Privacy Policy
& HIPAA Notice of Privacy Practices
Protecting Your Family's Information

Effective May 1, 2026

Haven is committed to safeguarding the privacy and health information of our members and their families.

1

Table of Contents

Privacy Policy

  1. Introduction & Commitment to Privacy
  2. Information We Collect
  3. How We Use Your Information
  4. How We Protect Your Information
  5. Who We Share Information With
  6. Your Privacy Rights & Choices
  7. Children's Privacy (COPPA)
  8. Data Retention Periods
  9. Cookies & Tracking Technologies
  10. Third-Party Links & Services
  11. Privacy Policy Updates
  12. Contact Information

HIPAA Notice of Privacy Practices

  1. Introduction & Effective Date
  2. Uses and Disclosures of PHI
  3. Your Rights Regarding Your PHI
  4. Haven's Duties Regarding Your PHI
  5. Complaints & How to File
2

Privacy Policy

1. Introduction & Commitment to Privacy

Welcome to Haven. Haven ("we," "us," "our," or "Haven") is a childcare, workspace, and fitness membership platform that serves families and communities. We are committed to protecting the privacy and security of the information you share with us, including sensitive health information about your children.

This Privacy Policy ("Policy") explains:

  • What personal information and health information we collect
  • How we use, protect, and share that information
  • Your rights and choices regarding your information
  • How to contact us with questions or concerns

HIPAA Compliance: Haven is a HIPAA-covered entity. We follow strict federal regulations to protect your children's Protected Health Information (PHI), including allergies, medical conditions, developmental notes, and emergency contacts. If you are in California, we also comply with California's Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

Effective Date: May 1, 2026. We will notify you of material changes to this policy via email or through your Haven account.

2. Information We Collect

A. Information You Provide Directly

Account Registration & Enrollment:

  • Parent/guardian names, email addresses, phone numbers, home address
  • Child names, dates of birth, gender
  • Username and password (securely encrypted)

Health & Medical Information:

  • Child allergies (food, environmental, medication)
  • Medical conditions and diagnoses
  • Medications and dosages
  • Developmental notes and special needs
  • Immunization records (if shared)
  • Emergency contacts and relationship information

Billing & Payment Information:

  • Credit card or payment method information (processed securely via third-party payment processors; we do not store raw card numbers)
  • Billing address and name
  • Payment history and invoices

Communication & Preferences:

  • Messages between parents and teachers/caregivers
  • Communication preferences (email, SMS, in-app notifications)
  • Feedback, reviews, and survey responses

B. Information Collected Automatically

Usage Data:

  • Pages visited, features accessed, and time spent
  • Enrollment pipeline activity (applications, acceptance dates)
  • Booking and scheduling activity
  • Login attempts and timestamps

Device & Network Information:

  • IP address and geolocation
  • Browser type and operating system
  • Device type (mobile, desktop, tablet)
  • Unique device identifiers

Cookies & Tracking Technologies: See Section 9 for details.

C. Information From Third Parties

  • Background check providers (if required for staff employment)
  • Payment processors and financial institutions
  • Communication platforms used to contact you
3

3. How We Use Your Information

Haven uses information we collect for the following purposes:

A. Providing Haven Services

  • Enrollment & Membership: Processing applications, confirming membership status, managing classroom/room assignment
  • Childcare Operations: Ensuring child safety and wellbeing, communicating health and developmental information to teachers and caregivers, managing pickup/dropoff procedures
  • Health & Safety: Managing allergies and medical conditions during activities, coordinating emergency response if needed
  • Scheduling & Booking: Facilitating class bookings, workspace reservations, fitness activities, and childcare schedules

B. Billing & Account Management

  • Processing payments and invoicing
  • Managing account credits, refunds, and disputes
  • Sending receipts and billing notifications
  • Account updates and password resets

C. Communication

  • Sending service updates, educational content, and resources about childcare or child development
  • Responding to inquiries and customer support requests
  • Coordinating between parents and caregivers regarding child activities, milestones, or concerns
  • Notifying you of policy changes, outages, or important operational information

