GitoCare ← Back to site

Privacy Policy

Effective 22 July 2026 · GitoCare Inc. (Delaware, USA)

This policy explains how GitoCare Inc. (“GitoCare,” “we”) handles information on our website and in our platform. We wrote it to be read, not to hide behind. If anything here is unclear, email privacy@gitocare.com.

Two different roles, two different rule sets.

1. Our website & sales. When you visit gitocare.com or contact us, this Privacy Policy governs the limited information we collect from you directly.

2. Protected health information (PHI) in the platform. When a clinic uses GitoCare, we act as a HIPAA Business Associate to that clinic. We process patient information on the clinic’s behalf and under a Business Associate Agreement (BAA) and the clinic’s own privacy notice — not under this policy. We do not use PHI for our own purposes and never sell it.

1. Information we collect

On our website

In the platform (on behalf of clinics)

2. How we use information

We do not sell your personal information, and we do not sell or share PHI or financial data for advertising.

3. How we share information

We share information only with:

We never sell your data.

4. How we protect information

We maintain administrative, physical, and technical safeguards: encryption in transit (TLS 1.2+) and at rest, role-based access with multi-factor authentication, immutable audit logging, and automated backups with a tested recovery process. Full detail is on our Security page. GitoCare operates as a HIPAA Business Associate; we do not claim “HIPAA certification” (no such certification exists).

5. Data retention and deletion

Website inquiry data is kept only as long as needed for the purpose collected. Clinic data is retained per the clinic’s BAA and applicable law and is returned or destroyed on the clinic’s offboarding. If a clinic disconnects a connected bank account, the access token and associated transaction data for that connection are deleted.

6. Your choices and rights

You can ask us to access, correct, or delete the personal information you provided to us directly by emailing privacy@gitocare.com. If you are a patient, requests about your health record are handled by your clinic (the Covered Entity); we support the clinic in fulfilling them.

7. Text messages (SMS)

Clinics using GitoCare can send appointment reminders, confirmations, and scheduling updates by text message. We only text a patient who has opted in — consent is recorded against the patient’s record and enforced in software, not left to a setting. Consent is never a condition of receiving care.

How consent is given. A patient opts in either by ticking the optional text-message box when completing digital intake or online booking, or by asking the clinic’s front desk, who records it on the patient’s chart with the date. The wording shown at opt-in reads: “You may text me appointment reminders, confirmations, and scheduling updates at the mobile number I provided. Message and data rates may apply, message frequency varies, and I can reply STOP to opt out at any time. This is optional and not required to receive care.”

What we send. Appointment reminders, confirmations, and scheduling updates only. We do not send clinical details by text, and we do not send marketing messages without a separate marketing opt-in.

Message frequency. Varies by appointment activity — typically a small number of messages around each scheduled visit.

Cost. Message and data rates may apply. GitoCare and your clinic do not charge you for these messages; your mobile carrier’s standard rates apply.

How to stop. Reply STOP to any message to opt out immediately — UNSUBSCRIBE, QUIT, END and OPTOUT also work. You will receive one confirmation that no further messages will be sent. You can also ask your clinic to switch reminders off, or reply HELP for assistance.

Who sees the number. Mobile numbers are used to deliver these messages and are not sold, rented, or shared with third parties for their own marketing. Message content and phone numbers are not shared with third parties or affiliates for marketing purposes.

Carrier note. Wireless carriers are not liable for delayed or undelivered messages.

Questions about text messages: support@gitocare.com.

8. Cookies

We use only the cookies needed to run the site and understand aggregate interest. We do not use cookies for third-party advertising.

9. Children

Our website is not directed to children. Patient records processed for a clinic may include minors; those are handled under the clinic’s authority and the BAA.

10. Changes

We may update this policy; we’ll change the effective date above and, for material changes, take reasonable steps to notify affected customers.

11. Contact

GitoCare Inc. · privacy@gitocare.com · Security matters: security@gitocare.com