Clinic Context — Privacy Policy
Effective September 23, 2026.
1. Who is responsible and what this policy covers
Wise Guys Technologies Inc., 4388 Rue Saint-Denis Suite 200 #622, Montreal, QC H2J 2L1, Canada, operates Clinic Context. Our Privacy Officer handles questions, requests, and complaints at privacy@clinicontext.com, or by mail at that address, marked "Privacy Officer".
This policy explains how we handle personal information in connection with our platform, business accounts, website analysis and editing, hosting, and support. Although our customers are clinics and healthcare businesses, information about account holders, staff members, and website visitors can be personal information.
For account administration, platform security, billing, our own support, and our own AI development and training, we determine the purposes of processing. When we handle permitted website content on a Customer's instructions to deliver the requested service, the Customer determines its purposes and we act as its service provider, subject to the applicable agreement and law. Separate data-processing terms may be required.
A clinic's own privacy notice explains its separate practices, including its patient-care and booking services. Our policy does not replace that notice. You may contact us about our own handling of your information even where a clinic is also responsible.
2. No patient information
Clinic Context is not a medical-record, patient-intake, booking, or emergency communication service. Customers and users must not submit patient information, including identifiable patient details, appointment requests identifying a patient, medical histories, diagnoses, treatment information, insurance information, or identifiable patient testimonials or images. This prohibition applies to imports, forms, website content, AI prompts, support messages, and attachments, even if the information was previously made public.
If you believe patient information has reached us, contact our Privacy Officer without including it in the initial message. We will assess the situation, restrict unnecessary access, and arrange appropriate removal or other legally required handling. A prohibition does not mean accidental collection is technically impossible or remove our obligations when it occurs.
3. Information we handle and why
Depending on the features used, we handle the following categories:
| Category and source | Examples | Purpose |
|---|---|---|
| Account and business information provided by users | Name, email, business identity, account identifiers, role, profile settings, and authentication information | Create accounts, authenticate users, manage permissions, and communicate about the service |
| Website information supplied by Customers or collected from public pages | URLs, page text and images, business contact details, professional profiles, metadata, and website configuration | Analyse, migrate, edit, publish, host, and monitor websites |
| AI feature inputs and outputs | Editing instructions, relevant page content, analysis evidence, generated text, and recommendations | Perform the requested analysis or editing feature, retain results in the workspace, and develop Clinic Context's own AI systems as described in section 4 |
| Support information provided by users | Name, reply email, issue description, correspondence, and optional attachments | Investigate problems and respond to requests |
| Subscription and billing information | Selected plan and currency, subscription status, billing contact details, invoices, and limited payment-method information where collected | Administer paid services, payments, and accounting |
| Technical information received during use | IP address, browser or device information, request times, requested resources, errors, and security events | Deliver content, diagnose failures, protect accounts, and prevent abuse |
| Browser-stored information | Session information, preferences, workspace state, and locally saved reports | Maintain sign-in, remember choices, and support the interface |
Payments are processed through Stripe checkout and its billing portal. We receive subscription, invoice, payment-status, and billing contact information needed to administer the service. Payment-card information is entered through Stripe's checkout or billing interface.
Our website-analysis features retrieve public pages and may use public search results and business listings. Public availability does not mean information is exempt from privacy protection. Contact our Privacy Officer about personal information appearing in a report.
We use information for the purposes described above, required legal compliance, and handling claims. Where applicable law requires consent, we obtain it for the relevant purpose. We will not treat acceptance of our Terms as consent to unrelated marketing or unrelated uses of personal information. Required account information is necessary to provide the corresponding service; optional attachments and other optional information need not be supplied.
4. AI processing
We use OpenAI for AI-assisted website analysis, recommendations, and editing. Relevant page content, your instructions, and supporting information can be transmitted to OpenAI to perform the requested feature. Some analysis features use web search, which can disclose search queries containing clinic or website information to the search functionality and its providers.
Under the standard Terms, Clinic Context may also use permitted customer website content to develop and train its own AI systems. This is a separate purpose from delivering a requested analysis or edit. Customers must not provide patient information. We limit training use of personal information to what applicable law permits and handle requests concerning personal information in training data through our Privacy Officer. This statement concerns Clinic Context's own training, not OpenAI's training practices.
Do not include patient information, credentials, or unrelated confidential information in these inputs. AI outputs can be inaccurate; a Customer must review content before publishing or relying on it.
5. Who receives information
Information may be accessible to authorized personnel who need it for their duties and to providers performing the relevant functions. Our providers include:
| Provider | Function and relevant information |
|---|---|
| Cloudflare | Website and application delivery, hosting, storage, processing, security, and email sending; relevant content, technical request information, login codes, and support, publication, and audit notification contents |
| Supabase | Authentication, database services, and file storage; account and workspace records, reports, and support attachments |
| OpenAI | AI processing described in section 4 |
| Stripe | Subscription checkout, payment processing, billing portal, and invoices; billing contact, subscription, and payment information |
| Google Tag Manager and Google Analytics | Optional analytics and tags loaded on the Clinic Context platform after the visitor accepts optional cookies; usage and technical information associated with those tools |
Account or workspace administrators and authorized team members may see information within their permitted access. Information published on a Customer's website becomes public. Reports designated as public or shareable may be accessible to anyone with the link; a hard-to-guess link is not a confidentiality guarantee.
