Privacy Policy
Last Updated: June 25, 2026
This Privacy Policy ("Privacy Policy") describes how Complya, Inc. ("Complya," "we," "us," and "our") collects, uses, stores, and shares information. This policy applies to all interactions with our public website located at https://complya.com (the "Site") and our proprietary enterprise practice management platform, associated artificial intelligence features, and technical services (collectively, the "Products" or "Services").
COMPLYA DOES NOT SELL YOUR PERSONAL INFORMATION, NOR DO WE DISCLOSE OR SHARE PERSONAL INFORMATION WITH THIRD PARTIES FOR THEIR DIRECT MARKETING PURPOSES. WE OPERATE EXCLUSIVELY AS A SERVICE PROVIDER AND BUSINESS ASSOCIATE PURSUANT TO APPLICABLE U.S. DATA PRIVACY LAWS.
By accessing the Site or using the Services, you acknowledge that you have read and understood the practices described herein. This policy is incorporated by reference into our Terms of Service and Master Service Agreement ("MSA").
1. Handling of Protected Health Information
Complya operates as a "Business Associate" as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). A substantial portion of data processed through our Products constitutes Protected Health Information ("PHI").
1.1 Primacy of the Business Associate Agreement (BAA)
The collection, use, maintenance, and disclosure of PHI are governed exclusively by the Business Associate Agreement ("BAA") located at https://complya.com/baa and the specific Notice of Privacy Practices provided by our Customers (healthcare providers). In the event of any inconsistency or conflict between this Privacy Policy and the BAA regarding the processing of PHI, the terms of the BAA shall supersede and prevail.
1.2 Infrastructure and Technical Isolation
Complya secures Customer Data in accordance with HIPAA requirements and industry-standard security frameworks. Our technical security protections include:
- Logical Isolation: Customer PHI is stored in logically isolated environments with strict network segmentation to prevent unauthorized cross-tenant access or data leakage.
- Minimum Necessary Access Protocols: Complya personnel may access PHI only for limited, audited troubleshooting purposes initiated or authorized by the Customer; all such access is logged and subject to audit.
- Encryption Standards: All PHI is encrypted at rest utilizing AES-256 and in transit utilizing TLS 1.2 or higher.
Complya's security program is designed to meet HIPAA Security Rule requirements and industry-standard best practices. Complya conducts regular security assessments and maintains comprehensive audit logs of access to systems containing PHI.
1.3 Performance Data and Clinical Metrics
In providing Services, users input clinical performance data such as trial-by-trial accuracy, behavioral frequency, and session progression metrics. Complya treats all such data with the same technical and legal safeguards as PHI, using it solely to generate clinical documentation and reporting for the Customer.
2. Information Collection and Sources
We collect information through two primary channels: (i) information provided directly by Customers and Authorized Users, and (ii) technical data collected automatically during interaction with the Services.
2.1 Statutory Information Categories
The following table describes the categories of personal information we may have collected about consumers within the last twelve (12) months.
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Real name, postal address, unique personal identifier, IP address (collected via server logs and security infrastructure; analytics SDKs are configured not to collect IP addresses), email, and account credentials. | YES |
| Customer Records | Signature, physical characteristics, telephone, insurance policy numbers, and medical info. | YES |
| Protected Classifications | Age, race, religion, marital status, disability, gender identity, and sexual orientation. | YES |
| Commercial Information | Records of services purchased, obtained, or considered within the Complya ecosystem. | YES |
| Biometric Information | Genetic, physiological, behavioral, or biological characteristics. | NO |
| Internet Activity | Interaction with the Site/Platform, search history within the app, and diagnostic logs. | YES |
| Geolocation Data | Physical movements used exclusively for Electronic Visit Verification (EVV) compliance. | YES |
| Sensory Data | Audio, electronic, visual, thermal, or olfactory information. | NO |
| Professional/Employment | Job history and performance evaluations for clinical staff (BCBAs/RBTs). | YES |
| Education Information | Records related to student progress and disciplinary records for school-based services. | YES |
| Inferences | Profiles reflecting psychological trends, predispositions, or intelligence/abilities. | NO |
2.2 Sources of Collection
- Direct Interaction: Information provided by you during account registration, Customer Support interactions, or clinical data entry.
- Automatic Collection: Data gathered via cookies, web beacons, server logs, and mobile and web software development kits ("SDKs") used for analytics, session replay, and diagnostics (described in Section 2.3), including device and usage information.
