Privacy at InnerOS Practice
How your data, and your clients’ data, is handled.
This explains how InnerOS Practice handles data when you use it to run your practice. It is written for you, the practitioner. The short version: your clients’ records are yours. You decide what is collected and why. InnerOS runs the tooling that holds and moves that data on your instructions, and nothing more.
1. Who is responsible for your clients’ data
For your clients’ personal data, you are the data controller and InnerOS is your data processor. You determine the purpose; we process on your instructions to provide the service. For your own account data as a practitioner, InnerOS is the controller.
2. What data InnerOS Practice handles
- Your practice profile: name, photo, bio, services, availability, and payment details.
- Client records: names and contact details, booking and session history, intake responses, session notes and any documents you upload, and payment records.
- Operational data: messages sent to clients, calendar events, and logs needed to run and secure the service.
3. The sub-processors we rely on
To provide the service we use a small set of sub-processors, each receiving only the data needed for its function:
- Razorpay — payments and payouts.
- WhatsApp and Meta — client messaging.
- Google — Meet video sessions and Calendar scheduling.
- Supabase — database and file storage hosting.
- Our AI providers — drafting session notes and related assistance.
We keep this list current and give you reasonable notice before adding a sub-processor that materially changes how your clients’ data is handled.
4. How we store and protect it
Data is stored on managed cloud infrastructure with access controls and encryption in transit. Uploaded client documents are held in private storage that only your account can reach. We limit access to what is needed to run and support the service.
5. Keeping, exporting, and deleting data
We keep your clients’ data for as long as your account is active and you need it to run your practice. You can export your records, and you can delete a client’s data or close your account, at which point we remove the associated data on a reasonable timeline, except where we must retain limited records to meet a legal or tax obligation.
6. Your clients’ requests
Because you are the controller, requests from your clients about their data — to see it, correct it, or have it deleted — are yours to answer. InnerOS gives you the tools to act on those requests and will support you in doing so.
7. Questions and grievances
If you have a question or concern about how data is handled, write to us at [email protected] and we will respond. This is also the contact for any grievance under applicable data-protection law.
8. Governing law
This applies to practitioners using InnerOS Practice in India, and is governed by the laws of India. Practitioners in other regions (for example the United States or Canada) will be covered by a jurisdiction addendum when those are offered; those addenda add to, and do not replace, what is written here.
Questions? Write to us at [email protected].