Skip to main content
Clickless
Legal

Privacy Policy

Effective Date: May 2026

At Clickless, Inc. (“Clickless,” “we,” “us,” or “our”), we are committed to protecting privacy and safeguarding the personal information we collect and process. This Privacy Policy describes how Clickless collects, uses, discloses, and protects personal information in connection with our websites, applications, browser extensions, workflow tools, and related services that link to this Privacy Policy (collectively, the “Services”).

The Services are designed for use by healthcare providers, medical practices, clinics, health plans, organizations, and their authorized users to support healthcare, administrative, operational, documentation, billing, scheduling, and related workflows.

This Privacy Policy applies to personal information we collect from or about website visitors, prospective customers, customers, provider users, practice administrators, authorized users, business contacts, and other individuals who interact with us or use the Services.

When we create, receive, maintain, or transmit protected health information (“PHI”) on behalf of a healthcare provider, medical practice, clinic, health plan, or other covered entity, we act as a Business Associate under HIPAA. Our processing of PHI is governed by the applicable Business Associate Agreement, HIPAA, customer instructions, and applicable law. If there is a conflict between this Privacy Policy and a Business Associate Agreement, the Business Associate Agreement controls with respect to PHI.

This Privacy Policy does not replace the privacy notices or privacy practices of healthcare providers, medical practices, clinics, health plans, or other covered entities that use the Services. Those entities are responsible for their own privacy notices and for handling patient requests regarding PHI as required by applicable law.

By using or accessing the Services, you acknowledge that you have read and understand this Privacy Policy. Where required by applicable law, we will obtain your consent before collecting, using, or disclosing your information.

1. HIPAA and PHI

Certain information processed through the Services may be protected health information, or “PHI,” under the Health Insurance Portability and Accountability Act and its implementing regulations, collectively referred to as “HIPAA.”

When Clickless creates, receives, maintains, or transmits PHI on behalf of a healthcare provider, medical practice, clinic, health plan, or other covered entity, Clickless acts as a “Business Associate” under HIPAA. In those circumstances, our processing of PHI is governed by the applicable Business Associate Agreement, HIPAA, customer instructions, and applicable law.

PHI may include identifiable patient information that is accessed, entered, displayed, copied, transferred, transmitted, organized, structured, or otherwise processed through the Services in connection with provider, practice, clinic, billing, scheduling, documentation, care-management, or other healthcare workflows.

HIPAA provides specific protections for the privacy and security of PHI and restricts how PHI may be used and disclosed. When we process PHI as a Business Associate, we use and disclose PHI only as permitted by the applicable Business Associate Agreement, HIPAA, customer instructions, and applicable law.

This Privacy Policy also describes how we collect, use, disclose, and protect personal information that is not PHI, such as website visitor information, demo-request information, business contact information, account information, support communications, billing contact information, device information, usage information, and other information collected outside our role as a Business Associate.

HIPAA does not apply to information that is not PHI. For example, information that a website visitor, prospective customer, provider user, practice administrator, or business contact provides directly to Clickless outside of a covered-entity healthcare workflow may not be PHI, although it may still be personal information protected by other privacy laws.

2. Information We Collect

We collect information in connection with our websites, applications, browser extensions, workflow tools, and related services. The information we collect depends on how you interact with us, whether you are a website visitor, prospective customer, healthcare provider, practice administrator, authorized user, or other representative of a customer.

2.1 Business Contact Information

We may collect business contact information from customers, prospective customers, vendors, partners, and other individuals who interact with us, including:

  • name;
  • business email address;
  • business phone number;
  • job title or role;
  • employer, practice, clinic, or organization name;
  • mailing address;
  • communication preferences;
  • information provided through demo requests, contact forms, sales inquiries, or event registrations.

We use this information to communicate with you, respond to inquiries, provide product information, manage customer relationships, schedule demos, and conduct ordinary business operations.

2.2 Account and User Information

When a customer or authorized user creates or uses an account, we may collect information such as:

  • name;
  • email address;
  • username or user ID;
  • password or authentication information;
  • role, permissions, and access level;
  • organization, practice, or clinic affiliation;
  • account settings and preferences;
  • login history;
  • authentication events;
  • user status, such as active, inactive, invited, or suspended.

We use this information to create and manage accounts, authenticate users, provide access to the Services, maintain security, apply role-based permissions, and administer customer organizations.

2.3 Customer and Organization Information

We may collect information about the healthcare providers, medical practices, clinics, organizations, and other customers that use the Services, including:

  • organization name;
  • practice or clinic name;
  • business address;
  • billing address;
  • tax or business-identification information, if needed for billing or contracting;
  • administrator contact information;
  • subscription, plan, contract, and billing details;
  • configuration settings;
  • authorized users;
  • integrations requested or enabled by the customer;
  • customer support history.

We use this information to provide and administer the Services, manage contracts, process billing, configure customer accounts, provide support, and comply with legal and business obligations.

2.4 Product Usage and Activity Information

When authorized users access or use the Services, we may collect usage and activity information, including:

  • pages, screens, or features accessed;
  • buttons clicked or actions taken;
  • dates and times of access;
  • session information;
  • workflow activity;
  • feature usage;
  • task status and completion information;
  • error messages;
  • diagnostic logs;
  • performance information;
  • user preferences and settings;
  • audit-log events, such as sign-in, sign-out, data access, task execution, permission changes, and other security-relevant events.

We use this information to provide, maintain, secure, troubleshoot, audit, and improve the Services.

2.5 Device, Browser, and Technical Information

We may collect technical information from devices, browsers, and systems used to access the Services, including:

  • IP address;
  • device type;
  • browser type and version;
  • operating system;
  • device identifiers;
  • referring and exit pages;
  • access dates and times;
  • approximate location derived from IP address;
  • language settings;
  • cookie identifiers;
  • system logs;
  • crash reports;
  • network and performance information.

We use this information to operate the Services, maintain security, prevent misuse, troubleshoot errors, understand usage patterns, and improve performance.

2.6 Cookies and Similar Technologies

We may use cookies, pixels, web beacons, local storage, and similar technologies on our websites and, where applicable, within the Services. These technologies may collect information such as browser and device information, pages viewed, links clicked, referring website, session identifiers, preferences, and analytics information.

We may use these technologies to operate our websites, remember preferences, analyze website traffic, improve user experience, secure the Services, and support business communications.

We do not intentionally use cookies, pixels, or similar tracking technologies to collect PHI. We do not use PHI for targeted advertising.

2.7 Communications and Support Information

If you contact us, request support, submit feedback, participate in training, or otherwise communicate with us, we may collect information such as:

  • name;
  • email address;
  • phone number;
  • organization;
  • content of your message;
  • support tickets;
  • chat messages;
  • call notes;
  • feedback;
  • troubleshooting information;
  • screenshots, files, or other materials you choose to provide.

Important: Please do not submit PHI through general contact forms, sales forms, or support channels unless the channel is intended and authorized for that purpose under an applicable Business Associate Agreement.

2.8 Billing and Payment Information

We may collect billing and payment-related information, including:

  • billing contact name;
  • billing email address;
  • billing address;
  • subscription or plan information;
  • invoice details;
  • payment status;
  • limited payment information, such as the last four digits of a payment card, where applicable.

We may use third-party payment processors to process payments. We do not typically store full payment-card numbers ourselves.

2.9 Integration and Connected-System Information

If a customer enables integrations with third-party systems, including electronic health record systems, scheduling systems, billing systems, identity providers, communication tools, or other software platforms, we may collect or process information necessary to provide the integration, including:

  • integration configuration settings;
  • system identifiers;
  • organization or tenant identifiers;
  • user identifiers;
  • access tokens or authentication credentials, where necessary;
  • sync status;
  • integration logs;
  • data exchanged between the Services and the connected system.

Where integrated systems contain PHI, our processing of that PHI is governed by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

2.10 Protected Health Information Processed on Behalf of Covered-Entity Customers

Our Services may create, receive, maintain, transmit, or otherwise process PHI on behalf of healthcare providers, medical practices, clinics, health plans, or other covered entities. Depending on the customer’s use of the Services, PHI may include:

  • patient names;
  • dates of birth;
  • contact information;
  • medical record numbers or other patient identifiers;
  • appointment information;
  • provider information;
  • clinical notes;
  • visit information;
  • diagnosis, treatment, medication, allergies and adverse reactions, laboratory, imaging, referral, insurance, billing, or care-management information;
  • information displayed in or retrieved from an electronic health record or other healthcare system;
  • information entered, extracted, copied, transferred, organized, structured, or otherwise processed by the Services for use by authorized healthcare users.

When we process PHI on behalf of a covered-entity customer, we act as a Business Associate under HIPAA. Our processing of PHI is governed by our Business Associate Agreement with the applicable covered entity, HIPAA, customer instructions, and applicable law. If there is a conflict between this Privacy Policy and a Business Associate Agreement, the Business Associate Agreement controls with respect to PHI.

2.11 Automation-Generated or Workflow-Generated Information

The Services may use automation, browser-based agents, or related technologies to assist authorized users with workflows, including navigating webpages, reading webpage or application content, clicking buttons or links, entering information into fields, extracting or organizing information, and completing user-directed tasks.

In connection with these workflows, the Services may collect, process, or generate information such as user instructions, webpage or application content, interface and page-structure information, workflow activity, task outputs, user edits or approvals, automation logs, audit logs, diagnostic information, system-generated metadata, error information, and integration responses.

Where automation-generated or workflow-generated information contains PHI, we treat it as PHI and process it according to the applicable Business Associate Agreement, HIPAA, customer instructions, and applicable law.

2.12 De-Identified or Aggregated Information

We may create or use de-identified, aggregated, or statistical information that does not reasonably identify an individual, customer, patient, or authorized user. We may use such information to understand usage trends, improve product performance, develop and enhance features, monitor security and reliability, and generate internal business analytics.

Where information is de-identified from PHI, we de-identify it in accordance with applicable legal requirements and contractual obligations.

2.13 Information from Third Parties

We may receive information from third parties, including:

  • customers and their authorized administrators;
  • healthcare providers and practice staff;
  • EHR, scheduling, billing, or other integrated systems;
  • identity providers;
  • payment processors;
  • business partners;
  • service providers;
  • publicly available sources;
  • marketing or event partners, where permitted by law.

We use this information to provide the Services, manage accounts, support integrations, communicate with customers and prospective customers, maintain security, and operate our business.

2.14 Information We Do Not Intentionally Collect Through General Website Use

Our public website and general marketing channels are not intended to collect PHI. We do not intentionally collect patient medical information, clinical information, insurance information, or other PHI through public website forms, demo-request forms, newsletter forms, or general contact forms.

If you submit PHI to us through an unauthorized channel, we may delete it, secure it, or handle it as required by applicable law and our contractual obligations.

3. How We Use Information

We use the information we collect to provide, operate, secure, support, and improve the Services. The purposes for which we use information depend on the type of information, how it was collected, and whether the information is PHI processed on behalf of a covered-entity customer.

3.1 To Provide and Operate the Services

We use information to provide, maintain, and operate the Services, including to:

  • create, manage, and authenticate user accounts;
  • configure customer organizations, roles, permissions, and settings;
  • enable authorized users to access and use the Services;
  • provide workflow automation, browser-based agent functions, and related product features;
  • process user instructions, workflow requests, and task inputs;
  • interact with websites, applications, EHRs, payer portals, scheduling systems, billing systems, and other connected systems as directed or configured by authorized users;
  • enter, extract, copy, transfer, organize, or structure information as part of user-directed workflows;
  • complete workflow steps such as navigation, clicks, text input, form completion, and task execution;
  • provide integrations, synchronization, and data exchange with systems enabled by the customer.

3.2 To Support Healthcare Provider and Practice Workflows

We use information to support administrative, operational, clinical-support, billing, scheduling, documentation, and other healthcare workflows performed by authorized users. This may include using information to:

  • help prepare, complete, transfer, or organize workflow entries, messages, forms, or other user-directed task outputs;
  • assist with scheduling, eligibility, prior authorization, billing, claims, referral, documentation, or care-management workflows;
  • retrieve, copy, transfer, organize, or structure information from connected systems;
  • populate fields or prepare entries based on user instructions and customer configuration;
  • reduce manual workflow steps for authorized users.

