1. Overview
Liminal Desk ("we", "our", "the Platform") is committed to protecting the privacy and security of your data and your clients' data. This Privacy Policy explains what information we collect, how we use it, and the measures we take to keep it safe.
2. Information We Collect
Account Information
- Email address and password (for authentication)
- Full name, business name, phone number
- Professional credentials and license numbers
Client Data (entered by you)
- Client demographics: name, age, contact information, address
- Health information: diagnosis, care goals, comfort preferences, accessibility needs
- Personal preferences: pronouns, gender identity, spiritual preferences
- Care records: session notes (PESP assessments), advance directives, vigil plans
- Relationship and support network details
- DWDA timeline events (where applicable)
Automatically Collected
- IP addresses and user agent strings (for signature audit logging only)
- Session timestamps and activity logs
3. How We Use Your Data
- Service delivery: To operate the Platform's features — client management, scheduling, billing, and documentation.
- Security: To authenticate users, enforce session timeouts, and maintain audit trails.
- Communications: To send email notifications you have enabled (appointment reminders, invoice receipts, agreement signing requests, bereavement follow-ups).
- Legal compliance: To maintain signature audit logs as required by ESIGN/UETA.
We do NOT:
- Sell or rent your data to third parties.
- Use client data for advertising or marketing purposes.
- Share data with third parties except as described in this policy.
- Use client health information for any purpose other than providing the service.
4. Security Measures
We implement robust security measures to protect your data:
- Encryption: All data is encrypted in transit (TLS/SSL) and at rest.
- Access control: Row-level security ensures users can only access their own data.
- Session management: Automatic 15-minute inactivity timeout with re-authentication required.
- Authentication: Email verification required. No anonymous access to practitioner accounts.
- Audit logging: Forensic-grade logging for sensitive operations (digital signatures), capturing IP address, user agent, and timestamps.
- Client portal: Tokenized, time-limited access links — no client login required, reducing credential risk.
5. Data Sharing
We share data only in these limited circumstances:
- Client Portal: When you generate a portal link, your client can view their own basic information, appointments, and shared resources. You control what is shared.
- Email notifications: When enabled, emails are sent via our email service provider containing appointment details, invoice information, or agreement content.
- Legal requirements: We may disclose data if required by law, court order, or governmental authority.
6. Data Storage & Retention
- Data is stored on secure, SOC 2-compliant cloud infrastructure.
- Active account data is retained for the lifetime of your account.
- Deleted data is permanently removed within 30 days of deletion request.
- Signature audit logs are retained for 7 years for legal compliance.
- Uploaded documents are stored in encrypted storage buckets with access restricted to the owning practitioner.
7. Your Rights
You have the right to:
- Access: View all data stored in your account at any time.
- Export: Download your data using the Platform's built-in export features (CSV/reports).
- Correct: Edit or update any information through the Platform.
- Delete: Request complete deletion of your account and all associated data.
- Restrict: Control email notifications on a per-client basis via Email Preferences.
8. Cookies & Tracking
The Platform uses only essential cookies for authentication and session management. We do not use tracking cookies, analytics pixels, or third-party advertising trackers.
9. Children's Privacy
The Platform is intended for use by adult professionals. We do not knowingly collect information from individuals under 18 years of age.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification at least 30 days before taking effect.
11. Contact
For privacy-related questions or to exercise your data rights, please contact us through the Help Center or at your account administrator's designated support channel.