Legal
Privacy Policy
Effective Date: March 1, 2026 | Last Updated: March 1, 2026
1. Introduction
Pathly CRM ("Company," "we," "us," or "our") operates a cloud-based sales and marketing platform designed for senior living communities. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information collected through our website at pathlycrm.com, our software platform, and sales and marketing interactions.
2. Information We Collect
A. Information You Provide
We collect information such as:
- Name
- Company name
- Job title
- Email address
- Phone number
- Billing information
- Account credentials
- Information entered into the platform
B. Client Data (Customer Data)
Clients may upload data relating to prospects, residents, families, and contacts, which may include names and contact details, communication history, move-in preferences, and limited care-related notes.
Data Controller: Clients are the Data Controllers. Data Processor: Pathly CRM acts as a Data Processor/Service Provider. Clients are responsible for lawful collection and consent.
C. Automatically Collected Information
We collect IP address, browser type, device information, usage data, and cookies and tracking technologies.
3. How We Use Information
We use personal information to:
- Provide and improve our Services
- Manage accounts and billing
- Provide customer support
- Ensure platform security
- Comply with legal obligations
- Communicate product updates
We do not sell personal information.
4. SMS & Text Messaging Compliance (TCPA)
Pathly CRM enables Clients to send SMS communications. Clients represent and warrant that they have obtained proper prior express consent, comply with the Telephone Consumer Protection Act (TCPA), maintain consent records, honor opt-outs immediately, and include opt-out instructions ("Reply STOP to unsubscribe"). Pathly CRM does not obtain consent on behalf of Clients. Client agrees to indemnify Pathly CRM against SMS-related claims.
5. Email Marketing (CAN-SPAM)
Clients using the platform for email communications must provide accurate sender information, avoid misleading subject lines, include a physical mailing address, provide clear opt-out mechanisms, and honor opt-outs promptly. Pathly CRM provides tools but does not monitor content for legal compliance.
6. HIPAA
If Services involve Protected Health Information (PHI), a Business Associate Agreement (BAA) will be executed where required. Pathly CRM implements safeguards aligned with HIPAA standards. Clients are responsible for determining whether HIPAA applies.
7. SOC 2 Security
Pathly CRM follows security controls aligned with SOC 2 principles but is not currently certified.
8. Data Security
We implement SSL/TLS encryption, role-based access control, secure cloud infrastructure, regular system monitoring, and daily backups. No system is 100% secure.
9. Data Retention
We retain data for the duration of the client contract, as required by law, and as necessary for legitimate business purposes. Upon termination, data export may be available for a limited period.
10. California Privacy Rights (CCPA/CPRA Addendum)
If you are a California resident, you may request access to collected personal information, deletion, correction, disclosure of categories collected, and information about data sharing. We do not sell personal information. Requests: support@pathly.care. We will not discriminate against individuals exercising rights.
11. International Transfers
If data is transferred internationally, appropriate safeguards such as Standard Contractual Clauses may be used.
12. Children's Privacy
Our Services are not directed to individuals under 18.
13. Changes to This Policy
We may update this Privacy Policy. Updates will be posted with a revised date.
14. Contact Information
Pathly CRM
Bentley Ventures LLC dba Pathly CRM
12650 W 64th Ave E114, Arvada, CO 80004
Email: support@pathly.care
Phone: (720) 780-9396
