CodaPath Privacy Policy
Effective date: [INSERT EFFECTIVE DATE]
This Privacy Policy includes CodaPath’s Washington Consumer Health Data Privacy Notice. It explains how CodaPath LLC (“CodaPath,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information through codapath.net, our public marketing website, the authenticated clinician application, client-portal functions, and related communications and support (collectively, the “Service”).
This policy should be read with the CodaPath Clinician Terms of Service and any separate Client Portal Terms. It does not replace any privacy notice or consent that a clinician, clinic, school, employer, or other organization is independently required to provide.
1. Scope and our privacy roles
This policy applies to individual clinician subscribers, website visitors, adults who access the client portal, and people who contact CodaPath. The individual subscription is intended for clinicians, not for independent use by children. Organization use is governed by a separate written license and may be subject to additional privacy terms.
CodaPath determines how clinician account, billing, website, support, and security information is handled for its own business purposes. For coded client information entered by a clinician, the clinician generally selects the information and directs its use through the Service, and CodaPath processes it to provide the requested functionality. Our legal role may vary by data, relationship, and applicable law.
CodaPath is not a healthcare provider and the individual subscription is not an electronic health record. It is designed for coded, non-identifying information and is not intended or authorized to receive protected health information (“PHI”). CodaPath does not enter into a HIPAA business associate agreement for individual subscriptions. This policy is not a HIPAA Notice of Privacy Practices.
2. Information we collect
We collect only the information described below, subject to the configuration and bracketed confirmations that must be completed before publication.
| Category | Examples | Primary purposes |
|---|---|---|
| Clinician account information | Name, professional email address, password or authentication credential, account identifier, profession or role, subscription plan, preferences, and information provided to manage the account. | Create and secure the account; authenticate the subscriber; provide the Service; administer subscriptions; communicate about the account. |
| Billing and transaction information | Billing name, billing contact details, subscription tier, transaction amount, dates, status, limited payment-method details such as card brand and last four digits, and tax or invoice information. Complete payment-card numbers are handled by Stripe and are not stored by CodaPath. | Process payments, prevent fraud, administer free and paid periods, maintain financial records, and resolve billing issues. |
| Coded client and service data | Random client code; structured goals and tracking selections; performance or progress data; session dates; materials selected or shared; approved summaries; status and activity needed to operate the client workflow. | Provide tracking, visualization, export, document-sharing, and client-communication features; maintain the account; troubleshoot; protect the Service. |
| Website and inquiry information | Information submitted through contact, waitlist, demo, or support forms, such as name, email address, organization, message, and communication preferences. | Respond to requests, provide information, deliver requested communications, and maintain business records. |
| Technical and security information | IP address, browser and device type, operating system, timestamps, pages or functions accessed, authentication events, error and diagnostic information, and security logs, subject to the limits described for the client portal. | Operate, secure, debug, measure, and improve the Service; detect misuse; maintain audit and incident records. |
| Client-portal information | Client code entered by an adult recipient, content made available through that code, and access events required to provide and protect the portal. CodaPath does not store client-portal IP address or device information with client records. | Display clinician-approved content, manage access, prevent misuse, and troubleshoot portal operation. |
| Communications and support | Messages with CodaPath, support history, feedback, and any attachments or screenshots a person chooses to send. Users must not include client identity, PHI, or other prohibited information. | Provide support, investigate issues, respond to feedback, enforce our Terms, and improve the Service. |
| Cookies and similar technology | Cookie identifiers, session information, consent preferences, and website interaction data used by Wix and [IDENTIFY ANY ANALYTICS OR COOKIE PROVIDERS]. | Run the marketing site, remember preferences, maintain security, and [DESCRIBE ANY ANALYTICS PURPOSES]. |
3. Client information the Service is designed not to collect
CodaPath does not request or provide fields for client names, initials, schools, email addresses, dates of birth, street addresses, telephone numbers, diagnoses, medical-record numbers, health-plan numbers, or a key that maps a client code to a person. CodaPath does not store clinician narrative journal notes. The Service uses structured fields and technical controls designed to prevent prohibited identifiable information from being submitted or uploaded.
A random client code is not derived from client information. Any external mapping between a client code and a person must remain outside CodaPath and under the clinician’s control. Users must not place identifying information in goals, titles, filenames, metadata, screenshots, support messages, or other fields.
The Service stores session dates. Users must not combine a date with information that identifies or reasonably permits identification of a client. Whether information is “personal information,” “consumer health data,” “PHI,” or deidentified is determined by applicable law and the surrounding facts, not by this policy alone.
