Privacy Policy
At Clineevo (“Clineevo Clinical Solutions”, “we”, “our”, or “us”), we hold medical confidentiality, data sovereignty, and patient privacy to the highest professional standards. This Privacy Policy explains how our software processes, secures, and isolates practitioner records, patient registries, and clinical billing data.
1. Roles: Data Controller vs. Data Processor
In medical practice management, clarity of roles is essential:
- Healthcare Practitioner (You / “Data Controller”): You collect patient details during clinical consultations, determine clinical necessity, establish patient consent, and submit billing codes. You retain primary ownership and ethical custody of your patient records.
- Clineevo (“Data Processor” / “Service Provider”): Clineevo acts strictly as an automated data processor and technical infrastructure provider. We store, calculate, and format your billing runs solely in accordance with your instructions and these terms.
2. Information We Collect and Process
To deliver our rapid batch billing, recall notifications, and earnings analytics, Clineevo processes the following categories of data:
A. Practitioner Account Details
Your full name, registered professional email address, medical specialty, facility names, provider numbers, and account credentials (passwords are cryptographically salted and hashed; Clineevo staff cannot view them).
B. Patient Registry & Clinical Billing Records
Data you choose to input during encounters, including patient name, medical identifier / MRN, date of birth, Medicare / private health fund numbers, consultation dates, Medicare Benefits Schedule (MBS) / item codes, facility service fee percentages, and recall dates.
C. Financial & Subscription Data
Subscription status, invoices, and payment histories. All payment transactions are executed directly by Stripe, Inc.Clineevo never collects, stores, or processes raw credit or debit card numbers.
D. System Telemetry & Security Audit Logs
Timestamps of sign-ins, IP addresses, browser user-agent strings, and diagnostic error reports used solely to detect unauthorized access attempts, prevent credential abuse, and maintain high service availability.
3. How We Use Your Information
We process your information strictly for legitimate clinical, administrative, and contractual purposes:
- Providing the batch billing entry interface, facility yield splits, and doctor net payout analytics.
- Maintaining isolated patient directories and delivering diagnostic testing recall reminders.
- Verifying provider credentials and securing account access against unauthorized clinical intrusion.
- Processing Pro tier subscriptions and communicating essential system security notices or maintenance alerts.
- Complying with applicable statutory legal obligations and regulatory standards governing clinical software providers.
4. Technical Security & Multi-Tenant Isolation
Clineevo employs enterprise healthcare architecture designed to ensure zero cross-practitioner data leakage:
Cryptographic Row-Level Isolation: Every patient, consultation record, and billing item is tagged with a unique practitioner identifier. Database access security rules strictly reject any query that does not originate from the authenticated practitioner. No practitioner can query, view, or search records belonging to another doctor.
Encryption Standards: Data in transit is secured with Transport Layer Security (TLS 1.3). Data at rest in our cloud datastore is protected using AES-256 bit encryption.
Mandatory Email Authentication: New clinical accounts require verified email ownership before production billing and patient logs can be accessed, mitigating fraudulent registrations.
5. Sub-processors & Third-Party Service Providers
We engage select, highly vetted cloud sub-processors who meet strict confidentiality and security benchmarks:
| Sub-processor | Purpose | Compliance / Certification |
|---|---|---|
| Google Cloud Platform / Firebase | Cloud database, user authentication, and secure compute hosting. | ISO 27001, SOC 1/2/3, HIPAA-ready infrastructure. |
| Stripe, Inc. | Subscription billing and payment transaction tokenization. | PCI-DSS Level 1 Service Provider. |
6. Data Retention, Export, and Account Deletion
You retain complete control over your clinical information:
- Data Portability & Export: You may export your billing logs, encounter records, and patient lists at any time for local practice archiving or reporting.
- Account Deletion: Upon receiving a verified cancellation and account deletion request, Clineevo permanently removes or irreversibly anonymizes all active database records associated with your account, subject only to statutory tax or regulatory retention requirements.
- Practitioner Retention Obligations: Please note that healthcare practitioners are subject to independent legal duties (such as mandatory health record retention periods under state and federal law). You are responsible for exporting required clinical records prior to account termination.
7. Patient Inquiries & Access Requests
Because Clineevo is an automated software processor that does not maintain direct physician-patient relationships with your patients, any individual patient inquiries regarding access, corrections, or deletions of their health information are promptly redirected to their treating practitioner. We provide you with the administrative tools necessary to fulfill valid patient requests.
8. Policy Updates & Notification
We may periodically update this Privacy Policy to reflect advancements in our clinical software or amendments to applicable health data laws. When material changes occur, we will update the “Effective Date” at the top of this document and notify active practitioners via their registered email address or within the dashboard.
If you have questions, privacy requests, or require assistance regarding our data practices, please contact our Privacy & Security Team directly: