Effective date: 08/18/2026
Last updated: 08/18/2026
This policy explains what The Doc Connect collects, why we hold it, who else sees it, how long we keep it, and what you can ask us to do about it. It covers our website, the platform our clinics sign in to, and the client portals we host on a clinic's behalf.
Two different roles, and why the difference matters
Most of what we hold falls into one of two buckets, and your rights are different in each.
Health information belongs to your clinic, not to us. When a clinic uses this platform to care for you, the clinic is the covered entity under the federal health privacy law known as HIPAA, and we are its business associate. We handle that information only as the clinic instructs and only as our agreement with the clinic permits. Your rights over your medical record are set out in our Notice of Privacy Practices and are exercised through your clinic. Asking us directly will reach the same people.
Everything else is ours to answer for. Visitors to our website, people who send us an enquiry, clinics that apply to join, physicians who apply to review, and the staff who sign in to run a practice. For that information we decide what is collected and why, and this policy is the whole of the answer.
What we collect
From a clinic and its staff. Names and work contact details, the business details required to verify a practice and the people in it, including professional licence and liability insurance documents, and a record of what each person did on the platform.
From a client of a clinic. Name, contact details, and the clinical information the clinic records about your care. We do not ask you for health information directly. It reaches us because your clinic put it there.
From a visitor to our website. The content of an enquiry or a live chat message you send us, any file you attach to one, and ordinary server records such as the pages requested and the time they were requested.
From an applicant. What you put in the application form, including the documents you attach.
We do not buy personal information from data brokers, and we do not enrich what you give us from outside sources.
Why we hold it
- To operate the platform your clinic uses, and to let a licensed physician review a prescription request.
- To verify that a clinic and the people in it are who they say they are, and are licensed to do what they are asking to do.
- To answer an enquiry or a support request, and to reach you about your account.
- To keep the records health privacy law requires us to keep, and to be able to show who did what.
- To keep the platform secure, and to investigate misuse.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to advertise to you.
Trackers and analytics
The platform runs no third-party advertising or analytics trackers. There is no advertising pixel and no third-party analytics script on any page, including the pages that show health information. Site statistics are collected first-party and are not shared.
We set cookies only where the site cannot work without them: keeping you signed in, keeping a session safe from cross-site request forgery, and remembering a preference you have set. None of them follow you to another website.
Who else holds this information
We use a small number of service providers, each under contract, and each one is only given what it needs to do its part:
- Healthie holds the clinical record itself: charts, documents, messages, appointments and invoices.
- Neon hosts the application database: accounts, practices, client records, prescriptions and the activity log.
- Vercel hosts and serves the application, and stores uploaded files. Verification documents, signed consent forms and contact-form attachments are held in a private store that is reached only through a route which has already checked who is asking.
- Google Cloud reads a clinic's public website copy before it is published, to check that it does not identify a patient. Requests are pinned to a single United States region.
- Mailgun delivers email.
- Stripe, reached through Healthie, processes card payments. Card numbers never reach our servers.
Each provider that handles health information does so under a business associate agreement. We publish this list because a change to it is a change to who holds your information, and you should be able to see it.
We also disclose information where the law requires it, to respond to a valid legal process, or to protect someone from harm. If our business is sold or merged, information transfers with it, and the successor is bound by this policy until it tells you otherwise.
Where it is held
Information is stored and processed in the United States. If you are reaching us from outside the United States, you are sending it to a country whose privacy laws may differ from your own.
How we protect it
Information is encrypted in transit and at rest. Access is limited to the people whose work requires it, granted by role rather than by person, and every sign-in and every action that touches a person's record is recorded. Sensitive pages are never cached. No system is perfectly secure, and we do not claim otherwise, but we will tell you and the appropriate authorities if a breach requires it.
How long we keep it
- Enquiries and live chat conversations: destroyed after ninety days.
- Applications from clinics and physicians: kept for one year after they are decided, then destroyed.
- Records of activity on the platform: kept and not pruned. Health privacy law lets a person ask for an accounting of disclosures going back six years, and these records carry identifiers and counts rather than anything a person typed, so they can outlive the information they describe.
- Signed consent forms: destroyed six years after they are uploaded.
- Clinical records: kept for as long as the law governing medical records requires, which is set by state law and by federal healthcare program rules rather than by HIPAA, and destroyed on a schedule after that.
- What we hold about a clinic that leaves: destroyed one year after the clinic closes its account.
A deletion request starts a short recovery window before the information is destroyed for good, so that a mistake can be undone. After that window it is gone and cannot be recovered.
Your choices
You can ask us to:
- tell you what information we hold about you,
- give you a copy of it,
- correct it if it is wrong,
- delete it, and
- stop sending you email that is not about your account.
California residents have specific rights, including the right not to be treated differently for exercising them. Those are set out on our California privacy rights page, which carries the request form. Residents of other states with comparable privacy laws may use the same form.
We will confirm we have your request, verify who you are before we act on it, and answer within the time the applicable law allows. We may need to keep some information even after a deletion request, where the law requires us to hold it or where it is part of a medical record.
Information held as part of your medical record is governed by health privacy law rather than by state consumer privacy law. Your rights over it are in our Notice of Privacy Practices.
Children
The platform is not directed to children under [AGE], and we do not knowingly collect information from them outside of care a clinic is providing with the consent of a parent or guardian. If you believe a child has given us information another way, contact us and we will remove it.
Changes to this policy
We will post any change here and update the date at the top. If a change materially affects what we do with information we already hold, we will tell you before it takes effect.
Who to contact
Emily McCarthy, Data Protection Officer
emily@thedocconnect.com
714-225-6933
The Doc Connect, Inc.
11612 Knott St,
Garden Grove, CA 92841