This Statement of Privacy applies to ProbityCare Solutions Inc. (“ProbityCare,” “we,” or “us”), a Florida corporation, and governs data collection and usage across probitycare.com and the ProbityCare application — a healthcare practice management system with an integrated electronic health record designed to improve outcomes for practices, providers, and clients. By using our website or application, you consent to the data practices described here.
1Scope of this policy
What changed in this version
- Added a full disclosure of Google Analytics 4 and Microsoft Clarity, including session replay, and introduced a consent banner that blocks both until you accept.
- Added a clear separation between PHI governed by the BAA and ordinary business contact data governed by this policy.
- Added a cookie table, retention periods, security measures, data location, and state privacy rights with an appeal process.
- We now honor Global Privacy Control signals automatically, and the “anonymous demographic information” claim has been removed — we do not collect age, gender, race, or religion for marketing purposes.
- Corrected the entity name and address to ProbityCare Solutions Inc., Miami, FL 33137.
This policy covers two different contexts, and the rules differ between them:
2Protected Health Information is governed by the BAA
Important distinction
When we process patient records on behalf of a provider organization, we act as a business associate, not as the controller of that data. Our use and disclosure of PHI is governed by HIPAA and by the Business Associate Agreement with that organization — not by this Privacy Policy.
If you are a patient and want to access, amend, or restrict your health record, or want an accounting of disclosures, contact your treatment provider directly. They are the covered entity and hold those obligations under their Notice of Privacy Practices. We will support your provider in responding to your request, but we cannot act on your health record without their direction.
We never use PHI for marketing, advertising, or analytics. No analytics or session-replay tooling runs on pages that display patient information.
3Information we collect
To provide the products and services we offer, we may collect personally identifiable information such as:
- First and last name
- Mailing address
- Email address
- Phone number
- Employer and organization
- Job title and professional role
If you purchase our products or services, we collect billing information. Card details are submitted directly to our PCI-DSS compliant payment processor; we receive a token and the last four digits, and we do not store full card numbers on our systems.
We do not collect personal information about you unless you voluntarily provide it. However, you may be required to provide certain information when you choose to use certain products or services. These may include: (a) registering for an account; (b) requesting a demonstration or pricing; (c) subscribing to updates; (d) sending us an email or support request; or (e) submitting payment information when ordering products and services.
Please do not send PHI by email
Ordinary email and web forms are not secure channels. Do not include patient names, dates of birth, diagnoses, or record numbers in a support request. Use the secure messaging tools inside the platform instead.
4Information collected automatically
When you visit our website, our servers and our analytics providers may record technical information about the visit:
- IP address (truncated before storage by our analytics providers)
- Browser type and version, operating system, and device type
- Screen size and general geographic region, derived from IP at city level or broader
- Pages viewed, time on page, scroll depth, and referring URL
- Clicks, taps, and mouse movement on marketing pages, where you have consented
This information is used in aggregate to understand how the website performs and to detect abuse. We do not attempt to identify individual visitors from it.
6Google Analytics and Microsoft Clarity
With your consent, we use two analytics services on our marketing website. Both are configured to minimize what they collect.
Google Analytics 4
Provided by Google LLC. We use it to measure aggregate traffic — which pages are visited, how visitors arrive, and which content leads to a demo request. Our configuration:
- IP anonymization is enabled and full IP addresses are not stored.
- Google Signals, advertising personalization, and ad remarketing are disabled. Analytics data is not used to build advertising audiences.
- Data retention is set to the shortest practical period.
Google’s handling of this data is described in the Google Privacy Policy. You can also install the Google Analytics opt-out add-on to block it across all sites.
Microsoft Clarity
Provided by Microsoft Corporation. Clarity produces heatmaps and session replays — reconstructions of how a visitor moved through a page — so we can find layout and usability problems.
How we limit session replay
- Clarity runs only on our public marketing website. It is not installed on any authenticated page of the platform, and it never sees patient records.
- Text input masking is enabled, so what you type into form fields is not captured in the recording.
- Replays are reconstructions of page events, not video or audio of you or your screen.
- We do not use Clarity to identify individuals or to build profiles.
Microsoft may use this data in accordance with the Microsoft Privacy Statement. Both providers act as our service providers and are contractually restricted from using the data for their own independent purposes.
7How we use information
We collect and use personal information to:
- Operate and deliver the services you have requested.
- Create and administer accounts, and authenticate users.
- Process payments and manage billing.
- Provide customer support and respond to your inquiries.
- Send service announcements, security notices, and product updates.
- Inform you of other products or services available from ProbityCare, where you have not opted out.
- Monitor and improve the performance, reliability, and security of our services.
- Detect, investigate, and prevent fraud, abuse, and unauthorized access.
- Comply with legal, regulatory, and accreditation obligations.
We do not use your information to train third-party AI models, and we do not make decisions about you through solely automated means that would have a legal or similarly significant effect.
