Introduction
MedVibe AI, Inc. (“MedVibe AI,” “we,” “us,” or “our”) is a business-to-business (B2B) artificial intelligence platform headquartered in Miami, Florida, that provides AI-powered patient engagement, smart scheduling, and client retention services exclusively to licensed Medical Spas, Cosmetic Clinics, and aesthetic healthcare practices (collectively, “Clinic Customers”) operating in the United States.
This Privacy Policy (“Policy”) describes how MedVibe AI collects, receives, uses, stores, shares, transfers, and protects information in connection with (i) our web-based platform available at medvibe.ai, (ii) our mobile and web applications, (iii) our application programming interfaces (APIs) and integrations, including the Meta WhatsApp Business Cloud API, and (iv) all related services, features, content, and communications (collectively, the “Services”).
This Policy applies to:
- Clinic Customers: authorized representatives, administrators, staff members, and agents of licensed healthcare and aesthetic practices that subscribe to the Services;
- End Patients: individuals whose personal and health-related information is processed by Clinic Customers through the Services;
- Visitors: individuals who browse the medvibe.ai website without registering for an account.
Important — Business Associate Role: With respect to End Patients’ Protected Health Information (PHI), MedVibe AI acts as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We process PHI solely at the direction of and on behalf of Clinic Customers, who are Covered Entities. A Business Associate Agreement (BAA) is available to all Clinic Customers on the Professional and Elite subscription tiers.
By accessing or using the Services, you acknowledge that you have read and understood this Policy. Clinic Customers also acknowledge this Policy on behalf of their End Patients to the extent they have obtained all required patient authorizations and consents under applicable law. If you do not agree to this Policy, please discontinue use of the Services immediately.
This Policy is incorporated by reference into our Terms of Service. In the event of a conflict between this Policy and the Terms of Service, this Policy governs with respect to privacy and data protection matters.
Definitions
The following capitalized terms have the meanings set forth below:
| Term | Definition |
|---|---|
| Business Associate | An entity that performs functions involving the use or disclosure of PHI on behalf of a Covered Entity, as defined under HIPAA, 45 C.F.R. § 160.103. |
| Clinic Customer | Any licensed medical spa, cosmetic clinic, dermatology practice, plastic surgery center, or similar aesthetic healthcare provider that subscribes to the Services. |
| Covered Entity | A healthcare provider that conducts certain standard administrative and financial transactions electronically and is subject to HIPAA, as defined at 45 C.F.R. § 160.103. |
| End Patient | An individual whose personal information or PHI is submitted to or processed through the Services by a Clinic Customer. |
| Meta API | The WhatsApp Business Cloud API and related Meta Platform APIs used to enable AI-powered messaging between Clinic Customers and End Patients via WhatsApp. |
| Personal Information | Any information that identifies, relates to, or could reasonably be linked to an identified or identifiable natural person, as defined under applicable US privacy laws including the CCPA. |
| PHI | Protected Health Information: individually identifiable health information transmitted or maintained in any form or medium that relates to an individual’s past, present, or future health condition, healthcare provision, or payment for healthcare. |
| Processing | Any operation performed on Personal Information or PHI, including collection, recording, storage, use, disclosure, transmission, structuring, or deletion. |
| Services | All MedVibe AI software-as-a-service products, APIs, integrations, mobile applications, and related offerings accessible through medvibe.ai. |
Information We Collect
We collect the following categories of information, depending on your role and how you interact with the Services:
3.1 Clinic Customer Account Information
When a Clinic Customer creates and manages an account, we collect:
- Business name, DBA name, and practice type;
- Business address, city, state, and ZIP code;
- Business phone number, email address, and website URL;
- Tax Identification Number (EIN) or National Provider Identifier (NPI) where required;
- Account administrator name, role, and contact details;
- Staff user names, email addresses, and role assignments;
- Subscription plan, billing address, and payment method metadata (we do not store full card numbers — see Section 3.6).
