Legal
Privacy Policy
CleriMed, LLC
- Effective Date
- [SET AT LAUNCH — TBD]
- Last Updated
- August 7, 2026
- Version
- Version 1.1
1.Introduction and Scope
This Privacy Policy (the "Policy") sets forth the information practices of CleriMed, LLC, a Georgia limited liability company ("Company," "we," "us," "our"), regarding the collection, use, retention, and protection of data processed through the CleriMed platform, accessible at clerimed.com and related domains (the "Platform").
Scope of Data Collection: CleriMed does not collect, store, process, or retain any patient personally identifiable information (PII), patient medical records, patient health data, or any information protected under the Health Insurance Portability and Accountability Act (HIPAA), 45 C.F.R. Parts 160 and 164. CleriMed collects only clinical operational data in the following categories: inventory records, medical supplies tracking, vial opening and tracking records, staff user account information, and appointment metadata received from third-party booking integrations.
Binding Nature: This Policy becomes binding upon a User's acceptance as described in Section 1.1 below. Users who do not agree to this Policy shall not create accounts or access the Platform.
1.1Acceptance of Policy
This Privacy Policy becomes binding and enforceable when a User selects the checkbox indicating acceptance of this Privacy Policy during account creation; receives a confirmation email containing this Policy in its entirety; or continues to use the Platform following any material amendments to this Policy.
CleriMed shall record the date, time, Internet Protocol (IP) address, and browser information associated with each User's acceptance of this Policy. Such records shall be maintained in the User's account and shall be admissible as evidence of acceptance in any dispute resolution proceeding.
Users shall retain copies of all confirmation emails for their records. Failure to receive or review the confirmation email shall not negate acceptance.
1.2Interpretation and Definitions
In this Policy, the following terms shall have the meanings ascribed to them:
"Affiliates" means any entity that controls, is controlled by, or is under common control with CleriMed.
"Clinic" or "User" means the medical spa, clinic, or healthcare provider entity that has registered with the Platform and authorized staff members to access it.
"Data Controller" means the entity that determines the purposes and means of data processing; in this relationship, Clinic is the Data Controller.
"Data Processor" means the entity that processes personal data on behalf of the Data Controller; CleriMed is the Data Processor.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" or "Process" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, transmission, or erasure.
"Subprocessor" means any entity engaged by CleriMed to Process Personal Data on its behalf.
2.Categories of Data Collected
2.1Data Provided Directly by Clinic
CleriMed collects the following information that Users or their authorized representatives provide directly through account creation, account administration, and Platform usage:
Clinic Information: Clinic or practice name, physical address, state of licensure, timezone, logo or branding materials, telephone number, and state license numbers or registration numbers.
User Account Information: Email address, hashed password, full name of authorized staff member, telephone number, and assigned role designation (Owner, Manager, or Staff).
Billing Information: Payment method information provided to Stripe, Inc. ("Stripe"), including card number, expiration date, and billing address. CleriMed does not store, retain, or have access to complete payment card information; such information is stored solely by Stripe in compliance with Payment Card Industry Data Security Standard (PCI DSS) requirements.
Inventory Data: Product name, product SKU, quantity on hand, lot number, expiration date, supplier identification information, cost of goods sold (COGS) data, and reorder history.
Medical Supplies Tracking Data: Vial identification and tracking records, beyond-use date (BUD) calculations, reconstitution event records, temperature excursion logs, vial opening records, and vial closing records.
Treatment Confirmation Data: Treatment confirmations linked to provider identification, product or supply usage quantity, date and time of service, and treatment category or type.
Supplier Directory Information: Supplier entity name, contact person name, title, email address, telephone number, mailing address, account number with supplier, and supplier portal login information.
Revenue Data: Monthly revenue amount by product category or treatment type, provided directly by clinic ownership.
2.2Data Collected Automatically Through Platform Use
CleriMed automatically collects certain information through Users' interactions with the Platform:
Usage and Behavioral Data: Pages or features accessed, user interactions or clicks, session duration and frequency, time and date of access, search queries entered, and browser-based interactions.
System and Audit Data: User login timestamps, changes to assigned roles, entries made to system audit logs, records of data access by role, and records of administrative actions.
