Last updated: August 15, 2026
Kondaro, Inc. (“Kondaro,” “we,” “us,” or “our”) operates a software-as-a-service platform for behavioral health treatment centers. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our platform at kondaro.com.
We collect information that facility administrators and authorized users provide directly when creating accounts, configuring the platform, or entering data into the system. This includes names, email addresses, job titles, and login credentials. Our platform also processes protected health information (PHI) on behalf of our facility customers as a HIPAA Business Associate.
We automatically collect certain technical information including IP addresses, browser type, device information, and usage logs to operate and improve the platform.
We use Plaid to enable facility operators to connect their financial accounts. When you connect a bank account through Plaid, Plaid collects and transmits your financial data directly to Kondaro in accordance with Plaid’s own Privacy Policy at plaid.com/legal.
We use collected information to provide, maintain, and improve the Kondaro platform, authenticate users and enforce access controls, respond to support requests, comply with legal obligations, and display financial data including account balances and transaction history within the platform dashboard.
We do not sell personal information. We do not use PHI for any purpose other than providing services to the facility that submitted it.
Kondaro operates as a HIPAA Business Associate for its facility customers. We maintain appropriate administrative, physical, and technical safeguards to protect PHI in accordance with the Health Insurance Portability and Accountability Act. We execute Business Associate Agreements with all covered entity customers upon request.
We share information only with service providers necessary to operate the platform:
Where a facility connects its electronic medical record system (e.g., Kipu), Kondaro ingests clinical and financial data from that system to power the platform’s reporting features, subject to the same safeguards described in this policy.
All third-party providers are bound by confidentiality obligations and are prohibited from using your data for their own purposes.
We may disclose information if required by law, court order, or governmental authority.
We implement industry-standard security measures including TLS encryption for all data in transit, encryption at rest, role-based access controls, AWS Identity and Access Management (IAM) and Systems Manager-based controls for infrastructure access, and multi-factor authentication for all administrative and end-user accounts.
We retain account and platform data for the duration of the customer relationship and for a period thereafter as required by applicable law or contract. Customers may request deletion of their data upon termination of service.
Authorized users may access, update, or request deletion of their account information by contacting us at info@kondaro.com. Facility customers may exercise rights regarding PHI in accordance with their Business Associate Agreement.
We may update this Privacy Policy from time to time. We will notify customers of material changes via email or in-platform notice. Continued use of the platform following notice of changes constitutes acceptance.
Kondaro, Inc.
info@kondaro.com
kondaro.com