Last Updated: October 24, 2023

Privacy Policy

We believe your data is your own. We are committed to protecting the privacy and security of our clients and their patients.

1. Introduction

Welcome to FrontOrbit ("we", "our", or "us"). We are committed to protecting your privacy and ensuring you have a positive experience on our website and in using our AI-powered front desk services (the "Services").

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Services, which are designed specifically for service businesses like MedSpas, Dental Clinics, and Salons.

2. Information We Collect

We collect several types of information from and about users of our Services, including:

  • Account Information: Name, email address, phone number, and billing information when you register for an account.
  • Clinic Data: Information about your business, staff schedules, and service menus integrated via your scheduling software.
  • Communication Data: Transcripts of AI phone calls, SMS messages, and Meta DMs processed on your behalf.
  • Usage Data: Information about how you interact with our dashboard, including IP addresses, browser types, and log data.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our AI receptionist services.
  • Process transactions and send related billing information.
  • Facilitate the booking and scheduling of appointments in your integrated calendar.
  • Train and improve our underlying AI models (using anonymized and aggregated data only).
  • Send administrative messages, technical notices, and security alerts.

4. HIPAA & Health Data

FrontOrbit is built from the ground up to serve healthcare providers. We act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA).

  • We execute Business Associate Agreements (BAAs) with covered entities.
  • Protected Health Information (PHI) processed during phone calls or texts is encrypted both in transit and at rest using AES-256.
  • We enforce strict access controls and maintain comprehensive audit logs.
  • AI training explicitly excludes raw PHI to prevent data leakage.

To request a signed BAA, please contact your account manager or email [email protected].

5. Data Sharing & Disclosure

We do not sell your personal data or your patients' data. We may share information with:

  • Service Providers: Third-party vendors who perform services on our behalf (e.g., cloud hosting via AWS/GCP, payment processing via Stripe).
  • Integrations: The scheduling platforms (e.g., Jane App, Boulevard, Mindbody) you explicitly authorize us to connect with.
  • Legal Requirements: If required to do so by law or in response to valid requests by public authorities.

6. Data Security

We implement enterprise-grade technical and organizational security measures designed to protect the security of any personal information we process. However, please remember that no transmission of data over the internet or any wireless network can be guaranteed to be 100% secure.

7. Your Privacy Rights

Depending on your location (such as California under CCPA or Europe under GDPR), you may have specific rights regarding your personal data:

  • The right to access the personal information we hold about you.
  • The right to request that we delete your personal information.
  • The right to opt-out of the sale of your personal information (Note: We do not sell your data).

To exercise these rights, please contact us using the details below.

8. Contact Us

If you have any questions or comments about this Privacy Policy, you may contact our Data Protection Officer at:

FrontOrbit Privacy Team

100 Innovation Way, Suite 400

New York, NY 10011

[email protected]