Where these workflows involve PHI, we process PHI only as permitted by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

3.3 To Secure the Services and Maintain Auditability

We use information to protect the security, availability, and integrity of the Services, including to:

  • authenticate users;
  • enforce access controls and permissions;
  • monitor for unauthorized access, misuse, abuse, or security threats;
  • maintain audit logs and security logs;
  • investigate suspicious activity;
  • detect and prevent fraud or misuse;
  • troubleshoot errors and system failures;
  • support incident response;
  • comply with security, privacy, and compliance obligations.

3.4 To Provide Customer Support

We use information to respond to support requests, troubleshoot problems, and assist customers and authorized users. This may include using account information, support messages, screenshots or files submitted by authorized users, diagnostic logs, workflow logs, error reports, integration status information, and system-response information.

Please do not submit PHI through general support, sales, or contact channels unless the channel is intended and authorized for that purpose under an applicable Business Associate Agreement.

3.5 To Communicate With Customers and Users

We use business contact, account, and communication information to:

  • respond to inquiries;
  • provide product updates;
  • send administrative notices;
  • provide security or service-related alerts;
  • schedule demos, trainings, or onboarding sessions;
  • communicate about billing, contracts, renewals, or account administration;
  • send information about features, services, or events that may be relevant to business contacts.

We do not use PHI for targeted advertising.

3.6 To Improve and Develop the Services

We may use information to understand, maintain, improve, and develop the Services, including to:

  • analyze product performance and usage trends;
  • identify errors, latency, reliability issues, or workflow failures;
  • improve usability and product design;
  • develop new features;
  • test and validate functionality;
  • improve automation quality, accuracy, and safety;
  • evaluate system performance and security.

Where permitted by applicable law and customer agreements, we may use de-identified, aggregated, or statistical information to improve the Services and understand usage trends.

3.7 To Manage Billing, Contracts, and Business Operations

We use information to operate our business, including to:

  • manage customer accounts and subscriptions;
  • process invoices and payments;
  • administer contracts and renewals;
  • maintain business records;
  • manage vendors and service providers;
  • conduct internal reporting and business planning;
  • enforce agreements;
  • respond to customer administrative requests.

3.8 To Comply With Legal and Compliance Obligations

We may use information to comply with legal, regulatory, contractual, and compliance obligations, including to:

  • comply with HIPAA where applicable;
  • comply with Business Associate Agreements;
  • respond to lawful requests from courts, regulators, law enforcement, or government authorities;
  • enforce our agreements and policies;
  • resolve disputes;
  • protect the rights, safety, and property of our company, customers, users, patients, or others;
  • investigate and prevent unlawful, unauthorized, or harmful activity.

3.9 How We Use PHI

When we create, receive, maintain, or transmit PHI on behalf of a healthcare provider, medical practice, clinic, health plan, or other covered entity, we act as a Business Associate under HIPAA.

We use PHI only as permitted by:

  • the applicable Business Associate Agreement;
  • customer instructions;
  • HIPAA;
  • other applicable laws and regulations.

We do not sell PHI or use PHI for targeted advertising.

3.10 Automated Outputs and User Review

The Services may produce workflow outputs, completed fields, extracted information, structured data, task results, or automated workflow actions. These outputs are intended to assist authorized users and support customer workflows.

Authorized users are responsible for reviewing, approving, confirming, or correcting outputs and actions as appropriate before relying on them for clinical, billing, administrative, or operational purposes.

4. Browser Agent and Workflow Automation

Our Services may include browser-based workflow automation tools that assist authorized users with healthcare, administrative, operational, documentation, billing, scheduling, and related workflows.

The Services may help authorized users perform user-directed workflow steps, such as navigating webpages or applications, reading webpage or application content, clicking buttons or links, selecting menu options, entering information into fields, copying or pasting information, submitting forms, and completing other configured workflow actions.

The Services operate based on user instructions, customer configuration, enabled integrations, available webpage or application content, and permissions granted by the customer or authorized user.

In connection with browser-based workflow automation, the Services may collect, process, or generate information such as:

  • user-provided task instructions and workflow requests;
  • webpage, application, EHR, payer portal, scheduling, billing, or other system content needed to perform the workflow;
  • interface and page-structure information, such as labels, field names, buttons, links, URLs, page titles, DOM data, accessibility-tree data, and metadata;
  • workflow activity, including clicks, text input, selections, navigation, form submissions, copy/paste actions, and related before-and-after page changes;
  • workflow outputs, such as draft entries, completed fields, extracted fields, structured data, task results, and system responses;
  • user edits, approvals, rejections, confirmations, overrides, or corrections;
  • automation logs, audit logs, diagnostic information, integration logs, timestamps, task status, error messages, and exception reports;
  • screenshots or visual page information, if enabled by the customer, submitted by an authorized user, or necessary to provide, secure, or troubleshoot the Services.

Where this information contains PHI, we treat it as PHI and process it only as permitted by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

The Services are designed to assist authorized users with workflow automation and do not replace professional judgment, clinical decision-making, billing judgment, or customer review and approval processes. Authorized users are responsible for reviewing, approving, confirming, or correcting outputs and actions as appropriate before relying on them for clinical, billing, administrative, operational, or other purposes.

5. Sharing and Subprocessors

We may disclose information to customers, authorized users, service providers, subprocessors, and other parties as described below. The types of information we disclose depend on the nature of the Services, the customer’s configuration, the purpose of the disclosure, and whether the information is PHI.

5.1 Sharing With Customers and Authorized Users

We may disclose information to the customer organization that uses the Services and to its authorized users, administrators, workforce members, or representatives.

For example, we may make information available to customers and authorized users to:

  • provide access to the Services;
  • display workflow results, task outputs, completed fields, messages, forms, extracted information, or structured data;
  • maintain user accounts, roles, permissions, and settings;
  • provide audit logs, automation logs, and activity records;
  • support customer administration, compliance, security, and troubleshooting;
  • provide reports, usage information, or service-related information.

Where information contains PHI, it is made available only as permitted by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

5.2 Sharing With Service Providers and Subprocessors

We may disclose information to third-party service providers and subprocessors that help us provide, operate, secure, support, and improve the Services.