3.2 End Patient Information HIPAA
Clinic Customers submit End Patient information to the Services to enable AI-powered engagement. This information may include:
- Full name, date of birth, and gender;
- Contact information: WhatsApp-registered phone number and email address;
- Appointment history, treatment types, scheduled procedures, and provider names;
- Pre-treatment questionnaire responses and intake form data;
- Post-treatment outcomes and satisfaction survey responses;
- Consent records and signed authorization documents;
- Health conditions, allergies, and medications mentioned in AI-assisted chat conversations;
- Before-and-after photographs where submitted through the platform;
- Payment deposit amounts and transaction references (not full payment credentials).
PHI Notice: Appointment records, treatment information, health conditions, and clinical notes submitted through the Services may constitute Protected Health Information under HIPAA. MedVibe AI processes this information solely as a Business Associate under the lawful direction of the applicable Clinic Customer (Covered Entity). End Patients should contact their clinic directly to exercise their HIPAA rights regarding their PHI.
3.3 WhatsApp Conversation Data Meta API
When Clinic Customers enable the WhatsApp Business integration, the Services receive and process the following data transmitted through the Meta WhatsApp Business Cloud API:
- WhatsApp phone number (WABA) of the clinic business account;
- End Patient WhatsApp phone numbers (used as message routing identifiers);
- Inbound and outbound message content (text, images, documents, and audio messages);
- Message timestamps, delivery status indicators (sent, delivered, read), and message IDs;
- Conversation session identifiers and thread metadata;
- Template message names and parameter values used in approved messaging campaigns;
- Opt-in and opt-out signals received from End Patients.
3.4 Integration and Third-Party Service Data
When Clinic Customers connect third-party tools (e.g., Mindbody, Jane App, Stripe, Google Calendar), we receive data necessary to enable the integration, including:
- OAuth access tokens and API credentials (stored encrypted);
- Appointment, booking, and scheduling records from practice management systems;
- Payment transaction references from payment processors;
- Calendar events and availability windows.
3.5 Usage and Technical Data
We automatically collect technical information when you access the Services:
- IP address, browser type, operating system, and device identifiers;
- Pages visited, features used, click-stream data, and session duration;
- Error logs, diagnostic data, and performance metrics;
- Referral URLs and UTM campaign parameters.
3.6 Payment Information
Subscription billing is processed by our PCI-DSS compliant payment processor (Stripe, Inc.). MedVibe AI stores only payment metadata (last four digits of card, expiration month and year, billing name, billing ZIP). Full payment card numbers, CVV codes, and bank account details are never stored on MedVibe AI servers.
How We Collect Information
We collect information through the following methods:
4.1 Directly from You
Information you voluntarily provide when registering an account, completing onboarding forms, configuring integrations, contacting support, or communicating with our team.
4.2 From Clinic Customers
Information about End Patients that Clinic Customers upload, import, or sync from their existing practice management systems and patient databases through the Services.
4.3 Through the Meta WhatsApp Business Cloud API
Message data, delivery notifications, and conversation metadata received programmatically from Meta Platforms, Inc. via the WhatsApp Business Cloud API when End Patients send messages to a Clinic Customer’s WhatsApp Business Account.
4.4 Through Third-Party Integration APIs
Data received from connected platforms (Mindbody, Jane App, Stripe, Google Calendar, etc.) via OAuth-authenticated API calls made at the Clinic Customer’s direction.
4.5 Automatically
Technical and usage data collected automatically via server logs, cookies, pixel tags, and similar tracking technologies when you interact with the Services (see Section 12).
How We Use Your Information
We use the information we collect for the following purposes, which constitute our legal bases for processing under applicable law:
| Purpose | Information Used | Basis |
|---|---|---|
| Providing and operating the Services | Account info, usage data, integration data | Contract performance |
| AI-powered patient engagement and automated messaging | End Patient info, conversation data | Contract performance; Legitimate interest |
| Smart appointment scheduling and calendar sync | Appointment data, calendar data | Contract performance |
| Client retention automation (reminders, re-booking) | End Patient contact info, treatment history | Contract performance; Legitimate interest |
| Billing and subscription management | Account info, payment metadata | Contract performance; Legal obligation |
| Platform security and fraud prevention | Technical data, usage data | Legitimate interest; Legal obligation |
| Customer support and technical assistance | Account info, usage data | Contract performance; Legitimate interest |
| Analytics and Service improvement | Aggregated, de-identified usage data | Legitimate interest |
| Legal compliance and dispute resolution | All categories as necessary | Legal obligation |
| Marketing communications to Clinic Customers | Account contact info | Legitimate interest; Consent |
We do not sell, rent, or trade Personal Information or PHI to third parties for their own marketing purposes. We do not use End Patient PHI for any purpose other than providing the Services to the applicable Clinic Customer, as directed by that Clinic Customer, and as permitted by applicable law including HIPAA.
Meta API & WhatsApp Business Platform Meta
MedVibe AI integrates with the WhatsApp Business Cloud API, operated by Meta Platforms, Inc. (“Meta”), to enable AI-powered patient messaging between Clinic Customers and their End Patients via WhatsApp. This section describes our specific data practices relating to this integration.
6.1 How the Integration Works
Clinic Customers register a WhatsApp Business Account (WABA) through the Meta Business Platform and authorize MedVibe AI as a Business Solution Provider (BSP). Once authorized:
- MedVibe AI sends outbound messages (appointment reminders, AI responses, payment links) to End Patients on behalf of the Clinic Customer via Meta’s Cloud API infrastructure;
- Inbound messages from End Patients are received by MedVibe AI’s servers via Meta webhooks and processed by our AI engine to generate contextually appropriate responses;
- All message traffic is routed through Meta’s global infrastructure before reaching MedVibe AI’s processing environment.
6.2 Data Received from Meta
MedVibe AI receives the following data from Meta’s WhatsApp Cloud API:
- End Patient WhatsApp phone numbers (used solely for message delivery);
- Message content in plaintext form as delivered to our API endpoint (see Encryption note below);
- Message delivery and read receipts;
- Conversation session identifiers and timestamp metadata;
- User opt-out signals (“STOP” or block events) which are honored immediately.
6.3 Encryption Disclosure Encryption
Important — WhatsApp Business API Encryption Model: WhatsApp’s consumer app uses end-to-end encryption (E2EE) between two individuals. However, WhatsApp Business Cloud API messages are NOT end-to-end encrypted in the same manner. When a business uses the Cloud API, Meta processes message content on its servers before delivering it to the business’s API endpoint. This is a documented characteristic of the WhatsApp Business Cloud API and is disclosed in Meta’s documentation. MedVibe AI applies additional encryption layers (TLS 1.3 in transit and AES-256 at rest — see Section 8) to protect message content once received. Clinic Customers are responsible for disclosing this characteristic to End Patients as required under applicable law and their own HIPAA policies.
6.4 Meta’s Data Practices
MedVibe AI’s use of the WhatsApp Business Cloud API is subject to Meta’s Privacy Policy, the WhatsApp Business Terms of Service, and the Meta Platform Terms. Meta independently processes certain data in connection with the API. MedVibe AI is not responsible for Meta’s independent data processing practices.
6.5 HIPAA and Meta API
Clinic Customers who are HIPAA Covered Entities and who use the WhatsApp Business integration to transmit or discuss PHI must:
- Obtain a BAA from MedVibe AI (available on Professional and Elite plans);
- Conduct an independent assessment of whether Meta’s Cloud API infrastructure meets their HIPAA obligations, including executing any required data processing agreements with Meta;
- Obtain appropriate patient authorization or consent to communicate PHI via WhatsApp, as required by HIPAA’s Privacy Rule (45 C.F.R. Part 164, Subpart E) and any applicable state laws;
- Ensure End Patients understand that WhatsApp Business API messages are not E2EE (see Section 6.3).
