Privacy Policy
Effective date: [EFFECTIVE DATE] · Last updated: [DATE]
1. Who we are
Arkometry ("Arkometry", "we", "us") is based at 2, Kumar Layout, Bangalore 562107, India. Contact: [privacy@arkometry.com] or hello@arkometry.com. Grievance Officer: [NAME, EMAIL] (section 15).
2. The two roles we play
- On our own behalf. When you visit arkometry.com, use our chat assistant or calculator, or talk to us about our services, we decide how that information is used.
- On behalf of our clients. Our clients are mainly medical and dental practices. When one of them uses Arkometry to answer calls and inquiries, we process their patients' and prospective patients' information on the practice's instructions. That practice is responsible for its own privacy notice (and, where HIPAA applies, its Notice of Privacy Practices), and for any notices or consents its callers need. If you contacted one of our clients, please take privacy requests to them first; we will help them respond.
3. Information we collect for our own purposes
- Information you give us: name, practice or business name, email, phone number, and anything you write in emails or in the chat assistant.
- Chat assistant: messages you type into the chat on this site are sent to an AI model provider to generate a reply. Your chat history is kept in your own browser so the conversation is there when you return; you can clear it by clearing your browser's site data. [CONFIRM: whether chat messages are logged by us or our providers, and for how long.] Please don't share health information in the chat.
- Calculator: the figures you enter are processed in your browser and are not stored or sent to us.
- Automatic information: device and browser data, pages visited, and approximate location, through [ANALYTICS PROVIDER] and our hosting/security providers (for example, a Cloudflare security cookie).
4. Information we process for clients
Caller and lead contact details; procedure or treatment of interest; timing and consultation preferences; appointment details; call audio recordings; transcripts and AI-generated summaries; message content (SMS, email, web forms, chat); call metadata; and anything else the practice configures us to collect.
When we work for a HIPAA covered entity, some or all of this may be protected health information (PHI). Where we act as a business associate, a Business Associate Agreement (BAA) between us and the practice governs that PHI and takes precedence over this policy.
By default our systems are configured not to request medical history, medications, diagnoses, clinical photos, X-rays, payment card numbers or government IDs. Patients are directed to the practice's own secure channels for these.
5. How we use information
To provide and support our services; to answer, route, summarize and follow up on calls and inquiries for our clients; to schedule and send reminders; to keep our services secure and working; to improve quality (for example, reviewing transcripts with a client's permission and within any BAA); to reply to you; and to meet legal obligations.
We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use PHI or client patient data to train general-purpose AI models [CONFIRM], and we contractually configure our AI providers the same way [CONFIRM]. We don't use client patient data for our own marketing.
6. Legal bases and consent
Where Indian law applies, we process personal data with consent or for legitimate uses allowed under the Digital Personal Data Protection Act, 2023 and its rules. For client data, the practice determines the purpose and is responsible for having a lawful basis and giving any required notices. [COUNSEL TO REVIEW]
7. Who we share it with
- Service providers (sub-processors): cloud hosting and database [PROVIDER, US REGION], telephony and SMS [PROVIDER], speech-to-text and AI model providers [PROVIDERS], email, scheduling and booking tools, analytics. Where PHI is involved, we use only providers that have signed a BAA (or equivalent subcontractor agreement) with us [CONFIRM]. Current list: [SUBPROCESSOR URL].
- Tools our clients connect: their practice-management software, calendar or CRM.
- Legal and safety: when required by law or to protect rights and safety.
- Business transfers: in a merger, acquisition or sale of assets, subject to this policy and any BAA.
8. International transfers and data location
We are based in India; our clients and their patients are mainly in the United States. Client data, including any PHI, is stored in [US REGION] [CONFIRM]. Our team may access it from India only as needed to provide and support the service, with access limited, logged and governed by our agreements with the practice [CONFIRM]. We follow any transfer restrictions the Government of India notifies under the DPDP Act.
