Privacy Policy
Last updated: June 2, 2026
1. Introduction
SOPdesk, Inc. ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SOPdesk service ("Service"). We are committed to maintaining the highest standards of data protection and security.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, organization name, and other information necessary to provide the Service.
Content and Documents
We collect and store the Standard Operating Procedures, documents, images, and other content you upload or create using the Service. This may include healthcare-related information.
Usage Information
We automatically collect information about how you use the Service, including pages visited, features used, time spent, and other analytics data.
Technical Information
We collect technical information such as IP address, browser type, device information, and operating system to provide and improve the Service.
3. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve the Service
- Process transactions and manage your account
- Provide AI-powered features for SOP creation and assistance
- Send service-related communications and updates
- Ensure security and prevent fraud
- Comply with legal obligations and healthcare regulations
- Analyze usage patterns to improve user experience
4. Information Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
- With your consent: When you explicitly authorize us to share information
- Service providers: With trusted third parties who assist in operating the Service
- Legal requirements: When required by law or to protect rights and safety
- Business transfers: In connection with mergers, acquisitions, or asset sales
- Within your organization: With other users in your organization as configured by administrators
5. Healthcare Data Protection
SOPdesk is designed for healthcare organizations and we understand the sensitivity of the information you manage. We implement robust security measures to protect your data:
- Data encryption in transit and at rest
- Role-based access controls and user authentication
- Comprehensive audit logging and monitoring
- Regular security assessments and updates
- Secure backup and disaster recovery procedures
Important — Not Intended for PHI: SOPdesk is a documentation, training, and compliance management platform. It is not intended for, and must not be used to store or transmit, Protected Health Information (PHI) such as patient names, medical record numbers, or other individually identifiable patient health data. SOPdesk does not act as a HIPAA Business Associate and is not represented as "HIPAA compliant." Users are responsible for ensuring their SOPs and documentation do not contain PHI or other sensitive patient data.
6. Data Security
We implement comprehensive security measures to protect your information:
- End-to-end encryption for data transmission
- AES-256 encryption for data storage
- Multi-factor authentication options
- Regular security audits and penetration testing
- Secure cloud infrastructure with AWS
7. AI and Machine Learning
Our Service includes AI features to assist with SOP creation and management. When you use these features:
- Your content may be processed by AI systems to provide suggestions and improvements
- We do not use your content to train AI models for other customers
- AI processing is performed securely and in compliance with privacy regulations
- You maintain control over your content and can opt out of AI features
8. Data Retention and Deletion
Retention: We retain your information for as long as your account is active or as needed to provide the Service. Some information may be retained longer for legal compliance.
Deletion: When you delete your account, we will delete your personal information and content within 30 days, except where retention is required by law.
Backup Data: Deleted data may remain in backup systems for up to 90 days before permanent deletion.
9. Your Rights and Choices
You have the following rights regarding your information:
- Access: Request a copy of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Export your data in a standard format
- Restriction: Limit how we process your information
- Objection: Object to certain processing activities
To exercise these rights, contact us at [email protected].
10. Cookies and Tracking
We use cookies and similar technologies to provide functionality, remember preferences, and analyze usage. You can control cookie settings through your browser, though some features may not work properly if disabled.
See our Cookie Policy for detailed information about our use of cookies.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses and adequacy decisions.
12. Children's Privacy
The Service is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Significant changes will be communicated via email or Service notification.
14. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
SOPdesk, Inc. - Privacy Officer
Email: [email protected]
Phone: +1 (800) SOP-ILOT
Address: 123 Healthcare Drive, Suite 100, Medical City, MC 12345