D. Safety, Compliance & Legal Obligations

  • Enforcing our Terms of Service and other agreements
  • Protecting against fraud, abuse, and security threats
  • Maintaining audit logs and security monitoring
  • Complying with law enforcement requests or legal obligations (with appropriate legal process)
  • Protecting the rights, property, and safety of Haven, our members, and the public

E. Improvements & Analytics (Aggregated/De-identified Only)

  • Improving Haven services, features, and user experience
  • Analyzing trends in enrollment, utilization, and member satisfaction
  • Developing new services or features
  • Important: We only use aggregated, de-identified data for these purposes. Individual health information is never used for analytics or improvement purposes.

F. Marketing & Member Engagement

  • Sending promotional emails about Haven services, classes, or events (with opt-out available)
  • Personalized recommendations based on your interests and activity (opt-out available)
  • Invitations to member appreciation events or webinars
Sensitive Health Information: We never use your child's health information for marketing, advertising, or profiling. Health information is used solely to operate our childcare services safely and in compliance with health and safety regulations.
4

4. How We Protect Your Information

Haven implements comprehensive technical, administrative, and physical safeguards to protect your information, particularly sensitive health information:

A. Encryption

  • In Transit: All communication between your device and Haven servers is encrypted using TLS (Transport Layer Security) 1.2 or higher, indicated by "https://" in your browser
  • At Rest: Sensitive health fields (allergies, medical information, developmental notes, emergency contacts) are encrypted using AES-256-GCM encryption at the database level
  • Encryption Keys: Encryption keys are stored separately from encrypted data and are accessed only by authorized systems

B. Access Controls & Role-Based Authorization

  • Role-Based Access: Teachers access only their classroom information; directors access their club; parents access only their family's information
  • Row-Level Security: Database policies enforce that families in Organization A cannot view families in Organization B, even if both use Haven
  • Principle of Least Privilege: Staff are granted minimum access needed to perform their role
  • Multi-Factor Authentication: Available for member accounts to add additional security

C. Monitoring & Audit Logging

  • Audit Trails: Haven maintains detailed logs of who accessed, viewed, or modified sensitive information, when, and from which IP address
  • Real-Time Monitoring: Continuous monitoring for suspicious activity, unauthorized access attempts, and rate limit violations
  • Anomaly Detection: Automatic alerts for unusual patterns (e.g., access outside normal hours, mass data downloads)
  • Incident Response: Dedicated incident response team for security breaches with established response procedures

D. Data Backup & Disaster Recovery

  • Automated Backups: Daily encrypted backups of all databases
  • Point-In-Time Recovery (PITR): 7-day recovery window to restore to any point in the past week if data is compromised
  • Backup Encryption: All backups are encrypted and stored in geographically separate locations

E. Infrastructure Security

  • Cloud Hosting: Haven is hosted on Vercel and Supabase, which maintain SOC 2 Type II compliance and enterprise-grade security
  • Network Security: Firewalls, intrusion detection, and DDoS protection
  • Regular Patching: All systems are regularly patched for known vulnerabilities
  • Penetration Testing: Annual third-party security assessments

F. Staff Training & Confidentiality

  • All staff sign confidentiality agreements protecting member privacy
  • Annual security and privacy training for all employees
  • Background checks for staff with access to sensitive information

G. Limitations

While we implement strong safeguards, no system is 100% secure. Haven cannot guarantee absolute security, and we encourage members to use strong passwords and enable multi-factor authentication.

