Meta Developer Platform & WhatsApp Business Cloud API Notice
This policy explicitly complies with the Meta Developer Platform Terms and WhatsApp Business Messaging Policy. Docly uses official Meta WhatsApp Cloud API webhooks solely to coordinate appointments between doctors and their patients. We do not sell user data, nor do we use private messaging data for marketing, profiling, or public AI model training.
1. Overview & Introduction
Docly (“Docly,” “we,” “our,” or “us”) operates a specialized multi-tenant software-as-a-service (SaaS) platform allowing registered medical doctors and healthcare practices (“Practitioners”) to connect their official WhatsApp Business phone number to an automated, AI-assisted appointment management assistant.
This Privacy Policy explains how we collect, store, process, and protect information when:
- Practitioners register for, configure, and use the Docly administrative dashboard.
- Practitioners authorize Meta WhatsApp Cloud API and Google Calendar integrations.
- Patients and end-users (“Patients”) send WhatsApp messages to a Practitioner's connected WhatsApp Business number to inquire about clinic timings, book slots, reschedule, or cancel consultations.
2. Data Controller & Contact Information
Depending on your relationship with Docly:
For Practitioners (Doctors):
Docly acts as the Data Controller regarding your account registration, billing data, profile settings, and dashboard configuration.
For Patients (End-Users on WhatsApp):
The Practitioner or clinic whose WhatsApp Business number you are messaging acts as the Data Controller. Docly acts as a secure Data Processor handling messages solely according to the Practitioner's instructions.
If you have questions or wish to exercise data rights, contact our Data Protection Officer at: privacy@docly.health
3. Information We Collect
We only collect information strictly required to facilitate appointment coordination and ensure system reliability:
A. Information Received via Meta WhatsApp Cloud API
- WhatsApp Phone Number & WhatsApp ID: Unique phone number of the patient initiating the conversation.
- WhatsApp Profile Name: The public display name configured on the user's WhatsApp account.
- Inbound Message Content: Text strings sent to request booking dates, available hours, service inquiries, or cancellations.
- Message Metadata: Message delivery timestamps, message IDs (wamid), read receipts, and webhook delivery status.
B. Information Collected from Practitioners
- Account Details: Full name, medical clinic/practice name, email address, password hash, phone number, and clinical specialty.
- Practice Availability & Services: Weekly working hours, appointment durations, consultation fees, buffer times, and clinic address.
- Integration Credentials: WhatsApp Business Phone Number ID, WhatsApp Business Account ID (WABA ID), and OAuth tokens for Google Calendar synchronization.
C. Appointment & Booking Records
- Scheduled Consultations: Patient name, chosen clinic service, appointment start/end time, status (Confirmed, Rescheduled, Cancelled, Completed).
- Patient Administrative Notes: Any specific non-clinical notes provided during booking (e.g., “first-time consultation”).
4. How We Use Collected Information
We use collected data solely for the following explicit purposes:
1. Automated Appointment Scheduling
Parsing patient scheduling requests in WhatsApp, checking doctor availability, reserving calendar slots, and confirming bookings.
2. Real-Time Calendar Sync
Syncing confirmed, updated, or canceled appointments directly into the doctor's authorized Google Calendar to prevent double-booking.
3. Automated Reminders & Notices
Sending automated WhatsApp appointment reminders (e.g., 24 hours and 2 hours prior) to minimize clinic no-shows.
4. Security, Audit & Fail-Closed Verification
Verifying Meta HMAC-SHA256 webhook signatures and ensuring strict tenant isolation so data never leaks between different doctors.
5. Artificial Intelligence & Large Language Model (LLM) Processing
Strict Commercial API Zero-Data-Retention Commitment
Docly utilizes enterprise-grade AI models (such as OpenAI GPT-4o API) solely to understand natural language booking inquiries (e.g. “Can I book Dr. Smith for Thursday 4pm?”) and generate polite responses.
- No Public Model Training: Under our enterprise API agreements, your inputs, messages, and outputs are never used by OpenAI or any third party to train or fine-tune public foundational models.
- Ephemeral Processing: Inquiries sent to the AI API are processed ephemerally solely for the purpose of answering the immediate scheduling inquiry.
- Deterministic Safeguards: Real-time booking decisions, slot availability, and doctor credentials are strictly controlled and verified by our backend server database, not by unsupervised AI.
6. Third-Party Service Providers & Data Processors
We share data with trusted third-party subprocessors strictly to operate our platform infrastructure:
| Provider | Purpose | Data Shared | Privacy Link |
|---|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business Cloud API messaging & webhooks | WhatsApp phone numbers, message payloads, status | Meta Terms |
| OpenAI, LLC | Natural language intent extraction & response generation | Message text of appointment inquiry (API zero-retention) | OpenAI Enterprise |
| Google LLC | Google Calendar API event synchronization | Appointment times, summary title, patient identifier | Google Privacy |
| Secure Cloud Infrastructure | Encrypted PostgreSQL database, Redis queues & hosting | Encrypted application databases and audit trails | SOC2 / ISO27001 |
7. Data Retention & Storage
We adhere to strict data minimization principles:
- Appointment Records: Maintained for the duration of the Practitioner's active account subscription to allow appointment tracking and historical clinic reporting, or until deleted upon request.
- WhatsApp Message Transcripts: Stored securely to provide conversation context during active scheduling dialogues. Transcripts are purged in accordance with clinic retention policies or within 30 days of an approved data deletion request.
- Account Termination: If a doctor closes their Docly account, all associated clinic data, WhatsApp webhook bindings, and calendar integration tokens are permanently eradicated from active databases within 30 days.
8. Your Rights & How to Exercise Them (GDPR & CCPA)
Under data protection laws and Meta developer guidelines, you have guaranteed rights regarding your personal data:
Follow our Meta-compliant instructions or submit an instant deletion ticket.
9. Technical & Operational Security Measures
We implement rigorous defense-in-depth technical safeguards to secure customer data:
- HMAC-SHA256 Webhook Verification: Every incoming Meta WhatsApp webhook is cryptographically validated against our Meta App Secret. Unsigned or invalid requests are instantly rejected.
- Fail-Closed Tenant Isolation: Every database query is strictly scoped to the verified
doctor_idassociated with the destination WhatsApp phone number. Cross-tenant queries are structurally disallowed by architecture. - Encryption: All data in transit is encrypted using TLS 1.3. Sensitive tokens (Google OAuth refresh tokens, WhatsApp access tokens) and database volumes are encrypted at rest using AES-256.
- Authentication & JWT Rotation: Secure short-lived JSON Web Tokens (15-minute access tokens) with rotating refresh tokens for dashboard practitioners.
10. Children's Privacy
Docly is intended for use by certified healthcare practitioners and adult patients. We do not knowingly solicit or collect personal information directly from children under the age of 13 (or under 16 in the European Union) without parental or guardian consent. When appointments are booked for pediatric patients, the booking must be conducted by the parent or legal guardian.
11. Contact & Regulatory Inquiries
For privacy inquiries, Data Protection Officer contact, or compliance verification by Meta App Review teams: