1. Scope
This Privacy Policy describes how DRootDx handles information on this public website. The protected clinical application has additional privacy and security controls presented to its authorized users. This public website is not intended for the submission of patient information, medical records, or urgent care requests.
2. Information this website collects
The public DRootDx website and VisitRoom signup flow may collect the clinic name, Clinic Owner name and email, selected clinician-seat quantity, trial eligibility information, and information needed to begin Stripe Checkout. DRootDx does not collect or store payment-card details entered on Stripe's hosted checkout page. Hosting, security, and fraud-prevention systems may process limited technical information such as IP address, device and browser characteristics, requested pages, timestamps, and security events to operate and protect the service, prevent duplicate trials, and troubleshoot the site. DRootDx does not sell this information or use it to create advertising profiles or marketing mailing lists.
3. Clinical and patient information
Do not submit protected health information through this public website or ordinary email. Patient and clinical information is handled only through authorized workflows in the protected application and according to the applicable clinic’s notices, agreements, and legal obligations.
4. Transactional email
DRootDx may send expected one-to-one transactional messages for secure intake invitations, authorized account setup, requested password resets, and reminders tied to an existing workflow. We do not use purchased, rented, or scraped address lists. Message content is kept minimal and secure links are designed to expire.
5. How technical information is used
Limited technical information may be used to:
- Deliver and maintain the website;
- Detect abuse, fraud, and security incidents;
- Diagnose reliability and performance problems; and
- Comply with applicable legal obligations.
6. Service providers and disclosure
We may use hosting, security, infrastructure, and transactional communication providers to operate DRootDx. They receive only the information reasonably necessary to provide their services. We do not sell personal information collected through this public site. Information may be disclosed when required by law or necessary to protect users, the public, or our systems.
7. Record keeping and retention
VisitRoom transcripts are retained for the period selected by the Clinic Owner, from 1 day through a maximum of 365 days; the default is 30 days. Each transcript is automatically deleted when that period expires. RootQ keeps working encounter data for 30 days after the encounter by default, after which it is automatically queued for deletion. Exporting or uploading a record to the clinic's chosen system does not stop the deletion clock. RootQ and VisitRoom are workflow services, not the clinic's official medical-record archive; the clinic remains responsible for retaining its official medical record for the period the law and its policies require.
Account, configuration, consent, transaction, and security records are kept only for the service, audit, safety, dispute-resolution, and legal purposes that apply to them. Technical website and security logs are retained only as reasonably necessary to operate, protect, and troubleshoot the services. We use administrative, technical, and organizational safeguards appropriate to the nature of the information, but no online system can be guaranteed to be completely secure.
8. What happens when an account closes
Cancellation overrides all clinic-selected retention periods. The Clinic Owner chooses immediate deletion or a fixed 30-day transcript- export window. Immediate deletion ends access and queues all clinical data for permanent deletion from active systems. If the export window is selected, normal VisitRoom access ends and the Clinic Owner receives read-only access only to retained transcripts and export tools for 30 calendar days. Transcript exports are available as CSV, Microsoft Excel, PDF, plain text, and a bulk ZIP archive. On the selected deletion date, active user sessions and connected integration credentials are revoked and the clinic's patient, encounter, transcript, scribe, message, consent, and uploaded-file data is queued for deletion from active systems, even when paid subscription time remains. Encrypted backup copies are deleted within 30 days after active-system deletion and are not restored for ordinary use.
DRootDx may retain limited, content-free proof that deletion was requested and completed. Billing and transaction records, security and fraud-prevention records, consent or signature evidence, and information subject to a legal hold may also be retained when independently required. Those exceptions do not permit continued use of encounter content for product operation.
9. Your choices
If you receive a DRootDx transactional message in error, do not use its secure link. Contact the clinic or organization identified in the message. Requests concerning clinical records should be directed to the clinic responsible for those records.
10. Children
This public website is directed to professional and general adult audiences and is not designed to collect information directly from children.
11. Changes to this policy
We may update this policy as DRootDx develops. The effective date above will be updated when material changes are published.
12. Contact
Questions about this public website or this policy may be directed through the organization or clinic that provided your DRootDx communication. Do not include medical information in an ordinary email inquiry.