Last Updated: August 11, 2026
1. Overview: Two Kinds of Data, Two Roles
BEHCA, LLC (“BEHCA,” “we,” “us”) provides behavior-tracking and care-documentation services used by residential care agencies, therapeutic providers, schools, and families (the “Services”). This Privacy Policy explains what we collect, how we use it, and the choices and rights available to you.
The Services involve two very different kinds of data, and our role differs for each:
- Client Data — we process it on our customers’ behalf. Organizations and families that subscribe to BEHCA (our “Customers”) use the Services to run their care and support operations: recording information about the individuals they support — residents, program participants, students, or family members (“Clients”) — and coordinating the staff who deliver that support. The records this creates include behavioral observations, health and medication information, incident reports, messages, e-signatures, and schedules, from Client visit schedules to staff shift assignments. We refer to all of these records as “Client Data,” whether they concern a Client or a staff member, because our role is the same either way: the Customer decides what is collected and why, and BEHCA acts as the Customer’s service provider (in privacy-law terms, a “processor,” and for HIPAA-covered Customers, a “business associate” under a Business Associate Agreement). We use Client Data only to provide the Services, as described in this Policy and our agreements with the Customer.
- Account & Site Data — we are responsible for it directly. Information about our Customers, their staff and account users, prospective customers, and website visitors — such as registration, billing, support, usage, and marketing data. For this data, BEHCA is the responsible party (the “controller”).
If you are a Client (or a Client’s parent or guardian) and have questions about information recorded about you or your child, the organization or family member that maintains the records is your primary point of contact; Section 10 explains how to exercise your rights.
2. Information We Collect
Client Data (entered by or for our Customers)
- Client profile details, such as name, date of birth, photo, and support or education context;
- behavioral and wellness observations, including behavior type, intensity, duration, frequency, environmental and health-related factors, and intervention notes;
- health information, including medication lists and medication administration records (MAR), alerts, and related notes;
- incident reports, including narratives, e-signatures, and review/authorization records;
- messages sent through the Services between Customer staff and the Clients they support (see Section 7 regarding minors); scheduling records, including staff schedules, shift assignments, and visit schedules; and visit-verification records where the Customer uses Electronic Visit Verification (EVV) features. When EVV is enabled by the Customer, the location of the staff member’s device is captured at shift check-in and check-out only — as required for Medicaid EVV compliance under the 21st Century Cures Act — and is visible to the Customer; the Services do not continuously track anyone’s location.
Account & Site Data (collected by us)
- Registration and contact data: name, organization, role, email address, phone number, password (stored in hashed form);
- billing data: plan, billing address, and payment details (processed by our payment processor, Stripe; we do not store full card numbers);
- support and communications data: messages you send us, training and onboarding records;
- usage and device data: IP address, device and browser type, operating system, app version, pages and features used, timestamps, and crash logs;
- cookies and similar technologies on our websites (see Section 12).
3. How We Use Information
We use Client Data only to: provide, secure, maintain, and support the Services for the Customer; back up and restore data; prevent or address technical or security issues; comply with law; and as otherwise instructed by the Customer or permitted by our agreement with them (including any BAA). We do not use Client Data for advertising, and we do not sell it — see Section 5.
We use Account & Site Data to: create and administer accounts; process payments; provide support and training; send service communications (such as renewal, security, and change notices); send marketing about our own services to business contacts, with the ability to opt out; improve and secure the Services; and comply with law.
De-identified and aggregated data. We may de-identify and aggregate data so that it no longer identifies any person or Customer, and use it to operate, benchmark, and improve the Services. Where the source data is PHI, de-identification follows the HIPAA standard, and we commit not to attempt re-identification.
4. AI Features and Automated Processing
Some features of the Services use artificial intelligence or machine learning — for example, to help surface behavioral patterns or generate summaries for care teams. For these features:
- AI outputs are decision-support for qualified humans. They do not make care, medication, disciplinary, or eligibility decisions about any Client, and the Services are designed so that a person reviews AI outputs before they are acted on.
- We do not use identifiable Client Data to train generalized AI models, or share it with third-party AI providers for their own model training, without the Customer’s consent.
- For individuals in Australia: this section describes the kinds of decisions that may be supported by computer programs using personal information, as required by the Australian Privacy Principles. Because a human reviews and makes the relevant decisions, we do not consider the Services to make solely automated decisions that significantly affect individuals; if that changes, we will update this Policy before the change takes effect.
