Privacy Policy
Last updated: February 27, 2026
1. Introduction
GCode Systems ("we," "us," or "our") is committed to protecting the privacy of individuals whose information is processed through our nonprofit management platform. This Privacy Policy describes how we collect, use, store, and disclose information when you use our Service.
2. Information We Collect
2a. Organization Account Information
When your organization signs up for the Service, we collect contact information (name, email, phone), organization details (name, type, size), and billing information necessary to manage your subscription.
2b. User Account Information
For each user provisioned by your organization, we collect name, email address, role, and authentication credentials (hashed passwords, MFA configuration).
2c. Client and Program Data
Your organization enters client data, case notes, assessments, service records, and other program-related information into the Service. This data may include Protected Health Information (PHI) and is processed on behalf of your organization as a data processor. We do not access this data except as necessary to provide the Service.
2d. Usage and Log Data
We automatically collect information about how the Service is accessed and used, including IP addresses, browser type, pages visited, and timestamps. This data is used for security monitoring, audit logging, and service improvement.
3. How We Use Information
We use collected information to:
- Provide, maintain, and improve the Service
- Process billing and manage subscriptions
- Communicate with you about your account and the Service
- Detect, prevent, and address security incidents and fraud
- Maintain HIPAA-required audit trails and access logs
- Comply with legal obligations
4. Data Security and Encryption
We implement robust security measures to protect your data:
- Encryption at rest: All sensitive data is encrypted using AES-256-GCM with per-organization encryption keys. Each organization's data is encrypted with a unique key that only their organization controls.
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Access controls: Role-based access control (RBAC) ensures users can only access data appropriate for their role. Row-level security is enforced at the database level.
- Multi-factor authentication: MFA is available and can be required by organization administrators.
- Audit logging: All data access and modifications are logged for HIPAA compliance and security monitoring.
- Session management: Automatic session timeouts after 15 minutes of inactivity.
5. Data Sharing and Disclosure
We do not sell your data. We may share information only in the following circumstances:
- Service providers: With trusted third-party providers who assist in operating the Service (e.g., cloud hosting, payment processing), under strict contractual obligations.
- Legal requirements: When required by law, subpoena, court order, or government regulation.
- Safety: When necessary to protect the rights, safety, or property of GCode Systems, our users, or the public.
- With your consent: When your organization has provided explicit authorization.
6. HIPAA and Protected Health Information
For organizations subject to HIPAA, we enter into a Business Associate Agreement (BAA) that governs our handling of PHI. Under the BAA, we agree to:
- Use and disclose PHI only as permitted by the BAA and HIPAA
- Implement appropriate safeguards to protect PHI
- Report any security incidents or breaches promptly
- Ensure subcontractors agree to the same restrictions
- Make PHI available to individuals exercising their HIPAA rights
- Return or destroy PHI upon termination of the agreement
7. Data Retention
We retain your data for as long as your subscription is active. Upon termination, data is available for export for 90 days, after which it is securely deleted. Audit logs are retained for a minimum of 6 years to comply with HIPAA requirements. You may request early deletion by contacting us, subject to legal retention requirements.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Export your data in a machine-readable format
- Object to or restrict certain processing of your data
To exercise these rights, contact us at info@thegcodesystems.com. For client data entered by your organization, please contact your organization directly, as they are the data controller.
9. Cookies and Tracking
We use essential cookies for authentication and session management. We do not use third-party advertising cookies. Analytics cookies, if used, are anonymized and do not track individual users across sites.
10. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13 as direct users of the Service. Organizations serving youth populations are responsible for compliance with COPPA and applicable state laws regarding minors' data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days before they take effect by email or through the Service. The "Last updated" date at the top of this page indicates when the policy was last revised.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
GCode Systems
Email: info@thegcodesystems.com