Legal
Privacy policy
What this website collects, what we do with it, and what you can ask us to do. Written to be read, not skimmed.
1. What this policy covers
This policy covers healdesk.io and the people who use it: clinic owners and staff considering healdesk, and anyone who tries the demo. healdesk ("we", "us") operates it; the operating entity is named in section 10. It does not cover patients of our customers, except as sections 11 to 13 say about the product.
Sections 11 and 12 also describe what the product does with data it receives from Google and from Meta when a clinic connects its Google Calendar, its Facebook Page, its Instagram account or its WhatsApp number, and section 13 says how to have that data deleted.
Patient information is not handled on this website. When a clinic becomes a customer, its patients' information is processed only inside the product, under a Business Associate Agreement the clinic signs at checkout. That agreement, not this page, governs patient data. If you are a patient of a clinic that uses healdesk, contact your clinic; it controls your records and we act on its instructions.
2. What we collect, and why
We collect only what a feature needs to work. In each case the feature is the reason.
- Your email, when you unlock the demo. The chat demo asks for an email after your first message. We use it to know who tried the product and to reply if you ask us something. It sets one cookie,
hd_demo, for 7 days, so you are not asked again. Alongside the address we keep: whether it is a business or a personal domain, which specialty's demo you opened, the campaign code if you arrived from an email we sent, the site that referred you (the site name only, never the full link), the dates you first and last unlocked the demo, and which steps of this site you reached afterwards (for example "viewed pricing", "started checkout"), recorded against your record so we know what worked. We do not email you a transcript, and we do not email you about the product unless you tick the box below. - Whether you ticked the marketing box. Beside the email field is an unticked checkbox reading: "Email me about AYA and healdesk. Unsubscribe with one click, any time.". If you tick it we record that, the wording you saw (notice version 2026-09-29.1) and the time, and we send at most four emails over the following eight days, each with a one-click unsubscribe; then we stop. If you do not tick it, we do not email you about the product. Unlocking the demo is not consent to marketing.
- What you type into the demo. Your messages are sent to Anthropic, our language model provider, to generate a reply, together with the public service information of the specialty being demonstrated. We do not store the conversation on our servers, during or after it. Do not put anyone's health information into the demo; it is a demonstration for clinic staff, not a patient channel.
- Your phone number, if you ask AYA to call you. Only when you tick a separate box reading: "I agree that healdesk may place one automated demo call to this number using an AI voice. Consent isn't a condition of purchase, call and data rates may apply, and I can end the call or say "stop" at any time.". We use this number for the demo call only. We don't sell it, we don't add it to a marketing list, and we delete it on request. The call is placed by Synthflow, the voice platform that runs this demo call (the product's own voice agent runs on a different platform and never calls anyone). The number, the exact wording you agreed to, its version, the time and your IP address are stored as the consent record for 4 years — the period in which a call could be disputed — and are used for nothing else.
- If we contacted you first. We research practices before we send a first email, using only what the practice publishes: its website, its public business listing (name, address, phone, rating, opening hours), its public job posts, and how it takes bookings. We keep that business profile with the email we sent. It is information about a business, not about a person; it is never patient information; and every email we send this way says who we are and carries a working unsubscribe.
- Contact form submissions — your name, your clinic's name if you give it, your email and your message. They are delivered to our inbox by email and kept as ordinary correspondence.
- What you enter at checkout. Your clinic's legal name, its specialty, the booking system it uses, the typical value of one booked appointment, which calls you want answered, your work email, and — to sign the Business Associate Agreement — your name and your title at the practice. Card details go directly to Stripe and never touch our servers. If you reach the payment page and stop, we send one email about it, an hour later, and no more; it carries the same one-click unsubscribe.
- Technical data. Your IP address and the page requested, used to rate-limit the demo and stop abuse. Rate-limit counters expire with their window: an hour for most, a day for the demo-call limit on a given number. Request logs are kept briefly by our hosting provider and never longer than 30 days.
- Analytics, only if you accept the cookie notice. Page views and named funnel steps (for example "viewed pricing", "reached checkout step 3"). Never the contents of a form, an email address, a phone number or a chat message. If you decline, nothing is measured and the site works identically.