5. How We Share Information — and How We Don’t
We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information (including health data) for purposes other than providing the Services and the other purposes permitted by applicable law and listed here. We do not serve third-party advertising in the Services.
We disclose personal information only:
- To service providers (subprocessors) that help us run the Services — including Amazon Web Services and Germinate LLC, our affiliated infrastructure operator (hosting and server maintenance); Stripe (payment processing); Intercom (customer support conversations); Amazon SES (email delivery, region-matched to the customer); Plausible (cookieless website analytics); PostHog (error diagnostics and support); and Google Firebase (provider of SMS delivery). They may use the data only to perform services for us, under contracts that impose confidentiality and data-protection obligations.
- Within the Customer’s account, as directed by the Customer’s administrators — for example, to the staff and collaborators the Customer authorizes.
- For legal reasons: to comply with law or valid legal process (such as a subpoena or court order); to enforce our agreements; or to protect the rights, safety, or property of Clients, users, BEHCA, or others. Where legally permitted, we will notify the affected Customer before disclosing Client Data in response to legal process, so the Customer can seek protective measures.
- In a business transfer: if BEHCA is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy’s commitments. Client Data and PHI remain subject to our agreements with Customers (including BAAs) and applicable health-data laws, and we will notify Customers of any such transfer as required.
- With consent or at your (or the Customer’s) direction.
6. HIPAA
Where a Customer is a covered entity or business associate under HIPAA, BEHCA processes protected health information (PHI) as that Customer’s business associate under an executed Business Associate Agreement (BAA). The BAA governs our use, disclosure, safeguarding, breach reporting, and return or destruction of PHI, and controls over this Policy in the event of a conflict with respect to PHI.
7. Children and Students
Accounts may only be created by adults (18+). However, the Services are used by our Customers to record information about Clients who may be children, and messaging features may allow Customer staff (such as teachers) to communicate with the minors they support. We protect children’s information as follows:
- Customers are responsible for obtaining verifiable parental or guardian consent before recording a child’s information in the Services or enabling messaging for a child — or, for school customers, authorization consistent with the COPPA school-authorization framework, in which the school consents on parents’ behalf for use limited to the school-authorized educational purpose.
- Limited use. We use children’s personal information only to provide the Services to the Customer. We do not use it for marketing or advertising of any kind, do not sell it, and do not disclose it to third parties except as described in Section 5.
- Messaging safeguards. Clients — including children — can message only the staff assigned to them. Child-to-child (peer) messaging is not available. Messages are visible to the Customer’s administrators for supervision.
- We retain children’s personal information only as long as reasonably necessary to provide the Services to the Customer, in line with the retention rules in Section 9 and our written retention policy.
- Parents and guardians. Parents/guardians may review, correct, or request deletion of their child’s information by contacting the school or organization that maintains the records; we support our Customers in fulfilling these requests. If a school withdraws authorization, we will delete the affected data at the Customer’s direction.
- If we learn that personal information of a child was collected without required consent or authorization, we will delete it.
8. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including: encryption in transit (TLS) and at rest; role-based access controls and audit logging; environment segregation; personnel confidentiality obligations and training; and vendor security review. No system is perfectly secure, and you play a role too: keep credentials confidential, use strong passwords, log out of shared devices, and tell us immediately about suspected unauthorized access.
Breach notification. If a breach of security affects personal information, we will notify affected Customers and individuals, and regulators where required, in accordance with applicable law — including state breach-notification laws, the HIPAA Breach Notification Rule for PHI (via the affected Customer under the BAA), and the Australian Notifiable Data Breaches scheme.
9. Retention
- Client Data: retained while the Customer’s subscription is active and as directed by the Customer. After a subscription ends, the Customer has 30 days to export its data; after that, access ends and the data is held in secure, access-restricted storage (with no user access) until it is permanently deleted from production systems 180 days after termination, and from backups in the ordinary backup cycle. Re-subscribing within the 180-day period restores access. Deletion occurs earlier where a verified deletion request, applicable law, or a BAA requires it.
- Account & Site Data: retained for as long as the account is active and thereafter as needed for legitimate business purposes (such as billing records and tax obligations), then deleted or de-identified. Typical periods: account registration and profile data — for the life of the account and up to 2 years after closure; billing and transaction records — 7 years, to meet tax and financial record-keeping requirements; support conversations — 3 years after the ticket is resolved; marketing contact data — until you opt out or after 2 years of inactivity; security and access logs — at least 12 months (and at least 6 years where the logs relate to systems holding PHI); technical and diagnostic logs — up to 12 months; website analytics — no more than 26 months.
