Compliance

Last updated: August 27, 2026

How ElderCareHub approaches legal and regulatory obligations for family health information.

Data protection

We apply the strictest principles to all users regardless of where they live: data minimization, purpose limitation, and the rights to access, export, correct, and delete. This approach is informed by the EU GDPR, the UK GDPR, Canada's PIPEDA, the California CCPA/CPRA, and similar laws.

Health information entered by families is treated as sensitive (special-category) data with explicit consent as its basis, plus encryption, access control, and audit logging regardless of jurisdiction.

EU, EEA, and UK users

Users in the EU, EEA, and UK have the data-subject rights described in our Privacy Policy, including access, rectification, erasure, portability, restriction, objection, withdrawal of consent, and complaint to a supervisory authority. Optional analytics runs only after opt-in consent, and never on pages containing health information.

Data protection questions and rights requests: privacy@eldercarehub.app.

HIPAA

ElderCareHub is a consumer family-coordination tool, not a covered entity or business associate under HIPAA. If you are a care organization requiring HIPAA-covered workflows and a Business Associate Agreement, contact organizations@eldercarehub.app about our Professional plan — we do not claim HIPAA compliance prematurely.

Not a medical device

The platform intentionally avoids diagnostic or predictive clinical claims. Safety escalations follow deterministic, family-configured rules. AI features organize and summarize entered information only and are governed by a safety layer that blocks clinical decision-making.

Children

ElderCareHub is designed for adults. Child/dependent profiles may be managed by their parent or guardian; children under 16 may not create accounts.