Privacy & Security
Your privacy is extremely important to us. This page outlines how we collect, use, store, disclose, and protect your personal and sensitive data when you use our website and services.
Effective Date: 01/01/2025 | Last Updated: 08/04/2025
1. Who We Are
SensePlanner is a digital platform designed to manage sensitive client information, including but not limited to personal data, health information, and behavioral records, in a secure and responsible manner.
2. Information We Collect
- Personal Identifiers: Full name, Email address, Phone number, Address
- Sensitive Client Data: Health records, Sensory profiles, Behavior assessments, Client notes or session data
- Technical Information: IP address, Browser type, Access times, Device identifiers, Cookies and usage data
3. How We Use Your Information
- To deliver and personalize our services
- To manage client cases and professional documentation
- To maintain security, audit, and regulatory compliance
- To improve website functionality and user experience
- To respond to inquiries or support requests
- To fulfill legal or contractual obligations
We do not sell your data.
4. Lawful Basis for Processing (for GDPR Users)
We process personal and sensitive data on the following lawful bases:
- Consent: You have given explicit permission for processing
- Contract: Processing is necessary to fulfill our service agreement
- Legal obligation: We must process data to comply with the law
- Legitimate interests: Processing is necessary for our legitimate business interests
5. How We Protect Your Data
- End-to-end encryption
- Secure servers and firewalls
- Role-based access control
- Regular security audits
- Staff training on data protection
6. Data Sharing and Disclosure
We may share your information in the following circumstances:
- Service providers: With trusted third-party providers under strict confidentiality agreements
- Legal authorities: When required by law or to protect rights and safety
- Authorized individuals: With therapists, guardians, or other authorized care providers as necessary
We will never sell or rent your personal information to third parties for marketing purposes.
7. Data Retention
Data is kept as long as necessary for:
- Service delivery and client care continuity
- Legal and regulatory obligations
- Professional standards and best practices
Data is securely deleted or anonymized when no longer needed.
8. Your Rights
You may have the right to:
- Access: Request a copy of your personal data
- Correction: Request corrections to inaccurate data
- Deletion: Request deletion of your data (right to be forgotten)
- Data Portability: Request your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Restrict Processing: Request limitation of processing
- Withdraw Consent: Withdraw previously given consent at any time
To exercise your rights, contact us using the details below.
9. Cookies and Tracking
We use cookies to:
- Analyze traffic and improve site performance
- Remember user preferences and settings
- Enhance security and prevent fraud
You can manage cookies through your browser settings. See our Cookie Policy for full details.
10. Children's Privacy
We do not knowingly collect data from users under 13 (or 16 in the EU) without verified parental consent. If we become aware of such collection, we will take immediate steps to delete the information.
11. International Users
Your data may be processed outside your country of residence. We ensure it is treated securely and in accordance with this policy, using appropriate safeguards such as standard contractual clauses.
12. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by posting the new policy on this page with an updated "Last Updated" date. Please check this page regularly.
We are committed to protecting the security and privacy of sensitive client data through multiple layers of protection.
Data Protection
- SSL/TLS encryption: All data transmitted between your browser and our servers is encrypted
- Secure login protocols: Multi-factor authentication and password strength requirements
- Regular updates and monitoring: Continuous system monitoring and security patches
- Firewall and malware protection: Advanced threat detection and prevention
- Database encryption: All stored data is encrypted at rest
Access Control
- Role-based access control (RBAC): Users only see data they're authorized to access
- Limited personnel access: Only authorized staff can access backend systems
- Audit trails: All access and changes are logged for accountability
- Session management: Automatic logout after inactivity periods
Secure Data Storage
- All data is stored in encrypted databases within secure hosting environments
- We use only verified and trusted plugins and themes
- Regular backups ensure data can be recovered in case of incidents
- Data centers comply with international security standards
Incident Response
We have a comprehensive incident response plan to:
- Quickly identify and contain security incidents
- Investigate and assess the scope of any breach
- Notify affected users per legal requirements (GDPR, etc.)
- Implement corrective measures to prevent future incidents
User Responsibilities
Security is a shared responsibility. Users should:
- Use strong passwords: At least 12 characters with mixed case, numbers, and symbols
- Keep credentials private: Never share your login details
- Log out when done: Especially on shared devices
- Report suspicious activity: Contact us immediately if you notice anything unusual
- Keep devices secure: Use updated antivirus and operating systems
We accept secure credit card payments via Stripe, a trusted and PCI-compliant payment processor.
Accepted Payment Methods
- Visa
- MasterCard
- American Express
- Discover (if supported)
- Other cards accepted by Stripe
Security
Your payment details are processed securely by Stripe. We do not store or have access to your full credit card information at any time. All payment information is encrypted and handled in accordance with PCI-DSS compliance standards.
Billing & Refunds
- You will be charged at the time of checkout
- A confirmation email will be sent upon successful payment
- Refunds are returned to the original payment method
- Stripe may take 5–10 business days to process refunds, depending on your bank
Disputes
If you believe there was an unauthorized or incorrect charge, please contact us first before filing a dispute through your card provider. We're happy to help resolve any concerns quickly.