Privacy Policy
Last updated: August 10, 2026
1. Overview
VitalDesk, a product of Creative World Prime LLC, a Florida limited liability company with its principal place of business in Tampa, Florida (“VitalDesk,” “we,” “us,” or “our”), provides AI receptionist, appointment request, callback, and patient communication tools for healthcare clinics (“Clinics”).
This Privacy Policy explains how information is collected, used, protected, retained, and shared when Clinics, clinic staff, patients, or website visitors use VitalDesk (the “Service”).
This Privacy Policy should be read together with our Terms & Conditions and, where applicable, our Business Associate Agreement (“BAA”), which governs the handling of protected health information as described below.
2. Information We Collect
Clinic Account Information. Clinic name, staff names, email addresses, phone numbers, login credentials, billing information, subscription information, and configuration data such as clinic hours, providers, services, insurance information, scheduling rules, appointment policies, and escalation instructions.
Patient-Provided Information. Patient name, phone number, contact details, and other information provided by or on behalf of a patient when making an appointment request, reschedule request, cancellation request, callback request, or similar communication through the Service.
Appointment and Communication Content. The substance of appointment requests, reschedule requests, cancellation requests, callback requests, call transcriptions, SMS message content, AI receptionist conversations, and related patient communications processed through the Service.
Communication Metadata. Call duration, timestamps, call routing information, phone numbers, SMS delivery status, message status, and similar communication metadata.
Technical and Usage Logs. IP address, device and browser information, access logs, authentication events, MFA events, diagnostic information, error logs, and usage information needed to operate, secure, monitor, troubleshoot, and improve the Service.
Session and Local Storage Data. Authentication tokens, session state, device/browser identifiers, and local storage values necessary to keep users signed in, enforce security controls, maintain dashboard functionality, and operate the Service.
PHI/ePHI. Where a Clinic’s use of the Service involves protected health information or electronic protected health information (“PHI”/“ePHI”), that information is handled as described in this Privacy Policy and the applicable BAA.
We collect this information directly from Clinics and clinic staff, directly from patients when they interact with the Service on a Clinic’s behalf, and automatically through use of the Service.
3. How We Use Information
We use the information described above to:
- Provide, operate, maintain, and support the AI receptionist and related Services;
- Process appointment requests, reschedule requests, cancellation requests, callback requests, and patient communications;
- Notify Clinic staff of patient requests and route communications as configured by the Clinic;
- Send appointment-related SMS, email, call, and dashboard notifications on a Clinic’s behalf;
- Authenticate users and maintain account and dashboard security, including MFA enforcement;
- Maintain session security, access controls, and account status;
- Monitor, troubleshoot, secure, and improve the performance, reliability, and functionality of the Service;
- Detect, investigate, and prevent fraud, abuse, unauthorized access, misuse, or security incidents;
- Provide billing, subscription, customer support, and administrative services;
- Comply with applicable legal, regulatory, contractual, security, and BAA obligations.
VitalDesk does not use PHI/ePHI to train public AI models or cross-Clinic AI models. PHI/ePHI is processed only as needed to provide, secure, support, and maintain the Service, or as otherwise permitted by the applicable BAA.
4. PHI/ePHI Handling and the Business Associate Agreement
Where a Clinic uses VitalDesk in connection with PHI/ePHI, that use is governed by a signed Business Associate Agreement (“BAA”) between the Clinic and VitalDesk.
The BAA is the controlling document for PHI/ePHI handling. If there is any conflict between this Privacy Policy and the BAA regarding PHI/ePHI, the BAA controls.
VitalDesk, as a business associate, is responsible for:
- Implementing administrative, technical, and physical safeguards for PHI/ePHI within VitalDesk-controlled systems;
- Using and disclosing PHI/ePHI only as permitted by the BAA and as reasonably necessary to provide, secure, support, and maintain the Service;
- Applying appropriate access controls, security controls, and vendor safeguards;
- Requiring vendors that process PHI/ePHI on VitalDesk’s behalf to be subject to appropriate contractual safeguards, including business associate subcontractor agreements where required;
- Providing security incident or breach notification in accordance with the BAA and applicable law.
The Clinic, as a covered entity or business associate of a covered entity, is responsible for:
- Determining the lawful basis for submitting PHI/ePHI to VitalDesk;
- Obtaining, documenting, and maintaining any required patient consent or authorization;
- Configuring the Service appropriately for the Clinic’s own compliance obligations;
- Managing its own workforce access, staff permissions, user accounts, MFA use, devices, and internal procedures;
- Reviewing and verifying AI-generated communications and appointment-related outputs before relying on them;
- Managing patient rights requests directed to the Clinic, such as access, amendment, deletion, restriction, or copy requests;
- Determining what categories of information are appropriate to submit through the Service based on the Clinic’s own regulatory obligations.
