What we store, how it is protected, who you choose to share it with, and how to take it with you or delete it.
This document is an internal working draft prepared to describe intended practice. It has not been reviewed or approved by a qualified attorney, it is not legal advice, and it does not yet constitute a binding privacy notice or create any commitment by [Legal entity name]. Bracketed values are unresolved placeholders. Nothing here should be relied upon by users, partners, or reviewers until counsel has completed a review and the placeholders have been filled with verified facts.
Effective date: [Effective date]
Controller / operator: [Legal entity name]
Registered address: [Registered address]
Privacy contact: [DPO / privacy contact email]
LicenseBriefcase ("the Service") is a system of record that an individual healthcare professional — a physician, NP, PA, nurse, allied professional, or student — uses to keep their own professional credentials organised: state licenses, DEA registrations, board certifications, education and training, hospital privileges, malpractice coverage, enrolments, and related records and documents.
The record belongs to the provider, not to an employer. When you create an account you are our user directly. An employer, staffing agency, practice group, or credentialing body does not become the owner or controller of your briefcase because you shared something with them, and cannot ask us to hand over, alter, or retain your record on their behalf.
Whatever you choose to put in your briefcase. Depending on how you use the Service this may include credential identifiers (such as license, registration, certificate, and policy numbers), issuing authorities, issue and expiry dates, training and employment history, sanctions and verification history, and uploaded documents such as scans of certificates.
Some of these fields are sensitive by any reasonable measure. You control what you enter; the Service does not require you to fill every field.
[Cookies and analytics — to be completed after an inventory of any tracking used on licensebriefcase.com and in the application. This draft makes no claim either way.]
Credential records are stored encrypted. Sensitive fields are encrypted individually rather than only at the disk level, so the stored representation of an identifier is not readable from the database alone.
We describe our encryption design in general terms only. We do not make representations here about the specific key-custody model pending engineering and legal confirmation, and users should not infer that [Legal entity name] is technically incapable of accessing stored data.
Access to production systems is limited to personnel who need it, and administrative access is logged.
We do not sell your data and we do not share your credential records with employers, recruiters, credentialing organisations, insurers, or anyone else on our own initiative. Sharing happens only when you initiate it.
When you share, the Service issues a one-time link that expires rather than sending your records as an attachment or granting a standing login. These links are minted by onelinktoken, a sibling Peasy Services component used for share links and invitations. The scope of what a link exposes is set when you create it, and links can expire or be revoked. [Link lifetime, single-use behaviour, and revocation semantics — to be confirmed and stated exactly.]
Once you have shared information with a recipient, that recipient has seen it. We cannot retract information from a third party's own records, and what they do with it afterwards is governed by their policies, not ours.
We use a small number of processors to operate the Service:
This list must be complete and accurate at publication and kept current thereafter. Processing locations and international transfer mechanisms: [to be completed].
Paid plans are billed through Stripe. Card details are entered on Stripe's own checkout and are handled by Stripe. We do not receive or store full card numbers. We retain the billing metadata needed to run a subscription — plan, status, and transaction references.
This section describes intent. It is not an assertion of any completed audit, certification, or executed agreement. The Service is designed with healthcare-sector expectations in mind: encryption of sensitive fields, audit logging, least-privilege access, and user-controlled disclosure.
We make no claim in this document that [Legal entity name] holds a SOC 2 report or any other third-party security certification, that it is HIPAA compliant, or that a Business Associate Agreement is available. Any such statement must be substantiated by a completed audit or an executed agreement before it appears anywhere on this site or in a sales conversation.
Credential and licensure records are, in the main, professional and licensure information about you as a practitioner rather than information about patients. We do not ask you to store patient information in the Service and you should not do so. How this data is characterised under applicable health-privacy and data-protection law is a legal question reserved for counsel and is not resolved in this draft.
Request handling timelines and verification steps: [to be completed].
We maintain a process for investigating suspected security incidents and will notify affected users and any authority where we are required to do so. Report a suspected issue via the security route on our Support page.
The Service is for licensed professionals and students in professional training, and is not directed to children. [Minimum age] — to be set.
We will post changes to this policy on this page and update the effective date. Material changes will be communicated to account holders. [Notice period].
Privacy questions: [DPO / privacy contact email]
Postal: [Legal entity name], [Registered address]
General support: licensebriefcase.com/support.html
Reminder: draft pending legal review. Every bracketed value above must be replaced with a verified fact, and every REVIEW comment in the page source resolved, before this page is treated as a published privacy notice.