Legal

Privacy Policy

How Orisan Clinical Systems collects, uses, and protects your information.

Effective date: April 8, 2026

Introduction

This Privacy Policy describes how Orisan Clinical Systems ("we," "us," or "our") collects, uses, and shares information when you visit orisanconnect.com or use the Orisan Connect platform.

Important Notice Regarding Protected Health Information

Protected Health Information (PHI) processed through the Orisan Connect platform is governed by our Business Associate Agreements (BAAs) with customers, not this Privacy Policy. This policy covers the personal information we collect from website visitors, prospective customers, and platform account holders in the course of providing our service.

Information We Collect

Information you provide through forms

When you request a demo or contact us, we collect the information you submit:

  • First name and last name
  • Email address
  • Phone number
  • Company name
  • Current EHR system
  • Message or description of your needs

Account information

When you create an Orisan Connect account, we collect:

  • Email address
  • Password (hashed with Argon2 — we never store plaintext passwords)
  • Organization name

Usage data

We collect information about how you interact with the platform, including page views, feature usage patterns, and error logs. This helps us improve reliability and user experience.

Technical data

We automatically collect technical information when you visit our site, including your IP address, browser type and version, and device information.

How We Use Your Information

We use the information we collect for the following purposes:

  • Provide and operate the service — authenticate your account, manage your integrations, and deliver the data synchronization platform
  • Respond to inquiries — follow up on demo requests, contact form submissions, and support questions
  • Improve the platform — analyze usage patterns and error logs to fix issues and build better features
  • Send transactional emails — account confirmations, password resets, sync status notifications, and other service-related communications delivered via Resend
  • Sales follow-up — sync demo request and contact form submissions to our CRM to coordinate outreach

How We Share Your Information

We share information only with the following categories of service providers:

Amazon Web Services (AWS)

Our infrastructure hosting provider. All platform data is hosted on AWS under a HIPAA Business Associate Agreement. Data is stored in the United States.

Resend

Transactional email delivery for account-related communications such as confirmations, password resets, and sync notifications.

We do not sell your personal data

We do not sell, rent, or trade your personal information to third parties for marketing or advertising purposes. We never have and never will.

We may disclose your information if required to do so by law, regulation, or legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

How We Protect Your Data

Orisan Connect handles protected health information and other sensitive data, and we apply the following technical safeguards to all of it — including any data we receive from Google APIs.

Encryption at rest

Sensitive fields are encrypted at the column level with AES-256-GCM envelope encryption before they are written to the database. Encryption keys are held in AWS Secrets Manager, are injected into the running service at deploy time, and are never committed to source control. We support key rotation and re-encryption without downtime. Each customer's records are additionally isolated in a separate database schema.

Encryption in transit

All traffic to and from the platform, and every call we make to a third-party API including Google's, uses TLS 1.2 or higher with certificate validation enforced. We do not transmit sensitive data over unencrypted channels.

Credential and token storage

Third-party credentials — including the Google OAuth refresh token used for the Calendar integration — are held in an encrypted credential vault using envelope encryption with KMS-managed keys. They are never written to logs, never exposed to the browser, and never stored in plaintext. Account passwords are hashed with Argon2 and are never stored in recoverable form.

Access controls

Access to sensitive data requires an authenticated session with a bounded lifetime, carried in a signed, HTTP-only, secure cookie that is not readable by JavaScript, and is further restricted by role-based authorization. Data is isolated per tenant so that one organization's records are not reachable from another's. Internal access follows least privilege and is limited to the personnel who need it to operate and support the service.

Monitoring and audit logging

Reads and writes of sensitive data generate entries in an append-only audit log recording who acted, what they acted on, and when. Audit records identify data by opaque identifiers rather than by content, and we do not log sensitive values.

Infrastructure

The platform runs on Amazon Web Services under a Business Associate Agreement, in private networks with restricted ingress. We maintain an information security program covering access review, change management, vulnerability remediation, and incident response, and we review it on an ongoing basis.

No system can guarantee absolute security, but these controls are applied to all sensitive data we hold, including data obtained through Google APIs.

Data Retention

  • Form submissions — retained for legitimate business purposes such as responding to your inquiry and maintaining a record of our communications
  • Account data — retained for as long as your account remains active. Upon account deletion, we remove your personal data within 30 days, except where retention is required by law
  • Audit logs — retained according to your plan tier, ranging from 30 days to 7 years, to meet HIPAA compliance and operational requirements

Google User Data

Orisan Connect can write your practice's appointments to Google Calendar. This section describes exactly how we access, use, store, and share Google user data, and applies in addition to the rest of this policy.

What we request

When you connect Google Calendar, we ask your permission for the narrowest scopes that make the feature work:

  • .../auth/calendar.events — to create, update, and delete the calendar events that Orisan Connect itself writes for your appointments.
  • .../auth/calendar.calendarlist.readonly — to list the calendars on your account so you can choose which one to write to. This does not let us read the contents of any calendar.

We do not request access to Gmail, Drive, Contacts, or any other Google service.

How we use it

Google user data is used for one purpose only: to keep the calendar you selected in sync with the appointments in your practice management or EHR system. We write only to the specific calendar you choose. We never write to a calendar you did not explicitly select.

What we store

  • An OAuth refresh token, encrypted at rest, so syncs can run on schedule without you being present.
  • The identifier of the calendar you selected, and a mapping between each appointment and the calendar event we created for it, so updates and cancellations reach the right event instead of creating duplicates.

We do not copy your Google Calendar's existing events into our systems, and we do not build a profile from your Google data.

Protected health information

You control how much detail is written to Google. Every event passes through a redaction step first, and a patient's full name is never written to a calendar event. Google Calendar should only ever be connected to an account covered by your organization's Business Associate Agreement with Google — not a personal consumer account.

Limited Use

Orisan Connect's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not sell Google user data, we do not use it for advertising, we do not use it to train generalized artificial intelligence or machine learning models, and we do not allow humans to read it except with your explicit consent, to resolve a support issue you have raised, for security purposes, or where required by law.

Revoking access and deletion

You can disconnect Google Calendar at any time from your Orisan Connect connections page, which revokes our access with Google and deletes the stored refresh token. You can also revoke access directly at myaccount.google.com/permissions. Calendar events already created remain on your calendar until you delete them, so that disconnecting never silently removes your practice's schedule.

Cookies

We use session cookies solely to maintain your authenticated session when you are logged into the Orisan Connect platform. These cookies are essential for the service to function and are deleted when you log out or your session expires.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

Your Rights

You have the right to:

  • Access — request a copy of the personal information we hold about you
  • Correction — request that we correct inaccurate or incomplete information
  • Deletion — request that we delete your personal information, subject to any legal retention requirements

To exercise any of these rights, email us at privacy@orisanconnect.com. We will respond to your request within 30 days.

Children's Privacy

Orisan Connect is a business-to-business platform designed for healthcare organizations. Our service is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify registered users by email and update the effective date at the top of this page.

We encourage you to review this policy periodically to stay informed about how we protect your information.

Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Orisan Clinical Systems

Email: privacy@orisanconnect.com

Website: orisanclinicalsystems.com

Have questions about our data practices?

Our team is happy to discuss how we handle and protect your information.

CONTACT US