Compliance
Last updated: August 27, 2026
How ElderCareHub approaches legal and regulatory obligations for family health information.
Data protection
We apply the strictest principles to all users regardless of where they live: data minimization, purpose limitation, and the rights to access, export, correct, and delete. This approach is informed by the EU GDPR, the UK GDPR, Canada's PIPEDA, the California CCPA/CPRA, and similar laws.
Health information entered by families is treated as sensitive (special-category) data with explicit consent as its basis, plus encryption, access control, and audit logging regardless of jurisdiction.
EU, EEA, and UK users
Users in the EU, EEA, and UK have the data-subject rights described in our Privacy Policy, including access, rectification, erasure, portability, restriction, objection, withdrawal of consent, and complaint to a supervisory authority. Optional analytics runs only after opt-in consent, and never on pages containing health information.
Data protection questions and rights requests: privacy@eldercarehub.app.
HIPAA
ElderCareHub is a consumer family-coordination tool, not a covered entity or business associate under HIPAA. If you are a care organization requiring HIPAA-covered workflows and a Business Associate Agreement, contact organizations@eldercarehub.app about our Professional plan — we do not claim HIPAA compliance prematurely.
Not a medical device
The platform intentionally avoids diagnostic or predictive clinical claims. Safety escalations follow deterministic, family-configured rules. AI features organize and summarize entered information only and are governed by a safety layer that blocks clinical decision-making.
Children
ElderCareHub is designed for adults. Child/dependent profiles may be managed by their parent or guardian; children under 16 may not create accounts.