Privacy Policy

Last updated October 20, 2025.

At AutoChiro.ai, we are committed to safeguarding your personal data. This policy details how we collect, use, store, and protect information from visitors, including AutoChiro.ai users and those connecting to our services via partner sites such as Facebook, Instagram, and Google.

Information We Collect:

1 - Personal Data: We collect information you provide during account creation (name, company, email, phone number).

2 - Third-party Connections: Users may choose to link Facebook, Instagram, and Google accounts to AutoChiro's CRM platform for improved integration.

Cookies and Tracking Cookies:

AutoChiro.ai uses single-session and multi-session cookies to track user activity, improve functionality, and personalize advertising. We use Google Analytics to collect non-personal information about your activities on our site (e.g., IP address, device type, browser version).

Use of Information

We use your information to provide and improve our services, including personalized advertising and content, responding to inquiries, and CRM integration. Your personal data may also be used to track service use and offer tailored recommendations.

Sharing Information with Third Parties

We do not sell or trade your personal information to third parties.

However, we may share your data with service providers to facilitate operations, including:

HighLevel LLC (CRM and automations)

Meta Platforms Ireland Ltd. (advertising)

WhatsApp Ireland Ltd. (communications)

Google Cloud EMEA Ltd. (hosting)

Stripe Payments Europe Ltd. (payments)

All subprocessors comply with the GDPR and are bound by Standard Contractual Clauses (SCCs) or certified under the EU–US Data Privacy Framework (DPF).

This ensures that all international transfers (for example, to HighLevel LLC in the USA) are fully compliant with Article 46 of the GDPR and provide an equivalent level of protection.

Data Processing on Behalf of Clients

When AutoChiro acts as a service provider for chiropractic clinics, it processes patient or lead information solely under their documented instructions and in accordance with the Data Processing Agreement (DPA).

In such cases, the clinic acts as the Data Controller, and AutoChiro SL acts as the Data Processor.

Email Communication and CAN-SPAM Compliance

AutoChiro complies with the CAN-SPAM Act. All emails from AutoChiro will clearly state who the message is from and provide options to unsubscribe. You can opt-out of our communications at any time via the unsubscribe link at the bottom of our emails.

Security of Information

We implement strong security safeguards, including:

SSL/TLS encryption in transit and AES-256 encryption at rest

Role-based access controls

Regular backups and security audits

Hosting in ISO 27001 and SOC 2 certified facilities

Data Retention and Deletion

AutoChiro retains personal data while your subscription is active and for 15 days following cancellation to allow export.

After this period, data is permanently deleted from all active systems and backups.

Legal Basis for Processing

We process personal data only when:

- Necessary for contract performance

- Based on user consent

- Required by law or legitimate interest

Data Subject Rights

You may request access, rectification, erasure, restriction, or portability of your data by contacting [email protected].

We will respond in accordance with GDPR timeframes.

Children’s Privacy

We do not knowingly collect information from children under the age of 13. If you believe we have collected such information, contact us at [email protected] to have it removed.

Meta Advertising and Lookalike Audiences

AutoChiro may use hashed or pseudonymized contact data from client clinics, under their explicit authorization, to help Meta improve ad delivery and measure campaign performance.

Data shared with Meta for this purpose is protected under encryption and cannot be used by AutoChiro for any other purpose.

These operations are covered under the Meta Business Tools Joint Controller Addendum and the EU–US Data Privacy Framework.

Clinics are required to obtain explicit patient consent before such data processing occurs.

Your Rights and Choices

You can manage your cookie preferences through your browser settings. If you wish to delete your personal data from our system or opt-out of further data collection, please contact us at [email protected]

Policy Updates

AutoChiro.ai may update this policy at any time. The latest version will always be available on our website.

For any questions or concerns about this Privacy Policy, please reach out to us at:

[email protected]