← Back to NextChair

Privacy Policy

Last updated: June 25, 2026 · Effective date: June 25, 2026

This Privacy Policy explains how NextChair (“NextChair,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with our waitlist, intake, openings, and referral-routing software (the “Service”). It is written for two audiences: the therapy and healthcare practices that license the Service (“Practices”), and the prospective and current patients who submit information through a Practice's intake link (“Patients”). This Policy is part of, and incorporated into, our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.

1. Our role: controller vs. processor

For patient health information submitted through a Practice's intake link, the Practice is the controller — in the United States, the “covered entity” under HIPAA; in Ontario, the “health information custodian” under PHIPA. NextChair acts as the Practice's service provider / processor — a Business Associate under HIPAA and an agent / information manager under PHIPA. We process patient information only on documented instructions from the Practice and under a signed Business Associate Agreement (“BAA”). For information about the Practices themselves (account, profile, and billing data), and for our websites and marketing, NextChair acts as the controller, and this Policy governs directly. If you are a Patient, please direct privacy requests to the Practice that collected your information; we will support the Practice in responding.

2. Information we collect

We collect the following categories of information:

3. How and why we use information

We use information for the following purposes and, where required, on the following legal bases:

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use patient health information for advertising or to train third-party advertising or AI models.

4. How we protect information

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security; however, we maintain administrative, physical, and technical safeguards designed to meet the requirements of HIPAA and PHIPA.

5. How we disclose information

We disclose information only as follows: (a) as the Practice directs, such as an approved referral to a colleague; (b) to service providers and infrastructure subcontractors who process information on our behalf under written contracts that impose confidentiality and security obligations and, where PHI is involved, Business Associate terms; (c) to comply with law or valid legal process, or to protect the rights, safety, and security of NextChair, our users, or the public; and (d) in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy and the BAA, with notice to affected account owners where required. We do not otherwise disclose patient information to third parties for their own purposes.

6. Retention and deletion

We retain patient information for as long as the Practice maintains its Account and as instructed by the Practice, and as required by applicable law and the BAA. On termination, and subject to legal retention requirements, we will return or delete patient information at the Practice's direction. Practice account and billing records are retained as long as needed for the purposes described above and to meet legal, tax, and audit obligations, after which they are deleted or de-identified. Security and audit logs are retained for a limited period appropriate to their purpose.

7. Your rights and choices

Depending on your jurisdiction and your relationship with us, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, to data portability, and to withdraw consent — including under HIPAA, PHIPA, PIPEDA, the EU/UK GDPR, and U.S. state privacy laws such as the California Consumer Privacy Act as amended (CCPA/CPRA). Because NextChair processes patient information on behalf of Practices, Patients should exercise these rights through the Practice that collected the information; we will assist the Practice in responding. Practices and website users may contact us at privacy@nextchair.co. We will verify requests and respond within the timeframes required by applicable law. We will not discriminate against you for exercising your rights, and where required we will provide an appeals process. You may also have the right to lodge a complaint with your data protection or privacy regulator (for example, the relevant EU/UK supervisory authority, the Office of the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Ontario, or the U.S. Department of Health and Human Services Office for Civil Rights).

8. Cookies and analytics

We use only strictly necessary cookies required to keep you signed in and to secure the Service. We do not use advertising or cross-site tracking cookies, and we do not sell or share information with advertisers. Any product analytics we use are limited, are configured to exclude patient health information, and are used solely to operate and improve the Service. Because we do not use non-essential cookies, no separate cookie-consent banner is presented; where local law requires additional choices, we will honor them.

9. Minors

The Service is not directed to children, and we do not knowingly collect personal information directly from children. Intake forms for minor patients are completed by a parent or legal guardian, who provides consent on the minor's behalf. We handle such information in accordance with the BAA and applicable law, including the Children's Online Privacy Protection Act (COPPA) in the U.S. and applicable provincial requirements in Canada. A parent or guardian may review, correct, or request deletion of a minor's information through the Practice.

10. International data transfers

Patient data is stored in the region appropriate to the Practice's jurisdiction (United States or Canada). Where personal information is transferred to or processed in a country other than the one in which it was collected, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses, the UK Addendum, and equivalent mechanisms — and on our written agreements with subcontractors. You may contact us for more information about these safeguards.

11. U.S. state privacy disclosures

Where applicable, this Policy serves as our notice at collection. In the prior twelve months we collected the categories described in Section 2 for the purposes described in Section 3, and disclosed information only as described in Section 5. We do not sell personal information or share it for cross-context behavioral advertising, and we do not knowingly process the sensitive personal information of consumers for purposes that would require an opt-out beyond providing the Service. California residents and residents of other states with comprehensive privacy laws may exercise the rights described in Section 7; an authorized agent may submit a request on your behalf with proof of authorization.

12. Breach notification

We maintain a documented incident-response process. In the event of a breach of unsecured PHI, we will notify the affected Practice without unreasonable delay and within the timeframes required by HIPAA, PHIPA, and applicable state and provincial law, and will provide the information the Practice needs to meet its own notification obligations. For information for which NextChair is the controller, we will provide any legally required notifications directly.

13. Changes to this Policy

We may update this Policy from time to time. If a change is material, we will notify account owners (for example, by email or in-product notice) and update the “last updated” date above. Your continued use of the Service after the effective date of a change constitutes acceptance of the updated Policy.

14. Contact us

Privacy questions or requests: privacy@nextchair.co · General: support@nextchair.co. If you are a Patient, please also contact the Practice that collected your information, as it is the controller of that information.

Terms of Service · Business Associate Agreement