1. Overview
This Privacy Policy explains how Nemsol Inc. (operating as Nem) ("Nem," "we," "our," or "us") collects, uses, shares, and protects information when you use our Service. Healthcare data is sensitive and we treat it that way: our architecture is designed to meet the HIPAA technical and administrative safeguards.
HIPAA has no official certification, and no organization can be certified HIPAA compliant, so we do not claim one. What we can say is that our architecture is built to the HIPAA Security Rule safeguards, our self-attestation is in progress, and SOC 2 is planned rather than held. We will never claim a certification we do not have.
2. Information we collect
Information you provide
- Account information - name, email, phone number, organization details.
- Billing information - payment method, billing address (processed via Stripe; we do not store full card numbers).
- Clinic configuration - staff records, treatment catalog, branding, Voice agent prompts.
- Patient information you enter - names, contact details, clinical notes, appointments, billing records. This may include Protected Health Information (PHI) under HIPAA.
Information collected automatically
- Voice agent call data - recordings, transcripts, caller phone numbers, AI summaries.
- Usage data - pages visited, features used, time spent, error logs.
- Device data - IP address, browser type, operating system.
3. How we use information
- To provide the Service - scheduling, Voice Agent, billing, reports.
- To communicate with you about your account, security, and product updates.
- To improve the Service - aggregated, de-identified usage analytics (not patient information).
- To prevent fraud and abuse.
- To comply with legal obligations.
We do not sell your data. We do not use patient information, call recordings, or transcripts for advertising, for training or improving AI models, or for any purpose other than providing the Service to the clinic that owns them.
4. How we store data
Production runs on Google Cloud in the us-central1 region of the United States, under a HIPAA Business Associate Agreement signed on August 8, 2026. Data is encrypted at rest by that provider and in transit on every connection. Data is stored encrypted at rest (AES-256) and encrypted in transit (TLS 1.2+). Access is restricted by role-based access control (RBAC) and logged.
5. How we share data
We share data only with:
- Subprocessors who provide infrastructure on our behalf (cloud hosting, voice AI, payment processing, email, analytics).
- Authorized users in your workspace - based on the roles you configure.
- Authorities when required by law, valid subpoena, or court order. We will notify you unless legally prohibited.
Nem uses a small set of subprocessors. PHI-touching subprocessors are Retell AI (voice infrastructure), Google Workspace (business email and documents), AWS (file storage, email transport) and Google Cloud (production application hosting and database (us-central1)), each under a Business Associate Agreement executed before any PHI is processed in production. PHI-free services are Vercel (marketing site hosting), Neon (development database), Stripe (subscription billing and payments), Cloudflare Turnstile (bot protection on sign-in and sign-up), Resend (transactional email) and PostHog (product analytics); they operate under a strict PHI-free policy and never receive PHI. Vercel and Neon are outside the production data path by architecture rather than by promise, so no Business Associate Agreement is sought for either. Cloudflare offers a Business Associate Agreement only at its Enterprise tier, which is precisely why Turnstile is kept out of every PHI path.
This list was last reviewed on September 2, 2026. A current subprocessor list is available on request to info@nemsol.org and on our Trust Center.
6. Google Calendar data
Connecting a Google Calendar is optional, off unless your clinic enables it, and done by an Owner or Admin, as one connection for the clinic, through Google's own consent screen. Once connected, your clinic's Owner or Admin chooses the sync direction, import mode, and private-events setting under Settings, Connections and integrations, Google Calendar, Details.
What we ask for. Nem requests three scopes: your basic Google account identifier and email address (openid, email), and calendar.events.owned, which covers only events on calendars you own. We do not request access to Gmail, Google Drive, contacts, or any other Google service, and we do not request the broader calendar.events scope.
Sync direction. Two-way (default): Nem writes appointments to your calendar and reads your calendar's busy times so Nem does not offer a slot you have already taken. One-way, Nem to Google: Nem still writes appointments to your calendar, but never reads it at all.
What we read, in two-way sync. We always read the start and end times of other events on your primary calendar, to hold them as busy intervals. Only an event that starts between one week ago and 40 days from now can become a Nem appointment; any other event is only ever a busy interval. What happens to an event's title depends on your import mode:
- Tagged events only (default). We read a title only in memory, to check whether it contains the tag NemPMS or NemCMS. An untagged event is kept only as a busy interval; its title is never stored. A tagged event becomes a Nem appointment, matched to a patient by an appointment code or patient ID in the title where present, or held for your staff to match otherwise.
- All events. If you turn this on, every timed event in that window that is not an all-day event is imported as a Nem appointment, and its title is stored, so that Nem can offer it for patient matching. Nem does not read event descriptions, locations, attendees or organisers in either mode.
