Clinitech

Clinic platform

Legal information

Privacy Policy

Last updated: August 27, 2026

CliniTech ("CliniTech", "we", "us", or "our") provides clinic-management software for healthcare organizations and their authorized staff.

This Privacy Policy explains how personal information is collected, used, stored, shared, and protected when you use the CliniTech website, web application, mobile application, and related services.

CliniTech is currently operated from Armenia. Questions or requests regarding privacy may be sent to support@clinitech.app.

1. Scope of this Policy

CliniTech processes different categories of information depending on how the Service is used.

In general, there are two main situations:

  1. CliniTech account and service information. We process information relating to users, clinics, authentication, billing, security, support, and operation of the CliniTech service.
  2. Patient and clinical information entered by clinics. Clinics use CliniTech to store and manage information relating to their patients and healthcare activities. For this information, the clinic determines what information is entered into CliniTech and how it is used for the clinic's healthcare activities. CliniTech processes and stores that information to provide the Service to the clinic.

Clinics are responsible for ensuring that they are legally authorized to collect, enter, use, and manage patient and clinical information through CliniTech.

2. Information We Process

2.1 Clinic Information

CliniTech may process information relating to clinics, including:

  • clinic name;
  • country and timezone;
  • clinic status and enabled features;
  • subscription and billing information;
  • clinic users and memberships;
  • clinic settings and preferences.

2.2 User and Staff Information

We may process information relating to users and clinic staff, including:

  • name;
  • email address;
  • optional WhatsApp number;
  • language and application preferences;
  • clinic membership;
  • user roles and permissions;
  • schedules;
  • notification preferences;
  • account status;
  • authentication and security information.

Clinic administrators may invite staff members to CliniTech using their email addresses.

2.3 Patient Information

Clinics may enter patient information into CliniTech, including:

  • first, middle, and last name;
  • date of birth;
  • gender;
  • patient number;
  • phone number;
  • email address;
  • address information;
  • emergency or other contact information;
  • medication information;
  • smoking information;
  • pregnancy or breastfeeding information;
  • allergies;
  • medical conditions;
  • complaints;
  • patient notes;
  • referral information.

The specific information entered for a patient is determined by the clinic using CliniTech.

2.4 Clinical and Healthcare Information

CliniTech may process healthcare information entered by clinics, including:

  • visits and visit history;
  • doctors responsible for visits;
  • visit dates, times, and status;
  • clinical notes and summaries;
  • procedures;
  • treatment plans;
  • dental charting and tooth-related treatment information;
  • referrals;
  • follow-ups;
  • appointment and scheduling information;
  • uploaded clinical documents, images, and other files.

CliniTech is a clinic-management tool and does not itself make medical diagnoses or treatment decisions.

2.5 Files and Documents

Authorized clinic users may upload files associated with patients, visits, and other supported records.

Supported files may include documents and images such as PDFs, DOC/DOCX documents, JPEG/PNG/WEBP images, and HEIC/HEIF images.

Images processed by CliniTech may be converted to another image format and may have metadata such as EXIF and GPS information removed as part of processing.

Clinical files are stored in private application storage and are served through authenticated and authorized CliniTech endpoints.

2.6 Authentication and Security Information

To operate and protect the Service, CliniTech may process:

  • password hashes;
  • authentication tokens;
  • password-reset information;
  • session identifiers;
  • login timestamps and activity;
  • IP addresses;
  • browser or device user-agent information;
  • security and rate-limiting information.

Passwords are not stored in plain text.

Mobile authentication tokens are stored by CliniTech in hashed form after issuance.

2.7 Audit and Activity Information

CliniTech maintains audit information to help clinics understand changes made to important records and to support security and accountability.

Audit information may include:

  • clinic and user identifiers;
  • affected record type and identifier;
  • action performed;
  • previous and updated values;
  • IP address;
  • device/browser information;
  • date and time of the action.

Because audit records may reflect changes to patient or clinical records, they may contain personal or healthcare-related information.

2.8 Billing Information

For international subscription payments, CliniTech may use Paddle or another disclosed payment provider.

