Privacy Policy
Last updated: August 20, 2026
ClinicChatDesk ("ClinicChatDesk", "we", "our", or "us") provides an AI-powered communication, receptionist, appointment-management, and revenue-recovery platform for clinics. ClinicChatDesk is operated by Coders Insight Technologies (Pvt) Ltd.
This Privacy Policy explains how information is collected, used, processed, stored, shared, and protected when clinics, clinic staff, patients, prospective patients, or website visitors use ClinicChatDesk, including our website, dashboard, WhatsApp integrations, and related services.
1. Information We Collect
Clinic and account information
When a clinic or clinic staff member creates or manages an account, we may collect:
- Clinic name and business information
- Account owner or administrator name
- Email address and phone number
- Country, phone country code, currency, timezone, and language preferences
- Clinic address, business hours, services, prices, doctors, staff, and FAQs
- Authentication, session, login, and account-security information
Patient and conversation information
When a clinic uses ClinicChatDesk to communicate with patients or prospective patients, we may process information such as:
- Name and phone number
- WhatsApp identifiers and messaging metadata
- Message content and conversation history
- Voice notes and text transcriptions
- Appointment requests, dates, times, services, and booking status
- Follow-up, lost-lead, cancellation, and recovery status
Clinics should avoid sending or storing unnecessary sensitive medical information in ClinicChatDesk.
2. WhatsApp and Meta Data
ClinicChatDesk may integrate with the WhatsApp Business Platform provided by Meta. When a clinic connects its WhatsApp Business account, ClinicChatDesk may process information made available through Meta APIs, including WhatsApp Business Account identifiers, Phone Number IDs, business account information, incoming and outgoing messages, message delivery status, timestamps, phone numbers, media, and voice notes.
We use this information only as necessary to provide the ClinicChatDesk service, support the clinic's configured workflows, maintain security, and comply with applicable platform requirements. ClinicChatDesk does not sell WhatsApp user data.
3. Artificial Intelligence and Voice Processing
ClinicChatDesk uses artificial intelligence services to assist with functions such as answering clinic-approved questions, understanding conversation intent, appointment booking, voice-note transcription, lost-lead follow-up, cancellation recovery, and routing conversations to staff.
Information necessary to perform these functions may be sent to third-party AI service providers, including OpenAI. We aim to limit the information provided to those services to what is reasonably necessary for the requested function.
ClinicChatDesk is designed so that clinic-specific facts such as services, prices, working hours, availability, and business rules can be retrieved from the clinic's configured data rather than relying solely on AI-generated information. AI outputs may still be inaccurate, and clinics remain responsible for reviewing their configuration and handling communications that require professional medical judgment.
4. How We Use Information
We may use information to:
- Provide, operate, maintain, and secure ClinicChatDesk
- Authenticate users and maintain account sessions
- Send and receive WhatsApp Business messages
- Answer administrative patient enquiries
- Create and manage appointment bookings
- Process voice notes and transcriptions
- Identify and manage follow-up opportunities
- Assist with cancelled appointment slot recovery
- Provide clinic dashboards, analytics, and service-usage information
- Provide customer support and troubleshoot technical issues
- Detect abuse, fraud, security incidents, or unauthorized access
- Comply with applicable legal and contractual obligations
We do not use patient conversation data for unrelated advertising, and we do not sell patient information to advertisers or data brokers.
5. Clinic Responsibilities
Depending on the applicable privacy law and the circumstances, a clinic may act as the controller or business responsible for determining why and how patient information is processed, while ClinicChatDesk may act as a processor or service provider acting on the clinic's behalf.
Clinics are responsible for having an appropriate legal basis for processing patient information, providing any required privacy notices, obtaining consent where required, configuring lawful messaging and follow-up practices, and complying with applicable healthcare, privacy, consumer-protection, and communications laws.
6. Service Providers and Information Sharing
We may share information with service providers only when reasonably necessary to operate ClinicChatDesk. These providers may include:
- Meta / WhatsApp for business messaging
- OpenAI and other configured AI or transcription providers
- Cloud hosting, infrastructure, database, and storage providers
- Email, notification, security, monitoring, and support providers
- Payment providers if paid subscriptions are enabled
We may also disclose information when required by applicable law, regulation, legal process, court order, or valid governmental request, or when reasonably necessary to protect the rights, safety, security, or integrity of ClinicChatDesk, our customers, or others.
7. Data Retention
We retain information for as long as reasonably necessary to provide the service, maintain account and appointment records requested by clinics, meet security and fraud-prevention needs, and comply with legal, accounting, contractual, or regulatory obligations.
Retention periods may vary by data type, customer configuration, contract, and applicable law. Certain deleted information may remain temporarily in backups, logs, or disaster-recovery systems until those systems rotate or expire.
8. Data Deletion Requests
Clinics and users may request deletion of eligible personal information by contacting privacy@clinicchatdesk.com. A request should include enough information for us to identify the relevant account or data, such as the clinic name, account email, or relevant phone number.
Patients may also contact the clinic they communicated with because the clinic may control the relevant patient information. We may need to verify identity before completing a request and may retain information where required by law or reasonably necessary for security, fraud prevention, dispute resolution, or accounting.
9. Meta User Data Deletion
If your information is associated with Meta or WhatsApp services used through ClinicChatDesk, you may request deletion by emailing privacy@clinicchatdesk.com and providing sufficient information to identify the relevant data. Valid requests will be handled in accordance with applicable law and our contractual obligations.
10. Security
We use reasonable technical and organizational safeguards intended to protect information, including HTTPS encryption in transit, authentication, access controls, clinic-level tenant separation, restricted administrative access, secure server-side handling of integration credentials, and security monitoring where appropriate.
No internet-based service can guarantee absolute security. Customers are responsible for protecting account credentials, configuring staff access appropriately, and notifying us promptly if they suspect unauthorized access.
11. International Data Processing
ClinicChatDesk and its service providers may process information in countries other than the country in which a clinic or patient is located. Where required by applicable law, appropriate safeguards should be used for international transfers of personal information.
12. Healthcare and Sensitive Information
ClinicChatDesk is intended as an administrative communication and appointment-management platform. Unless separately agreed in writing and supported by the necessary legal, contractual, and technical safeguards, ClinicChatDesk should not be used as an electronic medical record system, for medical diagnosis or treatment, for emergency medical communications, or to store regulated health records.
Organizations subject to sector-specific healthcare requirements, including HIPAA in the United States, should confirm that all required agreements and compliant configurations are in place before transmitting protected health information through the service.
13. Cookies and Technical Information
Our website and dashboard may process limited technical information such as IP address, browser type, device type, session identifiers, login activity, request metadata, and security or error logs. We may use cookies or similar technologies that are necessary for authentication, security, and core platform functionality.
14. Children's Privacy
ClinicChatDesk is a business service intended for clinics and clinic staff and is not intended for children to create business accounts independently. Where a clinic communicates with a minor, parent, or guardian, the clinic remains responsible for complying with applicable laws governing children's information.
15. Privacy Rights
Depending on your location and applicable law, you may have rights relating to your personal information, which may include the right to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where processing is based on consent.
To exercise a privacy right, contact privacy@clinicchatdesk.com. We may ask for information reasonably necessary to verify your identity and process the request.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time as ClinicChatDesk, applicable laws, or our service providers change. When we make material changes, we may update the date at the top of this page and provide additional notice where appropriate.
17. Contact Us
ClinicChatDesk
Operated by Coders Insight Technologies (Pvt) Ltd
Website: clinicchatdesk.com
Privacy contact: privacy@clinicchatdesk.com