Privacy Policy
Effective date: 4 August 2026
SuperHIPAA is a product of LowerPlane (“SuperHIPAA”, “we”, “us”). This policy explains what personal data we collect through www.superhipaa.com (the “Site”), why we collect it, who we share it with, and the rights you have over it. It applies to visitors of the Site and people who submit our forms. Data processed inside the SuperHIPAA product on behalf of customer organisations is governed by the customer agreement and, where applicable, a Business Associate Agreement — not this policy.
Data we collect
Information you give us. When you request a demo, download a resource, or contact us, we collect the details you submit: typically your name, work email address, organisation name, and workforce size, together with anything you write in a message field. Providing this information is voluntary, but we cannot respond to a request without it.
Information collected automatically. When you visit the Site, we collect standard technical data: IP address, browser type, device information, referring page, pages viewed, and timestamps. We use cookies and similar technologies for this — see our Cookie Policy for detail and controls.
Information from third parties. If you interact with us elsewhere — for example, at an event or through a partner — we may receive your business contact details from that source.
We do not intentionally collect protected health information (PHI) through the Site, and we ask that you do not submit it through our forms.
How we use your data
We use personal data to:
- Respond to your enquiries and provide the resources you request
- Operate, secure, and improve the Site, including analytics and debugging
- Send you relevant communications about SuperHIPAA, where permitted — every marketing email includes an unsubscribe link
- Manage our sales pipeline and customer relationships
- Comply with legal obligations and enforce our terms
Legal bases
Where the GDPR or similar laws apply, we rely on: consent (marketing communications and non-essential cookies), legitimate interests (operating and securing the Site, responding to business enquiries, business-to-business marketing where lawful), contract (steps taken at your request before entering an agreement), and legal obligation (records we are required to keep).
Sharing and subprocessors
We do not sell personal data. We share it only with service providers who process it on our behalf under contractual confidentiality and security obligations:
- Amazon Web Services (AWS) — hosting and infrastructure (United States)
- Cloudflare — CDN, DNS, and security (United States)
- Google Workspace — email and internal documents (United States)
- HubSpot — CRM and marketing automation; form submissions flow here (United States)
- Slack — internal notification of form submissions (United States)
We may also disclose data where required by law, to protect our rights or safety, or in connection with a corporate transaction such as a merger or acquisition, in which case this policy continues to apply until you are told otherwise.
International transfers
We are based in the United States and our data is stored in the United States. If you access the Site from elsewhere, your data will be transferred to and processed in the US. Where required, we rely on appropriate safeguards such as standard contractual clauses.
Retention
We keep personal data only as long as it is needed for the purposes above: enquiry and lead records are retained while there is an active relationship or ongoing interest, and reviewed periodically; analytics data is retained in aggregate or pseudonymised form; records required for legal, tax, or accounting purposes are kept for the mandated period. When data is no longer needed, we delete or anonymise it.
Your rights
Depending on where you live, you may have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to fix inaccurate or incomplete data
- Deletion — ask us to delete your data, subject to legal retention obligations
- Portability — receive your data in a structured, machine-readable format
- Objection and restriction — object to or restrict certain processing, including direct marketing
- Withdraw consent — at any time, where processing is based on consent, without affecting prior processing
To exercise any of these rights, email hello@superhipaa.com. We will verify your identity, respond within the timeline the applicable law requires, and will not discriminate against you for making a request.
California residents. Under the CCPA/CPRA you have the rights to know, delete, correct, and opt out of “sale” or “sharing” of personal information. We do not sell personal information and do not share it for cross-context behavioural advertising. You may exercise your rights, or designate an authorised agent to do so, via the email above.
EEA/UK residents. You also have the right to lodge a complaint with your local supervisory authority, though we would appreciate the chance to resolve your concern first.
Children
The Site is a business-to-business service and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
Security
We protect personal data with industry-standard measures, including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, and staff security training. No transmission or storage method is perfectly secure, but we treat the data you give us with the same discipline we describe in our Trust Center.
Changes to this policy
We may update this policy from time to time. The effective date at the top reflects the latest revision, and material changes will be flagged on the Site. Continued use of the Site after a change takes effect constitutes acceptance of the revised policy.
Contact
Questions about this policy or our data practices: hello@superhipaa.com. Security concerns: security@superhipaa.com.
This document is a template drafted for SuperHIPAA and should be reviewed by counsel before publication.