Legal

Privacy Policy

Effective July 30, 2026

Su Information Technologies LLC, doing business as Suithera

Two audiences, two roles

This policy covers our website visitors and the clinicians who hold Suithera accounts (“customers”). For that information, Suithera decides how data is handled and this policy governs.

If you are a client of a practice that uses Suithera, your clinician is the HIPAA Covered Entity and controls your records; Suithera processes them only on your clinician’s instructions as their business associate, under a business associate agreement. Your clinician’s own Notice of Privacy Practices governs your protected health information (PHI), and requests about your records should go to your clinician — we support them in fulfilling those requests.

Information we collect

How we use information

To provide, secure, and support the service; to meet legal obligations; to bill subscriptions; and to send transactional notifications — such as appointment reminders by email or text message where the recipient has opted in. We do not sell or share personal information, and we do not use it for third-party advertising.

How we share — subprocessors

We disclose information only to the service providers that run Suithera, when a clinician directs us to, or when the law requires it. Our infrastructure subprocessors:

WE DO NOT SELL OR SHARE YOUR PERSONAL INFORMATION.

Security

Data is encrypted in transit (TLS) and clinical fields are encrypted at rest (AES-256-GCM). Access to records is written to an append-only audit log that cannot be deleted, and production access is restricted and role-scoped.

Retention and deletion

Clinical records are retained according to each clinician’s configured retention policy and applicable law. When an account is closed, the customer has a 30-day window to export their data, as described in our Terms of Service.

Your choices — email and text messages

Appointment-reminder text messages are sent only to clients whose clinician enabled reminders and who consented to receive them. Message frequency varies with your appointment schedule. Message and data rates may apply. Reply STOP to any message to opt out at any time, or HELP for help. Consent is not a condition of receiving care. See the full SMS Terms.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.

Your rights under state law

Residents of Colorado, California, Connecticut, Florida, Oregon, Texas, Utah, Virginia, and other states with consumer privacy laws may have the rights to access, correct, delete, and obtain a portable copy of their personal information, to opt out of targeted advertising or sale (we do neither), and not to be discriminated against for exercising these rights. We honor Global Privacy Control signals. To exercise a right, email privacy@suithera.com; we respond within 45 days. Note that PHI processed for a clinician is governed by HIPAA and your clinician’s notice, not these state laws.

Children

Our website and accounts are not directed to children under 13, and we do not knowingly collect their information — records about minor clients exist only where a clinician creates them in the course of care, under the clinician’s control.

Where the service runs

Suithera is operated from the United States and hosted in United States Azure regions. The service is intended for use by clinicians practicing in the United States.

Changes and contact

Material changes will be posted here with a new effective date. Questions: privacy@suithera.com. See also our Terms of Service and SMS Terms.