Privacy Policy
This Privacy Policy explains how QSP Central ("QSP Central," "we," "us") collects, uses, and protects information in connection with the QSP Central care-operations platform (the "Service"), including the websites at qspcentral.com and app.qspcentral.com.
1. Who we are and our role
QSP Central provides care-operations software to North Dakota Qualified Service Providers ("QSP agencies" or "customers"). When we process protected health information ("PHI") on behalf of a QSP agency, we act as a Business Associate under the Health Insurance Portability and Accountability Act ("HIPAA"), and that processing is governed by a separate Business Associate Agreement ("BAA") with the agency. Where the BAA and this Policy conflict as to PHI, the BAA controls.
2. Information we collect
- Account & contact information — name, work email, agency, and role, used to create and secure accounts (authentication is provided by Clerk).
- Customer data, including PHI — caregiver, individual-served, schedule, authorization, timesheet, and payroll records that an agency imports or enters. This is processed under the agency's direction and the BAA.
- Usage & device data — log data such as IP address, timestamps, and actions taken, used for security, audit, and reliability.
3. How we use information
- To provide, secure, and improve the Service.
- To authenticate users and enforce role-based access.
- To maintain an append-only audit log of actions for security and compliance.
- To communicate with customers about the Service.
- To comply with legal obligations.
We do not sell personal information or PHI, and we do not use PHI for advertising.
4. Service providers (subprocessors)
We use vetted vendors to operate the Service, each under appropriate contractual and (where applicable) BAA protections, including: Amazon Web Services (hosting and storage), Clerk (authentication), and payroll export to ADP at the agency's direction. A current list of subprocessors is available on request at qspcentral@gmail.com.
5. How we protect information
Safeguards include tenant isolation enforced at the database layer (row-level security), least-privilege access roles, encryption in transit, an append-only audit log, and soft-deletion (records are archived, not destroyed). No method of transmission or storage is perfectly secure, but we work to protect information using reasonable administrative, technical, and physical safeguards consistent with HIPAA.
6. Data retention
We retain customer data for as long as an agency uses the Service and as required by the BAA and applicable law. Upon termination, customer data is handled as described in the BAA and the Terms of Service.
7. Your choices and rights
Individuals whose PHI is processed should direct privacy requests to the QSP agency that controls that data; we will support the agency in responding as required by the BAA. For account or website data, contact us at qspcentral@gmail.com.
8. Children's privacy
The Service is intended for use by QSP agency staff and is not directed to children. Any information about individuals served is handled as PHI under the BAA.
9. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with an updated effective date.
10. Contact
Questions about this Policy? Email qspcentral@gmail.com.