This policy is not legal advice. Applicable customer agreements control where they establish more specific data-handling commitments.
This Privacy Policy is not a HIPAA Notice of Privacy Practices. A Notice of Privacy Practices, where required, is issued by the covered entity to the individuals it serves. Where an executed BAA applies, it defines DODD Agency Pro's role and obligations for protected information within its scope. Nothing here states or implies that the platform is automatically, certified, or guaranteed HIPAA compliant; the platform is designed to support HIPAA-compliant operations, and HIPAA compliance is a shared responsibility between DODD Agency Pro and each agency customer.
1. Scope of This Policy
This Privacy Policy explains how DODD Agency Pro (“we,” “us,” or “the platform”) handles information when Ohio DODD provider agencies and their authorized users access the platform. It covers two distinct categories of information: information about the people who hold and use platform accounts, and the limited client information that an agency chooses to maintain in the platform on behalf of the individuals it serves.
DODD Agency Pro is a multi-tenant compliance-management platform. Each agency's data is logically separated from every other agency's data. This policy does not replace any agreement between an agency and DODD Agency Pro, including the Business Associate Agreement and the Terms of Service, which govern in the event of a conflict.
2. Information We Collect From Account Users
To create and operate an account, we collect information from the agency owners, administrators, compliance officers, and staff who use the platform. This is information about your workforce, not about the clients your agency serves.
- Account and profile details — name, work email address, agency name, role, and login credentials (passwords are stored only as salted hashes).
- Contact and billing details — the information needed to administer a subscription. Payment card data is handled by our payment processor and is not stored on our servers.
- Compliance work product — the tasks, determinations, findings, evidence descriptions, notes, and document templates your team creates while using the platform.
- Usage and technical data — log records, device and browser information, IP address, and audit trails that record who did what and when, which we use for security, troubleshooting, and integrity.
- Support communications — messages you send us through contact forms, support tickets, or email.
3. Limited Client Information We Maintain for Agencies
Separately from account information, an agency may use the Client Compliance Tracking and other enabled client-related features to support operational compliance workflows.
Agency customers control the client information they enter into DODD Agency Pro. Client Compliance Tracking stores an encrypted client name together with bounded service and compliance fields. Other enabled client-related features define their own fields. DODD Agency Pro processes that information to provide the contracted compliance-management services and does not use it for advertising, data brokerage, unrelated profiling, or training public artificial-intelligence models.
Client Compliance Tracking encrypts the client name at rest using AES-256-GCM. Its service categories and service-span dates are stored as structured operational fields and protected by tenant and role-based access controls rather than field-level encryption.
Customers must not enter medical records, diagnoses, medications, Medicaid numbers, Social Security numbers, service notes, billing information, incident narratives, or other client information into Client Compliance Tracking.
The correct home for those detailed records is your agency's own approved client-record system. Client Compliance Tracking is for identifying the client whose compliance checklist is being tracked, not for documenting care.
4. Why We Process Information
We process information only to deliver and support the compliance-management services our customers contract for, and to run the platform responsibly. Specifically, we use information to:
- provide the compliance tracking, scheduling, evidence, and reporting features an agency uses;
- authenticate users and protect accounts;
- maintain audit trails and support data integrity;
- provide customer support and respond to your requests;
- administer subscriptions and billing;
- secure, monitor, troubleshoot, and improve the reliability of the platform; and
- meet our legal and contractual obligations.
5. Customer Ownership and Control
Agencies own the data they put into the platform. As between DODD Agency Pro and an agency customer, the agency remains the owner and controller of its account data and its limited client information. We act on the agency's documented instructions.
Authorized administrators at an agency control who on their team has access, can add or remove users, and can export or delete the agency's records within the platform's features. We do not sell agency or client data, and we do not share it with third parties except the service providers described below or where required by law.
6. Our Role as a Business Associate
Where DODD Agency Pro and an agency execute a Business Associate Agreement (BAA), that agreement governs the parties' permitted uses, safeguards, subcontractor responsibilities, and breach-notification obligations for protected information within its scope.
The platform is designed to support HIPAA-compliant operations. HIPAA compliance is a shared responsibility: the agency, as the covered entity, remains responsible for its own policies, its workforce, the lawfulness of what it enters, and its obligations to the individuals it serves; DODD Agency Pro is responsible for the safeguards and commitments described in the BAA and this policy.
