Privacy Policy
This policy describes how Clinsia, a product of Novalab SA ("Clinsia", "we"), processes personal data from those who visit clinsia.com, from the healthcare institutions that use the product, and from their patients.
1. Who we are
Clinsia is an AI-assisted clinical documentation platform for healthcare institutions in Latin America. The product is operated by Novalab SA, owner of the product and its intellectual property, with its team based in Buenos Aires and Rosario, Argentina. Contact for privacy matters: contact@clinsia.com.
2. Our dual role
- Website and commercial contact data: Clinsia is the data controller for information you send us through the site (for example, the contact form).
- Clinical data from the product: information from consultations (audio, transcriptions, clinical notes, patient data) belongs to the healthcare institution, which acts as data controller. Clinsia acts as data processor, on behalf and under the instructions of the institution, in accordance with the data processing agreement (DPA) signed with each client.
3. What data we process
- On the website: name, institutional email, institution, job title and message content. We use aggregated traffic analytics (Vercel Analytics), without advertising cookies or cross-site tracking.
- In the product: audio from consultations captured with the physician's knowledge and patient consent; transcriptions and derivative documents (clinical note, summaries); and the minimal identification data for the professional and patient needed to associate each consultation with its record.
4. How we use them
- Provide the service: transcribe consultations and generate clinical documentation that the physician reviews, approves and signs.
- Respond to commercial inquiries and coordinate demos.
- Maintain the security, quality and availability of the service.
No secondary uses or resale: clinical data is not sold, is not shared for commercial purposes and is not used to train third-party models.
5. Patient consent
- Sending summaries to patients (via WhatsApp or email) requires their prior and recorded consent.
- Patients can revoke consent at any time; revocation is recorded and audited.
- We provide institutions with template consent texts adaptable to their protocols.
6. Sub-processors and international transfers
To provide the service we use vendors who process data on our behalf:
- Vercel: infrastructure and hosting, with primary hosting in the United States.
- AI model providers for transcription and writing, including OpenAI and Anthropic.
The complete and current list of sub-processors is detailed in the DPA. When data is transferred outside Argentina, we do so with appropriate contractual safeguards in accordance with Argentina's Personal Data Protection Law 25,326.
7. How long we retain them
- Original audio: retained as long as necessary to ensure service quality and then deleted. The timeframe is configurable by each institution.
- Transcriptions and documents: retained while the institution maintains the service, with timelines and deletion policies configurable by institution.
- Commercial contact data: retained while an active relationship or commercial interest exists, or until you request deletion.
- When the contract ends, the institution may export its data and request certified deletion.
8. How we protect them
Data is encrypted in transit (TLS 1.2+) and at rest. Access is restricted by role and by institution (multi-tenant isolation), with individual credentials and an audit trail of every action: who created, edited, approved and signed each document, and when. Details of our controls are available in the security overview.
9. Human oversight
No clinical document is finalized without review: the AI proposes and the physician approves and signs. Clinsia does not perform diagnostics or make clinical decisions, and it is not a diagnostic device.
10. Your rights
You can exercise your rights to access, rectification, update and deletion of your personal data by writing to contact@clinsia.com. If your data was processed by a healthcare institution through Clinsia, we will route your request to that institution, which is the data controller.
The Public Access to Information Agency (AAIP), the regulatory body for Argentina's Personal Data Protection Law 25,326, is authorized to hear complaints and claims relating to non-compliance with personal data protection regulations.
11. Changes to this policy
We may update this policy to reflect changes in the service or regulations. We will publish the current version on this page, with the date of last update.
Does your legal or IT team need more detail? We have NDA and DPA ready for signature, and we prepare technical annexes on request. Write to contact@clinsia.com.