This Privacy Policy describes how ClinicBot PH ("ClinicBot PH," "we," "us") handles information in connection with the ClinicBot PH service: an AI-powered Facebook Messenger assistant that clinics use to handle patient appointment booking, reminders, and related messages.
Note on legal status: ClinicBot PH generally acts as a data processor on behalf of the dental/medical clinics ("Clinics") that use our service — the Clinic is the data controller responsible for its patients' data and for its own privacy notice to patients. This policy covers ClinicBot PH's own handling of information as a processor and as the operator of this website/service.
1. Who this policy covers
- Clinics that sign up for ClinicBot PH ("Clinic," "you," if you're a clinic).
- Patients who message a Clinic's Facebook Page that uses ClinicBot PH ("Patients," "you," if you're a patient).
- Visitors to ClinicBot PH's own website/marketing materials.
2. What information we process
On behalf of Clinics (as processor), from Patients via Messenger:
- Facebook Page-scoped identifiers needed to reply to the right person (not a patient's general Facebook profile).
- Message content sent to the Clinic's Page (e.g., appointment requests, questions).
- Appointment details the patient provides: name, phone number, requested service, date/time preferences, and optional notes if volunteered.
- Booking history: holds, confirmations, cancellations, reschedules, and no-show records, stored in the Clinic's own Google Sheet, which the Clinic controls and can view or edit directly.
From Clinics directly (as their own data, for our own service operation):
- Clinic name, contact details, and business information needed to operate the service and bill for it.
- Configuration data the Clinic enters (services, hours, pricing, policies) used to power the assistant's responses to their patients.
We do not ask the assistant to collect or process clinical/diagnostic information — the system is explicitly designed to escalate any medical question, symptom description, or emergency to clinic staff rather than storing or acting on it.
3. How information is used
- To operate the booking assistant: understanding a patient's request, checking availability, placing holds, confirming/cancelling/rescheduling appointments, and replying to the patient.
- To send appointment reminders and no-show follow-ups via SMS (not Messenger, to stay within Meta's messaging policy windows).
- To route anything outside the assistant's scope (emergencies, complaints, insurance questions, medical records requests) to Clinic staff for a human response.
- To operate, maintain, and improve the ClinicBot PH service itself (e.g., diagnosing errors, monitoring uptime).
We do not sell patient or Clinic data, and we do not use patient conversation data to train third-party AI models beyond what's needed to generate that specific reply.
4. Where information is stored, and sub-processors
Each Clinic's booking data lives in that Clinic's own Google Sheet — the Clinic can see and directly edit it at any time. ClinicBot PH's automation runs on infrastructure hosted with the following sub-processors:
- Google (Google Sheets / Google Workspace) — stores each Clinic's booking data and configuration.
- Anthropic (Claude AI models) — processes message text to generate the assistant's replies.
- An SMS gateway provider — sends appointment reminder and no-show SMS messages to the phone numbers patients provide. Final provider selection is in progress; this section will be updated with the named provider once confirmed.
- Vultr — hosts the server infrastructure that runs the booking automation, currently in Tokyo, Japan. Patient data leaving the Philippines is disclosed here as a cross-border data transfer.
- Meta (Facebook Messenger Platform) — the channel patients use to message the Clinic; Meta's own data policy applies to that platform layer.
5. Data retention
Appointment records are retained for 12 months before being moved to an archive tab within the Clinic's own Sheet. Conversation history is retained for 12 months by default and can be deleted earlier at the Clinic's request.
6. Patient rights
Patients should direct requests about their personal data (access, correction, deletion) to the Clinic they messaged, since the Clinic is the data controller. Clinics can contact ClinicBot PH for assistance fulfilling such requests where our systems are involved.
7. Security
We use industry-standard measures appropriate to the scale of the service (encrypted connections/HTTPS, access-controlled infrastructure, secret-based authentication between system components) to protect data in transit and at rest. No system is perfectly secure, and we will notify affected Clinics promptly in the event of a data breach affecting their data.
8. Changes to this policy
We may update this policy as the service evolves. Material changes will be communicated to Clinics directly.
9. Contact
Questions about this policy: hello@clinicbot-ph.com