Privacy policy
Last updated: 6 August 2026
Draft pending legal review. This policy describes how the product actually works today and is written to be accurate, but it has not yet been reviewed by a qualified lawyer in your jurisdiction. Do not rely on it as legal advice.
NaetCare provides clinic-management software for NAET practitioners. This policy explains what personal data flows through the service, who processes it, and what rights people have. It covers three different groups of people, and the answers differ for each: website visitors, clinic staff who hold an account, and patients of those clinics.
1. Our role: controller vs processor
This distinction matters, because it determines who you go to about your data.
- For patient data, the clinic is the data controller and NaetCare is a processor. The clinic decides what to record about a patient and why. We store and process it on the clinic's instructions, and we do not use it for our own purposes. If you are a patient, your relationship is with your clinic — contact them first, and we will support them in responding to you.
- For clinic-staff accounts and website visitors, NaetCare is the controller. We decide how account and enquiry data is handled, and you can contact us directly.
2. What we collect
Website visitors
The marketing site at naetcare.com runs no analytics, no advertising trackers, and sets no tracking cookies. The only browser storage we use is a single entry recording your language choice (English or Arabic) so the site remembers it on your next visit. It stays on your device.
If you submit the “Book a demo” form, we receive the name, clinic name, email address, phone number and message you type, and we use them solely to reply to you.
Clinic staff (account holders)
Name, email address, password (stored only as a cryptographic hash — we never see or store your actual password), role and permissions within the clinic, optional profile details, and session and security records such as sign-in times and two-factor settings. We also keep an audit log of significant administrative actions.
Patients (entered by the clinic)
Whatever the clinic chooses to record, which typically includes: name, reference code, contact details, date of birth, gender, occupation, address, chief complaint, appointment and visit history, treatment and payment records, uploaded documents, and free-text notes.
It also includes health-related information — muscle-test results per allergen, which items are reactive or cleared, and any clinical notes. In the UK/EU this is “special category” data and receives additional protection. NaetCare never sells, shares, or repurposes it, and does not use it to train any AI model.
Voice recordings
If a practitioner uses voice auto-fill, the audio is transcribed so the results grid can be pre-filled. See the AI section below for exactly where that audio goes.
3. How we use data
- To provide the service: storing records, showing them back, generating share links.
- To authenticate users and keep accounts secure.
- To send transactional email (invitations, password resets, notifications).
- To reply to demo requests and support enquiries.
- To diagnose faults and keep the service reliable and secure.
We do not sell personal data, use patient data for advertising, or train AI models on your or your patients' data.
4. AI processing
Two optional features send data to OpenAI: transcription (audio dictated by the practitioner, processed by Whisper) and extraction (the resulting text plus your clinic's allergen catalogue, processed by GPT-4o-mini to map spoken phrases onto catalogue items). Translation of patient-facing text uses the same model.
We send the minimum required: dictated audio or text and the catalogue labels. We do not send patient names, contact details or identifiers. OpenAI processes this under its API terms, which state that API data is not used to train its models. Output is always reviewed by the practitioner before anything is saved — the AI never makes a clinical decision. A clinic that prefers not to use AI at all can leave voice auto-fill switched off, and no audio or text is sent anywhere.
5. Patient share links
Practitioners can generate a public link to share progress with a patient. These links are designed to reveal as little as possible:
- The address contains a long, randomly generated, unguessable token.
- Every link has an expiry date, and can be revoked at any time by the clinic.
- The page shows the patient's first name only.
- Clinical detail and financial detail are off by default — the practitioner must deliberately switch each on.
- Internal notes are never shown.
Anyone holding the link can open the page without signing in, so it should be sent only to the patient. Links are excluded from search engine indexing, but we cannot control onward sharing by the recipient.
6. Who else processes data (sub-processors)
| Provider | Purpose | Data involved |
|---|---|---|
| Neon | Managed PostgreSQL database | All application records |
| Google Cloud Platform | Application hosting (Cloud Run) and file storage | All application data; uploaded documents and images |
| Cloudflare | Website and app delivery, DNS, DDoS protection | Traffic metadata such as IP address |
| OpenAI | Voice transcription and result extraction | Dictated audio/text and allergen catalogue labels |
| Resend | Transactional and enquiry email | Recipient address and message content |
Application servers run in the European Union (Google Cloud, Belgium). Some providers above operate globally, so data may be processed outside your country under the transfer safeguards in their terms.
7. Security
- All traffic is encrypted in transit with HTTPS/TLS.
- Passwords are stored only as salted hashes.
- Each clinic's data is isolated: every request is scoped to the signed-in user's clinic, so one clinic can never read another's records.
- Access within a clinic is further restricted by per-user permissions — for example, practitioners without finance permission are not served prices at all.
- Administrative accounts can require two-factor authentication.
- Uploaded files are served through short-lived signed URLs, not public links.
No system is perfectly secure. If we become aware of a breach affecting personal data, we will notify affected clinics without undue delay.
8. Retention
Clinic and patient records are kept for as long as the clinic maintains its account, because the clinic decides its own retention needs and may be under professional record-keeping obligations. A clinic can delete individual records at any time. When an account is closed, we delete or irreversibly anonymise its data within 90 days, except where we must retain something to meet a legal obligation. Demo enquiries are kept only as long as needed to follow up.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing.
- Patients: contact your clinic. They control your record and can action most requests directly in the app; we assist them where needed.
- Clinic staff: contact us using the details below.
You also have the right to complain to your local data protection authority.
10. Children
NaetCare accounts are for practitioners and clinic staff, and are not offered to children. Clinics may treat and record data about patients who are minors; where they do, the clinic is responsible for obtaining any consent required by law.
11. Not a medical device
NaetCare is a record-keeping and patient-communication tool. It does not diagnose, treat, or make clinical recommendations, and it is not a medical device. Clinical decisions remain entirely the practitioner's.
12. Changes
If we make a material change to this policy we will update the date above and notify account holders by email or in the app.
13. Contact
Questions about this policy or about your data: hello@naetcare.com.