What we write. When an appointment is booked in Nem, we create a matching event on the connected calendar carrying a title of the form "Appointment - Jane D. · A7K2Q · NemPMS": the patient's first name and last initial, a random appointment code unique to that appointment, and NemPMS or NemCMS for whether it is a practice visit or a care management contact. The description holds only a link back to the appointment in Nem. We add no attendees, no visit reason, no clinical notes and no phone numbers. Where a clinic's administrator has ticked the Business Associate Agreement attestation for a Google Workspace account, the title may carry the patient's full name in place of the first name and last initial; we never do this for a personal Gmail account. By default the event is marked private, so anyone you share your calendar with sees only that you are busy; you can turn this off. We update and delete these events when the appointment changes or is cancelled. If you move a Nem-created event in Google, Nem keeps its own scheduled time and notifies your clinic of the mismatch rather than rescheduling the appointment.
Imported events. If a Google event you tagged (or, in all-events mode, any timed event) moves in Google, we move the matching Nem appointment to match. If it is deleted in Google, we flag the Nem appointment for your staff to review rather than cancelling it automatically. A care management (NemCMS) appointment never adds billable minutes on its own; billable time comes only from documented work such as recorded calls and logged care-plan time.
What we store. We store the refresh token that keeps the connection working, encrypted at rest with AES-256-GCM. We do not store Google access tokens. We also store the email address of the connected account, your sync direction, import mode and private-events choices, a synchronisation cursor, and the identifiers of the notification channel Google uses to tell us that a calendar has changed. An untagged event in tagged mode never has its title stored. The title of an event we import, whether tagged or, in all-events mode, any timed event, is stored with the imported booking in Pending Appointments until your staff resolve or reject it; rejecting it clears the stored title.
How we use it. Only to provide these scheduling features between Nem and your calendar. Google Calendar data is not sold, is not used for advertising, and is not used to train, retrain or improve any generalized artificial intelligence or machine learning model.
How we share it. We do not share Google user data with third parties, other than the cloud infrastructure that runs Nem and processes it on our behalf, or where we are required to by law.
Limited Use. Nem's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. You can disconnect at any time from the calendar settings page in Nem, under either sync direction. We stop syncing at once, stop the notification channel, revoke the token with Google, and delete the stored token and the busy intervals we were holding. You can also revoke access from your Google Account permissions page. Events Nem has already created remain on your calendar unless you delete them.
7. HIPAA and Business Associate Agreement
If you are a covered entity under HIPAA, you are required to have a Business Associate Agreement (BAA) in place before processing PHI through the Service. Contact info@nemsol.org to request our BAA. We will execute BAAs with HIPAA-eligible customers, and we execute BAAs with our PHI-touching subprocessors before any PHI is processed in production.
For customers processing Protected Health Information (PHI), the Business Associate Agreement (BAA) governs the handling of PHI and controls over any conflicting term. The order of precedence for PHI is: (1) the BAA, (2) your subscription order, (3) the Terms of Service, (4) the Privacy Policy, and (5) any other posted policy.
8. Data retention
Active customer data is retained for the duration of your subscription. After termination or cancellation your data remains available for 30 days so you can export it (CSV download); after that window we delete it, unless a legal or contractual retention obligation requires us to keep it longer. Deletion is a documented process we run, not an automated purge job. Encrypted backups are overwritten on a rolling 30-day cycle, so a copy can persist in backup for up to 30 days after deletion. Audit logs are retained for at least 6 years to support HIPAA-aligned operations.
For Protected Health Information, the return-or-destroy obligation in the Business Associate Agreement controls, including its infeasibility carve-out for data held in backup.
9. Your rights
You have the right to:
- Access the information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your information (subject to legal retention requirements).
- Export your data in a portable format (CSV).
- Opt out of non-essential communications.
To exercise these rights, email info@nemsol.org.
10. Children
The Service is not directed to children under 13. We do not knowingly collect data directly from children. Patient records you enter may include minors as patients of your clinic; the legal basis for processing is your responsibility as the controller of those records.
11. International transfers and remote access
Data is stored and processed in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US, where data protection laws may differ from those in your jurisdiction. Data is not stored outside the United States.
12. Security incidents
If we discover a security incident affecting customer data, we notify affected customers without unreasonable delay and no later than five (5) business days after discovery. The clock starts when we discover the incident, not when we finish confirming it. We provide the facts as they are known and keep updating until the matter is resolved.
For Protected Health Information the Business Associate Agreement sets this obligation and controls over any other document, including this page.
This is the same commitment published on our Security & Compliance page.
13. Changes to this policy
We may update this policy periodically. Material changes will be communicated by email and posted here with a new "Last updated" date.
14. Contact
Questions about privacy? Email info@nemsol.org. For BAAs and HIPAA inquiries, email info@nemsol.org.

