Legal
Privacy Policy
This policy explains what Clinical Systems International collects, why, and what we do with it. It covers two very different kinds of information: data about the clinics and staff who use our service, and the patient records those clinics store inside it. Our obligations differ for each, so they are described separately.
1. Who we are
Clinical Systems International (“CSI”, “we”, “us”) provides clinical records, imaging and patient-portal software to healthcare practices, together with an X-ray line-drawing and analysis service.
2. Two roles, two sets of duties
For information about our customers — the clinic, its staff accounts, billing details and support correspondence — we act as a data controller. We decide why and how that information is used, and this policy governs it.
For patient records that a clinic stores in our system, we act as a data processor. The clinic remains the controller. We process those records only on the clinic’s documented instructions, under the data-processing terms in our agreement with that clinic. We do not decide what patient data is collected, we do not use it for our own purposes, and we do not sell it under any circumstances.
3. What we collect as a controller
- Account information — name, work email, telephone number, role and the clinic you belong to.
- Authentication data — password hashes (never the password itself), two-factor codes, and a record of which devices you have chosen to trust.
- Billing information — clinic name, billing address, tax identifiers, the plan you are on, and the number of X-ray drawings requested in each period.
- Support correspondence — the messages you send us and our replies.
- Technical logs — IP address, browser and device type, pages requested and timestamps, kept for security and troubleshooting.
Payment card details are not collected or stored by us. Card payments are handled by Stripe, our payment processor, who receives them directly. We see only the outcome of a payment and the last four digits of the instrument used.
4. What we process as a processor
On behalf of clinics, our system stores patient records including identifying details, clinical histories and examinations, radiographs and other imaging, measurements and analyses derived from that imaging, treatment plans, appointment records and messages between a clinic and its patients.
Where a clinic asks us to perform line drawing, our analysis team accesses the specific radiograph submitted in order to mark landmarks and calculate the deviation from the alignment model. Access is limited to the staff performing that work, and it is logged.
5. Why we use it
- To provide the service and keep your account working.
- To authenticate users and protect accounts from unauthorised access.
- To calculate and collect the fees you owe, including metered line-drawing volume.
- To provide support when you ask for it.
- To detect, investigate and prevent security incidents and misuse.
- To meet legal, tax and regulatory obligations that apply to us.
We do not use patient data to train machine-learning models, and we do not use any of the information described here for advertising.
6. Keeping records separate
Each clinic sees only its own records. That boundary is enforced twice and independently: once in the application, where every read is checked against the signed-in user and the clinic being asked about, and again in the database through row-level security policies that re-apply the same rule. A mistake in one layer does not defeat the other.
A request for a record belonging to another clinic returns “not found” rather than “forbidden”, because a forbidden response would itself reveal that the record exists.
7. Who else sees data
We share information only with service providers who help us run the service:
- Our cloud hosting and database provider, which stores the data.
- Stripe, which processes payments and holds the billing relationship for card data.
- Our email delivery provider, used to send sign-in codes and service notices.
Each is bound by contract to process data only on our instructions and to protect it. We do not sell data or share it with advertisers. We will disclose information where we are legally compelled to, and where we can lawfully do so we will tell the affected clinic first.
8. Where data is held and for how long
Data is held on managed infrastructure and may be processed in a country other than your own. Where that happens we rely on appropriate safeguards for the transfer.
Patient records are retained for as long as the clinic’s account is active, and thereafter according to the clinic’s instructions and the medical-records retention period that applies to the clinic. On termination we make the clinic’s data available for export, then delete it within ninety days unless a longer period is required by law. Account and billing records are kept for as long as tax and accounting rules require. Backups are retained on a rolling cycle and deletions propagate to them as that cycle turns.
9. Security
- Data is encrypted in transit and at rest.
- Two-factor authentication is required on every account; codes expire after ten minutes and are discarded after five incorrect attempts.
- A device may be trusted for thirty days, after which the second factor is required again.
- Access by our staff is role-limited and logged.
- Backups are monitored and restore-tested, so that a backup which silently stops running is detected rather than assumed.
No system is perfectly secure. If a breach affects patient data we will notify the affected clinic without undue delay so that it can meet its own notification duties.
10. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable form. To exercise any of these in respect of your own account data, write to us at the address below.
If you are a patient and want to see, correct or delete your clinical record, please contact your clinic. The clinic controls that record; we act on its instructions and will support it in responding to you.
11. Cookies
We use only the cookies necessary to run the service — keeping you signed in, remembering a trusted device, and maintaining security. We do not use advertising or cross-site tracking cookies.
12. Changes
If we change this policy materially we will notify account holders by email before the change takes effect. The date at the top of this page always reflects the current version.
Questions about this document? Write to info@clinicalsystemsinternational.com, or post to Clinical Systems International, 304 Evergreen Drive, Brick, NJ, USA.