4. Sources of information
- Directly from clinician subscribers and people who contact CodaPath.
- From the clinician’s use of the Service, including structured entries, configuration choices, exports, and content the clinician authorizes for the client portal.
- From adult client-portal visitors when they enter a client code and use the portal.
- Automatically from browsers, devices, cookies, servers, and security systems when people visit or use the Service.
- From payment, authentication, hosting, email, support, and other service providers acting for CodaPath.
- From an employer or organization only when it lawfully provides account or licensing information under a separate written arrangement.
5. How we use information
- Provide, personalize, maintain, and support the Service and requested features.
- Create accounts, authenticate users, manage subscriptions, process payments, and provide service communications.
- Generate clinician-requested tracking views, progress displays, exports, approved summaries, and portal materials.
- Protect accounts, client codes, systems, and users; prevent abuse; investigate errors and security events; enforce our Terms.
- Respond to questions, requests, complaints, and support matters.
- Comply with law, valid legal process, accounting obligations, and lawful regulatory requests.
- Analyze and improve reliability, accessibility, performance, and features using information that is aggregated, deidentified where required, or otherwise processed as permitted by law.
- Send promotional communications only where permitted and according to the recipient’s choices. [CONFIRM WHETHER CODAPATH SENDS PROMOTIONAL EMAIL AND IDENTIFY THE PROVIDER.]
CodaPath does not use identifiable Subscriber Content or coded client data to train public or third-party artificial-intelligence models. [CONFIRM WHETHER ANY PRIVATE AI FEATURE OR VENDOR PROCESSES SERVICE DATA; IF NONE, STATE “NO AI FEATURE OR VENDOR PROCESSES SERVICE DATA.”]
6. How we disclose information
We may disclose information only as described below. “Disclose” and “share” in this general section are used in their ordinary sense; laws may define “share,” “sale,” or similar terms differently.
| Recipient category | Reason and limits |
|---|---|
| Service providers | Providers that host or store the application, authenticate users, process payments, deliver email, monitor errors, provide support, secure systems, or perform other functions for CodaPath. They may use information only to perform contracted services and as permitted by law. |
| At a clinician’s direction | Recipients or systems selected by the clinician, including an adult given a client code, a downloaded export, or another destination the clinician chooses. |
| Legal and safety | Government agencies, courts, advisers, or other parties when reasonably necessary to comply with law or valid process, protect rights and safety, investigate fraud or misuse, or establish or defend legal claims. |
| Business transaction | A potential or actual buyer, investor, lender, successor, or adviser in connection with financing, due diligence, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable confidentiality and health-data restrictions. |
| With permission | Another person or entity when the person to whom the information relates gives valid consent or when another lawful authorization applies. |
Service-provider register to complete
| Function | Provider / affiliate | Information and scope |
|---|---|---|
| Public marketing website | Wix.com Ltd. and relevant Wix entity [CONFIRM CONTRACTING ENTITY] | Website contact and technical data; cookies configured for the marketing site. |
| Payment processing | Stripe, Inc. and relevant Stripe entity [CONFIRM] | Clinician billing and transaction data; not coded client tracking data. |
| Application hosting and database | [LEGAL NAME OF HOSTING/DATABASE PROVIDER] | [LIST DATA CATEGORIES AND WHETHER CODED CLIENT DATA IS PROCESSED]. |
| Authentication | [LEGAL NAME OF AUTHENTICATION PROVIDER] | [LIST ACCOUNT AND LOGIN DATA; CONFIRM WHETHER PROVIDER CAN ACCESS CODED CLIENT DATA]. |
| Transactional email | [LEGAL NAME OF EMAIL PROVIDER] | [LIST ACCOUNT/COMMUNICATION DATA; CONFIRM NO CLIENT DATA]. |
| Customer support | [LEGAL NAME OF SUPPORT PROVIDER OR “INTERNAL ONLY”] | [LIST SUPPORT DATA AND ATTACHMENT HANDLING]. |
| Error monitoring/security logs | [LEGAL NAME OF PROVIDER OR “INTERNAL ONLY”] | [LIST TECHNICAL DATA; CONFIRM FILTERS EXCLUDE CLIENT CONTENT]. |
| Analytics | [LEGAL NAME OF PROVIDER OR “NONE”] | [MARKETING SITE ONLY / AUTHENTICATED APP; LIST DATA]. |
| Affiliates | [NONE, OR LIST EACH SPECIFIC AFFILIATE] | [DESCRIBE PURPOSE AND DATA]. |
No sale, targeted advertising, or model training
CodaPath does not sell personal information or consumer health data. CodaPath does not share personal information for cross-context behavioral advertising or use coded client data for targeted advertising. CodaPath does not allow advertising networks to collect data in authenticated areas. CodaPath does not use identifiable Subscriber Content or coded client data to train public or third-party AI models. [COUNSEL/ENGINEERING: CONFIRM THESE STATEMENTS AGAINST ALL CURRENT VENDORS, SDKs, PIXELS, AND CONTRACTS.]
