Partner FAQ: Data, Privacy & Compliance
Straight answers, including where we don't have one yet. If you're evaluating I'm Alive for your organization, this page exists so you don't have to dig for the honest version.
Is I'm Alive HIPAA compliant?
We're not going to claim that, because there's no such thing as a certifying body that awards a "HIPAA compliant" badge — it's a legal framework an organization operates within for specific data and workflows, not a checkbox a vendor can tick. What we can say plainly: I'm Alive's core product (an individual's daily check-in and their own emergency contacts) is not designed around handling Protected Health Information for a covered entity, and if you're a Medicare-certified home health agency, hospice, or similar HIPAA-covered organization evaluating our org-dashboard feature specifically, we haven't completed a formal business-associate review yet. That's an open item on our side, not a resolved one — we'd rather tell you that directly than paper over it with a compliance claim we can't back up.
Who owns the data — us, the individual user, or I'm Alive?
The individual user owns their own check-in data. For our org/bulk plan, any aggregate dashboard your organization sees is opt-in only — an individual has to actively choose to share their check-in status with your organization's dashboard. We don't default individuals into organizational visibility, and we don't sell user data to third parties.
What does the org dashboard actually show?
Aggregate, opt-in-only status — whether members of your program have checked in, not their location history, health details, or any other personal data beyond check-in status. We're being specific here on purpose: it's not a monitoring or tracking dashboard, and it's not built to replace clinical documentation or care records.
Where is data stored, and does it leave the country?
This is a fair question we don't yet have a public, name-the-exact-region answer for — if data residency (e.g., a specific AWS region) is a requirement for your organization or your regulatory environment, ask us directly before signing anything and we'll give you a straight answer rather than a vague reassurance.
Is I'm Alive GDPR compliant for European partners?
We're not putting a generic "GDPR compliant" banner on this page, because that claim is meaningless without naming a specific lawful basis for each data category. If you're evaluating us from an EU jurisdiction, this is worth a direct conversation before any commitment — including an open question we haven't resolved internally yet: whether we need to designate a formal GDPR Article 27 EU representative.
Can we see a case study or reference customer before committing?
Not yet, honestly — we haven't run a real organizational pilot to completion, so we don't have a case study to show you, and we're not going to invent one. The zero-commitment pilot program exists specifically so you can become that first reference rather than take our word for a track record we don't have yet.
What's the bulk/org pricing?
We don't have a published bulk-discount percentage yet — that number needs internal sign-off before we quote it publicly, so we're not going to guess at one here. If you're evaluating an org or bulk plan, reach out directly and we'll work through real numbers with you rather than publish a placeholder figure that might change.
Are you a preferred partner of NAHB, Age Safe, or similar certifying bodies?
No — not yet, and we won't claim otherwise. Pursuing a relationship like NAHB's CAPS program is something we're genuinely interested in, but it isn't secured, so we're stating that as an aspiration, not a fact.
Have a question not answered here?
Ask us directly — especially if it's about compliance, data residency, or pricing. We'd rather answer honestly than have you guess.
Contact usOr email us directly at support@imalive.co