6.6 Patient Opt-Out
End Patients may opt out of receiving WhatsApp messages from a Clinic Customer at any time by replying “STOP,” “OPTOUT,” or blocking the clinic’s number. MedVibe AI honors all opt-out signals within 24 hours and suppresses further outbound messaging to that number until the End Patient re-opts-in. Opt-out records are maintained for compliance auditing purposes.
HIPAA Compliance & Protected Health Information HIPAA
MedVibe AI is committed to compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act, and applicable implementing regulations (collectively, “HIPAA”).
7.1 Our Role as Business Associate
When Clinic Customers (as HIPAA Covered Entities or Business Associates) use the Services to process PHI, MedVibe AI acts as a Business Associate. We process PHI only:
- As specifically instructed by the applicable Clinic Customer;
- To the minimum extent necessary to perform the Services;
- In accordance with the Business Associate Agreement (BAA) executed with that Clinic Customer; and
- As otherwise required or permitted by HIPAA.
BAAs are available to Clinic Customers on our Professional and Elite subscription plans. Starter plan subscribers must not submit PHI through the Services without first upgrading to a plan that includes a BAA.
7.2 Administrative Safeguards
- Designated Security Officer and Privacy Officer responsible for HIPAA compliance;
- Workforce training on PHI handling policies and procedures (minimum annually);
- Access management policies with role-based access controls and minimum necessary standards;
- Business associate agreements with all sub-processors who access PHI;
- Contingency planning, disaster recovery, and data backup procedures;
- Regular risk analysis and risk management programs.
7.3 Physical Safeguards
- PHI is stored exclusively in U.S.-based, SOC 2 Type II certified cloud data centers;
- Physical access to data center facilities is restricted to authorized personnel only;
- Workstation and device security policies govern access to systems containing PHI.
7.4 Technical Safeguards
- Unique user authentication with multi-factor authentication (MFA) required for all staff accounts accessing PHI;
- Automatic session timeout after periods of inactivity;
- Audit logging of all access to and disclosures of PHI, retained for a minimum of six (6) years;
- Encryption of PHI in transit (TLS 1.3) and at rest (AES-256) — see Section 8;
- Integrity controls to prevent unauthorized alteration or destruction of PHI.
7.5 Breach Notification
In the event of a breach of unsecured PHI, MedVibe AI will notify affected Clinic Customers without unreasonable delay and in no event later than sixty (60) calendar days following discovery of the breach, as required by 45 C.F.R. § 164.410. Notification will include the information required by the HIPAA Breach Notification Rule, to the extent reasonably possible given the circumstances. Clinic Customers retain responsibility for notifying affected End Patients, the Secretary of HHS, and (where applicable) the media as required by 45 C.F.R. §§ 164.404–164.408.
7.6 End Patient Rights Regarding PHI
End Patients have specific rights regarding their PHI under HIPAA, including the right to access, amend, and receive an accounting of disclosures. Because MedVibe AI processes PHI as a Business Associate acting under the direction of Clinic Customers, End Patients must direct PHI-related requests to the applicable Clinic Customer (their healthcare provider). MedVibe AI will cooperate with Clinic Customers in facilitating compliance with patient rights requests as required under our BAA.
Data Security & Encryption Encrypted
MedVibe AI implements a comprehensive, defense-in-depth security program to protect the confidentiality, integrity, and availability of all data processed through the Services, including PHI and End Patient information transmitted via the Meta WhatsApp Business Cloud API.