5

5. Who We Share Information With

A. Haven Staff & Authorized Users

  • Teachers & Caregivers: Access to classroom information including enrolled children, schedules, and relevant health information (allergies, medical needs)
  • Club Directors & Administrators: Access to all members and children at their location for operations and billing management
  • Haven Leadership: Access limited to aggregated data, business metrics, and specific cases requiring escalation

B. Vendor & Service Providers (with Business Associate Agreements)

Haven works with trusted vendors to operate our platform. All vendors that handle Protected Health Information (PHI) sign a Business Associate Agreement (BAA) requiring them to maintain the same privacy and security standards as Haven:

  • Supabase (Database Provider): Hosts our database infrastructure; zero access to decrypted PHI
  • Vercel (Hosting Provider): Hosts our application; no access to member or health data
  • SendGrid (Email Service): Sends transactional and marketing emails; receives names and email addresses only (no health data)
  • Sentry (Error Monitoring): Monitors application errors; configured to exclude PHI from error reports
  • Payment Processors: Process credit card information using industry-standard encryption; we never see raw card numbers

No vendor has access to raw, unencrypted health information. PHI remains encrypted end-to-end.

C. When We Are Required to Share (Legal Obligations)

  • Law Enforcement: If required by court order, subpoena, or legal obligation (we will object to overbroad requests and notify members unless prohibited by law)
  • Health & Safety Emergencies: If a child's life is in danger, we may share health information with emergency responders or medical professionals
  • Regulatory Authorities: HHS, state health departments, or other regulatory bodies as required by law

D. What We Do NOT Do

  • We do not sell personal information or health information. Haven does not sell, rent, or trade member data to advertisers, data brokers, or other third parties
  • We do not share for marketing purposes. We do not share health information with third-party marketers
  • We do not use health data for profiling or discrimination. We do not create consumer profiles based on health information
  • We do not share without consent (except as required by law). We ask for your permission before sharing beyond these described uses
Your Control: You can opt out of non-essential communications and can request to know what vendors have accessed your information. Contact us at privacy@yourhaven.life.
6

6. Your Privacy Rights & Choices

A. Right to Access Your Information

You have the right to access and receive a copy of all information Haven holds about you and your child.

  • Log into your Haven account anytime to view enrollment, health, and activity information
  • Request a complete data export in a portable format (email privacy@yourhaven.life)
  • Response provided within 30 days at no charge

B. Right to Correction & Accuracy

You can correct or update any information that is inaccurate.

  • Edit your profile, child information, and health records directly in Haven
  • Request correction of information via email (privacy@yourhaven.life) if you cannot edit it yourself
  • We will correct the information and notify relevant parties

C. Right to Deletion (Right to Be Forgotten)

You can request deletion of your information, subject to certain restrictions.

  • You may request account closure and deletion of non-essential data
  • Limitations: We must retain billing records for 6 years (tax/legal requirement), audit logs for security purposes, and may retain de-identified data for research
  • Health records may be retained if required by law (e.g., immunization records)
  • Request via email: privacy@yourhaven.life; response within 45 days

D. Right to Data Portability

You can request your data in a machine-readable format for transfer to another service.

  • Request export of enrollment, health, and activity records in CSV or JSON format
  • Haven will provide data within 30 days at no cost
  • Email: privacy@yourhaven.life

E. Right to Restrict Processing

You can request limitations on how your information is used.

  • Restrict use of health information beyond what is necessary for childcare operations
  • Opt out of marketing communications (you will still receive essential operational emails)
  • Opt out of analytics/improvement purposes
  • Submit requests via privacy settings or email privacy@yourhaven.life

F. Right to Opt-Out of Marketing & Communications

  • Every marketing email includes an unsubscribe link
  • Manage communication preferences in your account settings
  • Email: privacy@yourhaven.life to opt out of all non-essential communications

G. Right to Object to Processing

You can object to certain uses of your information (particularly for direct marketing or analytics).

  • Send objection to: privacy@yourhaven.life
  • Specify what processing you object to
  • Haven will stop processing within 30 days unless there is a legal basis to continue

H. Right to Withdraw Consent

For any use based on your consent (not essential operations), you can withdraw consent at any time.

  • This does not affect the lawfulness of processing before consent was withdrawn
  • Withdrawal does not prevent essential childcare operations

I. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights:

  • Right to know what personal information is collected and used
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (Haven does not sell)
  • Right to correct inaccurate data
  • Right to non-discrimination for exercising privacy rights
  • Request: privacy@yourhaven.life; response within 45 days
No Retaliation: Haven will not deny services, charge different prices, or retaliate against you for exercising your privacy rights.
7

7. Children's Privacy (COPPA Compliance)

Haven does not directly collect information from children. We collect information from parents and guardians about their children for childcare operations.

