Privacy Policy

Last updated: January 2, 2026

Disclaimer: This policy is provided for general information and does not constitute legal advice. For specific legal questions, please consult with a qualified legal professional.

1. Introduction

Evoli Sense ("Company," "we," "us," "our") operates the Clinic CRM platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Service, including our website and any associated applications.

We are committed to protecting your privacy and ensuring you have a positive experience on our platform. This policy outlines our practices regarding data collection, usage, and security.

2. Information We Collect

We collect information in the following categories:

  • Account Information: When you create an account, we collect your name, email address, phone number, organization name, and location information.
  • Clinic/Organization Data: If you use our Service, you may provide information about your clinic or healthcare facility, including facility name, address, specialization, and user roles.
  • Usage & Activity Logs: We automatically collect information about how you interact with our Service, including login timestamps, feature usage, pages accessed, and actions performed within the platform.
  • Support Communications: When you contact our support team, we collect the content of your communications, including emails, chat messages, and attachments.
  • Device & Browser Information: We collect information about the device you use to access our Service, including device type, operating system, browser type, and IP address.
  • Patient Data (Clinic Data): Clinics using our Service may store patient records, appointment data, medical history, and other healthcare information. This data is owned and controlled by the clinic and processed by Evoli Sense as a service provider.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve the Clinic CRM Service
  • To authenticate your identity and prevent unauthorized access
  • To process your subscription and billing requests
  • To communicate with you about your account, service updates, and security alerts
  • To provide customer support and technical assistance
  • To monitor platform security, detect fraud, and prevent abuse
  • To generate aggregated analytics and usage statistics (anonymized, non-identifying)
  • To comply with legal obligations and respond to lawful requests
  • To send you service-related announcements (you can opt out of promotional emails)

4. Legal Bases for Processing

We process your information based on the following legal grounds:

  • Contract Performance: To fulfill our obligations under your Service agreement
  • Legitimate Interests: To improve our Service, ensure security, and maintain platform operations
  • Legal Compliance: To comply with applicable laws and regulations
  • Consent: Where you have explicitly agreed to specific processing activities (e.g., marketing communications)

5. Data Sharing & Disclosures

We do not sell your personal information. We may share information in the following circumstances:

  • Service Providers: We work with third-party vendors who help us operate the Service (e.g., hosting providers, payment processors, analytics services). These vendors are contractually bound to protect your data.
  • Legal Requirements: We may disclose information if required by law, court order, or government request.
  • Business Transfers: In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
  • Your Clinic Users: If you are a clinic administrator, information you provide may be visible to authorized users of your clinic's account.
  • With Your Consent: We may share information with third parties when you explicitly consent to such sharing.

6. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption in Transit: All data transmitted between your device and our servers uses TLS/SSL encryption to prevent interception.
  • Encryption at Rest: Sensitive data stored on our servers is encrypted using industry-standard encryption protocols.
  • Role-Based Access Control (RBAC): Access to patient and clinic data is restricted based on user roles and permissions, ensuring users only access data necessary for their role.
  • Audit Logs: We maintain comprehensive audit logs that track all access to sensitive information, including who accessed what data and when.
  • Multi-Tenant Isolation: Each clinic's data is logically and physically isolated from other clinics' data, ensuring strict data segregation.
  • Regular Security Updates: We conduct regular security assessments and implement patches and updates to address vulnerabilities.
  • Backup & Disaster Recovery: We maintain regular automated backups with disaster recovery procedures to protect against data loss.

While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security, but we commit to maintaining industry-standard protections.

7. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this policy. Retention periods vary by data type:

  • Account Information: Retained while your account is active and for a reasonable period thereafter for legal and business purposes.
  • Clinic Data: Retained as long as you maintain your subscription. Upon account termination, we retain data for 30 days to allow for recovery, then securely delete it.
  • Audit Logs: Retention periods depend on your plan (Clinic Start: 15 days; Clinic Grow: 60 days; Clinic Enterprise: 180-360 days as configured).
  • Support Communications: Retained for customer service purposes and deleted upon request or after 2 years of inactivity.

8. Your Rights & Choices

Depending on your location, you may have the following rights:

  • Right to Access: You can request a copy of the personal information we hold about you.
  • Right to Correction: You can request that we correct inaccurate or incomplete information.
  • Right to Deletion: You can request deletion of your information, subject to legal and contractual obligations.
  • Right to Data Portability: You can request your information in a structured, machine-readable format.
  • Right to Opt-Out: You can opt out of receiving promotional emails by clicking the unsubscribe link in our communications.
  • Right to Object: You can object to specific processing activities, such as profiling or targeted marketing.

To exercise any of these rights, please contact us at support@evolisense.com. We will respond to your request within 30 days.

9. International Data Transfers

Evoli Sense is based in India. If you are accessing the Service from outside India, your information will be transferred to and stored in India. By using our Service, you consent to the transfer of your information to India and its processing according to this Privacy Policy.

We implement appropriate safeguards to protect your information during international transfers, including data processing agreements and standard contractual clauses where applicable.

10. Children's Privacy

The Clinic CRM Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that a minor has provided us with personal information, we will promptly delete such information and terminate the minor's account if applicable.

11. Third-Party Links

Our website and Service may contain links to third-party websites and services. This Privacy Policy applies only to information collected through our Service. We are not responsible for the privacy practices of third-party websites. We recommend reviewing the privacy policies of any third-party services you use.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the "Last updated" date at the top of this policy and, if necessary, by sending you a notification email. Your continued use of the Service after changes become effective constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions about this Privacy Policy, your information, or our privacy practices, please contact us at:

Evoli Sense Privacy Team
Email: support@evolisense.com
Website: https://evolisense.com