Privacy policy
Draft. A placeholder until it’s checked by a privacy advisor. It covers Evenday’s own handling of information; each practice has its own privacy notice for its families.
Who we are
[Company name] provides Evenday to therapy practices. For your clients’ records, the practice is responsible and we act for it as its agent. For practice owners’ and staff accounts, and sign-ups, we are responsible.
What we hold
- Practice and account details: names, email addresses, and sign-in records (with the connection’s address, for security).
- Billing details: handled by Stripe; we never see card numbers.
- The practice’s records, stored encrypted.
- Demo visitors: a practice of made-up families for 24 hours, then deleted, and the connection’s address for limits.
Where it’s stored
With Cloudflare, mainly in its Oceania region. Emails are sent through Cloudflare’s email service; WhatsApp reminders (only for families who choose them) go through Meta; invoices go to Xero when the practice connects it. These providers act for us and the practice.
What we don’t do
- We don’t sell information.
- No AI reads or writes clinical notes.
- We don’t look at a practice’s records unless the practice asks us to help, or the law requires it.
Keeping it safe
Each practice’s records are private to it; everyone signs in with two steps; access to records is logged; backups are encrypted. If something goes wrong, we follow our breach response plan and tell affected practices and the Privacy Commissioner as the law requires.
Your rights
You can ask to see or correct information we hold about you: [privacy officer’s contact]. Families should contact their practice.