Privacy Policy
This policy explains how GitoCare Inc. (“GitoCare,” “we”) handles information on our website and in our platform. We wrote it to be read, not to hide behind. If anything here is unclear, email privacy@gitocare.com.
Two different roles, two different rule sets.
1. Our website & sales. When you visit gitocare.com or contact us, this Privacy Policy governs the limited information we collect from you directly.
2. Protected health information (PHI) in the platform. When a clinic uses GitoCare, we act as a HIPAA Business Associate to that clinic. We process patient information on the clinic’s behalf and under a Business Associate Agreement (BAA) and the clinic’s own privacy notice — not under this policy. We do not use PHI for our own purposes and never sell it.
1. Information we collect
On our website
- Information you give us — your name, email, phone, practice name, and message when you request a demo, contact us, or subscribe.
- Basic usage data — standard server logs and privacy-respecting analytics (pages viewed, approximate region, device type) to keep the site working and understand interest. We keep this minimal.
In the platform (on behalf of clinics)
- Patient and clinical data (PHI) the clinic enters or imports — handled under the BAA, encrypted, access-controlled, and audit-logged. See our Security page.
- Account and staff data for the clinic’s authorized users (name, work email, role) to provide access and log activity.
- Financial account information. If a clinic connects its bank account to reconcile payments, we use read-only access to that clinic’s own business-bank transaction data through our banking provider (Plaid). We request the Transactions product only; we do not access balances and cannot move money. This data is used solely to match deposits to posted payments for that clinic. It is not sold and not used for advertising.
2. How we use information
- To respond to your inquiries and provide, secure, and improve the platform.
- To reconcile a clinic’s payments against its bank deposits, when the clinic connects its bank.
- To meet legal, security, and contractual obligations.
We do not sell your personal information, and we do not sell or share PHI or financial data for advertising.
3. How we share information
We share information only with:
- Service providers (subprocessors) that help us run the platform — for example our cloud infrastructure, clearinghouse, payment processor, and banking provider. Each is bound by contract; those that handle PHI sign a BAA before any PHI flows. Our current subprocessors are disclosed to clinic customers on request.
- The clinic (Covered Entity) whose data we process, as the platform is provided to them.
- Legal and safety — when required by law or to protect rights and safety.
We never sell your data.
4. How we protect information
We maintain administrative, physical, and technical safeguards: encryption in transit (TLS 1.2+) and at rest, role-based access with multi-factor authentication, immutable audit logging, and automated backups with a tested recovery process. Full detail is on our Security page. GitoCare operates as a HIPAA Business Associate; we do not claim “HIPAA certification” (no such certification exists).
5. Data retention and deletion
Website inquiry data is kept only as long as needed for the purpose collected. Clinic data is retained per the clinic’s BAA and applicable law and is returned or destroyed on the clinic’s offboarding. If a clinic disconnects a connected bank account, the access token and associated transaction data for that connection are deleted.
6. Your choices and rights
You can ask us to access, correct, or delete the personal information you provided to us directly by emailing privacy@gitocare.com. If you are a patient, requests about your health record are handled by your clinic (the Covered Entity); we support the clinic in fulfilling them.
7. Cookies
We use only the cookies needed to run the site and understand aggregate interest. We do not use cookies for third-party advertising.
8. Children
Our website is not directed to children. Patient records processed for a clinic may include minors; those are handled under the clinic’s authority and the BAA.
9. Changes
We may update this policy; we’ll change the effective date above and, for material changes, take reasonable steps to notify affected customers.
10. Contact
GitoCare Inc. · privacy@gitocare.com · Security matters: security@gitocare.com