Privacy Policy
Last updated: July 2, 2026
Your privacy matters to us. This policy describes what data we collect, why we collect it, and the choices you have.
1. Overview
This Privacy Policy explains how MediBook ("we", "us") collects, uses, shares, and protects information when clinics and their patients use our platform. We act as a data processor on behalf of clinics for patient data, and as a data controller for clinic account data.
2. Information We Collect
- Clinic account data: clinic name, email, phone, address, and login credentials.
- Doctor data: name, specialization, contact details, and login credentials set by the clinic.
- Patient data: name, phone number, age, gender, and (optionally) email, provided during booking.
- Appointment data: selected doctor, date, time, and booking status.
- Usage data: messages exchanged with the AI agent, credit transactions, and basic technical logs.
3. How We Use Information
- To provide the booking service and operate clinic, doctor, and patient features.
- To verify identity via one-time passcodes sent by SMS or email.
- To process credit purchases and maintain transaction records.
- To send appointment confirmations and service-related notifications.
- To maintain security, prevent fraud, and improve the reliability of the Service.
4. Verification & Communications
We use third-party providers to send one-time verification codes (via SMS) and transactional emails. Phone numbers and emails are used only to deliver these messages and to identify returning patients. We do not sell personal data or use it for unrelated marketing.
5. AI Processing
Conversations with the booking agent are processed by third-party AI providers to understand requests and generate responses. Messages are used solely to fulfil the booking interaction and are not used to train third-party models without appropriate safeguards.
6. Data Sharing
- With the relevant clinic, whose patients and appointments are being managed.
- With service providers who help us operate the platform (payment processing, SMS/email delivery, AI processing, cloud hosting), under confidentiality obligations.
- When required by law, regulation, or valid legal process.
- We do not sell or rent personal information to third parties.
7. Data Security
We protect data using industry-standard measures including encrypted passwords, JWT-based authentication, per-clinic data isolation, and HTTPS-ready transport. No system is perfectly secure, but we work to safeguard your information and to promptly address any vulnerabilities.
8. Data Retention
We retain clinic and appointment data for as long as an account is active or as needed to provide the Service and meet legal obligations. Clinics may request deletion of their data, subject to any records we are legally required to keep.
9. Your Rights
- Access, correct, or update your account information.
- Request deletion of personal data, subject to legal retention requirements.
- Object to or restrict certain processing where applicable law provides such rights.
- Patients may contact the relevant clinic to exercise rights over their booking data.
10. Children's Privacy
The Service is intended for use by clinics and adult patients or guardians booking on behalf of minors. We do not knowingly collect data directly from children without appropriate consent from a parent or guardian.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated through the dashboard or by email. The "Last updated" date reflects the most recent revision.
12. Contact
For privacy questions or data requests, contact us at support@medibook.app.