CliniTech may receive and store information such as:

  • customer identifiers;
  • subscription identifiers;
  • subscription status;
  • product and price identifiers;
  • invoice and transaction references;
  • billing periods;
  • payment status;
  • amounts and currency;
  • billing-related provider information.

CliniTech does not itself store full payment-card numbers or card security codes when payment details are collected directly by Paddle.

2.9 Support Communications

If you contact CliniTech support, we may process:

  • your name and email address;
  • clinic name;
  • your message;
  • information you voluntarily provide regarding your question or issue;
  • relevant technical or account information needed to assist you.

Users should avoid sending unnecessary patient or sensitive clinical information through general support channels.

3. How We Collect Information

We may receive information:

  • directly from you when you register or manage your account;
  • from Clinic Administrators when they invite staff;
  • from authorized clinic users when they create or update patient and clinical records;
  • automatically when you use the Service, for security, session, and technical operation;
  • from payment providers in connection with subscriptions and payments;
  • from third-party integrations that you or your clinic choose to enable.

4. How We Use Information

CliniTech processes information where necessary to provide, operate, protect, and improve the Service.

This includes using information to:

  • create and administer accounts;
  • create and manage clinics;
  • authenticate users;
  • enforce roles and permissions;
  • provide patient and clinical record functionality;
  • provide scheduling, visits, treatment plans, referrals, follow-ups, and related clinic functions;
  • store and serve authorized clinical files;
  • process subscriptions and billing;
  • send account, invitation, password-reset, and service communications;
  • provide notifications selected by users;
  • provide customer support;
  • protect the security and integrity of the Service;
  • maintain audit records;
  • detect and investigate errors, abuse, or security incidents;
  • comply with applicable legal obligations.

We do not use patient or clinical information for advertising.

5. Clinic Responsibility for Patient and Clinical Data

Clinics using CliniTech are responsible for the patient and clinical information they enter into the Service.

The clinic is responsible for determining, as applicable:

  • the legal basis for collecting and processing patient information;
  • what patient information should be entered into CliniTech;
  • which staff members are authorized to access the information;
  • the accuracy and completeness of patient records;
  • appropriate medical-record retention periods;
  • responding to patient requests concerning their medical records;
  • compliance with healthcare, confidentiality, and data-protection requirements applicable to the clinic.

CliniTech processes this information to provide the Service and according to the clinic's authorized use of the platform, subject to applicable law.

6. Service Providers and Third Parties

CliniTech may use third-party service providers where necessary to operate the Service.

Hosting Provider

CliniTech currently operates production infrastructure using Contabo hosting located within the European Union.

The production database and application files are currently stored on CliniTech's server infrastructure. Infrastructure providers may process technical data as necessary to provide hosting services.

Resend

CliniTech uses Resend for transactional email delivery.

Email addresses, recipient names, and the content necessary to deliver account invitations, welcome messages, password-reset emails, and other transactional messages may be transmitted through Resend.

Paddle

CliniTech uses Paddle for certain international subscription and payment processing.

Paddle may process customer, billing, transaction, tax, and payment information in accordance with its own privacy and legal obligations.

Telegram

Users may optionally connect Telegram to receive certain CliniTech notifications.

When Telegram notifications are enabled, limited information necessary for the selected notification may be transmitted through Telegram. This may include items such as a CliniTech record identifier, visit date or time, doctor name, patient name, and an authenticated CliniTech link.

CliniTech intentionally limits Telegram notification content and does not intend to transmit detailed clinical notes, complaints, treatment information, or patient telephone numbers through Telegram notifications.

Telegram is optional and is not required to use the core CliniTech Service.

WhatsApp

CliniTech may provide links that allow users to contact CliniTech support through WhatsApp.

CliniTech does not currently use WhatsApp as an automated clinical notification provider. Information voluntarily sent using WhatsApp is also subject to WhatsApp's own services and privacy practices.

7. International Data Transfers

CliniTech is operated from Armenia and currently uses production hosting located within the European Union.

As a result, personal information may be processed or stored outside the country in which the clinic, user, or patient is located.

CliniTech may also use service providers operating in other jurisdictions.

