Privacy Policy

Effective August 11, 2026 · Version 1.0

Version 1.0. This is the initial version of this Privacy Policy. Provisions may change from time to time; when they do, we update the effective date above and describe the change in Section 12.

PHI is not covered by this Policy. Protected Health Information ("PHI") that we handle on behalf of a customer organization (typically an assisted living operator) is governed by the Business Associate Agreement executed with that organization and by that organization's own Notice of Privacy Practices.

This Policy covers our own information practices for the marketing site and platform account metadata, not the underlying resident records our customers store using the platform.

1. About this Policy

This Privacy Policy describes how Diana Software LLC ("Provider", "we", "us", "our") collects, uses, discloses, and protects information in connection with the Tendera marketing website at tendera.care (the "Site") and the Tendera software-as-a-service platform (the "Platform").

2. Information we collect

2.1 From marketing-site visitors

When you visit tendera.care, we automatically collect:

  1. IP address, browser type and version, operating system, and referral source;
  2. pages viewed, time on page, and navigation path;
  3. cookies and similar technologies (see Section 8).

When you submit the Book-a-Demo form, we collect the information you enter (typically name, work email, organization name, and any notes you provide).

2.2 From Platform users

When your organization is a paying customer of the Platform and you log in, we collect:

  1. account information: username, name, work email, initials, role, facility assignments;
  2. an authentication credential (bcrypt-hashed signing PIN or password) and, where enabled, multi-factor authentication metadata;
  3. audit log activity: which user performed which action, at what time, from what IP address, using what device;
  4. session cookies to keep you logged in.

2.3 From customer organizations on behalf of residents

The Platform stores resident information and PHI that your organization enters on behalf of the residents it serves. That information is Customer Data under the MSA and PHI under the BAA; this Policy does not govern its collection, use, or disclosure.

2.4 We do not intentionally collect

We do not intentionally collect information from anyone under age 18 through the Site or the Platform. If you believe a minor has submitted information, contact privacy@tendera.care and we will delete it.

3. How we use information

We use the information described in Section 2 to:

  1. provide and operate the Site and the Platform;
  2. authenticate users and secure the Platform;
  3. respond to Book-a-Demo submissions and other inquiries;
  4. send transactional communications (statement emails, compliance reminders, incident notifications, security alerts);
  5. provide customer support;
  6. improve the Site and Platform through aggregated and de-identified analytics;
  7. market our services to organizations that have opted in or that have expressed interest through the Site;
  8. comply with legal obligations, including HIPAA audit requirements;
  9. enforce our agreements and prevent fraud or abuse.

We do not use Platform account metadata for advertising or profiling. We do not sell personal information. We do not use PHI for any purpose other than as permitted by the BAA and the HIPAA Rules.

4. How we share information

4.1 Subprocessors. We share information with third-party service providers that help us deliver the Site and Platform. Our current subprocessor list is at tendera.care/subprocessors. Each subprocessor that receives PHI is bound by a Business Associate Agreement with us.

4.2 Legal and safety. We may disclose information as required by law, subpoena, or court order, or when we reasonably believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

4.3 Business transactions. If we are involved in a merger, acquisition, or sale of all or substantially all of our assets, information may be transferred to the successor entity. The successor is subject to this Policy in its handling of the transferred information, until this Policy is superseded by a new one applicable to the successor.

4.4 With your consent. We may share information with third parties when you give us permission to do so.

4.5 What we do NOT do.

5. Data retention

5.1 Marketing-site information. We retain Book-a-Demo submissions and related communications for as long as needed to respond to the inquiry, plus a reasonable tail for internal record-keeping. We retain marketing analytics for up to 26 months.

5.2 Platform account information. We retain account information for the duration of your organization's subscription, plus a reasonable tail for legal, audit, and security purposes.

5.3 Audit logs. We retain Platform audit logs for at least six years, consistent with HIPAA's documentation retention requirement (45 CFR 164.316(b)(2)).

5.4 Backups. Information persists in routine backups for up to 90 days after deletion from active systems.

5.5 Longer retention when required. We may retain information longer than the periods above when required by law, when necessary to enforce our agreements, or when necessary to resolve disputes.

