Privacy Notice
This notice explains what information the ARK Learning Portal collects, how we use and protect it, and the choices you have. Because ARK provides health and social services under a DCS contract, some information we handle is protected health information ("PHI") and is treated consistent with HIPAA (45 CFR Parts 160 and 164) where applicable.
1. Information we collect
You or your referral source provide: identity details (name, date of birth, contact information); referral details (referring court or agency, case/docket number, assigned program); and account credentials.
Created as you use the Platform: progress records (sessions started/completed, time spent, attendance); assessment results; certificates and compliance reports generated for the court; and technical/security logs (sign-in events, IP address, audit entries).
We practice data minimization — we collect only what the program and the court require.
2. How we use information
- To deliver your court-ordered program and track completion;
- To generate Certificates of Completion and compliance reports for the referring court or agency;
- To verify identity and secure accounts;
- To meet documentation and billing obligations under DCS Contract #94421;
- To maintain the audit trail required for court and contract compliance;
- To communicate with you (for example, access codes and program notices).
We do not sell personal information or use it for advertising.
3. How information is shared
- With your referring court or agency — judges, probation officers, or DCS Family Case Managers connected to your case may view your progress, attendance, and certificate.
- With DCS — as required under the contract, for the programs it funds.
- With service providers — vetted vendors that host or support the Platform under written agreements (including a Business Associate Agreement where they handle PHI): Supabase (database/hosting), SendGrid (email), and any others.
- As required by law — in response to lawful process or to comply with a court order.
Each user sees only the data their role permits; access is enforced at the database level.
4. How we protect information
- Data is encrypted in transit and at rest;
- Access is role-based and least-privilege; each participant's records are isolated from other participants;
- Multi-factor authentication is required for staff and agency accounts [recommended];
- Every access to records is logged in an append-only audit trail;
- Vendors handling PHI operate under a Business Associate Agreement.
5. How long we keep information
We retain records for as long as required by the DCS contract and applicable Indiana and federal law [confirm retention period — commonly [7] years], after which records are securely deleted or de-identified.
6. Your choices and rights
You may request access to or correction of your information, subject to verification and legal limits. Because programs are court-ordered, some records cannot be deleted on request while a legal obligation to retain them exists. To make a request, contact us using the details below. Where HIPAA applies, our Notice of Privacy Practices describes additional rights.
7. Children
Some programs serve minors (for example, Youth Anger Management). For participants under 18, a parent, guardian, or referring agency is involved as appropriate, and information is handled with corresponding care.
8. Changes to this notice
We may update this notice; material changes will be presented at next sign-in with the effective date.
9. Contact
Privacy contact: [privacy@arkhss.com] · ARK Health and Social Services (ARK Suppliers LLC) · Administrator · [mailing address] · 317-794-2939 · admin@arkhss.com