VIVID CONSENT

Privacy Policy

Effective September 1, 2026 ยท Clarified September 23, 2026

Plain-language summary: Vivid Consent helps service businesses collect, store, and manage client consent and service records. We process information needed to provide the service, secure accounts, maintain records, support privacy and security reviews, and operate the app.

Information we collect

We may process business account information such as email address, business name, selected professions, settings, staff-account information, and subscription or billing status. When a business uses Vivid Consent with a client, the app may process client information entered into a consent form or client file, including name, date of birth, contact details, health disclosures, consent responses, signatures, service information, guardian information when applicable, treatment or visit photos, and related consent documents. If a business chooses to use the optional Photo ID feature for an appropriate recordkeeping purpose, Vivid Consent may also store images of the front and/or back of a client's photo identification.

Security and audit information

Vivid Consent may record security and audit events needed to protect accounts and records, investigate incidents, and help authorized businesses review access to client information. These events may include the account or staff user involved, the client or business record involved, the type of action or access, session information, and the date and time. Audit information is intended for security, privacy, integrity, and accountability purposes rather than ordinary marketing use.

How we use information

We use information to operate and secure Vivid Consent, authenticate users, create and store consent and client records, provide account features, generate consent documents, maintain audit and integrity information, support authorized access reviews, improve reliability, provide support, and meet legal or regulatory obligations that may apply.

Who can access client records

Client records are intended to be accessible only to authorized users of the business account associated with those records. Vivid Consent uses account authentication, business-scoped access controls, private storage for sensitive consent files, treatment photos and optional Photo ID images, owner-PIN protections for sensitive owner actions, and optional authenticator-app two-step verification. If a user enables two-step verification, Vivid requires the verified second factor before that account can access protected business and client data. Photo ID images are not public and are shown through temporary private viewing links.

Public portfolio photos

The optional portfolio is different from private client-record storage: photos intentionally published to a business portfolio are publicly accessible. The business is responsible for ensuring it has appropriate permission or other lawful authority before publishing an identifiable client, treatment, or service photo. Vivid requires a publication confirmation before new portfolio photos are added.

Service providers

Vivid Consent relies on third-party infrastructure providers to host and operate the app, including database, authentication, file-storage, application-hosting, email, website, and payment services where those features are used. Those providers process data as needed to provide their services to Vivid Consent. Vivid reviews provider security, privacy, contractual, data-location, and incident terms as part of its ongoing privacy and security program.

Data retention

Consent, client, audit, and service records may need to be retained for business, professional, insurance, privacy, dispute-resolution, or legal reasons. A business using Vivid Consent is responsible for deciding what information it is appropriate to collect, including whether Photo ID is necessary, and for determining the retention period that applies to its records. Vivid also maintains platform retention rules for security and operational records and may retain information where required for legal, regulatory, security, fraud-prevention, dispute-resolution, or legitimate recordkeeping purposes.

Account deletion

Vivid Consent provides an in-app account-deletion option in Settings. If a user cannot access the app, a public account-deletion request page is also available. When account deletion is completed, account access and account information that is not required to be retained will be removed or de-identified. Some signed consent, transaction, security, audit, or recordkeeping information may be retained where necessary for legitimate legal, regulatory, fraud-prevention, dispute-resolution, privacy-accountability, or recordkeeping purposes.

Account deletion request page

Security

We use technical and organizational safeguards designed for the sensitivity of the information processed, including authenticated access, HTTPS transport, business-scoped authorization, private file storage for sensitive consent artifacts, treatment photos and optional Photo ID images, short-lived signed viewing links for private files, record-integrity protections, audit logging for selected sensitive actions, password-safety checks, and optional authenticator-app two-step verification. No system can guarantee absolute security, and safeguards are reviewed as the service changes.

Security incidents

Vivid maintains an incident-response process for suspected unauthorized access, loss, use, disclosure, alteration, or destruction of personal information. The process includes containment, evidence preservation, scope and risk assessment, corrective action, and notification assessment under applicable law and contractual obligations.

Your choices and rights

Depending on where you live and the role of the business using Vivid, you may have rights to request access, correction, deletion, or restriction of certain personal information. Business users can manage many account details directly in Vivid Consent. Authorized business owners and administrators also have tools that can assist with reviewing recorded access to a client's file. Privacy and support requests can be submitted through Vivid Consent support.

Children and minors

Vivid Consent is intended for use by professional service businesses. It is not directed to children for independent use. When a minor receives a service, the business is responsible for obtaining any parent or guardian involvement required by law or professional rules.

Changes to this policy

We may update or clarify this policy as Vivid Consent changes. The effective or clarification date above will be updated when appropriate.

Contact

Privacy, account, security, and technical questions can be submitted through the Vivid Consent support page.

Vivid Consent Support

Vivid Consent provides software tools for businesses. This policy does not replace any privacy notice or legal obligations that a business using Vivid Consent may independently have, and it is not a representation that Vivid is certified under a particular privacy or health-information law.