Legal
Privacy Policy
This policy explains how Cadence ABA, Inc. (“Cadence,” “we,” “us”) handles information when you visit our site and when your organization uses our platform.
Last updated September 2, 2026
Our two roles
We handle two kinds of data differently. For protected health information (PHI) - the client and session data your organization records in Cadence - we act as a Business Associateand process it solely on your organization's behalf, under a Business Associate Agreement and the terms described on our HIPAA & BAA page. For account and website data, we act as the controller and handle it as described below.
Information we collect
- Account & organization data - names, work email addresses, professional credentials, roles, and clinic affiliations of the staff you invite.
- Clinical data (PHI) - client records, session captures, notes, and authorizations that your staff enter or generate. We process this only to provide the service.
- Usage & device data - log data such as IP address, browser type, and actions taken, used to operate, secure, and improve the service.
- Marketing site forms - if you subscribe to our newsletter we keep your email address, where you signed up, and the IP address of the request; if you use the contact form we keep your name, email, organization, role, and message, and deliver them to our team by email. Neither form is a place for client information; please do not include PHI in a message to us.
- Billing data - handled by our payment processor, Stripe. We receive subscription and usage counts, not full card numbers, and Stripe receives no PHI.
How we use information
- To provide, maintain, and secure the platform.
- To generate documentation, validate authorizations, and prepare billing - always subject to a clinician's review and sign-off. What the automated agents may and may not do with that data is set out on AI accuracy & safety.
- To provide support and respond to your requests.
- To improve the product. We do not sell personal information, and we neveruse PHI to train AI models - ours or a vendor's.
Service providers and sharing
We share data only with vetted service providers that help us run the service. Those that can access PHI are our AI provider (Anthropic), speech-to-text (Deepgram), database host (Neon), and application host (Vercel); every one of them is covered by a BAA, and their roles are listed on our HIPAA & BAA page.
Three providers handle non-PHI data only: Stripe processes billing (subscription and usage counts, never PHI), Resend delivers our transactional email (invitations, password resets, email verification, and the contact-form relay - staff names and email addresses, never PHI), and, on the marketing site only, Google Analytics runs after you accept analytics cookies and Vercel Web Analytics counts page views without cookies or identifiers. We may also disclose information if required by law or to protect rights and safety.
How we protect information
We encrypt data in transit (TLS) and at rest, apply field-level AES-256-GCM encryption to the most sensitive PHI identifiers, enforce role-based access on the principle of minimum necessary, and maintain an append-only audit trail of access to clinical data.
Data retention and deletion
We retain account data for as long as your organization maintains an account. PHI is retained under your organization's record-retention policy, which your administrators set in Cadence: by default, seven years after a client is discharged. When a discharged client's records pass that window, the encryption keys for their direct identifiers are destroyed, which renders those identifiers unrecoverable; records under a legal hold are never affected. On termination, data is returned or securely deleted per your BAA. Your organization can export any client's record from within Cadence at any time, and you may request export or deletion of account data by contacting us. Analytics cookies set with your consent on the marketing site expire after 180 days.
Your rights and patient rights
Requests by individuals to access, correct, or delete clinical records are handled by the clinic that maintains the record (the covered entity); we support those organizations in fulfilling such requests. For account data, you may contact us to exercise rights available to you under applicable law.
Children's data
ABA services are frequently delivered to minors. Any data about a minor is PHI that we process strictly on behalf of the treating clinic - never for our own marketing - and we do not engage in behavioral advertising.
Cookies & product analytics
The signed-in application (/app) uses a single essential, httpOnly session cookie to keep you signed in, and no third-party analytics or advertising cookies - no external tracker runs on any page that can display PHI.
On our public marketing pages we use Google Analytics to understand aggregate, non-PHI site traffic - but only after you accept analytics cookies in our consent banner; decline and it never loads. It sets first-party analytics cookies only; we do not use cross-site advertising cookies, and it never loads on the authenticated application. Our host, Vercel, also counts page views on the marketing pages without cookies or identifiers (Vercel Web Analytics); it receives the page's address only, never a query string, and never a page inside the application. You can change your cookie choice anytime via “Cookie preferences” in the footer.
We also keep our own first-party product analytics, stored in our database and never shared with an analytics vendor. On the marketing site this records which pages were viewed and which campaign or referrer introduced a visit; that record is tied to a first-party cookie identifying your browser only if you accept analytics cookies. Decline, and the visit is still counted in the aggregate, but no analytics identifier is stored on your device - only your consent choice itself, in your browser's local storage - and the record is not linked to you.
Inside the application we record product usage - which section of the app was opened, and the same account actions already written to the HIPAA audit log - so we can see where the product is working and where people get stuck. This data is deliberately free of protected health information: we store the section of the app (for example “schedule”), never a page address that identifies a client, never a client’s name, and never anything a clinician typed or dictated. It sets no additional cookie.
Contact us about privacy
Questions about this policy, requests about your account data, and reports of unwanted email all go to privacy@cadenceaba.com. Clinical-record requests should go to the clinic that maintains the record; if you are unsure which organization that is, write to us and we will help you reach them.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above and, where appropriate, communicated to account administrators.