LEGAL / LEGAL

Privacy Policy

Last updated · June 28, 2026

1. Overview

This Privacy Policy explains how Nemsol Inc. (operating as Nem) ("Nem," "we," "our," or "us") collects, uses, shares, and protects information when you use our Service. Healthcare data is sensitive and we treat it that way: our architecture is designed to meet the HIPAA technical and administrative safeguards.

HIPAA has no official certification, and no organization can be certified HIPAA compliant, so we do not claim one. What we can say is that our architecture is built to the HIPAA Security Rule safeguards, our self-attestation is in progress, and SOC 2 is planned rather than held. We will never claim a certification we do not have.

2. Information we collect

Information you provide

  • Account information - name, email, phone number, organization details.
  • Billing information - payment method, billing address (processed via Stripe; we do not store full card numbers).
  • Clinic configuration - staff records, treatment catalog, branding, Voice agent prompts.
  • Patient information you enter - names, contact details, clinical notes, appointments, billing records. This may include Protected Health Information (PHI) under HIPAA.

Information collected automatically

  • Voice agent call data - recordings, transcripts, caller phone numbers, AI summaries.
  • Usage data - pages visited, features used, time spent, error logs.
  • Device data - IP address, browser type, operating system.

3. How we use information

  • To provide the Service - scheduling, Voice Agent, billing, reports.
  • To communicate with you about your account, security, and product updates.
  • To improve the Service - aggregated and de-identified analytics only.
  • To prevent fraud and abuse.
  • To comply with legal obligations.

We do not sell your data. We do not use patient information for advertising, ranking, or model training without explicit customer consent.

4. How we store data

Data is stored encrypted at rest (AES-256) on infrastructure operated by our hosting partners (currently Neon and Vercel, in the United States). Data is encrypted in transit (TLS 1.2+). Access is restricted by role-based access control (RBAC) and logged.

5. How we share data

We share data only with:

  • Subprocessors who provide infrastructure on our behalf (cloud hosting, voice AI, payment processing, email, analytics).
  • Authorized users in your workspace - based on the roles you configure.
  • Authorities when required by law, valid subpoena, or court order. We will notify you unless legally prohibited.

Nem uses a small set of subprocessors. PHI-touching subprocessors are Retell AI (voice infrastructure), Google Workspace (business email and documents), AWS (file storage, email transport), Vercel (application hosting), Neon (database) and NEMSOL (Pvt) Ltd (engineering and support personnel (pakistan)), each under a Business Associate Agreement executed before any PHI is processed in production. PHI-free services are Stripe (subscription billing and payments), Cloudflare Turnstile (bot protection on sign-in and sign-up), Resend (transactional email) and PostHog (product analytics); they operate under a strict PHI-free policy and never receive PHI. Cloudflare offers a Business Associate Agreement only at its Enterprise tier, which is precisely why Turnstile is kept out of every PHI path.

Nem is operated with the support of its affiliate NEMSOL (Pvt) Ltd (CUIN 0342731), registered in Pakistan. Named engineering and support personnel of that affiliate access the platform. Access to Protected Health Information is permitted only under an intercompany Business Associate Agreement executed before any PHI is processed in production, and we will tell customers before that arrangement changes.

This list was last reviewed on August 1, 2026. A current subprocessor list is available on request to info@nemsol.org and on our Trust Center.

6. HIPAA and Business Associate Agreement

If you are a covered entity under HIPAA, you are required to have a Business Associate Agreement (BAA) in place before processing PHI through the Service. Contact info@nemsol.org to request our BAA. We will execute BAAs with HIPAA-eligible customers, and we execute BAAs with our PHI-touching subprocessors before any PHI is processed in production.

For customers processing Protected Health Information (PHI), the Business Associate Agreement (BAA) governs the handling of PHI and controls over any conflicting term. The order of precedence for PHI is: (1) the BAA, (2) your subscription order, (3) the Terms of Service, (4) the Privacy Policy, and (5) any other posted policy.

7. Data retention

Active customer data is retained for the duration of your subscription. After termination or cancellation your data remains available for 30 days so you can export it (CSV download); after that window we delete it, unless a legal or contractual retention obligation requires us to keep it longer. Deletion is a documented process we run, not an automated purge job. Encrypted backups are overwritten on a rolling 30-day cycle, so a copy can persist in backup for up to 30 days after deletion. Audit logs are retained for at least 6 years to support HIPAA-aligned operations.

For Protected Health Information, the return-or-destroy obligation in the Business Associate Agreement controls, including its infeasibility carve-out for data held in backup.

8. Your rights

You have the right to:

  • Access the information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your information (subject to legal retention requirements).
  • Export your data in a portable format (CSV).
  • Opt out of non-essential communications.

To exercise these rights, email info@nemsol.org.

9. Children

The Service is not directed to children under 13. We do not knowingly collect data directly from children. Patient records you enter may include minors as patients of your clinic; the legal basis for processing is your responsibility as the controller of those records.

10. International transfers and remote access

Data is stored and processed in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US, where data protection laws may differ from those in your jurisdiction. Data is not stored outside the United States. Remote access to the platform by personnel of our overseas affiliate is described under "How we share data" above.

11. Security incidents

If we discover a security incident affecting customer data, we notify affected customers without unreasonable delay and no later than five (5) business days after discovery. The clock starts when we discover the incident, not when we finish confirming it. We provide the facts as they are known and keep updating until the matter is resolved.

For Protected Health Information the Business Associate Agreement sets this obligation and controls over any other document, including this page.

This is the same commitment published on our Security & Compliance page.

12. Changes to this policy

We may update this policy periodically. Material changes will be communicated by email and posted here with a new "Last updated" date.

13. Contact

Questions about privacy? Email info@nemsol.org. For BAAs and HIPAA inquiries, email info@nemsol.org.

Draft starting point. This document is a working draft prepared by the Nem team. It is not legal advice and must be reviewed by qualified counsel before production use. We will revise these documents periodically, current customers will be notified of material changes via email.