8.1 Encryption Standards
| Layer | Standard | Scope |
|---|---|---|
| Data in Transit | TLS 1.3 with strong cipher suites; HSTS enforced | All web, API, and webhook traffic |
| Data at Rest | AES-256 encryption | All database records, file storage, backups |
| API Credentials & Secrets | AES-256; Hardware Security Module (HSM) key management | OAuth tokens, API keys, integration credentials |
| Database Encryption | Field-level encryption for PHI identifiers | Patient names, phone numbers, health data fields |
| Backup Encryption | AES-256; encrypted at source before transfer | All automated and manual backups |
8.2 Access Controls
- Role-Based Access Control (RBAC) with least-privilege principles applied to all system access;
- Multi-factor authentication (MFA) required for all staff, contractor, and Clinic Customer administrator accounts;
- Privileged Access Management (PAM) for infrastructure and database access;
- Automated de-provisioning of access upon employee or contractor termination;
- Quarterly access reviews for all personnel with access to production systems or PHI.
8.3 Infrastructure Security
- Services hosted on SOC 2 Type II certified cloud infrastructure in the United States;
- Network segmentation with separate virtual private clouds (VPCs) for production, staging, and development environments;
- Web Application Firewall (WAF), DDoS protection, and intrusion detection systems;
- Automated vulnerability scanning and monthly third-party penetration testing;
- 99.9% uptime SLA with redundant infrastructure and automated failover.
8.4 Incident Response
MedVibe AI maintains a formal Incident Response Plan (IRP) that includes detection, containment, eradication, recovery, and post-incident analysis procedures. Security incidents are triaged within four (4) hours of detection. Clinic Customers affected by confirmed security incidents impacting their data will be notified as described in Section 7.5 (for PHI breaches) and within seventy-two (72) hours for other material security incidents.
8.5 Vendor and Sub-Processor Security
All third-party service providers and sub-processors who process Personal Information or PHI on our behalf are subject to security assessments, contractual data protection obligations, and (where applicable) Business Associate Agreements prior to engagement. A list of our current sub-processors is available upon request to [email protected].
Limitation: While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. Clinic Customers are encouraged to implement complementary security controls, including staff training and patient consent procedures.
Sharing & Disclosure of Information
MedVibe AI does not sell, rent, trade, or lease Personal Information or PHI. We may share information only as described below:
9.1 Service Providers and Sub-Processors
We share information with vetted third-party service providers that assist us in operating the Services, including cloud hosting providers, payment processors, email delivery services, analytics providers, and customer support platforms. These providers are bound by contractual data protection obligations and are permitted to use information only as necessary to perform services on our behalf.
9.2 Meta Platforms, Inc.
Message data is necessarily transmitted through Meta’s infrastructure as part of the WhatsApp Business Cloud API. MedVibe AI’s relationship with Meta is governed by the Meta Platform Terms and applicable data processing agreements. MedVibe AI does not independently share Personal Information or PHI with Meta beyond what is required for message delivery.
9.3 Clinic Customer Direction
We act on the documented instructions of Clinic Customers regarding PHI and End Patient data. If a Clinic Customer instructs us to share data with a specified third party (e.g., their EHR provider), we will do so in accordance with those instructions and the applicable BAA.
9.4 Legal Requirements
We may disclose information if we believe in good faith that disclosure is required or permitted by applicable law, including to:
- Comply with a subpoena, court order, or governmental demand;
- Enforce our Terms of Service or protect our legal rights;
- Investigate, prevent, or take action regarding illegal activity, suspected fraud, or threats to the physical safety of any person;
- Comply with mandatory HIPAA disclosure obligations or public health reporting requirements.
9.5 Business Transfers
In the event of a merger, acquisition, asset sale, financing, or other corporate transaction involving MedVibe AI, information held by MedVibe AI may be transferred to the successor entity. We will provide reasonable advance notice to Clinic Customers of any such transfer that materially affects their data, and require the successor entity to honor the terms of this Policy and any applicable BAAs.
9.6 Aggregated and De-Identified Data
We may use and share aggregated or de-identified data that cannot reasonably be used to identify any individual for research, analytics, benchmarking, marketing, and service improvement purposes. Such data is not subject to this Policy.
