Legal
Asellera Privacy Controls Summary
At Asellera, we believe that trust is the foundation of innovation. We are committed to maintaining the highest standards of data privacy and security, ensuring that our customers, partners, and users remain in control of their information.
Updated June 16, 2026
Ontario, Canada
1. PURPOSE
This document summarizes how privacy controls are applied across the Asellera data flow:
Patient → Communication Layer → AI Processing Layer → Workflow Engine → Data Storage → Clinic Systems → Human Review
At each stage, Asellera enforces technical, administrative, and procedural controls to protect personal information and personal health information (PHI).
2. Stage-by-Stage Privacy Controls
2.1 Patient → Communication Layer
Components:
Voice calls (Retell AI or equivalent)
SMS messaging providers
Web intake forms
Privacy Controls:
Consent prompts for voice/SMS interactions
Minimum necessary data collection (only what is needed for task)
TLS encryption for all inbound/outbound communication
No unnecessary persistent storage at edge systems
Phone/SMS masking where applicable
Protected Data:
Phone numbers
Message content
Voice recordings (if enabled)
2.2 Communication Layer → AI Processing Layer
Components:
Retell AI transcription systems
SMS message ingestion
API gateways
Privacy Controls:
Secure API authentication (API keys / OAuth)
Data transmitted over encrypted channels (TLS 1.2+)
Short-lived processing of raw audio/text where possible
No retention of raw audio beyond configured retention rules
Access logging of all API calls
Key Principle:
Only necessary conversation data is forwarded to AI systems.
2.3 AI Processing Layer
Components:
OpenAI or equivalent LLM systems
Privacy Controls:
Data minimization before prompt construction
No training of public models on PHI without explicit agreement
Prompt and response logging for auditability
Guardrails to prevent sensitive data overexposure in outputs
AI restricted to assistive functions only (no clinical decision-making)
Protected Data:
Transcripts
Intake data
Draft SOAP notes
Patient context
2.4 AI Processing → Workflow Engine
Components:
Asellera backend services
n8n automation workflows
Privacy Controls:
Structured data transformation (removal of unnecessary raw text where possible)
Role-based workflow execution
Secrets management for integrations
Limited access to full conversation history
Logging of workflow triggers (not full PHI where avoidable)
2.5 Workflow Engine → Data Storage Layer
Components:
Supabase database
Encrypted object storage (if used)
Audit log systems
Privacy Controls:
Row-Level Security (RLS) enforcement
Role-based access control (RBAC)
Field-level data access restrictions (where applicable)
Encryption at rest (AES-256 or equivalent)
Structured separation of:
identity data
clinical data
system logs
Retention policies enforced at database level
2.6 Data Storage → Clinic Systems
Components:
PMS systems
EHR integrations
Clinic dashboards
Google Calendar
Privacy Controls:
API authentication for all outbound data sync
Data minimization before export (only required fields sent)
Secure transmission (TLS encryption)
Access scoped per clinic tenant (multi-tenancy isolation)
No cross-tenant data leakage possible by design
2.7 Clinic Systems → Human Review Layer
Components:
Healthcare providers
Clinic staff
Admin users
Privacy Controls:
Role-based access controls inside clinic accounts
Audit logs of all data views and edits
Separation of draft vs finalized clinical outputs
Human approval required for all AI-generated clinical documentation
Access restricted to assigned clinic only (tenant isolation)
3. Cross-Cutting Privacy Controls (All Stages)
3.1 Encryption
TLS 1.2+ for all data in transit
AES-256 (or equivalent) for data at rest
Encrypted backups
3.2 Access Control
Role-Based Access Control (RBAC)
Multi-Factor Authentication (MFA) for sensitive systems
Principle of least privilege enforced
Unique user identities (no shared accounts)
3.3 Data Minimization
Only necessary patient data is collected
AI prompts are constructed with minimal required context
Non-essential identifiers are excluded where possible
3.4 Audit Logging
Logged events include:
Data access events
Authentication attempts
API calls involving PHI
Workflow executions
AI generation events
Logs are used for:
SOC 2 audits
Incident response
Compliance monitoring
3.5 Tenant Isolation
Each clinic operates in a fully isolated environment:
No cross-clinic data access
Separate logical partitions in database
Scoped API keys per tenant
Isolated workflow execution contexts
3.6 AI Privacy Controls
AI cannot independently store or retain memory beyond system design
No autonomous clinical decisions
Outputs are treated as draft suggestions only
Sensitive outputs are logged securely, not exposed broadly
4.Data Retention Enforcement
Privacy controls enforce retention rules from:
Data Retention Policy
Clinic-specific configurations
Legal/regulatory requirements
Automated deletion and archival mechanisms ensure compliance.
5. Vendor Privacy Controls
All vendors processing PHI must:
Sign data processing agreements (DPAs)
Enforce encryption in transit and at rest
Restrict use of data to service delivery only
Support deletion requests where applicable
Key vendors include:
OpenAI
Amazon Web Services
Retell AI (voice layer)
Supabase (database layer)
Messaging and scheduling providers
6. Incident Privacy Safeguards
In the event of a security incident:
Affected data is immediately isolated
Access is revoked or restricted
Logs are preserved for forensic review
Breach impact assessment is performed
Regulatory obligations are evaluated
7. Summary of Privacy Model
Asellera privacy is enforced through:
Technical controls (encryption, RBAC, tenant isolation)
Administrative controls (policies, audits, approvals)
Operational controls (logging, monitoring, incident response)
At every stage of the system:
Data is minimized, protected, isolated, and auditable.
Approval
Approved By: Shane Senha, CEO
Company: Asellera
Version: 1.0
Date: June 16th 2026
