Privacy
Privacy Policy
Version 2026-09-11Effective 11 September 2026
This document is incorporated by reference into 2care.ai service agreements. Where it conflicts with a signed Order Form, the Order Form controls the specific item it addresses.
This Privacy Policy explains how 2Care AI Inc. (2care, we, us) collects, uses and protects personal information in connection with the 2care.ai website and platform. It applies to visitors to our website and to the staff who administer our platform.
Patient Data processed on behalf of a clinic is not governed by this policy. When we handle patient personal data through the Services on a clinic's instructions, the clinic is the controller (or covered entity) and that processing is governed by the customer agreement and the applicable data-protection addendum: the HIPAA Business Associate Agreement in the United States or the Data Processing Agreement in the United Kingdom.
1. Information we collect
- Account information: name, business email, phone number and role of the clinic staff who register for or administer the Services.
- Usage information: device and browser data, IP address, and how the website and platform dashboard are used, including via cookies and similar technologies.
- Service content: where we act as processor for a clinic, call audio, transcripts, booking and enquiry data; this content is handled under the customer agreement and addendum, not this policy.
- Communications: information you provide when you contact us, book a demo or subscribe to updates.
2. How and why we use it
- To provide, secure, maintain and improve the website and platform.
- To respond to enquiries, provide support and send administrative or service messages.
- To send marketing communications where you have opted in, which you can withdraw at any time.
- To comply with legal obligations and to establish, exercise or defend legal claims.
3. Legal bases and disclosures
Where UK or EU data-protection law applies, we rely on legitimate interests, performance of a contract, consent, or compliance with a legal obligation, as appropriate to each purpose. We disclose personal information to service providers who process it on our behalf under contract, to professional advisers, and where required by law or to protect our rights. We do not sell personal information.
4. Sub-processors, retention and security
We use vetted sub-processors, for example telephony and voice providers, AI and large-language-model providers, cloud hosting, and messaging providers, bound by contractual data-protection obligations. We retain personal information only as long as necessary for the purposes described or as required by law, and we implement appropriate technical and organisational measures, including encryption in transit and at rest and access controls, to protect it.
5. Your rights
Depending on where you are located, you may have rights to access, correct, delete, port, restrict or object to the processing of your personal information, and to withdraw consent. To exercise a right, contact us using the details below. Where we act as a processor for a clinic, we will direct patient requests to the relevant clinic (the controller).
6. Region notes
- United States: where the California Consumer Privacy Act applies, California residents have rights to know, delete and opt out of the sale or sharing of personal information; we do not sell personal information.
- United Kingdom: processing is subject to the UK GDPR and the Data Protection Act 2018; you may lodge a complaint with the Information Commissioner's Office (ICO).
7. Changes and contact
We may update this policy from time to time and will change the effective date above when we do. For any privacy question or to exercise a right, contact us at privacy@2care.ai.