Contact us

CodaPath LLC

[MAILING ADDRESS]

Privacy requests and questions: [PRIVACY EMAIL OR SECURE WEBFORM]

Security concerns: [SECURITY EMAIL]

Privacy appeals: [APPEAL METHOD]

General support: [SUPPORT EMAIL OR WEBFORM]

When contacting us, do not include client names, diagnoses, narrative notes, or other prohibited information. Use a random client code only when necessary and requested through a secure process.