Section 01
Who this notice covers
AcuityRow, Llc ("AcuityRow", "we", "us") provides operating software to licensed senior living operators. This notice describes how we handle personal information collected through our public website, our operator product, and any data feeds an operator chooses to connect.
When an operator uses AcuityRow to handle resident records, we act as a business associate under HIPAA. The operator is the covered entity and remains responsible for resident notice and consent. This notice is not a substitute for the operator's own privacy practices notice.
Section 02
What we collect
We separate collection by source so it is clear what touches PHI and what does not.
- Public site: page views, IP, device and browser type, and information you submit in the request-access or contact forms (name, work email, organization, role, facility count, care setting, message).
- Operator product: account identifiers, role assignments, audit logs of every sign-in, signal review, approval, and family update action.
- Connected data feeds: resident records, staffing schedules, medication and incident events, and family contact information that the operator imports from systems like PointClickCare, MatrixCare, UKG, or ADP. This may include PHI.
Section 03
How we use it
- To assemble the daily morning brief, resident risk queue, staffing fit view, and family update draft queue requested by the operator.
- To produce an audit and survey trail for the operator's clinical and compliance teams.
- To operate, secure, monitor, and improve the service.
- To respond to support, security, or billing inquiries.
We do not sell personal information. We do not use PHI to train general-purpose AI models. Where the product uses AI to summarize or draft language, the prompt and output remain scoped to the operator's account and are not used to improve any third-party model.
Section 04
AI processing and PHI
Some AcuityRow workflows use AI models to cluster signals, summarize notes, and draft family-facing language. These calls run inside a private inference path governed by our BAA with the underlying provider. Prompts and outputs are logged for audit but are not shared across operators.
Drafts produced by AI are never sent to a resident's family without an approved human reviewer. End-of-life, hospitalization, and incident messages always require a named approver before delivery. See HIPAA & AI use for the full boundary.
Section 06
Retention, export, and deletion
Operator data is retained for the term of the operator's agreement plus the period required to satisfy legal and audit obligations. On request, we will:
- Export the operator's records in a machine-readable format.
- Delete operator data, including PHI, within thirty (30) days of contract termination, unless retention is required by law.
- Honor verifiable individual rights requests routed to us by the operator (the covered entity).
Section 07
Security
Encryption in transit and at rest, role-based access, least-privilege internal access, audit logging of administrative actions, and incident response procedures. A BAA is signed before any production PHI is connected. See the trust center for the operator-facing version.
Section 09
Changes to this notice
Material changes will be communicated to operator administrators in product and by email. The "last reviewed" date above reflects the most recent substantive update.
Section 10
Contact
Privacy questions: privacy@acuityrow.com. Security disclosures: security@acuityrow.com.
Questions about this page?
Write us at privacy@acuityrow.com. A person from the AcuityRow team will reply.
AcuityRow, Llc · 1489 W Palmetto Park Rd Ste 500, Boca Raton, FL 33486, United States · +1 (561) 310-6295 · https://acuityrow.com/
support@acuityrow.com · privacy@acuityrow.com · security@acuityrow.com