Your privacy is fundamental to our mission. As healthcare professionals ourselves, we understand the critical importance of protecting patient information and maintaining your trust through transparent, secure data practices.
SOAP-E, LLC ("Company," "we," "us," or "our") is committed to protecting the privacy and security of all information entrusted to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our healthcare documentation platform and related services (collectively, the "Service").
We are built by healthcare professionals, for healthcare professionals. We understand the sacred trust placed in us when handling patient information and personal data. Our privacy practices are designed to exceed industry standards and regulatory requirements.
This Privacy Policy applies to:
Our privacy practices are designed to comply with applicable federal and state privacy laws, including but not limited to the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA), and other relevant privacy regulations.
When you create an account or use our Service, we may collect:
In the course of providing our documentation assistance service, we process:
Important: We process this information solely to provide our documentation services and do not use it for any other purpose without your explicit consent.
We automatically collect certain technical information to operate and improve our Service:
When you contact us or interact with our support services:
We may receive information from:
We understand that you may input Protected Health Information (PHI) as defined by HIPAA into our system. We act as a Business Associate and implement all required safeguards to protect PHI in accordance with HIPAA regulations.
PHI may include any information you input that relates to:
We process PHI only as necessary to provide our documentation services. We encourage users to follow data minimization principles:
We protect PHI through comprehensive security measures including:
PHI is retained only as long as necessary to provide our services or as required by applicable law. We provide secure deletion mechanisms and maintain detailed records of PHI disposal activities.
We use your information to:
We may use aggregated, de-identified information to:
We may use information as necessary to:
With your consent, we may use your contact information to:
We do not sell, rent, or trade your personal information or PHI. We share information only in limited circumstances as described below, and always with appropriate safeguards in place.
We may share information with trusted third-party service providers who assist us in operating our Service, subject to strict contractual obligations:
All service providers that may access PHI are required to sign Business Associate Agreements and implement appropriate safeguards.
Where applicable and with proper authorization, we may share information with:
We may disclose information when required by law or to protect public safety:
In the event of a merger, acquisition, or sale of assets, user information may be transferred to the acquiring entity, subject to:
We may share de-identified, aggregated information for legitimate business purposes, including research, industry analysis, and service improvement, provided such information cannot be used to identify individuals or patients.
We implement a multi-layered security approach designed to protect your information from unauthorized access, disclosure, alteration, or destruction:
Our security program includes continuous monitoring, regular assessments, and ongoing improvement based on evolving threats and best practices. We maintain compliance with industry standards including HIPAA Security Rule requirements.
When you use our Service to process PHI, we act as your Business Associate under HIPAA. This means we are legally bound to protect PHI and use it only for the purposes specified in our Business Associate Agreement.
As a covered entity or individual, you have the following rights regarding PHI:
To exercise any of these rights, please contact our Privacy Officer using the information provided in Section 16. We will respond to your request within the timeframes required by HIPAA (typically 30 days for most requests).
We follow the HIPAA minimum necessary standard, which means we access, use, and disclose only the minimum amount of PHI necessary to accomplish the intended purpose.
This Privacy Policy serves as our Notice of Privacy Practices as required by HIPAA. If you are a covered entity using our Service, you should provide appropriate notice to your patients regarding your use of our services.
We retain different types of information for varying periods based on legal requirements and business needs:
When information is no longer needed, we securely delete or destroy it using industry-standard methods:
You can request deletion of your data at any time, subject to legal and regulatory retention requirements. We provide tools within the Service for you to delete specific documentation and manage your data retention preferences.
In certain circumstances (such as litigation or regulatory investigations), we may be required to preserve information beyond normal retention periods. We will notify you of such requirements when legally permissible.
You have comprehensive rights regarding your personal information:
You can control how we communicate with you:
Within your account settings, you can:
To exercise any of these rights, you can:
We will respond to your requests within 30 days and provide updates if additional time is needed. There is generally no charge for exercising these rights, though we may charge a reasonable fee for excessive or repetitive requests.
We use trusted OAuth providers (such as Google) for secure authentication. These providers:
We utilize enterprise-grade cloud services that provide:
We use PCI DSS-compliant payment processors that:
Our AI-powered features utilize secure, healthcare-compliant machine learning services that:
Our Service may contain links to third-party websites or integrate with external services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.
Your data is processed and stored within the United States in HIPAA-compliant data centers.
We implement strict controls on cross-border access to data:
We are committed to protecting your data from unauthorized government access. We:
Our Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected such information, we will take immediate steps to delete it.
Our Service is designed exclusively for licensed healthcare professionals and authorized personnel. Users must meet professional licensing requirements and age restrictions to access the Service.
When healthcare professionals use our Service to document care for minor patients:
We maintain comprehensive incident response procedures to address potential data breaches:
In the event of a breach involving personal information or PHI, we will:
Our breach notifications will include:
We continuously work to prevent breaches through:
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. We will notify you of material changes through:
Material changes include:
When we make material changes to this Privacy Policy:
We maintain an archive of previous versions of this Privacy Policy, which is available upon request. This allows you to review the evolution of our privacy practices over time.
We have designated a Privacy Officer who is responsible for overseeing our privacy program and handling privacy-related inquiries and requests. Our Privacy Officer can be reached at:
Email: privacy@soap-e.com
Phone: (910) 523-2612
Mailing Address:
Privacy Officer
SOAP-E, LLC
4030 Wake Forest Rd
Raleigh, NC 27609
For general questions about our Service or this Privacy Policy, you can contact us at:
Email: support@soap-e.com
Website: www.soap-e.com
You also have the right to file complaints with relevant regulatory authorities:
We are committed to responding to your privacy inquiries promptly:
This Privacy Policy was last updated on September 1, 2025. By continuing to use SOAP-E after this date, you acknowledge that you have read and understood this Privacy Policy.
Questions about this Privacy Policy? Contact our Privacy Officer at privacy@soap-e.com