3. What we do not do
- We do not sell or share your personal information, in the ordinary sense or in the sense defined by California law. There is no advertising pixel, tag manager or conversion tag on this site, and no data is sent to Meta, Google Ads or any other advertising platform. This is a design rule written into the site's code — the browser is told which servers this site may talk to, and those are not on the list — not only a policy.
- We do not use what you type into the demo to train any model, and neither does Anthropic.
- We do not knowingly collect information from anyone under 18; the site is for businesses.
- We do not use "dark patterns": declining analytics is one click and changes nothing else.
5. Who processes it
The companies below process visitor data for this website. Each receives only what the row says, and none receives patient information from this site. The full register, including the vendors inside the product that do handle patient information and the status of each one's agreement with us, is at /subprocessors.
| Vendor | Purpose | Receives |
|---|---|---|
| Anthropic (the website demo) | The language model behind the chat demo on this website, in a separate Anthropic organisation from the product's | What you type into the demo, and the public service information of the specialty being demonstrated. No training on any of it |
| Stripe | Billing the clinic for its healdesk subscription | Clinic name, billing contact, card details (held by Stripe, never by healdesk) |
| Synthflow | Places the one demo call a visitor asks for on this website. It carries no patient calls: the product's voice agent runs on Retell | The number you typed, the first name you gave, and the audio and transcript of the demo call |
| Resend | Transactional email: invitations, agreement copies, account and billing notices | Recipient address and non-patient content only |
| Vercel | Hosting this marketing website | Page requests, the demo gate email, contact-form submissions |
| Google (Google Sheets / Drive) | The marketing site's lead register: demo leads, funnel events and the demo-call consent record, in a Google Sheet | Work email, business or personal domain, specialty demoed, referrer host, campaign code, the marketing-consent record |
| PostHog (US cloud) | Funnel analytics on this website, after consent | Page views and named funnel steps; no form contents, no email, no chat text |
| Apify | Reading a practice's public website when we research it before a first email | Publicly published pages of the practice's own website |
6. How long we keep it
- A lead that never becomes a customer: 12 months after the last visit, then deleted automatically, together with the funnel events recorded against it.
- Server logs: 30 days.
- Demo-call consent records: 4 years, then deleted.
- Demo conversations: not stored by us at all; Anthropic's own retention applies to its processing.
- The demo call itself: Synthflow keeps its call record under its own retention; we hold the number only in the consent record above.
- Contact-form messages: as ordinary email correspondence, until the enquiry is closed.
- Customer billing records: for as long as tax and accounting law require.
- The record of a signed Business Associate Agreement: for six years after the relationship ends, as HIPAA requires.
7. Your rights
Wherever you are, you can ask us what we hold about you, ask for it to be corrected or deleted, and withdraw marketing consent. Email privacy@healdesk.io and we answer within 30 days. We will verify the request by replying to the address on file; we do not require an account or a form.
California residents. You have the rights to know, to delete, to correct, and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of; the rest are honoured through the address above, and we do not discriminate against anyone for exercising them. An authorised agent may act for you with written permission.
Washington residents. This website is not designed to collect consumer health data. If you type health information into the demo it is processed only to generate the reply and is not retained by us. The product itself, used by a clinic on your behalf, operates under that clinic's own notices and the agreement it signs with us.
Email marketing. Every marketing email carries a working unsubscribe link and our postal address, and we honour an unsubscribe within ten business days as the CAN-SPAM Act requires — in practice, immediately.
8. Text messages
This website does not send text messages, and nothing on it asks you to agree to any. The demo call in section 2 is a voice call. If we ever add texts, the programme will be described here first, with the carrier-standard terms: message frequency, "message and data rates may apply", and STOP to opt out and HELP for help. Marketing texts would need a separate, explicit opt-in.
9. Security
The marketing site holds no patient information, which is the first and best security control. What it does hold is encrypted at rest, and in transit wherever we control both ends, reachable only through this site's own server code, and rate-limited.
