Effective Date: July 10, 2025
Last Updated: July 10, 2025
Introduction
Purple Possibilities, LLC (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or engage with us for:
• Applied Behavior Analysis (ABA) Services – Evidence-based therapy for individuals with autism and developmental disabilities
• Special Education Evaluations & Advocacy (Non-ABA) – Independent educational evaluations, IEP support, and educational advocacy
• Educational Consulting & Training (Non-ABA) – Strategic consulting and training for educational organizations and professionals
Information We Collect
Personal Information
We may collect personal information that you voluntarily provide to us when you:
• Contact us for ABA therapy services
• Request special education evaluations or advocacy support
• Inquire about educational consulting and training services
• Schedule initial consultations or assessments
• Subscribe to our newsletter or communications
• Fill out contact forms on our website
• Request information about our services
This information may include:
• Name and contact information (email, phone, address)
• Student or child’s information (for ABA services and evaluations)
• Educational background and needs assessment
• Current service providers and support team information
• Insurance information (for ABA services)
• Assessment and evaluation data
• Communication preferences
Educational Records and Data
In our role as an ABA provider, educational evaluator, and consultant, we may have access to or collect:
• ABA Therapy Services:
✹ Behavioral assessment data (FBA, VB-MAPP, PEAK)
✹ Treatment plans and progress data
✹ Family training records
✹ Therapy session notes and data collection
• Special Education Services (Non-ABA):
✹ Independent educational evaluation results
✹ IEP and 504 plan documentation
✹ Academic assessment data
✹ Educational advocacy records
• Educational Consulting (Non-ABA):
✹ Organizational assessment data
✹ Training participation records
✹ Curriculum development materials
✹ Professional development documentation
Protected Health Information (PHI)
When providing ABA therapy services, we may encounter Protected Health Information as defined under HIPAA. We maintain strict protocols for handling any PHI in accordance with federal regulations.
Important Note: Our special education evaluation and advocacy services, as well as educational consulting and training services, are non-ABA services and are not considered Applied Behavior Analysis.
Automatically Collected Information
When you visit our website, we may automatically collect:
• IP address and browser information
• Device and operating system details
• Pages visited and time spent on our site
• Referring website information
• Cookies and similar tracking technologies
SMS and Communication Information
When you provide your mobile number and opt into SMS communications, we may collect:
• Mobile phone numbers
• SMS consent status and preferences
• Message delivery confirmations
• Response data (STOP, HELP requests)
We use mobile information to:
• Send appointment reminders and confirmations
• Provide service updates and important notifications
• Share educational resources (with your consent)
• Deliver time-sensitive information about your services
SMS Rights:
• Reply STOP to opt out of all messages
• Reply HELP for customer support
• Message frequency varies by service type
• Standard message and data rates apply
• We do not charge for our messages, but your carrier may
How We Use Your Information
We use the information we collect to:
• ABA Therapy Services:
✹ Provide comprehensive behavioral assessments and therapy
✹ Develop individualized treatment plans
✹ Monitor progress and adjust interventions
✹ Coordinate with families and school teams
• Special Education Services (Non-ABA):
✹ Conduct independent educational evaluations
✹ Provide IEP and 504 plan support
✹ Offer educational advocacy services
✹ Facilitate school meetings and consultations
• Educational Consulting & Training (Non-ABA):
✹ Provide organizational consulting services
✹ Develop and deliver professional training
✹ Support curriculum development
✹ Facilitate strategic planning initiatives
• General Business Operations:
✹ Process payments and manage invoices
✹ Schedule appointments and consultations
✹ Communicate about services and updates
✹ Send newsletters and educational resources (with consent)
✹ Provide customer support
✹ Improve our services and website functionality
✹ Comply with legal obligations
Educational Data Use
Educational records and data are used exclusively for:
• ABA Services: Developing and implementing behavioral interventions based on comprehensive assessments
• Special Education Services (Non-ABA): Conducting independent evaluations and providing advocacy support
• Educational Consulting (Non-ABA): Providing strategic recommendations and professional development
• Ensuring compliance with educational standards and regulations • Supporting evidence-based practice improvements
All educational data use complies with applicable federal and state educational privacy laws, including FERPA, institutional policies, and contractual agreements.
Information Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal information to third parties except in the following circumstances:
Service Providers
We may share information with trusted third-party service providers who assist us in:
• Payment processing
• Website hosting and maintenance
• Email marketing services
• Secure data storage and backup
• Legal and accounting services
• Practice management software
These providers are contractually obligated to protect your information and use it only for the specified services.
Legal Requirements
We may disclose your information when required by law, court order, or government regulation, or when we believe disclosure is necessary to:
• Protect our rights or property
• Ensure user safety
• Investigate potential violations
• Comply with legal processes
SMS and Communication Service Providers
We may share mobile phone numbers and communication preferences with trusted SMS service providers who help us deliver text messages, two-factor authentication, and customer notifications. These providers are contractually obligated to protect your information.
Educational Institutions and Partners
We may share de-identified or aggregate educational data with:
• Educational institutions we are contracted to evaluate or consult with • Research partners for educational improvement initiatives
• Accreditation bodies when required for compliance purposes
• Funding organizations for grant reporting requirements
All sharing of educational data is done in compliance with FERPA, institutional policies, and contractual agreements.
