Privacy Policy
How we collect, use, and protect your data on Clynevia
This policy details how Clynevia collects, processes, and protects personal and clinical data when you access or use the platform.
Who We Are
Clynevia is a clinical workspace platform (SaaS) built for independent nutrition practitioners and private dietetics clinics to build personalized meal plans, manage patient health records, coordinate appointments, and publish patient guidance.
Platform Operator: Clynevia, operated by Huthayfa J. H Salman
Contact Email: privacy@clynevia.com
Information We Collect
Clinic & Practitioner Data
When onboarding your clinic on Clynevia, we collect:
- Clinic name and contact information (Email, phone number)
- Account credentials (Username, encrypted passwords)
- Subscription, billing tier, and payment status
- Clinic profile settings (Logos, branding colors, print templates, regional preferences)
Patient & Clinical Data
The practitioner inputs client health files into the workspace, including:
- Personal details (Name, age, gender, contact number)
- Anthropometric and health metrics (Weight, height, body composition, medical history, dietary allergies)
- Customized nutrition plans (Meals, portions, calories, macronutrient targets)
- Consultation schedules, attendance, and clinical follow-up notes
- Clinical observations and reports
Important Clinical Notice: Patients do not create logins or direct accounts on Clynevia. All records are entered directly by the clinic. The clinic remains the designated Data Controller responsible for data accuracy and client consent.
Usage & Telemetry Data Upcoming Feature
- Access logs, authentication events, and feature interactions
- IP addresses, browser client, and operating system info
- Pages visited and features used
- Time spent in each section
In the Current Early Access Phase: We do not run invasive behavioral trackers or commercial analytics within practitioner accounts. General telemetry will be documented prior to any public release.
How We Use Collected Information
We use stored data strictly for legitimate clinical workspace operations:
- Core Provisioning: Enabling dietitians to author meal plans, monitor metrics, and manage visit schedules.
- Secure Client Sharing: Generating private, unguessable mobile links for patients to view their assigned nutrition programs without app installation.
- Support & Updates: Sending critical account alerts, platform notices, and direct support.
- Security & Tenant Isolation: Ensuring robust data integrity and preventing unauthorized cross-tenant access.
- Regulatory Compliance: Complying with applicable statutory accounting and record-keeping mandates.
- Platform Improvement: Understanding usage patterns to improve performance and develop useful features.
Data Storage, Security & Isolation
We apply rigorous security measures to protect sensitive clinical records:
- PostgreSQL Database: All workspace records are hosted on hardened relational databases featuring strict tenant-level isolation (Row-Level Security).
- Encryption in Transit: All communications enforce modern TLS 1.3 / HTTPS encryption.
- Authentication: Secure JSON Web Token (JWT) architecture with salted and hashed credentials.
- Automated Backups: Systematic database backup regimes Upcoming Feature.
- Restricted Access: Only authenticated clinic operators have access to their private patient roster.
In the Current Early Access Phase: Automated cross-region disaster recovery backups are in rollout. We advise keeping offline copies of historical files during the private preview.
In the event of a security breach resulting in a leak of patient data, we commit to notifying the affected clinic, the Palestinian Ministry of National Economy, and other competent authorities as soon as we become aware of it.
Connected Messaging Channels
A clinic may connect its own WhatsApp Business number, Facebook Page, and Instagram professional account to Clynevia so that patient messages can be read and answered alongside that patient’s record. Connecting a channel is optional, is always initiated by the clinic, and requires the clinic to grant permission through Meta’s own authorization dialog.
Where a channel is connected, we receive from Meta Platforms and store:
- Message content: the text, images, audio, and files exchanged between the clinic and the person messaging it.
- Sender identifiers: the WhatsApp phone number, or the platform-scoped identifier and public display name supplied by Facebook or Instagram.
- Message metadata: timestamps, delivery and read status, and which channel the message arrived on.
- Channel credentials: encrypted access tokens and account identifiers required to receive and send on the clinic’s behalf.
This data serves a single purpose: displaying the clinic’s own conversations inside the clinic’s workspace, and delivering the replies its staff write or explicitly approve. We do not:
- Sell, rent, or share messaging data with any third party.
- Use it for advertising, audience building, or profiling.
- Use it to train machine-learning models.
- Send any message on a clinic’s behalf that its staff did not write or approve.
- Expose messaging data to any other clinic — conversations sit behind the same tenant isolation as every other clinic record.
The clinic remains the Data Controller for these conversations, exactly as it is for clinical records, and is responsible for the lawful basis on which it communicates with the people who message it. A clinic may disconnect any channel at any time from its workspace settings, or revoke Clynevia’s access from its own Meta business settings; disconnecting halts all further collection immediately.
