Privacy Policy

How OneGRC Inc. collects, uses, and protects your data when you use Chairside. Effective July 6, 2026.

Information we collect

How we use information

We use information to deliver, secure, and improve Chairside for the Clinic that submitted it; draft encounter notes, referral letters, and patient summaries as requested by a clinician; process subscriptions and support requests; detect abuse, fraud, and security incidents; and comply with legal obligations.

Google Mail and Gmail API data

When an authorised Clinic administrator connects a practice Gmail or Google Workspace mailbox, Chairside receives the mailbox address and uses Google OAuth to obtain the permissions the Clinic chooses.

What we access and why

Default boundaries

By default, only Chairside-originated threads are written to or surfaced in Chairside. The Gmail API may return and Chairside may inspect newly added inbox message data before thread matching. Either the cold-inbound capture opt-in or the Google referral capture opt-in can widen processing beyond this default; unrelated inbox mail is filtered and is not surfaced or ingested by default.

Controls and lifecycle

Security and sharing

We use encryption in transit and at rest, role-based access controls, audit logging, and least-privilege production access. Limited subprocessors support payments and billing (Stripe, Inc.), SSO and directory sync (WorkOS, Inc.), transactional email (Twilio Inc. (SendGrid)), drafting (Anthropic, PBC.), Gmail API and speech-to-text (Google LLC), and hosting, database, and object storage (Amazon Web Services, Inc. (AWS)). They receive information only as needed to provide those services and are contractually bound by applicable protections.

Chairside is operated by OneGRC Inc. Questions, rights requests, and requests to delete Chairside copies can be sent to [email protected]. For PHI, requests should be routed through the Clinic that submitted the data.