Your data
Your data stays yours.
Before you let anybody near your systems, the fair question is what happens to your customers' information. We build for workflows that touch patient records, client files and payment details, and for owners whose customers aren't all in Texas. So here's the plain answer — before you have to ask for it: how we handle your data, and which rules land on your kind of business.
Clinics, therapists, dentists, billing offices
We'll sign a BAA. If your practice needs a Business Associate Agreement in place before anyone touches a system that sees protected health information, send us yours and we'll sign it. That obligation belongs in writing, not in a sales conversation.
What we won't do is wave a badge at you. Handling patient information properly is something your whole practice does — not something a vendor stamps on a website. So we'll show you exactly how a system is built and where the data sits, and you or your attorney can hold that up against what you're required to do.
Your accounts, in your name
Everything we build lives in accounts that belong to you, under your billing. We get access to do the work. If we stop, your data and your accounts stay yours, and anything you have paid for in full is yours to keep. There's no hostage situation, and no month where somebody else holds the keys to your own business.
People see only their job
Least-privilege access: the front desk sees what the front desk needs, and not the rest. Role-based logins for each person instead of one shared password everybody knows — so when somebody leaves, you switch off one account, not the whole system.
An audit trail
Who changed what, and when. It costs almost nothing to build in at the start, and it's the difference between answering a hard question six months from now and guessing at it.
Encrypted in transit and at rest
Your information is encrypted on the way in and while it sits there — that's standard on the managed platforms we build on, and we don't work around it. Passwords and keys go in a proper secrets store, never in a spreadsheet, an email, or a text message to us.
No training AI on your data
When a system uses AI, it works on your information to do the job you asked for. It isn't quietly feeding your files into somebody's model. If you ever do want AI that knows your own material, that's a decision you make on purpose — not a default we leave switched on.
A backup, and a way back
Backups run, and changes go out in a way that can be undone. If something goes wrong the answer is “put it back,” not “start over.” And you hear it from us first — we'd rather tell you about a problem we already fixed than have you find one we hid.
Which rules land on you
The rules don't stop at your county line.
Different information comes with different obligations, and some of them reach well past the state you operate in. What we can tell you is which ones come up most, and what each one needs your software to be able to do. Nothing below decides whether a law applies to you — that turns on your size, your industry and who you deliberately sell to, and it is your attorney's call every time. Find your line:
If you handle health information
Where HIPAA covers your practice it can reach us too — not because we are nearby, but when we are actually handling patient information on your behalf, which is what makes a vendor a business associate. Where that is the case, we'll sign a BAA. On the build side it means access limited by role, a record of who opened what, and encryption switched on by default rather than added later.
If you take cards
The card numbers never touch your systems. Payments run through a processor built for exactly that, like Stripe, Square or whoever you already use, so what lands in your database is a receipt and a last four, not a card number. It doesn't erase the card-industry rules (PCI DSS still applies to you as a merchant), but it keeps the heaviest parts of them on the processor instead of on you.
If you hold personal data on customers in other states
These are not one rule and they do not switch on the same way. California's CCPA and CPRA reach for-profit businesses operating there that clear a statutory size threshold. The Texas law here at home works differently — no revenue floor at all; it turns on doing business in Texas and not qualifying as a small business, and even then keeps a consent rule on selling sensitive data. Which one catches you is a question for your attorney. What they agree on is the handful of rights underneath: tell me what you have on me, delete it, don't sell it. Those have to be things your software can actually do on request — not a promise that somebody will get to it.
If you sell into Europe, the UK, Canada or Australia
Each of these has its own trigger, and they are not the same trigger. GDPR and UK GDPR reach you when you deliberately offer goods or services to people there, or track their behavior. PIPEDA turns on commercial activity with a real connection to Canada. Australia's Privacy Act generally starts above a turnover threshold, with exceptions that catch health providers at any size. One accidental order is rarely what pulls you in; a market you chose is. If that is the plan, it costs very little to build for on day one and a great deal to retrofit after somebody complains: consent recorded instead of assumed, and knowing which country the data physically sits in.
What that means for the software
Here's the useful part: the laws differ, but what they need your software toactually do barely changes. Build these in at the start and the software stops being the part standing in your way. The rest of any of these rules, meaning the policies, the training, the contracts and what you do on a bad day, is yours and your attorney's, and no build hands it to you.
- A real delete-my-data request — something you can actually run, not a promise to get to it
- Consent recorded when it's given, instead of assumed later
- Knowing where the data physically lives, down to the country
- Exporting everything you hold on one person, when they ask for it
- A record of who accessed what
We build the system so it can meet those obligations. We're not your lawyer, and when you need one we'll say so plainly — but you shouldn't have to pay a lawyer to discover that your software can't do what the rule asks of it.
Access stays tight, which cuts both ways: there's no room full of contractors touching your records, and there's no support queue between you and a straight answer. If your attorney, your insurer or your board has a list of requirements, send it before we start — we'll tell you which ones we can meet and which ones we can't.
Let's get started
Let's find what's costing you.
Thirty minutes on the phone and you'll know the one thing worth fixing first — and what it's worth to fix it. No pitch, no jargon, whether we end up working together or not.
Prefer to talk? (832) 639-5923
Tomball, TX · serving Houston and remote across the U.S. · usually reply same day