- Third-Party Data: We may receive information from third-party payers or integrated service providers as authorized by the Customer to facilitate the Services.
2.3 Analytics, Session Replay, and Mobile Diagnostics
To operate, secure, and improve our web and mobile applications, we and our subprocessors collect limited technical and usage information through embedded SDKs. This processing is configured to exclude Protected Health Information, as described below.
- Product Analytics: We use Amplitude to capture product-usage events such as screens viewed, features used, session activity, and the device, operating-system, and application-version attributes. Events are associated with a pseudonymous account identifier (the authenticated user's Complya ID, role, and workspace). The analytics SDK is configured not to collect end-user IP addresses.
- Session Replay: Within our applications we use Amplitude Session Replay to record in-application interactions and screen renders (such as navigation and taps) so we can diagnose usability and reliability issues. Session Replay is configured with privacy masking so that input fields and views containing Protected Health Information or other sensitive client information (such as client names, dates of birth, clinical notes, and goal data) are masked and are not captured in the recording. Recordings are used solely for internal product and reliability purposes and are never used for advertising.
- Performance and Crash Monitoring: We use New Relic across our web and mobile applications to collect diagnostic information such as crash reports, performance metrics, network-request metadata (excluding request and response bodies and URL query parameters that may contain identifiers), and device and operating-system attributes, in order to detect and resolve errors. We also use Datadog for infrastructure-level monitoring, log aggregation, and application performance management; Datadog is configured to collect operational metadata only and does not receive Protected Health Information.
- Mobile Device Identifiers: Our mobile application may process device and installation identifiers for the analytics and diagnostic purposes described above. We do not use these identifiers to track you across apps or websites operated by other companies, we do not sell this information, and we do not use it for cross-context behavioral advertising. Complya does not use device identifiers for cross-app or cross-website advertising tracking. To the extent our applications are required to do so under applicable platform policies, we comply with App Tracking Transparency requirements.
The analytics and diagnostics SDKs described in this section are configured to prevent the capture of Protected Health Information. PHI is governed exclusively by Section 1 and the BAA. Complya does not transmit PHI to analytics subprocessors. The subprocessors referenced here are listed in Section 11.
3. How We Use Information
Complya uses collected information solely to perform its obligations under the MSA and BAA, including:
3.1 Platform Operations and Documentation
We process data to provide the core functionality of the practice management platform, including progress note generation, scheduling, and supervisory hour tracking for RBTs and BCBAs.
3.2 Billing and Insurance Claims
We use identifiers and financial data to facilitate the submission of insurance claims and manage billing between healthcare providers and third-party payers.
3.3 Security, Integrity, and Troubleshooting
We use diagnostic logs and IP addresses to monitor for unauthorized access, conduct vulnerability assessments, and troubleshoot technical issues reported by the Customer.
3.4 AI-Assisted Feature Processing
AI-powered features within the Services may process Customer Data, including PHI, through Complya's AI infrastructure and third-party AI subprocessors, solely to provide the Services to Customer. Complya does not use Customer Data or PHI to develop, train, or improve AI or machine learning models. All AI subprocessors that process PHI have executed Business Associate Agreements with Complya and are listed in Section 11.
4. Disclosure and Onward Transfers
We disclose information to third parties only in the limited circumstances described below:
- Subprocessors: We share data with a select group of service providers (listed in Section 11) who provide essential infrastructure. These entities are contractually prohibited from using your data for any purpose other than providing services to Complya.
- Compliance with Law: We may disclose data to government authorities if we believe in good faith that such action is necessary to comply with a subpoena, court order, or other valid legal process.
- Safety and Protection: We reserve the right to disclose data to protect the rights, property, or safety of Complya, our Customers, or the public.
5. AI Features
Complya uses large language models to assist clinicians in drafting documentation.
- Processing Authorization: By enabling AI features, Customers authorize Complya to process Customer Data through our third-party AI subprocessors.
- Clinical Integrity: All AI output is probabilistic and provided on an "as-is" basis. A human-in-the-loop review is mandatory for all AI-generated medical records.
- No Model Training: Complya does not use Customer Data or PHI to develop, train, or improve AI or machine learning models. Customer Data processed through AI features is used solely to provide the Services to Customer.
