Home / Legal / Privacy policy
Privacy policy
What AlphaSync collects, why we collect it, who we share it with and what you can ask us to do with it.
Effective 1 January 2026. Last updated 1 January 2026.
Who we are and what this policy covers
AlphaSync LLC is a US software company trading at alphasync.ai. We sell business-to-business software to independent med spa practices: an AI system that answers missed calls, follows up with leads, and helps bring past patients back.
This policy explains what personal information we collect through this website and the services we provide to practices, why, who we share it with, how long we keep it, and what you can ask us to do with it.
It does not replace the privacy notice a practice publishes for its own patients.
Our two roles
Privacy law separates the organisation that decides why information is used from the one handling it on someone else's instructions.
- We are a controller for our own website enquiries and business contacts. When you send a form, email us or book a session, we decide what happens to those details and use them to reply.
- We are a processor, or service provider, for information a practice puts into the system. The practice decides what goes in, why, and how long it stays; we handle it only to run the service the practice asked for, on its instructions.
In plain words: we are responsible for information you send us directly, while information from a practice's patients or leads belongs to the practice, and we handle it as its vendor.
What we collect
- Contact details from website enquiries and booking: name, work email, phone, practice name, and your message.
- Business information about the practice: the practice name, location, services offered, and how its front desk handles calls.
- Call and message content where a practice deploys the system: call audio, recordings, transcripts, SMS and email content, and call metadata such as time, duration and direction.
- Website technical logs: IP address, browser and device type, pages requested, and timestamps.
Why we use it, and our lawful bases
Where a law such as the GDPR applies, each use needs a lawful basis. Ours are:
- Performing a contract: providing the services a practice has signed up for, and answering your booking or enquiry.
- Legitimate business interests: replying to enquiries, keeping our systems working, preventing misuse, and keeping records, weighed against your rights.
- Consent, where required: for some marketing messages and some call recording rules; you can withdraw it at any time.
- Legal obligations: the tax, accounting and other duties that apply to us.
The practice decides the purposes for its own patient and lead data; we handle it only to deliver the service asked for.
Protected health information and the Business Associate Agreement
Where the system handles protected health information on behalf of a practice, AlphaSync acts as a business associate under HIPAA, under a Business Associate Agreement with that practice. It sets out what we may do with the information, how we protect it, and what happens to it when the relationship ends.
The practice is responsible for its own HIPAA compliance and for its own notices to its patients, including how it tells them about call recording, text messaging and automated calls.
AlphaSync does not practise medicine. We do not diagnose, treat or give clinical advice.
Who we share it with: sub-processors and vendors
We use a small number of vendors:
- Cloud hosting, for storing and running the service.
- Voice and telephony, for answering and placing calls.
- SMS and email delivery, for sending messages.
- Scheduling, for calendar and appointment handling.
- Business email and office software, for internal communication.
We do not name every vendor here. We hold a written contract with each, review a vendor before we engage it, and limit what it may do with information it handles for us. A current list of sub-processors is available on request from todd@alphasync.ai.
We may also disclose information where the law requires it, or where a court, a regulator or someone's safety demands it.
How long we keep it, and why
We keep information only as long as we need it for the purpose we collected it, plus any period we must keep it for legal, tax, accounting or contractual reasons. Where no period is set, we delete what we no longer need.
Call recordings, transcripts and message content held for a practice are kept for the retention period that practice sets in its agreement with us, then deleted or returned. Ask us at todd@alphasync.ai how long a record is kept.
How we protect it
We protect information with controls that include encryption in transit and at rest; access controls, so only accounts that should reach a system can reach it; least privilege, so each person and system has only the access its task requires; logging and monitoring; and staff access limited to those who need it.
These are controls, not certifications we claim: we do not claim third-party security certifications, and we will say plainly what we have and have not done if you ask. No system is perfectly secure, and we cannot promise absolute security.
Cookies and tracking
This website sets no advertising cookies, no analytics cookies and no third-party cookies, and we run no advertising pixels or cross-site trackers here. That matches our Cookies policy. If we add measurement that sets a cookie, we will update both pages before it goes live.
Your rights and how to exercise them
Depending on where you live, you may have the right to access the personal information we hold about you; to correct what is wrong; to have information we no longer need deleted; to receive a copy in a portable format; and to object to certain uses.
Email todd@alphasync.ai with what you want. We will ask you to confirm who you are and will answer within the time the law allows.
If you are a patient or a customer of a practice and want to exercise a right over information that practice holds, contact the practice first: it controls that information, and we hold it on the practice's instructions. We will help the practice respond, and will not act without its direction.
Children
Our services are business-to-business software, not directed at children under 16, and we do not knowingly collect their information. If you believe a child has given us information, email todd@alphasync.ai and we will delete what we should not hold.
US state privacy law notice
Several US states have privacy laws giving their residents specific rights. Where they apply to us, we honour them on their own terms, including their own definitions, thresholds and exemptions. Much of what they require is described above.
California
For California residents, the CCPA as amended by the CPRA applies on its own terms. We have collected these categories of personal information:
- Identifiers and contact details: name, work email address, phone number, practice name, IP address.
- Commercial information: services a practice has asked about or bought.
- Internet or network activity: pages requested and timestamps.
- Audio and electronic information: call audio, recordings, transcripts, and SMS and email content, where a practice deploys the system.
- Professional information: the practice you work for and your role.
We collect these categories for the business purposes described above: providing the services, answering enquiries, running and securing our systems, and meeting legal obligations. We do not sell personal information, and we do not share it for cross-context behavioural advertising. The rights above are yours to exercise with us. You may use an authorised agent, and we will not discriminate against you for making a request.
International transfers
AlphaSync is based in the United States, where our systems and vendors operate. Where information is transferred from elsewhere to the United States, we use appropriate safeguards such as standard contractual clauses, together with the contracts we hold with our vendors. Ask us at todd@alphasync.ai which safeguard applies.
Changes to this policy
We may update this policy when our services, our vendors or the law change. We will post the new version here and change the "last updated" date at the top. If a change is significant we will say so. Using the services after an update means the updated policy applies.
Contact
Questions about this policy, or requests about your information, go to todd@alphasync.ai. You can also write to us at AlphaSync LLC, Attn: Privacy, mailing address available on request.