Skip to content
Legal

Privacy Policy

What SideClick itself collects about customers and website visitors — and why patient data is not in scope.

SideClick Privacy Policy

This policy is written to match what the systems actually do and is kept consistent with the in-app Privacy & Data Protection Notice.

1. Scope — two very different kinds of data

Patient and clinical data is not covered by this policy, because we designed the product so we don't have it. Clinical records live in an encrypted database on the practice's own machines; where our optional sync, portal or cloud services store practice data at all, they store only end-to-end-encrypted content we cannot read. For that data, the practice is the party responsible under the privacy law that applies to it, and we act (if at all) as its zero-knowledge processor, operator or business associate under the instruments linked from the Terms of Service §12. Patients should read the plain-language patient portal privacy notice and their own practice's privacy notice.

This policy covers what SideClick itself is responsible for: information about our customers, trial requesters, website visitors, and correspondents.

2. Who we are

SideClick (Pty) Ltd, a South African company. Registration number 2026/655265/07. Registered office: 175 Neptune Way, Olympus, Pretoria, 0081. Data-protection contact: privacy@sideclick.io. Information Officer (POPIA): Franco De Beer, franco@sideclick.io.

3. What we collect, and why

What Source Why (lawful basis)
Name, email, edition and seat count, subscription period, payment-processor customer and subscription identifiers Paddle (merchant of record) purchase notifications Issue and manage your licence (performance of contract)
Your signed licence key (which embeds your name and email) Generated by us Licence issuance, re-delivery, and revocation (contract)
Trial request: name and email; retained long-term only as a one-way hash of the email You, at trial request Provide the trial; enforce the one-trial-per-person rule (contract; legitimate interest in preventing abuse)
Activation record: licence id + a non-reversible device fingerprint hash (a hash of computer name and install path — we cannot recover either) The app, once per key install Enforce the per-key device cap (contract; legitimate interest)
Support, security-report and feedback correspondence You Responding to you (legitimate interest; contract)
Signed data-processing records (signer name, email, document text) for Cloud customers Your authorised signatory Legal obligation; contract

What we never receive: card numbers, billing addresses, and tax details are collected and held by Paddle as merchant of record under its own privacy policy; Paddle is an independent controller for payment processing. We also never receive patient data, clinical content, or usage analytics (§5).

What we can never recover: the keys that encrypt practice data exist only on your devices and in your own recovery material (vault password, backup passphrases, cloud recovery code, your practice's own key shares). Because we never receive them, we cannot read your data — and we also cannot restore it if every copy of that material is lost. There is no vendor-side reset or escrow (EULA §7.6).

Website: the marketing site is static. It sets no cookies, uses no analytics or tracking, and requires no account (see the Cookie Notice). Our hosting infrastructure keeps standard web-server access logs for 30 days.

4. Sync relay, portal, and cloud metadata (processor role)

If your practice uses the sync relay, patient portal, or Cloud edition, our servers necessarily observe service metadata: device and account identifiers, public keys, encrypted payloads with sizes and timestamps (including phone-captured photos and voice memos travelling as sealed media frames), push-notification subscriptions (browser push endpoints, or Apple device tokens for the iPhone companion), and connection records with hashed network addresses — but not the content, which is end-to-end encrypted. The precise inventory, and our obligations for it, are in the relay DPA Annex A and the Cloud edition's instruments. One nuance disclosed for completeness: the relay's copy of your licence entitlement includes the signed key, which embeds the licensee's name and email, and may embed relay connection settings (relay address, certificate fingerprint) and an organisation binding derived from the payment processor's customer identifier.

For the Cloud edition, our identity service additionally holds account data for your practice's users: emails stored only as keyed one-way hashes (the raw email transits our servers at sign-in but is never stored), password hashes, multi-factor authentication data (authenticator secrets stored encrypted under a service key we hold — unlike your content keys; backup codes stored only as keyed hashes; passkey public keys), enterprise single-sign-on federation records, and session records with hashed network addresses. One exception to address hashing, disclosed here: the clinical-plane audit trail records the raw source address of Cloud API calls, so that a practice can investigate access to its own tenancy. Your clinical records themselves remain client-side encrypted; your recovery code exists only with you, so we can reset your sign-in but never decrypt your data (EULA §7.6).

5. What the desktop and mobile apps send us: almost nothing

The apps are engineered for local-first operation and contain no telemetry, analytics, or crash reporting. The complete list of network calls the apps can make to anyone:

