Privacy Policy
Last Updated: September 18, 2026
This Privacy Policy describes how ClinikEHR ("ClinikEHR" or "we" or "us" or "our") uses and discloses the Personal Information our customers ("Customers" or "you") provide to us or that we collect when you use our websites, mobile applications, software, platforms and services that we operate and that link to this Privacy Policy ("Services"). Before using the Services or otherwise providing Personal Information to us, please review this Privacy Policy carefully.
Note: This Privacy Policy is not a contract and does not create any legal rights or obligations.
Who We Are
ClinikEHR is a product of Bettar Platforms, Inc., a company incorporated in Delaware, United States, with its registered office at 8 The Green, Suite B, Dover, DE 19901, United States. Where this policy says "we", "us" or "ClinikEHR", it means Bettar Platforms, Inc.
For the information we hold about you as a user of our platform, Bettar Platforms, Inc. is the data controller. For information your clinic records about its own patients, your clinic is the controller and we act on its instructions - Section 1 explains that split, and Section 9 covers what it means under European and United Kingdom law.
You can reach us about anything in this policy at [email protected], or by post at the address above.
1. Note to ClinikEHR Customers and their Clients
This Privacy Policy does not apply to the Personal Information we may collect about our customer's patients and clients ("Clients") in the context of providing the Services. Our treatment of Client Personal Information is governed by our agreements with our customers, including our Terms of Service and HIPAA Business Associate Agreement.
We have a limited relationship with the Clients of our Customers. If we receive inquiries or requests from Clients about their Personal Information, we will honor those requests as required by applicable data privacy laws and direct Clients to our Customers, the controller of their personal information.
2. Personal Information We Collect
"Personal Information" is information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your household. Personal information does not include aggregated or de-identified information.
We may collect Personal Information directly from you, automatically through cookies and data collection technologies, and from third-party sources. The categories of Personal Information we collect include:
- Identifiers and contact information - name, email address, mailing address, phone numbers, government-issued IDs, IP addresses, usernames and passwords.
- Professional and employment-related information - business name, license information, calendar and scheduling information.
- Billing information - credit or debit card numbers, tax IDs, insurance information.
- Audio, electronic and visual information - photographs, voice recordings, and similar information.
- Internet and device activity information - browsing history, search history, interactions with our Services, and the device, browser and network signals we collect on our sign-up and sign-in screens to prevent fraud (see Section 7).
- Commercial information - products and services purchased from us.
- Profile information and inferences - preferences and characteristics derived from collected information.
- Sensitive personal information - account login information, payment card numbers, social security number (optional), race or ethnic origin (optional), sexual orientation (optional), religious beliefs (optional).
3. How We Use Personal Information
We collect and use your Personal Information for the following purposes:
- To maintain and service your Account and send you product and service information and updates
- To respond to your customer service requests and address your questions and concerns
- To send you newsletters and marketing communications (you may opt-out)
- To administer and improve services and marketing efforts
- To understand and respond to your needs and preferences
- To develop, enhance, market, sell or provide products and services
- To detect security incidents and protect against malicious or illegal activity
- To comply with legal, regulatory and risk management obligations
Referral Program: ClinikEHR has a referral program that allows existing customers to refer our Services to others. If you receive a referral, we may collect your contact information to send you the referral content.
4. How We Share and Disclose Personal Information
We may share your Personal Information in the following circumstances:
- Publicly, with your permission - We may share your information publicly only with your explicit permission.
- To Service Providers - We share information with companies that provide services to us, such as hosting, marketing, and payment processing.
- To parties outside of ClinikEHR - Including referral program participants, parent and affiliate companies, insurance payers, and as required by law.
- In a corporate transaction - If ClinikEHR is involved in a merger, acquisition, or sale of assets.
Who else processes information for us. We use a small number of service providers - for hosting, email delivery, payments and error monitoring - who process information on our instructions and are bound by contract to protect it. We keep a current list naming each one, what it does and where it does it, and we will send it to you on request at [email protected]. If you are a customer clinic, we give you at least thirty days' notice by email before adding or replacing one, so you have time to object - see the Data Processing Agreement.
