For organizational buyers

Privacy answers before procurement.

A plain-language overview of user control, consent, organizational access, aggregate reporting, and the documents teams should review before adopting Umbrella.

The operating boundaries

What users control

Users decide what they write and whether to create or share a selected export or summary.

What organizations see

Organizational reporting is designed around aggregate adoption and engagement trends, not raw personal journal content.

What teams must define

Agree on consent, access, retention, deletion, escalation, integrations, and the exact reporting configuration before launch.

Questions for your review

Do not infer a certification: this page does not claim HIPAA, PHIPA, GDPR, SOC 2, or any other compliance status. Confirm the requirements and contractual terms for your specific program.

Documentation to start with

For broader risk-management context, organizations can also consult the voluntary NIST Privacy Framework and NIST Cybersecurity Framework.

Bring your review questions.

We can point you to the relevant product and legal documentation for your intended workflow.

Contact Umbrella

Information on this page is general and may change as the product, contracts, and applicable requirements evolve.