A. Children Under 13

  • Haven does not operate a public website or app that children access independently
  • Parents/guardians control all account information and health records for children under 13
  • Haven complies with the Children's Online Privacy Protection Act (COPPA)
  • We do not knowingly collect information directly from children without verifiable parental consent

B. Privacy Protection for Children

  • Child health information (allergies, medical conditions, developmental notes) is encrypted and protected
  • Only authorized teachers and administrators can view child information
  • Teachers access only children assigned to their classroom
  • No sharing of child information with advertisers or third parties (except as required for childcare)

C. Parental Control

As a parent/guardian, you can:

  • Review all information Haven holds about your child
  • Update or correct health and medical information
  • Request deletion of information (subject to record-keeping obligations)
  • Contact privacy@yourhaven.life with concerns
8

8. Data Retention Periods

Haven retains information for as long as necessary to provide services or as required by law:

Information Type Retention Period Reason
Account Information (names, contact info) Duration of membership + 6 months Transition period if rejoining Haven
Billing Records (invoices, payments) 6 years Tax and legal requirements
Health Records (allergies, medical info) Duration of enrollment + 3 years Statute of limitations for claims; medical practice standards
Enrollment & Activity Records Duration of membership + 3 years Operational history and dispute resolution
Communication Records (messages) Duration of membership + 1 year Reference and dispute resolution
Audit Logs (access records) 2 years Security monitoring and incident investigation
Device/IP Information 12 months Security threat detection
De-identified/Aggregated Data Indefinite Service improvement and analytics

Upon account closure, Haven will delete non-essential data within 90 days, subject to legal retention requirements. You can request accelerated deletion of certain data at privacy@yourhaven.life.

9

9. Cookies & Tracking Technologies

A. What Are Cookies?

Cookies are small files stored on your device that remember information between visits. Haven uses cookies to improve your experience and maintain security.

B. Types of Cookies Haven Uses

Essential Cookies (Always Used)

  • Session cookies: Keep you logged in while using Haven
  • Security cookies: Protect against unauthorized access and fraud
  • Preference cookies: Remember your language, accessibility settings
  • Cannot be disabled — required for Haven to function

Analytics Cookies (Aggregated Only)

  • Purpose: Understand how members use Haven (which features are popular, where members drop off)
  • Data: Aggregated and de-identified; no personal or health information
  • Opt-out: You can disable in privacy settings; this does not affect functionality

Marketing Cookies (Optional)

  • Purpose: Personalize promotional content; retarget ads on other sites
  • Opt-out: Disable in privacy settings or unsubscribe from marketing emails
  • Note: Third-party cookies may be set by advertising partners

C. Your Cookie Choices

  • Browser Controls: Most browsers allow you to delete or block cookies
  • Haven Settings: Disable analytics and marketing cookies in your account privacy settings
  • Do Not Track: Haven honors browser "Do Not Track" signals (analytics disabled)

D. Third-Party Cookies

Haven does not control third-party cookies placed by advertising or analytics partners. You can manage third-party tracking via:

  • Your browser's cookie settings
  • Industry opt-out tools (e.g., Network Advertising Initiative, Digital Advertising Alliance)
  • Individual company privacy pages

E. Tracking & Re-Targeting

  • Haven may display retargeted ads on other sites if you visit Haven but don't enroll
  • Retargeted ads do not contain personal or health information
  • You can opt out via your browser or advertising preference centers
10

10. Third-Party Links & Services

Haven may contain links to external websites, resources, and third-party services (e.g., learning platforms, fitness partners).

