Legal

Privacy policy

How Assertica handles personal information — on this website, and in ClinicDesk, our WhatsApp assistant for clinics.

Last updated: 29 September 2026

Assertica (“we”, “us”) builds AI agents and software for regulated businesses. This policy covers two things: the website at assertica.ai, and ClinicDesk, our WhatsApp assistant that clinics use to handle patient enquiries and appointments.

If you want to have your information deleted, that is set out in full on our data deletion page.

Part one — this website

We keep this deliberately small. If you submit the contact form we collect the name, email address, company, sector and message you enter, and mail it to ourselves so we can reply. Nothing from the form is stored in the website’s database.

Our host records standard server logs for every request — IP address, browser user agent, page and timestamp — used for security and troubleshooting. To stop the form being flooded we count recent submissions against a one-way hash of your IP address; the address itself is never stored and the counter is discarded after an hour. The typefaces are served by Google Fonts, which means loading a page makes a request to Google that reveals your IP address and user agent.

We use Google Analytics to count visits and see which pages people read. It tells us page views, the country a visit came from, and which site or search engine sent you — not who you are. Google receives that data and sets a cookie so a returning browser is recognised as the same visitor. If you are in the European Economic Area, the United Kingdom or Switzerland, no analytics cookie is set unless you consent, and visits are counted without one.

There is no advertising, no session recording and no other tracking on this site.

Part two — ClinicDesk on WhatsApp

ClinicDesk lets a patient message a clinic on WhatsApp to ask a question, book, reschedule or cancel an appointment. An AI assistant reads those messages and replies, and hands over to clinic staff when it should.

Who is responsible for your information

The clinic you are messaging is the controller of your information — it decides why your data is held and for how long. Assertica is a processor, acting on that clinic’s written instructions. Your clinic’s own privacy notice governs your patient record; this policy explains what ClinicDesk does with it on their behalf.

What ClinicDesk collects

  • Your WhatsApp phone number, which is how the conversation reaches you.
  • Your name, as you give it or as the clinic already holds it.
  • The content of your messages, including anything you choose to tell us about your reason for visiting. Please share only what the clinic needs.
  • Appointment details — the clinician, date, time and status of bookings made or changed through the conversation.
  • Technical message data supplied by WhatsApp, such as delivery timestamps and message identifiers.

ClinicDesk does not ask for payment card details, and you should not send them over WhatsApp.

Why it is used

To answer your questions, to make and change appointments, to send you appointment reminders and confirmations, and to pass the conversation to a human at the clinic when it needs one. We also keep basic operational records so the clinic can see what was said on its behalf.

Who processes it

ClinicDesk relies on a small number of providers, each acting under contract and only on our instructions:

  • Meta Platforms — operates WhatsApp and the WhatsApp Business Platform, which carries every message between you and the clinic. Your use of WhatsApp itself is also governed by Meta’s own privacy policy.
  • Anthropic — provides the AI model that reads a message and drafts the reply. Message content sent to the model is processed to produce that reply and is not used to train it.
  • Google — provides calendar and workspace services used to schedule and manage appointments.
  • Our hosting provider — runs the servers where conversation and appointment records are stored.

We do not sell personal information, we do not use it for advertising, and we do not share it with anyone outside that list except where the clinic instructs us to or the law requires it.

How long it is kept

Conversation and appointment records are retained for as long as the clinic remains a ClinicDesk customer and continues to need them, and are deleted when the clinic’s service ends or when it or you ask us to. Technical logs are held on a short rolling window. Because the clinic is the controller, its own retention rules — including any medical-records obligations it is under — take precedence over ours.

Security

Messages travel over WhatsApp’s encrypted transport. Data at rest is held on access-controlled servers, and access is limited to the people who need it to run the service. No system is perfectly secure, so please do not send anything through WhatsApp that you would not want a clinic’s front desk to see.

Data deletion

You can ask for your information to be deleted at any time, free of charge, and you do not need to give a reason. There are two ways:

  • On WhatsApp — reply to the ClinicDesk conversation with DELETE MY DATA.
  • By email — write to eliya@assertica.ai with the subject Data deletion request.

We acknowledge requests within 7 days and complete them within 30 days. Because the clinic is the controller of your patient record, we action the deletion in ClinicDesk and pass your request to the clinic, which may be legally required to keep a medical record even after the conversation is removed.

The full procedure, including what is deleted and what may remain, is on the data deletion page.

Your other rights

Depending on where you live you may also have the right to ask what is held about you, to have it corrected, to object to or restrict its use, and to receive a copy in a portable form. Write to eliya@assertica.ai and we will respond within 30 days, passing the request to the clinic where it is theirs to answer. If you are unhappy with the outcome you may complain to your local data protection authority.

International transfers

We operate from Pakistan and use providers that process data elsewhere, including in the United States and the European Union. Where information crosses a border we rely on the contractual safeguards offered by those providers.

Children

ClinicDesk is intended to be used by adults. Where a clinic uses it in relation to a child’s care, the conversation is expected to be conducted by a parent or guardian, and the clinic remains responsible for obtaining any consent required.

Changes

If this policy changes we will update it here and revise the date at the top. Material changes will be described rather than slipped in quietly.

Contact

Questions about this policy, about ClinicDesk, or about anything above go to eliya@assertica.ai. General website and business enquiries go to info@assertica.ai.