CV
CaseNote Vault™

Privacy Policy

Effective Date: June 1, 2026 · Last Updated: June 28, 2026

CaseNote Vault™ is committed to the responsible stewardship of sensitive youth services data. This Privacy Policy describes how we collect, use, protect, and handle data in connection with our platform.

1Data We Collect

Organizational account data: Organization name, contact email, billing information, and administrator details provided during account setup.

Staff and user data: Names, email addresses, phone numbers, roles, and system activity logs for users your organization invites to the platform.

Youth and participant records: Personal identifying information, dates of birth, intake and referral data, case notes, attendance records, incident reports, goal plans, medication records, family engagement logs, discharge summaries, and any other records your organization enters into the platform on behalf of the youth and families you serve.

Usage and system data: Pages visited, features used, session timestamps, and browser/device identifiers — collected for platform security, stability, and product improvement purposes only.

Communications data: Support requests, feedback submissions, and any correspondence with our team.

2How We Use Your Data

  • To provide, operate, and maintain the CaseNote Vault platform and its features
  • To support case management, compliance reporting, and service delivery workflows
  • To send account-related communications (billing receipts, security alerts, service updates)
  • To respond to support requests and improve the platform based on usage patterns
  • To generate aggregated, de-identified analytics for product development
  • We do NOT use participant data for advertising or marketing purposes
  • We do NOT sell, rent, or trade your data to any third party

3HIPAA Compliance

CaseNote Vault acts as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) when our platform is used by Covered Entities to store or process Protected Health Information (PHI).

We handle PHI in accordance with HIPAA's Privacy Rule (45 CFR Part 164, Subpart E) and Security Rule (45 CFR Part 164, Subpart C). Our Business Associate Agreement (BAA) is incorporated by reference and available at casenotevault.com/baa.

By using CaseNote Vault to store or process PHI, your organization (as a Covered Entity or another Business Associate) agrees to the terms of our BAA.

4FERPA Compliance

For organizations that maintain education records subject to the Family Educational Rights and Privacy Act (FERPA), CaseNote Vault acts as a school official with a legitimate educational interest, as permitted under 34 CFR § 99.31(a)(1).

We do not use or disclose education records for any purpose other than providing services to your organization. Organizations are responsible for ensuring appropriate FERPA notices and consents are obtained from students and families as required by law.

5Data Security Measures

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
  • Encryption at rest: All stored data is encrypted using AES-256 encryption
  • Role-based access controls: Organization Owners, Program Admins, Supervisors, Staff, and Auditors each have strictly limited access permissions
  • Organization-level isolation: Each organization's data is logically isolated — no cross-organization data access is possible
  • Audit logging: All data access, creation, modification, and export events are logged with user identity, timestamp, and action type
  • Secure authentication: Multi-factor authentication and secure session management
  • Regular security reviews: Periodic internal and third-party security assessments

For our complete security posture, see our Data Security page.

6Data Retention Policy

CaseNote Vault retains participant records for a minimum of 7 years from the date of last service, consistent with standard youth services documentation requirements and applicable state regulations.

Organizations may configure their own retention periods within the platform. Upon account cancellation, your data remains accessible for 30 days for export. After the retention period expires, data is permanently and irreversibly deleted from our systems.

You may request a full data export at any time by contacting support@casenotevault.com.

7Your Rights

Subject to applicable law, you and the individuals whose data your organization manages may have the following rights:

  • Access: Request a copy of data we hold about you or your organization
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of data, subject to legal retention requirements
  • Portability: Request an export of your data in a structured, machine-readable format
  • Restriction: Request that we restrict processing of your data in certain circumstances

To exercise any of these rights, contact us at privacy@casenotevault.com.

8Third-Party Sharing

We do not sell, rent, or trade your data. We share data only in the following limited circumstances:

  • Service providers: Infrastructure, hosting, payment processing (Stripe), and email delivery providers — under strict data processing agreements
  • Legal compliance: When required by law, court order, or lawful government authority
  • Safety: To prevent imminent harm to an individual when no other lawful means exists
  • Business transfer: In connection with a merger or acquisition, with advance notice to affected organizations

We never share participant data with third parties for advertising, marketing, or research purposes without explicit written consent.

9Cookies and Tracking

CaseNote Vault uses session cookies for authentication and maintaining your logged-in state. We do not use third-party advertising cookies, cross-site tracking technologies, or behavioral analytics that are shared with advertisers.

Essential cookies required for platform operation cannot be disabled without impairing functionality.

10Changes to This Policy

We will provide at least 30 days' advance notice of material changes to this Privacy Policy via email to your organization's registered contact address. Continued use of the platform after the effective date constitutes acceptance of the revised policy.

11Contact — Privacy Concerns

For privacy questions, data requests, or to report a concern:

This Privacy Policy was prepared to describe our data practices in plain language. Organizations with specific legal compliance requirements under HIPAA, FERPA, state privacy laws, or other regulations should consult qualified legal counsel to confirm their compliance obligations.