VitalDesk does not act as a covered entity with respect to Clinic patients and does not independently determine the purposes for which PHI/ePHI is used beyond providing the Service as directed by the Clinic and permitted by the BAA.
5. AI Processing and Human Review
VitalDesk uses AI systems to process patient communications, generate responses, route requests, and assist with scheduling workflows as configured by the Clinic.
AI-generated outputs may be incomplete, inaccurate, delayed, misunderstood, or affected by incorrect Clinic configuration. Clinics are responsible for reviewing and verifying patient requests, appointment information, call summaries, transcripts, SMS communications, and AI-generated outputs before relying on them for patient care, scheduling, or operational decisions.
VitalDesk does not provide medical advice, diagnosis, treatment recommendations, clinical triage, emergency response, or clinical decision-making.
6. No Sale of Patient Data
VitalDesk does not sell patient personal information or PHI/ePHI.
We do not sell, rent, or trade patient data, SMS opt-in data, SMS consent records, or PHI/ePHI to third parties for marketing, advertising, or any other independent third-party purpose.
Information is shared only as described in this Privacy Policy, the applicable BAA, our Terms & Conditions, or as required by law.
7. Subprocessors and Service Providers
VitalDesk uses third-party service providers and subprocessors to operate, secure, host, support, and improve the Service. These providers may support infrastructure, database hosting, private file storage, AI processing, transcription, telephony, SMS messaging, payment processing, transactional email, monitoring, security, and related operational services.
VitalDesk requires vendors that process PHI/ePHI on VitalDesk’s behalf to be subject to appropriate contractual safeguards, including business associate subcontractor agreements where required.
VitalDesk does not intentionally route PHI/ePHI through vendors designated below as not intended to process PHI/ePHI.
Core infrastructure and service providers that may process PHI/ePHI
| Provider | Function |
|---|---|
| Railway | Backend/API hosting |
| Amazon Web Services / S3 | Private file storage, compliance documents, signed BAA documents, and application storage |
| AWS RDS / PostgreSQL | Production database infrastructure |
| OpenAI | AI receptionist conversational processing |
| Deepgram | Voice and call transcription processing |
| Twilio | Phone, SMS, voice, and messaging infrastructure |
Service providers not intended to process PHI/ePHI
| Provider | Function |
|---|---|
| Vercel | Frontend/web hosting |
| Stripe | Billing and payment processing |
| Resend | Transactional email only, such as team invitations, account notices, and administrative communications. VitalDesk does not intentionally send PHI/ePHI through Resend. |
VitalDesk may update its vendors and subprocessors from time to time as needed to operate, secure, support, and improve the Service. Clinics with an executed BAA may request the current subprocessor list and advance notice of material subprocessor changes as provided in the BAA.
8. How We Share Information
With the Clinic. Patient request data, appointment-related data, communication data, call summaries, transcripts, SMS records, and related information collected through the Service are made available to the relevant Clinic through the dashboard and configured workflows.
For Legal Reasons. We may disclose information where required to comply with a subpoena, court order, legal process, regulatory request, or applicable law, or where necessary to protect the rights, property, security, or safety of VitalDesk, a Clinic, patients, users, or the public.
In Connection With a Business Transaction. Information may be disclosed or transferred in connection with a merger, acquisition, financing, corporate reorganization, sale of assets, or similar business transaction, subject to continued protection of PHI/ePHI consistent with the BAA and applicable law.
With Consent. We may share information where the Clinic or patient has separately and explicitly consented to a specific disclosure not otherwise described in this Privacy Policy.
We do not share information with third parties for their own independent marketing or advertising purposes.
9. Security Safeguards
VitalDesk maintains administrative, technical, and physical safeguards designed to protect information processed through the Service.
- Access controls: role-based access, user account controls, unique user IDs, MFA required for clinic dashboard access, and JWT-based authentication for application sessions;
- Session protection: automatic session timeout and authentication controls;
- Encryption: encryption of data in transit, and encryption at rest for PHI/ePHI and backup data where supported and configured in VitalDesk-controlled storage systems;
- Infrastructure security: hosting on infrastructure providers that maintain their own security controls, with production data stored in access-controlled database infrastructure;
- Monitoring and logging: logging of authentication events, access events, security events, administrative actions, and production-system activity to support monitoring and incident investigation;
- Vendor management: contractual safeguards with vendors that support the Service, including BAAs or business associate subcontractor agreements where required;
- Personnel controls: limiting internal access to PHI/ePHI to personnel with a legitimate operational need, consistent with VitalDesk’s obligations under the BAA;
- Private file storage: private storage of signed BAA documents and other compliance files, with temporary signed links for authorized viewing or downloading.
