Privacy Policy
Effective Date: March 2026 — Provided by hss.llc
1. What Data We Collect
Operational data (from facility systems): call alert event counts per location, response time measurements in minutes, location identifiers as configured by the facility, and report metadata. This data contains no resident names, medical records, or personal identifiers by design.
Account data: facility name, administrator name and email, authorized recipient email addresses, and encrypted password hashes.
Usage data: portal login events, report access timestamps, and upload source machine identifiers (truncated hardware UUID).
2. How We Use Data
We use collected data exclusively to generate monthly reports, deliver them to authorized recipients, display them in the portal, provide support, and maintain security logs. We do not sell your data, use it to train AI models, or share it between customers.
3. Third-Party Processors
We engage trusted third-party service providers solely to operate and deliver the Service. Each is bound by confidentiality obligations and permitted to use your data only as necessary to perform their designated function. We do not sell your data to any third party.
4. Data Retention
Active subscription data is retained for the duration of the subscription. Upon termination, data is retained for 90 days to allow export, then deleted. Activity logs are retained for 12 months.
5. Security
All data in transit is encrypted via TLS/HTTPS. Database contents are encrypted at rest. Portal access requires authenticated login. Facility machines are authenticated by registered hardware UUID. Access is role-based — users only see their own facility's data.
6. HIPAA
cAIrView is designed to operate below the threshold of PHI by processing only aggregate operational metrics. If your organization is a HIPAA Covered Entity, a Business Associate Agreement is required. You are responsible for ensuring your staff does not enter PHI into location name fields.
7. Cookies
The portal uses session cookies required for authentication only. We use no third-party tracking cookies, no advertising technology, and no analytics trackers.
8. Your Rights
You have the right to access, correct, delete, or export your data. To exercise these rights contact us at seniorlivingsupport@heart.net.
9. Contact
hss.llc — seniorlivingsupport@heart.net — hss.llc