Privacy Policy
Effective 28 August 2026
This policy explains what LYNT-X GLOBAL TECH LIMITED ("Minnato", "we") does with personal information when you visit our websites or use our platform. It is written for the people who run a practice or an agency. It is not the notice your patients receive — that remains yours to give.
1The distinction that governs everything below
Two different kinds of information pass through Minnato, and they are governed by two different documents.
Your information — the account you hold, the people at your organisation who log in, what you are billed, how you use the product. That is what this policy covers, and for it we are the controller.
Patient information — what a patient types into a form, says on a call, or uploads as a document. We handle that solely on your instructions as your business associate and processor. It is governed by the Business Associate Agreement and, where applicable, the Data Processing Addendum, not by this policy. Where those documents and this one differ on patient information, those documents win.
2What we collect about you
- Account details — name, work email, telephone number, job title, the organisation you belong to, and your password in hashed form.
- Billing details — your plan, invoices, and payment status. Card numbers go directly to Stripe and never reach our servers.
- Usage records — which pages of the console you opened, which actions you took, and when. Every action affecting patient data is written to an audit log that you can read and we cannot quietly alter.
- Support correspondence — what you write to us, and our replies.
- Technical records — IP address, browser and device type, and timestamps, captured in server logs for security and troubleshooting.
3What we do not do
We do not sell personal information, and we do not share it with anyone for their own advertising. We do not use patient information to train models, to improve our product, or for any purpose other than delivering the service you asked for.
Our patient-facing form pages load no third-party code — no tag manager, no advertising pixel, no font service, no session recording. This is a deliberate design decision, and we will issue you a signed, timestamped scan of your own form page that demonstrates it.
4Why we are allowed to hold it
Where the UK or EU General Data Protection Regulation applies, we rely on these legal bases:
- Performance of a contract — to give you the service you have subscribed to.
- Legitimate interests — to secure the platform, prevent abuse, and understand how the product is used, balanced against your rights.
- Legal obligation — to keep financial records and respond to lawful requests.
- Consent — for marketing email, which you may withdraw at any time without affecting your service.
We are established in the Dubai International Financial Centre and also process personal data in accordance with DIFC Data Protection Law No. 5 of 2020.
5Who else sees it
We share personal information only with the service providers listed in our sub-processor table, each under a written contract that limits them to our instructions. We will also disclose information where the law compels us, and we will tell you when we are permitted to.
If our business is sold or merged, your information may transfer to the acquirer. The obligations in this policy travel with it.
6Where it goes
Patient information is processed and stored in the United States, in Amazon Web Services' us-east-1 region, under a Business Associate Agreement accepted on 25 August 2026 and using only services AWS designates as HIPAA-eligible.
Our company is established in the DIFC, and the United Arab Emirates does not hold an adequacy decision from the European Commission or the United Kingdom. Transfers of personal data out of the EEA or the UK therefore rely on Standard Contractual Clauses, together with the technical measures described in our Data Processing Addendum — principally that patient information is encrypted with a key held per customer, so it is unreadable to anyone who obtains the ciphertext alone.
7How long we keep it
Account information is kept for as long as you are a customer, and for six years afterwards where we must retain records to meet legal and accounting obligations. Server logs are kept for ninety days. Patient information is kept for the retention period you configure, and is then purged in full — the encrypted payload, attachments, call summaries and submission context together.
When your account closes, we destroy the encryption key belonging to your practice. Because that key is unique to you, the remaining ciphertext is unreadable by anyone, ourselves included, and it cannot be reconstructed from backups.
8What you can ask us to do
Subject to the law that applies to you, you may ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable form. You may also complain to your data protection authority.
If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA, we have not done so in the preceding twelve months, and we will not discriminate against you for exercising your rights.
If your request concerns information a practice holds about a patient, we will direct it to that practice, because the practice — not Minnato — decides what happens to it.
Write to privacy@minnato.ai. We answer within thirty days.
9Cookies
Our patient-facing form pages set no cookies at all. Our marketing site and console set only what is necessary to keep you signed in, to remember your preferences, and to protect against cross-site request forgery. We use no advertising or cross-site tracking cookies anywhere.
10Security
Our security measures are described in full on our security page. To report a vulnerability, write to security@minnato.ai; we confirm receipt within one business day and do not pursue researchers acting in good faith.
11Children
Minnato is sold to organisations, not to individuals, and our console is not directed at children. Patient information about a minor may of course pass through a form your practice operates; that information is handled under the Business Associate Agreement on your instructions.
12Changes
If we change this policy in a way that materially affects you, we will email the account's administrators at least thirty days beforehand. The effective date at the top always reflects the current version.
13Contact
LYNT-X GLOBAL TECH LIMITED, [Registered office, DIFC, Dubai, UAE]. Privacy questions to privacy@minnato.ai; anything else to legal@minnato.ai.
Start by finding out what your websites are leaking.
A free scan of any practice site tells you in ninety seconds which trackers are loading on pages that collect patient information. No account, no card.