Legal

Privacy Policy

Last Updated: August 18, 2026

This Privacy Policy explains how Finit Systems Inc., a corporation organized under the laws of the State of New York ("Finit Systems," the "Company," "we," "us," or "our"), collects, uses, processes, discloses, and protects personal information and Protected Health Information ("PHI") in connection with EZAppointo, a platform developed, owned, and operated by Finit Systems, including its scheduling, messaging, and telehealth video consultation services (the "Platform").

EZAppointo is a product and brand of Finit Systems Inc. The Platform is designed to meet healthcare privacy expectations and incorporates administrative, technical, and operational safeguards.

1. Role of Finit Systems

Finit Systems provides the EZAppointo Platform as software infrastructure for healthcare Providers.

  • Providers are the data controllers of patient medical and appointment data.
  • Finit Systems acts as a data processor or service provider on behalf of Providers.

Finit Systems is not a healthcare provider and does not diagnose, treat, or provide medical care.

2. Information Collected

Patient Data:

  • Name, phone number, email;
  • Appointment date, time, provider, location;
  • short lived, 24 hour deletion policy;
  • Communications metadata.

Provider Data:

  • Provider name, clinic name, contact information;
  • Account credentials;
  • Scheduling configurations.

Technical Data:

  • IP address;
  • Device identifiers;
  • Log activity.

Payment Data:

  • Stripe payment tokens;
  • Subscription billing information;
  • Transaction metadata.

Finit Systems does not store full credit card numbers.

Video Consultation Data:

  • Session timestamps;
  • Connection diagnostics;
  • In-session communications.

Sessions are not recorded by default.

3. Protected Health Information (PHI)

Finit Systems may process PHI on behalf of Providers.

Finit Systems implements safeguards including:

  • access control restrictions;
  • encryption in transit;
  • authentication protections; and
  • monitoring and logging.

Providers are responsible for determining the PHI content entered into the Platform.

4. HIPAA Compliance and Business Associate Role

Where applicable under U.S. law, Finit Systems may function as a Business Associate with respect to PHI processed through the EZAppointo Platform.

Providers must execute a Business Associate Agreement with Finit Systems where required.

Finit Systems processes PHI solely to provide Platform services and does not use PHI for advertising or resale.

Providers are responsible for HIPAA compliance in their clinical workflows.

5. SMS Reminders and Communication

Finit Systems sends transactional SMS messages through the EZAppointo Platform to users who have explicitly opted in during the appointment booking or account registration process. Message types include appointment confirmations, appointment reminders, rescheduling notifications, video consultation links, and one-time verification (OTP) codes.

Opt-In: Customers can opt-in to receive SMS messages from the EZAppointo Platform by providing their phone number and checking the SMS consent checkbox through any of the following methods:

  • During the initial customer registration process.
  • When submitting a guest booking form.
  • By updating their preferences within their user profile settings.

Message Frequency: Message frequency varies based on your appointment activity.

Message & Data Rates: Standard message and data rates may apply depending on your mobile carrier plan.

Opt-Out: You can opt out of SMS communications from the EZAppointo Platform at any time through either of the following methods:

  • Via Text: Reply STOP to any message you receive from us. You will receive one final confirmation message, after which no further messages will be sent.
  • Via Profile Settings: Log into your account and uncheck the SMS consent checkbox in your user profile.

Help: Reply HELP to any message or contact us at info@finitsystems.com for assistance.

Carriers: SMS messages are transmitted via third-party telecommunications providers. Delivery cannot be guaranteed. Finit Systems is not liable for delayed or undelivered messages.

5.1 SMS Consent and Data Sharing

We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. We may share your Personal Data, including your SMS opt-in or consent status, with third parties that help us provide our messaging services, including but not limited to platform providers, phone companies, and any other vendors who assist us in the delivery of text messages.

Important Data Exclusion: All of the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.

6. Data Retention

We retain personal data only for the minimum period required to provide the Services or, where a specific legal retention obligation applies, for no longer than that obligation requires. Where no law sets a floor, we default to the shortest period needed for the operational purpose and delete the data afterward.

