Privacy Policy
1. Who this policy covers
This policy explains how Clinairo Automation Inc. ("Clinairo", "we", "us") handles information. It covers two different groups of people, and the rules are not the same for each:
- Visitors to this website and prospective clients — the practice owners and staff who contact us, request an audit, or browse clinairo.com.
- Patients of our client practices — individuals whose information passes through Clinairo because their clinic uses our service.
If you are a patient of a clinic that uses Clinairo, your relationship is with that clinic. It decides what information is collected and why. Requests about your own records should go to your clinic in the first instance, and we will support them in responding.
2. Our role under HIPAA
Where a client practice is a Covered Entity under the US Health Insurance Portability and Accountability Act, Clinairo acts as a Business Associate. We process protected health information only on that practice's documented instructions and only as permitted by the Business Associate Agreement in place between us.
Our obligations under that agreement include safeguarding the information, restricting its use to the purposes the practice has authorised, requiring equivalent commitments from any subcontractor that handles it, and reporting security incidents to the practice.
Being a Business Associate describes our legal role. It is not the same as a general claim that every part of our stack is certified. We will tell you exactly which agreements and controls are in place for your configuration, in writing, before you sign anything.
3. Information we collect
From website visitors and prospective clients
- Name, practice name, email address and phone number submitted through our forms
- Practice details you choose to share — practice type, booking software, consultation volume, locations
- Figures you enter into the consult economics calculator. These are submitted only when you press the button to send them, and are stored without your name or contact details attached
- Technical data such as IP address, browser type and pages viewed, used for security and to understand which pages are useful
From client practices in the course of providing the service
- Practice configuration: treatment menu, providers, opening hours, policies, pricing you authorise us to quote
- Patient contact details, appointment records, treatment interest and consultation outcomes
- Conversation content — call recordings and transcripts where the practice has enabled them, and message threads across the channels in use
- Consent records, opt-out status and suppression lists
What we deliberately do not collect
We do not collect clinical notes, diagnoses, medication records or treatment photography. Our service does not require them, and keeping our data footprint small reduces the risk to your patients if anything ever goes wrong.
4. How we use information
- To answer inbound patient contact, schedule and confirm appointments, and send reminders
- To run follow-up and recovery sequences the practice has configured
- To produce reporting on activity and attributed outcomes for the practice
- To provide support, investigate faults and keep the service secure and available
- To communicate with prospective clients who contacted us, and to prepare the audit they requested
- To meet legal, regulatory and contractual obligations
We do not sell personal information. We do not use patient communication data for third-party advertising. We do not use one client's patient data to benefit another client.
5. Who we share it with
We use third-party service providers to operate the platform. Where any of them handles protected health information on our behalf, we put an appropriate agreement in place before that happens.
| Category | Purpose |
|---|---|
| Voice and telephony providers | Answering, routing and recording calls; sending SMS |
| AI model providers | Understanding conversations and drafting responses |
| Hosting and database providers | Running the application and storing records |
| Booking platform integrations | Reading availability and writing bookings, at the capability your platform permits and with your authorisation |
| Payment processor | Taking deposits where your practice has enabled them |
We will provide the current list of subprocessors for your configuration on request. We may also disclose information where required by law, to enforce our agreements, or in connection with a corporate transaction — in which case the receiving party remains bound by equivalent obligations.
6. How long we keep it
For client practices, retention periods are set in your service agreement and can be configured to your requirements. Unless we agree otherwise, we delete or return the data we hold on your behalf when the agreement ends. Enquiry records from prospective clients are kept while we are in contact and for a reasonable period afterwards, then deleted.
7. Security
- Encryption of data in transit and at rest
- Access limited to the people and systems that need it, on a least-privilege basis
- Activity logging and audit trails, exportable for your compliance records
- Segregation of client data, so one practice cannot see another's
- Vendor review before any new provider handles patient data
No system is perfectly secure. If a breach affecting your data occurs, we will notify you in line with the timescales in our agreement and applicable law.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to certain processing, or to complain to a regulator. Patients of a client practice should direct these requests to their clinic, which holds the relationship and decides how information is used. We assist our clients in responding.
If you contacted us as a prospective client, you can ask us to delete your enquiry at any time by emailing us.
9. Messaging and calls
Where a practice uses Clinairo to contact patients, that practice is responsible for having a lawful basis and, where required, consent. Our platform records when and how consent was captured, applies contact-hour limits based on the recipient's time zone, honours opt-outs immediately across every channel, and maintains suppression lists.
Patients can opt out of messages at any time by replying with the stop keyword included in our messages, or by telling the practice directly. Where call recording is enabled, disclosure is configured to meet the consent requirements of the relevant state.
10. Cookies and analytics
Our website uses a small number of cookies to keep the site working and understand which pages are used. You can control cookies through your browser settings. We do not use patient communication data for advertising, and we do not run advertising trackers on pages where patient information is handled.
11. International transfers
Clinairo operates with a distributed team and uses infrastructure providers that may process data outside your country. Where personal information is transferred internationally, we put appropriate safeguards in place and restrict access to those who need it to deliver the service. We will tell you where your data is hosted and processed on request.
12. Children
Our service is not directed at children, and we do not knowingly collect information from anyone under 18 through this website. Where a client practice treats minors, handling of that information is governed by the practice's own policies and our agreement with them.
13. Changes to this policy
We may update this policy as the service develops or the law changes. We will update the date at the top, and for material changes affecting client practices we will give notice under the service agreement.
14. Contact us
Questions about this policy or our data handling can be sent to contact@clinairo.com. If you are a client practice and need documentation for a compliance review, say so and we will send the current package.
This document was prepared for Clinairo's specific service model and should be reviewed by qualified legal counsel in your jurisdiction before you rely on it. Nothing here is legal advice.