7. Use Restrictions
We restrict how information may be used. We do not, and will not:
- sell personal information or client information;
- use client information for advertising, data brokerage, or unrelated profiling;
- use customer or client data to train public artificial-intelligence models;
- use one agency's data for the benefit of another agency; or
- use information for any purpose beyond providing and supporting the contracted services, except as permitted by the BAA or required by law.
8. Data Minimization
Client-related features use defined fields and feature gates to limit what they collect. Client Compliance Tracking stores an encrypted name plus bounded service and service-span fields. Other enabled modules have different operational fields. Agencies should enter only what a feature requires and keep clinical source records in their approved record system.
9. Safeguards
We maintain administrative, physical, and technical safeguards intended to protect information against unauthorized access, use, or disclosure. These include:
- encryption of Client Compliance Tracking names at rest using AES-256-GCM, and encryption of data in transit using industry-standard TLS;
- role-based permissions and organization-scoped queries on client-related routes;
- audit logging of significant actions to support accountability and integrity;
- hashed and salted storage of credentials;
- server-side feature gates for protected client workflows.
No system can be guaranteed to be perfectly secure. These safeguards reduce risk but do not eliminate it, and effective security also depends on agencies protecting their own credentials and devices.
10. Vendors and Subprocessors
We use service providers to operate the platform. The categories below are supported by the application configuration; contractual terms and any required business-associate arrangements are evaluated separately.
| Category | Purpose | Typical data exposure |
|---|---|---|
| Cloud hosting | Application and database infrastructure | Application and database records; some sensitive fields use application-level encryption |
| Transactional email | Account, notification, and support email | User names and email addresses |
| Payment processing | Subscription billing | Billing contact and payment data |
| Error monitoring / logging | Reliability and troubleshooting | Technical and usage data |
See the Subprocessors page for the named providers identified in the current application configuration. Applicable agreements may include additional notice or approval terms.
11. Retention
The application retains active and archived operational records to provide the service and preserve review history. Specific post-termination retention and deletion commitments must be stated in the applicable agreement; this policy does not promise one universal schedule.
12. Deletion and Account Closure
The application supports archiving for many operational records and provides purge workflows for certain protected records. Account closure, data return, deletion, backup handling, and any certification or timeline are governed by the applicable agreement. Contact us for the terms that apply to your account.
14. Support Communications
When you contact support or submit a form, we use your message and contact details to respond and to improve support quality. Please do not include client or individual information in support requests. We may send you service and administrative messages (for example, security notices, billing notices, and important product changes); these are part of the service and are separate from any optional marketing messages, which you can opt out of.
15. Incident Handling
We maintain procedures to detect, respond to, and investigate suspected security incidents. If we discover a breach of unsecured protected health information affecting an agency's data, we will notify the affected agency without unreasonable delay and consistent with the Business Associate Agreement, the HIPAA Breach Notification Rule, and current HHS OCR guidance, and we will cooperate with the agency's own notification obligations. As the covered entity, the agency is responsible for any required notifications to affected individuals and regulators.
16. Your Legal Rights
Individuals served by an agency exercise their HIPAA and other privacy rights — such as access, amendment, and an accounting of disclosures — directly with that agency, which is the covered entity. We support our agency customers in responding to those requests as required by the Business Associate Agreement.
Account users may request access to or correction of their own account information, and depending on applicable law may have additional rights regarding their personal information. To make such a request, contact us using the details below. We will verify your identity before acting on a request.
17. How We Update This Policy
We may update this Privacy Policy as the platform, our practices, or the law change. When we make a material change, we will update the effective date above and, where appropriate, notify agency administrators through the platform or by email. The version posted at this page is the current version. Your continued use of the platform after an update takes effect means you have reviewed the change.
18. How to Contact Us
For privacy questions, requests, or to report a concern, email support@doddagencypro.com. Do not include client or individual information in your first message; we will arrange a secure channel if sensitive details are needed.
Mailing address: DODD Agency Pro, 4030 State Route 43, Kent, Ohio 44240. General questions about the platform can also be sent through our contact page.