Data Processing and BAA Readiness
Version: 12 July 2026. This page summarizes our data-processing position. A counsel-review draft DPA and conditional BAA schedule are included in the paid-client legal pack; neither authorizes unrestricted production PHI without clinic-specific execution and security approval.
Roles
The clinic is the controller of patient and prospect data and decides why it is collected and how it is used for intake, follow-up, and booking. Smart Clinic Reception AI is the processor and processes that data only to provide the service and on the clinic's documented instructions.
Processing details
- Subject matter: lead intake, staff-reviewed follow-up, booking, reminders, and reporting.
- Duration: for the term of the clinic's subscription plus routine retention windows.
- Data categories: contact details, treatment interest, consent evidence, message and delivery logs, appointment records.
- Data subjects: the clinic's leads, prospects, and patients.
Our processor commitments
- Process personal data only on documented instructions from the clinic.
- Ensure confidentiality of personnel with access to data.
- Apply appropriate security measures (encryption in transit, encrypted token storage, hashed credentials, clinic isolation, audit logging).
- Use subprocessors only under equivalent obligations and keep the list current at Subprocessors.
- Assist with data subject requests through in-product export and erasure tools.
- Delete or return personal data at the end of the engagement, subject to legal retention.
- Support reasonable audits and provide information needed to demonstrate compliance.
Data subject requests
The platform provides per-lead data export and erasure so clinics can fulfil access, portability, and deletion requests. Export includes consent and opt-out evidence, provider-calendar metadata, and the lead's audit trail. Erasure removes message content and personal data but preserves the minimal opt-out/suppression record so an earlier unsubscribe or STOP is still honored. Each export and erasure records who requested and who approved it. Email unsubscribe and SMS STOP handling support opt-out requests, with suppression enforced on future sends.
International transfers
Where subprocessors operate outside the clinic's region, transfers rely on recognized safeguards such as Standard Contractual Clauses or equivalent mechanisms. Data location options can be discussed for production deployments.
Healthcare privacy boundary (US HIPAA)
HIPAA may apply if protected health information is created, received, maintained, or transmitted on behalf of a covered entity. A Business Associate Agreement may be considered only after provider/subprocessor eligibility, security controls, the exact workflow, and applicable law are reviewed. Until a clinic-specific BAA is executed and activation is approved, unrestricted production PHI is prohibited.
Operating guidance
- Use intake and scheduling language only; no emergency handling, diagnosis, clinical advice, final pricing, or insurance guarantees.
- Keep human review enabled by default before automated patient-facing sends.
- Use consent-based forms and opt-out text for patient follow-up.
- Distinguish service messages (reminders, confirmations) from marketing messages.
Reference links
- HHS: Covered Entities and Business Associates
- HHS: Business Associates
- EDPB: Data controller or data processor
- ICO: PECR overview
Review the paid-client legal pack. To request a clinic-specific DPA review, contact support@smartclinicreception.online. Legal reviewer status: not appointed.