Privacy Policy
Last updated: May 2026
1. Data controller
The data controller for personal data collected through Citria is Touch of Tech, reachable at hello@touchof.tech. Citria is a WhatsApp-based medical scheduling platform operated by Touch of Tech.
2. Data we collect
We collect the following personal data:
- Clinic data: business name, WhatsApp Business number, email address, and doctor and schedule configuration.
- Patient data: name, phone number, and messages exchanged with the Noa assistant to manage appointments.
- Usage data: activity logs within the Citria web dashboard to ensure the service works correctly.
We do not collect medical records, diagnoses, or sensitive health information. Citria manages scheduling information only.
3. Purpose of processing
Data is used exclusively to:
- Provide the automated WhatsApp scheduling service.
- Send appointment confirmations, reminders, and updates to patients.
- Display appointments and conversations in the clinic's web dashboard.
- Improve and maintain the platform.
4. Legal basis
Processing is based on consent and on the performance of the service contract between Citria and the clinic. Patient data is processed on behalf of the clinic, which acts as the controller toward its own patients.
5. Third parties and subprocessors
To provide the service, we share data with:
- Meta (WhatsApp Business API): messages are transmitted through Meta's infrastructure under their own policies.
- Cloud infrastructure providers: for data storage and processing in regions with adequate protection standards.
We do not sell personal data to third parties or use it for advertising purposes.
6. Data retention
Data is retained while the clinic maintains an active Citria account and, after cancellation, for up to 12 additional months for legal and audit purposes. After that period, data is securely deleted.
7. Your rights
You have the right to access, correct, delete, or object to the processing of your personal data. To exercise these rights, email us at hello@touchof.tech with your request. We will respond within 20 business days.
8. Security
We implement reasonable technical and organizational measures to protect data against unauthorized access, loss, or alteration.
9. Changes to this policy
We may update this policy at any time. We will notify you of material changes by email or via a notice in the Citria dashboard with at least 15 days' notice.
10. Contact
For any questions about this policy, email us at hello@touchof.tech.