This Privacy Policy explains how Vantis Strategies LLC, doing business as nuemed, handles personal data when providing its website, clinic management software and related services.
1. Who we are
nuemed is a trade name of Vantis Strategies LLC, a Wyoming limited liability company. Our mailing address is 30 N Gould St Ste N, Sheridan, Wyoming 82801, USA.
Privacy enquiries may be sent to privacy@nuemed.io. Legal notices may be sent to legal@nuemed.io.
2. Our role
Clinics decide why and how patient data is used. The clinic is normally the controller of that data, and nuemed processes it on the clinic's documented instructions.
nuemed acts as a controller for its own website, customer accounts, billing, service administration, security and legal records.
If you are a patient, your clinic remains your primary contact for questions about your clinical record. This policy does not replace the clinic's own privacy notice.
3. Information we process
Depending on how the service is used, we may process:
- Clinic and staff account information, including names, work contact details, roles and login records.
- Subscription, invoice and payment-related information. Card details are handled by payment providers and are not stored in full by nuemed.
- Patient information entered by a clinic, including contact details, appointments, forms, clinical notes, photographs, prescriptions, communications and payment records.
- Files and other content uploaded by authorised clinic users.
- Device, browser, IP address, security, diagnostic and service-usage information.
- Enquiries, support requests and communications with us.
We do not intentionally collect full payment-card numbers. Payment providers process card information under their own security and privacy obligations.
4. How information is collected
We receive information directly from clinic customers and authorised users, from patients using clinic-controlled booking and form workflows, automatically from devices and service activity, and from providers or integrations selected by a customer.
Where a clinic imports existing records, the clinic is responsible for ensuring that the transfer is lawful and that the information is accurate and relevant.
5. Why we use information
We use personal data to provide and secure the service, authenticate users, process subscriptions, deliver requested features, support customers, prevent misuse, maintain records, comply with law and improve reliability.
Where we act as a controller, our legal bases may include performing a contract, legitimate interests, compliance with legal obligations and consent where consent is required.
Clinics are responsible for selecting an appropriate legal basis and special-category condition for the patient information they control.
6. Controller processing and lawful bases
- Contract: creating and administering customer accounts, processing subscriptions and supplying requested support.
- Legitimate interests: securing the service, preventing fraud, maintaining business records, understanding service performance and communicating with business customers.
- Legal obligation: complying with tax, accounting, regulatory, court and law-enforcement requirements.
- Consent: using non-essential cookies or sending marketing where consent is required. Consent may be withdrawn at any time.
Where we rely on legitimate interests, we consider the necessity of the processing and its impact on individuals. We do not use patient clinical data for our own marketing purposes.
7. Health and other sensitive information
Patient records may include health information and other sensitive data. The clinic determines what information is recorded and is responsible for identifying a lawful basis and any additional condition required for processing it.
nuemed processes this information only to provide the service, follow lawful documented instructions, protect the platform or comply with law. We do not independently determine a patient's treatment or use clinical records for advertising.
8. Artificial intelligence
Some nuemed features use third-party artificial intelligence services to transcribe, organise or improve user-provided content and to guide authorised users to relevant workflows.
AI output is a draft. An authorised clinic user must review and approve it. nuemed does not use AI to make autonomous medical decisions.
Short dictation recordings may be processed transiently by a speech-to-text provider. nuemed does not intentionally retain the original recording after the transcription request completes. Clinics and practitioners should avoid speaking unnecessary patient identifiers.
nuemed does not use clinic or patient data to train its own models, advertise to patients, sell data or create commercial benchmarks.
We apply controls intended to minimise personal identifiers provided to AI services. No automated filter can be guaranteed to identify every possible reference. Clinics must train authorised users to avoid unnecessary identifiers and review all generated content before use.
9. When information is shared
We use carefully selected providers for hosting, databases, file storage, email, payments, analytics, integrations and AI processing. They may process information only to provide their contracted services or as otherwise permitted by law.
