Scope and who we are
Scale Your Clinic (“Scale Your Clinic”, “we”, “us”, “our”) is a marketing and operations program for regenerative medicine clinics. This Privacy Policy explains how we handle information when you visit our website, contact us about our program, or work with us as a clinic client.
This policy covers two distinct categories of information: (i) information about the clinic operator (the practice owner, staff, and authorized representatives) and (ii) information about patients of the clinics we work with. Different rules and protections apply to each, as described below.
Information we collect
Information you give us
- Contact information such as your name, business name, phone number, and email address when you book a strategy call or contact us through our website.
- Practice information such as your specialties, treatment menu, geography, current marketing channels, and goals discussed during our onboarding.
- Account and billing information for engaged clinics, including payment method and billing address, processed through our payment provider.
- Communications you send to us, including email, SMS, and recorded strategy calls when you consent to recording.
Information collected automatically
- Standard server log information such as IP address, browser type, device type, referring page, and timestamps.
- Usage data on how you interact with our website (pages viewed, links clicked) via privacy-preserving analytics.
- Performance metrics from advertising platforms (Meta, Google) for the campaigns we run on behalf of clinic clients.
Information from third parties
- Lead information that your clinic forwards to us for handling by our AI Receptionist or for inclusion in your patient acquisition funnel.
- Performance data from advertising platforms, payment processors, and EMR integrations that you authorize us to connect to.
How we use information
We use the information described above for the following purposes:
- To deliver the Scale Your Clinic program — running ads, building landing pages, deploying the AI Receptionist, and managing the patient acquisition pipeline for your clinic.
- To respond to inquiries, schedule strategy calls, and onboard new clinic clients.
- To process payments and administer the business relationship.
- To improve our program, tooling, and creative assets through aggregated, de-identified performance analysis.
- To send operational communications (program updates, weekly reports, compliance notices) and, with your consent, occasional educational content.
- To comply with applicable laws, advertising platform policies, and our contractual obligations.
Patient health information
When we operate the AI Receptionist or patient platform on behalf of a clinic, we may handle information that could be considered protected health information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA).
For each engaged clinic that handles PHI, we enter into a written Business Associate Agreement (BAA) before connecting any system that may receive PHI. The BAA governs our handling of PHI and supplements this Privacy Policy with the specific protections required by HIPAA and applicable state law.
We do not use PHI for marketing, for training general-purpose AI models, or for any purpose other than performing services for the clinic that collected it.
Data retention
We retain information only for as long as needed to provide the services you have requested, to comply with our legal obligations, to resolve disputes, and to enforce our agreements.
- Inquiry and website-visitor information: up to 24 months from last contact, unless you become a client.
- Client and billing records: for the duration of the engagement plus seven years, as required for tax and accounting purposes.
- Patient health information: handled per the applicable BAA and the clinic’s retention policy. PHI is deleted on clinic instruction at the end of the engagement.
- Aggregated, de-identified data: retained indefinitely for benchmarking and program improvement.
Your rights and choices
Depending on where you live, you may have rights under applicable privacy laws (including GDPR, CCPA/CPRA, and similar state laws) to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete information, subject to our legal and contractual retention requirements.
- Object to or restrict certain processing.
- Receive a portable copy of information you provided to us.
- Opt out of marketing communications at any time using the unsubscribe link in any email or by contacting us.
To exercise any of these rights, email privacy@scale-your-clinic.com. For requests concerning PHI, contact the clinic where you receive care — they are the controller of your PHI, and we will support their response.
Security
We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit and at rest, access controls based on the principle of least privilege, audit logging on systems that handle PHI, and routine security reviews of our infrastructure and third-party providers.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you and applicable authorities as required by law.
Children
Our website and services are directed to clinic operators and adult patients. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child, please contact us so we can delete it.
International users
We operate primarily from the United States. If you are accessing our services from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different data protection rules than your country of residence.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Effective” date above and, where appropriate, notify clinic clients directly. We encourage you to review this policy periodically.
Contact us
If you have questions about this Privacy Policy or how we handle your information, contact us:
- Email: privacy@scale-your-clinic.com
- Mail: Scale Your Clinic, Attn: Privacy Officer, Tucson, AZ