Settings → Legal documents
Purpose
A signed-in-only library of the four subscriber / account-holder legal documents that govern how your practice uses CS Logbook. Unlike the public Terms of Service, Privacy Policy, and Cookie Policy (available to anyone on the marketing site), these four are only visible to logged-in account holders.
Note: These documents are the live, owner-approved in-app copy. As of this writing they are pending external counsel review — treat them as the operative terms of your subscription, not as legal advice.
When to use it
- Onboarding a practice: review how regulatory responsibility and data handling are allocated before you rely on CS Logbook
- Procurement / vendor review: your compliance or legal team wants the DPA, subprocessor list, and MSA
- Answering "who's responsible for DEA compliance?": the DEA Registrant Responsibility Acknowledgment is the canonical answer
Walkthrough
Step 1 — Open the legal documents index
Navigate to /home/legal-documents. You'll see a list of the four documents, each with a one-line summary and an effective date. Click any entry to read the full document (/home/legal-documents/<slug>).
Step 2 — The four documents
| Document | What it covers |
|---|---|
| Data Processing Addendum (DPA) | How Gleason Digital LLC processes personal information as your service provider under the CCPA/CPRA. Roles, categories of data, service-provider obligations, security, retention. |
| Subprocessors | The third-party services used to run CS Logbook Online (Supabase, Stripe, Resend) and what each may process, plus self-hosted services (Umami analytics, GlitchTip errors) that are not subprocessors. |
| DEA Registrant Responsibility Acknowledgment | Confirms that the DEA registration and all controlled-substance obligations belong to the individual veterinarian registrant and the practice — not to CS Logbook. Warnings are advisory; use is not a guarantee of compliance. |
| Subscriber / Master Services Agreement (MSA) | Terms for practices contracting under a written order or enterprise plan — services, subscription-required access gating, fees, data ownership/export, offboarding, warranties, liability. |
Step 3 — DEA acknowledgment (prescribing vets)
Prescribing veterinarians are prompted once, during onboarding, to acknowledge the DEA Registrant Responsibility Acknowledgment via a click-through nudge (see Getting started → Onboarding wizard). You can always re-read the full document here.
Key points these documents establish
- HIPAA does not apply. Veterinary records are not PHI and veterinarians are not covered entities; the privacy framework is CCPA/CPRA and state consumer-privacy law (ADR-007).
- DEA responsibility rests with the registrant and the practice, not the software — CS Logbook is a recordkeeping tool you control and it submits nothing to the DEA, a state board, or a state prescription-monitoring program on your behalf.
- Compliance warnings are advisory, never blocking (ADR-006).
- Regulated records are retained, not deleted on demand, and offboarding is by subscription cancellation with an export window (ADR-019).
- An active subscription is required for functional (create/edit) features — a billing condition, not a compliance block (ADR-021).
Related
- Privacy requests — submit a CCPA access/deletion request
- Settings → Billing — subscription that gates functional access (per the MSA)
- DEA Compliance → Registration overview — the registrant-responsibility principle in practice