No method of transmission or storage is completely secure, and VitalDesk cannot guarantee absolute security.
Clinics play a critical role in securing their own accounts, workforce members, devices, and access practices, as described in our Terms & Conditions.
10. Data Breach Notification
In the event of a security incident affecting PHI/ePHI, VitalDesk will provide notification to the affected Clinic in accordance with the timelines and procedures specified in the BAA and applicable law, including the HIPAA Breach Notification Rule where applicable.
Notification of a security incident is not an admission of fault or liability.
Clinics remain responsible for any further notification obligations they may have to patients, regulators, workforce members, payers, or other parties as a covered entity or healthcare provider.
Clinics are responsible for promptly reporting suspected unauthorized access, credential compromise, workforce misuse, lost or stolen devices, improper access, or other Clinic-side security concerns involving the Service.
11. Data Retention, Export, and Deletion
While a Clinic’s agreement is active, Clinic Data is retained for as long as necessary to provide, secure, support, maintain, and improve the Service, unless a shorter retention period is required by the signed BAA, applicable law, or written agreement.
Upon termination or expiration of the Clinic’s agreement, VitalDesk will make commercially reasonable efforts to provide the Clinic with an export or return of Clinic Data upon written request.
Unless a longer retention period is required by the BAA, applicable law, legal hold, security investigation, unresolved billing dispute, backup lifecycle, or written instruction from the Clinic, VitalDesk may delete or de-identify PHI/ePHI and patient communication records from active systems within ninety (90) days after termination.
Backup copies may persist for a limited period in encrypted backups until overwritten or deleted according to VitalDesk’s backup lifecycle, provided they remain protected and are not used for any purpose other than backup, security, disaster recovery, legal compliance, or restoration testing.
VitalDesk may retain compliance documentation, BAAs, security records, access-control records, audit evidence, billing records, legal records, and account records for at least six (6) years or longer where required by law, contract, dispute, audit, tax, security, or legitimate business need.
Patients who wish to access, amend, delete, restrict, or obtain a copy of their health information should contact the Clinic directly. VitalDesk acts as a service provider/business associate to the Clinic and will support the Clinic’s response to patient rights requests as required by the applicable BAA and law.
12. SMS/Text Messaging Privacy
If a patient provides a mobile number and consents to receive text messages from a Clinic, VitalDesk may send appointment-related and customer care SMS messages on behalf of that Clinic.
Messages may include appointment request confirmations, appointment approval or decline updates, reschedule updates, cancellation updates, callback notifications, appointment reminders, patient support follow-ups, and similar healthcare communication messages.
Message frequency varies. Message and data rates may apply. Reply STOP to opt out at any time, or HELP for assistance.
No mobile opt-in information or SMS consent information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging opt-in data and consent will not be sold, rented, or shared with third parties for marketing purposes.
Mobile information is used only to deliver the appointment-related and customer care messages a patient has consented to receive, to maintain messaging records, to process opt-outs, and to comply with applicable telecommunications laws and carrier requirements.
Opt-out requests are processed promptly through our SMS infrastructure provider. Clinics remain responsible for honoring patient communication preferences across any channels outside of VitalDesk-facilitated messaging.
13. Healthcare Information
VitalDesk is designed for healthcare communication workflows.
Clinics are responsible for configuring and using VitalDesk in accordance with applicable privacy, consent, healthcare, telecommunications, and patient communication requirements.
Clinics are responsible for ensuring that only information appropriate for processing through the Service, given the Clinic’s own regulatory obligations, is submitted to VitalDesk.
VitalDesk does not provide medical advice, diagnosis, treatment, clinical triage, emergency response, or clinical decision-making.
14. Children’s Information
The Service is intended for use by healthcare clinics and their administrative and clinical staff, not directly by children.
Where a Clinic submits appointment or communication information on behalf of a minor patient, the Clinic is responsible for ensuring that submission complies with applicable parental consent, guardian consent, privacy, and healthcare requirements.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Material changes will be reflected in an updated “Last updated” date and, where appropriate, communicated to Clinics via their account email or dashboard.
Continued use of the Service after changes take effect constitutes acceptance of the revised Privacy Policy.
16. Contact
For privacy questions, data export requests, or privacy-related inquiries, contact us at hello@creativeworldprime.com.