5. Access and Choice
Account Settings: You may modify or remove your Personal Information by logging into your Account and making changes in your Account settings.
Marketing Opt-out: You can opt out of receiving marketing emails by using the unsubscribe link in the email. We may still send you transactional emails about your Account.
Account Deletion: You may cancel and delete your Account at any time. Before deleting, please export your data using a secure connection. After deletion, there may be no way to retrieve the data. ClinikEHR is not responsible for lost or stolen data resulting from failure to follow security protocols.
6. Data Collection Technologies and Cookies
We and our third-party partners may automatically collect information from your device when visiting our Services, including:
- Log Data - IP address, operating system, device type, browser type, URLs visited
- Analytics Data - Electronic path through our Services, usage and activity information
- Location Data - General geographic location inferred from IP address
We use cookies and related technologies to automatically collect this information. Most browsers allow you to control cookies through settings. Disabling cookies may negatively affect functionality of our Services.
Do Not Track: Our Services are not configured to respond to "Do Not Track" signals from browsers. However, we recognize and respond to Global Privacy Control (GPC) browser signals.
7. Device and Network Signals for Fraud Prevention
When you use our authentication screens - creating an account, signing in, requesting a password reset, or registering as staff on an existing clinic - we collect a set of signals about the device, browser and network you are using. We collect these signals for one purpose only: to prevent fraud and protect accounts. They help us detect sign-ups made with stolen payment cards, automated credential-stuffing attacks, and attempts to take over an existing account.
The signals we collect are:
- Browser and environment - your time zone and UTC offset, the languages your browser is set to prefer, and the operating-system platform it reports.
- Hardware characteristics - your screen dimensions, pixel ratio and color depth, the number of CPU cores and the amount of device memory your browser reports, and the number of simultaneous touch points your device supports.
- Graphics characteristics - the vendor and renderer names your browser reports for its graphics hardware, and a short hash of a small test image your browser draws.
- Automation markers - the standard browser flag indicating that the page is being driven by automation software rather than by a person.
- Form timing and interaction - how long you took to complete the form, and whether the email and name fields were pasted into rather than typed.
- Network information - your IP address, recorded by our server from the request itself, the User-Agent string your browser sends, and the network operator and autonomous system number (ASN) that your IP address belongs to.
- Bot-check result - whether the Cloudflare Turnstile challenge on the form was passed.
- Device hash - a one-way hash we derive from the stable signals listed above. It cannot be reversed back into those values, and we use it only to group related sign-ups and sign-ins together.
- A one-way hash of your email address - where you have entered one on the form, we store a hash of it rather than the address itself. It lets us see that several sign-in attempts concerned the same account without keeping the address in our fraud records. As with the device hash, this is not anonymous data and we treat it as your Personal Information.
This is first-party only. We do not use a third-party fingerprinting service or SDK to collect these signals, and we do not use them to track you across other websites. They are not shared with advertisers and are not used for advertising, marketing, personalization, or any form of profiling.
These signals contain no patient information. They are collected on our platform account screens, before any clinical context exists. They include no patient data, no clinical records, and nothing about the people your clinic treats.
Why we read information from your device. Some of these signals are read from the browser and device you are using. We read them because they are necessary to secure the sign-in, sign-up or password reset you have asked us to carry out - an account on our platform controls access to clinical records, so protecting the door to it is part of providing the service safely. We do not read them for advertising, analytics or audience measurement, and we do not ask for or rely on your consent for this, because it is a security measure rather than an optional extra.
Collection fails open. If your browser, an extension, or a privacy setting blocks any of these signals, we simply record fewer of them. Signing up, signing in, resetting your password, and registering as staff all continue to work normally. We will not ask you to disable a privacy protection in order to use your account.
Our lawful basis is our legitimate interests. For people protected by European or United Kingdom data protection law, the basis we rely on for this processing is our legitimate interests. Those interests are specific: stopping fraudulent account creation, stopping payment fraud committed against us and against our customers, and stopping unauthorized access to systems that hold clinical records. We weighed these against your privacy, and we have limited what we collect to signals that actually serve those purposes and nothing more.
No automated decisions are made about you. These signals never automatically block, suspend, refuse or close an account. At most they raise a flag for review, and a person on our team decides what happens next. There is no automatic scoring that shuts you out of your account without a human looking at it.
