Clinician Privacy Notice
Effective date: July 26, 2026
This Notice explains how ClinX Academy LLC ("ClinX," "we," "us," or "our") handles personal information about clinicians who use Connect and related ClinX services (the "Service"). It also explains your choices and privacy rights.
This Notice is for United States users who are at least 18 years old. The Service is not intended for patients, minors, or people outside the United States.
1. Information we collect
Depending on how you use Connect, we collect the following categories.
Account and contact information: name, email address, phone number, login identifiers, account role, communication preferences, and authentication records.
Professional and profile information: licenses, specialties, states, education, training, experience, biography, availability, languages, professional entities, profile photo, CV or resume, and information you choose to add to your profile.
Relationship and opportunity information: companies and domains you add, pre-existing or externally sourced relationships, opportunity views and invitations, interests, candidacy, deal stages, status notes, messages, and contract-finalization facts.
Compliance-log information: your private logging address; forwarded email metadata, date, cleaned text, and extracted context; deal attribution; manually written records; attestations; edits; deletions; and exports. Deal name is the user-facing relationship label. Company is derived internally from the selected deal for access control and is not a separate compliance-entry field. Attachments sent to the email logging address are ignored and not stored through that workflow.
Billing information: Stripe customer and subscription identifiers, plan, coupon, billing period, invoice and payment status, amounts, due dates, dispute or nonpayment notes, and limited transaction metadata. Stripe, not ClinX, stores full payment-card and bank-account credentials.
Files you submit: CVs, profile photos, and files submitted through an authorized upload feature. Do not upload patient records, PHI, or files you are not authorized to share.
Device, use, and security information: IP address, browser and device information, timestamps, pages or features used, authentication events, application logs, security events, and records showing which legal version you agreed to or acknowledged.
Support and communications: messages you send to ClinX, responses to surveys, privacy requests, and other communications.
Inferences and suggestions: suggested profile fields, possible email-to-company or deal matches, and opportunity recommendations generated from the information above. These are aids, not final decisions.
We do not intentionally collect patient medical records or PHI. We do not need Social Security numbers, government identification, biometric templates, precise geolocation, or consumer health data to provide the current Service. Please do not submit them unless a specific future feature clearly requests and explains them.
2. Where information comes from
We collect information:
- directly from you;
- from your authorized representative;
- from companies, MSOs, and their representatives when they create opportunities or update a deal involving you;
- from email you intentionally forward to your private logging address;
- from Stripe and other service providers;
- from ClinX administrators who manage invitations, tiers, matching, billing, and support; and
- from public professional sources when reasonably needed to verify or complete information you provide.
3. Why we use information
We use personal information to:
- create, authenticate, secure, and support your account;
- build your professional profile and let authorized companies evaluate a match;
- provide opportunities, invitations, messaging, and deal-status tracking;
- create and maintain private compliance and relationship logs;
- attribute forwarded email to the correct deal;
- administer subscriptions, coupons, success-fee quotes, invoices, disputes, and payments;
- send transactional email and separately consented text messages;
- prevent fraud, misuse, security incidents, and unlawful activity;
- debug, measure, maintain, and improve the Service;
- comply with law, enforce agreements, and establish or defend legal claims; and
- create deidentified or aggregate analytics that are not reasonably linkable to you.
We do not use identifiable CVs, forwarded emails, compliance logs, or company content to train general-purpose AI models. Our vendors may process this information only to provide contracted services to us, subject to their service terms and our instructions.
4. AI-assisted processing
If you upload a CV, Connect may send extracted CV text to our AI service provider to suggest profile fields for your review. If you forward an email to your logging address, Connect first verifies the outer sender and email authentication. Only trusted email may proceed to automated security scanning, sensitive-data redaction, and AI-assisted classification to suggest the relevant deal.
Automated results can be wrong. ClinX does not use AI as the final decision-maker for employment, opportunity selection, professional eligibility, licensure, tier, fees, or access to legal rights. You review CV suggestions, and unresolved email matches ask you to select the correct deal.
5. How we disclose information
We disclose personal information only as reasonably needed for the purposes below.
Companies you engage with: An authorized company user may see the professional profile fields, candidacy information, messages, and deal history that Connect makes available for that company's opportunity or relationship. A company does not see your subscription, coupons, ClinX success fee, ClinX invoices, payment status, compliance logs, pre-existing relationships, or unrelated opportunities and candidates.
Service providers: We use providers for cloud hosting and database services, authentication, payment processing, email delivery and ingestion, sensitive-data scanning, AI-assisted processing, SMS delivery, security, and technical support. Current core providers include Supabase, Vercel, Stripe, Google Workspace and Google Cloud, OpenAI, Resend, and Twilio. They process information for us under contracts or service terms and may not use it for their own behavioral advertising.
Professional advisers and authorities: We may disclose information to lawyers, accountants, insurers, auditors, regulators, law enforcement, courts, or other authorities when reasonably necessary and lawful.
Business transfers: We may disclose information in a financing, merger, acquisition, reorganization, bankruptcy, or sale, subject to appropriate confidentiality and notice where required.
With your direction: We disclose information when you ask us to or intentionally use a feature that sends it to another person.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use third-party advertising trackers in Connect.
