Chordae is a staff/workforce tool and is not intended to collect patient health information (PHI). We do not knowingly collect PHI, and users are prohibited from entering it. Chordae is not a HIPAA business associate for patient data.
About clinical staff and program operations - not patients:
To operate the Service (scheduling, reminders, swaps, credential tracking, training administration), secure accounts, send service and account notices, and comply with law. We do not sell your personal information and do not use it for third-party advertising.
Within your organization per admin-configured access; with service providers (cloud hosting, email/SMS delivery) under contracts limiting their use; and for legal compliance or to protect rights and safety.
We send account and operational messages. SMS, if used, is opt-in and urgent-only, and message bodies never contain sensitive personal or health information - only a notice and a portal link.
We use industry-standard safeguards: encryption in transit (HTTPS), hashed passwords, passkey/2FA support, session controls, access restrictions, encryption of sensitive secrets, and regular backups. No system is perfectly secure.
We retain data while your account/organization is active and as needed for the above purposes or as required by law (including training-record retention). On termination, data may be exported for a limited period and then deleted.
You may review and update your profile, manage notifications, and request access to or deletion of your personal data, subject to legal and contractual retention obligations.
If a security incident affecting personal information occurs, we will notify affected parties and authorities as required by law (including the Texas Identity Theft Enforcement and Protection Act).
Chordae is for professional use by adults (18+). We will post updates here and notify you of material changes.
Chordae - admin@chordae.app