The short, honest versions — written to be read, with the effective dates that matter. (Design prototype: placeholder copy, not legal advice.)
What we collect. Account details you give us (name, work email, practice info), product usage (features used, device and log data), and billing details processed by our payment partner. Patient data your practice stores in Linden belongs to your practice — we process it only on your instructions, under the BAA below.
What we never do. We don't sell personal data. We don't use your patients' health information to train models, target ads, or build profiles. We don't show your clients other businesses — there is no marketplace.
Your rights. Access, correct, export or delete your data any time from Settings → Compliance, or by emailing privacy@lindenos.com. CCPA and state-law requests are honored regardless of where you live.
Retention. Practice data is kept while your subscription is active, exportable for 90 days after cancellation, then permanently deleted — with a final notice 7 days before deletion.
The deal. You pay a monthly subscription; we run the software, keep it available and support you. Plans are month-to-month — cancel anytime from Settings with no fee, and access runs to the end of the period you've paid for.
Your responsibilities. Keep your account secure, use the platform lawfully, and make sure you have the right to store the client data you upload. Clinical judgment stays with your licensed providers — Linden (including Lin and AI charting) is an administrative tool, not a medical device.
Payments. Card processing is provided with our payment partner; processing fees are shown at checkout and never marked up. Failed subscription charges retry twice before staff access pauses — patient data is never held hostage over billing.
If we part ways. Your data is yours: full export in open formats (CSV, PDF) before and up to 90 days after your plan ends. We can terminate for abuse, fraud or non-payment, with notice except where the abuse is severe.
Found a vulnerability? security@lindenos.com — we run a coordinated disclosure program and respond within 24 hours.
Available on request. A signed BAA is offered to practices handling PHI. You countersign electronically during onboarding; a copy lives in Settings → Compliance.
What it covers. We act as your business associate: PHI is used only to provide the service, disclosed only as the agreement allows, safeguarded per the Security Rule, and breach-notified within the statutory windows (we commit to 72 hours, faster than required).
AI and PHI. Lin's call transcripts redact PHI by default; AI charting runs on infrastructure covered by the same BAA; none of it trains shared models. Every AI feature can be disabled per practice.
Subprocessors. The current list (hosting, telephony, payments, email) lives at lindenos.com/subprocessors with 30-day advance notice of changes.