Legal
Privacy Policy
Last updated:
This Privacy Policy describes how Case Flow ID LLC ("CaseFlow," "we," "us") handles business and account data and website/usage information for our professional (B2B) users.
Important — PHI is not covered by this Policy. Protected Health Information (PHI) that CaseFlow processes on behalf of a Covered Entity is governed by HIPAA and the separate Business Associate Agreement (BAA), not by this Privacy Policy. Where this Policy and the BAA could conflict regarding PHI, the BAA controls.
1. Scope
This Privacy Policy applies to business and account data and website/usage information for professional users of the Case Flow ID service at https://caseflow.id.
2. Data We Collect
| Category | Examples |
|---|---|
| Account information | Name, professional role, organization, login credentials (hashed) |
| Professional contact info | Business email, business phone, clinic/lab name |
| Usage / log data | Pages/features used, timestamps, audit events (non-PHI), error/diagnostic events |
| Device/technical | IP address, browser/user agent, approximate location (from IP) |
| Cookies / similar | Session and preference cookies |
We do not intend to collect PHI through this Policy's data flows. PHI submitted into the Service is handled under the BAA.
3. How We Collect Data
- Directly from you (registration, account settings, support requests).
- Automatically (server logs, cookies, usage analytics) as you use the Service.
- From your browser/device (technical metadata).
4. How We Use Data
- Provide, operate, secure, and improve the Service.
- Authenticate users and maintain account security.
- Provide support and service communications.
- Maintain audit/security logs (PHI-free).
- Comply with legal obligations.
5. Legal Bases / Purposes
We process business/account data to perform our contract with you (the Terms of Service), for our legitimate business interests (security, service operation), and to comply with law.
6. Cookies and Tracking
We use essential and functional cookies, and may use limited analytics. We do not use advertising trackers on PHI.
7. Sharing With Subprocessors / Vendors
- We share data with vendors/subprocessors that help operate the Service (for example, cloud hosting).
- Vendors handling PHI are subject to required agreements (for example, an AWS Business Associate Agreement).
- We do not sell personal information.
8. Data Security (Overview)
We maintain administrative, physical, and technical safeguards designed to protect data, including encryption at rest, access controls, and PHI-minimized logging. No method of transmission or storage is 100% secure.
9. Data Retention
We retain business/account data as needed to operate the Service and meet legal obligations. PHI retention is governed by the BAA and applicable rules.
10. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, or delete certain personal data, and to other rights under applicable law. To make a request, contact info@caseflow.id.
11. State Privacy Laws
State consumer-privacy laws (for example, California CCPA/CPRA, and laws in other states) may grant additional rights and impose specific disclosures. Many have exemptions for HIPAA-regulated data and/or B2B data.
12. Children's Data
The Service is not directed to children and is intended for professional users. Any minor patient data processed through the Service is PHI governed by the BAA and HIPAA, not this Policy.
13. International Users
The Service is intended for U.S. use.
14. Changes to This Policy
We may update this Policy. Material changes will be notified and, where required, will require re-acknowledgment. The "Last updated" date on this page reflects the current published version.
15. Contact / Privacy Requests
- Privacy requests and legal notices: info@caseflow.id
- General support: support@caseflow.id