Privacy Policy

Last updated: March 23, 2026

OrgHealth Inc., dba OrgHealth ("we," "our," or "us") provides the Board Excellence Assessment, an online platform that helps organizations evaluate board governance. This Privacy Policy explains how we collect, use, and protect your information.

1. Information We Collect

We collect the following types of information:

  • Account information: first and last name, email address, password.
  • Assessment information: board details, participant invitations and responses, generated reports.
  • Payment information: processed securely by Stripe. We do not store full card numbers or billing information.
  • Technical information: IP address, device/browser type, and basic diagnostics for security, performance, and currency localization (e.g., displaying prices in your local currency).
  • Cookies: only essential cookies used for sign-in, session continuity, and security. We do not use tracking, advertising, or analytics cookies.

2. How We Use Your Information

We use your information to:

  • Provide and operate the Board Excellence Assessment platform.
  • Send transactional emails (e.g., invitations, password resets, assessment updates).
  • Process payments and prevent fraud.
  • Secure our services and comply with legal obligations.

3. Sharing of Information

We do not sell your data. We may share information with trusted service providers who help us deliver the service (e.g., Render for hosting, Mailgun for email, Stripe for payments, ipapi for IP-based location detection). These providers process data on our behalf under appropriate safeguards. We may also share information if required by law.

4. Data Retention

We retain account data while your account is active. Assessment data (including participant responses and reports) remains until you delete your account or specific data. When data is deleted, it is removed from active systems but may remain in secure backups for a limited period.

5. Your Rights

Depending on your location (e.g., Canada, EU/UK, certain US states), you may have rights to access, correct, delete, or restrict processing of your data, and to lodge a complaint with a regulator.

You can exercise these rights by contacting us at: privacy@orghealthteam.com.

6. International Users

Our services are hosted in the United States and/or Canada. If you use our services from outside these regions, you consent to the transfer and processing of your data internationally.

7. Security

We use industry-standard safeguards including encrypted connections, password hashing, and secure hosting. No method of transmission is 100% secure, but we work to protect your information.

8. Children

Our services are not directed to children under 16 and we do not knowingly collect their data.

9. Changes to this Policy

We may update this Policy periodically. We'll post the revised version and update the "Last updated" date.

10. Contact

If you have questions about this Privacy Policy, please contact:

OrgHealth Privacy Officer
privacy@orghealthteam.com

Cookie Notice (Essentials Only)

We use strictly necessary cookies to keep you logged in, maintain session security, and remember minimal preferences. We do not use analytics, marketing, or third-party tracking cookies.