Privacy Policy
Last updated: June 25, 2026 · Effective date: June 25, 2026
This Privacy Policy explains how NextChair (“NextChair,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with our waitlist, intake, openings, and referral-routing software (the “Service”). It is written for two audiences: the therapy and healthcare practices that license the Service (“Practices”), and the prospective and current patients who submit information through a Practice's intake link (“Patients”). This Policy is part of, and incorporated into, our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.
1. Our role: controller vs. processor
For patient health information submitted through a Practice's intake link, the Practice is the controller — in the United States, the “covered entity” under HIPAA; in Ontario, the “health information custodian” under PHIPA. NextChair acts as the Practice's service provider / processor — a Business Associate under HIPAA and an agent / information manager under PHIPA. We process patient information only on documented instructions from the Practice and under a signed Business Associate Agreement (“BAA”). For information about the Practices themselves (account, profile, and billing data), and for our websites and marketing, NextChair acts as the controller, and this Policy governs directly. If you are a Patient, please direct privacy requests to the Practice that collected your information; we will support the Practice in responding.
2. Information we collect
We collect the following categories of information:
- Patient information, submitted through a Practice's intake form: name, date of birth, contact details (email, phone, mailing area), insurance or payment preference, parent/guardian details for minors, presenting concerns and care preferences, scheduling availability, and the consents the Patient provides. This may constitute Protected Health Information and is handled under the BAA.
- Practice information: account credentials, professional profile (name, practice name, credentials, bio, location, accepted insurers, intake settings), Authorized User details, referral and colleague relationships, and support communications.
- Billing metadata: the count of billable patients and subscription status. Patient health information is never transmitted to our payment processor — only billing counts are shared.
- Technical and security data, collected automatically: IP address, device and browser type, timestamps, pages and actions taken, and append-only audit logs used to secure the Service and detect abuse.
- Cookies: strictly necessary cookies to keep you signed in and to protect the Service. See Section 8.
3. How and why we use information
We use information for the following purposes and, where required, on the following legal bases:
- To provide the Service — operate the waitlist and intake workflow, coordinate openings, and route referrals at the Practice's direction (performance of contract; processing on the Practice's instructions).
- To secure the Service — authentication, access control, fraud and abuse prevention, audit logging, and incident response (legitimate interests; legal obligation).
- To bill Practices — calculate usage and process payments (performance of contract).
- To support and communicate with Practices — respond to requests and send service, security, and administrative notices (legitimate interests; performance of contract).
- To improve and develop the Service — limited, aggregated, or de-identified analytics that never include patient health information (legitimate interests).
- To comply with law — meet legal, regulatory, and professional obligations and respond to lawful requests (legal obligation).
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use patient health information for advertising or to train third-party advertising or AI models.
4. How we protect information
- Encryption in transit (TLS) and at rest.
- Strict tenant isolation so one Practice can never access another Practice's patients.
- Role-based access controls, least-privilege internal access, and append-only audit logging.
- Data minimization — we collect only what the workflow needs, and notifications are kept light on health detail.
- Vetted infrastructure providers bound by written confidentiality, security, and (where they may handle PHI) Business Associate obligations.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security; however, we maintain administrative, physical, and technical safeguards designed to meet the requirements of HIPAA and PHIPA.
5. How we disclose information
We disclose information only as follows: (a) as the Practice directs, such as an approved referral to a colleague; (b) to service providers and infrastructure subcontractors who process information on our behalf under written contracts that impose confidentiality and security obligations and, where PHI is involved, Business Associate terms; (c) to comply with law or valid legal process, or to protect the rights, safety, and security of NextChair, our users, or the public; and (d) in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy and the BAA, with notice to affected account owners where required. We do not otherwise disclose patient information to third parties for their own purposes.
6. Retention and deletion
We retain patient information for as long as the Practice maintains its Account and as instructed by the Practice, and as required by applicable law and the BAA. On termination, and subject to legal retention requirements, we will return or delete patient information at the Practice's direction. Practice account and billing records are retained as long as needed for the purposes described above and to meet legal, tax, and audit obligations, after which they are deleted or de-identified. Security and audit logs are retained for a limited period appropriate to their purpose.
7. Your rights and choices
Depending on your jurisdiction and your relationship with us, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, to data portability, and to withdraw consent — including under HIPAA, PHIPA, PIPEDA, the EU/UK GDPR, and U.S. state privacy laws such as the California Consumer Privacy Act as amended (CCPA/CPRA). Because NextChair processes patient information on behalf of Practices, Patients should exercise these rights through the Practice that collected the information; we will assist the Practice in responding. Practices and website users may contact us at privacy@nextchair.co. We will verify requests and respond within the timeframes required by applicable law. We will not discriminate against you for exercising your rights, and where required we will provide an appeals process. You may also have the right to lodge a complaint with your data protection or privacy regulator (for example, the relevant EU/UK supervisory authority, the Office of the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Ontario, or the U.S. Department of Health and Human Services Office for Civil Rights).
8. Cookies and analytics
We use only strictly necessary cookies required to keep you signed in and to secure the Service. We do not use advertising or cross-site tracking cookies, and we do not sell or share information with advertisers. Any product analytics we use are limited, are configured to exclude patient health information, and are used solely to operate and improve the Service. Because we do not use non-essential cookies, no separate cookie-consent banner is presented; where local law requires additional choices, we will honor them.
9. Minors
The Service is not directed to children, and we do not knowingly collect personal information directly from children. Intake forms for minor patients are completed by a parent or legal guardian, who provides consent on the minor's behalf. We handle such information in accordance with the BAA and applicable law, including the Children's Online Privacy Protection Act (COPPA) in the U.S. and applicable provincial requirements in Canada. A parent or guardian may review, correct, or request deletion of a minor's information through the Practice.
10. International data transfers
Patient data is stored in the region appropriate to the Practice's jurisdiction (United States or Canada). Where personal information is transferred to or processed in a country other than the one in which it was collected, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses, the UK Addendum, and equivalent mechanisms — and on our written agreements with subcontractors. You may contact us for more information about these safeguards.
11. U.S. state privacy disclosures
Where applicable, this Policy serves as our notice at collection. In the prior twelve months we collected the categories described in Section 2 for the purposes described in Section 3, and disclosed information only as described in Section 5. We do not sell personal information or share it for cross-context behavioral advertising, and we do not knowingly process the sensitive personal information of consumers for purposes that would require an opt-out beyond providing the Service. California residents and residents of other states with comprehensive privacy laws may exercise the rights described in Section 7; an authorized agent may submit a request on your behalf with proof of authorization.
12. Breach notification
We maintain a documented incident-response process. In the event of a breach of unsecured PHI, we will notify the affected Practice without unreasonable delay and within the timeframes required by HIPAA, PHIPA, and applicable state and provincial law, and will provide the information the Practice needs to meet its own notification obligations. For information for which NextChair is the controller, we will provide any legally required notifications directly.
13. Changes to this Policy
We may update this Policy from time to time. If a change is material, we will notify account owners (for example, by email or in-product notice) and update the “last updated” date above. Your continued use of the Service after the effective date of a change constitutes acceptance of the updated Policy.
14. Contact us
Privacy questions or requests: privacy@nextchair.co · General: support@nextchair.co. If you are a Patient, please also contact the Practice that collected your information, as it is the controller of that information.