Oriste AI

Privacy Notice

Last updated: 2026-08-18-r2

Internally reviewed for a limited pilot. Independent legal review is required before public self-service sales.

This notice explains how HAGERSTANT LTD, the operator of Oriste AI, uses personal data about website visitors, prospective customers, clinic owners and staff. HAGERSTANT LTD is a limited liability company incorporated in the Republic of Cyprus (registration no. HE 496930) with registered office at Strovolou 77, Strovolos Center, 4th floor, Flat/Office 401, 2018 Strovolos, Nicosia, Cyprus. Privacy questions can be sent to privacy@oriste.ai. This is our privacy contact point; we have not appointed it as a statutory data protection officer.

1. When we are controller and when we are processor

We act as controller for our website, sales enquiries, business accounts, billing, service security, support and legal records. A clinic is the controller for its patient and client data; we process that data only for the clinic under our Data Processing Agreement. Patients should normally direct privacy requests to their clinic, which can instruct us to assist.

2. Data we collect

In the clinic-controlled service we may process patient names, phone numbers, appointment details, messages, voice notes, images and health-related information according to the clinic's instructions. We do not use this data for our own advertising or authorise it for training general-purpose AI models.

3. Purposes and legal bases

The clinic, not Oriste AI, determines the Article 6 basis and any Article 9 condition for patient data. The service is not intended to make solely automated decisions that produce legal or similarly significant effects.

4. Recipients and international transfers

We disclose data only to authorised personnel, professional advisers, authorities where legally required, and service providers needed to operate Oriste AI. The current product scope and runtime status are shown in our sub-processor register. Application and primary database hosting are in the EEA. Where a provider processes data outside the EEA, we require an applicable Chapter V GDPR mechanism and assess supplementary safeguards where required before enabling patient-data processing.

Our use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide the calendar synchronisation requested by the connected business. We do not sell it, use it for advertising, or use it to train general-purpose AI models. An authorised business owner can disconnect Google Calendar in Business settings; this revokes our access and removes the local synchronisation buffer under the applicable deletion workflow.

5. Retention

A documented legal hold may temporarily pause deletion for specifically identified records. Backups expire on their controlled rotation and are not restored for ordinary use after a deletion request.

6. Cookies

We currently use only cookies and equivalent storage that are necessary for sessions, authentication, security and checkout continuity. We do not currently use optional advertising or cross-site tracking cookies. If that changes, this notice and the consent controls will be updated before those technologies are enabled.

7. Your rights and data-deletion requests

Depending on the circumstances, you may request access, correction, erasure, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. We may need to verify identity and may retain limited information where the law requires it. You may also complain to the Cyprus Commissioner for Personal Data Protection or the supervisory authority where you live or work.

To request deletion, email the privacy contact above from your account email and identify the clinic or business concerned; do not include patient health information. If the request is for clinic-controlled patient data, contact the clinic directly or tell us which clinic should receive the request. We will acknowledge the request, verify identity proportionately, route it to the correct controller and explain completion or any lawful limitation.

8. Security, changes and contact

We use encryption, access controls, tenant isolation, audit logging, limited retention and incident procedures appropriate to the service. No system is completely secure. We will update this notice when our processing materially changes and will notify account owners when required. Contact us at privacy@oriste.ai.