Privacy policy
Last updated: 25 August 2026
KlinikSuite designs and operates websites and patient-facing assistants for health and wellness clinics. This policy explains what data we handle, why, and what you can do about it.
Two different relationships are worth separating. If you are a clinic that hires us, we are the controller of your account data. If you are a patient of a clinic that uses our software, the clinic is the controller and we act as its processor: we handle that data on the clinic's instructions and not for our own purposes.
Who is responsible
KlinikSuite. Responsible parties: Angel Alberto Vladimir Aguilar Martinez and William Evans. You can reach us at hola@kliniksuite.com.
What data we handle
Depending on your relationship with us:
- Client clinics: practice name, contact details, domain, site content, booking hours, and credentials for the services you connect.
- Assistant conversations: the messages exchanged, the language, and — only if the person provides them — their name and a contact detail.
- Appointments: date and time, mode (in person or online), and the name, email or phone the person gives so the booking can be confirmed.
- Patient records (an optional feature a clinic switches on): name, contact, notes and documents the clinic itself uploads.
- Technical data: IP address and browser, recorded alongside document access so it can be audited.
Sensitive and health data
Records and documents a clinic uploads may contain sensitive personal data under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties. We handle them only on the clinic's instructions, with these specific measures:
- Documents are encrypted before storage (AES-256-GCM), not held in the clear.
- Every view, download, upload and deletion is recorded with who, when, from which IP and with which browser.
- The AI assistant has no access to patient records or documents. They are outside its technical reach, so it cannot read them or quote them in a conversation.
- Our support staff have no routine access. An emergency access path exists which requires a written reason to be recorded before a file can be opened, and that reason is stored with the log entry.
What we use data for
We do not sell personal data. We do not use it for advertising. We do not train AI models on patient data or on conversations.
- Running the clinic's site and assistant: answering questions, booking and rescheduling appointments.
- Sending confirmations, reminders and calendar invitations.
- Supporting the clinic and fixing faults.
- Meeting legal obligations.
Who we share it with
Only the providers needed to run the service, and only the data each one needs:
- Vercel — site hosting and file storage.
- Neon — database.
- Anthropic — the language model that answers in the chat. It receives the conversation message; it does not receive patient records or documents.
- Resend — sending confirmation and notification emails.
- Meta (WhatsApp Business) — only if the clinic switches on WhatsApp.
- Google — only if the clinic connects its calendar; see the next section.
Google Calendar data
If a clinic chooses to connect its Google calendar, this is the part to know precisely:
- We request the availability (freebusy) scope. That scope returns busy and free intervals only.
- We cannot read event titles, guests, notes or attachments. That is a technical limit rather than a promise: the scope we request does not expose them.
- We use those intervals for one purpose: stopping the assistant from booking over an existing commitment.
- If event writing is also enabled, we create and update only the appointment events our system generates, marked as ours. We do not modify or delete events you created.
- The access token is stored encrypted and can be revoked at any time from your Google account settings or by asking us. Once revoked, we stop reading the calendar.
- We do not use Google Calendar data for advertising, do not sell it, do not transfer it to third parties, and do not use it to train models.
How long we keep it
We keep data while the clinic's account is active and while it remains necessary for the purposes described. Today we do not automatically delete conversations or appointments after a fixed period: they are kept until the clinic or you ask for deletion, or the account is closed.
We would rather state that than advertise a retention period the system does not enforce. If we implement automatic deletion, we will update this policy.
Your rights
You may request access to, correction of, cancellation of, or object to the processing of your personal data, and withdraw consent (ARCO rights under Mexican law). Write to hola@kliniksuite.com and we will respond.
If you are a patient of a clinic, please contact that clinic first: it is the controller of your record and we act on its instructions. If you write to us directly, we will help route your request.
You may also complain to the competent data protection authority.
International transfers
Our providers run servers outside Mexico, primarily in the United States. By using the service, the data described is processed on that infrastructure in accordance with this policy.
Changes to this policy
If we change this policy we will update the date in the header. Where a change is substantial, we will tell client clinics by email.
Contact
For anything about this policy or to exercise your rights: hola@kliniksuite.com.