Safar Privacy Policy
legal@joinsafar.com · joinsafar.com
This Privacy Policy describes how Safar collects, uses, stores, and protects information in connection with the Safar website and platform. It applies to practitioners who use Safar in their work and addresses how protected health information belonging to clients is handled within that context.
Practitioners and vendors who handle protected health information through Safar are also governed by a separate Business Associate Agreement. This Privacy Policy supplements that agreement and does not replace it.
1. Privacy Environments
Safar Website. The public site, contact forms, and communications. It operates outside of the platform and is governed by the website privacy terms in Section 2.
Safar Platform. The application where practitioner and client information, including protected health information, is created, stored, and processed. It is governed by the platform privacy and PHI terms in Section 3, together with HIPAA and applicable agreements.
The website privacy terms do not govern the Safar platform or any clinical information. The platform terms do not govern general website browsing.
2. Website Privacy Terms
This section applies to the Safar website only. No protected health information should be stored or exchanged here.
Information collected: name, email, and standard technical data such as browser and device information from visitors and from those who contact us or subscribe to communications.
How it is used: to operate the site, respond to inquiries, and send communications you have opted into.
Separation from the platform: the Safar website operates independently from the platform. Information submitted through the website for contact purposes is secure but is not encrypted to the same standard as platform data.
Cookies and analytics: the site may use cookies and analytics to understand usage, with opt-out available where applicable.
Scope: this section does not govern the Safar platform or any clinical or therapeutic information, which are covered in Section 3.
3. Platform Privacy and Protected Health Information
This section applies to information created, received, maintained, or transmitted through the Safar platform. This includes voice check-ins, journaling entries, protocol data, and assessment responses that belong to a practitioner's clients.
Safar recognizes that the protected health information processed through the platform is the information of clients — individuals who have entered into a care relationship with a practitioner. Safar accesses and handles that information only to support the delivery of the practitioner's services, and does so under the terms of the Business Associate Agreement in place with that practitioner.
3.1 How Client Information Is Handled
- Protected health information generated through client use of the platform is handled in accordance with HIPAA and applicable privacy and security law.
- Safar acts with the permission of the practitioner and handles client information under a Business Associate Agreement.
- Safar does not access, use, or disclose client information beyond what is necessary to deliver the service.
3.2 How Client Information Is Used and Disclosed
Client information is used only to provide the service and support the care relationship between the practitioner and client. It is not used for other purposes without authorization.
- Safar does not sell protected health information.
- Safar does not use protected health information for marketing without explicit authorization.
- Minimum necessary standard: internal systems and personnel access only the information required to perform a specific function.
- Any provider, vendor, or subcontractor that handles protected health information on Safar’s behalf is bound by a Business Associate Agreement requiring equivalent protection.
3.3 Automated and AI-Assisted Processing
Safar uses automated and AI-assisted systems to support practitioner workflows. The following describes how client information is handled within those systems.
Any automated or AI-assisted processing of client information occurs only within systems bound by appropriate agreements. Protected health information is not shared with any third-party AI system unless a Business Associate Agreement with that provider is in place.
Before information is processed by automated systems, Safar separates and protects identifying information. Protected health information is maintained within Safar's encrypted environment.
AI-generated signals, reflections, and protocol outputs are provided to practitioners as informational inputs. They do not constitute clinical advice, diagnosis, or treatment, and are subject to practitioner review and judgment.
3.4 Safeguards
Safar maintains administrative, physical, and technical safeguards designed to protect client information. The detailed controls are documented in Safar's internal security policies.
Information within Safar's environment is protected such that individual clients and practitioners cannot be identified from Safar's processed or encrypted data.
Safar does not disclose identifying information about the work conducted by practitioners on the platform, except as required by law or with authorization.
3.5 Client Rights Under HIPAA
Consistent with the rights HIPAA provides to individuals, clients may exercise the following with respect to their protected health information. Practitioners should be aware of these rights as part of their obligations to the clients they serve.
- Right of access: clients may request to see and receive a copy of their information.
- Right to amend: clients may request correction of information they believe is inaccurate or incomplete.
- Right to an accounting of disclosures: clients may request a list of certain disclosures of their information.
- Right to request restrictions: clients may request limits on how their information is used or disclosed.
- Right to confidential communications: clients may request that Safar communicate with them by alternative means or at an alternative location.
- Right to be informed: clients may request information about how their data is protected and used.
- Right to raise a concern: clients may raise a privacy concern or complaint without fear of retaliation.
Rights requests may be directed to legal@joinsafar.com.
3.6 Breach Notification
In the event of a breach affecting protected health information, Safar will provide notification as required by law and by its agreements with practitioners.
3.7 Data Retention
Protected health information is retained only as long as necessary for the purposes described here, for the duration of the care relationship, or as required by law and clinical record-keeping obligations. Practitioners may contact Safar at legal@joinsafar.com with questions about retention practices specific to their account.
4. Protection of Practitioners
Safar recognizes that practitioners conduct sensitive and often legally protected work. Safar is committed to protecting the confidentiality of that work.
- Safar does not disclose identifying information about the work conducted by practitioners on the platform, except as required by law or with authorization.
- Information about a practitioner’s client population, protocols, and outcomes is accessible only to that practitioner and to Safar personnel required to deliver the service.
- Practitioner-level data is not used to build competing products, shared with third parties for commercial purposes, or disclosed beyond the scope of the services Safar provides.
5. Changes to This Policy
Safar may update this Privacy Policy from time to time. Where changes are material, Safar will provide reasonable notice through the platform or by email. Continued use of the platform following notice of changes constitutes acceptance of the updated policy.
6. Contact
Questions about this Privacy Policy, requests to exercise rights, or privacy concerns may be directed to Safar at legal@joinsafar.com.
Integration Enterprises PBC · joinsafar.com