Trust & legal
One place for everything legal.
ClearReport stores legally sensitive incident reports for licensed California assisted living facilities. We expose every document an IT team, privacy officer, or compliance reviewer is likely to ask for — directly on this page, no email exchange required for the public docs.
For documents marked “available on request” (MSA), email contact@skdaddle.com and we'll get a signed version to you within two business days.
Public documents
Privacy Policy
DraftWhat we collect, why, with whom we share it, your rights under CCPA/CPRA, and how long we keep it.
Required reading for every customer.
Terms of Service
DraftThe contract governing your use of ClearReport. Billing, AI disclaimer, liability cap, governing law.
Required reading for every customer.
Security Overview
DraftEncryption, access control, audit logging, backups, breach response. The doc your IT team will want.
Hand this to a security reviewer for first-pass evaluation.
Data Processing Addendum (DPA)
DraftHow we process customer personal information on your behalf. CCPA/CPRA service-provider terms, GDPR-compatible language.
Enterprise IT teams and privacy counsel will want this.
Acceptable Use Policy (AUP)
DraftWhat you can't do with ClearReport. Standalone version of the rules summarized in our Terms.
Required for some enterprise procurement reviews.
Subprocessor list
PublicEvery third party that processes customer data on our behalf, what they do, and where they're located.
Updated when subprocessors change. We notify in writing 30 days before any change with access to report content.
Business Associate Agreement (BAA)
DraftNot currently offered. RCFEs are generally not HIPAA covered entities. Published for reference so a compliance reviewer can see the terms we would expect to operate under if we pursue HIPAA readiness.
If you are a covered entity, talk to us before purchasing.
Available on request
Compliance posture
CCPA / CPRA
In scope. We operate as a service provider; consumer-request workflow documented in Privacy Policy.
HIPAA
Not currently offered. RCFEs are generally not HIPAA covered entities, so a BAA is typically not required. If you also operate a skilled-nursing facility and need one, contact us before purchasing.
22 CCR § 87211
Embedded directly into AI prompts and deadline engine. Updated when CDSS publishes revisions.
SOC 2
Type I planned once we cross 25 paying customers or a contractual requirement. Until then, ask us for a walkthrough.
Penetration testing
Not yet performed. We'll commission one prior to enterprise contracts requiring it.
Incident notification SLA
72 hours from confirmed unauthorized access. See Security Overview.
Last reviewed June 9, 2026. We'll mark documents as “active” once a CA SaaS attorney has formally countersigned them; until then, every page on this hub is a first-draft document.
Operated by Skdaddle, Inc. — California assisted living incident reporting.