7. Cookies and online tracking
The public marketing website is hosted on Wix. Wix and [IDENTIFY OTHER MARKETING-SITE PROVIDERS] may place cookies or use similar technology to provide the site, maintain security, remember choices, and [DESCRIBE ANALYTICS, IF USED]. The authenticated CodaPath application is hosted separately from Wix.
CodaPath does not use advertising pixels or session-replay tools in authenticated areas. [CONFIRM WHETHER FIRST-PARTY OR PRODUCT ANALYTICS OPERATE AFTER LOGIN. IF YES, IDENTIFY THE PROVIDER, DATA, PURPOSE, RETENTION, AND OPT-OUT.]
You can adjust browser settings and, where available, use our cookie controls at [COOKIE SETTINGS LINK]. Blocking essential cookies may prevent parts of the Service from working.
California Do Not Track disclosure. Some browsers offer a “Do Not Track” signal. Because there is no uniform industry response, our Service [DOES / DOES NOT] respond to that signal. We honor legally required opt-out preference signals, such as Global Privacy Control, where they apply. Because CodaPath does not sell personal information or use it for cross-context behavioral advertising, such a signal generally does not change those practices. [CONFIRM TECHNICAL HANDLING BEFORE PUBLICATION.]
8. Coded client data and HIPAA
The individual CodaPath Service is designed for coded information and is not intended or authorized to receive PHI. It does not collect the client identifiers listed in Section 3, a re-identification key, diagnoses, or narrative clinical notes. The Service’s acceptance of structured data or session dates is not a representation that a clinician’s particular use satisfies a HIPAA deidentification method or an employer’s policies.
A clinician remains responsible for deciding whether information may lawfully be entered, maintaining any external mapping separately, obtaining required permissions, and keeping any official medical, educational, or employment record in the required system. If a user believes prohibited information was submitted, the user should use the available removal feature and contact [PRIVACY EMAIL] without repeating the prohibited information in the message.
9. Washington Consumer Health Data Privacy Notice
This section provides the disclosures required by Washington’s My Health My Data Act when the Act applies. To be conservative, CodaPath treats coded client tracking data as consumer health data if it is linked or reasonably linkable to a consumer under applicable law. Information that meets a statutory deidentification standard may fall outside that definition.
Consumer health data we may collect
| Category | Examples |
|---|---|
| Treatment or intervention information | Structured speech-language goals, therapy or intervention categories, tracking selections, materials selected, and approved summaries. |
| Measurements and progress information | Structured performance entries, counts, percentages, levels, observations selected from permitted fields, trends, and visualizations. |
| Service dates and activity | Session dates and dates or status associated with clinician-approved sharing, progress tracking, or portal content. |
| Inferences | Progress trends or summaries generated from permitted structured entries. CodaPath does not use these to diagnose a person. |
| Portal access information | The random client code entered and the clinician-approved content available through it. Client-portal IP address and device information are not stored with client records. |
Sources and purposes
Sources are the clinician subscriber, the clinician’s use of CodaPath, an adult client-portal visitor’s entry of a random code, and the Service’s operation of requested functions. We collect and use this information only to provide requested tracking, visualization, export, approved-summary, material-sharing, client-portal, support, security, and compliance functions; to maintain the Service; and for other purposes disclosed here or separately authorized as required by law.
Consumer health data we share and the recipients
CodaPath may share the categories above only as necessary to provide a requested product or service, at a clinician’s direction, with valid consent where required, or as otherwise permitted by law. Categories of recipients may include application hosting and database providers; security or error-monitoring providers that are configured to receive such data; the clinician and recipients the clinician authorizes through a client code or export; legal or safety recipients where permitted; and a successor in a qualifying business transaction.
