Introduction
Welcome to Siimplo, a comprehensive business management platform that enables service providers — including fitness studios, veterinary clinics, and health professionals — to manage their operations and maintain continuous communication with clients. This Privacy Policy explains how we collect, use, share, and protect your information.
Siimplo consists of two main portals: the Provider Portal for business management and CRM, and the Client Portal for accessing services and maintaining communication with providers. Both portals work together to create a seamless experience for all users.
By using Siimplo, you agree to the collection and use of information in accordance with this policy. We are committed to protecting your privacy and ensuring the security of your personal information.
Information We Collect
Provider Information
- Business details, services offered, and availability settings
- Professional credentials, specialties, and qualifications
- Contact information and business location
- Agenda, appointments, and scheduling preferences
Client Information
- Personal identification and contact details
- Appointment history and visit records
- Communication preferences and messages
- Documents and files shared with providers
Information Collected Automatically
- Usage data and analytics to improve our services
- IP addresses and device information for security
- Browser type and operating system for compatibility
How We Use Your Information
We use your information to provide, maintain, and improve our services:
- Facilitate appointment scheduling and management
- Enable secure messaging between providers and clients
- Process payments and manage subscriptions
- Send appointment reminders and important notifications
- Improve our platform through analytics and user feedback
- Ensure security and prevent fraudulent activities
Google Calendar Integration
Siimplo integrates with Google Calendar to provide seamless appointment synchronization. We are committed to protecting your Google data and using it only for the purposes you authorize.
Google Limited Use Disclosure
Siimplo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for any purpose other than providing and improving the calendar synchronization feature.
How We Use Your Google Calendar Data
When you connect your Google Calendar, we access and use your data ONLY for the following specific purposes:
- Reading your Google Calendar events to prevent scheduling conflicts (when you enable the 'Block calendar from Google' setting)
- Creating appointment events in your Google Calendar (when you enable the 'Sync appointments to Google' setting)
- Updating or deleting appointment events in your Google Calendar when you modify or cancel appointments in Siimplo
- Accessing your Google email address to identify your connected account
Permissions We Request from Google
To enable calendar synchronization, we request the following permissions from your Google account:
View your calendar events
This allows us to read your Google Calendar events and automatically block conflicting time slots in Siimplo, preventing double-bookings
Manage your calendar events
This allows us to create, update, and delete appointment events in your Google Calendar when you book, modify, or cancel appointments in Siimplo
View your email address
This allows us to identify which Google account is connected to your Siimplo profile for proper synchronization
How We Protect Your Google Data
- Google Calendar data is used exclusively for calendar synchronization and is NOT used for analytics, marketing, or any other purpose
- Your Google access tokens are encrypted using industry-standard AES encryption before storage
- We automatically refresh your access tokens to maintain secure connections
- Your Google Calendar data is NOT shared with any third-party services or analytics providers
- You can disconnect your Google Calendar at any time from your provider settings
- When you disconnect Google Calendar, we immediately delete all stored Google access tokens
Data Retention
We store your encrypted Google access tokens only as long as your Google Calendar integration is active. Event IDs are stored to track which appointments have been synced. When you disconnect your Google Calendar, all stored tokens are permanently deleted. Synced appointment data in Siimplo remains for your business records, but the connection to Google is completely severed.
Your Control
You have complete control over the Google Calendar integration. You can enable or disable specific sync features (blocking from Google, syncing to Google), disconnect your Google account at any time, and revoke Siimplo's access through your Google Account settings at any time.
YouTube Integration (Fitness)
The Fitness vertical of Siimplo includes a Training Module that allows fitness providers to upload training videos directly to their own YouTube channel. This integration is available exclusively to fitness providers and is used solely for video publishing.
Fitness-Only Feature
The YouTube integration is only available within the Fitness (Clases y Bienestar) vertical. Veterinary and Health verticals do not use this integration.
How the YouTube Upload Works
When you connect your YouTube channel as a fitness provider, Siimplo uses your authorization exclusively to:
- Upload training videos from the Training Module directly to your YouTube channel on your behalf
- Read your YouTube channel identifier to confirm the connected account
No Third-Party Processing
We do not process, analyze, transcode, store, or use your video content in any way beyond sending it to YouTube. Video files are transmitted directly to the YouTube API using your credentials and are not retained on our servers after the upload completes. No third-party tools or services are involved in handling your video content.
How We Protect Your YouTube Credentials
- Your YouTube OAuth access tokens are encrypted using industry-standard AES encryption before storage
- Tokens are used exclusively to authenticate video uploads to your channel — for no other purpose
- We automatically refresh your access tokens to maintain a secure connection
- You can disconnect your YouTube account at any time from your provider settings
- When you disconnect, all stored YouTube access tokens are immediately deleted
Your Control
You have complete control over the YouTube integration. You can connect or disconnect your channel at any time. Revoking access through your Google Account settings will also immediately terminate Siimplo's ability to upload on your behalf.
AI & Machine Learning
Siimplo uses artificial intelligence to enhance certain platform features. We are committed to transparency about how AI is integrated into our services and how your data interacts with AI systems.
AI Providers
Our AI features use more than one external provider, depending on the feature. Ryo's conversational engine — our in-platform AI assistant — uses Anthropic (Claude) or OpenAI; which one answers is a platform-wide configuration, not something you choose. The internal search that grounds Ryo's answers always uses OpenAI's embedding models, regardless of which provider is conversing. Receipt validation — an optional feature each provider turns on per payment method — uses Fal.ai to read the receipt image and Anthropic to check it against that payment method's data. The AI record summary — an optional AI helper — uses Anthropic to write a summary of a patient's clinical records. No provider receives more data than what is described below.
