Privacy policy
This policy explains what SHMEL collects, why, and what we do with it. It covers two very different kinds of data: information about the clinics and staff who use our product, and patient information that belongs to our customers and which we handle strictly on their instructions.
1. Who we are
SHMEL provides marketing software to healthcare practices. Where we handle protected health information on behalf of a covered entity, we act as a business associate under HIPAA and only under a signed Business Associate Agreement. In that role your practice is the controller of the patient data and we are the processor. We do not sell data, and we do not use patient data to market our own product.
2. Information about your practice and staff
- Account details: name, work email, role, practice name, locations and billing contact.
- Product usage: which agents you run, what you approve or reject, timestamps and audit events.
- Billing: handled by our payment processor. We store the last four digits and expiry of a card, never the full number.
- Support correspondence, including anything you send us in email or chat.
We use this to run the service, bill you, support you, prevent abuse, and improve the product. Our legal basis is performance of our contract with you and our legitimate interest in operating a secure service.
3. Patient information
To do its job, SHMEL reads limited patient information from the practice management or EMR system you connect. The scope is deliberately narrow.
| What we read | Why |
|---|---|
| Name and contact details | To send recall and reactivation messages you approve |
| Appointment history and last visit date | To identify lapsed patients and time recall to the treatment |
| Treatment or service type | To pick the right recall interval and offer |
| Communication consent and do-not-contact flags | To exclude patients we are not permitted to contact |
| Appointment and revenue outcomes | To attribute results honestly against real bookings |
We do not read clinical notes, diagnoses, images, lab results or payment card data from your system, and we do not need them.
What never leaves
- Patient information is never uploaded to advertising platforms, never used to build custom or lookalike audiences, and never placed in ad creative.
- Patient information is never used to train general-purpose models, and is not shared with model providers for training.
- Patient information from one practice is never exposed to another. Aggregate benchmarks are computed only from de-identified, aggregated figures across many practices.
4. Sub-processors
We use a small number of vendors to run the service. Each is bound by contract, and any vendor that could touch PHI is covered by a BAA. Current categories are cloud hosting, model inference, transactional email and SMS delivery, error monitoring, and payment processing. We maintain a current list of named sub-processors and will provide it on request, and we give notice before adding one that handles PHI.
5. Retention
- Patient information: retained only while your account is active and for 30 days after termination, then deleted. Earlier deletion on request.
- Compliance records: retained for six years, matching HIPAA documentation requirements, because their value is that they can be produced later. You can export them at any time.
- Account and billing records: retained as long as required for tax and accounting purposes.
6. Security
Data is encrypted in transit with TLS and at rest. Access is role-based and least-privilege, with staff access to customer data logged. Connections to your systems use OAuth or scoped API keys, and we request read-only scopes wherever the job allows. We are pursuing SOC 2 Type II; until that report is issued we do not claim to hold it.
7. Your rights
Where a patient asks your practice to access, correct, restrict or delete their information, tell us and we will act on your instruction promptly, because that data is yours and not ours. Practice staff can access, correct or delete their own account information by writing to us. Depending on where you live you may have additional rights under GDPR, UK GDPR, CCPA or CPRA, including the right to complain to a supervisory authority.
8. Cookies
This marketing site uses only what is needed to serve the page. We do not run advertising or cross-site tracking cookies on it. If that changes we will publish a cookie notice and ask for consent before setting anything non-essential.
9. International transfers
We process data in the United States. If you are outside the US, your information will be transferred there under appropriate safeguards.
10. Changes and contact
If we make a material change we will email account administrators before it takes effect. Questions, requests or complaints go to privacy@shmel.ai. Security reports go to security@shmel.ai.