You can object to this processing. Because we rely on legitimate interests, you have the right to object to it. Email [email protected] and we will consider your objection properly. We want to be straight with you that we cannot always agree to stop: where we can show compelling grounds for keeping a security control in place - an open fraud investigation, or an active threat to accounts - we may continue, and if that is our reason we will tell you so.
Hashing is not anonymization. Neither the device hash nor the email hash can be turned back into the values they were built from, but that does not make them anonymous. They still point to a particular device or account and can still be connected to you, so we continue to treat them as your Personal Information and your rights over them still apply. We will not describe them to you as anonymous data.
How long we keep them. The authentication event records that hold these signals are deleted after 180 days. If an event leads us to record a fraud or security assessment, we keep that assessment for seven years, because a payment chargeback or a disputed account takeover can surface long after the event itself and we may need the record to establish or defend a legal claim.
Deleting your account does not erase these records. You can ask us to delete your Personal Information, and we will - but security and fraud records are an exception we want you to know about in advance. Where we have recorded a fraud or security assessment, we keep it for the period described above even after the account it relates to has been closed, because we may need it to establish or defend a legal claim. We keep only what that purpose requires, and we do not reuse retained security records for marketing, analytics or any other purpose.
8. Retention and Security
We retain your Personal Information for as long as your Account is active, as needed to provide Services, and as necessary to comply with legal obligations, resolve disputes, and enforce agreements.
We follow generally accepted standards to protect Personal Information during transmission and storage, including encryption in transit. Our security controls are independently audited under SOC 2 Type II. Personal Information is stored in the United States and the European Union; where it leaves the EEA or the United Kingdom we rely on the safeguards described in Section 9. However, no method of transmission over the Internet is 100% secure.
9. Lawful Bases, and Your Rights in the EU and UK
This section applies if you are in the European Economic Area or the United Kingdom. It sits alongside the rest of this policy rather than replacing it.
The bases we rely on. We must have a lawful basis for every use of your Personal Information. Ours are:
- To perform our contract with you - creating and running your account, providing the platform, taking your subscription payments, and supporting you. Without this information we cannot provide the service you asked for.
- Our legitimate interests - keeping the platform secure, preventing fraud, and improving how the product works. Where we rely on this we have weighed our interest against your privacy, and we say so at the point it applies - see Section 7.
- Legal obligation - keeping records we are required to keep, including audit records relating to clinical systems, and responding to lawful requests.
- Your consent - where we ask for it specifically, such as optional marketing email. You can withdraw it at any time, and withdrawing it does not affect anything we did beforehand.
Health information. Where our Customers use the platform to record information about their patients, that information is theirs and they decide how it is used - the clinic is the controller and we act on their instructions, as set out in Section 1. This policy covers the information we hold about you as a user of our platform.
Your rights. You can ask us for a copy of your Personal Information; to correct it if it is wrong; to delete it; to restrict how we use it; to receive it in a portable form; and to object to processing we base on our legitimate interests. You can also complain to your national data protection authority, and you do not have to come to us first - though we would rather you did, so we can put it right.
Where we cannot simply delete. Two things survive a deletion request, and we would rather say so than surprise you: records we are legally required to keep, and fraud or security assessments we may need in order to establish or defend a legal claim. Section 7 explains the second in detail.
Where your information goes. Our systems and service providers are primarily in the United States and the European Union. When we move your information out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK is involved. Ask us and we will send you a copy of the safeguards we use.
To exercise any of this, email [email protected]. We answer within one month, and we will tell you if we need longer and why.
10. Your Rights in Africa
This section applies if you are in Africa. Our customers include clinics in Nigeria, Ghana, Sierra Leone, Uganda, Egypt and Namibia.
Nigeria. If you are in Nigeria, the Nigeria Data Protection Act 2023 applies, and Bettar Platforms, Inc. is registered with the Nigeria Data Protection Commission.
Your rights. You have the right to be told how your Personal Information is used; to access it; to have it corrected or deleted; to restrict or object to how we use it; to receive it in a portable form; and not to be subject to a decision based solely on automated processing that significantly affects you. Section 7 explains that our fraud checks never make such a decision on their own - a person always reviews them.