HIPAA-Covered Entities
When working with healthcare education programs or HIPAA-covered entities, we may share information only as permitted under Business Associate Agreements and HIPAA regulations.
Business Transfers
In the event of a merger, acquisition, or sale of our business, your information may be transferred to the new entity, subject to the same privacy protections and applicable educational privacy laws.
Educational Privacy Compliance
FERPA Compliance
Purple Possibilities recognizes and complies with the Family Educational Rights and Privacy Act (FERPA) when handling educational records. We:
• Access educational records only when authorized by the educational institution • Use educational records solely for the purposes specified in our service agreements • Maintain the confidentiality of personally identifiable information from education
records • Do not re-disclose educational records without proper authorization • Destroy or return educational records when no longer needed for authorized purposes
• Train our personnel on FERPA requirements and confidentiality obligations Student Privacy Protection
When working with student data, we:
• Minimize data collection to what is necessary for our authorized services • Use de-identified or aggregate data whenever possible
• Implement additional security measures for any personally identifiable student information
• Ensure compliance with state student privacy laws
• Obtain appropriate consents when required
HIPAA Compliance
When providing services to healthcare education programs or entities covered under HIPAA, we:
• Execute Business Associate Agreements (BAAs) when required
• Implement HIPAA-compliant safeguards for Protected Health Information (PHI)
• Limit access to PHI to authorized personnel only
• Report any suspected breaches in accordance with HIPAA requirements • Provide additional training on HIPAA compliance to relevant staff
• Maintain audit logs for PHI access and use
Institutional Agreements
Our privacy practices may be further governed by:
• Institutional Review Board (IRB) protocols
• Data Use Agreements with educational institutions
• Confidentiality agreements with research partners
• Professional ethics codes and standards
• Accreditation body requirements
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
• Secure data transmission (SSL encryption)
• Regular security assessments
• Limited access controls
• Secure payment processing through Stripe
• Regular data backups
• Firewall protection
However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Data Retention
We retain your personal information only as long as necessary to:
• Fulfill the purposes outlined in this Privacy Policy
• Comply with legal obligations and educational regulations
• Resolve disputes and enforce agreements
• Maintain business records as required
• Meet institutional and accreditation requirements
SMS Data Retention:
SMS-related information (phone numbers, message logs, opt-in records) is retained for: • The duration of your consent to receive SMS communications
• Legal compliance requirements
• Customer service and support purposes
• As long as necessary to honor opt-out requests
Educational Data Retention:
Educational records and data are retained according to:
• FERPA requirements and institutional policies
• Service agreement specifications
• Accreditation and compliance needs
• Research protocol requirements
• Legal and regulatory obligations
Typically, educational data is retained for the duration of our service engagement plus any required retention period, after which it is securely destroyed or returned to the educational institution as specified in our agreements.
Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
Access and Correction
You can request access to your personal information and ask us to correct any inaccuracies.
Data Portability
You may request a copy of your personal information in a portable format. Deletion
You can request that we delete your personal information, subject to certain legal limitations.
Opt-Out
You can unsubscribe from marketing communications at any time by:
• Clicking the unsubscribe link in emails
• Replying STOP to any SMS message
• Contacting us directly
• Updating your communication preferences
SMS Communication Rights
For SMS communications, you have the right to:
• Opt out by replying STOP to any message
• Get help by replying HELP to any message
• Update your mobile number by contacting us
• Withdraw consent for SMS communications at any time
Educational Rights
If you are affiliated with an educational institution that contracts with us, you may have additional rights under FERPA, including:
• The right to inspect and review educational records
• The right to request amendment of inaccurate records
• The right to request confidential communications
• The right to file complaints with the U.S. Department of Education
These rights are typically exercised through your educational institution rather than directly with us.
Children’s Privacy
Our services are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will promptly delete it.
International Data Transfers
If you are located outside the United States, please note that your information may be transferred to and processed in the United States, where our servers and service providers are located. By using our services, you consent to this transfer.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
• Posting the updated policy on our website
• Sending an email notification (if you have provided your email address) • Updating the “Last Updated” date at the top of this policy
Breach Notification
In the event of a data breach involving personal information, educational records, or Protected Health Information, we will:
• Immediately assess the scope and impact of the breach
• Take steps to contain and mitigate the breach
• Notify affected individuals and institutions as required by law
• Report breaches to appropriate regulatory authorities (Department of Education for FERPA violations, HHS for HIPAA violations)
• Cooperate with investigations and implement corrective measures • Review and strengthen security measures to prevent future incidents
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Purple Possibilities, LLC
Email: grow@purplepossibilities.com
Website: purplepossibilities.com
Address: 2102 Roosevelt Dr, Suite E
Dalworthington Gardens, TX 76013
For specific privacy-related requests, please include “Privacy Request” in the subject line of your email.
Educational Privacy Concerns
For questions specifically related to educational record privacy or FERPA compliance, please contact us with “Educational Privacy” in the subject line.
Health Information Privacy
For questions related to Protected Health Information or HIPAA compliance, please contact us with “Health Privacy” in the subject line.
Regulatory Contacts
• For FERPA concerns: Family Policy Compliance Office, U.S. Department of Education
• For HIPAA concerns: Office for Civil Rights, U.S. Department of Health and Human Services
This Privacy Policy was last updated on 07-10-2025 and is effective as of 07-10-2025.
