Privacy Policy

Effective date: September 3, 2026  ·  Last updated: September 3, 2026

This Privacy Policy describes how ClinicBot PH ("ClinicBot PH," "we," "us") handles information in connection with the ClinicBot PH service: an AI-powered Facebook Messenger assistant that clinics use to handle patient appointment booking, reminders, and related messages.

Note on legal status: ClinicBot PH generally acts as a data processor on behalf of the dental/medical clinics ("Clinics") that use our service — the Clinic is the data controller responsible for its patients' data and for its own privacy notice to patients. This policy covers ClinicBot PH's own handling of information as a processor and as the operator of this website/service.

1. Who this policy covers

2. What information we process

On behalf of Clinics (as processor), from Patients via Messenger:

From Clinics directly (as their own data, for our own service operation):

We do not ask the assistant to collect or process clinical/diagnostic information — the system is explicitly designed to escalate any medical question, symptom description, or emergency to clinic staff rather than storing or acting on it.

3. How information is used

We do not sell patient or Clinic data, and we do not use patient conversation data to train third-party AI models beyond what's needed to generate that specific reply.

4. Where information is stored, and sub-processors

Each Clinic's booking data lives in that Clinic's own Google Sheet — the Clinic can see and directly edit it at any time. ClinicBot PH's automation runs on infrastructure hosted with the following sub-processors:

5. Data retention

Appointment records are retained for 12 months before being moved to an archive tab within the Clinic's own Sheet. Conversation history is retained for 12 months by default and can be deleted earlier at the Clinic's request.

6. Patient rights

Patients should direct requests about their personal data (access, correction, deletion) to the Clinic they messaged, since the Clinic is the data controller. Clinics can contact ClinicBot PH for assistance fulfilling such requests where our systems are involved.

7. Security

We use industry-standard measures appropriate to the scale of the service (encrypted connections/HTTPS, access-controlled infrastructure, secret-based authentication between system components) to protect data in transit and at rest. No system is perfectly secure, and we will notify affected Clinics promptly in the event of a data breach affecting their data.

8. Changes to this policy

We may update this policy as the service evolves. Material changes will be communicated to Clinics directly.

9. Contact

Questions about this policy: hello@clinicbot-ph.com

This policy is being actively finalized alongside the product. A Philippine-licensed lawyer review is planned before this is relied on for a Meta App Review submission or before real patient data flows at scale.