Legal
Privacy Policy
What TheraCRM.pro and Aday Interactive, Inc. collect from visitors to this website and from practices using the service, how it is used, and where it is not shared.
Last updated: 27 July 2026 · Counsel review pending — see the note at the end of this page.
1. Overview and non-disclosure commitment
Aday Interactive, Inc. (“Aday Interactive,” “we,” “us”) operates TheraCRM.pro as a bilingual intake automation service for South Florida practices, built on HIPAA-enabled third-party infrastructure. We do not sell, rent, or otherwise monetize practice data, prospective-patient information, or protected health information (PHI) with third-party data brokers or advertising networks, under any circumstances.
2. Information we collect
From this website. If you submit the consultation form, we collect your name, practice name, contact details, and whatever you write in the message field. Standard technical data (browser, approximate location from IP, pages visited) is generated by hosting infrastructure regardless of any analytics we choose to run — see the Cookie Policy for exactly what this site sets today.
From a subscribed practice. Account registration details, clinician calendar settings, billing information, and staff login audit logs are practice data. Web intake form responses, contact details, insurance payer information, preferred session times, and two-way message logs submitted by prospective patients through your configured forms may constitute PHI, and are handled under the Business Associate Agreement described below.
3. How we use information
Website inquiry data is used to respond to your consultation request and, if you become a client, to configure your account. Practice data is used to operate and support your subscription. PHI moving through a subscribed practice’s account is used solely to provide the intake automation service to that practice — not for our own marketing, and not aggregated across practices for any purpose beyond the reporting features described on that account’s dashboard.
4. Text messages and phone calls
If you give us your mobile number on the consultation form, you are agreeing that we may text you about that inquiry and about setting up service. We use it for that. We do not sell, rent, or pass your number to third-party marketers, and we do not share it with anyone outside the vendors that actually carry the message.
You can stop the messages at any time by replying STOP, or ALTO or PARE if you are texting us in Spanish. Replying HELP or AYUDA returns contact information. Message frequency varies. Message and data rates may apply through your carrier. Opting out of texts does not opt you out of email, and it does not affect service to a practice that already subscribes.
Messages your practice sends to its own patients are a separate matter. When a subscribed practice uses this service to text or call the people who contact it, that practice is the sender. It is responsible for having a lawful basis to contact them, for honouring opt-outs, and for compliance with the Telephone Consumer Protection Act and Florida’s telemarketing rules. We configure the opt-out handling and the Spanish keywords; we do not supply the consent, and we cannot verify it on your behalf.
Calls placed or received through the AI voice agent may be recorded or transcribed where a practice has enabled that. Recording law varies by state and Florida requires all-party consent. A practice that turns recording on is responsible for the notice its callers receive.
5. Technical and physical safeguards
TheraCRM.pro is built on a third-party provider’s HIPAA-enabled infrastructure — that provider is named, with everything else that touches your data, in Section 11 of the Terms of Use. The technical safeguards below are provided by that platform; Aday Interactive is responsible for enabling and configuring them correctly for each practice, including turning on HIPAA mode per sub-account, which is never assumed and always checked before go-live.
Encryption. PHI is encrypted at rest (AES-256) and in transit (TLS 1.2/1.3), per the platform’s published standards.
Access controls. Role-based access is configured on a minimum-necessary basis, so staff see only what their role requires.
Audit logging. The platform logs access to covered data, and support access to it is restricted.
Full detail on what is and is not covered, including what we cannot yet confirm, lives on the HIPAA & BAA page — we would rather point you to the longer, more honest answer than compress it here.
6. The Business Associate chain
A subscribed practice, as a covered entity, executes a Business Associate Agreement (BAA) with Aday Interactive, Inc. as its business associate. Aday Interactive in turn maintains a BAA with the platform provider, which operates the underlying platform as a subcontractor business associate and maintains its own agreements with its subprocessors for messaging, telephony, email delivery, and hosting. We will provide our current subprocessor position on request.
HIPAA compliance is a shared responsibility: the platform provides technical safeguards, we configure them, and a subscribed practice maintains its own policies, training, and workforce controls. No vendor — including us — can make a practice compliant on its own, and no one is “HIPAA certified,” because no such government certification exists for anyone.
