Legal
Privacy Policy
Last updated: August 13, 2026
This Privacy Policy explains how ClinicZora Solutions LLC (“ClinicZora,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you visit cliniczora.com, request a demo, or use the ClinicZora software platform (the “Services”).
1. Who we are
ClinicZora is a practice-management software platform for clinical teams. We do not deliver clinical care. Customer clinics and their authorized users control client records entered into the platform.
Contact: info@cliniczora.com (general) · privacy@cliniczora.com (privacy requests).
2. Scope
This Policy covers:
- Our public marketing website and demo/contact forms
- Accounts and usage of the ClinicZora application
- Integrations you connect (for example Google or Microsoft calendars)
Where we process Protected Health Information (PHI) on behalf of a covered entity or business associate customer, that processing is also governed by a signed Business Associate Agreement and applicable law.
3. Information we collect
We may collect:
- Account and contact data: name, email, phone, clinic name, role, and billing contact details.
- Website and demo data: information you submit on contact forms, including practice size and interests.
- Customer content: client, scheduling, notes, billing, HR, and related operational data entered by authorized users.
- Calendar integration data: when connected, calendar events, free-busy, and the email tied to the calendar account, used only to provide scheduling features.
- Usage and device data: log data, approximate location derived from IP, browser type, and feature-usage analytics for security and product improvement.
- Cookies and similar technologies: as described in our Cookie Policy.
4. How we use information
- To provide, maintain, secure, and improve the Services
- To respond to demos, support requests, and account administration
- To send service, security, and (where permitted) product communications
- To sync calendars and enable booking, reminders, and scheduling workflows
- To detect, investigate, and prevent fraud, abuse, and security incidents
- To comply with law and enforce our Terms
5. Google API services
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access calendar data only as needed for scheduling and do not use that data for advertising or sell it to third parties.
7. Security
We use administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption in transit, access controls, audit logging, and per-clinic isolation. More detail is on our Security page. No method of transmission or storage is 100% secure.
8. Retention
We retain information for as long as needed to provide the Services, meet legal and contractual obligations, resolve disputes, and enforce agreements. Calendar OAuth tokens are retained while an integration is active and revoked/deleted when you disconnect. Customer content retention after account termination is described in the Terms of Service.
9. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. For marketing emails, you may unsubscribe using the link in the message.
Clinic customers control much of the client data in their accounts. End clients of a clinic should contact that clinic for access or correction of clinical records.
To exercise rights related to ClinicZora-held personal data, email privacy@cliniczora.com.
10. HIPAA and health information
We design the Services around HIPAA-aligned workflows and offer a Business Associate Agreement on paid plans. We are not “HIPAA-certified” (no such certification exists). PHI handling is further described in the BAA executed with eligible customers.
11. Children
The Services are directed to clinics and professionals, not to children under 13. We do not knowingly collect personal information from children through the marketing site. Clinics that enter pediatric client data are responsible for appropriate notices and consents under applicable law.
12. International transfers
We may process information in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms.
13. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date will change, and for material changes we may provide additional notice (for example email or in-product notice).
14. Contact
Privacy questions: privacy@cliniczora.com
ClinicZora Solutions LLC
Related: Privacy Policy · Terms of Service · Business Associate Agreement · Cookie Policy · Security