Your Privacy Rights CCPA
Depending on your state of residence and role, you may have the following rights with respect to your Personal Information:
10.1 California Residents — California Consumer Privacy Act (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of Personal Information we have collected about you, the sources, our business purposes, and the categories of third parties with whom it is shared;
- Right to Delete: Request deletion of Personal Information we have collected, subject to certain legal exceptions;
- Right to Correct: Request correction of inaccurate Personal Information;
- Right to Opt-Out of Sale or Sharing: MedVibe AI does not sell or share Personal Information for cross-context behavioral advertising. No opt-out action is required;
- Right to Limit Use of Sensitive Personal Information: To the extent we process Sensitive Personal Information (including health-related data), we limit its use to purposes permitted by the CCPA/CPRA;
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
To submit a CCPA/CPRA request, email [email protected] with the subject line “CCPA Privacy Request” or contact us via WhatsApp at https://api.whatsapp.com/send?phone=17866559195. We will respond within forty-five (45) days. We may extend this period by an additional forty-five (45) days where reasonably necessary, with prior notice.
10.2 Florida Residents — Florida Digital Bill of Rights
Florida residents whose personal data is processed by controllers meeting applicable thresholds under the Florida Digital Bill of Rights (FDBR), effective July 1, 2024, may have rights to access, correct, delete, and obtain a portable copy of their personal data. MedVibe AI will process qualifying requests submitted to [email protected] in accordance with applicable law.
10.3 Other State Privacy Rights
Residents of states with comprehensive consumer privacy laws (including but not limited to Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and Indiana) may have similar rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising or profiling. MedVibe AI honors verifiable requests from residents of states with enacted consumer privacy laws. Submit requests to [email protected].
10.4 Clinic Customer Account Holders
Clinic Customer account holders may access, update, and correct their account information at any time through the platform dashboard. To request account deletion, contact [email protected]. Deletion requests will be processed in accordance with our Data Retention Policy (Section 11) and any applicable legal obligations.
10.5 End Patient Rights
End Patients whose data is processed through the Services by their healthcare provider are considered “data subjects” of the applicable Clinic Customer. PHI rights under HIPAA should be directed to the Clinic Customer as the Covered Entity. Non-PHI personal data rights requests from End Patients may be directed to MedVibe AI at [email protected]; we will route such requests to the applicable Clinic Customer.
10.6 Authorized Agents
You may designate an authorized agent to submit privacy rights requests on your behalf. Authorized agents must provide written proof of authorization, and we may require you to verify your identity directly.
Data Retention
We retain Personal Information and PHI for the minimum period necessary to fulfill the purposes described in this Policy, or as required or permitted by applicable law:
| Data Category | Retention Period | Basis |
|---|---|---|
| Active Clinic Customer account data | Duration of subscription + 90 days post-termination | Contract performance |
| PHI and End Patient health data | 6 years from date of creation or last use (per HIPAA) | HIPAA 45 C.F.R. § 164.530(j) |
| WhatsApp conversation logs | 24 months from date of message (configurable by Clinic Customer) | Legitimate interest; HIPAA audit requirements |
| Appointment and scheduling records | 7 years | Legal obligation; Business records |
| Billing and payment records | 7 years | Tax and financial regulation |
| HIPAA audit logs | 6 years | HIPAA 45 C.F.R. § 164.312(b) |
| Security incident records | 6 years | HIPAA; Legal obligation |
| Website usage and technical data | 24 months | Legitimate interest |
| Marketing communications data | Until opt-out + 36 months | Legitimate interest; Consent |
Upon expiration of the applicable retention period, we securely delete or permanently de-identify data using industry-standard data destruction methods. Clinic Customers may request earlier deletion of their data (subject to legal retention requirements) by contacting [email protected].
Cookies & Tracking Technologies
MedVibe AI uses cookies and similar tracking technologies on the medvibe.ai website. We do not use tracking technologies within the core SaaS platform in ways that affect End Patient data.
