AltraSync Trust Center

Privacy Policy

Last updated: June 24, 2026. AltraSync is a secure therapy operations platform for authorized company users. This policy explains how AltraSync handles account information, uploaded documents, support requests, AI features, retention, and security controls inside the system.

Authorized use only

AltraSync is not a public patient portal. Access is limited to approved company users with role-based permissions.

PHI-aware workflows

The platform may process operational documents that contain protected or sensitive information. Users should upload only what is needed for business operations.

Retention controls

Uploaded evidence and document files are designed to follow configured retention and cleanup rules while preserving safer history and logs.

Summary

AltraSync helps therapy and ABA organizations manage audits, billing support workflows, client intake operations, internal communication, support tickets, and administrative follow-up. The app is designed to keep company data separated by tenant/company and to limit access based on the logged-in user's role.

Information AltraSync may process

  • Account details such as username, role, company, recovery email, login/security status, and permission settings.
  • Operational documents uploaded by authorized users, including PDFs, spreadsheets, images, billing files, support attachments, and related extracted metadata.
  • Workflow records such as audit findings, correction status, support tickets, replies, retention logs, AI summary logs, and admin activity history.
  • Technical security records such as login events, failed attempts, session state, device/IP metadata where available, and system configuration activity.

How information is used

Information is used to operate AltraSync workflows, show dashboard metrics, route support tickets, send correction/support emails, track retention, maintain audit history, help authorized users review documents, and provide secure access to company-specific records.

PHI and sensitive data handling

AltraSync is designed for healthcare-adjacent operations where uploaded documents may contain protected health information. Users should avoid placing unnecessary PHI into support tickets, internal chat, or free-text fields and should use job IDs, proof IDs, request IDs, or screenshots with sensitive details hidden whenever possible.

Customer and user responsibilities

Each customer remains responsible for deciding what documents are appropriate to upload, granting access only to authorized workforce members, maintaining its own HIPAA policies, Business Associate Agreement review, patient notices, consents, payer requirements, and internal compliance program. AltraSync users should not use the platform as a public patient portal or as a substitute for the customer's official Notice of Privacy Practices.

AI features

AI features are optional and controlled through Admin AI Settings. Dashboard AI summaries use company-level counts and safe issue categories only. They are designed not to send PDFs, full note text, evidence text, client names, provider names, dates of birth, member IDs, or PHI. Other AI review features should use extracted or masked text only when enabled by an authorized admin.

Storage and retention

On Azure, AltraSync stores persistent runtime data under the configured data root, currently expected to be inside /home. Uploaded documents, database files, support attachments, logs, and backups should remain separated from deployed code. Retention controls are designed to remove PHI-heavy uploaded/evidence files after the configured retention period while preserving safer operational logs.

Sharing and support

Support requests are visible to authorized Super Admin support users inside AltraSync. Support emails may include company name, username, user email, role, page, request ID, priority, topic, and attachment names so issues can be resolved faster. Users should not attach client documents unless necessary and approved.

Security controls

AltraSync includes role-based permissions, tenant/company isolation, HTTPS hosting, session timeout controls, optional single-login enforcement, mandatory recovery email setup, email two-factor verification, audit logs, support ticket history, and retention logs. These controls help reduce unauthorized access and improve accountability.

Security incidents

If a suspected privacy or security incident involves customer data, AltraSync support should review available logs, preserve relevant evidence, and coordinate with the affected customer so the customer can evaluate any required notices under its own legal and compliance obligations.

Official resources

For general HIPAA background, users can review HHS resources for the HIPAA Privacy Rule, HIPAA Security Rule, and Breach Notification Rule.

Contact

For privacy, security, support, or access questions, contact support@altrasync.com or use the Support Center inside AltraSync.

Important: This page describes AltraSync platform practices. It is not a substitute for each healthcare provider or organization's own HIPAA Notice of Privacy Practices, patient consent forms, contracts, BAA review, or legal compliance program.