Skip to content

Privacy

Privacy Policy

Last Updated: April 26, 2026

CayesDesk, operated by Oncova Clinical Research LLC, takes the privacy and security of healthcare data with the utmost seriousness. This Privacy Policy explains how we collect, use, and protect data when you use our website and B2B software services.

Full HIPAA compliance
BAA-ready deployment
No public AI model training
1

Our Commitment to Privacy

CayesDesk is built for high-ticket private clinics that need missed-call and after-hours concierge coverage without weakening patient privacy. We treat clinic communication, caller details, and conversion rules as sensitive information.

2

Distinction Between Business Data and Patient Data (PHI)

  • Business Data: When clinics visit our website or sign up, we collect B2B contact details, billing information processed securely through PayPal Business, and operational FAQs used to configure the concierge.
  • Patient Data (PHI): As an inbound Intelligent Patient Concierge, CayesDesk temporarily processes audio recordings, transcripts, caller ID, and appointment requests provided by patients. This data is classified as Protected Health Information (PHI). This Privacy Policy does NOT govern PHI. All PHI is governed by HIPAA and the specific Business Associate Agreement (BAA) we execute with your healthcare provider.
3

Zero-Retention AI Training Policy

CayesDesk explicitly guarantees that no patient data, call audio, or transcripts are ever used to train public Large Language Models (LLMs) or foundational AI models such as OpenAI, Gemini, or ElevenLabs. Patient data processed through CayesDesk is securely siloed, processed momentarily to provide the immediate service, such as routing a summary SMS to your staff, and handled in strict accordance with HIPAA.

4

Data Security & Sub-processors

We implement enterprise-grade security, including AES-256 encryption for data at rest and TLS 1.2+ for data in transit. We strictly utilize HIPAA-eligible infrastructure and sub-processors, including secure telecom providers and encrypted cloud hosts. We maintain downstream Business Associate Agreements (BAAs) with all critical sub-processors.

5

TCPA and Communications

CayesDesk acts as an inbound routing and response system. By providing CayesDesk with staff phone numbers for SMS summaries, the Clinic consents to receive automated text messages from CayesDesk related to patient inquiries and system alerts.

Next step

Review CayesDesk with your team.

These pages are designed to support buyer review before a live call, pilot, or onboarding conversation.

Contact Support
Speak with Vivienne. Patient Concierge · Demo.