These service providers and subprocessors may provide services such as:

  • cloud hosting and infrastructure;
  • data storage and database services;
  • authentication and identity-management services;
  • security, monitoring, logging, and audit services;
  • customer support and ticketing tools;
  • error tracking and diagnostics;
  • analytics for product performance and website usage;
  • email, communication, and notification services;
  • payment processing and billing support;
  • professional services, including legal, accounting, compliance, and security consulting.

We require service providers and subprocessors to process information only for the purposes of providing services to us or as otherwise permitted by applicable law and contract.

Where a service provider or subprocessor creates, receives, maintains, or transmits PHI on our behalf, we require appropriate contractual protections, including a Business Associate Agreement where required by HIPAA.

5.3 Integrated Systems and Customer-Enabled Connections

If a customer enables integrations with third-party systems, we may disclose, receive, or exchange information with those systems as necessary to provide the Services.

These systems may include:

  • electronic health record systems;
  • scheduling systems;
  • billing and claims systems;
  • payer portals;
  • eligibility or prior authorization systems;
  • identity providers;
  • communication platforms;
  • document-management systems;
  • other software, websites, applications, or services enabled by the customer.

Customers are responsible for authorizing, configuring, and managing integrations and for ensuring that connected systems are appropriate for their workflows and legal obligations.

Where integrated systems contain or receive PHI, our processing and disclosure of PHI are governed by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

5.4 Sharing With Healthcare Providers, Practices, and Covered Entities

When we provide Services to healthcare providers, medical practices, clinics, health plans, or other covered entities, we may disclose PHI and related workflow information to the applicable customer and its authorized users as necessary to provide the Services.

We may also disclose PHI to other parties as directed by the customer or as permitted by the applicable Business Associate Agreement, HIPAA, and applicable law.

We do not independently disclose PHI to third parties for advertising, data brokerage, or unrelated commercial purposes.

5.5 Business Transfers

We may disclose or transfer information in connection with an actual or proposed merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction. If such a transaction involves PHI, we will handle PHI in accordance with the applicable Business Associate Agreement, HIPAA, and applicable law.

5.6 Legal, Compliance, and Safety Disclosures

We may disclose information when we believe disclosure is necessary or appropriate to:

  • comply with applicable law, regulation, legal process, subpoena, court order, or government request;
  • comply with HIPAA, Business Associate Agreements, or other contractual obligations;
  • enforce our agreements, terms, and policies;
  • protect the rights, privacy, safety, or property of our company, customers, users, patients, or others;
  • detect, investigate, prevent, or respond to fraud, security incidents, misuse, unauthorized access, or unlawful activity;
  • support audits, investigations, or compliance reviews.

Where information is PHI, we will make such disclosures only as permitted or required by the applicable Business Associate Agreement, HIPAA, and applicable law.

5.7 Professional Advisors

We may disclose information to professional advisors, such as attorneys, accountants, auditors, insurers, consultants, and compliance advisors, where reasonably necessary for our business operations, legal compliance, risk management, and protection of our rights. Where such information includes PHI, we will disclose it only as permitted by the applicable Business Associate Agreement, HIPAA, and applicable law.

5.8 De-Identified or Aggregated Information

We may disclose de-identified, aggregated, or statistical information that does not reasonably identify an individual, patient, customer, or authorized user. We may use or disclose such information for product improvement, service performance analysis, security and reliability monitoring, business reporting, research and development, industry benchmarking, or general analytics.

Where information is de-identified from PHI, we de-identify it in accordance with applicable legal requirements and contractual obligations.

5.9 Marketing and Website Analytics Disclosures

We may disclose limited non-PHI website, business contact, or marketing information to service providers that help us operate our website, understand website usage, communicate with prospective customers, or manage marketing activities.

We do not disclose PHI to advertising networks, data brokers, or marketing analytics providers. We do not use PHI for targeted advertising. We do not sell PHI.

5.10 International Processing

Some of our service providers or subprocessors may process information in locations outside the jurisdiction where the customer or user is located. Where required, we use appropriate contractual, legal, and security measures for such processing. Where information is PHI, international processing, if any, will be handled in accordance with the applicable Business Associate Agreement, HIPAA, customer instructions, and applicable law.

5.11 Subprocessor List

We may maintain a list of subprocessors that support the Services. Customers may request information about applicable subprocessors by contacting us at privacy@useclickless.com or by reviewing our published subprocessor list, if available.

Where required by contract, we will provide notice of material subprocessor changes in accordance with the applicable customer agreement or Business Associate Agreement.

5.12 No Sale of PHI or Health Data

We do not sell PHI. We do not use PHI for targeted advertising. We do not disclose PHI to data brokers or advertising networks.

Where applicable law defines “sale,” “sharing,” or similar terms differently, we will comply with applicable legal requirements and provide any required rights or disclosures.

6. Analytics and Tracking

We may use analytics, cookies, logs, and similar technologies to operate, secure, understand, and improve our websites and Services. The types of analytics and tracking technologies we use depend on the context, including whether you are visiting our public website, using an authenticated product environment, or interacting with customer-enabled workflows.

6.1 Website Analytics

We may use analytics tools on our public websites to help us understand how visitors interact with our website, improve website performance, evaluate marketing effectiveness, and communicate with prospective customers.

Website analytics may collect information such as:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • referring website;
  • pages viewed;
  • links clicked;
  • time spent on pages;
  • approximate location derived from IP address;
  • cookie identifiers or similar online identifiers;
  • date and time of visits.

We use this information to understand website usage, improve our website, troubleshoot issues, and support ordinary business and marketing activities.

6.2 Cookies and Similar Technologies

We may use cookies, pixels, web beacons, local storage, software development kits, and similar technologies to:

  • operate and secure our websites and Services;
  • remember user preferences;
  • maintain sessions;
  • authenticate users;
  • measure website performance;
  • analyze website traffic;
  • understand how users interact with our website or Services;
  • improve user experience;
  • detect and prevent fraud, abuse, or unauthorized access.

You may be able to control cookies through your browser settings. If you disable certain cookies, some parts of our website or Services may not function properly.

