Trust
ProIntel by AZR Consulting
Security and your data
Plain answers to the questions a practice asks before trusting ProIntel with its patients: where the data lives, who processes it, what the AI sees, who can see what, and how records are kept, exported and protected.
Where your data lives
ProIntel's database and file storage are hosted in the United States on managed cloud infrastructure, encrypted at rest. Every connection between your device and ProIntel is encrypted in transit with TLS.
Uploaded files and recordings sit in private storage that only ProIntel's own server can reach.
Each practice's data is kept apart from every other practice's by row-level security on every table, so a signed-in person can only ever read their own practice's records.
Who processes what
ProIntel runs on a small set of specialist services. Each one receives only what its job needs.
Cloud hosting and database, in the United States
- Receives
- Everything the practice keeps in ProIntel. Clinical content arrives already encrypted by ProIntel.
- Audio
- Encrypted recordings, kept up to 7 days
- Identifiable information
- Stored encrypted, readable only through ProIntel
- Retention
- As set out under How long things are kept, below
Transcription service
- Receives
- The live audio of a consultation or meeting, to turn speech into text.
- Audio
- Yes, while recording
- Identifiable information
- What is said in the room
- Retention
- Receives the live stream only; ProIntel's own copy is deleted within 7 days
AI model providers
- Receives
- Inside the clinical scribe: the transcript and the patient context a clinician's request needs. Everywhere else: practice-level totals, and the practice's own procedure documents for the SOP assistant.
- Audio
- Never
- Identifiable information
- Inside the clinical scribe only
- Retention
- Sent per request, only what that request needs
Email delivery service
- Receives
- The emails a practice sends from ProIntel, with the attachments the sender chose.
- Audio
- Never
- Identifiable information
- The recipient and the message
- Retention
- Delivery records, under the service's terms
Meeting notetaker service
- Receives
- Only when a practice sends a notetaker into an online meeting: that meeting's audio.
- Audio
- That meeting only
- Identifiable information
- What is said in the meeting
- Retention
- Under the service's terms
Payment processors
- Receives
- Card details and the billing email for the practice's ProIntel subscription, entered directly on their checkout.
- Audio
- Never
- Identifiable information
- Patient information never reaches them
- Retention
- Under the processor's terms
Error-monitoring service
- Receives
- Where in ProIntel's code a software error happened.
- Audio
- Never
- Identifiable information
- Request bodies, cookies, user identities and screen recordings are all stripped first
- Retention
- Under the service's terms
Cloud storage, in the clinician's own account
- Receives
- Only when a clinician links one of their own folders: ProIntel reads the files in that folder, and saves finished consults there when the clinician turns that on.
- Audio
- Only when the clinician turns on consult auto-save
- Identifiable information
- Yes, in the clinician's own account
- Retention
- The clinician's own account, under their control
Cliniko (bookings and clinical records) and QuickBooks (accounts) connect only when a practice connects them, with the practice's or clinician's own credentials, which ProIntel keeps in an encrypted vault.
Vendor names are available to a practice under a confidentiality agreement on request.
What the AI sees
Outside the clinical scribe, ProIntel's AI features work from practice-level totals: counts and sums, never an individual patient's record.
Inside the clinical scribe, which only clinicians use, the AI receives the consultation transcript and the patient context needed to write the note, brief or document the clinician asked for. Recordings themselves are never sent to an AI model.
A clinician reviews and approves every note before it enters the record, and each proposed chart update is confirmed with its own tap.
Drug-safety checks and clinical calculations run on ProIntel's own verified code, with the formula shown, never on AI opinion.
Your consultations are never used to train AI models.
Approved notes are permanent: the database itself refuses any edit or deletion of an approved note, and a correction files as a dated amendment beside the original.
Audio and transcripts
Consultation audio travels from the browser to the transcription service, to produce the transcript, and to ProIntel's own encrypted store. ProIntel keeps it nowhere else.
