Last updated: April 17, 2026
ClinEthix LLC (“we”, “us”, “our”), a limited liability company registered in Wyoming, United States, operates the website clinethix.com and the ClinEthix Guidelines platform (collectively, the “Services”).
We are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our Services.
This policy is designed to comply with the General Data Protection Regulation (GDPR) (EU/EEA), the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) (US), Law 09-08 on the protection of individuals with regard to the processing of personal data (Morocco), and the EU-U.S. Data Privacy Framework (DPF) principles.
| Field | Details |
|---|---|
| Entity | ClinEthix LLC |
| Jurisdiction | Wyoming, United States |
| Contact | contact@clinethix.com |
As our processing activities grow, we will appoint a Data Protection Officer (DPO) and update this section accordingly. In the meantime, all privacy inquiries are handled directly by the founder.
When you browse our website, we may collect:
When you create an account and use the ClinEthix Guidelines platform, we additionally collect:
Important: ClinEthix Guidelines is a clinical decision support tool for healthcare professionals. It is NOT designed to process patient health records. No patient-identifiable information (names, dates of birth, medical record numbers, or any Protected Health Information as defined by HIPAA) should be entered into the platform. Users are solely responsible for de-identifying any information before submission.
Medical queries submitted by healthcare professionals may constitute indirect health-related data under GDPR Article 9. We process this data under the following justification:
Under the GDPR, we process your personal data on the following legal grounds:
| Purpose | Legal basis (GDPR) | Details |
|---|---|---|
| Providing our Services | Art. 6(1)(b) – Contract | Necessary to deliver the service you subscribed to |
| Account management | Art. 6(1)(b) – Contract | Managing your subscription, credentials, preferences |
| Processing medical queries | Art. 6(1)(b) + Art. 9(2)(i) | Core service delivery + public health interest safeguard |
| Product improvement | Art. 6(1)(f) – Legitimate interest | Anonymized analytics to improve accuracy and UX. You can opt out. |
| Marketing communications | Art. 6(1)(a) – Consent | Only with explicit opt-in. Withdraw anytime. |
| Legal obligations | Art. 6(1)(c) – Legal obligation | Tax records, regulatory compliance |
| Security and fraud prevention | Art. 6(1)(f) – Legitimate interest | Protecting our systems and users |
The ClinEthix Guidelines platform uses algorithms to match user queries with relevant published guidelines and present structured results. This processing:
If you believe an automated process has produced an inaccurate result, you can report it to contact@clinethix.com and request human review.
We do not sell, rent, or trade your personal data. Under the CCPA/CPRA, we confirm: we do not sell or share personal information for cross-context behavioral advertising.
We may share data with the following categories of service providers, all of whom are contractually bound by data processing agreements:
| Recipient category | Purpose | Location | Safeguards |
|---|---|---|---|
| Payment processor | Subscription billing | United States | PCI DSS Level 1 compliant |
| Cloud hosting provider | Platform and data hosting | European Union | ISO 27001, SOC 2 |
| Analytics provider | Anonymous usage statistics | European Union | IP anonymization, no cross-site tracking |
| Email service provider | Transactional and marketing emails | United States / EU | DPA in place, SCCs |
We may also disclose data when required by law, court order, or governmental authority, or to protect our rights or safety.
ClinEthix LLC is based in the United States. If you are located in the EU/EEA, the United Kingdom, Morocco, or another jurisdiction with data transfer restrictions, your data may be transferred to the United States.
We ensure adequate safeguards for international transfers through:
| Data type | Retention period | Justification |
|---|---|---|
| Account data | Duration of the account + 12 months | Reactivation window, then deleted |
| Query data | Duration of the account | Deleted on account closure or on request |
| Billing data | 7 years after last transaction | US tax and accounting obligations (IRS) |
| Analytics data | 26 months (anonymized) | Product improvement; no personal identifiers |
| Contact form submissions | 12 months | Follow-up and quality assurance |
| Marketing consent records | Duration of consent + 3 years | Proof of consent (GDPR accountability) |
| Security logs | 12 months | Incident detection and forensics |
After expiry, data is either permanently deleted or irreversibly anonymized. You may request early deletion at any time (subject to legal retention obligations).
| Category | Purpose | Duration | Consent required |
|---|---|---|---|
| Strictly necessary | Authentication, security, CSRF protection, load balancing | Session | No (exempt under ePrivacy) |
| Functional | Language preferences, display settings, cookie consent choice | 12 months | No (user-requested functionality) |
| Analytics | Anonymous page views, session counts, feature usage | 26 months | Yes – opt-in required |
On your first visit, a cookie consent banner allows you to accept or decline non-essential cookies. You can change your preference at any time by clicking “Cookie Settings” in the footer. You can also manage cookies via your browser settings, though this may affect site functionality.
To submit a CCPA request, email contact@clinethix.com with the subject “CCPA Request”. We will verify your identity before processing.
You may file a complaint with the CNDP (Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel) at www.cndp.ma.
| Channel | Details |
|---|---|
| contact@clinethix.com | |
| Subject line | “Privacy Request – [Your Right] – [Your Name]” |
| Verification | We verify your identity via email confirmation before processing |
| Response time | Within 30 days (GDPR/Morocco) / 45 days (CCPA) |
| Extension | Complex requests may be extended by 60 days (GDPR) or 45 days (CCPA) with notice |
| Cost | Free of charge (unless requests are manifestly excessive) |
We implement appropriate technical and organizational measures to protect your data:
Our Services are designed exclusively for licensed healthcare professionals, medical students (aged 18+), and healthcare institutions. We do not knowingly collect data from individuals under 18. If we become aware of such collection, we will promptly delete the data and terminate the associated account.
Our website does not currently respond to “Do Not Track” (DNT) browser signals, as there is no industry-standard protocol for DNT. However, we do not engage in cross-site tracking, and our analytics respect your cookie consent preference.
We may update this Privacy Policy from time to time. When we make changes:
Continued use of our Services after the effective date of changes constitutes acceptance of the updated policy.
For privacy-related questions, data access requests, or complaints:
| Type | Response time | |
|---|---|---|
| Privacy inquiries | contact@clinethix.com | We aim to respond promptly |
| Data rights requests | contact@clinethix.com | Within 30 days (GDPR) / 45 days (CCPA) as required by law |
| General inquiries | contact@clinethix.com | We aim to respond promptly |