Privacy Policy
Neleres provides a hosted electronic medical record (EMR) platform to healthcare clinics. This policy explains how we handle the information we process — both the protected health information (PHI) we hold on behalf of our clinic customers and the information we collect directly through our website and accounts.
Our two roles
Most of the data on the Neleres platform is health information that belongs to a clinic and its patients. For that data, Neleres is a Business Associate under the U.S. Health Insurance Portability and Accountability Act (HIPAA): the clinic is the covered entity that controls the information, and Neleres processes it only to deliver the EMR service under a signed Business Associate Agreement (BAA).
Separately, we handle a limited amount of information we collect directly — for example, when someone visits nlrs.com, requests a demo, contacts support, or holds a Neleres account. The sections below describe both.
Protected health information we process for clinics
- PHI on the platform belongs to the clinic. We use it only to provide, maintain, and support the EMR service on the clinic's behalf, and only as permitted by our BAA with that clinic and by HIPAA.
- We do not sell PHI, use it for advertising, or use it for our own purposes. Where assistant features send content to an AI inference provider, that content is not used to train models under our configured inference accounts.
- Each clinic's data is isolated in its own database, with no cross-tenant references by design and every application query scoped to a single clinic.
Information we collect directly
- Website and contact forms. When you contact us or request a demo, we collect what you provide — typically your name, email address, clinic, and message — so we can respond. Please do not include patient health information in these forms.
- Account information. For clinic staff and other account holders, we process the account details needed to authenticate you and operate the service.
- Operational logs. We keep standard server and security logs (such as IP address and request metadata) to run the site securely and diagnose problems.
We do not sell this information, and we use it only to operate Neleres, respond to you, and keep the service secure.
Where data lives and how it is protected
Production data is hosted on Google Cloud Platform in the United States
(primary region us-east4) under an executed Business Associate
Agreement. Clinic data is stored in dedicated, per-tenant Cloud SQL
Postgres databases. We encrypt data at rest with AES-256 (Google-managed
keys) and protect it in transit with TLS 1.2 or higher. Workforce access requires multi-factor
authentication and is granted only after training, verification, and
Security Officer approval scoped to specific clinics and roles. Every read
and change to PHI is recorded in a tamper-evident audit log. For more
operational detail, see our customer security overview, available on
request through the address below.
Subprocessors
We engage a small set of subprocessors to handle specific categories of data on our behalf: Google Cloud (core infrastructure), Mailgun (email), Telnyx (SMS), the clinic-elected payment gateway (one of Helcim, Stripe, Square, or Paya), and AI inference providers (Anthropic and Google Gemini) for assistant features. Every subprocessor that handles PHI is bound by a Business Associate Agreement that imposes substantially the same protections we accept under our BAA with each clinic. We notify clinics in advance of material changes to this list per BAA terms.
If you are a patient
Your medical record is held by your clinic, which is the covered entity responsible for it. Your clinic's Notice of Privacy Practices describes how your information is used and disclosed and explains your rights — including access, amendment, an accounting of disclosures, restrictions, and confidential communications. To exercise those rights, file a complaint, or ask how your record is used, please contact your clinic directly. Neleres acts only on your clinic's instructions and will route requests we receive to the appropriate clinic.
Retention and deletion
We retain clinic PHI for as long as the clinic's BAA and instructions require. On termination of service, we return or delete clinic data as directed by the BAA. Audit logs are retained for interactive query in the per-tenant database and archived to immutable storage for multi-year retention. Information we collect directly is kept only as long as needed for the purpose it was collected or as required by law.
Breach notification
If a breach of unsecured PHI occurs, we notify each affected clinic without unreasonable delay and no later than 60 days from discovery, with the detail required under our BAA so the clinic can meet its own notification obligations.
Changes to this policy
We may update this policy as our practices or the law evolve. When we do, we will revise the effective date above, and we communicate material changes that affect clinics through the channels set out in the BAA.
How to reach us
For privacy questions, requests, or to report a concern, write to our designated Security and Privacy Officer at compliance@nlrs.com.