6.3 Product Usage Analytics

We may collect product usage and operational analytics from authenticated users of the Services to help us provide, maintain, secure, troubleshoot, and improve the Services.

Product usage analytics may include:

  • account and organization identifiers;
  • user role or permission level;
  • features accessed;
  • workflow activity;
  • task status and completion information;
  • timestamps;
  • performance data;
  • error messages;
  • diagnostic logs;
  • audit logs;
  • integration status;
  • system-response information.

We use this information to operate the Services, improve reliability and usability, troubleshoot issues, maintain auditability, monitor security, and support customer administration.

6.4 PHI and Tracking Technologies

We do not intentionally use cookies, pixels, advertising tags, or similar tracking technologies to collect PHI. We do not disclose PHI to advertising networks, data brokers, or marketing analytics providers. We do not use PHI for targeted advertising. We do not sell PHI.

Where analytics or logging information contains PHI because of the customer’s use of the Services, we treat that information as PHI and process it only as permitted by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

6.5 Authenticated Product Environment

Our authenticated product environment is intended for provider, practice, clinic, or other customer-authorized use. We may collect operational, security, audit, diagnostic, and workflow information within the authenticated product environment as necessary to provide, secure, support, and improve the Services.

We do not use advertising pixels or cross-context behavioral advertising technologies in authenticated product areas where PHI may be displayed, entered, processed, or transmitted.

6.6 Workflow Automation Logs

Because the Services may include workflow automation, browser-based agents, or related technologies, we may collect logs and analytics related to automated workflows, including:

  • user workflow requests;
  • task status and completion information;
  • workflow steps and system events;
  • webpage or application interaction events;
  • error messages and exception reports;
  • diagnostic and performance information;
  • integration logs and system responses;
  • user edits, approvals, rejections, confirmations, or corrections.

We use this information to provide the Services, maintain auditability, troubleshoot issues, improve workflow reliability, detect errors, and support security and compliance.

Where this information contains PHI, we treat it as PHI and process it only as permitted by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

6.7 Marketing Analytics

We may use limited marketing analytics on our public website and marketing communications to understand engagement with our business communications, such as whether an email was opened or whether a link was clicked.

Marketing analytics may be used to:

  • evaluate interest in our Services;
  • respond to inquiries;
  • improve business communications;
  • manage prospective customer relationships;
  • measure website or campaign effectiveness.

We do not use PHI, patient information, clinical information, insurance information, or authenticated product workflow information for targeted advertising or marketing analytics.

6.8 Third-Party Analytics Providers

We may use third-party service providers to help us perform website analytics, product analytics, security monitoring, diagnostics, error tracking, and performance monitoring. These providers may process information on our behalf only as necessary to provide services to us or as otherwise permitted by contract and applicable law.

Where a third-party provider creates, receives, maintains, or transmits PHI on our behalf, we require appropriate contractual protections, including a Business Associate Agreement where required by HIPAA.

6.9 Your Choices

Depending on your location and the technologies used, you may have choices regarding cookies and tracking technologies. These choices may include:

  • changing your browser settings to block or delete cookies;
  • using available cookie preference tools, if provided;
  • opting out of certain marketing communications;
  • contacting us to exercise applicable privacy rights.

Some tracking technologies are necessary to operate, secure, or provide the Services and cannot be disabled without affecting functionality.

6.10 Do Not Track and Preference Signals

Some browsers may offer “Do Not Track” or similar signals. Because there is no uniform industry standard for responding to “Do Not Track” signals, our websites and Services may not respond to all such signals.

Where required by applicable law, we will honor legally recognized opt-out preference signals, such as Global Privacy Control, in accordance with applicable requirements.

7. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including PHI where applicable. Our safeguards are designed to help protect information from unauthorized access, use, disclosure, alteration, or destruction.

7.1 Security Safeguards

Depending on the nature of the information and the Services used, our safeguards may include:

  • access controls and role-based permissions;
  • authentication and session-management controls;
  • encryption of information in transit and, where appropriate, at rest;
  • audit logging and activity monitoring;
  • least-privilege access controls;
  • workforce confidentiality obligations and security training;
  • vendor and subprocessor review;
  • secure development and change-management practices;
  • vulnerability management and security monitoring;
  • backup, availability, and recovery measures;
  • incident-response procedures.

7.2 Access Controls

We limit access to personal information and PHI to authorized personnel, service providers, and subprocessors who need access to provide, secure, support, or operate the Services, or as otherwise permitted by applicable law and contract.

Customer administrators may control user access, roles, permissions, integrations, and workflow settings within the Services. Customers are responsible for managing their authorized users and ensuring that access is appropriate for their organization, workforce, and workflows.

7.3 Audit Logs and Monitoring

The Services may maintain audit logs, automation logs, security logs, and diagnostic logs to support security, troubleshooting, compliance, and auditability.

These logs may include information such as:

  • user access events;
  • authentication events;
  • workflow activity;
  • task execution events;
  • system actions;
  • integration activity;
  • timestamps;
  • IP addresses;
  • error messages;
  • security-relevant events.

Where logs contain PHI, we treat them as PHI and process them only as permitted by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

7.4 Browser-Based Agent Workflow Security

Because the Services may include browser-based agents and/or workflow automation tools that interact with webpages, applications, EHRs, payer portals, scheduling systems, billing systems, or other connected systems, we use safeguards designed to limit access and activity to authorized workflows.

These safeguards may include:

  • customer-controlled configuration settings;
  • role-based access permissions;
  • authentication and authorization checks;
  • workflow logging;
  • limits on automated actions;
  • error handling and exception reporting;
  • user review, confirmation, or approval steps where appropriate;
  • controls designed to prevent unauthorized access to connected systems.

Authorized users are responsible for reviewing and confirming automation-generated outputs and automated workflow actions as appropriate before relying on them for clinical, billing, administrative, operational, or other purposes.

7.5 Subprocessor and Vendor Security

We may use service providers and subprocessors to help provide, operate, secure, and support the Services. We evaluate vendors and require appropriate contractual protections based on the nature of the services they provide and the information they process.

