Privacy
Privacy overview
This page explains how Cairetech approaches privacy and data protection while the formal policy documents are prepared. It is not a substitute for a finalized Privacy Policy, DPA, or customer agreement.
Clinics remain responsible for their patient relationships and, where applicable, act as data controllers. Cairetech is building our solutions as a processor-style platform for clinical workflows, with privacy, access control, and transparent processing as design goals.
We will publish a GDPR-ready Privacy Policy covering what data is collected, legal bases, retention, transfers, and individual rights. Until that document is finalized and reviewed, treat the points below as directional product principles rather than binding legal commitments.
What we will document clearly
- Categories of practitioner, clinic, and patient data processed by the product
- Purposes of processing and clinic/controller responsibilities
- Sub-processors and any third-party AI or cloud services involved
- Retention, deletion, and exit handling when a clinic stops using our solutions
- Security measures such as access control, encryption, and audit logging once validated
- How individuals can exercise access, correction, deletion, and related rights
Waitlist, early-access, referral, and advisory forms on this website currently prepare a local message and do not claim to store data in a production backend. Contact and outreach flows will include explicit consent and an unsubscribe path when automated marketing is enabled.
For questions about privacy while formal documents are in progress, contact dpo@cairetech.com.
Privacy FAQ
How our solutions handle patient data
Answers for clinics evaluating our solutions. This is how the product is being designed — not a substitute for the Privacy Policy, DPA, and security documentation that will govern production use.