Security and Data Handling
What we do with clinic data, said plainly — who can see it, what is kept, and what a clinician stays in control of.
Fertility records are among the most sensitive in medicine. Clinics evaluating us ask the same questions in the same order — who else can see this, where does it live, what happens when we leave — so this page answers those directly rather than in a brochure. Where we cannot claim something, it says so. For your rights and how to exercise them, see the privacy policy.
One agreement covers everyone who touches your data
Every service that processes patient information is Microsoft Azure, under one BAA.
Most clinical AI runs on a patchwork — one vendor for the model, another for transcription, a third for messaging, a cloud provider underneath. Each one is a separate agreement, a separate breach surface, and a separate answer your privacy officer has to chase. Ours is not built that way. The models, the document storage, and the voice, SMS and email all run on Microsoft Azure, covered by a single Business Associate Agreement we hold with Microsoft. Language models run in Azure AI Foundry, inside that same agreement, and Microsoft's terms are that prompts and completions are not used to train models. There is no separate model vendor to ask about, and no transcription company holding a copy of your consultations.
Where your data is processed
East US 2, and we would rather you heard that from us than found it in a questionnaire.
Production runs in Microsoft Azure's East US 2 region, in the United States. That covers the application, the database, stored documents, the language models, and voice, SMS and email delivery. This describes the hosted service; on-premises and private-cloud (VPC) deployments are also available. We say it plainly because your privacy impact assessment needs it, and because a vendor who is vague about this is usually being vague for a reason. If your clinic requires processing in a particular jurisdiction, raise it in the first conversation — it shapes the deployment, and we would rather scope it honestly at the start than discover it at signature.
The controls that are actually in the product
Each of these is something the system does, not something we intend to do.
A clinician signs, or nothing happens
Human in the loop, by construction
Generated notes arrive as drafts. Every sentence is traced back to the line of transcript it came from, and anything the encounter did not support is flagged rather than filled in. Nothing enters the patient record until a clinician has reviewed and signed it.
Least privilege, and a record of who looked
Role-based access with a full audit trail
Access is role-based and scoped to the least a role needs. Every record carries an audit trail, so the question "who saw this, and when" has an answer rather than an assumption.
Consent tracked per patient and per channel
Not one blanket flag
A patient consenting to a text message has not thereby consented to a recorded call. Consent is held per patient and per channel, and the system checks it at the point of use rather than at sign-up.
Audio retention ships at zero days
Keeping a recording is a decision you make
The default retention period for captured audio is zero days — the recording is used to produce the draft and is not kept. Retaining audio is something a clinic switches on deliberately, not something it has to remember to switch off.
You can leave, and take nothing with us
Deletion that is a deletion
When a clinic ends its contract we delete its data — patients, cycles, embryology results, referrals, documents, messages, and the audit records of all of it. Not a flag marking rows as hidden while the content stays in the table: a real delete. The one exception is encrypted backups, which age out on their retention schedule, and we will tell you what that schedule is.
Encrypted in transit and at rest
Plus authentication and access logging
Data is encrypted in transit and at rest, behind authentication and access controls, with logging on access. The privacy policy sets out the safeguards in full.
What clinics ask before they sign
Answered as directly as we can answer them today.
Who owns the clinic's data?
The clinic does. We process it to provide the service the clinic asks for. We do not sell or rent personal data, and we do not use it to build a product for someone else.
Where is the data hosted?
In Microsoft Azure's East US 2 region, in the United States. That covers the application, the database, stored documents, the language models, and voice, SMS and email delivery. This describes the hosted service; on-premises and private-cloud (VPC) deployments are also available. If your clinic needs processing in a particular jurisdiction, raise it early — it shapes the deployment rather than being a setting we can change afterwards.
Does PHIPA require our data to stay in Canada?
No. PHIPA contains no data localization requirement. What it requires is that the clinic, as the health information custodian, takes reasonable steps to safeguard personal health information and stays accountable for the service providers it uses, wherever they operate. Some other provinces are stricter — Nova Scotia restricts public bodies from storing personal information outside Canada, and Quebec's Law 25 requires an assessment before personal information leaves the province. We are telling you where the data is so your own assessment can account for it. Your privacy officer should reach their own conclusion; we are describing our practices, not advising you on the law.
Who else touches our patients' data?
Microsoft, and no one else. The language models run in Azure AI Foundry, documents are stored in Azure Blob Storage, and voice, SMS and email are delivered through Azure Communication Services — all under a single Business Associate Agreement we hold with Microsoft. There is no separate model vendor, no third-party transcription company, and no messaging provider outside that agreement.
Will you sign our BAA?
Yes. We will also work from your paper rather than insisting on ours. Because every service that processes patient information sits under our Microsoft agreement, the flow-down obligations a BAA requires are already in place rather than something we would be arranging after signing with you.
Is our patient data used to train models?
No. Language models run in Azure AI Foundry under our agreement with Microsoft, whose terms are that prompts and completions submitted to the service are not used to train models. Your clinic's data is processed to deliver the service to your clinic, and it does not become training material for anyone — us included.
Which regulations do you work under?
We build for HIPAA in the United States and PHIPA and PIPEDA in Canada, and we sign Business Associate Agreements with clinics that need one. We do not hold a SOC 2, ISO 27001 or HITRUST certification, and we would rather say that than let a badge on a page imply one. The privacy policy covers collection, use, safeguards, international transfers and your rights in full.
Can you support our privacy impact assessment?
Yes, and under Ontario law the assessment is yours to make rather than ours — a health information custodian assesses its own use of a service. What we owe you is the inputs: the data flows, the subprocessors, where processing happens, what is retained and for how long, and where a human sits in the loop. Ask and we will put all of it in writing for your deployment.
What happens to a recording after a consultation?
By default it is not kept. Retention for captured audio ships set to zero days, so the audio is used to produce the draft note and then discarded unless the clinic has deliberately configured otherwise.
What happens to our data if we stop using you?
We delete it. Patients, cycles, embryology results, referrals, stored documents, messages, and the audit records of all of them are removed from the database — a real delete, not a flag that hides the rows while the content stays in the table. Encrypted backups are the one exception: they age out on their retention schedule rather than being edited, and we will tell you what that schedule is. If you want your data back before it goes, we will export it first.
Is the interactive demo safe to use with real information?
No, and please do not. The demo contains synthetic data only — every patient, clinician, appointment and message in it was invented. Accounts created inside it, and everything done with them, are deleted automatically within about a week. It is a demonstration environment, not a clinical system, and information entered there is not covered by the safeguards that apply to a real deployment.
Send us your security questionnaire
If your clinic has a review process, we would rather go through it early than late.
Book a demo and bring the questionnaire. The questions we cannot answer yet, we will say so — that is more useful to both of us than a document that sounds complete.