We may disclose information where required or permitted by law, including to address a valid legal demand, protect rights or safety, or investigate unlawful activity. A business transfer may involve limited disclosure subject to applicable legal safeguards. This does not authorize unrestricted reuse.
6. Processing outside Québec and Canada
Our providers and their authorized personnel may process information outside Québec and Canada. Information processed abroad may be accessible to courts or authorities under local law.
We do not promise that all information remains in Canada. Choosing Montréal for contractual disputes does not restrict an individual's mandatory privacy rights or access to a competent regulator.
7. Cookies, local storage, and external content
The platform uses browser storage for sign-in sessions, preferences such as pricing currency, workspace information, reports saved in the browser, and your optional-cookie choice. Some information persists after a browser window closes until it expires or is cleared. Clearing browser storage can sign you out or remove locally saved information; it does not by itself delete server records. With your permission, Google Tag Manager loads Google Analytics and may load other configured tags. You can reject optional cookies or change your choice through the site's cookie settings.
Hosted clinic websites may have different tracking settings, consent tools, and third-party integrations chosen by the clinic. Those choices must be disclosed in the clinic's notice and managed through the site's available controls. A tracking feature supported by our software is not necessarily enabled on our own platform or on every clinic site.
External content, such as embedded images or maps, can cause your browser to contact the content provider and disclose technical information. Following an external link places you under that service's practices.
8. Retention and deletion
We retain information only for a documented purpose and the applicable period. The following schedule applies when a paid website subscription ends:
| Information | Retention or deletion rule |
|---|---|
| Website hosting and customer retrieval access | End with the current paid subscription period |
| Affected website content, uploads, and revisions in active systems | Deletion begins at expiry and is completed within 90 days after expiry |
| Residual backup copies of that content | Expire within 90 days after the same subscription expiry date; access remains restricted and they are not used for ordinary business purposes |
| Billing and tax records | Retained for the legally required period, generally six years after the last tax year to which they relate, and longer where required |
| Records needed for a legal obligation or claim | Only the necessary records, retained for the applicable purpose and period, then deleted |
There is no additional customer retrieval window during the deletion process. Customers must retrieve content before expiry. If other subscriptions remain active, information necessary for those services may be retained. Relevant deletions are reapplied if a backup is restored for disaster recovery.
Other non-required information associated solely with the ended subscription, including its reports and support records, is deleted within 90 days after that subscription ends. Information needed for an active account or another active subscription remains until its own purpose or applicable period ends. Account records, security logs, consent records, and incident records are retained for their documented business or legal purposes, then securely deleted or anonymized. Records required for legal or accounting purposes may be kept for the applicable period.
Copies held independently in your browser, downloaded files, third-party search indexes, or other people's systems are outside our direct deletion control. This does not remove our duty to instruct providers under our control as applicable.
9. Security and incidents
We use administrative and technical measures appropriate to the information and risks, including authentication and access restrictions. Access must be limited to people who need information for the relevant purpose. No system can guarantee absolute security.
If an incident affects personal information, we will assess and address it and notify individuals and authorities where required by applicable law. Report suspected incidents to our Privacy Officer. Do not email sensitive evidence until a suitable method has been arranged.
10. Your rights and choices
Depending on applicable law, you may request access to your personal information, correction, a copy in a usable electronic format, deletion or restriction in applicable circumstances, and information about its sources, recipients, and retention. You may withdraw consent where processing is based on consent, subject to lawful limits; we will explain effects on the affected service. Withdrawal does not automatically invalidate earlier lawful processing.
Contact privacy@clinicontext.com with enough information to locate your records. We may request proportionate identity verification or proof of authority. Do not send identity documents unless requested through an appropriate method. We will respond within the applicable legal deadline and explain any lawful refusal and available recourse. Where we act only on a clinic's instructions, we may direct the request to that clinic and assist it as required.
You may complain directly to a competent authority, including the Commission d'accès à l'information du Québec or, where applicable, the Office of the Privacy Commissioner of Canada. You do not have to complete our contractual dispute process before exercising this right.
11. Individuals outside Canada
Offering business services internationally does not remove local privacy protections. Where the GDPR, UK GDPR, or another privacy law applies, we will honour the rights and obligations it provides. These can include rights to object, restrict processing, request erasure or portability, and complain to a local supervisory authority.
12. Changes and contact
We will publish an updated policy and effective date when our practices change and provide appropriate notice of material changes. Where a new purpose requires consent, we will obtain it before that use. An update does not itself authorize an incompatible use of information already collected.
Privacy Officer — Wise Guys Technologies Inc.
privacy@clinicontext.com
4388 Rue Saint-Denis Suite 200 #622
Montreal, QC H2J 2L1, Canada