How we handle your patients' data
You're trusting us with your phones and your patients' information. This page explains, in plain language, exactly how that data is treated — including the things we haven't finished yet.
Data minimization & automatic masking
Sensitive identifiers spoken during calls — Social Security numbers, dates of birth, account details — are detected and masked automatically before anything is stored. We keep the minimum data required to run your call flows, and nothing more.
Encryption
Call audio and stored records are encrypted in transit and at rest. [UPDATE: specify your exact stack — e.g., TLS 1.3 in transit, AES-256 at rest, key management details — after review with your infrastructure provider.]
Data retention & deletion
You control how long call records are retained, and you can request deletion of your practice's data at any time. Upon termination, your data is deleted within [UPDATE: e.g., 30] days, and we provide written confirmation.
Access controls
Access to production systems is limited to named personnel on a need-to-know basis, protected by multi- factor authentication, and logged. Your practice's staff access their own data through role-based accounts you administer.
Vendors & subprocessors
We work with a small number of infrastructure vendors, each under data-protection agreements. [UPDATE: publish the actual subprocessor list — vendor name, service, location. Practices' IT teams will ask for this.]
Incident response
If a security incident affecting your data occurs, we notify affected practices without undue delay and within any timeframe required by our HIPAA agreement. Security reports: [email protected].
Our current compliance status, honestly stated
Articence is an early-stage company. We have not yet completed third-party audits such as SOC 2 Type II or HITRUST certification — we will publish results here as they complete, and we never claim certifications we don't hold. We're happy to answer your IT team's security questionnaire directly.