This policy covers the financial account data handled by ChiroUnchained's Digital Office Manager module, specifically the bank account connection feature powered by Plaid. It applies to any practice (“tenant”) using this feature, and to the individual staff member or practice owner who connects a bank account through it.
This policy does NOT cover patient clinical or health records. Patient protected health information (PHI) is handled by a separate part of the ChiroUnchained platform, under a separate Business Associate Agreement with AWS for HIPAA-covered processing, and is not accessed by or connected to the Plaid integration described here.
The person who connects a bank account through this feature (“you”, “the user”) is a member of practice staff — typically the practice owner, office manager, or a designated bookkeeping role — connecting the practice's own business bank account for internal cash reconciliation and financial tracking. This is not a patient-facing feature and does not collect any patient financial information.
Through Plaid, ChiroUnchained receives and stores the following, and only the following:
ChiroUnchained does not request, and Plaid's response does not include, full bank account or routing numbers beyond what is required to maintain the connection. No transfer, payment-initiation, or account-modification data or capability is requested.
Data received through this connection is used exclusively for:
Data is never used to make automated financial decisions. Every recommendation or flagged discrepancy generated from this data requires a human staff member to review and respond — nothing is auto-approved, auto-transferred, or auto-resolved.
Raw transaction records are retained for 13 months, after which they are automatically deleted. Monthly and yearly summary totals are retained indefinitely for historical reporting, but these summaries do not contain individual transaction details — they are aggregate numbers only, calculated before the underlying raw records are deleted.
Financial account data collected through this integration is not sold, rented, or shared with any third party for marketing or any purpose unrelated to the practice's own internal financial tracking. Data is not shared between practices (tenants) using this platform — each practice's financial data is isolated to that practice.
Connecting a bank account through this feature requires explicit authorization through Plaid's own consent flow at the time of connection. You may disconnect a linked account at any time; upon disconnection, no further data is retrieved for that account, and previously stored data remains subject to the retention schedule in Section 6.
To request access to, correction of, or deletion of data collected under this policy, contact the practice's designated information security contact (see the practice's Information Security Policy for current contact details).
This policy will be updated as the platform's data handling practices change. The effective date at the top of this document reflects the version currently in force.