Where a service provider or subprocessor creates, receives, maintains, or transmits PHI on our behalf, we require appropriate contractual protections, including a Business Associate Agreement where required by HIPAA.

7.6 Incident Response

We maintain procedures designed to identify, investigate, respond to, and mitigate security incidents. If we determine that a security incident requires notification under HIPAA, applicable state data breach laws, the FTC Health Breach Notification Rule, or other applicable law, we will provide notice as required by law and, where applicable, in accordance with the applicable Business Associate Agreement.

7.7 Customer Responsibilities

Customers and authorized users play an important role in protecting information. Customers are responsible for:

  • managing authorized users and access permissions;
  • maintaining the confidentiality of account credentials;
  • using appropriate device, browser, and network security;
  • configuring integrations and workflows appropriately;
  • reviewing automated workflow actions and task outputs;
  • ensuring that use of the Services complies with their legal, regulatory, contractual, and professional obligations;
  • notifying us promptly of suspected unauthorized access or misuse.

7.8 No Guarantee of Absolute Security

Although we use safeguards designed to protect information, no method of transmission, processing, or storage is completely secure. We cannot guarantee that information will be completely secure from unauthorized access, use, disclosure, alteration, or destruction.

8. Retention and Deletion

We retain information for as long as reasonably necessary to provide, operate, secure, support, and improve the Services; comply with legal, regulatory, contractual, and accounting obligations; resolve disputes; enforce agreements; and maintain appropriate business records.

The length of time we retain information depends on the type of information, the purpose for which it was collected, the nature of our relationship with the customer or user, applicable legal requirements, and our contractual obligations, including any applicable Business Associate Agreement.

8.1 Retention of Business and Account Information

We may retain business contact information, account information, customer organization information, billing information, support communications, and related records for as long as necessary to provide and administer the Services, manage customer accounts and subscriptions, communicate with customers and authorized users, provide support, maintain business and financial records, comply with tax, accounting, legal, and contractual obligations, resolve disputes, and enforce agreements.

8.2 Retention of Product Usage, Audit, and Security Logs

We may retain product usage information, automation logs, audit logs, security logs, diagnostic logs, error reports, and system activity records for as long as reasonably necessary to operate and secure the Services, maintain auditability, troubleshoot issues, investigate errors or misuse, support customer administration and compliance, improve reliability and performance, and comply with legal, contractual, and security obligations.

Where logs contain PHI, we treat them as PHI and retain them in accordance with the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

8.3 Retention of PHI

When we create, receive, maintain, or transmit PHI on behalf of a healthcare provider, medical practice, clinic, health plan, or other covered entity, we retain PHI only as permitted by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

Retention periods for PHI may depend on:

  • the applicable customer agreement;
  • the Business Associate Agreement;
  • the customer’s configuration and instructions;
  • the nature of the workflow or integration;
  • legal, regulatory, or compliance obligations;
  • security, audit, backup, and incident-response needs.

Upon termination or expiration of the applicable customer agreement, we will return or delete PHI as required by the applicable Business Associate Agreement, unless retention is required or permitted by law.

8.4 Retention of Automation-Generated or Workflow-Generated Information

The Services may generate, process, or store automation-generated or workflow-generated information, such as task outputs, workflow steps, user edits, approvals, rejections, confirmations, audit logs, and diagnostic information.

We retain this information for as long as reasonably necessary to:

  • provide the Services;
  • support workflow continuity;
  • maintain auditability;
  • troubleshoot and improve reliability;
  • support customer review and compliance;
  • comply with applicable legal, contractual, and security obligations.

Where automation-generated or workflow-generated information contains PHI, we treat it as PHI and retain it only as permitted by the applicable Business Associate Agreement, customer instructions, HIPAA, and applicable law.

8.5 Backups and Archived Copies

Information may remain in backups, archives, disaster-recovery systems, or system logs for a limited period after deletion from active systems. We maintain backup and archival copies to support business continuity, disaster recovery, security, integrity of the Services, and legal and compliance obligations.

When backup or archived information contains PHI, we protect it in accordance with the applicable Business Associate Agreement, HIPAA, and applicable law. Backup or archived information is generally not accessed except for restoration, security, compliance, or legal purposes.

8.6 Deletion Requests

Customers may request deletion of information in accordance with the applicable customer agreement, Business Associate Agreement, product functionality, and applicable law.

Authorized users may request deletion or correction of certain personal information by contacting us at privacy@useclickless.com. We may need to verify the request and may retain certain information where permitted or required by law, contract, security obligations, audit requirements, dispute resolution, or legitimate business needs.

Requests relating to PHI should generally be directed to the applicable healthcare provider, medical practice, clinic, health plan, or other covered entity. Where required by the applicable Business Associate Agreement, we will assist the covered-entity customer in responding to such requests.

8.7 De-Identified and Aggregated Information

We may retain de-identified, aggregated, or statistical information that does not reasonably identify an individual, patient, customer, or authorized user. Where information is de-identified from PHI, we de-identify it in accordance with applicable legal requirements and contractual obligations.

We may retain and use de-identified or aggregated information for purposes such as service improvement, analytics, security, reliability monitoring, and business reporting, where permitted by applicable law and contract.

8.8 Legal Holds and Required Retention

We may retain information for longer periods where necessary to:

  • comply with legal, regulatory, tax, accounting, or reporting obligations;
  • comply with court orders, subpoenas, or lawful government requests;
  • preserve evidence;
  • resolve disputes;
  • enforce agreements;
  • investigate security incidents, fraud, misuse, or unauthorized activity;
  • protect the rights, safety, or property of our company, customers, users, patients, or others.

Where retained information includes PHI, we will retain and protect it in accordance with the applicable Business Associate Agreement, HIPAA, and applicable law.

8.9 Account Closure and Termination

If a customer closes an account or terminates use of the Services, we may retain certain information for a period of time as necessary to complete account closure, provide transition assistance, comply with contractual obligations, maintain business records, support audit and security requirements, and comply with applicable law.

PHI associated with a terminated customer account will be returned or deleted as required by the applicable Business Associate Agreement, unless retention is required or permitted by law.

9. Breach and Incident Notice

We maintain procedures designed to identify, investigate, assess, respond to, mitigate, and document security incidents involving information processed by the Services, including PHI where applicable.