Elsewhere in Africa. Data protection law differs from one country to the next, and in some it is still taking shape. Rather than give you less where the law happens to ask for less, we extend the rights set out just above to everyone in the region as a matter of our own policy. Any stronger right your national law gives you is yours as well, and nothing here limits it.
Our bases. The same as those in Section 9: performing our contract with you, our legitimate interests in security and fraud prevention, our legal obligations, and your consent where we ask for it.
If something goes wrong. Where a breach of your Personal Information is likely to result in a risk to your rights and freedoms, and you are in Nigeria, we will report it to the Nigeria Data Protection Commission within 72 hours of becoming aware of it. Elsewhere in the region we will report it to your national data protection authority where the law requires it, within the time that law allows. In every case we will tell you directly where the risk to you is high.
Complaints. Email [email protected] and we will look into it. You can also complain to your national data protection authority directly. In Nigeria that is the Nigeria Data Protection Commission, at ndpc.gov.ng.
11. Your Rights in Canada
This section applies if you are in Canada, under the Personal Information Protection and Electronic Documents Act (PIPEDA) and the provincial laws that stand in for it.
Your rights. You can ask us what Personal Information we hold about you and how we have used and disclosed it; ask us to correct it if it is inaccurate or incomplete; withdraw consent where our use of your information rests on consent, subject to legal and contractual limits we will explain at the time; and challenge how we have handled your information.
Consent. We ask for your consent where the law requires it, and we treat health-related information as sensitive - which means we look for clear, express consent rather than assuming it. Where we rely on a basis other than consent, Section 9 sets out what it is.
If something goes wrong. Where a breach of your Personal Information creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and tell you directly. We keep a record of every breach, whether or not it meets that threshold.
Information held outside Canada. Our systems and service providers are primarily in the United States and the European Union, so your information is processed outside Canada and is subject to the laws of those countries, including lawful access by their authorities. We remain accountable for it and require comparable protection by contract from the providers we use.
Complaints. Email [email protected]. If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
12. Your Rights in the United States
Residents of certain states (California, Colorado, Connecticut, Nevada, Utah, and Virginia) have specific rights under their state's privacy laws. If you are in the EU, the UK, Nigeria or Canada, see Sections 9 to 11 instead - those rights are broader. If you are in Puerto Rico or another United States territory, federal law applies to you, including HIPAA where your information is health information, though the state laws listed here do not:
- The right to know - Request information about Personal Information we have collected about you
- The right to deletion - Request deletion of your Personal Information
- The right to correct - Request correction of inaccurate Personal Information
- The right to access and data portability - Easy and portable access to your Personal Information
- The right to opt-out - We do not sell your Personal Information
- The right to limit use of sensitive information - We only use sensitive information as outlined in this policy
- The right to equal service - We will not discriminate against you for exercising your rights
To exercise these rights, send an email to [email protected]. We will verify your identity before processing your request.
Appealing Privacy Rights Decisions: You may appeal a decision by emailing us at [email protected] with the subject line "Privacy Request Appeal."
13. Additional Information
International Visitors: We are located in the United States. By providing us with your Personal Information and using the Services, you acknowledge that your information will be transferred to and processed in the United States.
Social Media Widgets: Our Services may include social media features. Your interactions with these features are governed by the privacy policy of the company providing them.
Links to Other Sites: Our Services may contain links to other sites. We are not responsible for the privacy practices of such sites.
Children's Privacy: Our Services are not directed to children under 13. If we learn we have received Personal Information from a child under 13 without parental consent, we will delete that information.
Changes to This Policy: We may update this Privacy Policy to reflect changes to our practices. We will notify you of material changes by email or through our Services.
14. Contact Us
For help with matters not related to exercising your privacy rights, please contact ClinikEHR Support.
For anything in this policy, including a data protection request or a complaint, write to us at:
Bettar Platforms, Inc.
8 The Green, Suite B
Dover, DE 19901
United States
[email protected]
Questions About Privacy?
If you have any questions about our Privacy Policy or how we handle your data, please contact our privacy team at [email protected]