Privacy Policy
Effective date: July 28, 2026 · VigilReady LLC
1. Who We Are
VigilReady LLC (“we,” “our,” or “us”) operates VigilReady, a HIPAA-compliant document management platform for disability services providers. Our principal place of business is in the United States. Questions about this policy can be directed to [email protected].
2. Information We Collect
We collect the following categories of information in connection with operating the platform:
- Account information — name, email address, and role provided at registration.
- Protected Health Information (PHI) — compliance documents uploaded by staff on behalf of clients, which may include names, dates of birth, Medicaid numbers, and service records.
- Usage data — document access events, approval actions, and audit log entries required by HIPAA.
- Technical data — session identifiers, and the request IP address, which is used for rate limiting and appears in our infrastructure provider’s access logs.
3. Cookies
The platform sets only the cookies it needs to keep you signed in and to remember which organization you are viewing: a session token, a refresh token, a one-time sign-in state value and code-exchange verifier used during login, and the selected organization. All are marked Secure and HttpOnly where the browser allows, are scoped to the application host only, and expire with your session (the refresh token after seven days). We set no advertising, analytics, or third-party cookies on the platform or on this website, and we do not load any third-party scripts, fonts, or embedded content. Because every cookie we set is strictly necessary to provide the service you asked for, we do not show a cookie consent banner.
4. How We Use Information
- To provide and operate the compliance document management service.
- To maintain the HIPAA-required audit trail of all PHI access.
- To detect and respond to unauthorized or anomalous access.
- To send system notifications (document status changes, expiring requirements).
- To comply with legal obligations including applicable federal and state regulations.
5. How We Share Information
We do not sell personal information. We share information only as follows:
- AWS (Amazon Web Services) — our cloud infrastructure provider. We maintain a Business Associate Agreement (BAA) with AWS covering all PHI stored or processed on their services.
- Payment processing — when subscription billing begins, it will be handled by Stripe. Stripe will receive only organization-level billing details (company name, billing contact, payment method). No client names, documents, or health information are transmitted to Stripe.
- Within your organization — authorized staff and administrators in your organization can access documents and compliance data scoped to your account.
- Legal requirements — we may disclose information if required by law, subpoena, or to protect the safety of individuals.
6. Data Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Documents are stored in a private Amazon S3 bucket accessible only via time-limited signed URLs. We enforce idle session timeouts and rate limiting on sensitive operations. Access to PHI is logged in an append-only audit trail. We conduct regular security reviews and monitoring.
7. Data Retention
Audit and security records are retained for at least six (6) years, as required of a business associate under 45 CFR §164.316(b)(2). Client records and uploaded documents are held on your organization's behalf: how long they are kept is governed by your organization's own record-retention obligations and by our Business Associate Agreement with you, not by a schedule we set. On termination, we return or securely destroy that data as your organization directs, in accordance with that agreement.
8. Your Rights
Depending on applicable law, you may have the right to access, correct, or delete your personal information. Requests regarding PHI must follow the process described in our HIPAA Notice. For other requests, contact [email protected].
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to account administrators. Continued use of the platform after changes take effect constitutes acceptance.