Specific third parties and affiliates that may receive consumer health data: [LIST THE LEGAL NAME AND ACTIVE CONTACT METHOD FOR EACH THIRD PARTY OR AFFILIATE THAT ACTUALLY RECEIVES CONSUMER HEALTH DATA. IF NONE IN A CATEGORY, STATE “NONE.” AT MINIMUM, CONFIRM THE APPLICATION HOSTING/DATABASE PROVIDER. DO NOT LIST WIX OR STRIPE HERE UNLESS THEY ACTUALLY RECEIVE CONSUMER HEALTH DATA.]
CodaPath does not sell consumer health data. CodaPath does not use consumer health data for targeted advertising or geofencing around healthcare facilities. We do not attempt to reidentify data that has been deidentified under applicable law, and we require recipients of deidentified data to maintain it in deidentified form where legally required.
Washington rights and how to exercise them
Subject to the Act and applicable exceptions, a Washington consumer may request to:
- Confirm whether CodaPath is collecting, sharing, or selling consumer health data concerning the consumer and access that data.
- Receive a list of third parties and affiliates with whom that consumer health data was shared or sold and an active contact method for each.
- Withdraw consent from future collection or sharing when processing is based on consent.
- Delete consumer health data concerning the consumer, including by notifying applicable processors and other recipients as required by law.
- Appeal CodaPath’s refusal to act on a request.
Submit a request through [SECURE PRIVACY REQUEST WEBFORM OR EMAIL] or, if you have a clinician account, through [IN-ACCOUNT REQUEST METHOD]. A person does not need to create a new account to make a request. We may request information reasonably necessary to authenticate the request. Do not send a client’s name, diagnosis, or other health details. For a portal record, provide the random client code and [DESCRIBE THE SAFE VERIFICATION PROCESS].
Where CodaPath processes coded client data solely on a clinician’s behalf, the clinician may be the appropriate party to receive and authenticate the request. CodaPath may direct the request to that clinician or assist the clinician as required by law. Because CodaPath does not hold the external identity-to-code mapping, it may be unable to connect a named person to a coded record without the code and appropriate verification.
We will respond without undue delay and within the period required by law, generally within 45 days under the Washington Act, subject to one permitted 45-day extension. Information is provided without charge up to twice annually unless a request is manifestly unfounded, excessive, or repetitive as defined by law.
If we deny a request, you may appeal through [APPEAL WEBFORM OR PRIVACY EMAIL WITH SUBJECT “PRIVACY APPEAL”]. We will respond within the period required by law and explain our decision. If the appeal is denied, you may contact the Washington State Attorney General at https://www.atg.wa.gov/file-complaint.
For a verified Washington deletion request, deletion from archived or backup systems may be delayed until those systems are restored, but not longer than six months after authentication where the Act applies, unless another legal exception permits retention.
10. Data retention
We keep personal information only for as long as reasonably necessary for the purposes described in this policy, including providing the Service, maintaining security, resolving disputes, enforcing agreements, and meeting legal, accounting, and tax obligations. The periods below must be completed before publication and matched to actual system behavior.
| Data | Retention rule |
|---|---|
| Clinician account/profile | [WHILE ACTIVE + NUMBER OF DAYS/MONTHS AFTER ACCOUNT DELETION] |
| Coded client/service data | [WHILE ACCOUNT ACTIVE + POST-CANCELLATION/DELETION PERIOD; DESCRIBE EXPORT WINDOW] |
| Backups | [BACKUP CYCLE AND MAXIMUM DELETION DELAY; NO MORE THAN SIX MONTHS FOR COVERED WASHINGTON REQUESTS] |
| Billing/tax records | [NUMBER OF YEARS REQUIRED FOR ACCOUNTING AND TAX PURPOSES] |
| Authentication/security logs | [NUMBER OF DAYS/MONTHS] |
| Support communications | [NUMBER OF MONTHS/YEARS] |
| Marketing inquiries | [NUMBER OF MONTHS/YEARS OR UNTIL OPT-OUT] |
| Privacy requests and consents | [NUMBER OF YEARS NEEDED TO DOCUMENT COMPLIANCE] |
Information may be retained longer when reasonably necessary to comply with law, preserve evidence, investigate misuse or a security incident, resolve a dispute, or exercise or defend legal claims. When data is no longer required, we delete, deidentify, or securely dispose of it according to our procedures.
