Privacy & Security

Privacy Policy

Last updated: September 17, 2026

🔒HIPAA Compliant
🛡️SOC 2 Type II
🔐256-bit Encryption
GDPR Ready

Your Privacy Matters

At Anaya Care, we understand the sensitive nature of health information. This policy explains how we collect, use, and protect your data in compliance with HIPAA, GDPR, and other privacy regulations.

1. Information We Collect

We collect information you provide directly to us, including: • Personal Information: Name, email address, phone number, and professional credentials • Health Information: Client care plans, assessments, medical records (for care providers) • Account Data: Username, password, and account preferences • Usage Data: How you interact with our Service, including access times and features used • Device Information: IP address, browser type, device type, and operating system We collect this information when you register, use our Service, or communicate with us.

2. How We Use Your Information

We use the information we collect to: • Provide, maintain, and improve our Service • Process transactions and send related information • Send technical notices, updates, and support messages • Respond to your comments and questions • Monitor and analyze trends, usage, and activities • Detect, investigate, and prevent fraudulent transactions • Comply with legal obligations and protect rights and safety • Facilitate care coordination between authorized parties

3. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information. We may share information: • With your consent or at your direction • With care team members you've authorized • With service providers who assist in our operations • To comply with legal obligations or valid legal requests • To protect rights, privacy, safety, or property • In connection with a merger, sale, or acquisition All third parties are required to maintain confidentiality and security of your information.

4. HIPAA Compliance

We are committed to protecting health information in accordance with HIPAA: • We maintain physical, technical, and administrative safeguards • Access to health information is limited to authorized individuals • We conduct regular security assessments and training • Business Associate Agreements are in place with relevant parties • Audit logs track all access to sensitive health information • Breach notification procedures are established and tested

5. Data Security

We implement industry-standard security measures: • Encryption of data in transit and at rest using AES-256 • Secure socket layer (SSL) technology for all data transfers • Regular security audits and vulnerability assessments • Multi-factor authentication options for enhanced account security • Regular backups with encrypted storage • Incident response procedures for potential security events

6. Data Retention

We retain your information for as long as necessary to: • Provide our services to you • Comply with legal obligations (typically 7 years for health records) • Resolve disputes and enforce agreements • Support legitimate business interests You may request deletion of your account, subject to legal retention requirements.

7. Your Rights and Choices

You have the right to: • Access your personal information • Correct inaccurate or incomplete information • Request deletion of your information (subject to legal requirements) • Object to or restrict certain processing • Data portability in machine-readable format • Withdraw consent where processing is based on consent • File a complaint with supervisory authorities To exercise these rights, contact privacy@anayacare.com

8. Children's Privacy

Our Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses and adequacy decisions.

10. Cookies and Tracking

We use cookies and similar technologies to: • Keep you signed in • Remember your preferences • Analyze usage patterns • Deliver targeted content You can manage cookie preferences through your browser settings. Disabling cookies may limit functionality.

11. Third-Party Services

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to read their privacy policies before providing information.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or Service notification. Your continued use after changes indicates acceptance of the updated policy.

13. Contact Us

For privacy-related questions or concerns: Data Protection Officer Anaya Care, Inc. Email: privacy@anayacare.com Phone: 1-800-ANAYA-DPO Address: 123 Healthcare Blvd, Suite 100, San Francisco, CA 94105 You may also contact your local data protection authority.

Your Data is Protected

We employ industry-leading security measures to ensure your information remains confidential and secure.