Privacy Policy
Last updated: January 15, 2026
Hymoglobin (“we”, “us”) provides software for clinics and healthcare professionals. This policy explains what personal data we process, why, on what legal basis, how long we keep it, and the rights you can exercise.
1. Who we are
Hymoglobin is the data controller for information collected via hymoglobin.com and our web application at web.hymoglobin.com. For any privacy request, contact hello@hymoglobin.com.
2. Data we collect
- Account data — name, email, phone, clinic name, role, password hash, billing address.
- Clinical data (as a processor) — patient records, prescriptions, appointments, uploaded files. We process this data on behalf of the clinic under a Data Processing Agreement; the clinic is the controller.
- Voice-receptionist data (Pro) — call audio, transcripts, and metadata generated by the AI receptionist, stored against the patient chart.
- Technical data — IP address, approximate country (from
cf-ipcountry/Accept-Language), browser, device, timestamps, error logs. - Payment data — billing details processed by Stripe, PayPal, or Algerian bank/postal partners. We never store full card numbers.
3. Why we process it
- Deliver, secure, and support the service (contract, Art. 6(1)(b) GDPR).
- Bill customers and prevent fraud (legal obligation & legitimate interest).
- Improve product quality via aggregated, non-identifiable metrics.
- Send transactional messages (essential to the service).
- Send occasional product updates — you can unsubscribe at any time.
4. GDPR / RGPD — your rights
If you are in the EEA, UK, or Algeria, you have the right to access, rectify, erase, restrict, and port your personal data, as well as to object to processing and to lodge a complaint with your local supervisory authority (e.g., CNIL in France, ARPCE in Algeria). Contact hello@hymoglobin.com to exercise a right — we respond within 30 days.
5. Data retention
Account data is kept for the life of the subscription and up to 90 days after cancellation. Clinical data is retained per the clinic's own retention policy and applicable medical-record law; on written request we permanently delete or export it within 30 days.
6. Sub-processors
We rely on a small set of sub-processors, each bound by GDPR-compliant contracts: hosting (EU regions), transactional email, SMS delivery, telephony for the AI receptionist, error monitoring, and payment providers (Stripe, PayPal, Algerian banking partners). An up-to-date list is available on request.
7. Security
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is least-privilege, audited, and requires multi-factor authentication for our staff. Backups run daily to an isolated region.
9. Terms of Service (summary)
By using Hymoglobin you agree to acceptable use, respect intellectual property, maintain the confidentiality of your credentials, and comply with local law regarding patient data. The full Terms are available on request while we complete their publication.
10. Changes
We'll post material changes here and, where required, notify users by email at least 30 days before they take effect.
© 2026 Hymoglobin. Questions? Email hello@hymoglobin.com.