11. Security
CodaPath uses administrative, technical, and physical safeguards designed for the nature of the information and the Service. These include structured fields and input restrictions intended to block prohibited client identifiers; access controls; encryption [IN TRANSIT AND AT REST — CONFIRM]; account authentication [DESCRIBE MFA OR OTHER CONTROLS]; logging and monitoring [CONFIRM]; vendor review; backups; and incident-response procedures [CONFIRM EACH CONTROL BEFORE PUBLICATION].
No method of transmission or storage is completely secure. Clinicians must protect credentials and client codes, use secure devices, revoke codes when access should end, and notify [SECURITY EMAIL] promptly of suspected unauthorized access. Do not include client identity or health details in an incident report.
12. Your privacy rights and choices
Depending on where you live and how the information is processed, you may have rights to know or access personal information, correct inaccuracies, delete information, obtain a portable copy, withdraw consent, restrict or object to processing, opt out of certain sales, targeted advertising, or profiling, and appeal a refusal. CodaPath does not discriminate against a person for exercising an applicable privacy right.
To submit a request, use [SECURE PRIVACY REQUEST METHOD] or email [PRIVACY EMAIL]. We will verify the request in a manner proportionate to its sensitivity. An authorized agent may submit a request where permitted, but we may require proof of authority and direct verification with the consumer. We may deny or limit a request when an exception applies and will explain the decision when required.
Clinician account holders may update [LIST SELF-SERVICE PROFILE FIELDS] through [ACCOUNT SETTINGS PATH], export [DESCRIBE EXPORTABLE DATA] through [EXPORT PATH], cancel a subscription through Account and Billing, and request account deletion through [ACCOUNT DELETION METHOD]. Canceling renewal does not itself delete the account or its data unless the interface expressly says so.
Marketing emails include an unsubscribe method. Account, billing, security, and other service messages are not promotional and may continue while an account or legal obligation remains.
13. California and other state disclosures
The categories of personal information collected, their sources, purposes, and recipient categories are described in Sections 2, 4, 5, and 6. CodaPath does not sell personal information and does not share it for cross-context behavioral advertising. CodaPath does not disclose personal information to third parties for their own direct-marketing use. California residents may use the request methods in Section 12 to ask about or exercise any right that applies to CodaPath’s processing.
California law requires disclosure of whether other parties may collect personally identifiable information about a person’s online activities over time and across different websites. [CONFIRM: OTHER THAN WIX AND THE SPECIFIC COOKIE/ANALYTICS PROVIDERS LISTED IN SECTION 6, CODAPATH DOES NOT PERMIT THIRD PARTIES TO COLLECT SUCH INFORMATION THROUGH THE SERVICE.] See Section 7 for Do Not Track and preference-signal information.
Residents of other states may submit requests through the same method. We will apply the law that governs the request, including any applicable exceptions, verification requirements, and appeal rights.
14. Children and minors
Clinician accounts are for adults age 18 or older. The client portal is intended for access by an adult client, parent, legal guardian, caregiver, or other authorized adult. CodaPath does not knowingly allow a child under 13 to create an account or directly submit personal information. A minor may view clinician-approved material only under the control of an authorized adult or treating professional.
If you believe a child has directly provided personal information contrary to this policy, contact [PRIVACY EMAIL] without including the child’s sensitive information. We will investigate and take appropriate action.
15. United States service and data location
The individual CodaPath Service is offered for use in the United States. Information is processed in [UNITED STATES / LIST OTHER COUNTRIES] by CodaPath and the providers listed in Section 6. If information is transferred across jurisdictions, we use safeguards required by applicable law. [CONFIRM ALL HOSTING, SUPPORT, AND VENDOR PROCESSING LOCATIONS.]
16. Changes to this policy
We may update this policy to reflect changes in the Service, law, or our practices. We will post the updated policy, revise the effective date, and provide additional notice or obtain consent when required. If a change would add a category or purpose for consumer health data that requires prior disclosure and affirmative consent, we will provide that disclosure and obtain consent before the new collection, use, or sharing begins.
Prior versions will be available at [PRIOR-VERSION LINK OR REQUEST METHOD].
17. Contact us
CodaPath LLC
[MAILING ADDRESS]
Privacy requests and questions: [PRIVACY EMAIL OR SECURE WEBFORM]
Security concerns: [SECURITY EMAIL]
Privacy appeals: [APPEAL METHOD]
General support: [SUPPORT EMAIL OR WEBFORM]
When contacting us, do not include client names, diagnoses, narrative notes, or other prohibited information. Use a random client code only when necessary and requested through a secure process.