Privacy Policy
This document is published in English. Translations elsewhere on the site are for convenience; the English version governs.
This policy explains how [Legal entity name], doing business as highertouch.ai, handles personal information. highertouch.ai is an AI front desk for aesthetic clinics: it answers customer messages, books appointments and sends follow-ups across LINE, WhatsApp, Instagram Direct and web chat.
1. Two roles we play
Read this part first, because it determines who you should contact about your data.
When we are the controller
For our own website, marketing and business relationships, we decide why and how personal information is used. That covers visitors to highertouch.ai, people who contact us or book a demo, and the staff at clinics who hold accounts with us.
When we are the processor
When a clinic connects its channels to our Service, the messages its customers send flow through our systems. In that case the clinic is the controller and we act on its instructions. If you messaged a clinic and want your data corrected or deleted, contact that clinic. We will support them in responding, and you can also contact us and we will route your request.
2. Information we collect
| Category | Examples | Role |
|---|---|---|
| Account and contact information | Name, work email, phone, clinic name, role, billing contact | Controller |
| Enquiry information | What you tell us in the contact form, demo requests, email threads | Controller |
| Clinic configuration | Treatments, prices, hours, booking rules, FAQs, brand voice | Processor |
| End customer conversations | Message content and metadata, name or handle as provided by the channel, language, timestamps | Processor |
| Booking records | Treatment requested, appointment time, practitioner, status, reminders sent | Processor |
| Usage and device data | Pages viewed, referring page, country inferred from IP for language selection, browser and device type | Controller |
| Payment data | Handled by our payment processor. We see billing contact and invoice status, not full card numbers. | Controller |
Health-related information. A customer may volunteer health details in a message to a clinic, for example describing a skin concern. We do not ask for it and the agent is configured not to solicit it, but where it appears we treat it as sensitive, restrict access, and process it only to deliver the Service to the clinic. Clinics are responsible for their own obligations under health privacy laws that apply to them.
3. How we collect it
- Directly from you, when you fill in a form, email us, create an account or configure your agent.
- Automatically, through server logs and, with your consent, analytics cookies. See our Cookie Policy.
- By detecting your country once, on your first visit only, so the site opens in Thai, Chinese or English. Your browser asks a third-party service (GeoJS) which country your IP is in and we keep only the resulting language choice. No cookie is set and the lookup is skipped once you have a language stored. Details in Location detection.
- From messaging channels, when a customer messages a connected clinic and the channel passes us the message and the profile fields it exposes.
- From clinics, when they upload or configure their own information.
4. How we use information
- To run the Service: answering messages, checking availability, writing bookings into the clinic's system, sending reminders and follow-ups.
- To support customers: responding to questions, investigating faults, restoring data.
- To secure the Service: detecting abuse, spam and unauthorised access, keeping audit logs.
- To bill and administer accounts.
- To improve the Service using aggregated, de-identified operational data such as volumes, response times and error rates.
- To send service messages, and marketing only where permitted, with an unsubscribe link in every marketing email.
- To meet legal obligations and to establish or defend legal claims.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use end customer message content to train general-purpose AI models.
5. Legal bases for processing
Where the GDPR, UK GDPR or a similar regime applies to our own processing, we rely on: contract, to provide the Service to a clinic and administer its account; legitimate interests, to secure and improve the Service and to run our business, balanced against your rights; consent, for non-essential cookies and for marketing where consent is required, which you can withdraw at any time; and legal obligation, for tax, accounting and lawful requests.
When we act as a processor, the clinic determines the legal basis for its own processing.
6. Who we share it with
We share personal information with service providers who help us run the Service, under contracts that restrict their use of it:
| Provider | What it does | Where |
|---|---|---|
| Vercel | Website and application hosting, edge delivery | USA / global edge |
| Google Analytics | Website analytics, only with your consent | USA |
| GeoJS (get.geojs.io) | Returns the country your IP appears to be in, once per visitor, so the site opens in the right language | Global |
| AI model providers | Generating agent replies from clinic-configured information | USA |
| Messaging channels | LINE, Meta (WhatsApp and Instagram), TikTok, delivering messages to and from customers | Varies by channel |
| Clinic booking systems | Reading availability and writing confirmed bookings | Determined by the clinic |
| Payment processor | Subscription billing and invoices | USA |
| Email and scheduling tools | Service email, demo scheduling | USA |
We may also disclose information to professional advisers, to authorities where legally required, and to a buyer in connection with a merger, acquisition or sale of assets, in which case we will tell you before your information becomes subject to a different policy.
7. International transfers
We are based in the United States and our providers operate globally, so personal information may be transferred outside the country where it was collected, including from Thailand, Taiwan or the European Economic Area to the United States. Where required, we rely on Standard Contractual Clauses or another lawful transfer mechanism, together with technical measures such as encryption in transit and at rest. You can ask us for details of the mechanism used.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and billing records | For the life of the account, then up to 7 years where tax or accounting law requires |
| Conversation and booking data | For the clinic's subscription term, then 30 days for export, then deleted |
| Enquiry and demo requests | 24 months from last contact |
| Server and security logs | 12 months |
| Analytics data | 14 months |
| Backups | Rolling 35 days, after which deleted records age out |
Clinics can ask us to apply a shorter retention period to their workspace.
9. Your rights
Depending on where you live you may have the right to access your personal information, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent, and complain to a regulator. You will not be treated differently for exercising these rights.
- California (CCPA/CPRA). Rights to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined. See Privacy Choices.
- EEA and UK (GDPR). The rights listed above, and the right to lodge a complaint with your supervisory authority.
- Thailand (PDPA). Rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent, and to complain to the Personal Data Protection Committee.
- Taiwan (PDPA). Rights to review, obtain copies, request correction, and request that collection, processing or use stops.
To exercise a right, email hello@highertouch.ai with enough detail to identify your records. We respond within 30 days, or 45 days for California requests where an extension is permitted. If your data sits inside a clinic's workspace we will forward your request to that clinic and help them answer it.
10. Cookies and tracking
We use strictly necessary cookies to run the site, and analytics cookies only if you allow them. Nothing non-essential loads until you choose. You can change your choice at any time from the Cookie Settings link in the footer. Full detail is in our Cookie Policy.
11. Security
We encrypt data in transit with TLS and at rest, restrict access to staff who need it, use least-privilege access controls and multi-factor authentication on administrative systems, keep audit logs, and review our providers. No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator as the law requires, and clinics without undue delay so they can meet their own obligations.
12. Children
The Service is built for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If a clinic's customer is a minor, the clinic is responsible for obtaining any consent its law requires. If you believe a child's information reached us, contact us and we will delete it.
13. Changes to this policy
We will update this policy as the Service changes. The date at the top always reflects the current version. For material changes we will give notice by email or in the dashboard before they take effect.
14. Contact us
[Legal entity name]
[Registered address], San Francisco, California, USA
Email: hello@highertouch.ai
If you are in the EEA or UK and we need an Article 27 representative, we will name one here.