Privacy Policy

Last updated: September 10, 2026

Effective date: September 10, 2026

Thank you for your interest in ABA MTD. We have prepared this Privacy Policy to explain how we collect, use, retain, and share information we obtain through your use of abamtd.com and the ABA MTD application (the "Site"), or when you contact us. It also explains how to opt out of certain communications, request disclosure or deletion of your Personal Information, and exercise your data rights. If you do not agree to this Privacy Policy, please do not use or access the Site.

Data Makes the Difference, LLC, located at 17 Greystone Drive, Mountain Top, Pennsylvania, USA, operates ABA MTD and is the controller of and responsible for your personal data (collectively referred to as "we," "us," or "our"). Our contact information appears at the end of this policy.

Our two roles

ABA MTD does two different things, and which one applies changes how we handle information about you.

As a practice management platform, we process clinical and billing records on behalf of the practice or clinician that holds the account. In that role we act as a service provider and, where applicable, as a HIPAA Business Associate. The practice is the covered entity and controls the record.

As a marketplace, we process the information families and providers give us in order to match them, arrange a consultation, and handle contracts and payment. In that role we act on our own behalf.

ABA MTD is not a clinical provider. We do not deliver behavior-analytic services, and we are not a party to the clinical relationship between a provider and a client.

Information we collect

Account information. When you register we may ask for your name, email address, password, telephone number, professional credentials, and payment details. Practices additionally provide organization details, staff members, roles, and availability.

Provider verification information. To list on the marketplace, providers supply BACB certification details, state licensure, identity documents, and background check authorization.

Learner information. When a learner is added, we collect information entered by an authorized adult, which may include name, date of birth, gender, diagnosis, medications, guardians, and insurance coverage.

Clinical records. The platform stores assessment results, programs and targets, trial-level session data, behavior data, session notes, supervision and co-signature records, treatment plans, progress reports, and discharge summaries.

Insurance and billing information. To check eligibility, request authorization, and bill for services, we process member identifiers, payer details, authorization records, claims, remittances, and related correspondence.

Communications. Messages sent through the platform are encrypted at rest. Telehealth sessions are described separately below.

Traffic Data. We automatically collect information when you visit the Site, including IP address, browser type, pages viewed, and links clicked. We use cookies to keep you signed in and to remember interface preferences.

Use of information

We use account information to create and secure accounts, process purchases, and provide support. We use learner and clinical information to deliver the assessment, data collection, scheduling, supervision, telehealth, and reporting features that the account holder has asked us to provide, and to generate progress reports. We use insurance information to check eligibility, track authorizations, and prepare and submit claims on the practice’s instruction. We use marketplace information to rank and present provider matches, arrange consultations, and administer contracts and payouts. Traffic Data helps us monitor usage, secure the platform, and improve the product.

Information sharing

We do not sell Personal Information. We may share it with trusted service providers who help us operate the platform, and those providers are contractually bound to protect it. We share information with payers, clearinghouses, and financial institutions where that is necessary to carry out a transaction you or your practice has initiated. We may also disclose information in response to lawful requests or to protect our legal rights.

Within a practice, access is controlled by role. Technicians, supervising clinicians, billing staff, and administrators see different parts of a learner record. Where a parent or guardian has been invited to a client portal, they see the records the practice has chosen to share with them.

Service providers

We work with trusted third-party service providers to deliver and support our services. These providers may process Personal Information solely to perform services on our behalf and are contractually required to maintain confidentiality and security. Examples include:

  • Amazon Web Services (AWS) — secure data hosting, file storage, and infrastructure
  • Amazon Bedrock — the AI features described below, inside our own AWS environment
  • Stripe — payment processing and provider payouts
  • LiveKit — telehealth video sessions and, where enabled, session recording
  • Stedi — insurance eligibility, authorization, and claims clearinghouse
  • Checkr — provider background checks
  • Our email delivery provider — transactional email such as verification and reminders
  • Google Calendar — only where a provider chooses to connect their calendar

A complete and current list of our subprocessors is published at trust.datamtd.com and is also available on request.

Telehealth and session recordings

Telehealth sessions run over an encrypted connection. Sessions are not recorded by default. Where a practice enables recording, the recording is initiated by the provider, all participants are shown a recording indicator, and the resulting file is stored encrypted and is accessible only to that practice. Recordings are clinical records of the practice, and the practice is responsible for obtaining any consent required in its jurisdiction before recording.

Data security and compliance

We are committed to protecting your data and to complying with the Health Insurance Portability and Accountability Act (HIPAA). Learner and user data is stored in encrypted databases hosted on Amazon Web Services. We use industry-standard encryption in transit and at rest, message content and sensitive fields are encrypted at the application layer, and access is restricted by role. We maintain HIPAA and SOC 2 compliance with continuous security monitoring.

