Compliance
Built for regulated businesses. Owned by you.
How we handle patient privacy, business texting, email, advertising and your data, stated plainly.
Medical practices
HIPAA and minimum-necessary messaging.
- We sign a Business Associate Agreement with every medical practice.
- We use HIPAA-eligible tooling for anything that touches patient information.
- Messages carry the business name, a time, an action and an opt-out. Never treatment details.
“Hi Sarah, it's been a while since your last visit at Glow Aesthetics. Reply BOOK to see this week's openings. Reply STOP to opt out.”
“Hi Sarah, your Botox is wearing off. Time for your next 20 units.”
Business texting
Registered, consented, quiet at night.
- All business texting is A2P 10DLC registered, for every client.
- Consent is captured, and a consent record is kept for every contact.
- STOP and HELP are honored automatically.
- Marketing texts respect quiet hours.
CAN-SPAM, every time.
- Every commercial email carries a physical address.
- Every commercial email carries a working opt-out.
Advertising
Within platform policy.
- Campaigns follow Meta's and Google's health and beauty advertising policies.
- No before-and-after or body-image claims.
Data ownership
Everything stays in your name.
- Ad accounts, phone numbers, website and data are held in your name.
- Full export on request.
- When an engagement ends, we remove our access.
Human oversight
Rules and review.
- Nothing the assistant writes reaches a client without a defined rule or human review.
- Conversations it can't resolve are handed to your team with a summary.
- We review transcripts weekly.
This page describes our operating standards. It is not legal advice.