ClinIQ IrelandSign in
Legal

Privacy Policy

Last updated: 18 June 2026

1. Data controller

The data controller for ClinIQ Ireland is [TODO: confirm legal entity name and registered address], Ireland. Contact: privacy@cliniq.ie.

2. What we collect

  • Account data: email, name, profession, specialty, registration body and registration number (self-declared).
  • Usage data: the clinical questions you ask, the AI answers generated, sources retrieved, feedback you give, saved items, settings.
  • Attachments: any images, PDFs, or audio you upload as part of a question (see “Attachments & de-identification” below).
  • Payment data: handled by Stripe; we receive subscription status and the last 4 digits of the card, not full card numbers.
  • Technical data: IP address, browser type, device, log timestamps, security events.

3. Why we use it (lawful basis)

  • Provide the service — contract (Art. 6(1)(b) GDPR).
  • Bill and collect payment — contract / legal obligation.
  • Improve safety and quality — legitimate interests (Art. 6(1)(f)), e.g. monitoring error rates, abuse, hallucinations.
  • Comply with law — legal obligation (Art. 6(1)(c)), e.g. tax, anti-fraud.
  • Marketing emails — only with your opt-in consent (Art. 6(1)(a)). You can unsubscribe at any time.

4. Attachments & de-identification

ClinIQ is for educational and reasoning support. You must not upload directly identifiable patient data (names, MRNs, PPS numbers, Eircodes, contact details, faces, DOBs). Before each submission we show a de-identification reminder; you are responsible for what you upload.

Attachments are stored in a private, access-controlled bucket scoped to your user account, processed by our AI providers (see below), and auto-deleted after 30 days. Signed URLs used to share files with our AI provider expire within one hour.

5. Sub-processors

We use the following sub-processors, each bound by GDPR-compliant data-processing terms:

  • Supabase — database, authentication, storage (EU region).
  • Stripe — payments and subscription billing.
  • Cloudflare — content delivery, security, edge runtime.
  • Lovable AI Gateway — secure proxy to AI model providers.
  • OpenAI, Google (Gemini) — AI model inference. Data sent for inference is not used to train their public models under the terms applied through the Gateway.
  • Brave Search — source retrieval for Research Mode (queries only; no personal data).
  • Resend / email provider — transactional and (with consent) marketing emails.

6. Retention

  • Account & subscription data — for as long as your account is active, plus up to 6 years for tax/audit.
  • Clinical questions and answers — retained per account until you delete them or close your account.
  • Attachments — auto-deleted 30 days after upload.
  • Logs and security events — up to 12 months.

7. Your rights

Under GDPR you have the right to access, rectify, erase, restrict, or port your personal data, to object to processing, and to withdraw consent. To exercise these rights, email privacy@cliniq.ie. We respond within one month.

You can lodge a complaint with the Irish supervisory authority, the Data Protection Commission.

8. International transfers

Where data leaves the EEA (e.g. AI inference in the US), it is protected by Standard Contractual Clauses and/or adequacy decisions.

9. Security

We use TLS in transit, encryption at rest, role-based access, row-level security in the database, secret rotation, audit logs, and least-privilege service accounts. No system is perfectly secure; please report any suspected vulnerability to security@cliniq.ie.

10. Changes

We will notify you in-app or by email at least 14 days before material changes to this policy take effect.

Pre-launch notice: this Privacy Policy is a working draft and must be reviewed by an Irish-qualified solicitor before public launch.