A. We Are Not Responsible for Third-Party Privacy

  • This Privacy Policy applies only to Haven's services
  • Third-party sites have their own privacy policies
  • Haven is not responsible for third-party privacy practices
  • Always review a third party's privacy policy before sharing information

B. Linked Services from Haven

If Haven officially integrates a third-party service, we will:

  • Vet the service for privacy and security standards
  • Require a Business Associate Agreement (if handling health information)
  • Notify you in this policy update and via member communication
  • Ask for your explicit consent before sharing data

C. Single Sign-On (SSO) / OAuth

If Haven offers "Sign in with Google" or similar services:

  • You control what information is shared with Haven
  • Review the permission screen before authorizing
  • You can revoke access anytime in your Google/provider settings
11

11. Privacy Policy Updates

Haven may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors.

A. Notification of Changes

  • Material changes: Haven will email members and/or post a prominent notice on the website at least 30 days before changes take effect
  • Minor updates: Clarifications or non-substantive changes may be posted without advance notice
  • Continued use: Using Haven after notice of changes constitutes acceptance of the updated policy

B. Contacting Us About Updates

If you have questions about policy changes, contact privacy@yourhaven.life.

12. Contact Information

Haven Privacy Officer
Name: Britt Riley
Email: privacy@yourhaven.life or britt@yourhaven.life
Mailing Address: [Haven Address]

Response Timeline: Haven responds to privacy inquiries within 10 business days. Complex requests may take up to 30 days.

California Residents: You may submit a verifiable consumer request via email or mail (see above). Haven will verify your identity before responding.

Last Updated: May 1, 2026
Effective Date: May 1, 2026
Next Review Date: May 1, 2027
12

HIPAA Notice of Privacy Practices

This Notice describes how medical information about you and your family may be used and disclosed by Haven and how you can get access to this information.

13. Introduction & Effective Date

HIPAA (Health Insurance Portability and Accountability Act): Haven is a HIPAA-covered entity and must comply with federal regulations protecting Protected Health Information (PHI).

This Notice is required by law and becomes effective on May 1, 2026.

What is PHI?

Protected Health Information includes any information in your medical records or health information that can be used to identify you or your child, including:

  • Child allergies and food sensitivities
  • Medical conditions and diagnoses
  • Medications and dosages
  • Developmental notes and assessment results
  • Mental health information
  • Immunization and health history records
  • Emergency contact information
  • Health insurance information

Who Must Comply

This notice applies to:

  • Haven, Inc. (organization)
  • All teachers, caregivers, and staff members
  • All locations / clubs that provide childcare services

Your Rights — Quick Reference

  • Right to Access: See and get copies of your child's health records
  • Right to Amendment: Request corrections to health information
  • Right to Accounting: Know who has accessed your child's health information
  • Right to Restrict: Request Haven limit how health information is used
  • Right to Confidential Communication: Request to be contacted using preferred methods
  • Right to Breach Notification: Be notified if your health information is compromised
13

14. Uses and Disclosures of PHI

A. Treatment — For Childcare Operations

Use: Haven uses health information to provide safe, appropriate childcare services to your child.

  • Managing allergies and dietary restrictions during meals and snacks
  • Coordinating medical care (e.g., medication administration, accommodations for health conditions)
  • Communicating with parents about child's health and wellbeing
  • Emergency response if child is injured or becomes ill
  • Developmental assessment and progress notes

Disclosure: Haven discloses health information to:

  • Teachers and caregivers in your child's classroom (only relevant information)
  • Club directors and administrators for operational purposes
  • Health professionals or emergency responders if your child needs medical attention

B. Payment — For Billing & Insurance

Use: Haven uses health information to bill for services and coordinate with insurance.

  • Processing enrollment fees and membership payments
  • Billing insurance for any covered services (if applicable)
  • Pursuing payment for outstanding balances

Disclosure: Haven may disclose to payment processors, insurance companies, and billing contractors.

C. Healthcare Operations

Use: Haven uses health information to operate and improve services.

  • Training staff on safe childcare and health protocols
  • Assessing quality of care and member satisfaction
  • Updating policies and procedures based on health-related incidents
  • Compliance with health regulations and accreditation standards
  • Fraud prevention and security monitoring

No use of health information for marketing or profiling.

