CompyMax

Privacy Policy

Last updated:

This policy explains what CompyMax(“we”, “us”) collects, why, how long we keep it, and who we share it with. It applies to hipaacompliancesoftware.org and to the compliance platform available through it.

The short version

  • We store compliance records — policies, tasks, training results, vendor registers, incident logs and evidence files you upload.
  • We are not designed to hold protected health information. Please do not upload patient records, claims data or any other PHI.
  • Where you connect Microsoft 365 or Google Workspace, we read security configuration only — never the contents of email, files, calendars or chats.
  • We do not sell personal information, we do not serve advertising, and we do not use your data or data from Google or Microsoft integrations to train machine learning models.

Information we collect

Account and organization information

Name, work email address, password credentials handled by our authentication provider, organization name, organization type, role, and for managed service providers, the client organizations you administer.

Compliance content you create

Risk assessment responses, remediation tasks and their owners, policy versions and acknowledgement records, training completions and any score recorded with them, certificates, vendor and business associate agreement records, incident records, and files you upload as evidence.

Integration data

If an administrator connects Microsoft 365 or Google Workspace, we use read-only access to check security settings. Specifically, we may read: whether multi-factor authentication is enforced, account status and last sign-in activity used to identify accounts that should have been deactivated, external sharing and public link settings, mailbox forwarding rules, audit logging status, and device or endpoint compliance status where available.

We store the resulting pass or fail status, a short summary of the observed setting, the account identifiers a check applies to, and the time the check ran. We retain this as dated evidence so your compliance record shows when a control was confirmed.

We never request or receive access to message bodies, file contents, calendar contents or chat contents. The scopes we request are limited to administrative and directory information required for the checks listed above.

Technical and usage information

IP address, browser and device type, pages viewed and actions taken in the application, and error diagnostics. We use first-party cookies that are strictly necessary to keep you signed in and to secure the service.

Google API Services — Limited Use disclosure

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular:

  • We use Google Workspace data only to provide and improve the compliance-checking features an administrator explicitly enabled.
  • We do not transfer or sell this data for advertising purposes.
  • We do not use this data to develop, improve or train generalized artificial intelligence or machine learning models.
  • We do not allow humans to read this data, except where we have your explicit consent for a specific issue, where it is necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and de-identified.
  • An administrator can disconnect the integration at any time from the application, or revoke access directly in their Google Admin console. We delete stored integration credentials on disconnection.

How we use information

  • To provide the compliance platform and generate your evidence exports.
  • To send service communications: training reminders, expiring agreement notices, deadline alerts, security notices and billing messages.
  • To secure the service, investigate abuse and maintain audit trails.
  • To provide support when you contact us.
  • To meet legal and accounting obligations.

We rely on performance of our contract with you for core service delivery, legitimate interests for security and product improvement, and consent where required for optional communications.

Who we share information with

We do not sell personal information. We share it only with service providers who process it on our behalf under contract:

  • Supabase — application database, authentication and file storage.
  • Vercel — application hosting and content delivery.
  • Resend — transactional email delivery.
  • Lunastric — payment processing. Card details are entered directly with the payment provider; we never receive or store full card numbers.

We may also disclose information where required by law, to enforce our terms, or in connection with a merger or acquisition — in which case we will give notice before your information becomes subject to a different policy.

Protected health information

This platform is built to hold compliance artifacts, not patient data. Do not upload protected health information as evidence. If you believe PHI has been uploaded to your organization in error, contact us at privacy@hipaacompliancesoftware.org and we will work with you to remove it.

Retention

Compliance records are retained for as long as your organization is active, because the value of the record is its history. HIPAA requires covered entities and business associates to retain certain documentation for six years, so we default to keeping your compliance records for that period unless you ask us to delete them sooner.

After cancellation, your data remains exportable for 30 days, then is scheduled for deletion. Integration credentials are deleted immediately on disconnection. Backups age out on a rolling 30-day cycle.

Security

Data is encrypted in transit and at rest. Each organization’s data is isolated at the database level using row-level security rather than application filtering alone. Administrative actions are written to an append-only audit log. Access to production systems is limited to personnel who need it and is itself logged.

Our infrastructure providers maintain their own third-party audits. To be precise about what that means: their certifications apply to their services, not to ours, and we do not present them as our own.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to complain to a supervisory authority. California residents may request disclosure of the categories of personal information collected and may opt out of sale — we do not sell personal information. Exercise any of these rights by writing to privacy@hipaacompliancesoftware.org; we respond within 30 days.

Where we process information on behalf of your employer, we act on their instructions, and requests about your account may be directed to them.

International transfers

We operate in the United States and process data there. If you access the service from elsewhere, you are transferring information to the United States, which may have different data protection rules than your own jurisdiction.

Children

The service is for business use and is not directed to anyone under 16. We do not knowingly collect information from children.

Changes

We will post any changes on this page and update the date above. For material changes affecting how we use your information, we will notify account administrators by email before the change takes effect.

Contact

Questions about this policy or your data: privacy@hipaacompliancesoftware.org.