- Messages: retained as part of Client Data on the same schedule as all other Client Data, including the post-termination timeline above.
10. Your Privacy Rights
If you are a Client, or a parent/guardian of a Client
The organization or family member that subscribes to BEHCA controls the records about you or your child. Requests to access, correct, or delete that information should go to them; we support our Customers in responding, and will notify and cooperate with the relevant Customer if we receive your request directly.
If you are an account holder, staff user, or website visitor in the United States
Depending on your state (including California, Oregon, Colorado, Washington, and others), you may have rights to: know/access the personal information we hold about you; obtain a portable copy; correct it; delete it; and opt out of targeted advertising, sale, or certain profiling (we do not engage in these). We do not discriminate against you for exercising rights. You may exercise rights by emailing privacy@behca.com; we will verify your request and respond within the time required by your state’s law (generally 45 days, extendable where permitted). If we decline a request, you may appeal by replying to our decision, and we will explain the outcome; you may also contact your state Attorney General.
We honor opt-out preference signals such as Global Privacy Control (GPC) on our websites where required by law.
Consumer health data (Washington and Nevada)
For individuals not covered by HIPAA whose health-related data we process for our own purposes (for example, family-plan account holders tracking a family member), Washington’s My Health My Data Act and Nevada law provide additional rights: to access consumer health data, know with whom it has been shared, withdraw consent, and have it deleted. We collect and share consumer health data only as necessary to provide the Services you request, or with your consent; we do not sell consumer health data. Requests: privacy@behca.com.
If you are in Australia
We handle personal information consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You may request access to and correction of your personal information by contacting privacy@behca.com; we will respond within a reasonable period (normally 30 days). If you are unsatisfied with our response to a privacy complaint, you may complain to the Office of the Australian Information Commissioner (OAIC, www.oaic.gov.au). Australian customers’ data is hosted in Australia — see Section 11.
11. Data Residency and International Transfers
BEHCA is based in Oregon, United States, and operates region-specific hosting environments on Amazon Web Services (AWS):
- United States customers: data is hosted in AWS data centers located in the United States.
- Australian customers: data is hosted in AWS’s Sydney, Australia region. Australian customers’ Client Data is stored in Australia and is not stored outside the country.
All Australian customers’ Client Data, including backups and disaster-recovery copies, is stored in Australia, and service emails to Australian users are sent from within Australia (Amazon SES, Sydney region). Two categories of access or disclosure do involve recipients outside Australia, and we disclose them here for the purposes of APP 8:
- Support access. BEHCA’s support and engineering personnel are based in the United States and may remotely access Australian-hosted data when needed to provide support, maintenance, and security operations. This access does not move the data’s storage location outside Australia; it is role-restricted and logged.
- Billing and support. Payment and billing information (which is Account & Site Data, not Client Data) is processed by our payment processor, Stripe, in the United States. Customer-support conversations are handled through Intercom in the United States.
For these cross-border disclosures, we take reasonable steps — including contractual safeguards with our personnel and service providers — to ensure personal information is handled consistently with the Australian Privacy Principles.
12. Cookies and Analytics
Our websites and apps use only the cookies and similar technologies needed to run the service: sign-in and session management (essential) and your preferences. We do not use advertising cookies, cross-site tracking, or tracking pixels. For website analytics we use Plausible, a privacy-focused service that uses no cookies and collects only aggregate statistics — it does not create profiles of individual visitors. We use PostHog for error diagnostics and support troubleshooting, which processes technical information such as error logs and device/session details when something goes wrong. You can control cookies through your browser settings; blocking essential cookies may prevent parts of the Services from working. Where required by law, we honor Global Privacy Control signals as an opt-out (see Section 10).
13. Changes to This Policy
We may update this Policy as our Services, legal obligations, or practices change. We will post the updated Policy with a new “Last Updated” date, and for material changes we will provide at least 30 days’ advance notice by email and/or in-product notice before the changes take effect. We will not make retroactive material changes to how we handle previously collected personal information without obtaining any legally required consent.
14. Contact Us
Privacy questions, requests, and complaints: privacy@behca.com. Mail: BEHCA, LLC, 8835 SW Canyon Ln Ste 404A, Portland, Oregon 97225, United States.