6. Your rights

Rights available to you depend on where you live and how you interact with us.

6.1 HIPAA rights (residents whose PHI is in the Platform)

Rights under HIPAA (access, amendment, accounting, restriction, confidential communications) run through the Covered Entity that holds the resident's records, typically the assisted living operator using the Platform. Contact your care facility, not us, to exercise these rights. We will support the Covered Entity's response as described in the BAA.

6.2 CCPA / CPRA (California residents)

If you are a California resident and we hold personal information about you (typically as a Site visitor or a Platform user, not as a resident whose PHI we hold on behalf of a customer), you have the right to:

  1. know what personal information we have collected about you;
  2. request a copy of that information;
  3. request correction of inaccurate information;
  4. request deletion of that information (subject to exceptions);
  5. opt out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising, so this right is inapplicable but stated for transparency);
  6. be free from retaliation for exercising these rights.

To exercise a CCPA right, contact privacy@tendera.care. We will respond within 45 days, or sooner if practical, and may extend by an additional 45 days when reasonably necessary with notice to you. We will verify your identity before responding, in proportion to the sensitivity of the request.

6.3 Other state privacy laws

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws generally have rights similar to those listed under CCPA above. To exercise a right under a state privacy law, contact privacy@tendera.care and identify the law you are relying on.

6.4 GDPR / UK GDPR

We do not currently offer the Platform to customers in the European Union or the United Kingdom. If we do so in the future, this Policy will be updated to include GDPR rights.

7. Marketing communications

We may send marketing emails to individuals who submit the Book-a-Demo form or otherwise express interest, and to individuals at organizations that are current customers. Every marketing email includes an unsubscribe link. Transactional communications (statement emails, incident notifications, security alerts, service announcements) are not marketing and cannot be unsubscribed while the underlying account or subscription is active.

8. Cookies and similar technologies

The Site and the Platform use cookies and similar technologies for the following purposes:

8.1 Strictly necessary cookies. These support session management (keeping you logged in), CSRF protection, and other security features. They cannot be disabled without breaking the service.

8.2 Preference cookies. These remember your choices, such as the bedside_theme cookie that stores your dark-mode / light-mode preference.

8.3 Analytics cookies. Used on the Site (tendera.care) to understand aggregated traffic patterns. We do not use analytics cookies inside the Platform tenant surfaces.

8.4 What we do NOT use. We do not use third-party advertising, retargeting, or cross-site tracking cookies.

Most browsers let you refuse cookies through their settings, but doing so may prevent the Site or Platform from functioning properly.

9. Security

We use industry-standard administrative, physical, and technical safeguards to protect information, including:

  1. encryption in transit using TLS 1.2 or higher;
  2. encryption at rest, with column-level encryption for the highest-sensitivity fields in the Platform database;
  3. role-based access controls, with multi-factor authentication required for administrative roles;
  4. audit logging of access to sensitive information;
  5. regular security reviews of infrastructure and code;
  6. breach notification procedures aligned with HIPAA and state law requirements.

No security is perfect. If you believe your information has been compromised, contact privacy@tendera.care immediately.

10. Children's privacy

The Site and Platform are not directed to children under 13, and we do not knowingly collect personal information from them. If we learn we have collected personal information from a child under 13 through the Site or Platform, we will delete it. Note that residents whose PHI is in the Platform are typically adults; PHI about children of care recipients would be handled under the customer organization's HIPAA obligations, not this Policy.

11. International users

Provider is based in the United States and stores information on infrastructure located in the United States. If you access the Site from outside the United States, your information will be transferred to, stored in, and processed in the United States. Data-protection laws in the United States may differ from those in your country.

12. Changes to this Policy

We may update this Policy from time to time. Updates take effect on the effective date shown at the top. If a material change materially reduces your rights, we will make reasonable efforts to give notice (for example, an email to customers with active subscriptions or a banner on the Site).

13. Contact us

For privacy questions, requests, or concerns:

Email: privacy@tendera.care
Mail: Diana Software LLC, 415 W Saguaro Arm Trl, Oro Valley, AZ 85755

If you are a California resident and would like to submit a request under CCPA, put "CCPA Request" in the subject line.