The controls the product commits to for patient information are set out in the Business Associate Agreement. There is an agreement with every vendor that holds patient information, signed before any patient information reaches it; Meta and Stripe sign none, so the product keeps clinical content away from them. Patient information is encrypted at rest, and in transit wherever we control both ends. Two routes are outside that: a phone call is not end-to-end encrypted, and a patient who telephones has chosen the telephone; and a message on Instagram, Messenger or WhatsApp travels through Meta's systems, which we do not control. Email that would carry patient information goes only over an encrypted connection, and is not sent if the receiving server cannot accept one. A breach is reported to the clinic within five calendar days of discovery.
The product's servers and its database run in Amazon Web Services' US East region. The voice provider's region is being confirmed in writing, and appears on the subprocessor page once it is. That page lists every vendor with the status of its agreement. No third party has audited us; these are our own commitments and we will show you the architecture behind any of them.
10. Operating entity, changes and contact
healdesk is a service of Viixi FZC, a company registered under the Sharjah Publishing City Free Zone, United Arab Emirates, registered address Business Center, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. Everything on this page applies regardless of the operating entity's place of incorporation.
- Privacy requests: privacy@healdesk.io
- Everything else: hello@healdesk.io
- US mailing address (correspondence only): 800 N King Street, Suite 304-1426, Wilmington, DE 19801, United States
When this policy changes we update the version and date at the foot of the page. A change that reduces your rights or widens what we collect is announced on this page for 30 days before it takes effect and, for customers, by email.
11. Google Calendar data (clinics that connect a calendar)
A clinic that uses healdesk connects its Google Calendar with a Google sign-in during setup, and chooses which calendar the assistant uses. With that access the product does two things, and only these:
- Reads availability on the chosen calendar, so the assistant offers patients times that are actually free.
- Creates and changes the events it books on that calendar.
It uses other events on the calendar only to see when the clinic is busy, never changes an event it did not create, and writes to no other Google service. The access is used only to provide the booking feature the clinic turned on. We do not sell Google user data, do not use it for advertising, do not use it to build or improve generalized artificial intelligence or machine learning models, and do not let people read it except where the clinic asks us to, where it is needed for security, or where the law requires it. It is shared with no one except the vendors on our subprocessor list that run the product, and only as they need it to do so.
healdesk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The connection is stored encrypted. A clinic can disconnect or change the calendar from its portal at any time, which deletes the stored connection, or remove healdesk's access from its Google Account's security settings, which ends it at once. The events the assistant booked stay in the clinic's own calendar, which the clinic controls under its own agreement with Google.
12. Messages received through Meta (Instagram, Messenger, WhatsApp)
A clinic can connect its Facebook Page, its Instagram professional account and its WhatsApp Business number. When it does, Meta sends healdesk the messages people send to those accounts, with the identifiers Meta attaches to them (on WhatsApp, the sender's phone number), and the assistant replies on the clinic's behalf.
- Only to answer. The assistant uses the messages to answer the person who wrote, on the clinic's behalf, and to book an appointment or send the clinic's own payment link while that conversation is open. The payment link itself carries an amount and a reference and never names a time, service or practitioner. The messages are never used for advertising, never sold, and never used to train models.
- Only when the person wrote first. The assistant replies only inside the window Meta opens when someone messages the clinic. It never messages anyone first and sends nothing after a conversation ends.
- Nothing clinical. Meta does not sign the agreements that health information requires, so these conversations are kept non-clinical: clinical content is detected when a message arrives and is not stored, and the assistant moves the conversation to a call or the clinic's own secure route.
- Kept for the clinic. The conversation is kept for the clinic that received it, under that clinic's instructions and its Business Associate Agreement with us, and is visible to that clinic's team in its portal, and to healdesk staff only as the clinic's agreement allows. If you wrote to a clinic, that clinic controls the record; see section 13.
13. Deleting your data
How to have data deleted, whether you visited this site, use healdesk as a clinic, or messaged a clinic that uses it, is set out on our data deletion page. In short: email privacy@healdesk.io and we answer within 30 days, as in section 7. Where the data belongs to a clinic's patients, we act on that clinic's instructions.
Version 2026-10-03.2 · last updated 3 October 2026 · questions to privacy@healdesk.io