You can view our current compliance posture and security certifications at trust.datamtd.com.

Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business or assets, information we hold — including Personal Information and learner information — may be reviewed under confidentiality obligations during the transaction and transferred to the successor or acquiring entity as part of it. Any successor will remain bound by the commitments in this Privacy Policy for information transferred, unless and until you are given notice of and, where required, consent to a different policy. Where a Business Associate Agreement, student data privacy agreement, or other written agreement governs specific data, that agreement continues to control, including any requirement to obtain the customer’s consent before the agreement is assigned or transferred.

Your rights

You have the right to opt out of marketing communications, request disclosure or deletion of your Personal Information, and request a copy or transfer of your data. We do not discriminate against individuals for exercising their data rights.

Where information is held on behalf of a practice, the practice controls the record. Direct requests about a learner’s clinical record to the practice that holds the account, or contact us and we will route the request.

Artificial intelligence features

The platform includes optional AI-assisted features that draft goals, targets, narrative sections of reports, and similar supplementary content from clinical data you have already entered. Key points:

  • AI features run on HIPAA-eligible infrastructure operated by Amazon Web Services within our own AWS environment, under a Business Associate Agreement with AWS
  • Assessment scores and related clinical data are sent to that service to generate output. We do not send learner names or contact details as part of an AI request; free-text you submit is sent as written
  • The AI provider does not retain your data to train its own models, and we do not permit any AI provider to use your data for that purpose
  • Data processed through AI features may be used to improve our internal models, subject to your organization's consent
  • Organizations may opt out of model training by contacting info@datamtd.com
  • AI-generated output is a supplementary drafting tool. It does not replace professional clinical judgment, and the clinician remains responsible for anything they review, edit, and sign

De-identified and aggregated data

We may create de-identified and aggregated data from information in the platform, including assessment results. De-identified data has had direct and indirect identifiers removed in accordance with the HIPAA de-identification standard at 45 C.F.R. § 164.514, so that it no longer identifies, and cannot reasonably be used to identify, any individual.

We may use and share de-identified and aggregated data to operate, evaluate, and improve our services, to conduct and publish research on skill development and intervention outcomes, to produce benchmarks and normative reference data, and for other lawful business purposes. We will not attempt to re-identify this data, and we require anyone we share it with to agree not to attempt to re-identify it.

We do not sell identifiable Personal Information or identifiable learner information. Where a Business Associate Agreement, student data privacy agreement, or other written agreement with your organization restricts de-identification or the use of de-identified data, that agreement controls and we will follow it.

Data retention

We retain Personal Information for as long as necessary to fulfill the purposes outlined in this policy unless a longer retention period is required by law. Clinical and billing records are often subject to state retention requirements that run for years after the last date of service, and where those apply we retain the record for the required period. Data deleted by users is removed from active systems within 30 days and purged from backups in accordance with our retention schedules.

Links to other websites

The Site may contain links to other websites with different privacy practices. We are not responsible for the content or privacy practices of those sites and encourage you to review their policies.

Children’s privacy

Our services are designed for use by professionals, organizations, and caregivers — not by children. Accounts may only be created and used by adults, and we do not knowingly collect Personal Information directly from a child.

Our services are, however, used to assess and support children. Information about a learner — which may include name, date of birth, gender, and optionally diagnosis or medications — is entered by an authorized adult, such as a clinician, technician, educator, or parent or guardian, acting under the authority of the organization that holds the account. We process that information on that organization’s behalf as a service provider and, where applicable, as a HIPAA Business Associate or as a school service provider under applicable student data privacy laws. The organization remains responsible for obtaining any parental consent or providing any notice required in its jurisdiction.

Parents and guardians may request access to, correction of, or deletion of a learner’s information by contacting the organization that holds the account, or by contacting us at privacy@datamtd.com.

Security measures

We implement technical and organizational measures to protect your Personal Information from unauthorized access or disclosure. However, due to the nature of the internet, we cannot guarantee absolute security.

Changes to this policy

We may update this Privacy Policy periodically. When we do, we will revise the "Last updated" date above, and each updated version carries an effective date. Your continued use of the Site on or after that effective date means you accept the updated Privacy Policy.

Where a change materially affects how we use or share your information, we will give notice in the application before the effective date and ask you to review and affirmatively accept the updated policy, and we may require that acceptance before you continue to use the affected features. If you do not agree to an updated version, you may stop using the Site and contact us to close your account or request deletion of your information.

An update to this Privacy Policy does not modify a Business Associate Agreement, student data privacy agreement, or other separately signed agreement between your organization and us. Those agreements continue to control and are amended only in accordance with their own terms.

Contact us

For questions or concerns about this Privacy Policy, contact us at privacy@datamtd.com or +1 (570) 550-4013.

Data Makes the Difference, LLC
17 Greystone Drive, Mountain Top, Pennsylvania 18707, USA