Skip to content
← CompliMED

Legal

Privacy Policy

This policy explains what CompliMED LLC collects, where it goes, and how long it is kept. It is in two parts, because this website and the CompliMED platform are different things that handle different data.

Effective 10 October 2026

How to read this policy

Part A covers this website — what happens when you browse it or ask for a demonstration. It applies to everyone.

Part B covers the CompliMED platform — the application your organization logs into. It applies if your employer is a CompliMED customer. Access to the platform is by invitation and under a separate written agreement; you cannot sign up for it on this website.

In both parts, “we” means CompliMED LLC, a Florida limited liability company, at 42041 Cypress Pkwy, Suite 4 PMB 55, Babcock Ranch, FL 33982.

PART A — This website

The demonstration request form

If you ask for a demonstration, the form collects five things: your name, email address, company, role, and whatever you write in the message field. Nothing else. There is no account, no password, and no payment.

The form carries two anti-spam controls. One is a hidden field that a person never sees and never fills in — if it comes back filled, the submission is discarded as automated. The other limits each submitter to one submission every twenty seconds. Neither collects anything about you.

Submissions are delivered to us in one of two ways, depending on how the site is configured at the time: to an internal webhook, or by email through Resend, an email delivery service. If neither is configured the submission is not delivered at all and the failure is logged.

Retention. Demonstration requests are kept for 24 months, then deleted. You can ask us to delete one sooner at any time.

Analytics

Nothing loads until you say yes. No analytics script runs on a first visit, and none runs at all if your browser sends a Do Not Track signal.

With your consent, two services are used:

Four things are true of that recording, and we state them because session recording is the most intrusive thing this site does:

What this site stores on your device

Two values, both in your browser's local storage, neither of which identifies you:

KeyWhat it holdsWhy
cm-analytics-consentYour analytics choiceSo you are not asked on every page
cm-themeLight or dark preferenceSo the site looks the way you left it

There are no advertising cookies, no tracking pixels, and no third-party ad networks on this site.

PART B — The CompliMED platform

Our role

The platform is business software. Your employer — the customer organization — decides what goes into it, who may use it, and what happens to it. We process that data on their instructions under a written agreement. If you are an employee of a customer organization, direct requests about your data to them first; we will support them in answering you.

What the platform holds

Account information about each user: name, email address, phone number, an optional profile picture, and a password stored only as a cryptographic hash that cannot be reversed.

Operational records about consignment inventory and its use. The fields that can identify a person or a place are:

RecordFields that can identify
Usage recordFacility name, procedure type, account number, physician name, free-text notes
Product incident reportComplainant name, phone, email and role; facility name; device identifiers; free-text narrative
Access requestEmail address, phone number
Bug reportBrowser user-agent string
Device session / push tokenDevice and token identifiers used to keep you signed in and to deliver notifications

No patient identifiers

The platform does not ask for, and does not store, patient-identifying information. There is no patient name field, no date of birth, and no case number. A case-number field existed earlier in development and was removed.

Two fields are free text — the notes on a usage record and the narrative on a product incident report. Neither asks for patient information, but a person can type anything into a text box. The customer agreement prohibits entering patient-identifying information, and the Terms of Service repeat that obligation.

If such information is entered anyway, it is stored and secured exactly as the rest of the record is, and it becomes subject to the retention rules below — including the append-only records, which cannot be edited. The practical consequence is that it may not be possible to remove it. That is why the obligation sits on the person typing rather than on a filter.

Agreements. A data processing agreement is available on request. We do not offer a business associate agreement, because the platform holds no patient-identifying information and a BAA would imply otherwise. Ask us if your organization needs one.

Who else processes this data

The platform runs on services operated by other companies. This list was accurate on 10 October 2026 and is reviewed when the infrastructure changes.

ServiceWhat it doesWhere
VercelHosts the applicationUnited States
NeonPostgreSQL database — the primary data storeAWS, US East
Vercel BlobStores profile picturesUnited States
AppleSign in with Apple, for people who choose itUnited States
ResendDelivers transactional email from the platform, and demonstration requests from the websiteUnited States
PostHogWebsite analytics, with consent — named eventsUnited States
Microsoft ClarityWebsite analytics, with consent — heatmaps and session recordingUnited States

How it is protected

These are the controls the platform actually implements. They are described here as engineering facts, not as a certification. We hold no security certification, audit report or attestation, and we claim none.

One honest limitation: the operator activity log is append-only but is not hash-chained in the way the customer audit and access logs are.

How long it is kept

Account and operational data is kept while your organization is a customer. When the relationship ends, offboarding runs on a contractual clock and the data is removed at the end of it.

Audit and disclosure records are the exception. They are retained indefinitely and there is no purge path. That is deliberate. The entire purpose of an append-only compliance record is that it cannot be removed — including by us, and including on request. A record that could be deleted would not be evidence of anything.

These records hold who did what and when. They do not hold inventory contents or free-text fields.

Both parts

Your choices

Not for children

This is business software sold to organizations. It is not directed at anyone under 18, and we do not knowingly collect information from children.

Where data is held

In the United States. If you are outside the United States, submitting a demonstration request or using the platform means your information is transferred to and stored there.

Changes

If this policy changes materially, the effective date at the top changes and the change is announced on this page. Continuing to use the site or the platform after that means the revised policy applies.

Contact

Privacy questions and requests: support@complimed.net. Postal: CompliMED LLC, 42041 Cypress Pkwy, Suite 4 PMB 55, Babcock Ranch, FL 33982.


See also: Terms of Service

Make your job easier.

Request a demo

See it on yourown inventory.

Tell us what you carry and who carries it.

We use this to reply, nothing else.