Volver al Inicio

Privacy Policy

Last updated: July 2026

At Serenity, protecting resident and staff data is our top priority. This policy outlines how we collect, use, store, and protect personal information within our management platform.

1. Platform Nature and Data Responsibility: Serenity is a Software-as-a-Service (SaaS) tool intended exclusively for administrative, operational, and financial management. Serenity, its parent entity, directors, officers, and employees do not provide medical or healthcare services. The subscribing organization is solely responsible for ensuring the accuracy, truthfulness, and legality of all entered data, as well as obtaining all legally required authorizations and consents from residents, guardians, and staff.

2. Data We Collect: We collect data provided by the subscribing organization to deliver the service, including resident information (full name, ID, health insurance, care history, vital signs, medication logs), staff information (name, email, role, employment documents), and administrative data (billing, plans, facility locations).

3. Purpose of Processing: Data is processed exclusively to: (a) deliver contracted care facility management services, (b) generate operational and financial reports, (c) facilitate compliance with applicable administrative regulatory requirements in the sector, (d) send service notifications.

4. Storage, Security, and Org ID Isolation: Data is stored on Supabase infrastructure (Amazon Web Services provider) in the US-East-1 region (Virginia, United States). We employ encryption at rest (AES-256) and in transit (TLS 1.3). We apply strict Row Level Security (RLS) policies and Organization ID scoping to guarantee absolute tenant isolation so each entity accesses only its own data. Automated daily backups are performed. Pursuant to applicable regulations, international data transfers strictly follow compliant security measures.

5. Cookies and Local Storage Usage: We use essential cookies and browser local storage solely to maintain active authenticated sessions, remember UI preferences, and measure system performance via aggregated analytics (Google Analytics). Users can manage or block cookies through browser settings.

6. Access and User Rights: Only authorized users within each organization can access data based on permissions assigned by their administrator. Subscribing organizations may request data export or deletion, processed within 10 business days.

7. Data Retention and Grace Period: Data is retained during active subscription and for up to 90 days after cancellation, after which it is irreversibly deleted unless retention is mandated by law.

8. Clinical Record Integrity and Traceability: Administrative and clinical records are not permanently deleted. Corrections preserve the original record through an immutable audit logging system recording user, date, time, and change details to ensure full legal traceability.

9. Authentication and Electronic Signatures: The platform utilizes individual user authentication with password verification as an electronic signature method for administrative and clinical actions under applicable digital signature laws. Each action is immutably linked to the authenticated user and server timestamp.

10. Applicable Law: This policy is governed by applicable personal data protection laws. For international users, local data privacy regulations apply.

Si tiene alguna pregunta sobre nuestra Política de Privacidad, por favor contáctenos a través de nuestro soporte técnico.