Our current provider categories are described on the Subprocessors page. Clinics may also enable integrations that cause information to be sent to providers they select.
We may disclose information where required by law, to protect rights and security, or in connection with a corporate transaction subject to appropriate safeguards.
We do not sell personal data. We do not share patient information with data brokers or use it for cross-context behavioural advertising.
10. Clinic-directed communications
Clinics may use the service to send booking confirmations, reminders, forms, recommendations, prescription links and permitted email campaigns. The clinic determines the recipients, content and legal basis for those communications.
nuemed acts on the clinic's instructions when delivering those messages. Recipients should contact the clinic about the substance of a message, appointments, consent or marketing preferences. We may process delivery events and technical records to provide and secure the communication service.
11. International transfers
nuemed operates internationally. Information may be processed in the European Economic Area and in other countries used by our contracted providers.
Where required, we use recognised safeguards such as the European Commission's Standard Contractual Clauses and the applicable UK transfer addendum or agreement.
We also assess transfer arrangements and may implement supplementary contractual, organisational or technical protections where appropriate. Individuals may contact us for information about the safeguards applicable to a transfer.
12. Retention and deletion
While a clinic account is active, patient data is retained according to the clinic's instructions and applicable record-keeping duties.
After termination, the clinic has 30 days to request an export. We aim to delete the clinic's production data within 60 days and allow deleted data to expire from rotating backups within 90 days, unless longer retention is required by law or agreed in writing.
We retain billing, security and legal records only for as long as reasonably necessary for their purpose.
Retention periods can differ where a valid legal hold, dispute, regulatory obligation or security investigation requires preservation. Data isolated in backups is not used for ordinary business purposes and remains protected until expiry.
13. Security
We use technical and organisational safeguards appropriate to the nature of the service. These include access controls, tenant separation, transport encryption, protected database storage, backups, permission-aware workflows and audit logging.
No system can guarantee absolute security. Clinics are responsible for assigning appropriate permissions, protecting credentials and using the service lawfully.
Access by nuemed personnel is restricted by role and operational need. Support access to customer-controlled clinical information is not part of ordinary account administration and requires an authorised process.
If a customer believes its account or data has been compromised, it should contact legal@nuemed.io promptly.
14. Individual rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object to or receive a copy of their personal data.
Patients should normally contact the clinic responsible for their record. We will assist clinics with valid requests. Requests concerning nuemed's own account or website data may be sent to privacy@nuemed.io.
Individuals may also complain to the data-protection authority responsible for their location.
We may need to verify identity and authority before responding. Rights are not absolute and may be limited by legal, professional record-keeping or third-party rights. We will explain any lawful refusal or restriction.
15. Marketing choices
We may send business customers service information and, where permitted, information about nuemed products. Recipients can unsubscribe from marketing using the link in a message or by contacting us. Operational, billing, security and legal notices are not marketing and may still be sent while an account exists.
16. Children
nuemed is sold only to businesses. Patients do not create nuemed accounts. A clinic that records information about a child is responsible for establishing the necessary authority and safeguards.
Our website and customer accounts are not directed to children. If a child or guardian has a question about a clinic-controlled record, they should contact that clinic.
17. Cookies and analytics
We use essential technologies to operate and secure the website. Non-essential analytics technologies are used only where permitted and, where required, after consent. More information appears in our Cookie Policy.
18. Regional information
Individuals in the EEA, United Kingdom and other jurisdictions may have additional rights under local law. Vantis Strategies LLC is established in the United States. Where local law requires a representative, contact or additional notice, we will provide the relevant details before commencing the affected processing.
Nothing in this policy limits rights that cannot legally be waived.
19. Changes
We may update this policy to reflect changes in the service, providers or law. We will publish the updated date and provide additional notice where a material change requires it.
20. Contact
Privacy requests and questions may be sent to privacy@nuemed.io. Our mailing address is Vantis Strategies LLC, 30 N Gould St Ste N, Sheridan, Wyoming 82801, USA.