FairRota
DRAFT for attorney review. Not in effect. Bracketed items are placeholders to fill in before publishing.

Privacy Policy

Effective date: [Effective date] · Last updated: [Date]

This policy explains what personal information FairRota collects, how we use it, and the choices you have. It covers the fairrota.com website and the FairRota scheduling application (the "Service"), offered by [Company legal name] ("FairRota", "we", "us").

Our role

Most information in FairRota is put there by a medical group or hospital (our "Customer") to schedule its own staff. For that information, the Customer decides what is collected and why, and we process it on the Customer's behalf as a service provider. If you are a staff member and have questions about your schedule data, contact your group's FairRota admin first. For our own website visitors, pilot sign-ups and sales contacts, we decide how information is used.

What we collect

Information Customers and Users put in the Service

Information collected automatically

Information you send us directly

What we don't collect

FairRota is not built for patient information. Our Terms ask Customers not to enter protected health information (PHI) or other patient details. We do not knowingly collect information from anyone under 18.

How we use information

We do not sell personal information, share it for cross-context behavioral advertising, or use Customer Data to train AI models offered to others.

Text messages and email

Users receive text messages only after opting in. Message frequency varies with schedule activity. Message and data rates may apply. Reply STOP to opt out or HELP for help. We do not share mobile numbers or opt-in consent with third parties for their marketing.

Who we share information with

We share information only with service providers that help us run the Service, under contracts that limit their use of it, when the Customer directs us to, or when the law requires it. Our current providers:

ProviderPurposeLocation
[Hosting provider]Application hosting and database[United States]
[Email provider]Schedule and account emails[United States]
[SMS provider]Text message notifications[United States]
[Error monitoring]Finding and fixing errors[United States]

If FairRota is involved in a merger or sale, information may transfer to the new owner under this policy.

How long we keep it

We keep Customer Data while the Customer's account is active. When it ends, the Customer can export its data for [30] days, then we delete it. Backups expire within [35] days. Security logs are kept for [12 months]. Some records may be kept longer if the law requires.

Security

We protect information with encryption in transit and at rest, role-based access, sign-in protections, an append-only change history, and limited staff access. No system is perfectly secure. If a breach affects your personal information, we will notify the Customer and, where required, the people affected.

Your choices and rights

To make a request, email [privacy@fairrota.com]. We will verify your request and reply within the time the law requires. You may use an authorized agent.

Cookies

The Service uses cookies that are needed to keep you signed in and to protect your account. [If analytics are added: name the tool, what it measures, and how to opt out. Add a cookie notice if required.]

Changes

We will post any changes here and update the date above. If a change is material, we will tell Customers by email or in the Service before it takes effect.

Contact

[Company legal name], [business address]. Email [privacy@fairrota.com].