Privacy Policy

Effective Date: August 30, 2025
Last Updated: August 30, 2025

LactaSite ("we," "our," or "us") is committed to protecting the privacy and security of information entrusted to us. This Privacy Policy explains how we collect, use, and safeguard personal and health information when you use our web application, which is designed for lactation professionals to manage their practice and patient records. Our platform is password protected and built to comply with the Health Insurance Portability and Accountability Act (HIPAA).

1. Information We Collect

We may collect the following types of information:

  • Professional Information: Name, email address, phone number, practice details, and account login credentials.
  • Patient Information: Protected Health Information (PHI) as defined by HIPAA, which may include patient names, contact information, medical history, lactation notes, and related records.
  • Technical Information: Device type, IP address, browser type, operating system, and usage activity within the app.
  • Support and Communication Records: When you contact us for support, we may collect information related to your inquiry.

2. How We Use Information

We use information solely to:

  • Provide, maintain, and improve our web application.
  • Enable lactation professionals to securely document and manage patient care.
  • Ensure compliance with HIPAA and other applicable regulations.
  • Communicate with users regarding updates, support, and security notifications.
  • Monitor and enhance system security, performance, and reliability.

We do not use patient information for marketing or any non-care-related purposes.

3. Data Security and HIPAA Compliance

We implement administrative, physical, and technical safeguards designed to meet HIPAA standards, including but not limited to:

  • Password-protected, role-based access controls.
  • Encrypted data transmission (TLS/SSL) and encrypted storage.
  • Regular security audits and monitoring.
  • User authentication and session management.
  • Secure backup and recovery procedures.

All staff and contractors with access to PHI are trained in HIPAA compliance and bound by confidentiality agreements.

4. Data Sharing and Disclosure

We do not sell or rent your information. We may share information only in the following limited circumstances:

  • With Authorized Users: Patient information is accessible only to the healthcare professionals who create or are granted access to the record.
  • With Service Providers: We may use third-party vendors (e.g., secure hosting, backup, or technical support) bound by HIPAA-compliant Business Associate Agreements (BAAs).
  • As Required by Law: We may disclose information when required by applicable law, regulation, or court order.

5. User Responsibilities

As a covered entity or business associate under HIPAA (depending on your role), you are responsible for:

  • Using the platform in accordance with HIPAA regulations.
  • Maintaining the confidentiality of your login credentials.
  • Ensuring that patient access and permissions are properly managed.

6. Data Retention

We retain records in accordance with legal, clinical, and HIPAA requirements. Users may request data export or deletion in compliance with applicable laws and contractual obligations.

7. Your Rights

Depending on your role (provider or patient), you may have the right to:

  • Access and obtain a copy of your information.
  • Request corrections or updates.
  • Request restrictions on certain uses or disclosures.
  • Receive an accounting of disclosures.

We will respond to requests as required by HIPAA and applicable state law.

8. Children's Privacy

This application is intended for professional use only. We do not knowingly collect personal information directly from children under 18.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Any significant changes will be communicated to registered users via email or in-app notification.

10. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us at:

Margaret Salty LLC
Email: [Email Address]
Phone: [Phone Number]
Mailing Address: PO Box 5 S Washington St Set 346, Naperville, IL 60540

For additional support or questions, please contact us.