Privacy
This privacy statement covers fenna.tech’s secure upload portal, including the live General Movements Assessment Parent Upload Portal built with the Developmental Disabilities Association (DDA).
fenna.tech is published by Marcus Fan. For privacy questions, email support@fenna.tech.
What the portal is for
The portal helps an organization collect a single file from someone outside the organization through a private, one-time link. Uploaded files are stored in cloud storage the organization owns and controls (for the DDA deployment, that is the clinic’s OneDrive).
Information we handle
Depending on how a deployment is configured, the portal may process:
| Kind of information | Examples | Typical purpose |
|---|---|---|
| Link details | Child or person identifier, expected date / EDC, link expiry | Create and validate a one-time upload link |
| Upload details | Recording date, file name metadata, upload timestamps | Accept the file and name it correctly |
| Uploaded files | Assessment videos or other documents | Deliver the file to the organization’s storage |
| Admin account details | Microsoft account email for allowlisted staff | Sign in to the admin console |
| Operational logs | Errors, delivery status for notification emails | Keep the system working and diagnose issues |
Parents and other uploaders do not create accounts. Opening a link does not require a Microsoft login.
Where files go
Uploaded files are sent to the organization’s connected cloud storage — not to a fenna.tech “vault” that holds your content long term. For the DDA deployment, that destination is the clinic’s OneDrive folder configured in the admin console.
fenna.tech may temporarily process upload data while moving a file to that destination. After a successful transfer, the durable copy lives with the organization.
How long links last
Parent links are temporary and usually single-use. After a successful upload, or after the configured lifetime, the link stops working. Organizations choose those settings in the admin console.
Who can see what
- Uploaders only see the upload page for their own link.
- Allowlisted clinic or organization staff can use the admin console and access files in their own storage.
- fenna.tech may access operational systems as needed to host, maintain, or support the portal, and will not use uploaded clinical content for marketing.
Email notifications
When an upload finishes, the portal may send an email to staff configured by the organization (for example via Azure Communication Services). That message typically includes identifying context and a link into the organization’s storage.
Cookies and sessions
The portal uses short-lived browser cookies or similar session tokens so a valid parent link can open the upload page, and so signed-in staff can use the admin console. These are functional, not advertising cookies.
Third-party services
A typical deployment may rely on:
- Microsoft Entra ID / Microsoft Graph / OneDrive for staff sign-in and file storage
- Redis (for example Upstash) for link and settings data
- An email provider (for example Azure Communication Services) for notifications
- Hosting infrastructure (for example Vercel)
Each provider processes data under its own terms and the organization’s configuration.
Your choices and requests
- Parents / uploaders: contact the clinic or organization that sent you the link, or email support@fenna.tech if you need help reaching them.
- Organizations: manage links, settings, and storage access in the admin console; contact support@fenna.tech for product or hosting questions.
- Access or deletion requests for files already in organizational storage should go to that organization, because those files are under their control.
Changes
We may update this statement as the product evolves. The current version lives in these docs. Material changes will be reflected here.