12.1 Types of Cookies Used
- Strictly Necessary Cookies: Required for authentication, security, and core website functionality. These cannot be disabled.
- Functional Cookies: Remember your preferences (language, display settings) to personalize your experience.
- Analytics Cookies: Collect anonymized data about website usage (Google Analytics 4) to help us improve our content and services.
- Marketing Cookies: Used to measure the effectiveness of our advertising campaigns (Meta Pixel, Google Ads). Only placed with your consent.
12.2 Cookie Consent and Opt-Out
We obtain your consent for non-essential cookies via our cookie consent banner. You can manage your cookie preferences at any time through your browser settings, or by contacting [email protected]. Opting out of analytics or marketing cookies will not affect your ability to use the Services.
Children’s Privacy
The Services are designed exclusively for use by licensed businesses (Clinic Customers) and are not directed to, and should not be used by, children under the age of thirteen (13). We do not knowingly collect Personal Information from children under 13 through the medvibe.ai website or as part of Clinic Customer onboarding.
With respect to End Patients: Clinic Customers may treat minor patients (“Minors”) in the course of their licensed healthcare practice. Any PHI relating to Minors that is processed through the Services by a Clinic Customer is subject to applicable federal and state laws governing the privacy of minors’ health information. Clinic Customers are solely responsible for ensuring they have appropriate parental or guardian consent before submitting any Minor’s PHI to the Services.
If we discover that we have inadvertently collected Personal Information from a child under 13 through our website, we will promptly delete such information. Contact [email protected] if you believe we may have collected such information.
Third-Party Links & Services
The Services may contain links to, or integrate with, third-party websites, services, and platforms (including but not limited to Mindbody, Jane App, Stripe, medvibe, Google Workspace, and Meta Platforms). This Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you interact with.
MedVibe AI is not responsible for the privacy practices, security measures, content, or data handling of third-party services, even where we have integrated with them. Our integration with a third-party service does not constitute an endorsement of that service’s privacy practices.
International Data Transfers
MedVibe AI is headquartered in Miami, Florida, and our primary data processing infrastructure is located in the United States. We do not intentionally transfer Personal Information or PHI outside the United States for storage or primary processing.
Certain sub-processors (including Meta Platforms, Inc. in connection with the WhatsApp Cloud API) may process data in multiple jurisdictions as part of their global infrastructure. MedVibe AI requires such sub-processors to implement appropriate transfer mechanisms and contractual protections for any cross-border data transfers.
If you are located outside the United States and access our website or use our Services, please be aware that your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country of residence. By using the Services, you consent to such transfer where required by applicable law.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, the Services, applicable law, or regulatory guidance. When we make material changes, we will:
- Update the “Last Updated” date at the top of this Policy;
- Post a notice on the medvibe.ai website homepage;
- Send an email notification to the primary account administrator of each active Clinic Customer account at least fourteen (14) days before the changes take effect (for material changes);
- Where required by HIPAA or other applicable law, provide additional notice.
Your continued use of the Services after the effective date of any updated Policy constitutes your acceptance of the revised terms. If you do not agree to a material change, you may terminate your subscription in accordance with our Terms of Service.
Previous versions of this Privacy Policy are available upon request by contacting [email protected].
Contact Us & Data Requests
For questions, concerns, or requests regarding this Privacy Policy or MedVibe AI’s data practices, please contact our Privacy Team using the information below. We aim to respond to all inquiries within five (5) business days.
MedVibe AI — Privacy Team
1000 Brickell Avenue, Suite 715
Miami, FL 33131, United States
Disclaimer: This Privacy Policy is provided for informational purposes. It does not constitute legal advice. MedVibe AI recommends that Clinic Customers consult qualified legal counsel to ensure their own compliance with HIPAA, applicable state privacy laws, and all requirements relating to the use of third-party APIs (including the Meta WhatsApp Business Cloud API) in a healthcare context.