Legal

Privacy

What we collect, why we are allowed to, where it lives, who else touches it, and what you can make us do with it. Written to be read rather than to be survived.

Last updated 10 August 2026

01We are in two different roles, and the difference matters

Clinic+ handles two kinds of personal data, and the law treats them differently.

For the people who use our software — clinic owners, clinicians, front-desk staff, and visitors to this website — we are the controller. We decide what to collect and why, and this policy is the answer.

For patient records inside a clinic's account — examinations, prescriptions, consent forms, appointment histories — we are only the processor. The clinic decides what goes in and what happens to it; we hold it and act on their instructions. If you are a patient and want your record changed or deleted, ask the clinic. They can do it themselves, and we cannot do it behind their back. The terms governing that relationship are in the Data Processing Agreement.

02Who we are

Clinic+ is a product of Pull House LLC, a limited liability company incorporated in Delaware, United States, at 8 The Green, Suite 23111, Dover, DE 19901, United States.

Pull House LLC is the entity behind this policy. Clinic+ is the product; the company is who you are contracting with and who answers for the data.

For anything in this policy, write to hello@clinicplus.io. A person reads it.

03What we collect as controller

Only what the product needs to work or what your browser sends us on its own.

DataWhy we have it
Account detailsName, email address and the clinic you belong to — needed to create your login and decide what you are allowed to see.
Authentication dataSession cookies and sign-in records, so you stay logged in and we can tell a legitimate session from a stolen one.
Clinic profileClinic name, branches, working hours, services and anything else you enter to configure the product.
Billing detailsSubscription status and invoices. Card numbers are handled by our payment provider and never reach our servers.
Technical logsIP address, browser, timestamps and errors. Used to keep the service up and to investigate abuse, then aged out.
Support correspondenceWhat you write to us, so a thread makes sense on the second reply.
Agreement recordWhen your clinic accepted the Terms, this policy and the Data Processing Agreement — including who accepted, the country given, and the IP address and browser it came from. This is evidence that a contract was formed, which is the only reason we keep an IP address attached to a name.

We do not buy personal data, we do not sell it, and we do not run advertising or third-party analytics trackers on this site.

04Cookies

One cookie does real work: __session, which holds your signed-in session. It is strictly necessary — without it the panel cannot tell one request from another, and you would be logged out on every click. The name is not a choice: our hosting layer strips every cookie except that exact one.

We set no advertising cookies and no cross-site trackers, which is why you are not reading this through a consent banner.

06Where your data is, and who else touches it

The database, file storage and application servers run on Google Cloud in europe-west1 (St. Ghislain, Belgium). That is the primary location for both account data and clinic records.

Sub-processorWhat it doesWhere
Google Cloud / FirebaseDatabase, file storage, authentication, application hostingeurope-west1 (Belgium)
ResendTransactional email — appointment confirmations, reminders, magic linksus-east-1 (United States)

Transactional email means an address and the contents of that message leave the EU. Where a transfer needs a legal mechanism, we rely on the European Commission's Standard Contractual Clauses — with the UK Addendum or the Swiss amendments where those apply — and they form part of our Data Processing Agreement with their annexes completed. If your own regulator requires something more specific for health data, tell us before you sign; this is a question we would rather answer early than in an audit.

07How it is protected

Isolation between clinics is enforced in the database rules themselves, not in the application code that queries them. A request that does not carry a valid membership for a clinic cannot read that clinic's data, even if the code above it asks wrongly. Roles are carried as signed token claims, so revoking someone's access takes effect at the database, not just in the interface.

Traffic is encrypted in transit and data is encrypted at rest by the platform. Access to production by our own staff is limited to what is needed to run the service and to answer support requests.

No system is beyond compromise. If one occurs and it affects personal data, we will notify the affected clinics without undue delay and give them what they need to meet their own notification duties.

08How long we keep it

Account and clinic-configuration data live as long as the account does. When a subscription ends, the clinic can export its data; after 90 days from termination we delete it from live systems, and backups age out on their own cycle after that.

Technical logs are kept for a short operational window and then discarded. Billing records are kept for as long as accounting law requires us to keep them, which is longer than we would otherwise choose.

09What you can ask us to do

Subject to the law that applies to you, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing based on legitimate interest, ask us to restrict it, or ask for it in a portable form.

Write to hello@clinicplus.io. We answer within one month; if a request is genuinely complex we will say so rather than let it run silent.

If you are unhappy with how we handled it, you can complain to a supervisory authority — the authority for the country you live in, work in, or where you think the problem happened .

One limit worth stating plainly: if your request concerns a patient record held inside a clinic's account, we have to send you to that clinic. Acting on it ourselves would mean changing a medical record at the request of someone the clinic has not verified.

10Children

The panel is a professional tool and is not offered to children. Patient records held by a clinic may of course concern a child; that data belongs to the clinic's relationship with the family and is governed by the Data Processing Agreement, not by this policy.

11Changes to this policy

When something material changes we will update the date at the top and tell account owners by email before it takes effect. Silent rewrites of a privacy policy are a bad habit and we do not intend to acquire one.