Back to home
Plain-language summary · Final legal version coming soon

Privacy notice.

This page summarizes, in plain English, how CliniVox handles data. The legally binding version sits alongside your Business Associate Agreement; if anything below conflicts with that document, the BAA governs.

Last updated September 21, 2026.

What we collect

From your dental practice: organization name, billing contact, team member emails, the API credentials needed to talk to your PMS, and any phone numbers you forward to CliniVox.

From your patients (on your behalf): call audio, transcripts, callback numbers, names, dates of birth as needed to look them up in your PMS, and the appointments they ultimately book. We hold this as your Business Associate. It never leaves your organization.

From your browser: on your dashboard we record device type, IP address, and page interactions so we can keep the product working. On our public marketing pages we also use Google Analytics, which sets a cookie to count visits. We do not run advertising or retargeting cookies, and we do not sell traffic data.

How we use it

To answer calls, take messages, and write appointments into your PMS. That's what you signed up for.

To run the campaigns and SMS flows you configure inside your organization.

To support your team when you contact us. Support reps see only what they need; impersonation sessions are logged and visible to you in your audit log.

We do not train shared AI models on your patient data. Voices and scripts are configured per-organization; the underlying speech models are general-purpose and frozen at version release.

How we protect it

Patient data is encrypted at rest with per-organization keys. Decryption only happens inside CliniVox services that need it (the conversation engine, the PMS sync, the dashboard you log into).

CliniVox does not hold your practice management credentials. We read and write your schedule through NexHealth, our integration partner, which handles patient data on our behalf under a signed business associate agreement. For server-based systems their Synchronizer runs at your office and connects outbound; your server never opens to the internet.

We host in US cloud regions. Patient data does not leave the United States. Backups are encrypted and retained for 30 days.

Your rights and your patients' rights

You own your data. Export everything (calls, transcripts, campaigns, contacts) at any time from the Settings page or the API.

Your patients have the rights HIPAA grants them: access, correction, portability, deletion. Forward any request to us and we'll honor it within 30 days.

Cancel anytime. After cancellation, your organization is retained for 60 days (so you can reactivate) then permanently deleted, including backups, within 90 days unless legally required to keep it.

Sub-processors

We use a small set of vendors to deliver CliniVox: cloud hosting, AI model providers for speech and language, a telephony carrier, a payments processor, a transactional email service, a scheduling tool for booking demos with our team, and a web analytics provider for our public marketing pages only.

Our analytics provider is Google Analytics, and it runs only on our public clinivox.ai marketing pages. It is not loaded on your dashboard and it is not loaded on the patient booking page we host for your practice. It never receives patient data and it is not a business associate.

Every sub-processor that touches PHI signs a Business Associate Agreement with us before handling any data. Email hello@clinivox.ai for the current list; we'll notify you at least 14 days before adding one that processes PHI.

Questions?

Email hello@clinivox.ai and a human will get back to you.