Privacy Policy

Last updated: July 2026

1. Who we are

Your Clinic Heart is a brand of Socialogic (Romany, LLC) ("we", "the platform"): an appointment management and operational intelligence platform for specialty clinics, operated by Socialogic. Each clinic that uses the platform is responsible for its patients' data; we process it on the clinic's behalf as its business associate under HIPAA.

2. What information we collect

We collect only the administrative information needed to schedule and manage appointments:

  • Name, phone number, email address, and date of birth.
  • Insurance plan and record number (assigned by the office).
  • Appointments, their status, and preferences (language, contact channel).
  • Card token (through Stripe; never the card number itself).

We do not store clinical information(conditions, diagnoses, medications, allergies, medical history, or clinical forms). That lives in the clinic's electronic health record (EHR).

3. This is protected health information (PHI)

Even minimal, the fact that a person has an appointment at a specialty clinic is protected health information. We treat it as such: encrypted at rest and in transit, with role-based access controls and audit logs. We do not include PHI in URLs, technical logs, or analytics tools.

4. How we use your information

  • To schedule, confirm, remind, modify, and cancel your appointments.
  • To send you notifications through your preferred channel (email/SMS).
  • To process the no-show charge when applicable (see Terms).
  • To generate aggregated, de-identified reports for clinic administration (no name lists).

5. Who we share it with

We do not sell your information. We share it only with providers that need it to operate the service:

  • Hosting and database (Fly.io) — this is where your information lives, under a Business Associate Agreement (BAA).
  • Payments (Stripe) — to validate the card and charge no-shows.
  • Messaging (Sinch/Mailgun) — they only receive your phone number or email to deliver a neutral notice (date, time, and a secure link). They never see health detailsor your clinic's name; your appointment details are served by our platform when you open the link.
  • Your clinic's EHR — only your demographic data, and only at check-in at the office.

6. Consent and communications (SMS/texts)

At booking we ask for a double consent: (a) to receive automated communications about your appointments by text and email (TCPA), and (b) to the handling of your protected health information under our privacy practices and HIPAA. Both are required to complete an online booking.

You can opt out of text messages at any time by replying STOP (and opt back in with START), and out of emails using the unsubscribe link. Reply HELP for help. Message frequency varies with your appointments. Message and data rates may apply.

Mobile opt-in data and consent are not shared with third parties or affiliates for marketing or promotional purposes. Messages are used solely for notices about your appointments and to send you a one-time verification code when you request one: when you enter your number while booking, to confirm it belongs to you, and to sign in to your account. Those codes expire in 10 minutes, are stored hashed, and are sent from a phone number separate from the one used for appointment notices.

7. Security

We enforce per-clinic isolation at the database level (Row-Level Security), encryption in transit and at rest, role-based access control, and audit logging. No method is 100% infallible, but we follow practices aligned with HIPAA.

8. Your rights

You may request access to your administrative information or its correction by contacting your clinic. For requests related to your medical record, contact the clinic directly.

If you believe the privacy of your health information has been violated, you may file a complaint with your clinic or with the U.S. Department of Health and Human Services, Office for Civil Rights (HHS OCR). We will not retaliate for filing a complaint.

9. Breach notification

If a breach affecting your protected health information occurs, we will notify the affected clinic without undue delay so that you can be informed as required by the HIPAA Breach Notification Rule.

10. Retention

We retain your administrative information while you are a patient of the clinic and as required by applicable law and our agreements with the clinic.

11. Minors

The platform is for adults 18 years or older.

12. Changes and contact

We may update this policy; the current version will be published here. For questions, write to hello@yourclinicheart.com.