CLINSIA
Privacy Policy
Last updated: July 2026

Privacy Policy

This policy describes how Clinsia, a product of Novalab SA ("Clinsia", "we"), processes personal data from those who visit clinsia.com, from the healthcare institutions that use the product, and from their patients.

1. Who we are

Clinsia is an AI-assisted clinical documentation platform for healthcare institutions in Latin America. The product is operated by Novalab SA, owner of the product and its intellectual property, with its team based in Buenos Aires and Rosario, Argentina. Contact for privacy matters: contact@clinsia.com.

2. Our dual role

3. What data we process

4. How we use them

No secondary uses or resale: clinical data is not sold, is not shared for commercial purposes and is not used to train third-party models.

5. Patient consent

6. Sub-processors and international transfers

To provide the service we use vendors who process data on our behalf:

The complete and current list of sub-processors is detailed in the DPA. When data is transferred outside Argentina, we do so with appropriate contractual safeguards in accordance with Argentina's Personal Data Protection Law 25,326.

7. How long we retain them

8. How we protect them

Data is encrypted in transit (TLS 1.2+) and at rest. Access is restricted by role and by institution (multi-tenant isolation), with individual credentials and an audit trail of every action: who created, edited, approved and signed each document, and when. Details of our controls are available in the security overview.

9. Human oversight

No clinical document is finalized without review: the AI proposes and the physician approves and signs. Clinsia does not perform diagnostics or make clinical decisions, and it is not a diagnostic device.

10. Your rights

You can exercise your rights to access, rectification, update and deletion of your personal data by writing to contact@clinsia.com. If your data was processed by a healthcare institution through Clinsia, we will route your request to that institution, which is the data controller.

The Public Access to Information Agency (AAIP), the regulatory body for Argentina's Personal Data Protection Law 25,326, is authorized to hear complaints and claims relating to non-compliance with personal data protection regulations.

11. Changes to this policy

We may update this policy to reflect changes in the service or regulations. We will publish the current version on this page, with the date of last update.

Does your legal or IT team need more detail? We have NDA and DPA ready for signature, and we prepare technical annexes on request. Write to contact@clinsia.com.