Privacy Policy
Last updated: May 22, 2026
1. Use of Protected Health Information
ResiOnboarding standard accounts are intended to support non-clinical senior living workflows, including move-in coordination, resident onboarding, first-90-day engagement, satisfaction tracking, task management, and resident experience support.
Unless your organization has entered into a signed Business Associate Agreement with ResiOnboarding and your account has been specifically configured for HIPAA-related use, you should not enter, upload, transmit, store, or otherwise submit protected health information, medical records, diagnoses, medications, physician orders, care plans, clinical notes, hospital discharge information, or other health-related information into the platform.
Customers and users are responsible for ensuring that information entered into the platform is appropriate for their account type and permitted use.
2. HIPAA-Configured Accounts
For customers whose workflows require the use, storage, or transmission of protected health information, ResiOnboarding may offer HIPAA-configured account options subject to additional requirements. These requirements may include a signed Business Associate Agreement, appropriate technical safeguards, vendor safeguards, access controls, audit logging, and other administrative, physical, and technical safeguards designed to support HIPAA-regulated workflows.
A standard ResiOnboarding account should not be used for protected health information unless and until ResiOnboarding and the customer have executed the necessary agreements and the account has been configured for HIPAA-related use.
Nothing in this Privacy Policy is intended to replace or modify the terms of a signed Business Associate Agreement. If a Business Associate Agreement applies, the terms of that agreement will govern the handling of protected health information.
3. Customer Responsibility
Customers are responsible for managing their users, account permissions, internal policies, staff training, and the type of information entered into the platform. Customers should ensure that their employees, contractors, residents, family members, and other users do not submit protected health information unless the customer has confirmed that a Business Associate Agreement is in place and the account is authorized for HIPAA-related use.
Customers should also avoid entering protected health information into free-text fields, notes, document uploads, messages, survey responses, support requests, or other areas of the platform unless authorized under a HIPAA-configured account.
4. Information We May Collect
Depending on how the platform is used, ResiOnboarding may collect information such as names, contact details, account login information, community or organization information, move-in coordination details, task assignments, onboarding progress, resident experience feedback, satisfaction survey responses, uploaded documents, support requests, and usage information.
For standard accounts, users should avoid submitting clinical, medical, or health-related information. For HIPAA-configured accounts, the collection and handling of protected health information will be subject to the applicable Business Associate Agreement and related safeguards.
5. How We Use Information
We may use information to provide and improve the ResiOnboarding platform, support move-in coordination, manage onboarding workflows, provide customer support, improve user experience, maintain platform security, communicate with customers, analyze platform performance, and comply with applicable legal or contractual obligations.
We do not use protected health information for marketing purposes. Customers should not submit protected health information into the platform unless their account has been authorized and configured for HIPAA-related use.
6. Security Safeguards
ResiOnboarding uses administrative, technical, and organizational safeguards designed to protect information submitted through the platform. These safeguards may include access controls, user permissions, secure authentication, encryption where appropriate, audit logging, vendor management practices, and other security measures.
No system can guarantee absolute security. Customers and users are responsible for using the platform appropriately, protecting login credentials, limiting user access, and ensuring that sensitive information is entered only into authorized areas and account types.
7. Document Uploads and Free-Text Fields
Users should be careful when uploading documents or entering information into notes, comments, survey responses, messages, or other free-text fields. Unless your organization has a signed Business Associate Agreement with ResiOnboarding and your account is configured for HIPAA-related use, do not upload or enter medical records, diagnoses, medication lists, physician orders, care plans, clinical notes, hospital discharge documents, or other protected health information.
8. Third-Party Service Providers
ResiOnboarding may use third-party service providers to support hosting, database management, authentication, application deployment, email delivery, analytics, support, security, and other operational functions. These providers may process information only as needed to provide services to ResiOnboarding.
Where protected health information is involved, ResiOnboarding will use appropriate service providers and agreements as required for HIPAA-configured accounts. Standard accounts should not be used to submit protected health information.
9. Resident Data
Resident information entered into the platform is owned by your organization. We act as a data processor and handle this information in accordance with applicable regulations. Protected health information should only be entered into HIPAA-configured accounts subject to a signed Business Associate Agreement.
10. Cookies and Tracking
We use essential cookies to maintain your session and preferences. We may use analytics tools to understand how our Service is used, which helps us improve the experience.
11. Your Rights
You have the right to access, correct, or delete your personal information. You may also request a copy of your data or ask us to restrict its processing by contacting us.
12. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Upon account deletion, we will remove your personal data within 30 days.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the Service.
14. Contact Us
If you have questions about this Privacy Policy, data handling, account configuration, or whether your organization requires a HIPAA-configured account, please contact ResiOnboarding at support@resionboarding.com.