Recordings are encrypted and kept for up to 7 days, so a consult can be picked up on another device. After 7 days they are deleted automatically, without exception.
A clinician can delete a recording sooner at any time: deleting a consult's transcript deletes its recording with it, and discarding a consult deletes both at once.
Transcripts are encrypted and kept until the clinician deletes them, and only that clinician can read them.
If the connection drops mid-consult, the device keeps an encrypted copy of the recording in progress, erased the moment ProIntel's server confirms it has it, and on sign-out.
A clinician who turns on auto-save to their own linked cloud folder also receives a copy of each finished consult there, in their own account.
Encryption
Every piece of clinical content (notes, transcripts, recordings, uploaded documents, patient demographics, the structured chart and patient messages) is encrypted by ProIntel with AES-256-GCM before it is stored.
The encryption keys live only in the server environment, never in the database, so a copy of the database on its own holds unreadable ciphertext.
The database and file storage are also encrypted at rest by the hosting infrastructure, and every connection is encrypted in transit with TLS.
Credentials for connected systems (Cliniko keys, accounting and cloud-storage connections) are kept in an encrypted vault and never reach a browser or a log.
Who can see what
Each person's access follows their role: owner, manager, clinician or staff. Clinical content (notes, transcripts, recordings and pre-consult briefs) is for clinicians.
The practice owner gives each staff member exactly the access their job needs, one permission at a time: managing bookings, filing incoming documents into a patient's file, viewing a patient's documents, or reading consult notes history. Transcripts, recordings, briefs and the AI scribe stay with clinicians.
The audit log records who viewed, downloaded, exported, approved, amended or changed a patient's record, and when, including every read. The log itself can never be edited or deleted, by anyone.
Every change passes through ProIntel's server, which checks who is asking first: signed-in people hold read-only access to the database at most, and clinical tables are reachable through the server alone.
Error reports and logs carry structural facts only, such as status codes and counts, never the content of a clinical record.
How long things are kept
Approved notes are the medical record and are kept permanently. Everything else follows a written retention policy:
- Approved consultation notes
- Permanently, as the medical record
- Consultation and meeting recordings
- 7 days, then deleted automatically
- Unfinished drafts
- 7 days after their last save
- Consultation transcripts
- Until the clinician deletes them
- Patient files
- Until deleted, file by file
- The audit log
- Permanently
Backups
ProIntel's database runs on managed cloud infrastructure with encrypted backups.
Signing in
People sign in with their email address and a password, and reset a forgotten password through a link sent to their email.
Each session belongs to the browser that signed in. Signing out ends every session the account holds and clears any recording held on that device.
Your records, exported and deleted
A patient's complete record (demographics, every note with its amendment history, documents and the record's access log) exports in one action as a readable PDF and structured data, ready for another clinician, a lawyer or the patient.
Every invoice downloads as a PDF, and files, transcripts and recordings delete one by one from the patient's file or the consult.
Your data is yours. On request, AZR Consulting exports a practice's complete data within 30 days.
When an owner closes the practice account, billing stops, every other member is signed out, and linked cloud-storage connections are revoked straight away. The owner keeps read-only access for 30 days to export records. Clinical records are kept for 7 years after closure, in line with clinical record-keeping obligations, and remain available to the practice on request.
If something goes wrong
If a security incident affects a practice's data, AZR Consulting tells the affected practices within 72 hours of confirming it.
The law in Trinidad and Tobago
ProIntel is built for the Data Protection Act of Trinidad and Tobago, which treats health information as sensitive personal information, and applies the same protections everywhere: application-layer encryption, role separation, an audit log of every access, and a clinician approval gate before anything enters the record.
Who makes ProIntel
ProIntel is built and run by AZR Consulting, based in Trinidad and Tobago. Every question about it reaches the team that builds it at prointel@azr-consulting.com.
If ProIntel ever shut down, every practice would receive its complete export first.
A written security questionnaire covering each of these points in more detail is available to any practice on request.