D. Legal Obligations & Required by Law

Haven must disclose PHI when required by law:

  • Court orders or subpoenas from law enforcement
  • Reporting suspected child abuse or neglect to child protective services
  • Reporting to state or federal health authorities for disease surveillance or public health purposes
  • Compliance with state licensing regulations for childcare facilities

E. With Your Authorization

Haven will not disclose health information beyond these described uses unless you provide written authorization.

You can authorize Haven to share health information with:

  • Other healthcare providers
  • Family members or designated representatives
  • Schools or other educational providers
  • Other organizations (with your specific, signed consent)

F. What Haven Does NOT Do

  • No sale of PHI. Haven does not sell health information to third parties
  • No marketing use. Haven does not use health information for marketing or advertising
  • No disclosure without consent (except as described above). Haven does not share health information without authorization unless legally required
  • No use for genetic testing or research. Unless specifically authorized by you
Important: If you revoke authorization for a disclosure, the revocation does not apply to any information already shared with your prior consent.
14

15. Your Rights Regarding Your PHI

A. Right to Access & Inspect

You have the right to inspect and receive a copy of your child's health records.

  • How to Request: Contact privacy@yourhaven.life or submit a written request to Haven's Privacy Officer
  • Format: Request the format you prefer (electronic, paper, USB drive)
  • Timeframe: Haven will provide access within 30 days
  • Cost: Reasonable reproduction and delivery costs may apply (but not for first copy)
  • Right to Deny (Limited): Haven may deny access if requested by legal representative or law enforcement, or in rare circumstances where access could harm you or others (with explanation)

B. Right to Amendment & Correction

You can request correction of health information that you believe is inaccurate or incomplete.

  • How to Request: Email privacy@yourhaven.life with description of what needs correction and why
  • Timeframe: Haven will respond within 30 days
  • Process: Haven will amend the record and notify others who may have relied on the incorrect information
  • Right to Disagree: If Haven disagrees, you can submit a written statement of disagreement, which will be included in the record

C. Right to Accounting of Disclosures

You can request a list of all disclosures of your child's health information made by Haven.

  • What's Included: Who received information, when, what information was shared, and why
  • Exclusions: Does not include disclosures for treatment, payment, operations, or disclosures you authorized
  • How to Request: Email privacy@yourhaven.life or submit written request
  • Timeframe: Haven will provide within 30 days
  • Frequency: Entitled to one free accounting per 12 months; additional requests may have a fee

D. Right to Restrict Use & Disclosure

You can request Haven restrict how health information is used and disclosed.

  • Restrictions Haven MUST honor: Any restriction you request (though Haven may negotiate)
  • Example Requests: "Don't share my child's allergy information with substitute teachers" or "Only contact me via email, not phone"
  • How to Request: Written request to privacy@yourhaven.life specifying the restriction
  • Limitation: Haven may not restrict disclosures required by law or for treatment emergencies (but must follow your preferences when possible)

E. Right to Confidential Communication

You can request that Haven contact you about health information using a specific method or location.

  • Examples: "Contact me only at work email, not home email" or "Send all communications to my mailing address, not phone"
  • How to Request: Specify preferred contact method when submitting requests or via privacy settings
  • Reasonable Request: Haven must accommodate reasonable requests

F. Right to Breach Notification

If your child's health information is breached, you will be notified.