6. Data Retention, Export, and Destruction
Complya retains data as follows:
- Ongoing Retention: We maintain data for the duration of the active subscription term.
- 60-Day Safeguard Period: Upon termination of the Service Agreement, Complya will maintain Customer Data for a period of sixty (60) days ("Data Retention Period"). This period is provided as a safeguard to allow Customers to complete final exports.
- CSV Format: During the Data Retention Period, data is available for export exclusively in Comma Separated Values (CSV) format.
- Final Destruction: Following the 60-day period, Complya shall permanently destroy PHI and Customer Data using industry-standard data sanitization methods. Where de-identification is used in lieu of destruction for residual technical copies (e.g., backup media), Complya will apply HIPAA-standard de-identification methods and document the process accordingly.
7. Consumer Privacy Rights (CCPA/CPRA)
7.1 Patient and Client Data (PHI and Clinical Records)
Under the CCPA/CPRA, Complya acts as a Service Provider to our Customers (the healthcare organizations) with respect to patient and client data. If you are a patient or client of a Complya Customer and wish to exercise rights of access, deletion, correction, or portability over your personal information or health records, you must direct those requests to the healthcare organization that provides your care. If Complya receives such a request directly, we will refer the individual to the relevant Customer within thirty (30) days.
7.2 Authorized User Data (Employees and Contractors of Customers)
With respect to personal data Complya processes about Authorized Users (e.g., employees, BCBAs, RBTs, and contractors of our Customers) — such as account credentials, contact information, and usage analytics — Complya may act as a "business" directly under CPRA where that data is not processed solely on behalf of the Customer. Authorized Users subject to CPRA may contact Complya directly at support@complya.com to exercise rights of access, correction, deletion, or opt-out of sale or sharing (Complya does not sell or share such data). Complya will respond to verified requests within the timeframes required by applicable law.
7.3 Notice of Privacy Practices
This Privacy Policy governs Complya's own data practices as a technology vendor. It is not a HIPAA Notice of Privacy Practices ("NPP"). Customers (the covered entities and healthcare providers using Complya's platform) are solely responsible for providing their own HIPAA-compliant NPP to their patients and clients in accordance with 45 C.F.R. § 164.520. Complya's Privacy Policy does not fulfill that obligation on behalf of any Customer.
8. Protection of Minors
Our Services are professional tools used by clinicians to treat patients, many of whom are minors. Complya does not knowingly collect information directly from children under 13. All data concerning minors is provided by licensed healthcare professionals or legal guardians within an authenticated clinical environment.
9. Data Location
Complya currently operates exclusively within the United States. All data is stored and processed on servers located within the U.S.
10. Contact Information
For questions regarding this policy or to report a suspected security incident, please contact:
- Complya, Inc.
- ATTN: Privacy Officer
- Email: support@complya.com
11. Subprocessors
Complya utilizes the following third-party subprocessors to deliver the Services. All subprocessors are subject to strict data processing agreements and security audits.
| Entity | Service Description | Processes PHI |
|---|---|---|
| Amplitude | Product-usage analytics and session replay (configured with PHI masking) for platform optimization and reliability. | NO |
| Anthropic | AI language models for clinical documentation assistance. | YES |
| Apple Developer Program | Mobile application distribution and developer services. | NO |
| BetterStack | Platform monitoring, log management, and incident response. | NO |
| Cloudflare | DNS management, DDoS protection, and WAF security. | NO |
| Datadog | Infrastructure monitoring, application performance management, and log management. | NO |
| GitHub | Secure source code hosting and version control. | NO |
| Google Cloud Platform (including Firebase) | Cloud hosting, storage, primary infrastructure, and application development backend. | YES |
| Google Play Console | Mobile application distribution and developer services. | NO |
| Google Workspace | Business productivity suite (email, documents, and collaboration) for internal Complya operations; Authorized Users are responsible for ensuring PHI is not transmitted through these channels. | NO |
| HubSpot | Customer Relationship Management (CRM) for Customer support. | NO |
| New Relic | Application performance monitoring, crash reporting, and diagnostics across web and mobile. | NO |
| OpenAI | AI language models for workflow automation. | YES |
| PandaDoc | Management of MSAs and Order Forms via e-signature. | NO |
| Resend | Transactional email delivery (password resets, system notifications). | NO |
| Stripe | Payment processing and billing lifecycle management. | NO |