Legal
Asellera Privacy Policy
At Asellera, we are committed to being transparent about how we collect, use, and protect your personal and health information. This policy outlines your rights and our commitment to maintaining the confidentiality and integrity of your data in accordance with Canadian privacy laws.
Updated June 16, 2026
Ontario, Canada
1. Overview
Asellera (“we,” “our,” or “us”) provides an AI-powered workflow automation platform for dental clinics and healthcare providers.
We process personal information and protected health information (“PHI”) on behalf of healthcare providers in accordance with applicable privacy laws and contractual obligations, including the Health Insurance Portability and Accountability Act (“HIPAA”), where applicable.
Asellera is designed to operate as a service provider to healthcare organizations and enters into Business Associate Agreements (“BAAs”) with covered entities where required.
Scope of This Policy
This Privacy Policy applies to:
Dental clinics and healthcare organizations using Asellera
Authorized clinic staff and administrators
Patients whose information is processed through Asellera on behalf of a clinic
Website visitors and account users
3. Information We Collect
3.1 Information Provided by Clinics
We may collect:
Clinic identifiers and business contact information
Staff names, roles, and authentication credentials
Configuration and workflow settings
System usage data and audit logs
3.2 Protected Health Information (PHI)
When provided by a clinic, Asellera may process PHI, including:
Patient identifiers (name, phone number, email)
Appointment scheduling and treatment coordination data
Call transcripts and SMS communications
Intake form submissions
AI-generated administrative or clinical draft outputs
We do not collect PHI directly from patients except when acting on behalf of a healthcare provider.
4. How We Use Information
We use information strictly to:
Deliver automated communication and workflow services
Process voice, SMS, and intake interactions
Generate draft outputs for clinic review (e.g., summaries, notes, responses)
Route data into clinic systems (PMS, EHR, scheduling platforms)
Maintain system security, reliability, and audit logs
We do not:
Sell personal information or PHI
Use PHI for unrelated marketing purposes
Use PHI to train generalized machine learning models unless explicitly authorized by the healthcare provider in writing
5. Legal Basis for Processing
When handling PHI, Asellera processes data only:
As instructed by the covered entity (healthcare provider)
Under a signed Business Associate Agreement (BAA), where required
For permitted operational, administrative, and healthcare workflow purposes
Messaging and scheduling providers
6. AI and Automated Processing
Asellera uses artificial intelligence systems to support communication and workflow automation.
AI processes PHI only as necessary to perform requested services
Outputs are assistive and non-diagnostic in nature
AI does not replace clinical judgment or licensed healthcare providers
Final responsibility for all clinical decisions remains with the healthcare provider
PHI is not used to train generalized AI models unless explicitly authorized by the healthcare provider in writing
7. Data Sharing and Disclosure
We may share PHI only under the following conditions:
7.1 Service Providers (Subprocessors)
We engage third-party service providers to support infrastructure and functionality, including:
Cloud hosting providers (e.g., AWS)
AI processing providers (e.g., OpenAI or equivalent)
Communication providers (e.g., voice/SMS systems such as Retell AI)
Database and workflow providers (e.g., Supabase, automation tools)
All subprocessors are required to:
Enter into confidentiality and data protection agreements
Use PHI only to provide contracted services
Maintain appropriate technical and organizational safeguards
This list of subprocessors may be updated from time to time.
7.2 Healthcare Providers
All PHI is made available to the healthcare provider (clinic) that owns the patient relationship.
7.3 Legal or Safety Requirements
We may disclose information if required to:
Comply with legal obligations
Respond to lawful requests from public authorities
Protect the security, rights, or safety of users, patients, or systems
8. Data Security Safeguards
Asellera implements administrative, technical, and physical safeguards consistent with HIPAA Security Rule principles, including:
Technical Safeguards
Encryption in transit (TLS 1.2+)
Encryption at rest (AES-256 or equivalent)
Role-based access control (RBAC)
Multi-tenant data isolation
Secure API authentication
Audit logging of PHI access and system activity
Administrative Safeguards
Access restricted to authorized personnel
Principle of least privilege enforcement
Security training for personnel handling PHI
Incident response and breach procedures
Operational Safeguards
Continuous system monitoring
Activity logging and anomaly detection
Controlled production access environments
9. Data Retention and Deletion
We retain PHI only as long as necessary to:
Provide services to healthcare providers
Comply with legal and contractual obligations
Support audit, compliance, and security requirements
Clinics may request deletion, export, or correction of data, subject to legal and operational requirements.
10. Patient Rights
Depending on jurisdiction and clinic policies, individuals may have rights to:
Access their PHI
Request corrections to inaccurate information
Request restrictions on certain uses or disclosures
Request an accounting of disclosures
Requests should be directed to the relevant healthcare provider or to Asellera where applicable.
11. Business Associate Agreements (BAA)
Where required, Asellera enters into Business Associate Agreements (BAAs) with covered entities. These agreements define:
Permitted uses and disclosures of PHI
Security and safeguarding obligations
Breach notification procedures
Subprocessor requirements
12. International Data Transfers
PHI and personal data may be processed in jurisdictions outside the healthcare provider’s location, including Canada and the United States.
We ensure appropriate safeguards and contractual protections are in place to protect such data in accordance with applicable laws.
13. Cookies and Website Analytics
Our website may use cookies and analytics tools to improve performance and user experience.
These tools do not access PHI.
Users may disable cookies through their browser settings, though some website features may not function properly.
14. Breach Notification
In the event of a security incident involving PHI, Asellera will:
Contain and isolate affected systems
Assess scope and impact
Notify affected healthcare providers without unreasonable delay
Support investigation and remediation efforts
Comply with applicable breach notification laws and contractual obligation
15. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted with a revised effective date.
16. Contact Information
For privacy or PHI-related inquiries:
Email: contact@asellera.com
Company: Asellera
Approval
Approved By: Shane Senha, CEO
Company: Asellera
Version: 1.0
Date: June 16th 2026
