1. Who we are
SmartyClinic is a software platform that helps clinics manage appointments, patients, doctors and WhatsApp conversations, with an AI receptionist that responds on the clinic's behalf. This policy explains what data the platform handles, why, and how it is protected. It applies to clinic accounts using SmartyClinic and to visitors of this website.
2. What we collect
We handle four categories of data:
- Account information — names, email addresses, phone numbers and login credentials of clinic owners, doctors, receptionists and platform administrators.
- Clinic data — clinic details, doctor profiles and schedules, services, knowledge-base content and settings that each clinic adds to its workspace.
- Patient records stored by clinics — patient contact details, family links, appointment and visit history, and notes that a clinic keeps in its workspace. Clinics control this data; we store it on their behalf.
- WhatsApp message content — messages and media exchanged between a clinic and its patients, processed on the clinic's behalf to power the shared inbox and the AI receptionist.
3. How we use data
Data is used to provide the service: running clinic workspaces, delivering and displaying WhatsApp conversations, booking and managing appointments, and generating analytics for the clinic. AI replies are generated from the clinic's own knowledge base and clinic data — the AI receptionist answers on behalf of the clinic, using the information that clinic has chosen to provide. We do not use clinic or patient data for advertising.
4. Data isolation per clinic
Each clinic operates in its own isolated workspace. A clinic's patients, conversations, knowledge base and settings are scoped to that clinic and are not visible to, or used by, any other clinic on the platform. The AI receptionist for a clinic only draws on that clinic's own content.
5. Access control and security
Access inside a workspace is role-based: owners, doctors and receptionists each see only what their role and permissions allow, and clinic owners can grant granular staff permissions. Administrator and clinic accounts can be protected with two-factor authentication (TOTP). We apply reasonable technical and organizational measures to protect data against unauthorized access, loss or misuse.
6. No selling of personal data
We do not sell personal data. We do not share clinic or patient data with third parties except the service providers necessary to operate the platform (such as messaging infrastructure used to deliver WhatsApp messages) or where required by law.
7. Data retention
Data is retained while a clinic's account is active, subject to the storage and history limits of the clinic's subscription plan. When an account is closed, or when data exceeds plan limits, it is deleted or becomes inaccessible in line with the plan's terms. Clinics may request deletion of their workspace data.
8. Clinic responsibilities toward patients
Clinics are the controllers of the patient data they store in SmartyClinic. Each clinic is responsible for having a lawful basis to process its patients' data, for informing patients about how their information is used — including that automated (AI) replies may be used in conversations — and for honoring patient requests regarding their data. SmartyClinic processes this data on the clinic's instructions.
9. Your rights
Account holders may access and correct their account information from their workspace settings. Depending on your jurisdiction, you may have additional rights such as access, correction, deletion or portability of your personal data. Patients should direct requests about their records to their clinic, which controls that data; we support clinics in fulfilling such requests.
10. Changes and contact
We may update this policy as the product evolves; the date above reflects the latest revision, and material changes will be communicated to account holders. For any privacy question or request, reach us through the contact page.