Device and Network Information: Internet Protocol (IP) address, browser type and version, operating system and version, device type, and connection method.
Third-Party Integration Data: Appointment data received via webhook from Zenoti, Inc., limited to appointment date and time, assigned provider identification, appointment category or service type, and appointment duration. No patient name, patient age, patient medical information, or patient contact information is collected through this integration.
2.3Data Not Collected
CleriMed explicitly does not collect, request, accept, or retain the following categories of information:
- Patient name, patient age, patient date of birth, or other patient identifiers;
- Patient contact information, including telephone number, email address, or mailing address;
- Patient medical history, diagnoses, medications, allergies, or clinical assessments;
- Prescriptions, treatment plans, medical orders, or clinical protocols;
- Social Security numbers, driver's license numbers, passport numbers, or other government-issued identification numbers;
- Health insurance information, member ID, or insurance claims data;
- Biometric data, including fingerprints, facial recognition data, or genetic information;
- Payment card information beyond what is processed by Stripe; and
- Records protected under HIPAA, 45 C.F.R. Parts 160 and 164, or similar healthcare privacy regulations.
3.Purposes of Data Processing
CleriMed Processes Personal Data and clinic operational data solely for the following purposes:
3.1Service Delivery and Platform Operations
Creating, administering, and authenticating User accounts; applying role-based access control restrictions to ensure appropriate data access by role; displaying real-time inventory data, alerts, and dashboards; calculating reorder recommendations based on consumption patterns, lead times, and committed appointments; managing purchase order workflows and approval processes; tracking vial opening, beyond-use date expiration, and first-in-first-out (FIFO) compliance; logging temperature excursions and environmental monitoring events; recording receiving discrepancies and automated resolution workflows; and generating automated audit logs of all data access and administrative actions.
3.2Billing, Payment Processing, and Account Management
Processing subscription payments via Stripe; generating invoices and billing statements; monitoring usage metrics against plan-based tier limits; assessing and charging overage fees if applicable; implementing grace periods and subscription suspension for failed payments; and processing refunds and money-back guarantee requests.
3.3Communications and Notifications
Transactional messages, including password reset instructions, account confirmation emails, and invoice confirmations; operational alerts selected by User, including low stock notifications, product expiration warnings, and receiving discrepancy notifications; morning briefing emails containing operational summaries (delivery frequency and receipt subject to User notification preferences); weekly owner narrative summaries generated through artificial intelligence (delivery subject to User notification preferences); and service-related announcements and critical security notifications.
3.4Platform Improvement and Analytics
Analyzing usage patterns to identify frequently used and underutilized features; detecting technical bugs, software errors, or platform performance issues; aggregating and anonymizing usage data for internal statistical analysis; identifying training opportunities or feature education needs; and optimizing user interface design and workflow efficiency.
3.5Peer Benchmarking and Data Aggregation
Aggregating cost of goods sold (COGS) by product category across multiple clinics; calculating median and mean COGS figures for product categories; comparing individual clinic COGS performance against anonymized peer benchmarks; identifying clinic-level waste patterns and cost trends relative to peers; and presenting aggregated benchmarking data to clinic owners for comparative analysis.
In all benchmarking activities, individual clinic identity is protected through anonymization and aggregation. No individual clinic shall be identifiable in any benchmarking output provided to other clinics.
3.6Artificial Intelligence and Anomaly Detection
Transmitting anonymized clinic inventory data to Anthropic PBC's Claude API to identify statistical anomalies in product consumption; generating written anomaly narratives and clinical insights based on consumption patterns; calculating reorder recommendations based on appointment forecasting and historical consumption data; identifying temperature excursion anomalies and regulatory compliance risks; and generating weekly owner narrative summaries in natural language format.
CleriMed does not use Clinic data to train, fine-tune, or otherwise improve any third-party AI provider's underlying models. Under Anthropic's commercial API terms, data submitted through the API is not used for model training and is retained by Anthropic for up to thirty (30) days for abuse and safety monitoring purposes only, after which it is deleted, unless CleriMed has configured a Zero Data Retention arrangement with the provider (where available). CleriMed itself does not separately store or archive AI provider responses beyond the duration necessary to deliver the output to the User.