Retention: messaging data is retained while a channel is connected and for 30 days after the channel is disconnected or the account is closed, after which it is permanently deleted. Earlier deletion may be requested at any time through our Data Deletion process, and we honor deletion requests relayed to us by Meta Platforms on a user’s behalf.
Our use of data obtained through WhatsApp, Messenger, and Instagram is governed by the Meta Platform Terms and Developer Policies in addition to this policy.
Booking Through an AI Assistant
Some clinics let you book an appointment from inside an AI assistant such as ChatGPT, using the "Clynevia Booking" plugin. It is optional and works only for clinics that asked for it to be switched on. This section explains what happens to your information when you book this way.
What we receive: When you ask the assistant to book, it sends us only the following:
- Booking details: the clinic you chose and the appointment time you asked for.
- Identification: your full name and your phone number.
- App name: the name of the assistant the booking was made through.
We do not receive the rest of your conversation with the assistant. We do not:
- Ask for or accept any health information through the assistant. If the clinic wants a form completed before your visit, you receive a link and fill it in yourself on the clinic's Clynevia page, not in the conversation.
- Sell this information or share it with advertisers.
- Send any automatic message to your phone number because of the booking. The clinic contacts you to confirm the time.
- Take or process any payment through the assistant.
Why we use it: to place your booking request with the clinic you chose, to let you check, cancel or move that booking later, to show the clinic where the request came from, and to limit misuse of the booking service.
Who receives it: only the clinic you booked with. Your name, phone number and requested time appear in its schedule as a booking request awaiting its confirmation, exactly as if you had booked from its own booking page.
Your booking code: after booking you receive a short code. The code, together with the phone number you booked with, lets you check, cancel or move the booking from any conversation. Keep the code to yourself: anyone who has both the code and your phone number can cancel the booking. After the first day we keep the code only in a form that cannot be read back.
Retention:
- A booking you were shown but did not confirm expires after 15 minutes and is deleted one day after it expires.
- The technical record of an assistant's connection to us is deleted about a month after it was last used. It contains the app's name and no information about you.
- A confirmed booking becomes part of the clinic's records and is kept for as long as the clinic keeps your file. You can ask the clinic to delete it, or use our data deletion page.
- We keep a log of booking actions (prepared, booked, cancelled, moved) for the clinic. It contains no names, phone numbers or other personal details.
The assistant's provider: what you type or say to an AI assistant is also handled by the company that provides it (OpenAI, for ChatGPT) under its own privacy policy. We do not control how that company uses your conversation.
Third-Party Disclosures
We do not sell, monetize, or lease your clinic or patient data to third parties. Data is processed only with reputable technical providers necessary for operations:
- Infrastructure Providers: Secure cloud hosting, database nodes, and transactional messaging.
- Meta Platforms: where a clinic has connected a WhatsApp, Facebook, or Instagram channel, messages pass between Clynevia and Meta in order to be delivered. Nothing is disclosed to Meta beyond what is required to deliver a message the clinic has authored.
- Statutory Compliance: When strictly mandated under lawful judicial court orders.
- Protecting Rights: When necessary to defend legal rights or protect user safety.
Data Retention & Deletion
Your clinic data is preserved for as long as your subscription is active. Upon account termination:
- Patient files and custom meal plans are queued for permanent deletion within 30 days.
- Immediate erasure can be requested via our Data Deletion process.
- Invoices and transaction metadata may be retained up to 7 years to fulfill tax and fiscal obligations.
In the Current Early Access Phase: Full account deletion is handled by the Clynevia team after you contact us, while targeted deletion of a patient profile, meal plan, or article is already available in the platform. Self-service account deletion is an upcoming feature for public release.
Your Privacy Rights
In accordance with global privacy principles (such as GDPR and regional equivalents), practitioners retain full rights to:
- Access: Obtain a verifiable copy of stored personal records.
- Rectification: Correct or modify inaccurate clinic information.
- Erasure: Request permanent removal of clinic records.
- Restriction: Restrict processing in qualifying circumstances.
- Portability: Receive clinic data in machine-readable formats (Excel / CSV).
- Objection: Restrict processing under qualified circumstances.
To exercise any of these rights, contact us using the email address below.
The Clinic as Data Controller
Legal Framework: With respect to patient and client health files, the clinic acts as the Data Controller, while Clynevia functions strictly as the Data Processor. Consequently:
- The clinic obtains patient authorization for record storage.
- The clinic dictates clinical record retention rules.
- Clynevia processes patient data only according to the clinic’s instructions.
- Patients wishing to modify or erase records should coordinate directly with their treating practitioner.
Changes to this Policy
We may periodically update this policy to reflect operational improvements. Notice will be published here with an updated revision date.
In the Current Early Access Phase: Email and in-platform notifications are upcoming features. We communicate material changes directly during the private preview.
Contact Privacy Support
For questions or privacy requests, please reach out directly:
Email: privacy@clynevia.com