Skip to content

Legal

Privacy Policy

HyperCRM holds clinical records, so this policy is written to be read rather than to be impenetrable. It explains what we collect, the two different roles we play, who else touches the data, and what you can demand of us.

In short

For patient records we act on your practice's instructions; for your own account details we decide ourselves. The sections below set out what is collected, who else touches it, how long it is kept, and what you can ask us to do with it.

Last updated: 15 August 2026

Who we are

HyperCRM is practice management software operated by Hypermetron, the company behind it. Hypermetron is the entity your practice contracts with and the entity that invoices you, and it is the data controller for your billing and account relationship; your practice remains the controller of its own clinical records, with us as processor. For any privacy question, or to request our full legal entity and registration details, write to hello@hypercrm.app — a person answers.

We have not appointed a formal Data Protection Officer. Privacy requests go to the address above and are handled by the team that builds the product, not a ticket queue.

The two roles we play

This is the most important distinction in this policy, and it follows from how the product is built:

  • Your patients' clinical data — your practice is the controller, we are the processor. Patient records, notes, appointments, uploaded files, imaging and invoices belong to the practice that entered them. We process them only to run the service, on your instructions. The Data Processing Agreement sets out those terms.
  • Your account data — we are the controller. What we need to operate the service itself: staff names and email addresses, passkey credentials, and any support correspondence. This policy governs that.

What we collect

Account data. Staff names and email addresses, passkey (WebAuthn) credentials, and the content of messages you send us. We never hold a shared practice password, because sign-in does not use one.

Practice data, on your behalf. Patient demographics, clinical notes, intake and consent responses, uploaded documents, imaging and 3D scans, appointments and invoices. This can include health data, which is special-category data under GDPR Article 9. We do not decide what goes in — your practice does.

Technical data. Server logs and security signals needed to keep the service running and to investigate abuse.

Two fraud signals, and only if you use a referral code. Our referral programme pays a practice for recommending us, so it has to be able to tell a real recommendation from a practice referring itself for the reward. Where a practice signs up with a referral code we record two things about it, both described in full below:

  • The IP address the signup came from, kept for 90 days. A code entered later in settings records no IP at all — only the signup itself does.
  • A card fingerprint, once that practice starts paying. This is worth being precise about: a fingerprint is an opaque token Stripe gives us that identifies a card without revealing it. It is not a card number. We never see, receive or store your card number, expiry date or security code — those go straight to Stripe and stay there. The fingerprint's only use is comparing one referral against another, to see whether the same card is paying for both sides of a referral that claims to be between two independent practices.

Cookies and tracking

We run no advertising trackers and no third-party analytics. Sign-in uses passkeys and short-lived bearer tokens rather than a tracking cookie. Two things do set a cookie, and both are named here rather than left in a footnote:

  • Google reCAPTCHA sets its own cookies, and loads only where a practice has enabled it to protect public booking and form pages.
  • hc_ref, which we set ourselves, if you arrive on this site by a referral link. It is first-party, lasts 90 days, and holds one thing: the referral code that was in the link. It exists because a clinician may follow a colleague's link days before signing up, and without it that recommendation is lost. It is sent to no one else and shared with no one. Until a practice is actually created it identifies nobody — it records that a code was followed, not who followed it — and it is read once, when someone finishes setting up a practice.

Why we are allowed to process it

Account data is processed to perform our contract with your practice, and on our legitimate interest in keeping the service secure. Clinical data is processed solely on your practice's documented instructions — your practice is responsible for its own lawful basis and, for health data, its own Article 9 condition.

The two referral fraud signals rest on legitimate interest, and we would rather name the interest than hide behind the phrase: a referral programme that cannot detect a practice referring itself pays out money it should not, and that money comes from the price everyone else pays. Both signals are limited to that purpose — they are never used to profile you, to market to you, or to work out where you are. You can object to either, at the address above; the referral is then decided without them.

Who else touches it

We do not sell personal data and we do not use your patients' data to train machine-learning models.

We do share it with the service providers that make HyperCRM work. Every one of them is listed at sub-processors, along with what it handles and when it runs — three are essential, three only run if your practice turns them on, and Stripe runs once your practice is on a paid plan. Beyond that list we disclose data only where the law compels us.

Some of those providers are based in the United States, so data reaches them there. They offer the standard transfer safeguards for EU data — Standard Contractual Clauses and, where applicable, EU–US Data Privacy Framework participation. If you need the transfer mechanism documented per provider for your own compliance file, ask us and we will provide what we hold.

How we protect it

In summary: passkey sign-in, owner and assistant roles, an audit log of every change, private file storage reachable only through short-lived signed links, and encryption in transit and at rest. The security page explains each of those properly.

How long we keep it

While your account is open, we keep your data so the service works. After an account closes we keep it for 30 days so an accidental closure is recoverable and you have time to export, then we delete it.

A subscription lapsing is not a closure and deletes nothing. If you cancel, or simply stop paying, the account becomes read-only and we keep your data — indefinitely, with no timer running against you — because clinical records carry retention obligations that are your practice's and an unpaid invoice is not a reason to destroy them. Once a year we email the account owner to say the data is still there and to give the export link and the route to close. The deletion clock starts only when you close the account, which is always something you do deliberately.

The two referral fraud signals have their own, shorter limits, and they are enforced by a nightly job rather than by this paragraph. A signup IP is erased 90 days after the referral was recorded, whatever state that referral is in. A card fingerprint is kept only for the life of the referral record and goes when that record does, with the account it belongs to; the referring practice's own fingerprint is read at the moment of the comparison and never stored at all.

Two caveats worth stating plainly. Clinical records are often subject to a legally mandated minimum retention period in the country where a practice operates — that obligation sits with the practice, and you should not rely on our recovery window to satisfy it. Export before you close. Backups roll off on their own cycle shortly after deletion.

Your rights

You may have rights to access, correct, delete, restrict, port or object to processing of your personal data.

For clinical data, your practice is the controller: patients should ask their practice, and we will help the practice answer. For account data, write to us at the address above. Beyond any legal right, practice data is exportable whenever you like — every list to CSV, every file downloadable, no fee and no waiting period.

If you think we have handled your data badly, tell us first — but you are also entitled to complain to your national data protection authority.

Children

HyperCRM is a tool for clinics, not a service for children to use. Patients may of course be minors, and their records are entered by the practice under the practice's own lawful basis and consent processes.

Changes

This policy will change as the product does. The date at the top always reflects the current version, and we will tell account holders by email before a material change takes effect.

Questions about your data?

Ask a real person. We would rather answer than have you guess.

Contact us