ClinicAgent

Legal

Privacy Policy

What ClinicAgent collects, why, where it is kept, and who else can see it. Written to be read, not filed away.

Last updated 21 August 2026

Data protection contact: dpo@clinicagent.app.

1. The short version

  • Clinic and patient data is stored in Singapore.
  • We never sell personal data and never use it for advertising.
  • Nothing your clinic or its patients type is used to train AI models.
  • Your clinic decides what is collected in a chat; we hold it on your instructions.
  • You can export or delete your clinic’s data at any time.

2. Who is responsible for what

Under Singapore’s Personal Data Protection Act (PDPA), the clinic using ClinicAgent is the organisation responsible for its patients’ personal data. We act as its data intermediary: we process that data on the clinic’s instructions, for the purpose of running the service, and for nothing else.

For data about the clinic’s own staff and its account with us — names, work emails, billing records, support conversations — we are the responsible organisation, and this policy is our own notice to you.

Where the EU or UK GDPR applies to a clinic’s use of the service, read “data intermediary” as processor and “responsible organisation” as controller.

3. What we collect

From the clinic

  • Account details: name, work email, mobile number, password, role and permissions.
  • Clinic profile: clinic name, address, phone, email, logo, subdomain, timezone and currency.
  • Operating settings: services, prices, session lengths, rooms, practitioners and working hours.
  • Billing: plan, invoices and payment status. Card details go directly to Stripe; we never receive them.

From the clinic’s patients and website visitors

  • What they type in the chat: the conversation, including anything they choose to say about why they want an appointment.
  • Booking details: name, contact details, the service requested, the appointment time, attendance and payment status.
  • Callback requests left when the assistant hands over to a person.

Automatically

  • Technical logs: IP address, browser and device type, pages viewed, timestamps, errors.
  • Product usage: which features an account uses and how often, so we know what to improve.

We ask patients only for what a booking needs. We do not ask for identification numbers, insurance details or medical history, and we ask clinics not to configure the assistant to collect them.

4. Why we use it

  • To run the service: taking bookings, holding the diary, sending confirmations and reminders.
  • To bill for the plan and keep the accounting records we are required to keep.
  • To answer support requests and investigate faults.
  • To keep the service secure — detecting abuse, fraud and unauthorised access.
  • To understand how the product is used in aggregate, so we know what to build next.
  • To send service notices about outages, security and changes to terms. These are not marketing and cannot be turned off while an account is open.

Marketing email is separate, needs your consent, and has an unsubscribe link in every message.

5. The assistant and AI models

The assistant sends the current conversation, plus the clinic’s own settings it needs to answer, to a third-party large language model provider. That provider processes the text to produce a reply and does not retain it for training.

We do not train models on clinic data or patient conversations, and we do not allow our providers to. Transcripts stay in your clinic’s account so you can read what was said; owners can delete them.

6. Who else processes data

We use a small number of service providers, each bound by a contract limiting them to processing on our instructions:

Provider What for Where
Cloud hosting Application and database Singapore
Stripe Card payments and invoicing Singapore, United States
LLM provider Generating assistant replies Singapore, United States
Email delivery Confirmations and service notices Singapore
Error and uptime monitoring Diagnosing faults European Union

We also disclose data where the law requires it, and to professional advisers under a duty of confidence. If the business is ever sold or merged, data moves with it and we will tell account owners first.

We do not sell personal data, and we do not share it with advertising networks or data brokers.

7. Where data is kept

Clinic and patient data is stored in Singapore. Some of the providers above process data outside Singapore, as noted. Where that happens we rely on contractual protections comparable to the PDPA’s transfer requirements, and on standard contractual clauses where GDPR applies.

8. How long we keep it

  • While the account is open: for as long as the clinic needs it. Clinics control their own records and can delete appointments and transcripts at any time.
  • After an account closes: 30 days, then deletion. Ask us and we will delete sooner.
  • Billing and tax records: five years, as Singapore law requires.
  • Technical logs: 90 days.
  • Backups: overwritten within 35 days.

9. Security

  • Encrypted in transit (TLS 1.2+) and at rest.
  • Each clinic’s data is separated by tenant and reachable only through its own subdomain and accounts.
  • Role-based access inside the clinic; least-privilege access for our own staff, granted only when support work needs it and logged.
  • Passkeys and two-factor authentication are available and recommended for owner accounts.
  • Independent penetration testing, and SOC 2 Type II certification.

If a breach affects your data we will notify affected clinics without undue delay and, where required, the PDPC.

10. Your rights

You may ask us to give you a copy of the personal data we hold about you, correct it, delete it, or tell you how it has been used and disclosed in the past year. Write to dpo@clinicagent.app and we will respond within 30 days.

You can withdraw consent to marketing at any time. Withdrawing consent to processing that the service depends on means closing the account.

If you are unhappy with how we have handled a request you may complain to the Personal Data Protection Commission of Singapore, or to your local supervisory authority where GDPR applies.

11. If you are a patient

If you chatted with an assistant or booked an appointment on a clinic’s website, that clinic holds your data and decides how it is used. Contact the clinic first — its name and contact details are in the chat window and on every confirmation email. If you cannot reach them, write to us and we will pass the request on.

12. Cookies

The application uses only cookies it needs: a session cookie to keep you signed in, and a token to protect forms against cross-site request forgery. The chat widget stores a conversation identifier in the visitor’s browser so a chat survives a page reload. No advertising or cross-site tracking cookies, on the marketing site or in the product.

13. Changes to this policy

When this policy changes we update the date above. If a change materially affects how personal data is handled we email account owners at least 30 days before it takes effect.

14. How to reach us

A2Z WEB PTE. LTD., Singapore. Data protection: dpo@clinicagent.app. Anything else: support@clinicagent.app. See also the Terms of Use.