  • What You'll Receive: Written notice describing what information was breached, how the breach occurred, and steps being taken
  • Timeframe: Without unreasonable delay and no later than 60 days from discovery
  • Contact Method: Most likely contact at the phone or email on file with Haven
  • Investigation: Haven will conduct a risk assessment to determine if notification is required (some breaches may not pose significant risk)
No Retaliation: Haven will not punish, deny services, or discriminate against you for exercising your HIPAA rights.
15

16. Haven's Duties Regarding Your PHI

A. Duty to Protect Privacy

Haven must:

  • Limit use and disclosure to necessary purposes
  • Implement safeguards to protect PHI from unauthorized access
  • Maintain confidentiality agreements with staff and vendors
  • Conduct regular security audits and risk assessments
  • Respond promptly to incidents involving PHI

B. Duty to Provide This Notice

Haven must provide a copy of this notice:

  • At the time of enrollment or service
  • Upon request
  • When policy changes are made

C. Duty to Maintain Privacy Records

Haven keeps records of:

  • All disclosures of health information
  • Access logs showing who viewed health records and when
  • Requests for access, amendment, or restrictions
  • Incidents or breaches involving PHI

D. Duty to Accommodate Requests

Haven must:

  • Respond to requests for access, amendment, or accounting within required timeframes
  • Honor reasonable restrictions and confidential communication requests
  • Provide information in the format you request (if feasible)

E. Duty to Notify of Breaches

Haven must notify you if your PHI is breached and there is a reasonable risk of harm.

F. Changes to This Notice

Haven may change this notice at any time. The new notice will apply to all health information Haven has on file. Notice of material changes will be provided at least 30 days in advance.

16

17. Complaints & How to File

A. File a Complaint with Haven

If you believe Haven violated your privacy rights, you can file a complaint:

Haven Privacy Officer
Name: Britt Riley
Email: privacy@yourhaven.life or britt@yourhaven.life
Mailing Address: [Haven Address]
Phone: [Haven Phone]

What to Include in Your Complaint:

  • Your name and contact information
  • Description of what happened and when
  • Why you believe it violated your privacy rights
  • What you would like Haven to do about it
  • Any documentation supporting your complaint

Timeframe: Haven will acknowledge your complaint within 5 business days and provide a response within 30 days. Complex complaints may take longer.

B. File a Complaint with the U.S. Department of Health & Human Services (HHS)

You also have the right to file a complaint with the federal government:

Office for Civil Rights (OCR)
U.S. Department of Health & Human Services

Online: https://ocrportal.hhs.gov/ocr/cp/complaint.html

Mail:
U.S. Department of Health & Human Services
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201

Phone: 1-800-368-1019 (TDD: 1-800-537-7697)
Email: OCRComplaint@hhs.gov

Timeframe: You can file a complaint with HHS at any time. There is no time limit under HIPAA for filing complaints, though some state laws may have time limits.

C. No Retaliation

Haven will not retaliate, punish, or discriminate against you for:

  • Filing a complaint with Haven or HHS
  • Requesting access to your health records
  • Requesting correction of inaccurate information
  • Requesting restrictions on use of your information
  • Exercising any other privacy rights under HIPAA
17

Acknowledgment & Questions

Your Privacy Matters

Haven is committed to protecting your family's information. We have implemented comprehensive safeguards including encryption, access controls, audit logging, and regular security testing.

Summary of Key Protections

  • Encryption: Health information encrypted at the database level using AES-256-GCM
  • Access Controls: Role-based, organization-scoped permissions (families can't see each other's data)
  • Monitoring: Continuous audit logging and anomaly detection
  • Incident Response: Dedicated team and procedures for any security incidents
  • Vendor Accountability: All vendors handling health data sign Business Associate Agreements
  • No Selling: We do not sell or share health information for marketing purposes
  • Your Control: You have rights to access, correct, and restrict how your information is used

Questions?

Haven Privacy Officer:
Britt Riley
Email: privacy@yourhaven.life or britt@yourhaven.life
Phone: [Haven Phone]

We're happy to answer any questions about your privacy or Haven's practices.

Acknowledgment of Receipt

By enrolling in Haven or using our services, you acknowledge that you have received and reviewed this Privacy Policy and HIPAA Notice of Privacy Practices. You understand your rights and how your information is used and protected.

Document Information

Title: Haven Privacy Policy & HIPAA Notice of Privacy Practices
Effective Date: May 1, 2026
Last Updated: May 1, 2026
Next Review: May 1, 2027
Approved By: Britt Riley, Privacy Officer
Organization: Haven, Inc.