Skip to document

Provider open beta

Whistle Provider Agreement

Agreement version provider-open-beta-2026-07-15-v1 · Open-beta copy updated July 15, 2026

Agreement and access

These responsibilities supplement the Whistle Terms of Use and apply to each speech-language pathologist, practice, and other provider who creates an account while Whistle's open beta is enabled or is later approved for commercial Professional access. Public open-beta signup does not require payment and grants product-discovery access only to the authenticated provider account. It is not an active Professional subscription, final legal review, or commercial provider approval. Commercial authority still exists only while Whistle maintains the required active approval record for that account, including the current agreement and no-PHI and no-school-record attestations. Whistle may suspend either lane in its reasonable discretion.

Limited service and clinical responsibility

Whistle supplies parent-controlled home-practice activities, adherence information, scored speaking time, assigned targets, and automated nonclinical practice signals. Signals may be inaccurate and are not clinically validated assessments. Whistle does not diagnose, establish a plan of care, determine eligibility, replace treatment, create a legally required clinical record, or make an automated professional decision. The provider remains solely responsible for licensure, competence, assessment, treatment, instructions, goals, documentation, interpretation, supervision, family communication, and compliance with professional standards.

Parent-controlled consent and linking

A provider may create only a generic, one-time, expiring linking code that contains no child data. The provider must not create a reader, private label, target, or link, and provider assurance is not a substitute for the parent's authority. An authenticated parent or legal guardian creates each reader only after reviewing the direct notice and separately affirming guardian authority and the disclosed Azure audio processing. The parent must then select that exact active reader and separately authorize the provider link. Provider signup, possession of a code, or a provider assertion alone grants no reader access. The parent may remove provider access or withdraw consent at any time.

No PHI, school records, or direct identifiers

The open build beta is not authorized for protected health information, education records, clinical notes, medical or insurance records, institutional patient or student identifiers, child legal names or initials, birthdates, addresses, child contact details, school or classroom names, diagnoses, recordings uploaded through support, or any other direct identifier. Use only the post-consent quest alias and structured minimum-necessary controls. The provider must not attempt to re-identify a reader, combine Whistle data with institutional identifiers inside Whistle, or use Whistle until any required BAA, school data agreement, parental authorization, procurement review, or institutional approval is separately executed. This Agreement is not a BAA, FERPA agreement, or institutional data-processing addendum.

Access control and personnel

The provider must use an individual account, strong unique credentials, supported devices, reasonable endpoint security, and only personnel with a need to know. Credentials and exports may not be shared through a group login, unsecured message, public link, or consumer file-sharing account. The provider must promptly remove departed personnel, review its caseload and family links, and notify Whistle of suspected credential compromise, incorrect access, or unauthorized information. Whistle may require multi-factor authentication, access review, or other safeguards before enabling or continuing open-beta access.

Permitted use and reports

Provider access is limited to supporting the linked family's authorized practice, setting appropriate structured targets, configuring the parent view, reviewing practice activity, and exporting a report for a lawful professional purpose. The provider must review every signal and export before relying on or sharing it, preserve any legally required professional record outside Whistle under the provider's own compliant system, avoid adding identifiers to filenames or downstream notes, and accurately communicate Whistle's limitations. Whistle data may not be used for emergency decisions, diagnosis, eligibility, adverse action, surveillance, advertising, model training, or sale.

Incidents and prohibited-data response

The provider must notify Whistle through the authenticated support path without undue delay and no later than twenty-four hours after discovering suspected unauthorized access, wrong-family or wrong-provider linkage, credential compromise, prohibited information, an exposed export, or another security or privacy event involving Whistle. The notice must avoid unnecessary child content and state the account, event category, timing, and containment taken. The provider must preserve relevant evidence, cooperate with containment and legally required notices, delete unauthorized copies, and not notify a child or regulator on Whistle's behalf unless law requires or Whistle authorizes it.

Suspension, revocation, and data disposition

Whistle may immediately suspend or revoke provider functionality for prohibited data, unauthorized access, misleading clinical use, nonpayment, agreement breach, security risk, or legal uncertainty. Revocation blocks future provider access and linking-code creation. Family-owned reader data remains under the parent's controls; a provider link does not create indefinite retention or a provider veto over deletion. Provider-specific links, labels, and targets are removed under the Retention and Deletion Policy, subject only to a narrow documented legal or security hold.

