Privacy Policy
Last updated: May 28, 2026
CliniqHQ ("CliniqHQ," "we," "us," or "our") provides a cloud-based clinic management platform for healthcare providers and their patients. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit cliniqhq.com, use our applications, or otherwise interact with our services (collectively, the "Services").
1. Who this policy applies to
This policy applies to:
- Clinic staff and administrators who use the CliniqHQ staff portal
- Patients who use clinic-branded patient portals powered by CliniqHQ
- Visitors to our marketing website
- Individuals who connect third-party integrations such as Google Calendar
2. Information we collect
Account and clinic information. Name, email address, phone number, clinic name, role, billing details, and credentials you provide when registering or managing a clinic account.
Patient health information (PHI). When clinics use CliniqHQ, we process patient demographics, appointments, medical records, prescriptions, billing, and other health-related data on behalf of the clinic. Clinics are the data controllers for patient data; CliniqHQ acts as a data processor/service provider.
Usage and device data. IP address, browser type, device identifiers, pages viewed, actions taken in the product, and diagnostic logs used to secure and improve the Services.
Communications. Support requests, emails, and messages you send to us.
Payment information. Processed by our payment partners. We do not store full card numbers on our servers.
3. How we use information
- Provide, operate, maintain, and improve the Services
- Authenticate users and enforce role-based access controls
- Schedule appointments, manage records, billing, and clinic workflows
- Send transactional notifications (appointments, reminders, account alerts)
- Provide optional integrations such as Google Calendar sync
- Generate AI-assisted clinical documentation when enabled by the clinic
- Monitor security, prevent fraud, and comply with legal obligations
- Respond to support requests and communicate product updates
4. Google Calendar integration
If a clinic chooses to connect Google Calendar, CliniqHQ uses Google OAuth to access the connected Google account's calendar with the calendar.events scope.
What we access: Permission to create, read, update, and delete calendar events on calendars the user can access through that Google account.
How we use it: Solely to sync confirmed clinic appointments (patient name, time, duration, doctor, and related appointment details) to the calendar the clinic staff member connected. We do not use Google Calendar data for advertising, profiling, or unrelated purposes.
Storage: We store an encrypted OAuth refresh token and the Google Calendar event ID linked to each appointment. We do not store the contents of unrelated personal calendar events.
Your controls: Clinics can disconnect Google Calendar at any time from Settings → Integrations. Disconnecting stops future sync. You may also revoke CliniqHQ's access from your Google Account permissions.
CliniqHQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. AI features
When enabled, AI features (such as medical scribe and documentation assistance) may process consultation inputs to generate structured notes. Clinics control whether and how these features are used. We use third-party AI providers under contractual terms that restrict use of submitted data for training unrelated models where applicable.
6. How we share information
We do not sell personal information. We may share information with:
- Cloud infrastructure and hosting providers (e.g., Google Cloud) under data protection agreements
- Communication providers (SMS, email, WhatsApp) to deliver clinic-configured notifications
- Payment processors for subscription billing
- Professional advisors or authorities when required by law or to protect rights and safety
- A successor entity in connection with a merger, acquisition, or asset sale, subject to this policy
Each clinic's patient data is logically isolated in our multi-tenant architecture and is not shared with other clinics.
7. Data retention
We retain account and clinic data for as long as the subscription is active and as needed to provide the Services. Clinics may export data before account closure. We may retain limited records as required for legal, security, or backup purposes, then delete or anonymize them in accordance with our retention schedule.
8. Security
We implement administrative, technical, and organizational measures including encryption in transit (TLS), encryption at rest for sensitive credentials, role-based access control, tenant isolation, and audit logging. See our Security page for more detail.
9. International transfers
CliniqHQ is operated from India. Your information may be processed in India and other countries where our service providers operate. We take steps to ensure appropriate safeguards for cross-border transfers.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal information, or to object to certain processing. Patients should contact their clinic directly for health record requests; clinics may coordinate with us as needed.
To exercise rights related to your CliniqHQ account, email privacy@cliniqhq.com.
11. Children
The Services are not directed to children under 13. Patient records for minors are managed by clinics and guardians through the clinic's use of the platform.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may be communicated by email or in-product notice.
13. Contact us
CliniqHQ
Email: privacy@cliniqhq.com
Website: https://cliniqhq.com