Effective February 2, 2026
This policy describes how Compassly, LLC handles personal information on our marketing site and, at a high level, how product data is treated for behavioral health customers. PHI in a customer environment is governed by the BAA and customer agreement.
Who we are
Compassly, LLC (“Compassly,” “we,” “us”) provides clinical operations software for behavioral health organizations. This Privacy Policy covers compassly.io, demo and support communications, and general product privacy practices.
Controller for marketing-site and lead data: Compassly, LLC. Contact: support@compassly.io. A registered mailing address is available on request.
For PHI processed on behalf of a customer after a BAA is signed, Compassly acts as a business associate. That PHI is not used for Compassly marketing.
Two different data contexts
Website and sales: information you submit on compassly.io, in demo requests, careers inquiries, or support email, plus limited technical data from your browser.
Customer product: records your organization stores in Compassly (clinical, operational, workforce). That environment is controlled by the customer. Workforce users should follow their employer’s policies. Individuals seeking copies of their own health records should contact the provider organization, not Compassly’s marketing site.
Information we collect
Depending on how you interact with us, we may collect:
- Identity and contact details you provide (name, work email, phone, organization, role).
- Demo and support content (program type, site count, questions you send).
- Account identifiers created when a customer provisions users.
- Device and log data reasonably needed to operate the site and product (IP address, browser type, approximate region, timestamps, security events).
- Limited analytics if you consent on this site (see Privacy Choices). Default for marketing analytics is denied until you opt in.
- Information you submit through a privacy request form (access, deletion, correction, or other requests).
Sources
We collect information directly from you, from your organization when it invites you as a user, from service providers that host or secure the Services, and from publicly available business contact sources when we respond to inbound sales interest. We do not buy sensitive health information for advertising.
How we use information
We use personal information to:
- Operate compassly.io, respond to demo and support requests (target: one business day), and communicate about the Services.
- Authenticate users, assign roles, maintain audit logs, and protect against abuse.
- Provide, maintain, and improve the product under a customer agreement and BAA where applicable.
- Meet legal, security, and recordkeeping obligations.
- Send operational messages you or your organization enable (including SMS where consented).
Assisted product features
Some product capabilities may use automated assistance (for example, documentation support when generally available). We do not use customer PHI from production environments to train public foundation models. Any future assistance features will follow the customer agreement, BAA, and approved marketing claims—no unverified AI promises.
Retention
Marketing and support records are kept for as long as needed to respond, maintain business records, and meet legal obligations, then deleted or de-identified. Customer Data retention follows the customer agreement, BAA, and the customer’s own retention rules. Security logs are kept for a period reasonably needed for incident investigation.
Security
We use administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption in transit, role-based access, authentication options such as multi-factor and mobile biometrics, and audit logging. No method of transmission or storage is perfectly secure. Details live on /security. We do not display HITRUST, PCI DSS, or SOC 2 marks because those certifications are not claimed today.
Your privacy rights
Depending on your location (including U.S. state consumer laws such as those in California, Colorado, Connecticut, Virginia, and Utah), you may have rights to request access, correction, deletion, a copy of personal information, and to appeal a denial. You may also opt out of sale or sharing—practices we do not currently perform.
Submit a request at /privacy-request or email support@compassly.io. We will need enough information to verify you and to distinguish marketing records from Customer Data we process only as a business associate. PHI requests are typically fulfilled by the customer covered entity.
Authorized agents may submit requests where the law allows, with proof of authorization. We will not discriminate against you for exercising privacy rights.
Children
The marketing site is not directed to children under 13, and we do not knowingly collect personal information from children on compassly.io. The product may be used by professionals who document care for children; that data is Customer Data under the customer’s policies and the BAA, not Compassly marketing data.
International visitors
We operate from the United States. If you access the site from another country, you understand that information may be processed in the U.S., where laws may differ from those in your location.
Changes to this policy
We will post updates on this page with a new effective date. Material changes will be described at the top of the policy. Continued use of the marketing site after the effective date means you acknowledge the updated policy.
Contact
Privacy questions and requests: Compassly, LLC, support@compassly.io. Related pages: /privacy-choices, /privacy-request, /security, and /baa.
