Patient Privacy Notice
WIP — work in progress, not a final document. This page is published so the text can be read and reviewed while it is still being worked on. It is not in force, binds nobody, and its wording will change.
This is a template we maintain for clinics that use Foyer. The clinic is the data controller and publishes this notice under its own name, completing the bracketed fields. It is public here so patients and clinics can read what it says about Foyer before anyone signs anything.
Template for clinics — version 0.2, draft for counsel review. The clinic adopting Foyer completes the bracketed fields and publishes this notice under its own name. Foyer's role is described here exactly because the clinic must disclose it.
[CLINIC NAME] ("the Clinic", "we"), located at [CLINIC ADDRESS], is the data controller for personal data you share when contacting us through our messaging channels. We use a service provider, ART.FAUNDEYSHEN LLP ("Foyer") — registered in Kazakhstan as Товарищество с ограниченной ответственностью «АРТ.ФАУНДЕЙШЕН» under BIN 221040005236 — to operate these messaging assistants on our behalf and under our instructions. Foyer acts as a data processor; it does not use your conversation for its own purposes, except as described in section 9.
Clinic contact: [CLINIC PRIVACY CONTACT]. Foyer contact: Kirill Artemev, privacy@foyerbot.com.
Summary: what we do and why
| Purpose | Legal basis | Retention |
|---|---|---|
| Operating the messaging assistant that answers your enquiries on our WhatsApp / LINE / Telegram / widget / email channel | Performance of the service you requested from the Clinic (PDPA s.24(1)); consent where required (s.19) | 90 days from your last message, unless the Clinic has set a different period (see section 12) |
| Answering your questions from the Clinic's own knowledge base (services, prices, doctors, scheduling) | Same as above | Same as above |
| Showing your question to our staff when the assistant could not answer it | Same as above | Until the question is answered and resolved |
| Recording details you volunteer about your enquiry (procedure of interest, expected travel dates, number of visits) | Consent (s.19); health-related details — s.26, see section 10 | 90 days or the Clinic's configured period |
| Keeping technical audit records of which knowledge entries produced each answer | Legitimate interests: security and accountability (s.24(5)) | Indefinitely — but these records contain no message text (section 12) |
| Keeping technical records of undeliverable messages (wrong routing configuration) | Legitimate interests: operating and troubleshooting the service | 30 days, automatic deletion |
This table is the whole document in miniature; the sections below explain each row in plain language.
1. What is processed
When you write to one of our assisted channels, Foyer processes:
- your identifier on that channel — for WhatsApp, your phone number. It is stored in normal readable form, not hashed or encoded. This honesty matters: anyone who tells you otherwise about any messaging service is overpromising;
- the content of your messages and of the assistant's replies;
- timestamps, delivery statuses, language detection, and technical metadata of each message;
- metadata of media you send (type, file name, checksum) — see section 2;
- details you volunteer about your enquiry that help us prepare a proper answer — for example the procedure you are asking about or when you plan to travel. You are never required to provide them in the chat;
- which parts of the Clinic's knowledge base were used to compose each answer — kept separately from your messages and containing no message text.
2. Photos, voice messages and location
Media you send is not downloaded or stored by Foyer. Only its technical metadata (identifier, type, file name, checksum) is recorded so that our staff can follow up if needed. If you send your location, the coordinates arrive in the message metadata and are stored like other message content. Voice messages, images and documents are never transcribed, analysed or forwarded anywhere by Foyer itself.
3. Who can read the conversation
You should assume real people can read what you write, in these situations only:
- The first 48 hours after we connect a new channel ("shadow mode"): every reply of the assistant is confirmed by a named member of our staff before it reaches you. During those two days people see the entire conversation — this is deliberate, so the assistant earns autonomy rather than assuming it.
- Unanswered questions: if the assistant cannot answer from the Clinic's knowledge base, your question appears verbatim in our staff's queue, and an answer written by our staff is then sent to you.
- Live takeover: a staff member may join a conversation at any point; you will be told when a person takes over.
- Foyer staff: only to resolve technical problems and only on our instruction; such access is logged. Temporary disclosure: during initial setup, some configuration steps are performed by Foyer personnel acting on our explicit instruction; this decreases as self-service tools become available, and we will narrow this paragraph accordingly.
No one reads conversations to evaluate or market to you.
4. You are talking to an automated assistant
The first message of each conversation states that you are speaking with an automated assistant, not a person, and how to reach a person at any time. A human is always reachable through the same chat.
