Privacy Policy

Last Updated: September 12, 2025

Important:

This Privacy Policy explains how Clinxra collects, uses, and protects your information when you use our clinical management platform. We are committed to protecting your privacy and maintaining the confidentiality of healthcare information.

1. Introduction

Clinxra ("we," "us," or "our") operates the clinical management platform available at clinxra.com and through our mobile applications (the "Service"). This Privacy Policy informs you of our policies regarding the collection, use, and disclosure of personal information when you use our Service.

By using our Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Personal Information

We collect several types of information from and about users of our Service:

2.2 Patient Health Information (PHI)

Healthcare Data:

As a healthcare management platform, Clinxra processes Protected Health Information (PHI) and personal health data that you input into our system, including but not limited to:

  • Patient demographics and contact information
  • Medical histories and clinical assessments
  • Treatment plans and progress notes
  • Appointment schedules and medical records
  • Diagnostic information and test results

2.3 Technical Information

3. How We Use Your Information

3.1 Service Provision

3.2 Account Management

3.3 Legal and Compliance

4. Legal Basis for Processing (GDPR Compliance)

When applicable, we process personal data based on the following legal grounds:

5. Information Sharing and Disclosure

5.1 We Do Not Sell Your Data

We do not sell, trade, or otherwise transfer your personal information or patient health information to third parties for commercial purposes.

5.2 Limited Sharing

We may share information only in the following circumstances:

5.3 Healthcare Provider Responsibilities

Healthcare providers using our platform are responsible for:

6. Data Security

6.1 Technical Safeguards

6.2 Administrative Safeguards

6.3 Physical Safeguards

7. Data Retention

Data TypeRetention PeriodPurpose
Account InformationDuration of subscription + 7 yearsLegal compliance and tax records
Patient Health InformationAs directed by healthcare provider*Medical record keeping requirements
Usage Analytics2 yearsService improvement and support
Communication Logs3 yearsCustomer support and dispute resolution
Security Logs1 yearSecurity monitoring and compliance

*Healthcare providers are responsible for determining appropriate retention periods for patient data based on applicable medical record laws and professional requirements.

8. Your Rights and Choices

8.1 Access and Control

8.2 Patient Rights

If you are a patient whose information is processed through our platform, you should contact your healthcare provider directly to exercise your rights regarding your health information.

8.3 Communication Preferences

9. International Data Transfers

Our primary servers are located in Jordan. When we transfer data internationally, we ensure appropriate safeguards are in place:

10. Cookies and Tracking Technologies

10.1 Types of Cookies

10.2 Cookie Management

You can control cookies through your browser settings. However, disabling certain cookies may limit functionality of our Service.

11. Children's Privacy

Our Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us immediately.

12. Healthcare-Specific Compliance

12.1 HIPAA Compliance (US)

For US-based healthcare providers, we serve as a Business Associate and comply with HIPAA requirements through:

12.2 Other Healthcare Regulations

We also comply with other applicable healthcare privacy laws and regulations in jurisdictions where our users operate.

13. Data Breach Notification

In the event of a data breach affecting personal or health information, we will:

14. Third-Party Services

Our Service may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those external services. We encourage you to review the privacy policies of any third-party services you use.

15. Updates to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

Your continued use of the Service after any modifications indicates your acceptance of the updated Privacy Policy.

16. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Clinxra Data Protection Officer

Email: privacy@clinxra.com

Website: clinxra.com

Subject Line: Privacy Policy Inquiry

For Healthcare Providers:

Business Associate Agreement requests: legal@clinxra.com

For Patients:

Please contact your healthcare provider directly for questions about your health information.

EU Representative (if applicable):

[To be appointed if EU users require local representation]

17. Governing Law

This Privacy Policy is governed by the laws of Jordan. For users in other jurisdictions, we also comply with applicable local privacy laws including GDPR, CCPA, and other relevant data protection regulations.