Privacy notice
Therapist Credentialing prepares insurance credentialing applications for therapists. What passes through it is the provider's own professional information — name, contact details, license, NPI, practice address, malpractice cover, CAQH details — and the documents the provider uploads. We never ask for and do not want any information about a patient.
Who is responsible
Responsible for this service: Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions about your data: privacy@vitersoft.com or credentialing@vitersoft.com.
What we collect, and why
- Your name, e-mail, practice name and state, and your answers on the order form — to answer the order.
- The intake: license, NPI, taxonomy, practice address and phone, malpractice policy, CAQH ID and attestation date — to prepare and submit your applications.
- What the federal NPPES registry says about your NPI — to check the intake against it.
- The documents you upload (license, malpractice certificate, W-9, anything an insurer asks for) — to send to the insurers. A W-9 carries a taxpayer number: if you have an EIN, use it.
- Your signed authorization: its version, the insurers it names, your typed name and signature, and when.
- Each application's status, dates and our notes.
- Counts of how the site is used: numbers and categories, never a name or a number from your intake.
We do not store IP addresses. No automated decision is made about you: a person reads every intake, and the insurers decide on the applications.
Who receives it
- The insurers you name in your authorization, and CAQH (DataSpring) — your intake and documents, only after you sign, only those insurers.
- CMS NPPES registry — the NPI number you type, and nothing else, to look it up.
- Cloudflare, Inc. (USA) — runs the application.
- Supabase (EU, Frankfurt) — the database and the private file storage. Only our server can read them.
- Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (trading as Brevo) — sends sign-in links, status updates and CAQH reminders. A status update names the insurer and the status; no message carries a license number, an NPI or a document. Brevo puts an invisible image in every letter, so it registers when a letter is opened; we cannot switch it off per message.
- PostHog (EU, Germany) — the usage counts above, without cookies or profiles.
- The person working on your file for us.
We do not sell or share your personal information
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we show no advertising. We use your information only for the credentialing you asked for.
How long
Uploaded documents are deleted automatically 180 days after upload — by then every application has gone in; if an insurer asks again, you upload it again. An account nobody ever signed in to is removed after 30 days. Everything else stays until you delete your account, which you can do yourself in settings at any time: that removes everything at once, and we count each of our tables and the storage afterwards to confirm nothing is left. Applications already with an insurer stay with that insurer. Sign-in links are stored only as a hash and removed within a day of expiring.
Your rights, whichever state you live in
Several states give residents rights over their personal information — California's law, for example, lets residents ask what a business holds, have it deleted or corrected, opt out of its sale or sharing, and limit the use of sensitive information (California Attorney General). We give these rights to everyone, in every state: ask what we hold, have it corrected or deleted (the last you can do yourself in settings), and — though we neither sell nor share — tell us not to. We will not treat you differently for asking. If we refuse a request you may ask us to reconsider, and we answer within 45 days. Write to privacy@vitersoft.com.
Cookies
One: the sign-in cookie, which holds the account and the person and nothing else. The analytics run without cookies and without local storage.