What AI Is Used For
AI is used exclusively for the following features within Siimplo:
- Receipt validation — an optional feature each provider turns on per payment method (off by default). When enabled, AI reads the receipt image and checks it against that payment method's data — account holder, bank, CBU/CUIT, and expected amount — to catch duplicates and confirm it matches
- Ryo, the AI assistant — a conversational assistant built into the portal (a paid-plan feature, off by default) that answers questions about using the platform based on our documentation. To answer with context, it sees the current conversation history and limited profile data — see below.
- AI record summary — an optional AI helper, available only on plans that include AI helpers. Nothing is sent unless a provider chooses a patient and a period and presses "Write summary"; AI then writes a narrative of that patient's clinical records from the period — see below.
What Ryo, the AI Assistant, Sees
When you talk to Ryo, we send the history of that conversation and a limited selection of your profile data so responses have context: for providers, name, email, specialties, business address, and bio; for clients, email and country. Ryo has no access to clinical data, passwords, payment information, or other providers' or clients' data, and its answers are grounded in our platform documentation.
What the AI Record Summary Sends
The AI record summary is optional: nothing is sent to an AI provider until a provider, on a plan that includes AI helpers, chooses a patient and a period of months and presses "Write summary".
- What is sent: up to 150 of that patient's clinical records from the chosen period (the most recent ones, if the period holds more) are sent to Anthropic, our AI provider, to write the summary. That covers consultation notes (reason, history, description, diagnosis, treatment and vitals); the names, results and observations of vaccines, exams and procedures; prescription drug lines; and the wording of certificates. Each free-text field is cut at 2,000 characters.
- Identity data: no identity field — name, email, phone or document number — is sent on its own. The text itself can still name people: certificate wording carries the owner's and the patient's names, and free text is sent as the professional wrote it.
- Storage: the summary that comes back is saved in Siimplo, encrypted at rest, and the provider can delete it at any time. The PDF is generated each time it is requested and is not stored.
- Review: the summary is written by AI. The provider must check it against the records before relying on it, and remains responsible for how it is used. Writing a summary never changes the records themselves.
- Consent: because the feature is optional, the provider is responsible for having whatever consent from their patients or clients the laws of their jurisdiction require before using it.
Data Separation from Google & YouTube
AI features operate completely independently from all Google integrations. Specifically: Google Calendar data is NEVER sent to or processed by AI services. YouTube video data is NEVER sent to or processed by AI services. OAuth tokens and Google account credentials are NEVER shared with AI providers. The AI system has no access to any Google or YouTube user data whatsoever.
No Training on User Data
Your data is never used to train or fine-tune AI models. All AI processing is done via Anthropic's and OpenAI's commercial APIs, whose terms state that they do not use API inputs to train their models. Data we send is used solely to generate each response.
Data Minimization
We send data to an AI provider only for features the provider has turned on. For receipt validation, enabled per payment method, we send the receipt image to Fal.ai, and to Anthropic the data read from the receipt together with that payment method's data — account holder, bank, CBU/CUIT, expected amount — and recent transfer IDs, to catch duplicates. For Ryo, the current conversation history and the limited profile data described above are sent. For the AI record summary, only the clinical records of the patient and period the provider chose are sent, as described above, and only when the provider asks for a summary. Outside that feature, we never send clinical data to an AI provider, and we never send passwords or card numbers to one.
Data Security
We implement industry-standard security measures to protect your information:
- Encryption of data in transit using HTTPS
- Storage with encryption at rest: fields holding clinical content and sensitive personal data — notes, diagnoses, treatments, prescriptions, certificates, allergies, emergency contact, insurance details and message content — are stored as AES-256-GCM ciphertext in the database, field by field. The identifiers, dates and names the system needs to locate a record remain readable. This is not end-to-end encryption: the platform decrypts these fields in order to show them to you.
- JWT-based authentication with refresh tokens
- Secure cloud storage for file handling
- Regular security audits and updates
- Data secured on SOC 2 and HIPAA compliant infrastructure
Information Sharing
We do not sell your personal information. We share information only in the following circumstances:
- Between providers and their connected clients for service delivery
- With payment processors (like Stripe) to handle transactions
- With infrastructure and cloud service providers necessary to operate the platform
- When required by law or to protect rights and safety
- With your explicit consent for specific purposes
Google Calendar Data Protection
Data obtained from Google Calendar integration is NEVER shared with third parties. Google Calendar data is used exclusively within Siimplo for calendar synchronization purposes and is stored securely with encryption. This data remains within our secure infrastructure and is not transmitted to any external services.
Your Rights
You have the following rights regarding your personal information:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Portability: Export your data in a machine-readable format
- Opt-out: Ask your provider to stop promotional messages, use WhatsApp's own controls, or close your account (see Account Deletion)
Account Deletion: To delete your account, please contact our support team at [email protected]. We will process your request within 30 days and remove all personal information, except where retention is required by law.
Communication Features
Our platform enables various communication features:
- Secure messaging between providers and clients
- File attachments and document sharing (up to 10MB per file)
- Appointment reminders via email, WhatsApp and in-app notifications
- System notifications for important updates
- Promotional messages, such as invitations to book again, sent at your provider's discretion. You can ask your provider to stop sending them, use WhatsApp's own controls for promotional messages, or close your account to stop all communications (see Account Deletion).
Payment Information
We work with trusted payment processors to handle financial transactions:
- Payment information is processed securely through Stripe
- We do not store credit card numbers on our servers
- Subscription and billing history is retained for accounting purposes
Children's Privacy
Siimplo is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected].
International Data
Your information may be transferred to and maintained on servers located outside of your country. By using Siimplo, you consent to such transfers. We ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the 'Last Updated' date. For significant changes, we will provide additional notice through email or in-app notifications.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us: