Scale Your Clinic
The Method AI Receptionist Process Results FAQ
Book a call →
Legal · Document 01

Privacy Policy

How we collect, use, and protect information from clinic operators who work with us and the patients in their care.

Effective · January 1, 2026  ·  Version · 2.1
Contents
  1. Scope & who we are
  2. Information we collect
  3. How we use information
  4. Patient health information
  5. Sharing & third parties
  6. Cookies & tracking
  7. Data retention
  8. Your rights & choices
  9. Security
  10. Children
  11. International users
  12. Changes to this policy
  13. Contact us

Scope and who we are

Scale Your Clinic (“Scale Your Clinic”, “we”, “us”, “our”) is a marketing and operations program for regenerative medicine clinics. This Privacy Policy explains how we handle information when you visit our website, contact us about our program, or work with us as a clinic client.

This policy covers two distinct categories of information: (i) information about the clinic operator (the practice owner, staff, and authorized representatives) and (ii) information about patients of the clinics we work with. Different rules and protections apply to each, as described below.

Information we collect

Information you give us

  • Contact information such as your name, business name, phone number, and email address when you book a strategy call or contact us through our website.
  • Practice information such as your specialties, treatment menu, geography, current marketing channels, and goals discussed during our onboarding.
  • Account and billing information for engaged clinics, including payment method and billing address, processed through our payment provider.
  • Communications you send to us, including email, SMS, and recorded strategy calls when you consent to recording.

Information collected automatically

  • Standard server log information such as IP address, browser type, device type, referring page, and timestamps.
  • Usage data on how you interact with our website (pages viewed, links clicked) via privacy-preserving analytics.
  • Performance metrics from advertising platforms (Meta, Google) for the campaigns we run on behalf of clinic clients.

Information from third parties

  • Lead information that your clinic forwards to us for handling by our AI Receptionist or for inclusion in your patient acquisition funnel.
  • Performance data from advertising platforms, payment processors, and EMR integrations that you authorize us to connect to.

How we use information

We use the information described above for the following purposes:

  • To deliver the Scale Your Clinic program — running ads, building landing pages, deploying the AI Receptionist, and managing the patient acquisition pipeline for your clinic.
  • To respond to inquiries, schedule strategy calls, and onboard new clinic clients.
  • To process payments and administer the business relationship.
  • To improve our program, tooling, and creative assets through aggregated, de-identified performance analysis.
  • To send operational communications (program updates, weekly reports, compliance notices) and, with your consent, occasional educational content.
  • To comply with applicable laws, advertising platform policies, and our contractual obligations.

Patient health information

When we operate the AI Receptionist or patient platform on behalf of a clinic, we may handle information that could be considered protected health information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA).

For each engaged clinic that handles PHI, we enter into a written Business Associate Agreement (BAA) before connecting any system that may receive PHI. The BAA governs our handling of PHI and supplements this Privacy Policy with the specific protections required by HIPAA and applicable state law.

Practical effect for patients: if you are a patient contacting a clinic that uses our AI Receptionist, your conversation is logged inside your clinic’s secure patient record and is treated as PHI. We do not sell or use that information for any purpose outside delivering services to your clinic.

We do not use PHI for marketing, for training general-purpose AI models, or for any purpose other than performing services for the clinic that collected it.

Sharing and third parties

We do not sell personal information. We share information only as described below:

  • Service providers. Hosting, analytics, communications (voice and SMS), payment processing, advertising platforms, and EMR/financing partners we use to deliver the program. Each provider is bound by contract to handle information only as instructed by us and to meet appropriate security standards.
  • With your clinic. Patient and lead information collected through your funnel is shared with your clinic as the controller of that information.
  • Legal compliance. When required by law, court order, or to investigate suspected violations of our terms.
  • Business transfers. In connection with a merger, acquisition, or sale of assets, with notice to affected parties where required.

We do not share PHI except as permitted under the applicable Business Associate Agreement and HIPAA.

Cookies and tracking

Our website uses cookies and similar technologies for the following limited purposes:

  • Essential cookies that enable the site to function (for example, remembering whether you have dismissed a notice).
  • Analytics that help us understand which pages are most useful to clinic owners considering the program.
  • Conversion tracking from advertising platforms when you arrive through one of our ads.

You can control cookies through your browser settings. Disabling cookies will not affect your ability to browse the site or contact us.

Data retention

We retain information only for as long as needed to provide the services you have requested, to comply with our legal obligations, to resolve disputes, and to enforce our agreements.

  • Inquiry and website-visitor information: up to 24 months from last contact, unless you become a client.
  • Client and billing records: for the duration of the engagement plus seven years, as required for tax and accounting purposes.
  • Patient health information: handled per the applicable BAA and the clinic’s retention policy. PHI is deleted on clinic instruction at the end of the engagement.
  • Aggregated, de-identified data: retained indefinitely for benchmarking and program improvement.

Your rights and choices

Depending on where you live, you may have rights under applicable privacy laws (including GDPR, CCPA/CPRA, and similar state laws) to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Delete information, subject to our legal and contractual retention requirements.
  • Object to or restrict certain processing.
  • Receive a portable copy of information you provided to us.
  • Opt out of marketing communications at any time using the unsubscribe link in any email or by contacting us.

To exercise any of these rights, email privacy@scale-your-clinic.com. For requests concerning PHI, contact the clinic where you receive care — they are the controller of your PHI, and we will support their response.

Security

We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit and at rest, access controls based on the principle of least privilege, audit logging on systems that handle PHI, and routine security reviews of our infrastructure and third-party providers.

No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you and applicable authorities as required by law.

Children

Our website and services are directed to clinic operators and adult patients. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child, please contact us so we can delete it.

International users

We operate primarily from the United States. If you are accessing our services from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different data protection rules than your country of residence.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Effective” date above and, where appropriate, notify clinic clients directly. We encourage you to review this policy periodically.

Contact us

If you have questions about this Privacy Policy or how we handle your information, contact us:

  • Email: privacy@scale-your-clinic.com
  • Mail: Scale Your Clinic, Attn: Privacy Officer, Tucson, AZ
Scale Your Clinic

Patient acquisition, engineered for regenerative medicine. Compliance-first, AI-powered, done-for-you.

Contact
info@scale-your-clinic.com Book a strategy call →
© 2026 Scale Your Clinic. All rights reserved.
Privacy Policy  ·  Terms of Service