Last updated 21 August 2026

Privacy policy

This policy explains what SHMEL collects, why, and what we do with it. It covers two very different kinds of data: information about the clinics and staff who use our product, and patient information that belongs to our customers and which we handle strictly on their instructions.

Draft pending counsel review. This policy was prepared to describe SHMEL's intended data practices accurately. It has not yet been reviewed by healthcare privacy counsel and must be before SHMEL processes production patient data. Do not treat it as a final legal instrument.

1. Who we are

SHMEL provides marketing software to healthcare practices. Where we handle protected health information on behalf of a covered entity, we act as a business associate under HIPAA and only under a signed Business Associate Agreement. In that role your practice is the controller of the patient data and we are the processor. We do not sell data, and we do not use patient data to market our own product.

2. Information about your practice and staff

We use this to run the service, bill you, support you, prevent abuse, and improve the product. Our legal basis is performance of our contract with you and our legitimate interest in operating a secure service.

3. Patient information

To do its job, SHMEL reads limited patient information from the practice management or EMR system you connect. The scope is deliberately narrow.

What we readWhy
Name and contact detailsTo send recall and reactivation messages you approve
Appointment history and last visit dateTo identify lapsed patients and time recall to the treatment
Treatment or service typeTo pick the right recall interval and offer
Communication consent and do-not-contact flagsTo exclude patients we are not permitted to contact
Appointment and revenue outcomesTo attribute results honestly against real bookings

We do not read clinical notes, diagnoses, images, lab results or payment card data from your system, and we do not need them.

What never leaves

4. Sub-processors

We use a small number of vendors to run the service. Each is bound by contract, and any vendor that could touch PHI is covered by a BAA. Current categories are cloud hosting, model inference, transactional email and SMS delivery, error monitoring, and payment processing. We maintain a current list of named sub-processors and will provide it on request, and we give notice before adding one that handles PHI.

5. Retention

6. Security

Data is encrypted in transit with TLS and at rest. Access is role-based and least-privilege, with staff access to customer data logged. Connections to your systems use OAuth or scoped API keys, and we request read-only scopes wherever the job allows. We are pursuing SOC 2 Type II; until that report is issued we do not claim to hold it.

7. Your rights

Where a patient asks your practice to access, correct, restrict or delete their information, tell us and we will act on your instruction promptly, because that data is yours and not ours. Practice staff can access, correct or delete their own account information by writing to us. Depending on where you live you may have additional rights under GDPR, UK GDPR, CCPA or CPRA, including the right to complain to a supervisory authority.

8. Cookies

This marketing site uses only what is needed to serve the page. We do not run advertising or cross-site tracking cookies on it. If that changes we will publish a cookie notice and ask for consent before setting anything non-essential.

9. International transfers

We process data in the United States. If you are outside the US, your information will be transferred there under appropriate safeguards.

10. Changes and contact

If we make a material change we will email account administrators before it takes effect. Questions, requests or complaints go to privacy@shmel.ai. Security reports go to security@shmel.ai.