6. Cookies, browser signals, and Global Privacy Control
Connect uses only cookies and similar storage reasonably needed for authentication, security, session continuity, and core preferences. We do not use them for cross-site behavioral advertising.
Because we do not track users across unrelated services for advertising, browser Do Not Track signals do not change how Connect operates. We honor Global Privacy Control where it applies. Under our current practices, a GPC signal does not trigger an additional opt-out because we do not sell or share personal information for behavioral advertising.
7. Retention
We keep information only as long as reasonably needed for the Service, security, legal obligations, disputes, and the purposes described above. Our normal schedule is:
- unverified or unauthenticated sender attempts: metadata only for up to 7 days, after which the held Gmail message is trashed and the quarantine record is removed unless you verify or discard it sooner;
- email-processing excerpts for accepted sender email: up to 24 months, then text content is redacted or deleted unless a legal hold applies;
- active account, profile, relationship, and ordinary compliance-log information: while the account is active, then normally deleted or deidentified within 90 days after a verified deletion request or account closure;
- billing, tax, legal acceptance, material deal, and finalized-contract records: generally 7 years;
- security and access logs: generally 24 months; and
- backups: up to 90 days before routine rotation.
We may keep information longer when required by law, needed to collect or dispute an amount, protect users, investigate abuse, or preserve a legal claim. A documented legal hold pauses normal deletion for the covered record.
8. Security
We use administrative, technical, and physical safeguards designed for the nature of the information, including access controls, role boundaries, private storage, encrypted connections, audit records, and vendor controls. No service can guarantee perfect security. Keep your login secure and contact us promptly if you suspect misuse.
9. Your choices and rights
You may update many profile fields in Connect, manage billing through Stripe, withdraw optional SMS consent, unsubscribe from marketing email, and request account closure.
Depending on your state and how its law applies, you may have rights to:
- confirm whether we process your personal information;
- access or obtain a portable copy;
- correct inaccurate information;
- delete information, subject to exceptions;
- opt out of a sale, targeted advertising, or certain profiling;
- limit certain uses of sensitive information;
- withdraw consent where processing depends on consent;
- appeal a denied privacy request; and
- receive equal service without unlawful discrimination for exercising a right.
To make any request or appeal, email info@clinxacademy.com. State your name, account email, state of residence, the right you want to exercise, and whether the message is an appeal. We may ask for information reasonably needed to verify identity and authority. An authorized agent may submit a request where state law permits, but we may verify the agent's authority and your identity.
We will respond within the period required by applicable law. If a particular state privacy law does not apply, we may still honor a reasonable request at our discretion. Some information cannot be deleted immediately, including invoices, legal acceptances, security records, and material deal facts we must keep for legal, accounting, fraud-prevention, or dispute purposes.
Maryland residents may have rights to access, correct, delete, obtain a copy, and opt out of sale, targeted advertising, or certain profiling under the Maryland Online Data Privacy Act, when it applies. They may appeal a denial by replying to our decision or emailing info@clinxacademy.com with "Privacy appeal" in the subject.
California residents may request the categories and specific pieces of personal information collected, sources, purposes, categories of recipients, correction, deletion, and portability, subject to legal exceptions. They may also opt out of sale or sharing and limit certain sensitive-information uses where applicable. ClinX does not currently sell or share personal information for cross-context behavioral advertising and does not use sensitive information to infer characteristics. We will not unlawfully discriminate for exercising a California privacy right.
For California's required look-back disclosure, the categories we may have collected are identifiers; professional or employment information; commercial and transaction information; internet or network activity; user-provided visual information such as a profile photo; communications content intentionally sent to us; and inferences described above. We collect and disclose those categories for the business purposes in Sections 3 and 5. We have not sold or shared those categories for cross-context behavioral advertising.
10. Email and text choices
You may unsubscribe from marketing email using the link in the message or by emailing us. We may still send account, security, opportunity, deal, legal, and billing messages needed to provide the Service.
SMS is separate and optional. Reply STOP to opt out or HELP for help. Withdrawing SMS consent does not close your account or stop email invitations.
11. Patient information and HIPAA
Connect is for professional business activity, not patient care. Do not submit PHI, patient communications, medical records, or clinical images. ClinX does not offer this version of Connect as a HIPAA business associate and does not enter business associate agreements for it.
If we detect information that appears to be PHI or other prohibited sensitive content, we may redact, quarantine, restrict, or delete it and may contact you. Tell us promptly at info@clinxacademy.com if you believe prohibited information was submitted.
12. Children and users outside the United States
The Service is not for anyone under 18. We do not knowingly collect personal information from minors. If you believe a minor provided information, contact us so we can investigate and delete it.
The Service is offered only in the United States. Do not use it from another country or submit information about people outside the United States unless ClinX has expressly approved that use in writing.
13. Changes to this Notice
We may update this Notice as the Service or law changes. We will post the new effective date and provide additional notice for material changes. If a change requires consent, we will ask for it separately. We record the version you acknowledged.
14. Contact us
For privacy questions, requests, appeals, or complaints:
ClinX Academy LLC
10811 Barn Wood Lane
Potomac, MD 20854
info@clinxacademy.com