Privacy Policy
Last Updated: May 2026
At HebaAI, we take your privacy and the privacy of your patients seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our digital clinic automation platform. This policy is aligned with the principles outlined in the Data Protection Act, 2011 of Trinidad and Tobago.
1. Information We Collect
We collect information in the following categories:
- Client Information: Information about the clinics and pharmacies that use our service, including business names, contact details, billing information, and account credentials.
- Patient Information (as a Data Processor): Information submitted by patients through our automated booking systems, secure portals, and AI chatbot/WhatsApp integrations. This may include names, contact details, appointment dates, and brief medical context. We process this strictly on behalf of the Client (the healthcare provider).
- Usage Data: Automatically collected data regarding how the platform is accessed and used, including IP addresses, browser types, and interaction metrics to help us improve the service.
2. How We Use Your Information
We use the collected data for various purposes:
- To provide, maintain, and support our Service.
- To process transactions and manage your account.
- To facilitate patient communication and appointment booking on your behalf.
- To detect, prevent, and address technical issues and security breaches.
- To improve the AI models and system functionalities (using anonymized and aggregated data only).
3. Information Disclosure
We do not sell, trade, or rent your personal information or your patients' personal information to third parties. We may share information with trusted third-party service providers (e.g., hosting providers, database managers, SMS/WhatsApp API gateways) who assist us in operating our platform, so long as those parties agree to keep this information confidential and comply with data protection standards.
We may also disclose information when legally required to do so to comply with the law of Trinidad and Tobago, enforce our site policies, or protect ours or others' rights, property, or safety.
4. Data Security
We implement a variety of security measures to maintain the safety of your personal information. We utilize encryption, secure server hosting, and regular security audits. However, please understand that no method of transmission over the internet, or method of electronic storage, is 100% secure.
5. Data Retention
We will retain your information only for as long as is necessary for the purposes set out in this Privacy Policy, or as dictated by your instructions as the Data Controller regarding patient data, subject to legal obligations.
6. Your Rights
Subject to local laws, you may have the right to access, correct, update, or delete your personal information. If you are a patient of a clinic using HebaAI, please direct your data access requests to your healthcare provider, as they are the Data Controller of your medical information.
7. Contact Us
If you have any questions about this Privacy Policy, please contact us at: support@hebaai.com