Privacy Policy
PRIVACY POLICY (2026-08-14)
1. Who We Are and What This Policy Covers
Office Puzzle, Inc., a Delaware corporation (“Office Puzzle,” “we,” “us”), provides practice-management software to healthcare providers, primarily Applied Behavior Analysis practices. This Privacy Policy explains how we handle personal information in two different settings:
- our marketing website at officepuzzle.com, which is open to the public; and
- our platform at the logged-in application our customers use to run their practices.
These are handled very differently, and the difference matters. It is set out in Sections 2, 4, and 8.
2. Our Role — Please Read This First
Most of the personal information in our platform is entered by our customers — the clinics and providers who use Office Puzzle to run their practices. For that information:
- the customer decides what is collected, how it is used, and how long it is kept;
- we process it only to provide the Services to that customer, under our agreement with them; and
- under HIPAA we act as a Business Associate to the customer, who is the Covered Entity.
If you are a client, patient, family member, employee, or contractor of one of our customers and you want to see, correct, or delete information about you, or you no longer wish to be contacted, please contact that practice directly. They control that information; we cannot act on it without their instruction. We will support them in responding to you.
We handle other information as the responsible party in our own right — principally information about visitors to our marketing website, and contact details for the people who administer customer accounts.
3. Information in the Platform
Our customers may enter information about the people they serve, including:
- name and contact details, and emergency contact details;
- demographic information;
- insurance and payment information;
- health information, including diagnoses, assessments, session notes, treatment plans, and service history; and
- other information the practice considers relevant to care.
If you are an employee or contractor of one of our customers, the practice may also enter your job title, compensation and benefits information, taxpayer identification number, licensure and certification details, disciplinary history, and education.
The specific information held about any individual depends entirely on how that practice uses the Services.
When you use the platform we also collect account and technical information — your name, work email, and role; IP address, browser and device type, and operating system; and records of activity in the application, which we use to operate, secure, troubleshoot, and support the Services.
4. Information We Collect on Our Marketing Website
When you visit officepuzzle.com — as distinct from logging into the platform — we and our advertising and analytics partners collect information to understand how people find us and to market our software to healthcare practices.
This includes:
- information you give us directly, such as name, work email, phone number, practice name, and anything you write in a form or request;
- device and browser information, IP address, and approximate location derived from it;
- pages viewed, links clicked, time on page, and referring website;
- campaign and source identifiers, including URL parameters and unique links we provide to referral partners so we can identify where a visit came from; and
- cookie and advertising identifiers set by us and by our partners.
We use this information to measure and improve our marketing, to understand which campaigns and referral sources bring visitors to us, and to show our advertisements to people who have visited our website (commonly called retargeting).
Our marketing and advertising partners currently include Google, Meta, LinkedIn, and HubSpot, which also hosts our website. These partners receive information such as cookie identifiers, device information, and pages viewed, and they may combine it with information they already hold about you.
None of this happens on the logged-in platform. See Section 8.
5. How We Use Information
We use information to:
- provide, operate, maintain, secure, and support the Services;
- process payments and administer subscriptions;
- detect and prevent fraud and abuse, and investigate incidents;
- respond to support requests;
- improve the Services and develop new features, using de-identified or aggregated data as described in Section 6;
- communicate with account administrators about service, security, and billing matters; and
- market our software to healthcare practices, including through advertising, retargeting, and attribution measurement — using marketing website information only, never information from the platform.
We do not sell personal information for money. We do not use any information our customers place in the platform, including health information, for our own marketing or advertising, and we do not disclose it to advertising partners.
6. De-Identified and Aggregated Data
We may create de-identified data from information in the platform, using the methods HIPAA permits, and use it to operate, secure, analyze, and improve the Services and to produce aggregate statistics. We do not attempt to re-identify that data and we do not permit others to do so. Aggregate statistics never identify a customer, an individual, or a practice.
7. How We Share Information
We share information only as follows:
- Service providers. Companies that help us run the Services, such as cloud hosting, payment processing, communications, and support tooling. They may use the information only to provide services to us, under written agreements. Where they may handle health information, we put a HIPAA Business Associate Agreement in place. We maintain a current list of these providers and make it available to customers on request.
- Advertising and analytics partners, on our marketing website only. As described in Section 4.
- At our customer’s direction. We transmit information where a customer instructs us to, for example to a payor or a party the practice designates.
- Legal and safety. Where required by law or legal process, or where we reasonably believe disclosure is necessary to protect our rights, investigate fraud, or protect the safety of any person. Where a request concerns information held for a customer, we notify that customer unless we are legally prohibited from doing so.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to the protections in this policy and applicable law.
8. Cookies and Tracking Technologies
We treat our marketing website and the logged-in platform differently, and the difference is deliberate.
