ClinicalSOPs — Privacy Policy
Preliminary draft — has not yet been reviewed by an attorney. Bracketed items mark terms still being finalized. See note at the bottom.
This Privacy Policy explains what information ClinicalSOPs ("we," "us") collects from the medical spas and aesthetics practices that use our platform ("Customer," "you") and their staff, and how we use it.
This policy covers business/account data, not patient data.ClinicalSOPs is a reference and drafting tool — consent and treatment-record templates in the product are unsigned drafts, and the Service is not designed or intended to store real patient health information. If your staff ever enter real patient information into a free-text field not intended for it, that's outside the Service's intended use and this policy doesn't attempt to describe HIPAA-covered handling of it — talk to your attorney if this applies to you.
1. Information we collect
Account information
Name, email address, password (stored as an irreversible hash, never in plain text), role, and which location(s) you're assigned to.
Organization information
Practice name, logo, brand color, and other branding settings you configure. If you choose to use your own AI provider key instead of our shared one, that key (stored encrypted, never in plain text, used only to run scans on your behalf).
Content you create or import
Protocols, templates, and their edit history; Medical Director sign-off records (status, initials, attestation, timestamp — treated as a permanent compliance record and not deleted even if the underlying content later changes); support requests you submit and signup requests submitted through our public signup form.
Usage and technical data
Login session tokens and basic operational logs generated by our hosting/infrastructure providers.
We do not intentionally collect or store: patient names, patient health information, payment card numbers, or precise device/location tracking.
2. How we use this information
- To provide the Service: authenticate you, apply your role's access rules, render your organization's branding, generate PDFs, and run compliance scans.
- To communicate with you: password-reset and account-setup emails, compliance-alert notifications, and responses to support requests.
- To operate and improve the Service: understanding usage patterns, diagnosing bugs.
- To enforce our Terms of Service and protect the security of the Service and other customers' data.
We do not sell your information, and we do not use it to serve you third-party advertising.
3. Who we share it with
We share information only as needed to run the Service, with these categories of sub-processor:
| Purpose | Provider | What they process |
|---|---|---|
| Hosting, serverless compute | Vercel | All application traffic; file storage (logos, generated PDFs) |
| Database | Neon (Postgres) | All account/content data described above |
| Transactional email | Resend | Recipient address, name, and message content for password-reset, welcome, alert, and support-notification emails |
| AI-assisted compliance scanning & content drafting | Anthropic (Claude API) | Protocol text sent for scanning/drafting assistance — not patient data, not full account records |
[Once billing exists, our payment processor will be added to this list.]
We may also disclose information if required by law, to enforce our Terms, or in connection with a merger, acquisition, or sale of assets.
4. Cookies and sessions
We use a single essential session cookie to keep you signed in. We do not use third-party advertising or tracking cookies.
5. Data retention and deletion
- We retain your organization's data for as long as your account is active.
- You can export a full copy of your organization's data at any time (Settings > Data Export).
- If your account is terminated, we retain data for [a period to be finalized] to allow for export or reactivation, after which it may be deleted.
- Medical Director sign-off records may be retained longer as a compliance record even after the underlying protocol content changes or the account is closed.
6. Your rights and choices
- Access & export: any Owner can export their organization's protocols, templates, and sign-off history at any time.
- Correction: your Owner can update account details for your organization's users; individual users can update their own password via Account.
- Deletion: contact us (Section 8) to request deletion of your organization's account and data, subject to the retention terms above.
[If we have customers/staff in California, the EU/UK, or other jurisdictions with statutory privacy rights, specific rights language for those laws will be added here.]
7. Security
We use industry-standard measures to protect your information, including password hashing, encrypted storage of sensitive fields, single-use expiring tokens for password resets, and role-based access controls that restrict what each staff member can see. No system is 100% secure, and we can't guarantee absolute security.
8. Contact
Questions about this policy or your data: use the in-app Support form, or contact [privacy contact email].
9. Changes to this policy
We may update this policy from time to time. We'll notify you of material changes before they take effect.