Privacy Policy

ProIntel · Effective 24 August 2026

ProIntel (the “Platform”) is a business intelligence service operated by AZR Consulting (“AZR”, “we”) for professional practices (“Clients”). It presents each Client’s own operational and financial information back to that Client’s authorised team. It is a private tool for our Clients. There is no public sign-up.

What we collect

With a Client’s authorisation, the Platform connects to systems the Client already uses, practice management software and accounting software such as QuickBooks Online (via Intuit’s APIs), and retrieves operational records: appointments, invoices, payments, and related business data. We deliberately minimise personal data: patient and customer names, contact details, and clinical notes are not stored by the Platform’s business-intelligence features. The clinical scribe is the one exception, described in its own section below. Where a business-intelligence screen needs a name, it is retrieved live from the source system at the moment of display and discarded.

How we use it

Data retrieved from a Client’s connected systems is used solely to provide the Platform’s reporting and analysis to that same Client. We do not sell data, we do not use one Client’s data for another Client, and we do not use it for advertising. The one narrow exception: aggregated, de-identified usage patterns (for example, which document formats users most often adjust) may be used to improve the Platform for everyone. No note, document, or patient content is ever part of that aggregation, and nothing in it can identify a practice, a user, or a patient. Data obtained through Intuit’s APIs is used only to provide the Platform’s services to the business that connected its QuickBooks account, and is never resold or shared with third parties for their own purposes.

Payments

Subscription payments are handled by the payment partner shown at checkout (currently Whop or Paddle). Your card number and full payment details go directly to that partner and are never seen or stored by the Platform; we receive only what is needed to manage your subscription, such as the plan purchased, its status, and the billing email.

Where it lives and how it is protected

The Platform runs on Vercel with data held in Supabase (PostgreSQL, hosted on AWS). Data is encrypted in transit (TLS) and at rest. Access credentials for connected systems are stored in an encrypted vault and are never exposed to browsers or logs. Every database table is protected by row-level security so a Client’s users can only ever read their own practice’s data, and financial data is further restricted to owner and manager roles.

Service providers

We use a small set of infrastructure providers to operate the Platform: Vercel (hosting), Supabase/AWS (database and storage), Sentry (error monitoring, no personal data in logs), Anthropic (the AI features), and Voyage AI (search indexing for the procedure assistant).

Because AI processing sends data outside the Platform, we state exactly what is sent. Three things only. First, practice-level totals: monthly billing and collection sums, visit counts by service type, package sales, and revenue grouped by condition, with any group smaller than five patients merged so no figure describes a handful of people. Second, the text of procedure documents a Client uploads, together with the question a staff member types, so the assistant can answer from them. Third, for Clients using the clinical scribe, consultation and meeting transcripts, so notes can be written from them, processed under agreements that prohibit the AI provider retaining or training on them.

Individual patient records are never sent: no names, dates of birth, contact details, identifiers or clinical notes. Because the AI is given a fixed set of totals rather than access to the database, no question asked of it can retrieve a patient record. Staff are asked not to type patient details into the assistant, and should not.

The clinical scribe

Clients who use the clinical scribe record consultations and meetings so their notes and minutes are written for them. For that feature only, the Platform stores more than business data, and protects it accordingly. Recordings are kept for up to 7 days: encrypted with keys the database itself never holds, readable only by the clinician who made them, deletable at any time, and deleted automatically after 7 days without exception. Transcripts, notes, and documents a clinician chooses to keep are stored under the same encryption and are readable only by that clinician; deleting a session’s transcript deletes its recording with it. Audio is sent to our transcription provider under an agreement that prohibits retention, and stored audio is never sent to any AI system.

Cloud storage connections (Google Drive and Microsoft OneDrive)

A member of a Client’s team may connect their own Google Drive or Microsoft OneDrive account to the Platform. Connecting is always an individual, deliberate act, and access can be revoked at any time from the Platform’s settings or from the Google or Microsoft account itself.

What we access is deliberately narrow. For exports (sending a document, meeting minutes, or consultation records to the user’s own cloud storage), the Platform only creates and updates files and folders of its own; with Google this uses the restricted “per-file” permission that cannot see the rest of the Drive. Reading broader content happens only when a user explicitly links one of their own folders to the Platform, and is then used solely to list and read the files inside that linked folder. The Platform never deletes or reorganises a user’s own files.

Files imported from a linked folder into a patient’s record are protected exactly as the clinical scribe section describes: encrypted with keys the database never holds, readable only through the owning clinician’s account, deletable per file. Outside of that, the Platform stores only structural details of a connection (folder identifiers, file sizes and timestamps) with file and folder names encrypted. Connection credentials live in an encrypted vault and are never exposed to browsers or logs.

ProIntel’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google Drive or Microsoft OneDrive is used only to provide the features described above to the user who connected the account. It is never sold, never used for advertising, and never used to train AI models.

Retention and disconnection

A Client may disconnect any linked system at any time, which revokes the Platform’s access.

When an owner closes their account, billing stops immediately and every other member is signed out; the owner keeps read-only access for 30 days to export their records, and any linked cloud-storage connection is revoked straight away. Non-clinical business data (leads, dashboards, reports, and similar practice-management content) is then deleted. Clinical records (patient notes, files, and consultation transcripts) are kept for 7 years after closure, in line with standard clinical record-keeping obligations, and remain available to the practice on request during that time; deleting them sooner is a manual step taken only at the owner’s written request.

Advertising and analytics cookies

Our public website pages (pricing, the scribe overview, sign-up and sign-in) use the Meta (Facebook/Instagram) Pixel and, where configured, Google Analytics, to measure how our advertising performs and to show ads to people who have visited our site. These record page views, button clicks, and an anonymised browser identifier; they are never present inside the signed-in application, and no clinical or practice data is ever included. You can opt out of Meta’s ad personalisation in your Meta ad settings, or block these scripts entirely with your browser’s cookie or tracking-protection controls.

Contact

Questions about this policy: prointel@azr-consulting.com.