Legal

Privacy Policy

Last updated: 24 May 2026  ·  Effective: 24 May 2026

1. Introduction

ClinicAI ("we", "our", "us") operates a software-as-a-service clinic management platform designed for aesthetic clinics in Thailand. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in accordance with Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and other applicable laws.

This policy applies to all users of the ClinicAI platform, including clinic owners, administrators, doctors, and clinic patients whose data is processed through the platform.

2. Data We Collect

We collect the following categories of personal data:

3. Legal Basis for Processing

Under the PDPA, we process personal data on the following legal bases:

Sensitive data note: Medical records, health conditions, and treatment photos are considered sensitive personal data under the PDPA. We process this data only on the basis of explicit consent or as otherwise permitted by law for healthcare purposes.

4. How We Use Your Data

5. Data Sharing and Disclosure

We do not sell personal data. We share data only in the following circumstances:

Each clinic's data is strictly isolated from all other clinics on the platform. No clinic can access another clinic's data.

6. Data Retention

We retain personal data for as long as necessary to provide the service and meet legal obligations:

7. Security Measures

We implement industry-standard safeguards to protect personal data:

8. Your Rights Under the PDPA

If you are a data subject whose personal data is processed through our platform, you have the following rights under the PDPA:

To exercise these rights, please contact the clinic that holds your records directly, or contact us at the address below if your request relates to data we control as the platform provider.

9. Cookies and Local Storage

The ClinicAI admin panel uses localStorage in your browser to store your session token, language preference, and UI settings. No third-party advertising cookies are placed on any ClinicAI page. The landing page does not set cookies.

10. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify clinic administrators by email. Continued use of the platform after changes constitutes acceptance of the updated policy.

Contact & Data Controller

ClinicAI — operated by Damian Klepacki

[email protected]

For data subject requests, please include your full name, the name of the clinic you attended, and a description of your request. We aim to respond within 30 days.