  1. One-time licence activation (§3) — only if a licensing-service address is configured; never during normal operation afterwards.
  2. Updates — on store platforms (Microsoft Store, Mac App Store, App Store), the platform store delivers updates under its own terms and may collect its own installation and update telemetry, which we neither receive nor control. Where a direct (non-store) channel is used, an update check is an ordinary fetch of a static release file from our distribution host; the request carries no account or practice information beyond what any web request reveals (network address, user agent).
  3. AI and speech model downloads — enabling on-device AI downloads the language model once from Hugging Face's content network; Hugging Face sees a normal download request (your network address, the model requested) under its own privacy policy. On macOS, dictation uses Apple's on-device speech framework, which downloads its speech model from Apple once, on first use, under Apple's terms. All AI inference and all speech recognition then run entirely on your device; recordings and clinical text never leave it. The iPhone companion ships no AI model download at all.
  4. Relay, portal and cloud traffic — only if your practice enables those editions (§4). When enabled, the phone companion also uploads sealed captures (photos, voice memos, pending changes) in the background while the phone is locked — the same encrypted relay traffic, with no readable content.
  5. Push notifications — if enabled, delivered via your browser's push service or the Apple Push Notification service. The payloads are engineered to be content-free (a fixed alert text and opaque identifiers, enforced by automated test); Apple sees the device's push token and delivery metadata, never your data.
  6. Cloud edition sign-in — Cloud accounts authenticate against our identity service (§4).
  7. Video-consultation links — if you store a link from a video service you chose, opening it sends your browser to that service; the app itself sends nothing to it.

Scanning a QR code during device enrolment processes camera frames locally on the device and stores no images.

6. Sharing

For the hosted editions, the parties that host or carry your encrypted practice data are listed in the sub-processor register: Amazon Web Services (hosting) and Apple (push-notification delivery to iPhones — device tokens and content-free payloads only).

Some recipients are not sub-processors: Paddle (payments — merchant of record and independent controller); Hugging Face and Apple (as download sources your own device contacts directly for the optional AI and speech models); and the platform app stores (distributors of the apps under their own developer terms, including any store telemetry). We also disclose to authorities where the law requires. We do not sell personal information and we do not advertise with it.

7. International transfers

We are based in South Africa; customer and licensing records are processed on Amazon Web Services infrastructure. The sync relay and the patient portal service are hosted in the United States (AWS us-east-1); Cloud-edition practice data stays in the region the practice selects. Hosted practice data is not moved across regions. Push notifications to iPhones traverse Apple's infrastructure in the United States (content-free payloads — §5). Where personal information leaves your jurisdiction we rely on the safeguards your region's law provides for: standard contractual clauses or an adequacy decision for the EU and the UK, and the equivalent grounds under other laws, as set out in the regional disclosures in §13.

8. Retention

  • Commercial and licensing records: for as long as tax and accounting law requires after the relationship ends.
  • Revocation records: kept while the key could still circulate.
  • Trial email hashes: kept indefinitely (one-way, non-reversible) to enforce the single-trial rule.
  • Support and security correspondence: 24 months after the last message.
  • Relay and cloud content: controlled by the practice; our deletion obligations are in the instruments (deleted on the practice's instruction, or 90 days after an account is closed).

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict the personal information we hold about you, to receive a copy of it, and to object to certain processing. Ask us at privacy@sideclick.io; we answer within 30 days. You may also complain to the privacy regulator for your country — the regional disclosures in §13 name them. We never make automated decisions with legal effect about you.

10. Security

Customer and licensing data are held in encrypted stores with strict access control; licence keys are cryptographically signed; device-activation and trial records are stored only as one-way hashes; hosted practice data is end-to-end encrypted so that our staff cannot read it even in principle. If a security incident affects personal information, we notify affected practices and regulators under our incident-response process within the statutory deadlines that apply to each of them.

11. Children

Our website and store are aimed at healthcare professionals, not children. Patients — including minors under the care of a practice — interact with their practice's portal under the practice's own notices (portal privacy notice).

12. Changes

We will post changes here and, for material changes, notify customers by email at least 30 days in advance. This policy must always match what the software actually does; where the in-app Privacy & Data Protection Notice is more specific, the more specific statement governs. The in-app notice is versioned and maintained in lock-step with this policy — a revision of either is carried into the other in the same change.

13. Regional disclosures

United States. For practices covered by HIPAA we act as a business associate for the hosted editions under the relay Business Associate Agreement or the Cloud edition's agreement. We do not sell personal information, we do not share it for advertising, and we use no tracking technologies on our website or in our apps.

European Union and United Kingdom. We are the controller of the information in §3 and a processor of hosted practice data under the relay Data Processing Agreement. You have the rights in Chapter III of the GDPR (and the UK GDPR): access, rectification, erasure, restriction, portability, and objection. Transfers out of the EU and the UK rely on standard contractual clauses or an adequacy decision. You may complain to your national supervisory authority, or in the UK to the Information Commissioner's Office. We will publish the details of an EU or UK representative here if and when one is appointed.

Australia. We handle personal information under the Australian Privacy Principles. You may complain to the Office of the Australian Information Commissioner if we do not resolve a complaint to your satisfaction.

South Africa. We are a responsible party under the Protection of Personal Information Act and, for hosted practice data, an operator under the POPIA operator schedule. You may exercise your rights under sections 23 to 25 of the Act through privacy@sideclick.io, and you may complain to the Information Regulator (South Africa) at enquiries@inforegulator.org.za or POPIAComplaints@inforegulator.org.za.


SideClick (Pty) Ltd · privacy@sideclick.io Version 1.1 · Published 2026-09-12