7. Cookies and similar technologies
This website’s use of cookies is covered in full in the Cookie Policy, including exactly what is set today and what is not.
8. Payment processing
Subscription payments are handled by a third-party payment processor. Card numbers are submitted to that processor directly and are not stored on our systems. What we retain is the billing contact, the plan, and the transaction record we need for accounting and support. The processor handles that data under its own terms and privacy policy.
9. Security, stated plainly
The platform provides encryption in transit and at rest, access controls, and audit logging, and we configure them per practice. Those are real protections and they are described in Section 5.
They are not a guarantee. No method of transmitting data over the internet and no method of electronic storage is completely secure, and any vendor who tells you otherwise is selling something. We use commercially reasonable measures and we hold a Business Associate Agreement that obliges us to report breaches; we cannot promise that a breach will never happen. If one affects your practice’s data, our obligations to notify you are set out in that agreement and in Florida’s Information Protection Act.
10. Your data rights, export, and portability
A subscribed practice retains ownership of its own patient records and contact lists. On request, we will export your contacts, form submissions, and pipeline history in a standard tabular format, and we will not withhold your data or condition its release on anything.
Two limits we state plainly rather than let anyone discover later. First, the underlying platform does not publish a guaranteed export format, retention period, or deletion timeline for protected health information, so our commitment is to act promptly and in good faith rather than to a documented service level we do not control. Second, a HIPAA-enabled sub-account can only be transferred to another agency that also holds the platform’s HIPAA module — so moving to a partner who does not hold it means migrating data rather than transferring the account.
We are seeking written clarification from the platform on both points and will update this policy when we have it. Ask us about this on your consultation call; we would rather answer it before you sign than after.
11. State privacy rights
Residents of several states have statutory rights to see, correct, delete, or obtain a copy of the personal information a business holds about them. Whether a given statute binds us turns on revenue and volume thresholds that a business our size does not currently meet, and we are not going to claim a compliance status we have not earned.
What we will say is the part that matters to you in practice: we honour access, correction, and deletion requests for your own information whether or not a statute compels us to. Ask through the contact route in the last section. We may need to verify who you are before acting, and we may have to keep records a law or the Business Associate Agreement requires us to keep — if we cannot delete something, we will tell you which obligation prevents it.
If you are a prospective patient rather than a practice, your records sit inside a practice’s account and that practice controls them. Send your request to the practice. We will support them in answering it; we will not act on their patient records without their instruction.
12. Retention and deletion
We retain website inquiry data for as long as reasonably needed to respond to it and, if you become a client, for the life of the relationship plus a limited period afterward for our own recordkeeping. For PHI inside a subscribed practice’s account, retention and deletion follow that practice’s own instructions and configuration, subject to the platform limitation described in Section 10 above.
13. If this business changes hands
If Aday Interactive is acquired, merged, or sells the assets behind this service, practice data and any PHI would move with it, and the acquirer would be bound by the same Business Associate Agreement obligations. We would notify subscribed practices before that happened, so a practice that does not want to continue under new ownership has time to export its data and leave.
What happens if we stop operating altogether is a separate question with a real answer, and it is set out on the HIPAA & BAA page rather than buried here.
14. Links to other sites
This site links to pages we do not run — the platform vendor, government and Census sources, and occasionally a competitor where naming one is more honest than not. Following a link takes you to someone else’s privacy practices, which we do not control and are not responsible for.
15. Children’s information
This website is directed to practice owners and administrators, not to children. We do not knowingly collect information from children through this site. Information about minors that a practice collects as part of its own patient intake is that practice’s data, handled under its own consent and authorization processes.
16. Changes to this policy
We will update this page as our practices change, particularly as the open questions in Section 10 and on the HIPAA & BAA page get answered in writing. The date at the top of this page reflects the last substantive revision.
17. Contact
Questions about this policy, or a request to export or delete your practice’s data, can be directed through our contact page or by phone at (305) 209-8453.
This information is general and does not constitute legal advice. We are not attorneys. Consult qualified healthcare counsel regarding your practice’s specific obligations under HIPAA, Florida’s Information Protection Act, and any other applicable law. This policy is pending review by Florida healthcare counsel.