Effective Date: March 7, 2026
Bit2Sky Inc. ("Company," "we," "us," or "our") provides a family of multi-tenant software-as-a-service (SaaS) communication and healthcare technology products used by businesses and healthcare organizations. This Privacy Policy applies to all Bit2Sky products and services, including:
- HelloThere — a multi-tenant video, voice, and SMS communication platform (video meetings, voice calling, scheduling, and text notifications).
- ClinicShark — a HIPAA-compliant EHR/EMR (electronic health and medical records) platform with AI-assisted clinical documentation.
- HealHub.life — a HIPAA-compliant patient portal for healthcare organizations (appointment access, records, and care communication).
Where a specific product is used to transmit Protected Health Information (PHI), the platform is designed to meet HIPAA safeguards. References to "the platform" or "our services" below apply to whichever Bit2Sky product you are using.
1. Information We Collect
We collect the following types of information across our products:
- Personal Information: Name, email address, phone number, date of birth, and mailing address provided during account registration.
- Health Information: Where a product is used in a healthcare context, Protected Health Information (PHI) as defined by HIPAA, including appointment details, medical records, and clinical notes.
- Communication Data: SMS messages, call logs, and video/voice session metadata.
- Technical Data: IP address, browser type, device information, and usage analytics.
2. How We Use Your Information
We use your information to:
- Provide and maintain the Bit2Sky product you are using
- Send meeting and call join links, appointment reminders, and scheduling confirmations via SMS
- Send one-time verification codes for account security (2FA)
- Send account, care, and service notifications (e.g., missed-call, voicemail, waiting-room, and documentation-ready alerts)
- Facilitate video and voice sessions and clinical documentation workflows
- Improve our services and user experience
- Comply with legal and regulatory requirements, including HIPAA where applicable
3. SMS Communications
Several Bit2Sky products send SMS text messages, each from its own dedicated toll-free number. By providing your phone number and opting in (including by texting a keyword such as START to the applicable product's toll-free number), you consent to receive text messages from that Bit2Sky product. Depending on the product, these may include:
- Meeting and call join links and invitations (HelloThere)
- Appointment and meeting reminders and confirmations
- Account verification codes (one-time passcodes / 2FA)
- Account, care, and service notifications (e.g., documentation-ready, missed-call, voicemail, and waiting-room alerts)
Message frequency: Varies based on your activity within the product. Typically 1–10 messages per month.
Message and data rates may apply. Contact your wireless carrier for details about your messaging plan.
You may opt out of SMS at any time by replying STOP to any message. Reply HELP for assistance, or email [email protected]. Opting out of SMS will not affect your ability to use the underlying Bit2Sky product.
Mobile opt-in data: The mobile phone number and SMS consent you provide will not be sold, rented, or shared with any third parties or affiliates for their marketing or promotional purposes. Text-messaging originator opt-in data and consent will not be shared with any third parties. Service providers that help us deliver messages (such as Azure Communication Services) process this data solely to send the messages you requested.
4. HIPAA Compliance
Where a Bit2Sky product is used to transmit Protected Health Information (PHI), it is designed to comply with the Health Insurance Portability and Accountability Act (HIPAA). We implement administrative, physical, and technical safeguards to protect PHI, including:
- End-to-end encryption for video and voice sessions
- Encrypted data storage and transmission
- Role-based access controls
- Audit logging of all data access
- Business Associate Agreements (BAAs) with all service providers
5. Information Sharing
We do not sell, trade, or rent your personal information. We may share your information only in the following circumstances:
- Healthcare Providers: Where applicable, with your healthcare providers as necessary for treatment, payment, and healthcare operations.
- Service Providers: With trusted third-party service providers who assist us in operating our products (e.g., Azure Communication Services for SMS and calling, cloud hosting), under strict confidentiality and BAA agreements.
- Legal Requirements: When required by law, regulation, or legal process.
- Emergency: To prevent serious harm to you or others.
As stated in Section 3, mobile phone numbers and SMS opt-in consent are never shared with third parties for marketing or promotional purposes.
6. Data Security
We use industry-standard security measures to protect your data, including:
- TLS/SSL encryption for all data in transit
- AES-256 encryption for data at rest
- Multi-factor authentication
- Regular security audits and vulnerability assessments
- Azure cloud infrastructure with SOC 2, HIPAA, and HITRUST certifications
7. Data Retention
We retain your personal and, where applicable, health information for as long as your account is active or as needed to provide services. Medical records are retained in accordance with applicable state and federal regulations. You may request deletion of your account by contacting us.
8. Your Rights
You have the right to:
- Access your personal and, where applicable, health information
- Request corrections to inaccurate information
- Request deletion of your account and data (subject to legal retention requirements)
- Opt out of SMS communications at any time
- Receive a copy of your health records where applicable
- File a complaint if you believe your privacy rights have been violated
9. Children's Privacy
Our products are not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13 without parental consent.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the effective date.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us: