Privacy Policy
Last updated: July 2026 · Jibreix Technologies Ltd · London, UK
Inayexa is designed for healthcare. We take patient privacy and data protection as seriously as your clinic does. This policy explains exactly what we collect, how we use it, and how we protect it.
1. Who we are
Inayexa is a product of Jibreix Technologies Ltd, a company registered in England and Wales (registered address: London, UK). References to "Inayexa", "we", "us" or "our" in this policy mean Jibreix Technologies Ltd.
We operate as a data processor on behalf of businesses (our clients), who are the data controllers for patient information handled through our service.
Contact: privacy@inayexa.com
2. Information we collect
From business owners (our clients)
- Name, email address and clinic details provided during signup and onboarding
- Payment information — processed securely by Stripe. We never store card numbers.
- Business configuration data: clinic name, greeting scripts, hours, services
- Usage data: dashboard activity, feature usage, login timestamps
From patient callers (processed on behalf of clinics)
- Phone number of the caller
- Call recording (where permitted and configured by the clinic)
- Call transcript — the text of the conversation with the AI
- Name and appointment details shared during the call
- SMS messages sent as part of the missed-call text-back service
Automatically collected
- Server logs including IP addresses and request metadata (retained for 30 days)
- Dashboard analytics: page views, clicks, session duration
3. How we use your information
- To provide and operate the Inayexa AI receptionist service
- To send call transcripts, appointment summaries and alerts to business owners
- To process payments and manage subscriptions via Stripe
- To improve the AI's accuracy and our product (using anonymised, aggregated data only)
- To send service-related emails (account setup, billing, feature updates)
- To comply with legal obligations
We do not sell personal data. We do not use patient call data for advertising. We do not share data with third parties except as required to operate the service (see Section 5).
4. HIPAA compliance
Inayexa is designed to support HIPAA compliance for US-based healthcare providers. We operate as a Business Associate and will execute a Business Associate Agreement (BAA) upon request for eligible clients.
Patient call recordings and transcripts are treated as Protected Health Information (PHI) and are:
- Encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Accessible only to the authorised clinic account
- Not used for any purpose other than serving the clinic
- Deletable upon written request
To request a BAA or ask about HIPAA compliance: privacy@inayexa.com
5. UK GDPR & data protection
For users in the United Kingdom and European Economic Area, we comply with UK GDPR. Our lawful bases for processing are:
- Contract — processing necessary to provide the service you've subscribed to
- Legitimate interests — service improvement, security, fraud prevention
- Legal obligation — where required by law
You have the right to access, rectify, erase, or port your personal data. You also have the right to object to processing. To exercise any of these rights, contact privacy@inayexa.com. We will respond within 30 days.
6. Third-party processors
We use the following sub-processors to deliver the service:
- Twilio — phone call routing and SMS delivery
- Vapi — AI voice call processing
- Supabase — database and authentication
- Stripe — payment processing
- Railway — cloud infrastructure
- SendGrid — transactional email
All sub-processors are bound by data processing agreements and operate under appropriate legal frameworks.
7. Data retention
- Call transcripts and recordings: retained for 12 months from the call date, then deleted
- Appointment records: retained for 24 months
- Account data: retained while your subscription is active, plus 90 days after cancellation
- You may request deletion of any data at any time by emailing privacy@inayexa.com
8. Security
We use industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, JWT-based authentication, and access controls limiting data to authorised accounts only. We perform regular security reviews.
9. Cookies
Inayexa uses only essential cookies necessary for authentication and session management. We do not use advertising cookies or third-party tracking pixels on the main website.
10. Changes to this policy
We will notify active clients by email of any material changes to this policy at least 14 days before they take effect. The latest version is always available at inayexa.com/privacy.
11. Contact
For any privacy-related questions, requests, or complaints: privacy@inayexa.com
Jibreix Technologies Ltd · London, United Kingdom