On our marketing website
We and our partners use cookies, pixels, and similar technologies for site functionality, analytics, advertising, retargeting, and attribution, as described in Section 4. Our website presents a cookie consent banner where you can manage your choices, and you can also control cookies through your browser settings. Opting out of advertising cookies does not stop you from using the website.
On the logged-in platform
We do not use advertising cookies, advertising pixels, or third-party behavioral analytics on authenticated pages of the platform, including any page where health information may be displayed. Only first-party technologies necessary to operate, secure, and support the platform are used there
Where required by law, we honor recognized opt-out preference signals on our marketing website.
9. Children’s Information
Many of our customers provide services to children, including children under 13. We process information about children only as a service provider to those practices, on their instructions.
The practice, not Office Puzzle, is responsible for obtaining any parental consent required by law, including verifiable parental consent under the Children’s Online Privacy Protection Act and analogous state laws. We require our customers to obtain and maintain those consents.
Our marketing website is directed to healthcare professionals, not to children, and we do not knowingly collect information directly from children through it. If you believe a child has provided information to us directly, please contact us and we will delete it.
If you are a parent or guardian with questions about information a practice holds about your child, please contact that practice.
10. How Long We Keep Information
We keep information in the platform for as long as needed to provide the Services to the customer who entered it.
After a customer’s subscription ends, we make their data available for export for sixty days. During that period the customer may instruct us to return or destroy it. After the sixty-day export period we have no obligation to retain the data and may delete it at any time. We do not offer extended or archival retention. Customers are responsible for exporting and independently retaining any records they are required to keep.
We keep information we hold in our own right, such as marketing website and account records, for as long as needed for the purpose it was collected and to meet our legal obligations.
11. How We Protect Information
We maintain an information security program designed to protect information against unauthorized access, use, disclosure, alteration, and destruction. It includes encryption of data in transit and at rest, access controls and unique user credentials, restriction of employee access to what is needed to do the job, background screening for staff with access to production systems, security and HIPAA training, and written agreements with vendors who handle health information.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a security issue, please contact us at the address in Section 14.
12. Your Privacy Rights
Which rights apply to you depends on where you live and on the kind of information involved. Most comprehensive state privacy laws contain exemptions for information covered by HIPAA, so the rights below generally do not apply to health information we hold for our customers — for that information, please contact the practice. They are most likely to apply to information we collect through our marketing website.
Depending on your state, you may have the right to:
- know what personal information we hold about you and how we use it;
- request a copy of it, or that it be transferred to another organization;
- request that we correct inaccurate information;
- request that we delete it;
- opt out of targeted advertising and of the sale or sharing of personal information; and
- not be discriminated against for exercising these rights.
To make a request, contact us using the details in Section 14. We will verify your identity before responding, and will respond within the period required by the law that applies to you. If your request concerns information we hold for one of our customers, we will let you know and direct you to that practice.
California Residents
This section applies to California residents and supplements the rest of this Section 12.
Health information we hold on behalf of our customers is protected health information under HIPAA and is exempt from the California Consumer Privacy Act. This section therefore concerns the information we collect through our marketing website, described in Section 4.
The categories of personal information we collect, the sources we collect it from, the purposes we use it for, and the categories of third parties we disclose it to are described in Sections 4, 5, and 7. We do not sell personal information for money. We do disclose online identifiers and browsing activity to advertising partners for targeted advertising, which California law treats as “sharing.” We do not collect sensitive personal information through our marketing website, and we do not knowingly sell or share the personal information of anyone under 16.
California residents may request to know, access, correct, or delete their personal information; may opt out of sharing for targeted advertising; and may not be treated differently for exercising these rights. To make a request, email support@officepuzzle.com or write to us at the address in Section 14. To opt out of sharing, use the cookie preferences link on our website; we also honor Global Privacy Control signals. We will verify your identity before responding and will respond within 45 days, extendable as permitted by law. An authorized agent may submit a request on your behalf with proof of authorization.
Individuals outside the United States
Our Services are offered to customers in the United States. Our customers may, however, employ or engage people located in other countries, and may enter information about them into the platform. Where that happens, the customer is the controller of that information and remains responsible for its own compliance obligations in the relevant country. Office Puzzle acts as a processor and processes that information only on the customer’s documented instructions. Customers with obligations under the European Union or United Kingdom General Data Protection Regulation should contact us to put appropriate data processing terms in place.
13. Changes to This Policy
We may update this policy. If we make a material change, we will post the updated policy here with a new effective date and, where the change affects our customers, notify account administrators by email. We encourage you to review it periodically.
14. Contact Us
Questions, requests, or concerns about this policy or our privacy practices:
Office Puzzle, Inc.
Attn: Privacy · 760 NW 107th Ave, Suite 420, Miami, FL 33172
support@officepuzzle.com
If you are a client, family member, employee, or contractor of a practice that uses Office Puzzle, please contact that practice first — they control the information and can act on it directly.