Security overview
Version 1.0 · July 2026
contact@clinsia.com
Security, privacy and compliance
A reference document for legal, IT and medical leadership teams evaluating Clinsia. It summarizes how clinical information is protected at every stage: capture, processing, storage and transmission.
1. What data does Clinsia process
Audio from consultations, captured in the office with the physician's knowledge and patient consent.
Transcription and derivative documents (clinical note, medical record summary, patient summary).
Minimal identification data for the professional and patient, required only to associate each consultation with its record.
2. Encryption and technical security
Data encrypted in transit (TLS 1.2+) and at rest, using industry standards.
Access to data restricted by role and by institution (multi-tenant isolation).
User authentication with individual credentials; no shared accounts.
Audit trail: who generated, edited, approved and signed each document, and when.
3. Hosting and sub-processors
Item
Detail
Data hosting
Cloud infrastructure managed by Vercel, with primary hosting in the United States and enterprise-grade security standards.
Data processor sub-processors
Vercel (infrastructure and hosting) and AI model providers for transcription and writing, including OpenAI and Anthropic. The complete and current list is detailed in the DPA.
Original audio retention
Retained as long as necessary to ensure service quality and then deleted. The timeframe is configurable by each institution.
Transcription and document retention
Retained while the institution maintains the service. Timelines and deletion policies are configurable by institution.
4. Data ownership and use
Clinical information belongs to the institution. Clinsia acts as data processor.
No secondary uses or resale: data is not used to train third-party models and is not shared for commercial purposes.
When the contract ends, the institution may export its data and request certified deletion.
5. Patient consent
Sending summaries to patients (WhatsApp or email) requires prior and recorded consent.
Patients can revoke consent at any time; revocation is audited.
Clinsia provides template consent texts adaptable to each institution's protocols.
6. Human oversight
No clinical document is finalized without review: the AI proposes, the physician approves and signs.
Clinsia does not perform diagnostics or make clinical decisions. It is not a diagnostic device.
7. Regulatory framework
Data processing is aligned with Argentina's Personal Data Protection Law 25,326 and its principles of quality, purpose and confidentiality for health data.
Designed to interoperate with health standards (HL7 FHIR).
Agreements available for signature: confidentiality agreement (NDA) and data processing agreement (DPA), ready on request from the institution. If your team requires a technical security annex (detail of controls and architecture), we prepare it together with your systems team.
This document is a commercial reference sheet and does not constitute legal advice. Contractual commitments are formalized in the DPA and service agreement. For an in-depth technical review (architecture, penetration testing, internal policies), we coordinate a session with your systems team: contact@clinsia.com.