Contents
1. Who this covers
Closefly LLC ("Closefly", "we", "us") helps medical spas and other appointment-based businesses answer inquiries and book consultations. This policy explains what we do with personal information in two very different situations, and the difference matters:
- When we act for ourselves. You visit our website, fill in a form, book a call with us, email us, or become our client. Here we decide how the information is used, and this policy governs.
- When we act for a client. A clinic hires us and we handle messages with that clinic's patients and inquiries on the clinic's behalf. Here the clinic decides how the information is used. We act only on the clinic's written instructions, under our client agreement and, where the clinic is a HIPAA covered entity, under a Business Associate Agreement. If you are a patient of one of our clients, that clinic's own privacy notice governs your information, not this policy. Contact the clinic first; we will support them in answering you.
2. What we collect
Information you give us
- Name, business name, role, email address, phone number, and city, when you fill in a form, request a Leak Report, book a call, or reply to one of our messages.
- The content of your messages to us: email, text message, web chat, and voicemail.
- Billing and account details if you become a client. Card details are handled by our payment processor; we do not store full card numbers.
- Anything you choose to send us, including recordings or notes from a meeting you agreed to record.
Information we collect automatically
- Device and browser type, operating system, IP address, approximate location derived from IP address, referring page, pages viewed, and time on page.
- Email opens and link clicks in messages we send you.
- Message metadata: phone number, carrier, and the date, time, and delivery status of texts between you and us.
Information from other sources
- Publicly available business information used to research a practice before we contact it: website content, public review profiles, business listings, and advertising libraries.
- Referrals and introductions from people in our network.
3. How we use it
- To answer you, provide the services you asked for, and run our accounts and billing.
- To prepare research documents about a practice, such as a First Findings document or a Leak Report.
- To send you service and account messages: confirmations, reminders, alerts, and replies.
- To send marketing messages about Closefly, where you have consented or where the law otherwise allows it, and always with a way to stop.
- To secure our systems, prevent abuse and fraud, and enforce our terms.
- To improve our services. We may use information in an aggregated or de-identified form that does not identify you or any patient. If we hold information under a Business Associate Agreement, we only do this to the extent that agreement allows.
- To meet our legal obligations and to establish, exercise, or defend legal claims.
4. Text messages and consent
If you give us your mobile number and agree to receive text messages from Closefly, you consent to receive messages from us at that number, which may be sent using automated technology and may include content generated with the help of artificial intelligence.
- Consent to receive marketing texts is never a condition of buying anything from us.
- Message frequency varies. Our marketing programme will not normally exceed 10 messages a month.
- Message and data rates may apply. Ask your carrier about your plan.
- Reply STOP to any message to stop all messages from us. Reply START to resume. Reply HELP for help, or email legal@closefly.ai.
- We keep a record of when and how you consented, and we keep it after you opt out, so we can prove we honoured your choice.
Our full Messaging Terms and Conditions apply to texts between you and Closefly. They do not apply to texts between you and a clinic that uses our services; those are governed by the clinic's own terms and notices.
5. Automated and AI-assisted messaging
We use artificial intelligence to help draft and send replies, both for ourselves and, on their instructions, for our clients. Messages may be composed or sent automatically without a person reading them first. AI output can be wrong or incomplete. Nothing we or our systems send is medical advice, a diagnosis, a price quote, or a promise of a clinical result. If you ask whether you are talking to a person or an automated system, our systems are instructed to tell you the truth and to hand you to a person on request.
6. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We share it with:
- Service providers who run parts of our operation on our instructions and under contract, including our messaging and CRM platform, our text and voice carriers, our scheduling and form tools, our AI providers, our email and hosting providers, and our payment processor. Our current list is published in our Subprocessor List.
- Our clients, when the information relates to a conversation we handled on their behalf.
- Professional advisers: lawyers, accountants, insurers, and auditors, under confidentiality.
- Authorities, when the law requires it, or to protect the rights, safety, or property of Closefly, our clients, or the public.
- A buyer or successor, if Closefly is involved in a merger, acquisition, financing, or sale of assets. We will tell you if this changes how your information is handled.
7. Patient information and HIPAA
Some of our clients are covered entities under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). Where we handle protected health information for such a client, we act as a business associate under a signed Business Associate Agreement. In that role:
- We use and disclose protected health information only as that agreement and HIPAA allow.
- The clinic, not Closefly, is responsible for its notice of privacy practices and for obtaining any patient consents and authorisations required before we begin work.
- Patients should direct requests about their records to the clinic. We will help the clinic answer them within the deadlines in our agreement.
- We require the same protections in writing from any vendor of ours that handles that information.
8. Cookies and tracking
Our websites use cookies and similar technologies to make the site work, remember your preferences, measure traffic, and measure the performance of our advertising. You can block or delete cookies in your browser settings; some parts of the site may then stop working. Where a legally recognised opt-out preference signal such as Global Privacy Control is sent by your browser, we treat it as an opt-out of sale and sharing for that browser.
9. How long we keep it
We keep personal information for as long as we need it for the purpose we collected it, and then for as long as we need it to meet legal, tax, accounting, and dispute-resolution obligations. Records of text message consent and opt-out are kept for at least four years, because that is the window in which a claim about them can be brought. Information we hold as a business associate is returned or destroyed at the end of the engagement, except where the law requires us to keep it, as set out in the Business Associate Agreement.
10. Your rights and choices
Depending on where you live, you may have the right to ask us to: confirm whether we hold personal information about you and give you a copy; correct it; delete it; stop selling or sharing it, which we do not do in any case; and not be discriminated against for exercising these rights. Florida residents have these rights under the Florida Digital Bill of Rights, and California residents under the California Consumer Privacy Act. Other states have similar laws.
To make a request, email privacy@closefly.ai. We will verify who you are before we act, normally by confirming details we already hold. We will answer within 45 days and may extend once where the law allows. You may use an authorised agent; we will ask for proof. If we refuse, we will say why, and you may appeal by replying to our decision; if we deny the appeal you may complain to the Florida Attorney General or to your own state's attorney general.
If your request concerns information we hold for one of our clients, we will forward it to that client and support them in answering it. The clinic, not Closefly, decides the outcome.
11. Security
We use administrative, technical, and physical measures designed to protect personal information, including access controls, encryption in transit, multi-factor authentication on our core systems, and limiting access to the people who need it. No system is perfectly secure, and we cannot guarantee absolute security. If a breach of unsecured protected health information occurs, we will notify the affected client without unreasonable delay and within the timeframe set out in our Business Associate Agreement.
12. Where your data is handled
Closefly is based in the United States and your information is stored and processed there. Some of our service providers and technical personnel are located outside the United States, including in Argentina. Where that is the case, we require them by contract to protect the information to the same standard we apply, to use it only on our instructions, and to accept the same restrictions we have accepted, including under HIPAA where applicable. Our Subprocessor List names each provider and the country it operates from.
13. Children
Our services are for businesses. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, email privacy@closefly.ai and we will delete it.
14. Changes
We may update this policy. We will change the effective date at the top and, if the change is significant, tell you by email or by a notice on our site before it takes effect. Older versions are available on request.
15. Contact us
Closefly LLC, Miami, Florida, United States
Privacy questions and rights requests: privacy@closefly.ai
Legal notices: legal@closefly.ai