Effective August 11, 2026 · Version 1.0
PHI is not covered by this Policy. Protected Health Information ("PHI") that we handle on behalf of a customer organization (typically an assisted living operator) is governed by the Business Associate Agreement executed with that organization and by that organization's own Notice of Privacy Practices.
This Policy covers our own information practices for the marketing site and platform account metadata, not the underlying resident records our customers store using the platform.
This Privacy Policy describes how Diana Software LLC ("Provider", "we", "us", "our") collects, uses, discloses, and protects information in connection with the Tendera marketing website at tendera.care (the "Site") and the Tendera software-as-a-service platform (the "Platform").
When you visit tendera.care, we automatically collect:
When you submit the Book-a-Demo form, we collect the information you enter (typically name, work email, organization name, and any notes you provide).
When your organization is a paying customer of the Platform and you log in, we collect:
The Platform stores resident information and PHI that your organization enters on behalf of the residents it serves. That information is Customer Data under the MSA and PHI under the BAA; this Policy does not govern its collection, use, or disclosure.
We do not intentionally collect information from anyone under age 18 through the Site or the Platform. If you believe a minor has submitted information, contact privacy@tendera.care and we will delete it.
We use the information described in Section 2 to:
We do not use Platform account metadata for advertising or profiling. We do not sell personal information. We do not use PHI for any purpose other than as permitted by the BAA and the HIPAA Rules.
4.1 Subprocessors. We share information with third-party service providers that help us deliver the Site and Platform. Our current subprocessor list is at tendera.care/subprocessors. Each subprocessor that receives PHI is bound by a Business Associate Agreement with us.
4.2 Legal and safety. We may disclose information as required by law, subpoena, or court order, or when we reasonably believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
4.3 Business transactions. If we are involved in a merger, acquisition, or sale of all or substantially all of our assets, information may be transferred to the successor entity. The successor is subject to this Policy in its handling of the transferred information, until this Policy is superseded by a new one applicable to the successor.
4.4 With your consent. We may share information with third parties when you give us permission to do so.
4.5 What we do NOT do.
5.1 Marketing-site information. We retain Book-a-Demo submissions and related communications for as long as needed to respond to the inquiry, plus a reasonable tail for internal record-keeping. We retain marketing analytics for up to 26 months.
5.2 Platform account information. We retain account information for the duration of your organization's subscription, plus a reasonable tail for legal, audit, and security purposes.
5.3 Audit logs. We retain Platform audit logs for at least six years, consistent with HIPAA's documentation retention requirement (45 CFR 164.316(b)(2)).
5.4 Backups. Information persists in routine backups for up to 90 days after deletion from active systems.
5.5 Longer retention when required. We may retain information longer than the periods above when required by law, when necessary to enforce our agreements, or when necessary to resolve disputes.
Rights available to you depend on where you live and how you interact with us.
Rights under HIPAA (access, amendment, accounting, restriction, confidential communications) run through the Covered Entity that holds the resident's records, typically the assisted living operator using the Platform. Contact your care facility, not us, to exercise these rights. We will support the Covered Entity's response as described in the BAA.
If you are a California resident and we hold personal information about you (typically as a Site visitor or a Platform user, not as a resident whose PHI we hold on behalf of a customer), you have the right to:
To exercise a CCPA right, contact privacy@tendera.care. We will respond within 45 days, or sooner if practical, and may extend by an additional 45 days when reasonably necessary with notice to you. We will verify your identity before responding, in proportion to the sensitivity of the request.
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws generally have rights similar to those listed under CCPA above. To exercise a right under a state privacy law, contact privacy@tendera.care and identify the law you are relying on.
We do not currently offer the Platform to customers in the European Union or the United Kingdom. If we do so in the future, this Policy will be updated to include GDPR rights.
We may send marketing emails to individuals who submit the Book-a-Demo form or otherwise express interest, and to individuals at organizations that are current customers. Every marketing email includes an unsubscribe link. Transactional communications (statement emails, incident notifications, security alerts, service announcements) are not marketing and cannot be unsubscribed while the underlying account or subscription is active.
The Site and the Platform use cookies and similar technologies for the following purposes:
8.1 Strictly necessary cookies. These support session management (keeping you logged in), CSRF protection, and other security features. They cannot be disabled without breaking the service.
8.2 Preference cookies. These remember your choices, such as the bedside_theme cookie that stores your dark-mode / light-mode preference.
8.3 Analytics cookies. Used on the Site (tendera.care) to understand aggregated traffic patterns. We do not use analytics cookies inside the Platform tenant surfaces.
8.4 What we do NOT use. We do not use third-party advertising, retargeting, or cross-site tracking cookies.
Most browsers let you refuse cookies through their settings, but doing so may prevent the Site or Platform from functioning properly.
We use industry-standard administrative, physical, and technical safeguards to protect information, including:
No security is perfect. If you believe your information has been compromised, contact privacy@tendera.care immediately.
The Site and Platform are not directed to children under 13, and we do not knowingly collect personal information from them. If we learn we have collected personal information from a child under 13 through the Site or Platform, we will delete it. Note that residents whose PHI is in the Platform are typically adults; PHI about children of care recipients would be handled under the customer organization's HIPAA obligations, not this Policy.
Provider is based in the United States and stores information on infrastructure located in the United States. If you access the Site from outside the United States, your information will be transferred to, stored in, and processed in the United States. Data-protection laws in the United States may differ from those in your country.
We may update this Policy from time to time. Updates take effect on the effective date shown at the top. If a material change materially reduces your rights, we will make reasonable efforts to give notice (for example, an email to customers with active subscriptions or a banner on the Site).
For privacy questions, requests, or concerns:
Email: privacy@tendera.careIf you are a California resident and would like to submit a request under CCPA, put "CCPA Request" in the subject line.