Trust Center

Privacy

What data we collect, why, how long we keep it, and your rights over it.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

What data we collect, why, how long we keep it, and your rights over it.

The principle first

A privacy page from a compliance vendor should be held to a higher standard than most, so here is ours in one sentence: we collect the minimum data needed to run the service, we use it only for that purpose, and we delete it when the purpose ends. The formal, legally binding version is the privacy policy; this page is the plain-language map of what we hold and why.

What we collect and why

Three broad categories of data pass through SuperHIPAA:

Account and contact data. Names, work email addresses, and authentication details for the people who use the product, plus billing information for the organisation. Used to operate accounts, authenticate users, and invoice. Not sold, not shared for advertising.

Customer workspace content. The policies, risk registers, evidence files, and assessment answers your team puts into the product. This is your data. We process it solely to deliver the service, under the terms of your agreement and BAA. If it contains ePHI, HIPAA’s business associate obligations apply on top of everything else on this page.

Service and usage data. Logs, diagnostics, and product analytics needed to keep the service secure and improve it. Analytics are configured to minimise personal data (first-party analytics with IP addresses truncated, no advertising trackers, and no cross-site profiling), and security logs are retained for 12 months because they are themselves a safeguard.

What we do not do

The absences matter as much as the practices:

  • We do not sell personal data, to anyone, for anything.
  • We do not use customer workspace content to train machine-learning models, ours or anyone else’s, without explicit written agreement.
  • We do not mine your compliance data for benchmarking products or “industry insights” sold to third parties.
  • We do not run advertising trackers inside the authenticated product.

Retention and deletion

Data has a lifecycle, and ours is written down:

  • Workspace content is retained while your subscription is active.
  • At termination, content is returned on request and then deleted within 30 days, with deletion certified per the BAA.
  • Backups containing deleted data age out on the backup retention schedule (35 days) rather than persisting indefinitely.
  • Account and billing records are kept as long as law and accounting obligations require, and no longer.

What we commit to

  • We never sell personal data, and we never use customer workspace content to train models without explicit written agreement.
  • Workspace content is deleted within 30 days of a termination request, and backup copies age out within the 35-day backup retention window.
  • Access to customer data is role-based, protected by SSO and enforced MFA, and reviewed quarterly.

Your rights

Depending on where you are, statutory rights may apply to your personal data — access, correction, deletion, portability, and objection among them. We honour requests through [email protected], verify identity before acting, and respond within the timelines the applicable law sets. Where a request concerns data we process on behalf of a customer organisation, we will usually route it through that organisation, because they — not we — control that data and HIPAA may govern how it can be handled.

Where to look next

The privacy policy is the binding document and covers cookies, lawful bases, and jurisdiction-specific detail. The subprocessors page lists every third party that touches customer data. And the BAA page explains how HIPAA obligations layer over all of this when ePHI is involved. If those three documents plus this page leave a question open, ask — a privacy programme that cannot answer questions about itself is not much of a programme.

Documentation available on request

  • SOC 2 Type II report (under NDA)
  • Penetration test summary
  • Business Associate Agreement
  • Architecture and data flow diagram
  • Completed CAIQ / SIG Lite

Questions

Security questions go to [email protected] and get a human answer within one business day. Privacy-specific questions and data subject requests go to [email protected] and get the same treatment.

Questions

Will you sign our BAA instead of yours?

Usually yes. Send it over — we redline rather than refuse.

Can we get your SOC 2 report?

Yes, under NDA. Request it through the trust package form on this page.

Where is our data stored?

Region is selectable at provisioning. See the Infrastructure page for the current list.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo