Privacy policy
Last updated October 1, 2026 · Applies to Clinic Answering Service by Radiatus
What this policy covers
This policy explains what Radiatus ("we"), based in Coimbatore, Tamil Nadu, India, collects when you use Clinic Answering Service (the "Service"), why we collect it, how long we keep it and who processes it for us. It applies to the public website and to the application used by US healthcare practices ("workspaces") and their staff. For protected health information (PHI), the Business Associate Agreement (BAA) you sign with us also applies and prevails if it conflicts with this policy.
Information we process
- Account data (practice staff): name, work email, phone, practice name, role and password hash (Argon2id).
- Patient and caller data (PHI), processed for the practice under the BAA: caller name, phone number and date of birth; appointment details and reason for visit; insurance payer and member ID (member IDs are field-encrypted with AES-256-GCM); 270/271 eligibility requests and responses; call recordings, transcripts and three-line summaries; intake-form answers; waitlist entries and SMS messages.
- Integration credentials: EHR client secrets you enter, encrypted with AES-256-GCM.
- Usage, device and audit data: IP address, browser, pages and actions, timestamps, the PHI access log and the change audit trail.
- Billing data: plan, invoices and usage (minutes, numbers, locations). Card details are handled by the payment provider and never stored by us.
- Website inquiries: name, phone, email, practice and message from the contact or demo form.
Why we use it
- PHI: only to answer calls, book and change appointments, run eligibility checks, fill cancellations, send the texts the practice configures and deliver data to the practice's systems. Never for advertising, never sold, never used to train AI models.
- Account, usage and audit data: to provide, secure and support the Service, keep the access logs HIPAA requires and send transactional notices.
- Billing data: to bill subscriptions and usage.
- Website inquiries: to answer you and, only with consent, send product updates. You can opt out at any time.
Retention, by category
- Call recordings, transcripts and summaries: kept while the workspace is active and deleted 30 days after cancellation, unless your order form sets a fixed period between 30 days and 7 years.
- Patient records, appointments, eligibility checks and intake answers: kept while the workspace is active; deleted 30 days after cancellation, after you have had the chance to export them.
- Patient deletion requests received through the practice: completed within 30 days and logged.
- PHI access log: six years, matching the BAA. Other security and audit logs: 12 months.
- Backups: encrypted nightly, retained 30 days, so deleted data leaves backups within a further 30 days.
- Billing records: as long as tax law requires. Website inquiries: 24 months.
Where data is hosted
This website and trial workspaces run on Amazon Web Services in Mumbai, India (ap-south-1). Trial workspaces are for sample data only and must not contain real patient information. Production PHI for US practices is hosted in an Amazon Web Services region in the United States, set up before the BAA is signed and patient calls are forwarded. Our team works from India and reaches production data only through the logged application, to resolve a support request from the practice.
Sub-processors
- Hosting: Amazon Web Services (US region for production PHI; ap-south-1 Mumbai for the website and trials). AWS signs a BAA.
- Voice and SMS: the AvanceZone gateway (our group company), under a BAA, which connects calls and texts through US telecom carriers.
- Speech-to-text and language model processing: used only under a signed BAA with terms that forbid training on your data. Provider names are in the sub-processor list sent with the BAA.
- Eligibility clearinghouse: none contracted yet; eligibility runs in sandbox mode with test data. A clearinghouse will be named and placed under a BAA before live checks start.
- Email delivery: a transactional email provider; emails carry no PHI.
- Payments: the card or bank payment gateway chosen at checkout; receives no PHI.
The current named list is available from info@radiatus.com. We tell workspace owners about a new sub-processor that touches PHI before it starts. We never sell personal data.
HIPAA and protected health information
For US healthcare practices, Clinic Answering Service acts as a business associate. We sign a BAA (current version 2026-10) with every practice, on every plan, before any PHI is processed; it can be signed in the app on the Compliance screen or on paper. To request a copy, use the contact page.
- Safeguards: TLS 1.2+ in transit; AES-256 encrypted storage at rest, with field-level AES-256-GCM for member IDs and EHR credentials; role-based access by role and location; a PHI access log of every view, export and AI read (user, time, IP, device), exportable as CSV; automatic session timeouts and least-privilege staff access.
- Breach notification: we report any breach of unsecured PHI, or any use or disclosure the BAA does not permit, to the practice within 10 business days of discovery (inside HIPAA's 60-day limit), with the facts the practice needs for its own notices to patients and HHS.
- Patient rights: requests for access, amendment or an accounting of disclosures should go to the practice; we provide what the practice needs within 15 days, as the BAA states.
- Termination: PHI is returned (export) or destroyed as described in Retention above; where that is infeasible, its protections continue.
Automated outputs
Eligibility read-backs and urgency routing are automated aids. They repeat what payers return and route calls to people; they never give medical advice, guarantee coverage or replace the judgement of the practice's staff.
Your rights
You may ask to access, correct, export or erase your personal data, or withdraw consent, by emailing info@radiatus.com. Patients should contact the practice first; we help the practice respond. Patients may also file a HIPAA complaint with the U.S. Department of Health and Human Services Office for Civil Rights. Residents of India also have rights under the Digital Personal Data Protection Act, 2023.
Cookies
We use a strictly necessary session cookie for logged-in users and, if enabled, privacy-friendly analytics with IP anonymisation. No advertising cookies.
Security
See the Security page for safeguards, support hours and incident response.
Changes and contact
We will post changes here and notify workspace owners of material changes by email. Questions: info@radiatus.com or +91-9585160363 (India), Monday to Friday, 9 am to 5 pm US Eastern Time. Radiatus, Coimbatore, Tamil Nadu, India.
Related: Privacy policy · Terms of service · Refund policy · Security and compliance · Clinic Answering Service pricing · Contact us