Privacy Policy

Effective date: [Effective Date] · Last updated: [Last Updated Date]

1. Who we are and the scope of this policy

Portanus ("the System," "we," "us") is a private, multi-tenant platform operated by Twin Raven Studios, Inc. for service-dog and assistance-animal organizations ("Customer Organizations"). It is used to manage applications, dogs, breeding, placements, donors, payments, volunteers, staff, and related program operations.

For most personal information in the System, the Customer Organization is the controller (it decides what is collected and why) and we act as a processor / service provider that hosts and safeguards the data on their behalf. This policy explains how the System handles personal information generally; a Customer Organization's own privacy notice governs its specific relationship with the individuals it serves.

2. Information the System processes

Depending on a person's role, the System may process:

  • Identity & contact data — name, address, email, phone, emergency contacts.
  • Application & eligibility data — application responses, household and pet information, references.
  • Health & disability information — disability-related and medical details relevant to placement and care, including veterinary records for dogs.
  • Financial data — donations, payments, invoices, and fee/sponsorship records. Card and bank details are handled by our PCI-DSS-compliant payment processors; we do not store full card numbers.
  • Background & verification data — for volunteers and certain roles, where the Customer Organization requires it.
  • Documents — uploaded files such as medical documentation, certifications, and signed agreements.
  • Account & security data — credentials, multi-factor authentication status, roles and permissions, and audit logs of activity.
  • Technical data — limited logs (IP address, timestamps, device/browser) needed for security and reliability.

3. How and why we use information

Information is used solely to provide and protect the service, including to:

  • operate the program workflows the Customer Organization configures (applications, placements, dog care, donations, communications);
  • authenticate users and enforce role-based access;
  • communicate transactional and program messages the Customer Organization sends;
  • maintain security, prevent fraud and abuse, and keep audit trails;
  • meet legal, regulatory, and contractual obligations.

We do not use personal information for advertising, behavioral profiling, or to train external/general-purpose AI models.

4. We never sell or share your data

We do not and will not sell, rent, or trade personal information, and we do not disclose it for cross-context behavioral advertising. We share information only with: (a) the Customer Organization that owns the records and its authorized users; (b) service providers / subprocessors that operate the platform under contract and confidentiality (for example, cloud hosting, email/SMS delivery, payment processing, e-signature); and (c) authorities when required by law or to protect safety, after appropriate review. Subprocessors act only on documented instructions and are bound to equivalent privacy and security obligations.

5. Security program

Protecting sensitive information — including medical, financial, and disability-related data — is a primary design goal. The System is designed and operated to meet the requirements of SOC 2, the HITRUST CSF, and HIPAA. Formal third-party attestation and certification are being pursued; this page will be updated when those reports are available. (Designing to these standards is a commitment to their control requirements; it is distinct from holding a completed audit report, which we will not claim until obtained.)

Technical and organizational safeguards include:

  • Encryption — data encrypted in transit (TLS) and at rest, with sensitive fields additionally encrypted at the application layer.
  • Access control — role-based permissions and least-privilege access; enforced multi-factor authentication for privileged accounts.
  • Tenant isolation — each Customer Organization's data is logically separated (schema-per-tenant) so one organization cannot access another's records.
  • Auditing & monitoring — comprehensive audit logging of create/update/delete and administrative actions, plus security monitoring and error tracking.
  • Secure SDLC — code review, automated testing, dependency vulnerability scanning, and least-privilege infrastructure.
  • Vendor diligence — subprocessors are assessed for security, and Business Associate Agreements (BAAs) are executed where HIPAA applies.

6. Data retention

Records are retained for as long as the Customer Organization needs them to operate its program and to meet legal, tax, and regulatory requirements, then deleted or de-identified. The System uses soft-deletion so records can be recovered from accidental removal; permanent deletion follows the Customer Organization's retention policy.

7. Your rights and choices

Depending on your jurisdiction (for example, under GDPR or U.S. state privacy laws) and the applicable HIPAA rights where relevant, you may have the right to access, correct, delete, restrict, or obtain a copy of your personal information, and to object to certain processing. Because the Customer Organization controls its records, please direct these requests to that organization; we will assist it in responding. We do not use your data in ways that would require selling-opt-outs, because we do not sell data.

8. Breach notification

We maintain an incident-response process. In the event of a security incident affecting personal information, we will notify the affected Customer Organization without undue delay and support breach-notification obligations, including those under HIPAA and applicable state law.

9. Children's information

The System is an operational tool for organizations and is not directed to children. Where a program necessarily involves information about minors, that information is provided and controlled by the Customer Organization and handled with the same safeguards described above.

10. SMS/text messaging and mobile consent

Where the System offers SMS/text messaging (for example, sign-in verification codes, security alerts, and account notifications), we text only individuals who have given express opt-in consent by adding and verifying their mobile number and enabling SMS in their account settings. Consent is recorded (including a timestamp and the disclosure text agreed to) and can be withdrawn at any time by replying STOP to any message or turning off SMS in account settings; reply HELP for help. Message frequency varies, and message and data rates may apply. Consent to receive SMS is never a condition of using the System.

We never share mobile information for marketing. We do not sell, rent, or trade mobile phone numbers or SMS opt-in information, and we do not share mobile opt-in information or consent with any third parties or affiliates for marketing or promotional purposes. Phone numbers are used solely to deliver the account, security, and authentication messages you requested, and are shared only with the SMS-delivery provider that transmits those messages on our behalf under contract. See our SMS/Text Messaging Policy for full details.

11. Changes to this policy

We may update this policy to reflect changes in the System, the law, or our compliance posture. Material changes will be reflected by an updated effective date, and significant changes will be communicated to Customer Organizations.

12. Contact us

Questions about this policy or your information can be directed to [privacy contact email] (or, where your information is held by a Customer Organization, to that organization directly).


This document is provided for transparency and is not legal advice. It should be reviewed and tailored by qualified privacy/compliance counsel before being relied upon, and supplemented with the separate agreements and notices (e.g., HIPAA Notice of Privacy Practices and Business Associate Agreements) that apply to your organization.