AI-Generated Content is labeled as such within the Platform (for example, "AI Weekly Briefing" or "AI-detected anomaly") so Users can identify when they are viewing algorithmically generated output rather than raw data.
CleriMed's AI features do not make fully automated decisions that produce legal or similarly significant effects on Users without human involvement. Purchase order approval, inventory adjustments, and other material actions require human review within Clinic's own account, consistent with the Terms of Service, Section 3.7.
3.7Legal Compliance and Security
Investigating suspected fraud, unauthorized access, data breaches, or violations of this Policy or Terms of Service; preserving data for litigation, regulatory investigation, or law enforcement request; complying with subpoenas, court orders, or governmental agency requests; enforcing CleriMed's Terms of Service and other agreements; and protecting the security and integrity of the Platform and User data.
4.Lawful Basis for Data Processing
4.1GDPR Legal Basis (European Union and United Kingdom Users)
For clinics with staff located in the European Union, United Kingdom, or other jurisdictions subject to Regulation (EU) 2016/679 (the "General Data Protection Regulation" or "GDPR"), CleriMed Processes Personal Data under the following lawful bases:
Performance of Contract: CleriMed Processes data necessary to perform the services requested by Clinic and to fulfill the contractual obligations contained in the Terms of Service and this Policy.
Legitimate Interests: CleriMed Processes data to protect the Platform's security, prevent fraud and unauthorized access, and maintain accurate audit logs and compliance records.
Legal Obligation: CleriMed Processes data to comply with applicable tax requirements, financial reporting obligations, and legal process requests from governmental authorities.
Important Notice Regarding Data Controller Status: Clinic shall be the Data Controller with respect to personal data of its staff members. CleriMed shall be the Data Processor. Clinic shall be solely responsible for obtaining necessary consents from staff members prior to processing their personal data; providing legally required privacy notices to staff members; maintaining compliance with applicable data protection regulations; and responding to data subject access requests and fulfilling data subject rights.
If Clinic requires a Data Processing Agreement (DPA) in accordance with GDPR Article 28, Clinic shall request such agreement by sending written notice to legal@clerimed.com. CleriMed shall provide a standard DPA within thirty (30) business days of request.
4.2California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
For clinics with staff or operations in California, the following provisions apply:
CleriMed does not "sell" Personal Data as defined under California Civil Code Section 1798.100 et seq. CleriMed does not sell, rent, release, disclose, disseminate, or otherwise communicate Personal Data to third parties for monetary or other valuable consideration.
California clinics have the following consumer rights under CCPA/CPRA:
Right to Know: You may request disclosure of the categories of Personal Data collected, the purposes for collection, and the categories of third parties with whom data is shared.
Right to Delete: Subject to certain legal exceptions, you may request deletion of Personal Data collected from you.
Right to Opt-Out: You may opt-out of the Processing of Personal Data for purposes of targeted advertising. CleriMed does not engage in targeted advertising; therefore, this right is not applicable.
Right to Non-Discrimination: You shall not be subject to discrimination for exercising CCPA/CPRA rights.
To exercise any rights under CCPA/CPRA, send written request to support@clerimed.com with your clinic name, authorized representative status, and specific right being exercised. CleriMed shall respond within forty-five (45) business days.
5.Data Retention and Deletion
5.1Data Retention During Active Subscription
During the period when Clinic maintains an active, paid subscription to the Platform, CleriMed shall retain all data necessary to deliver Platform services, including inventory records, treatment confirmations, audit logs, and system configuration data.
5.2Data Retention Upon Subscription Cancellation
Upon cancellation or expiration of Clinic's subscription, the following data retention schedule shall apply:
Days 1 through 90: CleriMed shall retain all clinic data in its entirety. This retention period permits Users to dispute billing transactions or process refunds; export data in available formats; reactivate subscriptions within this window without loss of historical data; and resolve any disputes with CleriMed regarding data accuracy or service delivery.
Day 91 and thereafter: CleriMed shall permanently and irreversibly delete all clinic data, with the following exceptions: anonymized and aggregated data used for peer benchmarking (retained indefinitely in anonymized form); audit logs related to billing disputes or suspected fraud investigations (retained for seven (7) years as required by tax and record-keeping regulations); tax records, including invoices and payment records (retained for seven (7) years as required by Internal Revenue Service regulations and Georgia state law); and data subject to legal hold in connection with pending litigation, regulatory investigation, or government subpoena (retained until legal obligation expires).