9.1 Security Incidents

A security incident may include an attempted or actual unauthorized access, use, disclosure, alteration, loss, destruction, or compromise of information or systems.

Not every security incident is a reportable breach. We evaluate incidents based on the nature of the information involved, the circumstances of the incident, applicable law, our contractual obligations, and any applicable Business Associate Agreement.

9.2 Incidents Involving PHI

When we create, receive, maintain, or transmit PHI on behalf of a healthcare provider, medical practice, clinic, health plan, or other covered entity, we act as a Business Associate under HIPAA.

If we discover a breach of unsecured PHI involving PHI that we process on behalf of a covered-entity customer, we will notify the applicable covered entity as required by HIPAA and the applicable Business Associate Agreement. Under HIPAA, business associates must notify covered entities without unreasonable delay and no later than 60 days after discovery of a breach of unsecured PHI.

Where applicable and reasonably available, our notice may include information such as:

  • a description of what happened;
  • the date of the incident and, if known, the date of discovery;
  • the types of PHI involved;
  • the individuals or categories of individuals potentially affected, if known;
  • steps we have taken or are taking to investigate, mitigate, and remediate the incident;
  • steps the customer may need to take, if applicable;
  • contact information for follow-up questions;
  • any other information required by the applicable Business Associate Agreement, HIPAA, or applicable law.

9.3 Notices to Individuals, Regulators, or Other Parties

For PHI processed on behalf of a covered-entity customer, the covered entity is generally responsible for determining and providing any required notices to affected individuals, regulators, the media, or other parties, unless the applicable Business Associate Agreement or law provides otherwise.

We will reasonably cooperate with the covered-entity customer in connection with required breach assessment, investigation, mitigation, documentation, and notification obligations, as required by the applicable Business Associate Agreement and HIPAA.

9.4 Incidents Involving Non-PHI Personal Information

If we determine that a security incident involving non-PHI personal information requires notification under applicable state, federal, or international data breach notification laws, we will provide notice as required by applicable law.

The content, timing, and recipients of any such notice may depend on the type of information involved, the nature of the incident, the risk of harm, applicable law, and our contractual obligations.

9.5 FTC Health Breach Notification Rule

In some circumstances, non-HIPAA health information may be subject to the FTC Health Breach Notification Rule. The FTC finalized changes in 2024 clarifying the rule’s application to health apps and similar technologies.

If we determine that the FTC Health Breach Notification Rule applies to a breach involving unsecured health information, we will provide notices as required by that rule and applicable law.

9.6 Mitigation and Remediation

When we identify a security incident, we may take steps designed to contain, investigate, mitigate, and remediate the incident, which may include:

  • suspending or restricting access;
  • rotating or revoking credentials, tokens, or keys;
  • preserving relevant logs and evidence;
  • investigating affected systems, workflows, integrations, or accounts;
  • notifying affected customers or parties where required;
  • implementing corrective actions;
  • updating security controls, policies, procedures, or training as appropriate.

9.7 Customer Responsibilities

Customers and authorized users are responsible for promptly notifying us if they suspect unauthorized access, misuse, credential compromise, improper disclosure, or any other security issue involving the Services.

Customers are responsible for managing their authorized users, access permissions, devices, integrations, and internal workflows. Customers are also responsible for complying with their own breach-notification, patient-notification, regulatory-reporting, recordkeeping, and professional obligations.

9.8 No Limitation of Contractual Obligations

This Privacy Policy provides a general description of our incident and breach-notification practices. Additional or different obligations may apply under a customer agreement, Business Associate Agreement, data protection addendum, or applicable law.

If there is a conflict between this Privacy Policy and a Business Associate Agreement, the Business Associate Agreement controls with respect to PHI.

10. Privacy Rights

Depending on your location and applicable law, you may have certain rights regarding your personal information. These rights may include the right to access, correct, delete, or receive a copy of certain personal information, and the right to object to or opt out of certain uses of personal information.

These rights may be subject to exceptions under applicable law. They may also apply differently depending on whether we process the information as a business, controller, service provider, processor, or Business Associate.

10.1 Personal Information Covered by This Section

This section generally applies to personal information that we collect and process directly, such as:

  • website visitor information;
  • business contact information;
  • demo-request information;
  • marketing and communication information;
  • account and user information;
  • billing contact information;
  • support communications;
  • non-PHI product usage information.

This section does not generally apply to PHI that we process on behalf of a healthcare provider, medical practice, clinic, health plan, or other covered entity under a Business Associate Agreement.

When we process PHI on behalf of a covered-entity customer, requests relating to that PHI should generally be directed to the applicable covered entity. We will assist the covered entity as required by the applicable Business Associate Agreement, HIPAA, and applicable law.

10.2 Your Rights

Depending on your location and applicable law, you may have the right to request that we:

  • confirm whether we process your personal information;
  • provide access to personal information we maintain about you;
  • provide a copy of certain personal information in a portable format;
  • correct inaccurate personal information;
  • delete certain personal information;
  • restrict or object to certain processing;
  • opt out of certain processing for targeted advertising, sale of personal information, or certain profiling, where applicable;
  • limit certain uses or disclosures of sensitive personal information, where applicable;
  • withdraw consent where processing is based on consent;
  • appeal a decision we make regarding your privacy request, where applicable.

For example, California residents have rights to know, delete, opt out of sale or sharing, and non-discrimination under the CCPA, and Colorado residents have rights to access, correct, delete, portability, and opt out of certain uses such as targeted advertising, sale, or certain profiling.

10.3 California Privacy Rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, may provide you with specific rights regarding your personal information.

Subject to applicable exceptions, California residents may have the right to:

  • know what categories of personal information we collect, use, disclose, sell, or share;
  • know the categories of sources from which personal information is collected;
  • know the business or commercial purposes for collecting, using, disclosing, selling, or sharing personal information;
  • know the categories of third parties to whom personal information is disclosed;
  • access the specific pieces of personal information we have collected about you;
  • request deletion of personal information we collected from you;
  • request correction of inaccurate personal information;
  • opt out of the sale or sharing of personal information, where applicable;
  • limit the use and disclosure of sensitive personal information, where applicable;
  • not be discriminated against for exercising privacy rights.

