01 Who we are
Autopoiema is a boutique automation studio based in Prague, Czech Republic. We build the assistant, run it on infrastructure we operate, and support the practices that use it.
For anything in this policy, write to hello@autopoiema.com. A person answers.
02 Who decides, and who executes
This distinction determines every right you have, so it comes before the detail.
- The practice is the controller. The clinic, doctor or practitioner who uses the assistant decides that it runs, on which phone number, and for which patients. The patient relationship is theirs. The WhatsApp Business account and the calendar are theirs.
- Autopoiema is the processor. We act on the practice's documented instructions and for no purpose of our own. We do not decide what happens to patient data, and we do not use it to build anything else.
If you are a patient and you want your data removed, the fastest route is to tell the practice. You can also write to us directly and we will act on it; see Data deletion.
03 What the assistant actually stores
Short list, and it is the whole list. Each row is a field that exists on disk on our server.
| What | Why it exists |
|---|---|
| The patient's WhatsApp number, in the identifier form Meta gives us | To attach an appointment to the right conversation and send the reminder to the right person |
| The patient's display name, as WhatsApp reports it | So the practitioner reads a name and not a number in the calendar |
| Date, time and duration of the appointment, and its status: booked, rescheduled, cancelled, confirmed | This is the appointment. It is the product |
| A record that a reminder was sent, with its timestamp and result | So nobody is reminded of the same appointment twice |
| The identifiers of messages already processed, capped at the last 2,000 | WhatsApp re-delivers webhooks. Without this, one message could book two appointments |
| Operational logs: that a message arrived, from which number, and how many characters it had | To diagnose failures. The text itself is not there |
Appointments are also written to the practice's own Google Calendar, because that calendar is the interface the practitioner already uses. There is no dashboard and no patient portal.
04 What it deliberately does not keep
These are design decisions, not settings we forgot to turn on. They cost us features and we took them anyway.
The content of messages is never written to disk
The assistant needs recent context: when the practitioner replies "that works", the hour was in the patient's previous message. So it holds a rolling buffer of at most 25 messages per conversation, in memory only. That buffer is erased 12 hours after the last activity, and it disappears entirely whenever the service restarts. It is never saved to a file, never backed up, and cannot be recovered. The cost is real: after a restart, the practitioner may have to repeat an hour. We consider that the correct price.
The reason for the visit is off by default
"Root canal", "pain in a molar" — this is health data, a special category under Article 9 of the GDPR and Article 9 of the Mexican federal data protection law. The assistant ships with that field disabled: appointments are stored with a name and an hour and nothing else. It is not enabled because it would be convenient for the practitioner. Enabling it requires the patient's express written consent, and that is the practice's obligation as controller.
No advertising, no resale, no model training
We do not sell patient data, share it for advertising, profile anyone, or use it to train any model. There is no analytics tracker inside the assistant.
05 The language model runs locally
Deciding whether a conversation just closed an appointment is a language problem, so the assistant uses a language model for the ambiguous cases. That model runs on our own server, not on a third-party API. Patient conversations are not sent to OpenAI, Anthropic, Google or anyone else for interpretation, and they never leave the machine that processes them.
Most messages never reach the model at all: a cheap pattern filter runs first, and if nothing in the recent conversation looks like scheduling, the model is not woken up.
06 Where the data lives, and who else touches it
The assistant runs on infrastructure operated by Autopoiema in the Czech Republic, inside the European Union. Three third parties are unavoidably involved, and each one only sees what it needs to do its job.
| Who | What they see | Why |
|---|---|---|
| Meta Platforms (WhatsApp Business Platform) | The messages themselves, as the carrier of the conversation | WhatsApp is the channel. Meta's own terms govern that leg, and they would see those messages with or without us |
| Google (Calendar API) | Name, date and time of each appointment | The appointment is written into the practice's own Google account, which the practice controls and can revoke |
| Autopoiema | The fields listed in section 03 | To run the service |
There are no other subprocessors. No advertising network, no analytics vendor, no customer-data platform, no offshore support desk.
07 How long it is kept
- Message content: up to 12 hours, in memory, then gone.
- Appointments: for as long as the practice uses the service, because a past appointment is the practice's own record. On termination we delete our copy within 30 days. The copy in the practice's Google Calendar is theirs and stays with them.
- Reminder records and processed-message identifiers: capped lists that roll over on their own, oldest first.
- Logs: kept while they are useful for diagnosis, and they contain no message text.
08 Your rights
If the practice is in the European Union, the GDPR gives you the right to access your data, correct it, erase it, restrict or object to its processing, and receive it in a portable form. If the practice is in Mexico, the federal law gives you the equivalent access, rectification, cancellation and objection rights.
Because the practice is the controller, those requests are normally made to the practice and we execute them. You can also send one straight to us at hello@autopoiema.com — we will act on it and tell the practice. We answer within 30 days, and we do not charge for it.
Step-by-step instructions for deletion are on their own page: Data deletion.
You also have the right to complain to a supervisory authority. In the Czech Republic that is the Office for Personal Data Protection.
09 Security
- Every incoming webhook is signature-verified against the shared secret before it is read. Unsigned requests are rejected, not logged as data.
- Traffic in and out runs over TLS.
- Credentials live in environment files with restricted permissions, never in the source code and never in a repository.
- Writes to disk are atomic, so a crash cannot leave a half-written file of appointments.
- The smallest surface we could build: no admin panel, no public API, no patient login. Nothing to break into that does not need to exist.
10 Children
The assistant is not directed at children and has no way to identify them. When a parent books for a child, the record that exists is the same as any other: a name, a number and an hour, held under the practice's responsibility as controller.
11 Changes to this policy
If we change it, the date at the top changes with it, and practices using the service are told directly before the change takes effect. We do not make quiet edits.
12 Contact
Autopoiema · Prague, Czech Republic · hello@autopoiema.com