6.1 Account and Profile Data

No specific law mandates a retention period for general account/profile data. Retained while your account is active; deleted or de-identified within 30 days of account closure or a deletion request, except where Section 6.6 applies.

6.2 Appointment and Scheduling Data

Where this data constitutes, or is associated with, protected health information handled on behalf of a healthcare provider: retained for six (6) years from the date of creation or last use — the minimum required under the HIPAA Security Rule (45 CFR § 164.316(b)(2)(i)) — or such longer period as applicable state law or your practice's own legal obligations require. We do not retain PHI longer than this floor on our own initiative.

Where this data does not involve PHI (e.g., a booking with a non-healthcare provider such as a salon or trainer): no specific retention law applies. Deleted within 30 days of account closure, consistent with Section 6.1.

6.3 Call Audio, Transcripts, and Voice-Agent Data

No law mandates a minimum retention period for booking-call audio of this kind. Default retention is 90 days from the call date, after which it is automatically deleted, unless the practice using the Services configures a different period to meet its own compliance obligations.

6.4 Payment Data

Finit Systems Inc. does not store full payment card numbers; that data is held by our PCI-DSS compliant payment processor under its own retention schedule. We retain transaction metadata (amount, date, status) for three (3) years from the date of the transaction, consistent with the IRS's general recommended record-retention period (IRS Publication 583) and standard New York State sales-tax record-keeping practice, after which it is deleted. (Final period to be confirmed with our NY sales tax preparer given the §186-e excise-tax gray area noted internally.)

6.5 Security, Access, and Audit Logs

Retained for six (6) years — the minimum required under the HIPAA Security Rule for documentation of security-related actions, activities, and assessments — after which they are securely deleted or archived in de-identified form.

6.6 Legal, Backup, and Compliance Retention

Where data is subject to a legal hold, active dispute, audit, or a lawful request from a regulator or law enforcement, we retain only that specific data, only for the duration of the underlying matter, and delete it within 90 days after the matter concludes. Data in routine encrypted system backups is purged on a fixed 90-day rolling cycle from the date of the corresponding live-system deletion.

6.7 Deletion Requests

You may request deletion of your personal data by contacting us using the details in Section 12. We will honor deletion requests except to the extent retention is required under Section 6.2, 6.5, or 6.6, in which case we will tell you the specific legal basis and period that applies.

7. Breach Notification

If Finit Systems becomes aware of a confirmed unauthorized access event affecting regulated PHI, Finit Systems will notify affected Providers without unreasonable delay, consistent with applicable law and contractual obligations (including any applicable Business Associate Agreement).

Providers are responsible for regulatory reporting and patient notification unless otherwise agreed in writing.

8. User Rights

Users may request:

  • access to their personal information;
  • correction of their personal information; and
  • deletion of their personal information.

Requests may be sent to info@finitsystems.com.

Patients should contact their Provider for medical record requests.

9. Limitation of Liability Related to Data

To the maximum extent permitted by law, Finit Systems shall not be liable for:

  • Provider misuse of the Platform;
  • Provider PHI handling violations;
  • user credential compromise;
  • third-party integration security failures; or
  • telecommunication delivery failures.

To the maximum extent permitted by law, Finit Systems' liability in connection with data processing under this Policy is limited as set forth in the applicable Underlying Agreement.

10. Cookies

Finit Systems uses cookies on the EZAppointo Platform to:

  • maintain sessions;
  • improve performance; and
  • enhance security.

Users may disable cookies through their browser settings, though doing so may affect Platform functionality.

11. Policy Changes

Finit Systems may update this Privacy Policy from time to time. The "Last Updated" date indicates the latest revision. Continued use of the Platform constitutes acceptance of the revised Policy.

12. Contact

Finit Systems Inc.

Operator of the EZAppointo Platform

Email: info@finitsystems.com

Privacy Policy | EZAppointo