5.3Money-Back Guarantee Period
CleriMed offers a thirty (30) day money-back guarantee period beginning on the date of initial subscription. If Clinic cancels within this period: full refund shall be processed to the original payment method; all clinic data shall be retained pursuant to Section 5.2 retention schedule above; and no refund shall be issued if CleriMed discovers evidence of data fraud, Terms of Service violations, or Acceptable Use Policy violations.
5.4Early Deletion Request
Clinic may request deletion of data prior to expiration of the ninety (90) day retention period by sending written notice to support@clerimed.com. Early deletion requests shall be subject to approval by CleriMed in CleriMed's sole discretion. CleriMed shall not approve early deletion if data is subject to legal hold or if dispute resolution or refund processing is pending.
5.5GDPR Right to Erasure (Data Subject Requests)
Notwithstanding the 90-day retention schedule, if a Clinic staff member (data subject) in the European Union requests deletion of their Personal Data under GDPR Article 17, CleriMed shall delete such Personal Data within thirty (30) days of receiving the request, except where data is required to be retained for legal or tax purposes or is subject to legal hold. Clinic shall forward data subject requests to legal@clerimed.com.
6.Data Transfers and Subprocessors
6.1Third-Party Service Providers
CleriMed utilizes the following Subprocessors to assist in delivering the Platform and Processing data:
| Service Provider | Function | Processing Location |
|---|---|---|
| Supabase | Database storage, authentication, row-level security controls | United States (Amazon Web Services, US-East-1) |
| Vercel, Inc. | Platform hosting, content delivery network (CDN), SSL/TLS certificate provisioning | Global (primary: United States) |
| Stripe, Inc. | Payment processing, billing and invoice management | United States (PCI DSS Level 1 compliant) |
| Resend | Transactional email and notification delivery | United States |
| Upstash Technologies | Caching, rate limiting, temporary session data | Global (geo-routed based on user location) |
| Anthropic PBC | Artificial intelligence services for anomaly detection and narrative generation | United States (data in transit only; not retained by service provider) |
| Zenoti | Third-party appointment data ingestion via webhook | User's Zenoti account infrastructure (subject to Zenoti's privacy policies) |
| Sentry | Error logging, application monitoring, exception tracking | United States (error logs only; no Personal Data transmitted) |
6.2Data Protection Agreements
All Subprocessors are contractually bound by Data Processing Agreements that restrict their Processing of data solely to purposes necessary to deliver contracted services. Subprocessors are prohibited from using clinic data for their own business purposes or competitive purposes; selling, licensing, or sharing clinic data with third parties; combining clinic data with other datasets for profiling or analysis; or retaining clinic data beyond the contractual performance period.
6.3International Data Transfers
CleriMed's infrastructure and that of its primary Subprocessors is located within the United States. By creating an account and using the Platform, Users consent to the transfer of their data to the United States and Processing under United States law, subject to the requirements of applicable privacy regulations including GDPR and CCPA where applicable.
For European Union Clinics: CleriMed relies on Standard Contractual Clauses (as updated by the European Commission following the Schrems II decision) to ensure adequate safeguards for data transfers. A copy of CleriMed's Data Processing Agreement containing Standard Contractual Clauses is available upon request to legal@clerimed.com.
7.User Rights and Data Subject Requests
7.1Right of Access
Any authorized representative of Clinic may request access to all Personal Data and clinic operational data maintained by CleriMed in a portable, machine-readable format, including JSON or CSV export. CleriMed shall respond to requests within thirty (30) business days and shall provide the requested data within thirty (30) days of request submission.
7.2Right to Correction
Users may correct inaccurate or incomplete data directly through the Platform's administrative interface. For corrections that Users cannot make through the Platform, Users may submit a written request to support@clerimed.com with specific identification of inaccurate data and proposed correction. CleriMed shall process correction requests within fifteen (15) business days.
