Legal

ClinoView Privacy Policy

Last updated: August 10, 2026

ClinoView LLC — Version 2.0 — Last updated: August 10, 2026

ClinoView LLC ("ClinoView," "we," "our," or "us") respects your privacy and is committed to handling information responsibly. This Privacy Policy explains what information we collect, how we use it, and how we protect it when you use the ClinoView platform and related services (collectively, the "Services").

If you are a clinic or healthcare organization using our Services, this policy describes how we handle your account information and the patient data you upload or generate through the platform.

1. Information We Collect

1.1 Account Information

When you create an account, we collect information such as:

  • Name and contact details of the account holder or authorized representative.
  • Organization or clinic name.
  • Email address and phone number.
  • Billing contact information.

1.2 Clinic and Practice Information

As part of setting up and using the Services, we may collect:

  • Clinic name, address, and contact details.
  • Professional license information provided by the account holder.
  • Subscription and plan details.
  • Configuration and settings for your account.

1.3 Patient Information

The Services allow clinics to collect, store, and manage patient information as part of their clinical workflows. This may include:

  • Patient names, contact details, and demographic information.
  • Medical history, intake forms, clinical notes, and assessments.
  • Clinical documents, reports, and uploaded files.
  • Any other information the clinic chooses to enter or upload.

ClinoView processes this information solely on behalf of the clinic, as a data processor. The clinic remains the data controller and is responsible for how patient information is collected, used, and disclosed. See Section 14.

1.4 Uploaded Files

Customers may upload documents, forms, PDFs, images, and other files through the Services. We store and process these files to provide the Services and do not use them for any other purpose.

1.5 Usage and Technical Data

We automatically collect certain technical information when you use the Services, including IP address and device type, browser type and version, pages and features accessed within the platform, timestamps and session duration, and error logs and performance data. This information helps us operate, secure, and improve the Services.

1.6 Cookies and Similar Technologies

We use cookies and similar technologies to operate and improve the Services:

  • Essential cookies: required for the platform to function, such as session management

and authentication.

  • Analytics cookies: used to understand how the Services are used so we can improve

them. Our analytics provider receives page and feature usage together with an opaque account identifier, clinic name, and role. We do not send names, email addresses, or any patient information to analytics providers.

  • Preference cookies: used to remember your settings and preferences.

You can manage cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the Services.

2. How We Use Information

We use the information we collect to:

  • Provide, operate, secure, and maintain the Services.
  • Process payments and manage Subscriptions.
  • Respond to support requests and communicate with Customers.
  • Send service updates, security alerts, and administrative notices.
  • Analyze usage patterns to improve the platform's features and performance.
  • Detect, investigate, and prevent fraud, abuse, or security incidents.
  • Comply with legal obligations.

We do not use Customer Data or patient information for advertising, for marketing to third parties, or for any purpose unrelated to delivering the Services. We may use aggregated, de-identified data that cannot reasonably be used to identify any individual, Customer, or patient to operate and improve the Services.

3. AI Processing

Some features of the Services use artificial intelligence to assist with tasks such as report generation, document analysis, and workflow automation. When a Customer uses these features, relevant data — including intake responses, clinical notes, and uploaded documents — may be processed by AI systems to generate outputs.

AI processing occurs solely to provide the Services. AI outputs are workflow assistance tools only, and are not medical advice or clinical decisions. Healthcare professionals must review all AI-generated content before it is used for any clinical purpose.

We require our AI providers to process data only to provide the requested service. We do not permit them to use Customer Data or patient data to train or improve their models, and we do not use patient data to train AI models for purposes unrelated to the Services. AI providers may retain submitted data for a limited period for security and abuse monitoring under their own published terms.

4. Service Providers and Subprocessors

We work with trusted third-party providers ("Subprocessors") to deliver the Services. These may process certain data on our behalf, including:

  • Cloud infrastructure and data hosting providers.
  • AI and language model providers.
  • Payment processing providers.
  • Email and communications services.
  • Analytics, error reporting, and monitoring tools.

All Subprocessors are contractually required to protect the information they process on our behalf, to use it only for the purposes we direct, and to maintain appropriate security standards. We remain responsible for their performance.

We maintain a current list of Subprocessors — including name, country of processing, and function — and make it available on request at privacy@clinoview.com. We will give reasonable advance notice of a new or replacement Subprocessor where practicable.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

5. International Data Transfers and Data Hosting

ClinoView stores and processes data on cloud infrastructure located in the United States, using providers with enterprise-grade security controls. We do not host data in the Customer's local jurisdiction unless separately agreed in writing.

If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.

This Privacy Policy is not by itself a cross-border transfer mechanism. Where the law that applies to you requires one, we will execute it with you before patient data is transferred — incorporating, as applicable, the Brazilian ANPD standard contractual clauses without modification, an Argentine AAIP model controller-to-processor agreement, the EU Standard Contractual Clauses where the GDPR applies, or the annex required in Peru or Mexico. Request the applicable package at privacy@clinoview.com.

Customers are responsible for their own controller obligations, including obtaining any required patient authorizations for the transfer and processing of personal data. That responsibility does not replace our own obligations as processor and data importer.

6. Security

We implement reasonable technical and organizational measures to protect information against unauthorized access, disclosure, alteration, and loss. Our practices include:

  • TLS encryption for data in transit and provider-managed encryption for infrastructure

storage at rest.

