Privacy Policy
Last updated: August 17, 2026
Senior Care Connected (“the Service”) is operated by GDI Digital Solutions (“we,” “us,” “our”). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service you agree to this policy.
Information We Collect
Account information. Names, email addresses, usernames, roles, and contact details for the staff and family members who use the Service.
Care-center records. Information that care centers enter to operate their facility — participant/resident profiles, contacts, attendance, activities, medications, incidents, assessments, billing, and related documents.
Usage and device data. Basic technical information such as log data, browser type, and pages accessed, used to keep the Service secure and reliable.
How We Use Information
We use information to provide and operate the Service, authenticate users, process payments, send transactional emails and notifications, provide support, maintain security, and comply with legal obligations. We do not sell personal information.
Health Information (PHI) & HIPAA
Care centers use the Service to record health-related information about the people in their care — medical examinations, TB testing, vitals, medications, care plans, assessments, and incident reports. This is protected health information (PHI) under HIPAA. Each care center is the covered entity responsible for that information and for obtaining any required consents; we act as its business associate, enter into Business Associate Agreements (BAAs) with the centers we serve, and apply the administrative, technical, and physical safeguards described below. PHI is made available only to the center’s authorized users and the family members it designates.
How We Protect PHI — Encryption
Encryption in transit. Every connection to the Service — from browsers, the iOS and Android apps, and the public form links — uses HTTPS (TLS 1.2+). Connections between our application servers and the database are also encrypted with TLS, with server-certificate verification enabled.
Encryption at rest — storage layer. All databases run on encrypted storage (AES-256) with keys managed by the AWS Key Management Service, and all uploaded documents and photos are stored with server-side AES-256 encryption.
Encryption at rest — field level. On top of storage encryption, the most sensitive data is individually encrypted by the application with AES-256-GCM authenticated encryption before it is written to the database. This includes health records (medical examination reports, TB testing and questionnaires, care plans and progress notes, personal-care and level-of-care assessments, incident details, and clinical forms), government and insurance identifiers (Social Security, SIS, SSI, Medicare, Medicaid, and member numbers), employee HR records (applications, medical statements, evaluations), and family contact details submitted through inquiry links.
Key management. Encryption keys are stored in a dedicated secrets manager, separate from the data they protect, with access restricted to the application.
Credentials. Passwords are never stored in plain text — they are one-way hashed with bcrypt. Temporary passwords must be changed at first sign-in.
How We Protect PHI — Access & Accountability
Minimum-necessary access. Every user signs in with an individual account, and clinical records are restricted by role — staff see only the health information their job requires, and family members see only their own loved one.
Accountability. Access to and changes of records are logged in an audit trail, and sessions sign out automatically after inactivity.
Infrastructure. The Service runs in Amazon Web Services data centers that maintain independent security certifications (including SOC 2 and ISO 27001), with least-privilege controls on our own infrastructure access.
How We Share Information
We share information only with: (a) service providers that help us run the Service (for example, cloud hosting and payment processing) under contractual confidentiality and security obligations; (b) a care center’s own authorized users and the family members it links to a resident; and (c) authorities when required by law. We do not sell or rent personal information.
Data Security
Beyond the PHI protections above, the same safeguards — TLS in transit, encrypted storage, field-level AES-256-GCM encryption for sensitive fields, role-based access, and audit logging — apply across the Service. No method of transmission or storage is 100% secure, but we design every layer to protect your information.
Data Retention
We retain information for as long as a care center maintains its account or as needed to provide the Service and meet legal, accounting, or recordkeeping requirements. Care centers may request export or deletion of their data, subject to applicable retention laws.
Your Choices & Rights
Depending on your location, you may have rights to access, correct, or delete personal information, or to object to certain processing. Family and staff users should direct requests to their care center, which administers the data; you may also contact us using the details below.
Cookies
The Service uses essential cookies and similar local storage to keep you signed in and to operate core features. See our Cookie Policy for details.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
Contact Us
Questions about this policy? Email info@gdidigitalsolutions.com.