7.3Right to Deletion
Subject to the exceptions listed below, Users may request deletion of their clinic data by submitting written notice to support@clerimed.com. CleriMed shall delete requested data within thirty (30) business days, except that CleriMed shall retain data as follows: data within the ninety (90) day post-cancellation retention period; tax records and financial records (seven (7) years); data subject to legal hold or litigation; and anonymized and aggregated benchmarking data.
7.4Right to Data Portability
Users may request their clinic data in a standard, machine-readable, and portable format. CleriMed shall provide data in JSON, CSV, or other commonly used formats. CleriMed shall respond to portability requests within thirty (30) business days.
7.5Right to Withdraw Consent
Users may withdraw consent to Processing of data at any time by requesting account deletion or by selecting opt-out options within the Platform's notification preferences. Withdrawal of consent shall not retroactively invalidate Processing conducted prior to withdrawal.
7.6Right to Opt-Out
Users may opt-out of specific Processing activities through notification preferences, including:
- Email notifications for low stock alerts;
- Email notifications for product expiration warnings;
- Morning briefing email summaries;
- Weekly owner artificial intelligence narrative summaries;
- Inclusion of clinic data in peer benchmarking analysis (with acknowledgment that Platform performance may be affected).
7.7Exercise of Data Subject Rights
To exercise any right described in this Section 7, Users shall submit written request to support@clerimed.com or legal@clerimed.com with the following information:
- Clinic name and registered account email address;
- Name and title of requesting party;
- Specific right being exercised (access, correction, deletion, portability, withdrawal of consent, opt-out);
- Detailed description of the request; and
- Proof of authorization to act on behalf of Clinic.
CleriMed shall respond within thirty (30) business days. If CleriMed cannot fulfill a request in whole or in part, CleriMed shall explain the legal or technical reasons for denial and shall advise the User of alternative remedies.
8.Information Security
8.1Technical Security Measures
CleriMed maintains the following technical security controls:
Encryption in Transit: All data transmitted between User devices and CleriMed servers shall be encrypted using HTTPS with Transport Layer Security (TLS) 1.2 or higher.
Encryption at Rest: Data stored in CleriMed's database shall be encrypted using Advanced Encryption Standard (AES) with 256-bit keys.
Authentication: User accounts shall require multi-factor authentication. Passwords shall be hashed using bcrypt or equivalent cryptographic algorithm.
Access Control: CleriMed shall enforce role-based access control at the database level using Supabase Row-Level Security (RLS) policies. Users shall access only data appropriate to their assigned role.
Automatic Backup: Daily automated backups of all data shall be maintained in geographically distributed locations.
Disaster Recovery: CleriMed shall maintain disaster recovery and business continuity procedures to restore Platform functionality within twenty-four (24) hours of service interruption.
8.2Operational Security Measures
Limited Employee Access: CleriMed personnel shall have access to production databases only as necessary to deliver Platform services. Access shall be logged and monitored.
Secure Credential Management: All API keys, access tokens, and credentials shall be stored in environment variables or secure key management systems. No credentials shall be embedded in source code or configuration files.
Audit Logging: All access to production data shall be logged with timestamp, user identification, and action performed.
Code Security: CleriMed shall use automated security scanning tools in its continuous integration/continuous deployment (CI/CD) pipeline. All code shall pass security review prior to deployment.
Security Incident Response: CleriMed shall maintain an incident response plan to address suspected data breaches or unauthorized access.
8.3Compliance Standards
CleriMed's infrastructure utilizes hosting and database providers that maintain SOC 2 Type II compliance certification. Payment card information is processed through Stripe, which maintains PCI DSS Level 1 compliance. CleriMed itself does not store, process, or have access to complete payment card numbers.
8.4Data Breach Notification
In the event that CleriMed discovers or suspects unauthorized access to, theft of, or loss of any Personal Data or clinic operational data, CleriMed shall notify affected Clinic by email to the address on file within seventy-two (72) hours of discovery; provide detailed description of the data accessed, the nature of unauthorized access, and affected data categories; describe remediation steps CleriMed has taken or will take; and provide contact information for questions or further communication.
User Responsibility for Notification to Third Parties: Clinic shall be solely responsible for notifying staff members, state regulatory authorities, or other third parties as required by law.