Provider warranties

The provider represents and warrants that it has authority to enter this Agreement; maintains required licensure, insurance, and institutional authorization; will comply with applicable professional, privacy, consumer, child, and records laws; will not submit prohibited data; will make accurate statements to families; and will use Whistle only within the open beta or an approved commercial lane. The provider must maintain commercially reasonable professional liability, cyber/privacy, and technology or general liability coverage appropriate to its activities and provide evidence upon reasonable request.

Provider indemnity

The provider will defend, indemnify, and hold harmless Whistle and its owners, officers, personnel, and agents from third-party claims, regulatory investigations or proceedings, damages, penalties, judgments, settlements, and reasonable attorney fees and costs arising from the provider's professional services or decisions; lack of authority, consent, or institutional approval; prohibited or identifying data; misuse or misrepresentation of scores, reports, or outputs; insecure downstream storage or disclosure; violation of law or institutional policy; or breach of this Agreement. The provider will reimburse reasonable documented investigation, containment, notification, restoration, remediation, and processor costs to the extent directly caused by its breach. Whistle will give reasonably prompt notice; delay excuses the provider only to the extent materially prejudiced. The provider may control the defense with qualified counsel reasonably acceptable to Whistle, and Whistle may participate at its own cost. Whistle may control a defense involving conflicting interests, potential criminal liability, a regulator, injunctive relief affecting the service, or material privacy or security obligations. The provider may not settle a matter that admits Whistle fault, imposes nonmonetary obligations on Whistle, affects child or personal information, or fails to release Whistle without written consent, and may not speak for Whistle. This duty does not apply to the extent a final determination attributes the matter to Whistle's fraud, breach of its express privacy or security commitments, gross negligence, willful misconduct, or an obligation applicable law does not permit Whistle to transfer.

Limited Whistle intellectual-property indemnity

Whistle will defend an approved provider from a third-party claim that the unmodified Whistle service, when used exactly as authorized, infringes a United States patent, copyright, or trademark. Whistle may modify or replace the affected feature or terminate access and refund prepaid unused fees. This obligation does not apply to provider data or instructions, combinations, modifications, continued use after notice, or use outside the approved scope. The same notice, defense-control, cooperation, and settlement procedures apply. This section states Whistle's complete obligation for intellectual-property claims to the extent permitted by law.

Provider disputes

The Federal Arbitration Act governs this section. Subject to nonwaivable law, Oregon law governs this Agreement. Before arbitration, a party must provide individualized notice through the contact method in the Terms and allow thirty days for good-faith resolution. Except for temporary injunctive relief, eligible small-claims matters, and claims that applicable law makes non-arbitrable, a provider dispute will be resolved by binding individual arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules in effect when filed. One arbitrator will hear the dispute in Portland, Oregon or remotely as the parties agree. The arbitrator may protect child, personal, security, confidential, and trade-secret information. The parties share administration and arbitrator fees as the rules provide, subject to reallocation in the award, and bear their own attorney fees unless law or the award provides otherwise. No class, collective, consolidated, coordinated, private-attorney-general, or representative arbitration is authorized to the extent enforceable. A non-arbitrable provider dispute is subject to state or federal courts in Multnomah County, Oregon, and each party waives trial by jury to the extent lawful.

Fees, term, and incorporated terms

Any provider subscription automatically renews and may be cancelled as stated in the Terms and checkout disclosure, but billing never substitutes for commercial approval. Open-beta functionality begins only while the single open-build-beta switch, authenticated provider role, accepted responsibilities, and account access remain current. It ends when any of those conditions ends. Commercial functionality separately requires the durable approval record. Confidentiality, ownership, payment, indemnity, dispute, limitation, and records-disposition provisions survive as their nature requires. The Terms' warranty, liability, Oregon law, informal-resolution, FAA arbitration, individual-action, and venue provisions apply to this Agreement; the AAA Commercial Arbitration Rules apply when the provider acts in a commercial capacity.

Open beta and contact

This page accompanies Whistle's open product-discovery beta. Authenticated adults may create provider beta accounts while the open-build-beta switch remains enabled, without an invitation or payment. That access does not represent a public commercial launch, an active Professional subscription, provider access to any reader, or final commercial or legal signoff. Commercial Professional access and broad public publication remain separate. The public privacy/account form is the intake path. Whistle's final operating entity, physical notice address, monitored email, telephone number, commercial terms, and legal approval remain pending before commercial provider publication; they do not block authenticated open-build-beta use.