Legal
Privacy policy
Last updated 26 July 2026. Written to be read, not to be survived.
The short version
MedAligna is workforce software. We hold information about the people who work at your organization (their names, roles, licenses, shifts and hours) because that is what a schedule is made of. We do not hold information about your patients.
We do not sell your data. We do not share it with advertisers. We do not use it to train models for anybody else. You can export everything and you can ask us to delete it.
Who is responsible for what
Your organization decides what staff information goes into MedAligna and why. In data-protection language, your organization is the controller and MedAligna is the processor: we handle the data on your instructions, for the purpose of running your schedule.
If you are a member of staff and you want your information corrected or removed, your employer is the right first port of call, though you can always contact us directly and we will help.
What we collect
Account and organization details: your name, work email, role, and the organization you belong to.
Staff records: names, contact details, employment type, positions, skills, contracted hours, pay or bill rates where you enter them, and home location.
Credentials: licenses, certifications, screening results and their expiry dates, along with any documents uploaded. Credential documents belong to the individual who uploaded them and are stored in a private bucket, reachable only through short-lived signed links.
Schedules and time: shifts, assignments, swaps, time-off requests, clock-in and clock-out records, and, where your organization enables geofenced clock-in, the location captured at the moment of clocking in or out, and at no other time.
Client records, for home care organizations only: a client's name and address, held so that visits can be scheduled. This is the one category of information in MedAligna that constitutes protected health information, and it is treated accordingly, including a separate access log that records every read, not merely every change.
Technical data: log records, IP address, browser and device information, and error reports, used to keep the service running and secure.
Website and product analytics, measured by us rather than by anybody else: the pages and screens you viewed and their full web addresses, how long you spent reading each one, the address of the site you arrived from, your IP address, your browser's user-agent string, and your country, device and browser. No analytics company receives any of it, because we do not use one, and we do not sell it or share it for advertising.
How long, and how it is linked: these records are kept for as long as they are useful to us, and they are linked over time. When you first arrive we store a cookie on your device containing a random identifier, which lasts two years, and we use it to recognise later visits as the same browser — including when your IP address changes, as it does when a phone moves between wifi and mobile data. If your browser refuses the cookie we fall back to combining your IP address and browser into an identifier instead. That is a change from how this site used to work, and it is the reason this paragraph exists rather than an assurance that it does not happen.
Inside the signed-in application, the same measurement records which screens were opened and certain product events — for example that an assignment was refused by a scheduling rule, which rule codes refused it, that a sign-in failed, or that an error page was shown — linked to your account and organization. What it deliberately never records is the content of your work: no staff names, no schedule details, no credential information and nothing you type reaches the analytics, and the changes you make in the product remain recorded only in the audit log your own employer can see. We use these measurements to find where the product fails or confuses people, and for nothing else. This paragraph used to say the signed-in application was not measured at all; that changed in August 2026, and this page changed with it.
How to opt out: open medicalstaffscheduling.com/api/collect/optout in your browser. Nothing further from that browser will be recorded, and the identifier described above is deleted from your device. It sets a single cookie to remember the choice, and it takes effect immediately. You can also write to us and we will remove what we hold about you.
What we don't collect
No patient names, diagnoses, charts, notes, or medical records. MedAligna schedules staff, not patients. Aggregate census counts ('eighteen patients on this unit tonight') identify nobody, and are used only to compute staffing ratios.
We do not run background checks or order consumer reports. Where a background check appears in MedAligna, it is a result your organization obtained from its own provider and recorded here.
Who can see it
Tenant isolation is enforced at the database level, not by application code. One organization cannot see another organization's data, and a query that omits its filter returns nothing rather than everything.
Inside an organization, access is by role. Owners, admins and schedulers can see staff records and credentials because credentialing is their job. Ordinary staff members see their own information and the shifts of colleagues they work alongside, not their colleagues' license numbers or documents.
Every change to a schedule, credential, membership or time record is written to an append-only audit log that nobody, including us and including your account owner, can edit or delete.
Sub-processors
We use a small number of vendors to run the service: a database and file-storage provider, an application host, and an email provider for transactional messages. Each of them processes data only to deliver their part of the service.
Ask us for the current list and we will send it to you in writing.
How long we keep it
For as long as your organization has an account with us, plus a limited period afterwards so that a cancelled account can be reinstated and so that payroll and audit records survive the year they relate to.
Cancelling does not delete. A lapsed or cancelled account becomes read-only: you keep everything, and you can export it. If you want it deleted, ask us and we will delete it.
Getting your data out, or deleted
Export: staff, schedules, credentials and hours export to CSV or JSON from inside the application, at any time, including after cancellation. This is a product feature, not a favor.
Deletion: write to us and we will delete your organization's data. Note that entries in the audit log survive the deletion of the person they refer to: the actor is forgotten, but the record that something happened remains, because an audit log that can be erased by the people it audits is not an audit log.
Security
Traffic is encrypted in transit; data is encrypted at rest by our database provider. Uploaded documents live in a private bucket and are reachable only through short-lived signed links. Sessions expire. Access is role-based and enforced in the database.
The controls are described in more detail, and in checkable terms, on our security page.
Contact
Questions, requests, or a security questionnaire: hello@medicalstaffscheduling.com. A person answers, in writing.