At DocAI Health, protecting your personal information and health-related data is one of our highest priorities.
We are committed to implementing appropriate technical, organizational, and administrative safeguards to protect your information from unauthorized access, disclosure, alteration, loss, or misuse.
This Data Protection Policy explains how we protect, manage, and secure data collected through our website, mobile applications, and AI-powered services.
1 Our Commitment to Data Protection
DocAI Health is committed to:
- Protecting user privacy
- Maintaining data confidentiality
- Applying industry-standard security measures
- Minimizing data collection whenever possible
- Providing transparency regarding data usage
- Respecting applicable privacy regulations
We continuously review and improve our security practices to address evolving cybersecurity risks.
2 Categories of Data We Protect
The information protected under this policy may include:
Personal Information
- Full name
- Dirección de correo
- Date of birth
- Account credentials
- Language preferences
Health Information
- Symptoms submitted through the platform
- Medical history voluntarily provided
- Medication information
- Consultation summaries
- Health-related interactions with our AI systems
Technical Information
- IP address
- Device information
- Browser type
- Operating system
- Session logs
- Security logs
3 Security Measures
DocAI Health uses multiple layers of security designed to protect user information.
Our safeguards may include:
Encryption
- Data encrypted during transmission (TLS/SSL)
- Encryption of sensitive information at rest
- Secure communication channels
Access Controls
- Role-based access management
- Authentication controls
- Restricted access to sensitive systems
- Monitoring of privileged accounts
Infrastructure Security
- Secure cloud hosting environments
- Firewalls and intrusion prevention systems
- Continuous monitoring
- Vulnerability assessments
Security Audits
- Periodic security reviews
- Internal security testing
- Third-party assessments where appropriate
4 Data Minimization
We strive to collect only the information necessary to:
- Provide services
- Improve platform performance
- Maintain security
- Comply with legal obligations
We avoid collecting unnecessary personal or health information whenever possible.
5 Data Retention
We retain information only for as long as necessary to:
- Provide services
- Maintain account functionality
- Meet legal and regulatory requirements
- Resolve disputes
- Enforce agreements
When information is no longer required, it is securely deleted or anonymized where appropriate.
6 International Data Protection
DocAI Health operates globally and may process information in multiple jurisdictions.
When transferring data internationally, we implement appropriate safeguards designed to protect personal information and maintain compliance with applicable privacy laws.
These safeguards may include:
- Standard Contractual Clauses (SCCs)
- Secure cloud infrastructure
- Data transfer protection measures
- Contractual privacy obligations
7 User Rights
Depending on your location, you may have the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your information
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent where applicable
Requests may be submitted by contacting:
8 Data Breach Response
In the event of a security incident involving personal information, DocAI Health will:
- Investigate the incident promptly
- Take appropriate containment measures
- Assess potential risks
- Notify affected individuals when required by law
- Cooperate with relevant authorities where necessary
9 Third-Party Service Providers
We may use trusted third-party providers for:
- Hosting services
- Cloud infrastructure
- Analítica
- Payment processing
- Customer support tools
These providers are required to implement appropriate security measures and may only process information for authorized purposes.
10 Artificial Intelligence and Data Processing
DocAI Health uses artificial intelligence technologies to provide health guidance and platform functionality.
AI systems may process information submitted by users in order to:
- Generate responses
- Personalize user experiences
- Improve service quality
- Maintain platform performance
AI-generated outputs are subject to technical limitations and should not be considered professional medical advice.
11 Children's Data
DocAI Health does not knowingly collect personal information from children under the age required by applicable law without parental or guardian consent.
If we become aware that such information has been collected improperly, we will take steps to remove it.
12 Regulatory Compliance
DocAI Health is committed to maintaining compliance with applicable privacy and data protection laws, including where applicable:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- California Privacy Rights Act (CPRA)
- Other applicable privacy regulations
Compliance efforts may evolve as regulations change.
13 Updates to This Policy
We may update this Data Protection Policy periodically.
Updated versions will be published on this page and become effective upon posting.
Users are encouraged to review this policy regularly.
14 Contáctanos
If you have any questions regarding this Data Protection Policy or our security practices, please contact:
Nuestro compromiso
At DocAI Health, we believe that trust is the foundation of digital healthcare.
We are committed to protecting your information through responsible data practices, modern security measures, and continuous improvement of our privacy and security programs.