PalSuiteby Osman Consulting Services, LLC

Privacy Policy

Osman Consulting Services, LLC (“OCS”, “we”, “us”) · Effective August 22, 2026 · Applies to EMRpal, TherapistPal Pro, NursePal Pro, Agency Portal and CEULogic (the “Services”).

1. What this policy covers

This policy explains what information we collect when you use our websites and Services, how we use it, and the choices you have. Each product may display additional in-app notices specific to that product. For EMRpal, which processes protected health information (PHI) on behalf of healthcare providers, Section 8 applies in addition to everything else.

2. Information we collect

Information you give us

  • Account information — name, email address, phone number, professional credentials (licence number, NPI, discipline), organisation name and address.
  • Billing information — billing contact and address. Card numbers are entered directly into Stripe, our payment processor; we never receive or store full card details.
  • Content you create — documents, notes, course progress, uploads and messages you enter into a Service.
  • Support requests — what you send us when you contact support.

Information collected automatically

  • Usage and device data — pages viewed, features used, timestamps, IP address, browser and operating system, and error reports.
  • Cookies — strictly necessary cookies for sign-in and security. We do not use advertising cookies or sell data to advertisers.

3. How we use information

  • To provide, operate, secure and improve the Services.
  • To process payments, send receipts and manage subscriptions.
  • To respond to support requests and send service notices (e.g. trial ending, payment failed, security alerts).
  • To meet legal, regulatory and contractual obligations, including HIPAA and continuing-education reporting requirements.
  • With your consent, to send product news. You can opt out at any time.

4. How we share information

We do not sell personal information. We share it only with:

  • Service providers that help us run the Services under contracts that restrict their use of the data — hosting (Amazon Web Services), payments (Stripe), email delivery (Amazon SES), networking and security (Cloudflare), and AI model providers used for drafting assistance (Anthropic), each bound by appropriate data-protection terms and, where PHI is involved, a Business Associate Agreement.
  • Your organisation — if your account was created by an employer, clinic or agency, its administrators can access information in that account.
  • Legal requirements — when required by law, subpoena or to protect rights, safety and the integrity of the Services.
  • Business transfers — in a merger, acquisition or sale of assets, subject to this policy.

5. Data retention

We keep account and billing records for as long as your account is active and as required for tax and legal purposes (generally seven years for financial records). Clinical records in EMRpal are retained according to your organisation’s agreement and applicable medical-records retention law. You may request deletion of non-regulated personal data by contacting us; we will honour the request unless retention is required by law or contract.

6. Security

We use encryption in transit (TLS) and at rest, role-based access controls, audit logging, regular backups and least-privilege infrastructure on AWS. No method of transmission or storage is perfectly secure; if we learn of a breach affecting your data we will notify you and regulators as required by law.

7. Your choices and rights

  • Access, correct or export your account information from within the Service or by contacting us.
  • Opt out of marketing email using the link in any message.
  • Residents of certain states (including California, Colorado, Virginia and others) may have additional rights to access, delete or limit use of personal information. We honour these requests regardless of where you live, subject to legal exceptions. We do not sell or share personal information for targeted advertising.
  • The Services are not directed to children under 16 and we do not knowingly collect their data.

8. HIPAA — EMRpal and other Services handling health information

When a healthcare provider uses EMRpal (or any other Service) to store or transmit protected health information, OCS acts as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). The provider is the Covered Entity and remains responsible for its own notices of privacy practices to patients.
  • We use and disclose PHI only as permitted by our Business Associate Agreement (BAA) with the provider and by HIPAA — to provide the Service, for our own management and administration, and as required by law.
  • We implement administrative, physical and technical safeguards consistent with the HIPAA Security Rule, including access controls, audit trails, encryption, workforce training and incident response procedures.
  • Subcontractors that may access PHI (e.g. our cloud-hosting and AI-drafting providers) are bound by their own BAAs with us.
  • We report security incidents and breaches of unsecured PHI to the Covered Entity without unreasonable delay and within the timeframe set in the BAA.
  • Patients should direct requests to access or amend their records to their healthcare provider; we assist the provider in fulfilling those requests.
  • Referral-portal submissions on EMRpal are transmitted to the receiving clinic and handled under that clinic’s privacy practices.

9. International users

The Services are operated from the United States and intended for U.S. users. If you access them from elsewhere, your information will be processed in the United States.

10. Changes

We may update this policy from time to time. Material changes will be announced in the Service or by email, and the effective date above will be updated.

11. Contact

Osman Consulting Services, LLC · Orland Park, IL 60467 · info@ceulogic.com · (708) 449-4066