Last updated: July 20, 2026
Draft — pending legal review. This page is a placeholder so the footer link is not dead while final counsel-reviewed language is prepared. It describes our actual data practices in good faith but has not yet been reviewed by an attorney. Do not treat it as a substitute for a signed HIPAA Business Associate Agreement. TODO: replace with attorney-reviewed copy before relying on the HIPAA/FERPA claims made elsewhere on this site.
SLPDesk ("we", "us") provides clinical documentation, scheduling, and progress-monitoring software for school-based speech-language pathologists. This policy covers data collected through slpdesk.com and the SLPDesk application. Contact us at hello@slpdesk.com with any privacy question.
Student and clinical records handled through SLPDesk are treated as protected health information (HIPAA) and education records (FERPA). We apply role-based access control, per-district data isolation, and audit logging to every record. School districts and clinics remain the HIPAA covered entity / FERPA-responsible party; SLPDesk acts as a business associate / school official under a data processing agreement. TODO: link the executed BAA / DPA template here once finalized.
We use collected data to operate, secure, and improve SLPDesk — generating reports, sending scheduled deadline and session emails you've configured, and diagnosing bugs. We do not sell student or clinician data, and we do not use student data for advertising.
Data is retained for as long as the district or clinic's account is active, or as required by applicable education/health record retention law. Account owners can request export or deletion by emailing hello@slpdesk.com.
Questions about this policy: hello@slpdesk.com.