Privacy policy
Last updated: September 14, 2026
This is a translation, provided for convenience. The French version is the reference text and prevails in case of any discrepancy.
1. Who we are
Allo Clinique (the “Service”) is an artificial-intelligence voice receptionist for health clinics across Canada (all disciplines), operated by Lotfi Hichem Boutalbi (the “Provider”), based in Quebec, Canada.
For any question about this policy, or to exercise your rights, contact us at contact@allo-clinique.com.
1 bis. How we govern your information
One person answers for the protection of personal information here: the officer named in section 10. That is who you write to, and who decides.
- Our rules are written down. Security policy, access management, incident handling, retention and destruction: each exists as a dated document, reviewed at least once a year.
- We assess before we launch. Any feature that touches information about people goes through a privacy impact assessment before it goes live, and that assessment is reviewed whenever the feature changes.
- Access is limited and traced. Each person at your clinic has a profile, and every time a patient record is opened it leaves a named trace that you can consult.
- We destroy what has expired. The periods in section 6 are applied by a daily automatic clean-up, not by hand.
- An incident follows a written procedure, with a register, a risk assessment and the notices required by law (section 6 ter).
- A complaint has a path, described in section 10.
2. Data we collect
To provide the Service, we process three categories of data:
- Client clinic data: clinic name, address, time zone, opening hours, average value of a visit, email and phone number of the person in charge, name, email and phone number of the person to notify in case of an incident, if the clinic designates one, access token to the practice-management software if an optional synchronisation is enabled.
- Data about patients who call (collected on behalf of the client clinic): phone number, first name, last name, reason for the call, text transcript of the call, appointments requested or changed. The client clinic is the controller of this data; we act as a processor.
- Technical data: IP address, browser type, error logs (through Sentry), phone-call metadata (duration, timestamp, status, cost).
3. Purposes of processing
- Running the voice agent and appointment booking (basis: performance of the contract).
- Sending SMS confirmations and reminders to patients (basis: performance of the contract with the clinic).
- Diagnosing a defect in the service, which may require reading an individual transcript — for no other purpose.
- Meeting our legal obligations (invoicing, accounting).
We never use patient transcripts to train third-party AI models. The content stays confidential.
4. Hosting and Law 25 compliance
The primary storage of your data (records, appointments, transcripts) is located in Canada, on Supabase infrastructure (AWS ca-central-1 region, “Canada (Central)”). During the call, some technical processors nonetheless handle data outside Canada, mostly in the United States:
- the voice passes through Twilio and Vapi for the duration of the call; there has been no audio recording of calls since August 3, 2026 (section 6);
- Deepgram transcribes the voice in memory, without writing it to persistent storage;
- Anthropic receives the text of the conversation to produce the agent's replies, and deletes it within 30 days;
- Vapi keeps the transcript only long enough to send it to us: we have it deleted there as soon as it is written on our side. Its documents do, however, describe daily backups kept for 30 days, which its agreement does not require it to purge: a copy may remain there for that period.
Our main processors and the jurisdictions involved:
- Supabase — database (Canada)
- Vercel — application hosting (United States, data in transit)
- Twilio — phone and SMS gateway (United States)
- Vapi — AI voice engine (United States)
- Anthropic — Claude language model (United States)
- ElevenLabs — voice synthesis (the assistant’s voice) (United States)
- Microsoft Azure — fallback fr-CA voice synthesis (United States or European Union)
- Deepgram — real-time transcription (United States)
- Stripe — payments (United States)
- Sentry — error logging (United States)
- Hostinger — delivery of our emails (outside Canada: company established in Cyprus; server location not stated in its agreement)
- GitHub — code repository and encrypted backups (United States)
The last two were added to this list on September 3, 2026: they were missing. Hostinger delivers the alert emails we send to your clinic — as of that date those emails no longer contain your patients' phone number, only its last four digits and a link to your dashboard. GitHub stores our backups, which are encrypted before being uploaded: their contents are not readable to it.
Transfers to those jurisdictions outside Quebec rely on the data processing agreement of each provider, most often incorporated into its published terms. The exact form, provider by provider, is set out in our data processing agreement. These transfers are the subject of a privacy impact assessment (PIA).
5. Your rights (Law 25)
As a person whose data is processed, you have the right to:
- Access: obtain a copy of the data concerning you.
- Rectification: correct inaccurate data.
- Erasure: ask for your data to be deleted (right to be forgotten).
- Portability: receive your data in a structured, readable format.
- Objection: object to the processing of your data.
- De-indexing: have your data removed from search results.
To exercise these rights, write to contact@allo-clinique.com. We answer within 30 days.
How this works in practice. We first check that you are the person concerned — we call you back at the number already on file, or we go through your clinic. We never ask for identity documents by email. We then answer you in writing, saying what we did; if we refuse, we say why and on what legal basis, and we tell you what recourse you have.
- Copy of your file and portability: we give you everything we hold about you — appointments, calls, text messages, missed calls — as a machine-readable file that you can hand to someone else.
- De-indexing: if information about you is circulated in a way that causes you serious injury, we stop the circulation or have the link removed. We first check whether a legal or accounting obligation requires us to keep that information — if so we tell you, and we still stop any circulation that is not mandatory.
- Access restriction: you can ask that certain information no longer be visible to part of your clinic's staff, for a period you set. We apply the restriction inside the product, and every attempt to consult it stays traced.
- After a death: the spouse, a close relative or the liquidator of the estate may request the information needed to settle the estate, or information that helps with grieving, by providing the death certificate and proof of the relationship. We then disclose only what serves that request — never the whole file — and only if the deceased had not objected during their lifetime.
6. Retention
- Clinic account data: term of the contract + 7 years (accounting obligations).
- Call transcripts: 12 months, then automatic daily deletion. The content of text messages follows the same period.
- Messages from the public-site chat, demo call-back requests and pilot program applications: 90 days, then automatic deletion. Where an application led to an account being opened, we keep only the record of the link to the program (status and date), with no contact details.
- Patient data (name, phone, appointments): kept for the term of the contract with the client clinic, which is the controller. No automatic deletion by age is applied to it today. It is erased at the request of the clinic or of the person concerned (section 5), a request we handle within 30 days. The end of the contract does not on its own trigger that erasure: the data stays in place until such a request, which the clinic can send us when it leaves.
- Audio recordings: there is no more recording. Since August 3, 2026, no recording of your call is created, neither by us nor by the voice platform that handles the call (section 4): of your conversation, only the text transcript exists, kept for the periods above. Calls before that date may still have a recording at that provider, under its own retention policy, which we do not control — write to us to ask for its deletion and we will claim it from them.
- Technical logs (Sentry): 90 days.
6 bis. Calls handled by artificial intelligence
Phone calls to clinics using the Service are answered by an automated voice agent (artificial intelligence) and are transcribed to text, kept for the periods in section 6. The agent identifies itself as a virtual assistant. If you would rather speak to a human, simply say so during the call: the agent will transfer you to the front desk or take a message so that someone calls you back.
An appointment booked during that call is set by an automated system. It is not final: someone at the clinic can review it, correct it or refuse it, and you can ask for a person to re-examine what the agent decided. To find out what led it to offer one time rather than another, ask your clinic: it has the transcript of the call and the detail of the steps the agent followed.
6 ter. Confidentiality incidents
In the event of a confidentiality incident involving personal information, we undertake to: keep a register of incidents; assess the risk of serious injury; notify the Commission d’accès à l’information (CAI) and the persons concerned where the law requires it; and assist client clinics (controllers under Law 25) with their own notification obligations.
When the incident affects the information of a client clinic, we also undertake to that clinic to:
- notify it without undue delay, and no later than 72 hours after becoming aware of it, with what we know: nature of the incident, information affected, persons concerned if identifiable, measures taken. An incomplete first notice is followed by updates as soon as they are known;
- work with it to assess the risk of serious injury and, where the law requires it, to notify the CAI and the persons concerned;
- give it, and it alone, a written report (timeline, information affected, measures taken), the log extracts needed for its own declaration and the list of the persons affected;
- offer it a template notice to the persons concerned;
- give it a single point of contact: support@allo-clinique.com.
7. Cookies
Our site uses a small number of cookies. Here they all are:
- Supabase session cookies: to keep you signed in to the dashboard. Necessary for the Service to work.
- Stripe cookies: only if you start a payment. Necessary for the payment.
- allo_pending_checkout: set when you click “Get started” from the pricing page. It sets your order aside (plan, number of phone numbers, add-ons) while you sign in, so you do not have to enter everything again. Duration: 30 minutes.
- allo_last_seen: set while you are signed in to the dashboard. It contains only a timestamp — the moment of your last action — and is used to sign you out automatically after a period of inactivity set by your clinic. It says nothing about who you are and does not follow you to any other site. Necessary for the security of the Service.
- allo_ref: set only if you arrive through a referral link (address of the form allo-clinique.com/r/CODE). It contains nothing but the code of the clinic that recommended the Service, so that the referral can be credited if you sign up — no identifier about you. Duration: 30 days. This is the only one of our cookies that is not strictly necessary: if you refuse or delete it, the site works normally, only the referral credit is lost.
- _fbp and _fbc (Meta pixel): only if you clicked “Accept” in the banner. They measure our advertising campaigns on Facebook and Instagram: your visit and, where applicable, your click on our phone number are sent to Meta Platforms, which can match them to your account. This is an advertising cookie, it allows profiling and cross-site tracking, and it is set by a third party located outside Quebec. As long as you have not accepted, this pixel is not loaded: no request is sent to Meta and none of these cookies is set. If you refuse, the site works normally. You can change your mind by clearing the site data in your browser: the banner will appear again.
allo_pending_checkout, allo_ref and allo_last_seen are set by allo-clinique.com, are unreadable by scripts on the page (httpOnly flag) and are sent over an encrypted connection only; neither serves advertising and neither follows you across other sites. Our audience measurement (Vercel Web Analytics) is anonymous and cookie-free: page views and aggregated events, with no individual identifier. The Meta pixel is the only device on this page that belongs to advertising — and it depends on your consent.
8. Security
All data in transit is encrypted with TLS 1.2+. Data at rest is encrypted by default on the Supabase side. Access to patient data is restricted to the owning clinic account through PostgreSQL Row-Level Security. Access tokens to third-party software (optional synchronisations) are encrypted and reachable only by our backend service.
9. Changes
We will publish any significant change to this policy on this page with a new update date. For substantial changes, we will notify client clinics by email at least 30 days in advance.
10. Contact and complaints
Person in charge of the protection of personal information: Lotfi Hichem Boutalbi — contact@allo-clinique.com.
To complain to us. Write to the address above with “complaint” in the subject line. Tell us what happened, when, and what you expect from us; attach what you have (date of the call, screenshot, email received). We acknowledge receipt, we look into it, then we answer you in writing within 30 days, telling you what we concluded and what we are changing. Every complaint is entered in a register. If our answer does not satisfy you, or if we do not answer within that time, you can go to the Commission d’accès à l’information.
If you believe your rights are not being respected, you can file a complaint with the Commission d’accès à l’information du Québec: cai.gouv.qc.ca.