Last updated: June 15, 2026
Plotador Inc. (“Plotador,” “we,” “us,” or “our”) operates the Plotador CRM platform, including plotador.com and our iOS and Android applications (the “Service”). This Policy explains how we handle information.
Plotador is a business-to-business tool for healthcare sales and business-development teams. Access requires an account provisioned by your organization. Plotador acts as a HIPAA Business Associate: we create, receive, maintain, and transmit information — including limited Protected Health Information (PHI) — on behalf of our customers (Covered Entities such as home health agencies and hospices) under signed Business Associate Agreements (BAAs). For data we process on a customer’s behalf, that customer is the controller and our handling is governed by our BAA and services agreement with them; this Policy describes our own practices.
From app users (your organization’s staff):
Business records entered by users:
Data minimization: We store only the minimum PHI necessary for referral tracking. We do not store Social Security numbers, full medical records, detailed clinical documentation, or financial-account/credit-card numbers.
Provide, operate, secure, and improve the Service; authenticate users and send sign-in codes; display accounts, maps, activities, and analytics; communicate about the Service; and comply with legal and contractual obligations. PHI is used only to provide the CRM service to the relevant customer and as permitted by our BAA.
We do not sell your personal information and do not use it for third-party advertising. We share it only:
Plotador is a Business Associate and maintains executed BAAs with its healthcare customers. We safeguard PHI per the HIPAA Security and Privacy Rules. Patient rights (access, amendment, accounting of disclosures, restriction) are handled through the customer (the Covered Entity) that owns the patient relationship — if you are a patient, contact that organization directly; Plotador will not disclose PHI directly to patients. In the event of a breach involving PHI, we notify the affected customer per our BAAs.
Operational data is retained while your organization’s account is active. Audit logs and HIPAA-related records are retained for six years, then deleted under an automated lifecycle policy. Operational database backups follow a 30-day rolling retention. Customers may export their data (CSV/JSON) at any time and may request complete deletion.
We apply administrative, physical, and technical safeguards, including: AES-256 encryption at rest and TLS 1.3 in transit (with HSTS and Perfect Forward Secrecy); passwordless authentication via single-use, time-limited email one-time codes with authorized-domain whitelisting, and MFA required for administrative/privileged access; role-based access control enforced through to database security rules; complete tenant isolation; immutable audit logging of PHI access (retained six years) with quarterly access reviews; and continuous monitoring. No method of transmission or storage is 100% secure. We do not transmit PHI in email (OTP emails contain no PHI).
Data is stored in the United States on Google Cloud Platform with multi-region replication.
The Service is not directed to children and we do not knowingly collect information from anyone under 16.
The Service is operated in the United States; if you access it from elsewhere, you consent to U.S. processing.
We may update this Policy and will revise the “Last updated” date; material changes will be communicated as required.
Plotador Inc., 1407 Ethridge Ave, Austin, TX 78703 · privacy@plotador.com