Legal

Privacy Policy

This policy explains how Cadence ABA, Inc. (“Cadence,” “we,” “us”) handles information when you visit our site and when your organization uses our platform.

Last updated June 30, 2026

Our two roles

We handle two kinds of data differently. For protected health information (PHI)—the client and session data your organization records in Cadence—we act as a Business Associateand process it solely on your organization's behalf, under a Business Associate Agreement and the terms described on our HIPAA & BAA page. For account and website data, we act as the controller and handle it as described below.

Information we collect

  • Account & organization data — names, work email addresses, professional credentials, roles, and clinic affiliations of the staff you invite.
  • Clinical data (PHI) — client records, session captures, notes, and authorizations that your staff enter or generate. We process this only to provide the service.
  • Usage & device data — log data such as IP address, browser type, and actions taken, used to operate, secure, and improve the service.
  • Billing data — handled by our payment processor, Stripe. We receive subscription and usage counts, not full card numbers, and Stripe receives no PHI.

How we use information

  • To provide, maintain, and secure the platform.
  • To generate documentation, validate authorizations, and prepare billing—always subject to a clinician's review and sign-off.
  • To provide support and respond to your requests.
  • To improve the product. We do not sell personal information, and we do not use your PHI to train third-party models beyond what is necessary to provide the service to you.

Service providers and sharing

We share data only with vetted subprocessors that help us run the service—our AI provider (Anthropic), speech-to-text (Deepgram), database host (Neon), application host (Vercel), and payment processor (Stripe). Every subprocessor that can access PHI is covered by a BAA; the full list and their roles are on our HIPAA & BAA page. We may also disclose information if required by law or to protect rights and safety.

How we protect information

We encrypt data in transit (TLS) and at rest, apply field-level AES-256-GCM encryption to the most sensitive PHI identifiers, enforce role-based access on the principle of minimum necessary, and maintain an append-only audit trail of access to clinical data.

Data retention and deletion

We retain account data for as long as your organization maintains an account, and PHI for as long as needed to provide the service or as directed by your organization under its BAA. On termination, data is returned or securely deleted per your BAA. You may request export or deletion by contacting us.

Your rights and patient rights

Requests by individuals to access, correct, or delete clinical records are handled by the clinic that maintains the record (the covered entity); we support those organizations in fulfilling such requests. For account data, you may contact us to exercise rights available to you under applicable law.

Children's data

ABA services are frequently delivered to minors. Any data about a minor is PHI that we process strictly on behalf of the treating clinic—never for our own marketing—and we do not engage in behavioral advertising.

Cookies

The signed-in application (/app) uses a single essential, httpOnly session cookie to keep you signed in, and no third-party analytics or advertising cookies—no external trackers run on any page that can display PHI.

On our public marketing pages we use Google Analytics to understand aggregate, non-PHI site traffic — but only after you accept analytics cookies in our consent banner; decline and it never loads. It sets first-party analytics cookies only; we do not use cross-site advertising cookies, and analytics never load on the authenticated application. You can change your choice anytime via “Cookie preferences” in the footer.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “last updated” date above and, where appropriate, communicated to account administrators.

Related

Questions about this page? Contact us.