Soltrack runs the part of a clinic’s front desk that touches patients directly. That means we hold names, phone numbers, message threads and, where a clinic records calls, recordings of them. This page says what we do with that, who else can reach it, and what we do not claim.
01What we hold
- Contact details a patient gave the clinic: name, phone number, email, and the channel they arrived on.
- The conversation itself: the message thread, or the call transcript, and the recording where the clinic records calls.
- Appointment data we need to book against a real diary: provider, treatment, time, and whether a deposit was taken.
- Clinic configuration: your prices, providers, hours, and the rules you gave us about what has to go to a person.
We do not ask for, and the desk is not built to collect, clinical notes, diagnoses, medical history or payment card numbers. If a patient volunteers something clinical in a message, it stays in that thread and goes to a human.
02Where it lives
Data is held in managed cloud infrastructure, encrypted in transit with TLS and encrypted at rest by the provider. Nothing sits on a laptop, a personal drive or a shared inbox. Access to the production database is through the application, and the application enforces one clinic’s data being visible only to that clinic.
03Who can reach it
- Named accounts only. No shared logins, and no generic admin account that several people use.
- Two-factor authentication on every account that can reach production or billing.
- The smallest access that does the job. Somebody who needs to read a thread does not get the ability to export the database.
- Access is removed the day somebody stops working on your account, not at the end of the month.
04Call recording and consent
We only record where the clinic has told us to, and the desk discloses the recording at the start of the call. Consent and disclosure rules differ by country and by state, and the clinic decides what applies to them. Recordings and transcripts are kept for 90 days by default. If you want a shorter window, say so and we will set it shorter.
05The line the desk will not cross
The desk does not give clinical advice, does not tell a patient whether a treatment is right for them, and does not answer questions about pain, risk or aftercare. It says it cannot answer that, and it hands the conversation to a person. This is a product rule rather than a policy: it is configured before the desk answers anything, and it is the same rule on every clinic we run.
06Who else touches it
We use a small number of providers to run the service. Each one sees only what it needs to do its job.
- Voice and telephony: to place and answer calls, and to produce transcripts.
- Language models: to draft what the desk says. We use business tiers where the provider does not train on our data.
- Database and hosting: to store the record and serve the portal.
- Messaging and email delivery: to send what the desk writes.
- Payments: to bill the clinic. Card details go to the payment processor and never reach us.
The current list of named sub-processors is available on request, and we tell existing clients before we add one that touches patient data.
07HIPAA, BAAs and health data
Where a clinic is a HIPAA covered entity, we act as a business associate and we will sign a BAA before any data moves. Ask for it at the baseline call and you will have it before a single patient record reaches us, not after the build.
What that means in practice is on this page rather than in a badge. The safeguards a BAA obliges us to have are the ones described above: named accounts with no shared logins, two-factor on everything that reaches production, encryption in transit and at rest, one clinic’s data visible only to that clinic, a written deletion path, and a named list of sub-processors we tell you about before it changes.
What we are not is certified. There is no SOC 2 report and no ISO 27001 certificate to attach to your vendor form, and we would rather you heard that here than three calls in. If your practice cannot onboard a vendor without one, we are the wrong vendor this year and we will say so on the first call.
The desk is also narrower than HIPAA assumes a system might be. We do not ask for clinical notes, diagnoses, medical history or card numbers, and the desk is not built to collect them. If a patient volunteers something clinical it stays in that thread and goes to a human at your clinic.
Where GDPR or UK GDPR applies, we act as a processor on the clinic’s instructions, and our agreement carries the processing terms. We are not a medical device, we do not diagnose, and nothing the desk says is medical advice.
08How long we keep it
Conversations and appointment records stay for as long as the clinic is a client, because they are the clinic’s own record of its patients. Recordings and transcripts default to 90 days. When an engagement ends we export everything to the clinic and delete our copy within 30 days, or sooner if asked. A written deletion request for a single patient is actioned within 30 days.
09If something goes wrong
If we confirm a breach that affects a clinic’s data, we tell that clinic within 72 hours of confirming it, in writing, with what we know at the time rather than waiting until we know everything. We do not sit on it while we work out how it reads.
10Reporting a problem
If you have found something, email mikail@soltrack-ai.com with enough detail to reproduce it. You will get a human reply within one business day. We will not threaten you for reporting something in good faith, and we will credit you if you want to be credited.
11What we do not claim
Soltrack is a small company and we would rather be exact than impressive. We are not SOC 2 certified and we are not ISO 27001 certified. We do not have a third party audit to point at. What we have instead is a short list of things we actually do: least privilege, two-factor everywhere, encryption in transit and at rest, no data held outside managed infrastructure, a written deletion path, and a security review before any change that touches patient data goes live.
If your practice needs a certification we do not hold, tell us at the baseline call rather than after a build. We will say so plainly instead of finding a form of words.
12Contact
Security questions, deletion requests and BAA requests go to mikail@soltrack-ai.com. It is read by the person who built the system.