Skip to content

How Compassly handles website and lead information, and how customer PHI is separated under a BAA.

Effective February 2, 2026

This policy describes how Compassly, LLC handles personal information on our marketing site and, at a high level, how product data is treated for behavioral health customers. PHI in a customer environment is governed by the BAA and customer agreement.

Who we are

Compassly, LLC (“Compassly,” “we,” “us”) provides clinical operations software for behavioral health organizations. This Privacy Policy covers compassly.io, demo and support communications, and general product privacy practices.

Controller for marketing-site and lead data: Compassly, LLC. Contact: support@compassly.io. A registered mailing address is available on request.

For PHI processed on behalf of a customer after a BAA is signed, Compassly acts as a business associate. That PHI is not used for Compassly marketing.

Two different data contexts

Website and sales: information you submit on compassly.io, in demo requests, careers inquiries, or support email, plus limited technical data from your browser.

Customer product: records your organization stores in Compassly (clinical, operational, workforce). That environment is controlled by the customer. Workforce users should follow their employer’s policies. Individuals seeking copies of their own health records should contact the provider organization, not Compassly’s marketing site.

Information we collect

Depending on how you interact with us, we may collect:

  • Identity and contact details you provide (name, work email, phone, organization, role).
  • Demo and support content (program type, site count, questions you send).
  • Account identifiers created when a customer provisions users.
  • Device and log data reasonably needed to operate the site and product (IP address, browser type, approximate region, timestamps, security events).
  • Limited analytics if you consent on this site (see Privacy Choices). Default for marketing analytics is denied until you opt in.
  • Information you submit through a privacy request form (access, deletion, correction, or other requests).

Sources

We collect information directly from you, from your organization when it invites you as a user, from service providers that host or secure the Services, and from publicly available business contact sources when we respond to inbound sales interest. We do not buy sensitive health information for advertising.

How we use information

We use personal information to:

  • Operate compassly.io, respond to demo and support requests (target: one business day), and communicate about the Services.
  • Authenticate users, assign roles, maintain audit logs, and protect against abuse.
  • Provide, maintain, and improve the product under a customer agreement and BAA where applicable.
  • Meet legal, security, and recordkeeping obligations.
  • Send operational messages you or your organization enable (including SMS where consented).

Assisted product features

Some product capabilities may use automated assistance (for example, documentation support when generally available). We do not use customer PHI from production environments to train public foundation models. Any future assistance features will follow the customer agreement, BAA, and approved marketing claims—no unverified AI promises.

How we share information

We share personal information with service providers who host, secure, communicate, or support the Services under contract; with your organization when you are a product user; with professional advisors; and when required by law or to protect rights, safety, or security.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising as those terms are used in U.S. state privacy laws. If that practice ever changes, we will update this policy and Privacy Choices before it begins.

Material subprocessors used to run the product are available on request in a sales-led security review. We do not list speculative vendors here.

Cookies and similar technologies

Essential cookies or local storage may be required for security and basic site function. Measurement tags (including Google Tag Manager / GA4 when configured) stay off until you opt in on Privacy Choices, matching our default-denied consent posture.

You can change that choice at any time on /privacy-choices. Browser controls may also block cookies; blocking essentials can break parts of the site.

Retention

Marketing and support records are kept for as long as needed to respond, maintain business records, and meet legal obligations, then deleted or de-identified. Customer Data retention follows the customer agreement, BAA, and the customer’s own retention rules. Security logs are kept for a period reasonably needed for incident investigation.

Security

We use administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption in transit, role-based access, authentication options such as multi-factor and mobile biometrics, and audit logging. No method of transmission or storage is perfectly secure. Details live on /security. We do not display HITRUST, PCI DSS, or SOC 2 marks because those certifications are not claimed today.

Your privacy rights

Depending on your location (including U.S. state consumer laws such as those in California, Colorado, Connecticut, Virginia, and Utah), you may have rights to request access, correction, deletion, a copy of personal information, and to appeal a denial. You may also opt out of sale or sharing—practices we do not currently perform.

Submit a request at /privacy-request or email support@compassly.io. We will need enough information to verify you and to distinguish marketing records from Customer Data we process only as a business associate. PHI requests are typically fulfilled by the customer covered entity.

Authorized agents may submit requests where the law allows, with proof of authorization. We will not discriminate against you for exercising privacy rights.

Children

The marketing site is not directed to children under 13, and we do not knowingly collect personal information from children on compassly.io. The product may be used by professionals who document care for children; that data is Customer Data under the customer’s policies and the BAA, not Compassly marketing data.

International visitors

We operate from the United States. If you access the site from another country, you understand that information may be processed in the U.S., where laws may differ from those in your location.

Changes to this policy

We will post updates on this page with a new effective date. Material changes will be described at the top of the policy. Continued use of the marketing site after the effective date means you acknowledge the updated policy.

Contact

Privacy questions and requests: Compassly, LLC, support@compassly.io. Related pages: /privacy-choices, /privacy-request, /security, and /baa.

Compassly

Compassly

Clinical operations, at treatment speed.

Scalable software for behavioral health teams that need mobile documentation, progress tracking, and operational control—without burying clinicians in admin work.

© 2026 Compassly, LLC

COMPASSLY