This service is operated from Tunisia. This policy is written to comply with the EU General Data
Protection Regulation (GDPR) for personal data belonging to individuals in the European Union, regardless
of where CliniqoAI itself is established (see section 6). The
French version is the legally authoritative one in case of any
discrepancy.
1. Who is responsible for your data?
This policy distinguishes two situations, since they carry different responsibilities under the GDPR:
- Visitors to cliniqoai.com (contact form, booking a call, demo chat widget):
CliniqoAI (site publisher, see our
legal notice) acts as data controller.
- Patients and leads of a client clinic, whose messages are processed by the CliniqoAI AI
assistant deployed on that clinic's behalf (the clinic's own website, WhatsApp, Instagram, Messenger):
the client clinic is the data controller, and CliniqoAI acts as a data
processor under a data processing agreement signed with each clinic. If you are a patient of a
clinic using CliniqoAI, please exercise your rights with that clinic first.
2. Data collected on the marketing site
When you visit cliniqoai.com or contact us, we collect:
- Information you voluntarily provide (name, email, phone, message) via the contact form or booking request;
- The content of your exchanges if you try the demo chat widget on the site;
- Technical browsing data (IP address, browser type) via the cookies described in section 7.
3. Data processed through the product, on behalf of client clinics
When a clinic deploys CliniqoAI on its website, chat widget, or WhatsApp, Instagram and Messenger
channels, the AI assistant processes, on that clinic's behalf:
- The content of conversations between the patient/lead and the AI assistant;
- Contact details voluntarily shared by the patient/lead (name, phone, email) so they can be reached back;
- The content of the knowledge base configured by the clinic (its treatments, pricing, availability).
CliniqoAI does not determine the purposes of this processing: these are defined by each client clinic for
its own patient front-desk and qualification needs.
4. Purposes of processing
- Responding to your contact or demo requests;
- Qualifying a request and routing a lead toward booking, on behalf of the relevant clinic;
- Operating, securing and improving the Service;
- Meeting our legal and accounting obligations (invoicing, record-keeping).
5. Legal basis
Depending on the case: your consent (chat widget, non-essential cookies), performance of pre-contractual
steps or of a contract (responding to a demo request, providing the Service to a client clinic), or our
legitimate interest, or that of the client clinic, in providing an effective patient front-desk.
6. Recipients and processors
Depending on the feature used, your data may be shared with the following third parties:
- Meta Platforms, Inc. — when a clinic connects WhatsApp Business, Instagram or
Messenger, messages flow through Meta's official APIs under Meta's own terms and privacy policy.
- AI provider(s) — by default, the CliniqoAI assistant relies on OpenAI
as its language-model provider. Each clinic can, however, configure a different provider from its
assistant's configuration area, in which case that provider processes messages on its behalf. Only the
content strictly necessary to generate a reply is sent to whichever provider is configured; it is not
used by CliniqoAI for any purpose beyond providing the Service.
- DigitalOcean — our hosting provider, for storing and running the Service (see our
legal notice).
- Booking tools — Calendly today; Doctolib and Google Calendar once that integration is
available, only if the clinic enables that connection.
CliniqoAI is based in Tunisia. CliniqoAI's own processing of personal data belonging to patients or leads
residing in the European Union is therefore itself a transfer of data outside the EU, separate from any
transfer to our sub-processors. This transfer is governed, in the same way as transfers to our
sub-processors located outside the EU (in particular our default AI provider, based in the United
States), by the Standard Contractual Clauses (SCCs) adopted by the European Commission, or by any other
GDPR-recognized equivalent transfer mechanism (an adequacy decision, or the EU–U.S. Data Privacy
Framework where applicable for our U.S.-based sub-processors). CliniqoAI commits to putting these
safeguards in place under the data processing agreement signed with each EU-based client clinic (see
section 1), and to verifying that its own sub-processors provide appropriate safeguards before going into
production. Our hosting (DigitalOcean, Frankfurt/FRA1 region) is physically located within the European
Union: it is CliniqoAI's own location, not that of the hosted data, that this transfer mechanism
concerns.
7. Cookies and local storage
This site uses:
- Strictly necessary local storage (language choice, cookie-consent choice) which does not require prior consent;
-
A non-essential third-party script/cookie (the Chatbase chat widget), loaded only after you consent via
the banner shown on your first visit. You can change your choice at any time by clearing your browser
data for this site.
8. Retention periods
- Marketing-site contact data (form, demo): retained for 3 years from last contact, absent an ongoing business relationship.
-
Conversations and contact details processed on behalf of a client clinic: because of CliniqoAI's
architecture, where each clinic runs its own dedicated instance, this data is retained for as long as
the clinic's instance remains active. The instance stays active as long as the clinic keeps up with the
infrastructure costs described in our Terms of Service. If the Service is
discontinued — whether at the clinic's request or for non-payment of those costs — the instance is
deactivated and the data tied to it is deleted along with it: CliniqoAI, acting as processor, does not
retain this data beyond the lifecycle of the clinic's instance. It's the clinic's responsibility, as
controller for its own patients' data, to request an export before the Service is discontinued if it
wants to keep that data.
- Billing data: retained for the period required by applicable accounting regulations.
9. Your rights
Under the GDPR, you have the following rights over your personal data:
- Right of access and rectification;
- Right to erasure ("right to be forgotten");
- Right to restriction of processing;
- Right to data portability;
- Right to object, for processing based on legitimate interest;
- Right to set directives on what happens to your data after death.
If you are a patient of a client clinic, please direct your request to that clinic first, as the data
controller. For any other request, contact us at: [email protected]. We commit to
responding within one month. You also have the right to lodge a complaint with the relevant data
protection authority in your country — in France, the
CNIL.
10. Security
We implement reasonable technical and organizational measures to protect your data against unauthorized
access, loss or alteration, including encrypted communications and per-clinic data isolation.
11. Changes to this policy
This policy may be updated to reflect changes to the Service or applicable regulation. The last-updated
date appears at the top of this page.
12. Contact
For any question about this policy: [email protected]