RemindReview

Company

Security & privacy practices

Plain-English overview of what RemindReview handles for appointment SMS — written for chiropractic, dental, PT, and similar clinics that keep Google Calendar. Not legal advice; not a claim that we are HIPAA-certified, SOC 2 certified, or HITRUST certified.

What data we handle

In a healthcare context, names, phones, and appointment times can still be ePHI even when texts stay non-clinical. That is why clinics can sign a Business Associate Agreement with us.

What we don’t put in SMS

Templates forbid diagnosis and treatment details. Texts use logistics only: first name, business name, date/time, and confirm / cancel / review links. You control the wording — please keep it non-clinical.

Encryption

Access control

Audit logging

We keep an audit_log of significant staff and admin actions. Signing a BAA records action baa.signed with version and content hash. SMS delivery history is available in the staff dashboard.

Retention & deletion

Same policy is reflected in our Privacy Policy.

Breach notification

If we discover a breach affecting your clinic’s data, we will notify affected customers without unreasonable delay, and in any event no later than 60 days after discovery — aligned with the HIPAA business-associate notification expectation, stated in plain language. This page is not legal advice.

Subprocessors

ProviderRoleNotes
Cloudflare Hosting, Workers, D1 database, CDN Primary application infrastructure.
Telnyx SMS / telecom routing Telnyx generally positions standard telecom transmission under the HIPAA conduit exception and does not traditionally sign a BAA for basic carrier routing. See Telnyx Help Center. We do not claim a Telnyx BAA.
Google Calendar Appointment source of truth Connected under your Google account / Workspace. Google’s terms apply to that account.
Stripe Payments / subscriptions Processes payment and billing details. Not used to store clinical notes.

We may add email delivery later; if we do, this table will be updated.

Business Associate Agreement available

Clinics that need a customer-facing BAA can sign RemindReview’s native BAA in the staff app — no DocuSign. Signing captures name, identity, IP, user agent, timestamp, version, and content hash.

Sign in to Settings → Sign BAA Privacy Policy

SMS is not blocked if a BAA is unsigned (beta / non-healthcare shops still work). Availability and status are what matter for healthcare sales.

Disclaimer

This page is a founder-written overview of security practices for sales and transparency. It is not legal advice, not a certification badge, and not a substitute for your own counsel’s review of HIPAA obligations for your practice.