Legal

Privacy policy

Last updated 5 August 2026

FlexicaAI provides an AI-powered health management system to health practices. This policy explains what we do with information, and it separates two very different situations, because they carry different obligations.

If you are simply reading this website, almost none of it applies to you. We do not ask you for anything here. If you are a practice using FlexicaAI, or a patient of one, the sections from Using FlexicaAI onwards are the ones that matter.

Visiting this website

This site has no sign-up form, no contact form and no comment box. There is nowhere on it to type anything, so we collect nothing about you here. Getting in touch means WhatsApp, email or a phone call, and at that point you have chosen what to tell us.

We set one cookie on the public site. It is called klenic_theme, it stores nothing but the word light or dark, and it exists so the page does not flash the wrong colour when you come back. It is not used to identify you or to follow you anywhere.

There is no analytics, no advertising pixel and no third-party tracker on this site. Our hosting provider keeps standard server logs, which include IP addresses, for security and troubleshooting.

Using FlexicaAI

When a practice uses FlexicaAI, the practice decides what is recorded about its patients and why. In data protection terms the practice is the controller and we are the processor. We hold and process that information to run the service the practice has asked for, and not for our own purposes.

Depending on which parts of the product a practice uses, this can include:

  • Staff account details, which is a name, username, email address, role and permissions.
  • Patient details, which is a name, phone number, age or date of birth, gender, address and any notes the practice adds.
  • Appointments, visits and clinical notes, including the audio of a consultation where the voice scribe is used and the transcript produced from it.
  • Prescriptions and treatment plans.
  • Money records, meaning invoices, receipts, payments, discounts and expenses.
  • WhatsApp messages sent to and received from patients, together with their delivery status.
  • An activity log of actions taken in the account, which records who did what and when.

We do not sell any of this, we do not share it with advertisers, and we do not use one practice's data to benefit another. Each practice's records are scoped to that practice and every query is filtered by it.

Artificial intelligence, and what leaves our systems

Two features send content to outside providers, and we would rather be specific about it than hide it behind the word cloud.

  • Voice scribe. When a clinician records a consultation, the audio is sent to OpenAI for transcription using the Whisper model, and the resulting text is sent to Anthropic to be structured into a draft note using Claude. Both may therefore process clinical content and anything the clinician said aloud.
  • Message drafting. Where the product suggests a reply to a patient message, the message text is sent to Anthropic for the same reason.

Every output of these features arrives as a draft. It is not saved to a patient record until a clinician has reviewed it and approved it. The software will not finalise a clinical note or a prescription on its own.

We keep the original AI draft alongside the clinician's corrected version. That is how we measure whether the scribe is getting better or worse, and it stays inside the practice's own account.

WhatsApp messages

Appointment confirmations, reminders, recall messages and receipts are delivered over WhatsApp. That means a patient's phone number and the content of the message pass through our messaging provider and through Meta, which operates WhatsApp. Their handling of the message is governed by their own terms, which we do not control.

A patient who does not want these can tell the practice, which can stop them.

Who else is involved

We keep the list of outside providers short on purpose. At the time of writing it is:

  • Our hosting and database providers, who store the data and run the application.
  • OpenAI, for voice transcription.
  • Anthropic, for turning a transcript into a structured draft.
  • Our WhatsApp messaging provider, and Meta, for delivering messages.

Each of them receives only what their function needs. If we add a provider that handles patient data, we will update this page.

How long we keep things

This one deserves plain language, because our deletion behaviour is deliberately not what people assume.

Deleting a record in FlexicaAI does not erase it. It moves to a Trash area where the practice can restore it, by default for 30 days. After that window it disappears from the practice's view, but it is still held in the database. This is intentional. Health records get deleted by accident, and a patient history that can be destroyed by one mis-click is a liability for the practice and for the patient.

Permanent erasure is possible and is performed by us on request, for example where a practice has a legal obligation to erase a record. Ask us and we will do it.

While an account is active we keep its data for as long as the practice keeps using the service. If a practice leaves, we can return an export of its data and then remove it.

How it is protected

These are the measures actually in place, not aspirations:

  • Traffic is encrypted in transit over HTTPS.
  • Passwords are stored as bcrypt hashes and are never recoverable, by us or by anyone else.
  • Sessions use an opaque token in a cookie that JavaScript cannot read, and only a hash of that token is stored.
  • Access is role based and can be narrowed per person, so a receptionist need not see clinical notes.
  • Every practice's records are separated, and each request is scoped to a single practice.
  • Actions on patient data are written to an audit log.

No system is perfectly secure, and we will not claim otherwise. If we become aware of a breach affecting a practice's data, we will tell that practice without unnecessary delay.

Where the data is

The application and its database are hosted with our infrastructure providers, and the AI and messaging providers named above operate internationally, so processing can take place outside your country. We are building towards keeping data in the region it comes from, and we will say so here when that is in place rather than before.

Patient requests

If you are a patient and you want to see, correct or remove what a practice holds about you, ask the practice. They control the record and they can act on it directly. If they need us to help, they can contact us and we will.

We do not act on a patient request on our own, because we cannot verify who you are or what your relationship with the practice is. The practice can.

Changes to this policy

If we change how we handle information we will update this page and move the date at the top. Where a change is significant for practices using the product, we will tell them directly rather than relying on them noticing.

Contact us

Questions about this policy, or a request about data, can go to [email protected] or 03010186111. Our terms of service are on the terms page.

FlexicaAI, www.flexicaai.com