  • Additional application-layer AES-256 encryption of direct patient identifiers, intake

payloads, and clinical notes. Not every clinical or analytics field receives application-layer encryption; structured classification and score fields are stored in a queryable form by design.

  • Data held in a shared multi-tenant environment and separated by authenticated,

role-based, clinic-scoped application access controls.

  • Logging of authentication and selected administrative events. We do not currently

maintain a complete audit trail of every patient-record view, download, or change.

  • Regular backups with documented and periodically exercised recovery procedures.

Our security program is designed using industry-recognized practices for protecting health information, including principles consistent with the HIPAA Security Rule as a design and operational reference. This describes our design standard; it is not, by itself, a certification of compliance with any framework, and we have not undergone a third-party security audit or certification.

No system is completely secure. If you become aware of a security incident involving your account, notify us immediately at security@clinoview.com.

7. Security Incident Notification

If we become aware of a suspected or confirmed security incident that compromises the confidentiality, integrity, or availability of personal data we process on a Customer's behalf, we will notify that Customer without undue delay and, where feasible, within twenty-four (24) hours. We will not delay the initial notice pending completion of our investigation; we may report in phases and will supplement promptly as facts develop. The notice will include the information reasonably available to us to help the Customer meet its own notification obligations. Where a Data Processing Agreement or Business Associate Agreement applies, its notification terms control if they are shorter or stricter.

8. HIPAA

The standard self-service configuration is not authorized for protected health information subject to the U.S. Health Insurance Portability and Accountability Act. A Customer that is a "covered entity" or "business associate" may submit protected health information only after we confirm in writing that a Business Associate Agreement is in effect and that a HIPAA-eligible account configuration has been enabled. Accepting our Terms or completing payment does not by itself provide that confirmation. Request a BAA at legal@clinoview.com. Where a BAA is in place, it governs our handling of protected health information.

9. Data Retention

We retain Customer Data for as long as the Subscription is active. After a Subscription ends:

  • Customer Data is retained for at least ninety (90) days so that an export can be

requested and fulfilled (see Terms Section 26).

  • Deletion is an operator-managed process rather than an automatic one. We do not commit to

a fixed deletion date; on request we carry out deletion without undue delay and confirm it in writing only once we have verified removal from both database records and file storage.

  • Encrypted backup copies may persist for up to one (1) year under our standard backup

rotation and are restored only for disaster recovery.

  • Authentication and administrative event logs are retained for security and compliance

purposes. These contain account and access activity only, not patient clinical records.

If a Customer's account becomes inactive for more than ninety (90) days with no response to our notices, we may delete the data as described in our Terms of Service.

10. Your Rights

Depending on your location and applicable law, you may have rights regarding your personal information, including:

  • Access: request a copy of the personal information we hold about you.
  • Correction: request that we correct inaccurate or incomplete information.
  • Deletion: request that we delete your personal information, subject to legal

retention obligations.

  • Portability: request your data in a machine-readable format. We fulfil these requests

with operator assistance rather than a self-service export (see Terms Section 26).

  • Objection: object to certain uses of your information.

To exercise these rights, contact privacy@clinoview.com. We will respond within the timeframes required by applicable law and will not discriminate against you for exercising them.

Patient data. If you are a patient whose information was entered into the platform by a clinic, requests about your personal information should be directed to that clinic, which controls the data. We will assist the clinic in fulfilling such requests where required by law.

11. California Residents

If you are a California resident, you may have additional rights under the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), including the right to know what personal information we collect and how we use it, the right to delete it (with exceptions), the right to correct inaccurate information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising your privacy rights.

We do not sell or share personal information as those terms are defined under the CCPA. To submit a request, contact privacy@clinoview.com or use the process in Section 10.

Medical information handled by a covered health care provider may be governed by the Confidentiality of Medical Information Act rather than the CCPA.

12. Children

The Services are designed for use by healthcare professionals and organizations. We do not knowingly collect personal information from individuals under 18 through our registration or account processes.

Patient data uploaded by a clinic may relate to minors. The clinic is responsible for ensuring appropriate consents and legal authorizations are in place for processing minors' health information.

13. Automated Decision-Making

The Services apply automated processing to patient intake data to produce scores, structured classifications, risk indicators, and draft reports. These outputs are decision support: they have no legal or similarly significant effect on their own, because a qualified healthcare professional at the clinic reviews them and makes every clinical decision.

A patient who wants human review of an automated output, an explanation of it, or wants to contest it should contact the clinic that treats them, since the clinic controls that data and makes the decisions. We will support the clinic in responding where the law requires it.

14. Privacy Responsibilities of Customers

Clinics and healthcare organizations using the Services act as data controllers for the patient information they collect and process through the platform. ClinoView acts as a data processor, handling that information on the clinic's behalf and only as directed.

Clinics are responsible for:

  • Obtaining all required patient consents before collecting or uploading patient

information.

  • Complying with all applicable privacy and healthcare laws in their jurisdiction.
  • Maintaining their own privacy notices for patients.
  • Ensuring their use of the Services complies with their professional and regulatory

obligations.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the updated policy with a revised "Last updated" date and give reasonable notice to Customers. Your continued use of the Services after an update constitutes acceptance of the revised policy.

16. Language

This policy is written in English. Any translation is provided for convenience only; the English version controls in the event of a discrepancy.

17. Contact

ClinoView LLC