Where required, CliniTech and its customers are responsible for ensuring that international transfers of personal information are made using an appropriate legal basis and safeguards under applicable law.

8. Cookies and Similar Technologies

CliniTech currently uses cookies and similar browser mechanisms necessary for operation and security of the web application.

These may include:

  • session cookies;
  • authentication-related cookies;
  • CSRF/XSRF security cookies.

CliniTech does not currently use advertising cookies, advertising trackers, Google Analytics, Meta Pixel, session-replay tools, or similar marketing-tracking technologies.

If this changes, this Privacy Policy and the CliniTech Cookie Policy will be updated as appropriate.

9. Data Security

CliniTech uses technical and organizational measures intended to protect personal and clinical information from unauthorized access, disclosure, alteration, or loss.

Measures currently include, where applicable:

  • authenticated application access;
  • clinic-based access separation;
  • role and permission controls;
  • protected API access;
  • password hashing;
  • hashed mobile authentication-token storage;
  • private storage for sensitive clinical files;
  • authorized file-download endpoints;
  • HTTPS transport encryption;
  • audit logging;
  • restricted application administration;
  • database-backed session management;
  • removal of EXIF/GPS metadata during supported image processing.

No information system can be guaranteed to be completely secure. CliniTech reviews and improves its security controls as the Service develops.

10. Data Retention

CliniTech retains information for as long as reasonably necessary to provide the Service, satisfy contractual obligations, maintain security and audit records, and comply with applicable legal requirements.

Patient and clinical information may be subject to healthcare and medical-record retention requirements. For this reason, deleting or archiving a record from normal clinic workflows does not necessarily mean that all underlying medical information can immediately be permanently destroyed.

The clinic is responsible for determining the legally applicable retention obligations for its patient and medical records.

CliniTech may retain relevant information where continued retention is required or permitted by law, necessary for legal claims, security, fraud prevention, billing, audit requirements, or other legitimate purposes.

11. Account, Clinic, and Record Deletion

User Accounts

Users or Clinic Administrators may have mechanisms to deactivate or remove access to user accounts.

Historical records may retain information necessary to identify who created or modified clinical records, even after that person's active access has ended.

Patient Records

Clinics may archive or remove patients from active use within CliniTech where supported.

Permanent destruction of patient or clinical information may be restricted by applicable healthcare, medical-record, legal, contractual, or regulatory retention requirements.

Clinic Accounts

A clinic that stops paying for CliniTech may enter a read-only state rather than having its data automatically deleted.

A clinic may separately contact CliniTech to request cancellation, closure, data access, or deletion.

Requests involving permanent deletion of clinical information will be handled subject to applicable legal and medical-record retention requirements.

12. Your Rights and Requests

Depending on applicable law and your relationship with CliniTech, you may have rights to request:

  • access to personal information;
  • correction of inaccurate information;
  • information about how your data is processed;
  • restriction or objection to certain processing;
  • deletion where legally permitted;
  • withdrawal of consent where processing is based on consent.

For information contained in a patient's clinical record, the relevant clinic will normally be the appropriate first point of contact because the clinic determines and manages the patient's healthcare record.

Requests concerning your CliniTech account or CliniTech's own processing may be sent to:

support@clinitech.app

We may need to verify the identity and authority of a person making a request before acting on it.

13. Children's Information

CliniTech is designed for use by healthcare organizations and authorized healthcare staff, not for independent use by children.

Clinics may nevertheless use CliniTech to maintain healthcare records relating to minor patients where permitted by applicable law.

The clinic is responsible for ensuring that information relating to minors is collected and processed lawfully.

14. Changes to this Privacy Policy

We may update this Privacy Policy as CliniTech develops, applicable laws change, or our service providers and data-processing activities change.

The updated version will be published on this page with a revised "Last updated" date.

Where required by law or where changes are material, we may provide additional notice.

15. Contact Us

Questions, privacy requests, or data-related concerns may be sent to:

CliniTech
Armenia
Email: support@clinitech.app

For questions relating to patient medical records, patients should generally contact the clinic responsible for their care first.