Legal

Asellera Privacy Policy

At Asellera, we are committed to being transparent about how we collect, use, and protect your personal and health information. This policy outlines your rights and our commitment to maintaining the confidentiality and integrity of your data in accordance with Canadian privacy laws.

Updated June 16, 2026

Ontario, Canada


1. Overview

Asellera (“we,” “our,” or “us”) provides an AI-powered workflow automation platform for dental clinics and healthcare providers.

We process personal information and protected health information (“PHI”) on behalf of healthcare providers in accordance with applicable privacy laws and contractual obligations, including the Health Insurance Portability and Accountability Act (“HIPAA”), where applicable.

Asellera is designed to operate as a service provider to healthcare organizations and enters into Business Associate Agreements (“BAAs”) with covered entities where required.


  1. Scope of This Policy

This Privacy Policy applies to:

  • Dental clinics and healthcare organizations using Asellera

  • Authorized clinic staff and administrators

  • Patients whose information is processed through Asellera on behalf of a clinic

  • Website visitors and account users



3. Information We Collect

3.1 Information Provided by Clinics

We may collect:

  • Clinic identifiers and business contact information

  • Staff names, roles, and authentication credentials

  • Configuration and workflow settings

  • System usage data and audit logs

3.2 Protected Health Information (PHI)

When provided by a clinic, Asellera may process PHI, including:

  • Patient identifiers (name, phone number, email)

  • Appointment scheduling and treatment coordination data

  • Call transcripts and SMS communications

  • Intake form submissions

  • AI-generated administrative or clinical draft outputs

We do not collect PHI directly from patients except when acting on behalf of a healthcare provider.



4. How We Use Information


We use information strictly to:

  • Deliver automated communication and workflow services

  • Process voice, SMS, and intake interactions

  • Generate draft outputs for clinic review (e.g., summaries, notes, responses)

  • Route data into clinic systems (PMS, EHR, scheduling platforms)

  • Maintain system security, reliability, and audit logs

We do not:

  • Sell personal information or PHI

  • Use PHI for unrelated marketing purposes

  • Use PHI to train generalized machine learning models unless explicitly authorized by the healthcare provider in writing


5. Legal Basis for Processing


When handling PHI, Asellera processes data only:

  • As instructed by the covered entity (healthcare provider)

  • Under a signed Business Associate Agreement (BAA), where required

  • For permitted operational, administrative, and healthcare workflow purposes

  • Messaging and scheduling providers


6. AI and Automated Processing

Asellera uses artificial intelligence systems to support communication and workflow automation.

  • AI processes PHI only as necessary to perform requested services

  • Outputs are assistive and non-diagnostic in nature

  • AI does not replace clinical judgment or licensed healthcare providers

  • Final responsibility for all clinical decisions remains with the healthcare provider

  • PHI is not used to train generalized AI models unless explicitly authorized by the healthcare provider in writing


7. Data Sharing and Disclosure

We may share PHI only under the following conditions:

7.1 Service Providers (Subprocessors)

We engage third-party service providers to support infrastructure and functionality, including:

  • Cloud hosting providers (e.g., AWS)

  • AI processing providers (e.g., OpenAI or equivalent)

  • Communication providers (e.g., voice/SMS systems such as Retell AI)

  • Database and workflow providers (e.g., Supabase, automation tools)

All subprocessors are required to:

  • Enter into confidentiality and data protection agreements

  • Use PHI only to provide contracted services

  • Maintain appropriate technical and organizational safeguards

This list of subprocessors may be updated from time to time.

7.2 Healthcare Providers

All PHI is made available to the healthcare provider (clinic) that owns the patient relationship.

7.3 Legal or Safety Requirements

We may disclose information if required to:

  • Comply with legal obligations

  • Respond to lawful requests from public authorities

  • Protect the security, rights, or safety of users, patients, or systems



8. Data Security Safeguards

Asellera implements administrative, technical, and physical safeguards consistent with HIPAA Security Rule principles, including:

Technical Safeguards

  • Encryption in transit (TLS 1.2+)

  • Encryption at rest (AES-256 or equivalent)

  • Role-based access control (RBAC)

  • Multi-tenant data isolation

  • Secure API authentication

  • Audit logging of PHI access and system activity

Administrative Safeguards

  • Access restricted to authorized personnel

  • Principle of least privilege enforcement

  • Security training for personnel handling PHI

  • Incident response and breach procedures

Operational Safeguards

  • Continuous system monitoring

  • Activity logging and anomaly detection

  • Controlled production access environments

9. Data Retention and Deletion



We retain PHI only as long as necessary to:

  • Provide services to healthcare providers

  • Comply with legal and contractual obligations

  • Support audit, compliance, and security requirements

Clinics may request deletion, export, or correction of data, subject to legal and operational requirements.


10. Patient Rights

Depending on jurisdiction and clinic policies, individuals may have rights to:

  • Access their PHI

  • Request corrections to inaccurate information

  • Request restrictions on certain uses or disclosures

  • Request an accounting of disclosures

Requests should be directed to the relevant healthcare provider or to Asellera where applicable.


11. Business Associate Agreements (BAA)

Where required, Asellera enters into Business Associate Agreements (BAAs) with covered entities. These agreements define:

  • Permitted uses and disclosures of PHI

  • Security and safeguarding obligations

  • Breach notification procedures

  • Subprocessor requirements


12. International Data Transfers

PHI and personal data may be processed in jurisdictions outside the healthcare provider’s location, including Canada and the United States.

We ensure appropriate safeguards and contractual protections are in place to protect such data in accordance with applicable laws.


13. Cookies and Website Analytics


Our website may use cookies and analytics tools to improve performance and user experience.

These tools do not access PHI.

Users may disable cookies through their browser settings, though some website features may not function properly.



14. Breach Notification

In the event of a security incident involving PHI, Asellera will:

  • Contain and isolate affected systems

  • Assess scope and impact

  • Notify affected healthcare providers without unreasonable delay

  • Support investigation and remediation efforts

  • Comply with applicable breach notification laws and contractual obligation

15. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted with a revised effective date.

16. Contact Information

For privacy or PHI-related inquiries:

Email: contact@asellera.com
Company: Asellera



Approval

Approved By: Shane Senha, CEO
Company: Asellera
Version: 1.0
Date: June 16th 2026