9We do not sell or share your personal data
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended, or under comparable state laws. We have not done so in the preceding twelve months.
We do not knowingly sell or share the personal information of consumers under 16 years of age.
10Email and SMS communications
From time to time we may contact you by email with announcements, promotional offers, alerts, confirmations, surveys, and other general communications. To stop receiving marketing or promotional email, click unsubscribe in any message or email privacy@probitycare.com.
You cannot opt out of transactional messages that are necessary to your account — security alerts, billing notices, and legal updates — while your account remains active.
SMS messages are used only for two-step authentication and are covered in Section 6 of our Terms. Reply STOP to opt out. We never include PHI in an SMS or email notification.
11Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding personal information we hold about you as a business contact or website visitor:
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and Florida — including under the Florida Digital Bill of Rights — as well as other states with comprehensive privacy laws, may exercise these rights regardless of which state law applies to them. We extend the same process to everyone.
How to make a request
Email privacy@probitycare.com with the subject line “Privacy Request.” We will verify your identity, usually by confirming control of the email address on file, and respond within 45 days. We may extend once by a further 45 days where reasonably necessary, and will tell you if we do.
You may use an authorized agent, who must provide written proof of authorization. Requests are free unless they are excessive or repetitive.
Appeals
If we decline your request, you may appeal by replying to our decision with the word “Appeal.” A reviewer not involved in the original decision will respond within 45 days with a written explanation. If your appeal is denied, you may contact your state attorney general.
12Right to deletion
Subject to certain exceptions, on receipt of a verifiable request we will delete your personal information from our records and direct our service providers to delete it from theirs.
We may be unable to comply with a deletion request where the information is necessary to: complete a transaction or provide a service you requested; detect security incidents or protect against fraudulent or illegal activity; debug and repair errors; exercise free speech or another legal right; comply with a legal obligation, including medical record retention requirements; or use the information internally in a lawful manner compatible with the context in which you provided it.
Deletion requests concerning a patient health record must be directed to the treating provider, as described in Section 2. Health records are subject to state retention laws that generally prevent deletion on request.
13How long we keep data
We keep personal information only as long as necessary for the purpose it was collected, or as required by law.
14How we protect information
We maintain administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption in transit with TLS 1.2 or higher, and encryption at rest with AES-256.
- Mandatory multi-factor authentication and role-based least-privilege access.
- Continuous audit logging, monitoring, and alerting on access to sensitive data.
- Annual risk analysis, penetration testing, and workforce security training.
- Documented incident response and breach notification procedures.
Full detail is available on our HIPAA compliance page. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe your account has been compromised, contact security@probitycare.com immediately.
15Data storage and location
We store data on infrastructure operated by third-party hosting vendors with whom we have contracted, including a signed business associate agreement where PHI is involved.
All PHI is stored and processed within the United States. We do not transfer PHI outside the United States. Limited business contact information may be processed by support and analytics vendors that operate globally; where that occurs, we rely on contractual safeguards with those vendors.
16Children and minors
Our website is not directed to children and we do not knowingly collect personal information from children through it. If you believe a child has provided information through our website, contact us and we will delete it.
Within the platform, our provider customers may maintain health records for patients under the age of thirteen as part of treatment. That information is PHI, is entered by the provider rather than by the child, and is governed by HIPAA and the BAA rather than by this policy. Provider organizations are responsible for obtaining any consent required from a parent or guardian and for honoring state law on minor consent and confidentiality, including records protected by 42 C.F.R. Part 2.
Parents with questions about a child’s record should contact the treating provider. If you have questions about our practices generally, contact us using the details below.
17Changes to this statement
We reserve the right to change this Privacy Policy from time to time. We will notify you about significant changes in the way we treat personal information by sending a notice to the primary email address specified in your account, by placing a prominent notice on our application, or by updating this page. Where a change materially expands how we use information, we will give at least 30 days notice and, where required, ask for your consent again.
Your continued use of the application or services after such modifications constitutes your acknowledgment of the modified policy and agreement to be bound by it.
18Contact information
We welcome your questions or comments regarding this Statement of Privacy. If you believe we have not adhered to it, please contact us.
Privacy contact
ProbityCare Solutions Inc.2125 Biscayne Blvd, Ste 303Miami, FL 33137
Privacy: privacy@probitycare.com
Security: security@probitycare.com
Telephone: 781-654-5718
You also have the right to lodge a complaint with your state attorney general, or with the US Department of Health and Human Services Office for Civil Rights for matters involving PHI.
19Revision history
- Version 3.0. Disclosed Google Analytics 4 and Microsoft Clarity and added an opt-in consent banner with a cookie table. Separated PHI handled under the BAA from business contact data. Added state privacy rights with an appeal path, retention periods, security measures, data location, and Global Privacy Control support. Removed the collection of demographic categories. Corrected the entity name and address.
- Version 2.0. Added the right to deletion, restricted third-party sharing, and added provisions on external data storage.
- Version 1.0. Initial publication.
