Legal

Privacy policy

This draft explains what data Dolce Health handles, why we handle it, and how clinics stay in control of their patients' records.

Draft, September 2026
Draft for legal review. This page is a working draft and is not yet in effect.

About this policy

This is a draft. It has not been reviewed by a lawyer, and it will change before it is published.

In this policy, Dolce Health, we and us mean [Company legal name], located at [address]. We make Dolce Health EMR, software for medspas and aesthetic practices. This policy explains how we handle personal information when clinics use our software and when people visit our website.

Our customers are clinics. Patients do not sign up with us directly. If you are a patient, your clinic decides how your information is used. Please contact your clinic with questions about your records, and read its own privacy notice.

Our role and the clinic's role

When a clinic uses Dolce Health EMR, the clinic is responsible for its patients' information. Under HIPAA, the clinic is usually a covered entity. Under other privacy laws, it is the controller of that information.

For patient information, Dolce Health intends to act as the clinic's business associate under HIPAA, and as its processor or service provider under other privacy laws. That means we handle patient information only to provide our services to the clinic, and only on the clinic's instructions.

If Dolce Health and a clinic sign a business associate agreement or a data processing agreement, that agreement controls over this policy for the information it covers.

For account, billing, website and usage information, Dolce Health decides how the information is used. This policy describes those uses.

Information we collect

We collect the kinds of information listed below. We do not store full card numbers. For cards on file, the software keeps only limited details, such as a card label and the last four digits.

  • Account information. Names, work email addresses, phone numbers, job titles, credential types and roles of the clinic staff who use our software, plus sign-in details and account settings.
  • Clinic information. Clinic names, locations, rooms, services, prices, provider details, branding, message templates, forms and settings, and billing details for the clinic's subscription.
  • Patient information we process for clinics. What a clinic enters or collects in the software, such as patient contact details, date of birth, medical history, allergies, intake and consent forms, chart notes, injection maps, photos, appointments, invoices, payment records, messages and marketing preferences.
  • Usage information. Records of how the software is used, such as sign-ins, pages viewed, actions taken, IP address, browser and device type, and error reports. E-signatures record the time, IP address and device.
  • Website and contact information. What you send us when you visit our website, contact us or ask for a demo, such as your name, email address, clinic name and message.

How we use information

We use information for the purposes listed below. We do not sell personal information. We do not use patient information to market our own services, and we do not use it for any purpose the clinic has not allowed.

  • Provide, maintain and support the software for clinics
  • Create and manage user accounts and confirm who is signing in
  • Process patient information on each clinic's instructions, such as sending a form, reminder or receipt the clinic asks us to send
  • Keep the software secure, record activity in the audit log, and prevent misuse
  • Bill clinics for their subscription
  • Send service notices, such as security alerts and product updates
  • Fix problems and improve the product, using usage information
  • Meet our legal obligations and enforce our terms

AI features

Dolce Health EMR includes AI features that draft text for clinic staff. Examples include drafting a SOAP note from what a provider documented, suggesting billing codes, summarizing a patient's history, drafting forms, suggesting revenue and retention ideas from the clinic's own data, and writing campaign or review request copy.

When an AI feature runs, we send the minimum text needed to produce the draft to our AI provider. For a chart note, that is the treatment details the provider documented. The AI provider returns a draft, and we show it to the user.

AI output is always a draft. A person on the clinic's team reviews, edits and approves it. For chart notes, the provider reviews and signs the note. AI features do not sign notes, send messages or change records on their own.

Clinics control how their staff use AI features and whether to accept each draft. [Confirm the AI provider's data use and retention terms, including that submitted data is not used to train its models, before publishing.]

Service providers we use

We use other companies, called subprocessors, to run the software. They may handle information only to provide their services to us. Before a subprocessor handles patient information, we intend to have written terms in place that require it to protect that information. We will share a current list of subprocessors with clinics on request.

  • Cloud hosting and database providers, which store and run the software
  • Email delivery providers, which send the emails a clinic or user asks us to send
  • Text message (SMS) providers, which send the texts a clinic asks us to send
  • Payment processors, which handle card payments and subscription billing
  • AI providers, which produce drafts when a user runs an AI feature

Other times we share information

We may share information when the law requires it, such as to answer a valid court order. We may also share it to protect the safety of people or the security of our software, or with a clinic's permission.

If we are involved in a merger, sale or similar deal, information may move to the new owner under this policy. We will tell clinics before that happens.

When a clinic exports its data or sends it to another service, the clinic controls where that data goes.

How we protect information

We build safeguards into the software, and clinics can adjust several of them. No system is perfectly secure, so we cannot promise that information will never be accessed without permission. If we learn of a breach that affects a clinic's patient information, we will tell the clinic as the law and our agreements require. Current safeguards include the controls below.

  • An audit log that records user actions, including viewing, changing and deleting records, and amendments
  • Roles and permissions, so each user sees only what their job needs, and individual logins, so actions are tied to the right person
  • Session timeout after inactivity, set to 30 minutes by default, and a lock screen with a PIN or password for shared workstations
  • An IP allowlist that clinics can use to limit sign-ins to approved networks
  • Sign and lock for chart notes, so signed notes cannot be edited, and amendments that require a reason
  • E-signatures that record the time, IP address and device
  • Separation of each clinic's data from every other clinic's data
  • Email verification at sign-up, and password reset links that expire and work only once

How long we keep information

Clinics control the patient records they keep in Dolce Health EMR. Each clinic decides what to keep and for how long, based on the medical record laws that apply to it. We keep patient information while the clinic's account is active, or until the clinic deletes it.

The audit log is kept for 7 years by default, to support record keeping and investigations.

If a clinic closes its account, it has [number] days to export its data. After that, we delete or de-identify the clinic's data, unless the law requires us to keep it longer. Audit log records may be kept for their retention period. Copies in backups are removed on our regular backup schedule. [Confirm the backup retention period before publishing.]

We keep account and billing information while the account is active, and afterward for as long as we need it for legal, tax and accounting reasons.

Your rights and choices

If you use Dolce Health EMR at a clinic, you can ask us to access, correct, export or delete your account information. Some requests may need your clinic's approval, because your account belongs to the clinic. Depending on where you live, state or other privacy laws may give you more rights, such as the right to know what we collect.

If you are a patient, please contact your clinic. The clinic controls your records and will respond to your request. If you contact us instead, we will pass your request to your clinic and help it respond.

You can stop marketing emails from us at any time with the unsubscribe link in each email. We will still send service notices about your account.

To make a request, email privacy@dolcehealthemr.com. We may need to confirm your identity first. We will not treat you differently for using your privacy rights.

Cookies

We use cookies and similar tools that are needed to keep users signed in and to run the software and website. [List any analytics or advertising cookies used on the website, and how to opt out of them, before publishing.]

Children's information

Our website and software are meant for clinic staff and are not directed to children. We do not knowingly collect personal information directly from children.

Clinics may enter information about patients who are minors. That information is patient information we process on the clinic's behalf. The clinic is responsible for any parental consent the law requires.

Where we store information

We store and process information in [hosting region]. If information moves across borders, we protect it as this policy describes and as the law requires.

Changes to this policy

We may update this policy as our software and the law change. We will post the new version on this page with its date. If a change is significant, we will tell clinic administrators by email or in the app before it takes effect.

Contact us

For questions about this policy or to make a privacy request, email privacy@dolcehealthemr.com or write to [Company legal name], [address].