Legal information

Privacy notice

How personal data given on the website, in the chat and when getting in touch is handled.

This is an English translation of the Hungarian Adatkezelési tájékoztató. If the two versions differ, the Hungarian version prevails.

1. The controller

Tokár Ádám egyéni vállalkozó (5700 Gyula, Szőlős utca 4/1., Hungary, tax number: 92003747-1-24, email: hello@clinicai.hu), hereinafter: the Provider. For data protection questions, the Provider can be reached at this email address.

2. Getting in touch and requesting a demo

Data processed: name, the name of the practice, email address and/or phone number, the content of the message. Purpose: answering the request, arranging a demo, making an offer. Legal basis: the consent of the data subject (GDPR Article 6(1)(a)), and steps taken before entering into a contract (GDPR Article 6(1)(b)). Retention: 1 year from the last contact, or until consent is withdrawn.

3. The website chat and the voice call

The chat and the voice call that can be started from the browser are a digital assistant that gives information about the ClinicAI services. It gives no health advice. Please do not write health data in the chat.

Data processed: the text of the conversation, the transcript of the voice call, and anything you choose to give (name, practice name, contact details). Purpose: answering questions, recording an enquiry and passing it on to the Provider, checking the quality of the service. Legal basis: consent (GDPR Article 6(1)(a)). Retention: the conversation for 30 days, data recorded as an enquiry as set out in section 2.

To process the texts and the voice, the Provider uses processors (see section 6). For the voice call, the browser asks for microphone permission, and the microphone only switches on when you start the call.

4. Cookies and local storage

The website only uses storage that is strictly necessary for it to work: the chat stores a session identifier in the browser's session storage, which is deleted when the tab is closed, and the website remembers that the cookie notice was dismissed. The website uses no analytics, marketing or tracking cookies. The fonts are loaded from the website's own hosting, so no data is sent to an outside provider for them.

5. The data of the practices' patients

For the data of the patients of practices that use the ClinicAI service, the controller is the practice, the Provider is a processor, and acts under the written data processing agreement concluded with the practice (GDPR Article 28). Health data is a special category of data under Article 9 of the GDPR. The Provider applies encrypted data transfer and storage, role-based access and logging of access. Patients can exercise their rights primarily with the practice.

6. Processors

  • Hosting and server functions: Netlify, Inc. (512 2nd Street, Suite 200, San Francisco, CA 94107, USA)
  • Text processing in the chat: OpenAI Ireland Ltd. (1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, Ireland)
  • Voice call control: Vapi, Inc. (United States of America)
  • Speech generation: Eleven Labs Inc. (United States of America)
  • Speech to text: Soniox, Inc. (United States of America)
  • Sending email notifications: Resend (Plus Five Five, Inc., United States of America)
  • Domain and email: Rackhost Zrt. (6722 Szeged, Tisza Lajos körút 41., Hungary)

For processors outside the European Economic Area, data is transferred on the basis of the standard contractual clauses adopted by the European Commission (GDPR Article 46) or, where the processor is certified, under the EU-US Data Privacy Framework. The processors may use the data only on the Provider's instructions, to provide the service.

7. Your rights

You can request access to your personal data, its rectification, erasure or the restriction of its processing, you can object to the processing, and you can request data portability. You can withdraw your consent at any time; this does not affect the lawfulness of processing before the withdrawal. You can send your request to hello@clinicai.hu, and the Provider answers within 1 month at the latest.

You can lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, 1055 Budapest, Falk Miksa utca 9-11., naih.hu), or go to court.

8. Data security

The Provider transfers data over an encrypted connection, limits access to those who need it for their task, and logs access to the data. In the event of a personal data breach, the Provider acts in accordance with Articles 33 and 34 of the GDPR.

Effective: October 4, 2026.