5. What the assistant will not do
- It does not give medical advice, diagnoses, or assessments of any condition, regardless of how a question is phrased. It provides facts about the Clinic's services from the Clinic's own materials.
- Prices come only from the Clinic's official price list, always with the note that final cost is determined after consultation.
- It makes no automated decisions producing legal or similarly significant effects about you: no decisions about treatment eligibility, appointment approval, or refusal. It answers questions and escalates to humans; humans decide.
- When information may be outdated or the situation looks urgent, it escalates to a person instead of guessing. Silence followed by escalation is its design, not its failure.
6. Records about our staff
Actions of named staff members (approving an answer, closing a gap, connecting a channel) are recorded for security, audit and quality purposes. These records exist to keep the service accountable — not to monitor individual productivity — and are visible to system administrators and auditors, not to colleagues.
7. Your previous chat history
If we connect a WhatsApp channel where we have already spoken with you, up to 180 days of prior history may be imported so context is preserved. That import is performed by the Clinic and is the Clinic's responsibility; this notice discloses it, and our agreement with the Clinic requires them to have had a basis for the original conversations.
8. Security measures
Foyer separates the data of different clinics at the database level (row-level security enforced by the database engine itself, not only by application code). Data travels encrypted in transit. Audit records are structurally separated from message content. Media files are never downloaded. Infrastructure runs on servers operated by Foyer and its sub-processors — see Foyer's list of sub-processors.
Where your clinic hosts Foyer entirely on its own premises, what leaves that perimeter depends on the deployment level: with a locally hosted model, nothing leaves except hourly technical heartbeat reports (software versions and counters, never conversation content); with an on-premises deployment using a cloud model under the clinic's own key, message content still goes to that model provider. Your clinic can tell you which level applies to it.
9. Improving the service across clinics
General statement: your conversation is used to serve you and the Clinic; it is not sold, not used for advertising, and not used to train AI models — neither by Foyer nor by its model providers.
One named exception: if the assistant repeatedly fails to answer the same kind of question across several clinics (three or more), the de-identified, generalised text of the question alone may be added to shared question templates for that medical specialty. Your phone number and identity are removed; the answer prepared by your clinic, prices, and facts about the clinic are never transferred. A person reviews each promoted template before release. We name this exception openly rather than hide it behind "service improvement".
10. Health-related details
Medical tourism enquiries often include health-related information (for example, treatment history for fertility planning), which is treated as sensitive data. Such fields exist only where relevant to the specialty. Your Clinic decides which fields it needs and must obtain any consent required before using them; this notice describes where they live and for how long. The assistant itself never asks for diagnoses and never stores more than you volunteer.
11. Records without expiry
Two categories are kept indefinitely by design, both deliberately stripped of conversation content:
- audit records (which template and knowledge entries produced each answer);
- append-only event logs (what changed in the setup, when, by whom).
Deletion requests cannot remove these, because they never contained your message text or identifiers in the first place. Everything else is deletable — see below.
12. Retention and deletion
Message content and contact identifiers are deleted 90 days after your last message unless the Clinic has configured a different period — ask the Clinic for their exact figure; it is part of their contract with Foyer.
To exercise deletion, contact the Clinic (they control your data) or write to Kirill Artemev, privacy@foyerbot.com — we will route your request to the Clinic and confirm closure to you within the deadline in section 14. Technical failure records are kept at most 30 days regardless of any request. The indefinite categories in section 11 contain no message content to delete.
13. Cross-border processing
Foyer operates from Kazakhstan; sub-processors are listed at foyerbot.com/subprocessors with their countries. Transfers out of Thailand rely on the Standard Contract Terms issued by Thailand's Personal Data Protection Committee under PDPA s.28, agreed between the Clinic and Foyer in their data processing agreement.
14. Your rights
You have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent, and the right to complain to the supervisory authority. Contact the Clinic — the controller — or Foyer at Kirill Artemev, privacy@foyerbot.com, which forwards requests to the Clinic and tracks closure.
Requests are answered within 10 calendar days wherever they arrive. That is our single published standard across all markets, chosen as the strictest among them rather than seven different deadlines.
15. Children
Our channels serve patients of all ages, but a child's enquiry must come from a parent or guardian. When an adult shares a child's details, responsibility for that disclosure lies with the adult and the Clinic; we do not knowingly build profiles of children.
Notice version: August 27, 2026. Template maintained by Foyer; substantive changes are communicated to the Clinic before adoption.