Privacy Policy
Last updated: June 1, 2026
1. Introduction
Clinelix Inc. (“Clinelix”, “we”, “us”, “our”) respects your privacy and is committed to protecting personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), Quebec’s Law 25, British Columbia’s PIPA, Alberta’s PIPA, and other applicable Canadian privacy laws. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in connection with our website, dashboards, APIs, and related services (the “Services”).
2. Privacy Officer
Our Privacy Officer is responsible for compliance with this policy and applicable privacy laws. You can reach the Privacy Officer at: privacy@clinelix.com or by mail at Clinelix Inc., Attn: Privacy Officer, Calgary, Alberta, Canada.
3. Information we collect
Depending on how you interact with us, we may collect:
- Account information: name, email, password hash, role, and profile picture (if you sign in with Google).
- Clinic profile: clinic name, specialty, province, number of operatories, number of providers.
- Billing data: procedure codes, provider names, insurer names, charged and paid amounts, claim status, and service dates that you import via CSV or that we receive from your connected practice-management system.
- Banking data (when you choose to link an account via Flinks (or another Canadian Open Banking aggregator)): account name, balances, and transaction-level outflows used to compute monthly burn. We do not store full bank credentials.
- Usage data: log files, IP address, browser type, device identifiers, pages viewed, and actions taken in the dashboard.
- Support and marketing data: messages you send to support, demo-request form submissions, and survey responses.
Clinelix is designed to operate on aggregated, non-identified financial data. We do not require patient names, addresses, dates of birth, or health information to deliver our Services and we ask customers to avoid uploading such information.
4. How we use your information
- Provide, secure, and improve the Services, including computing your Practice Financial Score and powering the AI assistant.
- Authenticate users and prevent fraud or abuse.
- Communicate with you about your account, product updates, security incidents, and (where you consent) marketing.
- Generate de-identified, aggregated benchmarks across the Clinelix customer base (e.g., median fee-guide compliance by specialty in a province). Aggregated benchmarks never identify any single clinic or patient.
- Comply with legal obligations and enforce our Terms.
5. Legal basis and consent
We collect, use, and disclose your information with your consent (express or implied) and as otherwise permitted by PIPEDA and applicable provincial laws. You may withdraw your consent at any time, subject to legal or contractual restrictions, by contacting our Privacy Officer.
6. How we share information
We do not sell your personal information. We share it only in the following circumstances:
- With service providers (“subprocessors”) that help us deliver the Services, under contracts that require equivalent protection: MongoDB Atlas (database, Canada Central region), Flinks (Open Banking, Canada), Plaid (Open Banking, United States), the practice-management and eClaims platforms that you choose to connect, Stripe (billing), OpenAI / Anthropic / Google (AI engine), Postmark (transactional email), Sentry (error tracking), Cloudflare (CDN and WAF), and observability tools.
- When required by law, court order, or to protect the rights, safety, or property of Clinelix or others.
- In connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.
A current list of subprocessors is available at our Security page and is updated when we add or remove providers.
7. International transfers
Some of our subprocessors process data outside of Canada (primarily the United States). When this happens, we use contractual safeguards and require that the data be protected at a comparable standard. Customer billing data is stored at rest in Canada Central; aggregated AI prompts may transit to U.S. LLM providers.
8. Security safeguards
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls and audit logs for every sensitive action.
- Background-screened personnel with least-privilege production access.
- Annual penetration tests and continuous vulnerability scanning.
- Mandatory multi-factor authentication available for clinic owners.
- PIPEDA-aligned breach response plan including 72-hour notification where appropriate.
9. Retention
We retain your information for as long as your account is active and for a reasonable period after termination to satisfy legal, accounting, and audit requirements. Customers can request export or deletion of their data at any time by contacting our Privacy Officer.
10. Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of personal information (subject to our legal obligations).
- Withdraw consent to specific uses, including marketing communications.
- File a complaint with our Privacy Officer and, if you are not satisfied, with the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) or your provincial privacy regulator.
11. Cookies and analytics
We use a minimal set of strictly necessary cookies (for authentication and security) and privacy-friendly analytics tooling that does not require cross-site tracking. We do not use ad-targeting cookies on the Clinelix web property.
12. Children’s privacy
The Services are intended for use by Canadian healthcare practices and their authorized personnel. We do not knowingly collect personal information directly from children under 13.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-product notice. The “Last updated” date above indicates when this policy was last revised.
14. Contact us
Questions or concerns about your privacy or this policy: privacy@clinelix.com.