We do not sell PHI. We do not use PHI for targeted advertising. We do not disclose PHI to advertising networks or data brokers.

If we engage in activities that constitute a “sale” or “sharing” of personal information under California law, we will provide any required notices and opt-out mechanisms. California recognizes opt-out rights for sale and sharing, including via Global Privacy Control where applicable.

10.4 Other State Privacy Rights

Residents of certain U.S. states may have similar rights under applicable state privacy laws. Depending on your state and the law that applies, these rights may include access, correction, deletion, portability, opt out of targeted advertising, opt out of sale of personal information, opt out of certain profiling, and appeal of a denied privacy request.

We will respond to applicable privacy requests as required by the law that applies to your request.

10.5 How to Exercise Your Rights

To exercise privacy rights, please contact us using the information provided in the “Contact Us” section below and include “Privacy Request” in the subject line of your email.

Please include enough information for us to understand your request and verify your identity. For example, we may ask you to provide your name, email address, organization, state of residence, relationship to us, or other information reasonably necessary to verify and process your request.

If your request relates to PHI maintained by a healthcare provider, medical practice, clinic, health plan, or other covered entity, please contact that covered entity directly. If we receive a request relating to PHI that we process as a Business Associate, we may refer the request to the applicable covered entity or assist the covered entity as required by our Business Associate Agreement.

10.6 Verification

Before responding to certain privacy requests, we may verify your identity and authority to make the request. The information we request for verification may depend on the nature of the request, the sensitivity of the information, and applicable law.

We will use information provided for verification only to verify and process the request, except as otherwise permitted by law.

10.7 Authorized Agents

Where permitted by applicable law, you may authorize another person or entity to submit a privacy request on your behalf. We may require proof that the agent has authority to act on your behalf. We may also require you to verify your identity directly with us, unless otherwise prohibited by applicable law.

10.8 Timing of Responses

We will respond to privacy requests within the time period required by applicable law. If we need additional time, we may notify you as permitted by law. If we deny all or part of your request, we will explain the reason where required by applicable law and provide information about any available appeal process where applicable.

10.9 Appeals

If applicable law gives you the right to appeal our decision regarding a privacy request, you may submit an appeal by contacting us at privacy@useclickless.com. Please include “Privacy Request Appeal” in the subject line and describe the request you are appealing.

10.10 Marketing Communications

You may opt out of marketing emails by using the unsubscribe link in the email or by contacting us at privacy@useclickless.com.

Even if you opt out of marketing communications, we may still send you non-marketing communications, such as security notices, administrative messages, account-related notices, service updates, billing notices, or legal notices.

10.11 Customer-Administered Accounts

If your account is provided by your employer, practice, clinic, healthcare organization, or another customer, that customer may control certain account settings, access permissions, data, and user information.

Requests to access, correct, delete, or restrict information associated with a customer-administered account may be subject to the customer’s instructions, the applicable customer agreement, and applicable law.

10.12 Non-Discrimination

We will not discriminate against you for exercising privacy rights under applicable law. For example, we will not deny services, charge a different price, or provide a different level or quality of service solely because you exercised your privacy rights, except as permitted by applicable law.

10.13 Limitations and Exceptions

Privacy rights are not absolute. We may deny or limit a request where permitted or required by law, including where necessary to:

  • comply with legal, regulatory, contractual, accounting, tax, security, or recordkeeping obligations;
  • protect the security, integrity, or functionality of the Services;
  • prevent fraud, misuse, or unlawful activity;
  • complete transactions or provide services requested by you or our customer;
  • maintain audit logs and business records;
  • comply with Business Associate Agreements, HIPAA, or customer instructions;
  • protect the rights, privacy, safety, or property of our company, customers, users, patients, or others;
  • retain information subject to legal holds, disputes, or investigations.

11. Children's Privacy

The Services are intended for use by healthcare providers, medical practices, clinics, health plans, organizations, and their authorized users. The Services are not intended for direct use by children or individuals under the age of 18.

We do not knowingly collect personal information directly from children through our public websites, marketing channels, or general account-registration processes. If we learn that we have collected personal information directly from a child without appropriate authorization, we will take appropriate steps to delete or handle the information as required by applicable law.

The Services may process PHI relating to minors when used by healthcare providers, medical practices, clinics, health plans, or other covered entities in connection with patient care, healthcare operations, billing, scheduling, documentation, or other authorized workflows. In those circumstances, we process such PHI as a Business Associate under the applicable Business Associate Agreement, HIPAA, customer instructions, and applicable law.

Requests relating to PHI of minors should generally be directed to the applicable healthcare provider, medical practice, clinic, health plan, or other covered entity.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, Services, legal requirements, or other operational, business, or regulatory reasons.

When we update this Privacy Policy, we will revise the “Effective Date” at the top of the policy. If we make material changes, we may provide additional notice, such as by posting a notice on our website, notifying customers through the Services, or sending an email or other communication, where appropriate or required by law.

Your continued use of the Services after an updated Privacy Policy becomes effective means that you acknowledge the updated Privacy Policy, to the extent permitted by applicable law.

For PHI processed on behalf of a covered-entity customer, our obligations will continue to be governed by the applicable Business Associate Agreement, HIPAA, customer instructions, and applicable law.

13. Contact Us

If you have questions about this Privacy Policy, our privacy practices, or how we collect, use, disclose, or protect personal information, you may contact us at:

For privacy-rights requests, please include “Privacy Request” in the subject line of your email and provide enough information for us to understand and verify your request.

If your request relates to PHI that we process on behalf of a healthcare provider, medical practice, clinic, health plan, or other covered entity, please contact the applicable covered entity directly. When required by the applicable Business Associate Agreement, HIPAA, customer instructions, or applicable law, we will assist the covered entity in responding to requests involving PHI.

If you are a customer contacting us about your account, organization, users, integrations, billing, or Business Associate Agreement, please include your organization name and the nature of your request so we can route it appropriately.

Privacy

privacy@useclickless.com

Privacy Policy questions & rights requests

Security

security@useclickless.com

Suspected unauthorized access or incidents

Support

support@useclickless.com

Product questions & account support