9.International Considerations
9.1Data Hosting Location
All User data and Personal Data shall be hosted on servers located within the United States. By creating an account and using the Platform, Users acknowledge and accept that their data shall be processed and stored in the United States and shall be subject to United States law and legal process.
9.2GDPR Data Subject Rights
For clinics operating in the European Union or employing staff located in the European Union, CleriMed shall provide a Data Processing Agreement containing Standard Contractual Clauses upon request; respond to requests for data access, correction, deletion, and portability within applicable legal timeframes; maintain records of Processing activities and data subject requests; and cooperate with competent data protection authorities in investigation of complaints or inquiries.
9.3Compliance Responsibility
Clinic shall be responsible for complying with applicable data protection laws in Clinic's jurisdiction; ensuring that staff members' Personal Data is collected, processed, and shared in compliance with applicable law; providing privacy notices and obtaining necessary consents from staff; and responding to data subject access requests and exercising data subject rights on behalf of staff.
10.Changes to This Policy
10.1Amendments
CleriMed may amend this Policy at any time. Amendments shall be communicated to Users as follows:
Material Amendments: For changes that materially affect Users' privacy rights or data Processing practices, CleriMed shall provide electronic notice to registered Users at least thirty (30) days prior to the effective date. Users may reject material amendments by canceling their subscriptions within thirty (30) days of notice.
Non-Material Amendments: For changes that do not materially affect privacy rights or Processing practices, including clarifications, formatting corrections, or contact information updates, CleriMed may implement amendments without advance notice.
Emergency Amendments: For amendments required by law, court order, or regulatory authority, CleriMed may implement amendments immediately and shall provide notice as soon as practicable.
10.2Continued Use
Continued use of the Platform following the effective date of any amendment shall constitute Users' acceptance of the amended Policy.
11.Contact Information
11.1General Privacy Inquiries
For general questions regarding this Policy or CleriMed's privacy practices, Users may contact:
Email: support@clerimed.com Mailing Address: CleriMed, LLC, [REGISTERED BUSINESS ADDRESS], Cumming, Georgia 30041, United States11.2Data Subject Rights Requests
To submit requests to exercise data subject rights under GDPR, CCPA, or other privacy regulations, Users may contact:
Email: legal@clerimed.com Mailing Address: CleriMed, LLC, Legal Department, [REGISTERED BUSINESS ADDRESS], Cumming, Georgia 30041, United States12.Regulatory Compliance Notices
12.1Disclaimer Regarding Medical Advice and Regulatory Compliance
CleriMed provides inventory management and operational analytics tools only. CleriMed does not provide medical advice, clinical guidance, regulatory compliance advice, or recommendations regarding clinical decision-making. Users shall not rely on CleriMed's recommendations or reports as substitutes for professional legal, medical, or regulatory advice.
Clinic shall be solely responsible for compliance with:
- Food and Drug Administration (FDA) regulations concerning medical device reporting and adverse event reporting;
- Drug Enforcement Administration (DEA) regulations concerning controlled substance tracking and reporting;
- State medical board regulations concerning scope of practice and clinical supervision;
- State pharmacy board regulations concerning medication storage, tracking, and dispensing;
- Local licensing and permitting requirements for medical spa or clinic operations;
- Healthcare privacy regulations including HIPAA where applicable; and
- All other applicable federal, state, and local laws and regulations.
CleriMed is not a regulatory compliance system and shall not be relied upon as sole compliance mechanism.
12.2Data Controller and Data Processor Relationship
For purposes of GDPR and other data protection regulations:
Clinic acts as the Data Controller. Clinic determines the purposes and means of Processing Personal Data of clinic staff. CleriMed acts as the Data Processor. CleriMed Processes Personal Data only as instructed by Clinic and as necessary to deliver Platform services.
Clinic shall be responsible for:
- Determining lawful bases for Processing staff Personal Data;
- Obtaining necessary consents from staff members;
- Providing privacy notices to staff;
- Responding to data subject requests; and
- Documenting Processing activities and maintaining records of consent.
- Effective Date
- [SET AT LAUNCH — TBD]
- Last Updated
- August 7, 2026
- Version
- Version 1.1
End of Privacy Policy