9. Retention
Our own records: [X months] after our last interaction. Client data: as the practice configures (default recordings [X days], transcripts and summaries [X days]), then deleted or returned within [X days] after the contract ends, or as the BAA requires.
10. Security
[Encryption in transit and at rest, role-based access, multi-factor authentication, audit logging, staff confidentiality and training: CONFIRM.] No system is perfectly secure. If a breach affects client data, we will notify the practice without undue delay, and within any deadline in our BAA, so it can meet its own obligations, including under the HIPAA Breach Notification Rule where applicable. Where Indian law applies, we will notify the Data Protection Board of India and affected individuals as required.
11. Calls, recordings and text messages
- Recording: federal law and many US states allow recording with one party's consent, but some require all parties' consent (e.g. California, Florida, Illinois, Maryland, Massachusetts, Pennsylvania, Washington) [COUNSEL TO VERIFY]. Our systems play a recording and AI notice at the start of calls where enabled, and we recommend practices use it.
- AI disclosure: some states regulate undisclosed bots or AI in consumer and health interactions [COUNSEL TO LIST CURRENT LAWS]. We recommend the assistant identify itself.
- Calls and texts: the TCPA and state laws restrict automated calls and texts, especially marketing; the FCC treats AI-generated voices as "artificial" under the TCPA. Practices are responsible for the consent their messages need. We honor opt-outs (STOP), support quiet hours, and follow carrier registration (A2P 10DLC).
- Marketing vs. care communications: under HIPAA, some communications about a practice's services may count as marketing and require patient authorization. Practices decide, with their counsel, which follow-ups they send.
12. Health information
- We design our services to collect only the minimum information needed to book and follow up.
- Business Associate Agreements: [available on request / TBD]. We will not process PHI for a covered entity without a signed BAA [CONFIRM POLICY].
- We do not claim HIPAA compliance or any security certification (such as SOC 2 or HITRUST).
- State health-privacy laws may also apply, including to information outside HIPAA. Examples: Washington's My Health My Data Act, Nevada's consumer health data law, Connecticut's consumer health data provisions, California's Confidentiality of Medical Information Act, and Texas's medical records privacy law. [COUNSEL TO CONFIRM APPLICABILITY]
- Photos: our assistants are configured not to request clinical photos and to direct patients to the practice's secure channel.
13. Your rights
- US residents: depending on your state (e.g. California under the CCPA/CPRA; Colorado, Connecticut, Virginia, Texas, Oregon and others), you may have rights to know, access, correct or delete your personal information, to opt out of sale, sharing or targeted advertising, to limit use of sensitive information (including health information), and not to be discriminated against. Patients of our clients should contact their practice; HIPAA rights (e.g. access to records) are exercised through the practice. We [honor Global Privacy Control: CONFIRM].
- Individuals in India: under the DPDP Act, rights to a summary of personal data, correction, completion, updating or erasure, withdrawal of consent, nomination, and grievance redressal.
- How to ask: [privacy@arkometry.com]. We verify requests and respond within [X] days, or as the law requires.
14. Children
Our services are for businesses and not directed to children. We do not knowingly collect personal information from children under 13 (US) or under 18 (India) without appropriate consent. Practices treating minors should tell us so we can configure intake accordingly.
15. Grievance Officer (India)
[NAME], [EMAIL], [ADDRESS]. We will acknowledge grievances within [X] and resolve them within [X] days. If you're not satisfied, you may complain to the Data Protection Board of India once it is available to you.
16. Cookies and similar technologies
Essential cookies (security, load balancing) and [analytics cookies/scripts]. [Cookie controls / banner: CONFIRM.] We don't add advertising or tracking pixels to any patient-facing forms, messages or pages we provide for clients [CONFIRM].
17. Changes
We'll post updates here and change the "Last updated" date. Material changes will be highlighted [and emailed to clients].
18. Contact
Arkometry, 2, Kumar Layout, Bangalore 562107, India · [privacy@arkometry.com] · hello@arkometry.com