Skip to main content

Public validation notice · version 1.2

Privacy and no-PHI notice.

This notice explains the current ClinLedger public-validation pages and the safeguards that govern the controlled founding-reservation form when active.

The controlled reservation form is active. It is hosted by Tally and is limited to the business-fit fields described below. It has no uploads, payment, automatic Tally email, webhook delivery, broad free text, scheduling, or unrelated marketing signup. A submission may authorize one later QuraZone email only if the founding service opens.

What these pages do now

The ClinLedger page package displays public validation information and a synthetic sample. Its static scope guide does not collect, transmit, or store answers. The package adds no advertising tracker, marketing analytics script, checkout, payment form, scheduling tool, account creation, or file upload control.

Like most websites, the QuraZone WordPress host and network providers may process standard technical request data needed to deliver and protect the page, such as IP address, request time, requested URL, browser information, and security or error logs. ClinLedger does not use those logs to make a practice-assurance decision.

QuraZone Holdings Ltd operates this validation and determines why the limited reservation information is used. It is also the named seller for any future ClinLedger service. This does not mean a paid service is currently available.

The active form uses controlled business-fit fields only.

The reviewed Tally form collects the following limited field set for the specific non-binding reservation request:

  • confirmation that the practice is in Alberta;
  • the submitter’s authorized business role;
  • whether the exact AI-scribe product and plan are known;
  • the current evaluation, implementation, PIA, change, or renewal stage;
  • a business email;
  • whether CAD 499 fits the proposed founding scope;
  • required authority, no-patient-information, privacy, terms, and one-email acknowledgements.

The form does not accept broad narratives, unrelated marketing consent, files, payment information, appointment requests, or clinical details. Tally stores the submitted reservation in the form workspace so the specific request can be reviewed; owner and respondent email notifications, automatic email, webhooks, partial submissions, and save-for-later are disabled. The reservation authorizes QuraZone to send one email only if the founding service opens, with final scope, timing, and payment details. It does not authorize calls or meeting requests unless the submitter later asks.

When Tally accepts a submission, it automatically creates submission and respondent identifiers. Tally states that the respondent identifier is stored in browser local storage and can persist across forms in the same workspace. ClinLedger does not use that identifier for marketing, cross-business profiling, or duplicate prevention. No hidden field, page query forwarding, UTM capture, or submission limit is configured for this form.

Do not send patient or clinical information.

ClinLedger is designed not to receive personal health information or patient data. Do not include patient names, identifiers, appointment details, recordings, transcripts, clinical notes, diagnoses, medications, results, messages, EHR screenshots, patient-level incident narratives, or any other information about an identifiable patient.

Also do not send passwords, access tokens, API keys, private keys, or other credentials. A future product may use layered detection as a secondary control, but detection is fallible and would never replace the prohibition and careful customer review.

Current and future provider boundaries

  • one.com and WordPress support the QuraZone website and may process the technical data needed to host, deliver, secure, and troubleshoot these pages.
  • Google Workspace may process a message if you choose to email the privacy contact.
  • Tally hosts the controlled reservation form and processes the business-fit fields submitted through it. Loading or using the embedded form may also give Tally ordinary technical request data under its policies. Tally states that form data is stored in Europe and describes its subprocessors and data-handling practices in its GDPR information. No file, payment, webhook, or automatic Tally-email feature is enabled for this form. The one later service-opening email described above would be sent by QuraZone only under the submitter’s specific request.

The current ClinLedger page package does not add an AI model call. Fit answers are not sent to OpenAI or another model provider.

Keep only what the validation purpose requires.

one.com and WordPress may process technical delivery, security, error, and access-log data under their own configurations and policies. Those operational records are separate from the reservation responses described below and may not follow the same deletion timing.

A no-cost lifecycle-only process is scheduled daily and at user sign-in. It removes completed reservations from the active Tally workspace after they are more than 90 days old, unless a documented legal requirement requires longer. Tally’s submission-listing endpoint returns submission objects with their responses to the authorized retention process. That process immediately reduces each object to its submission identifier and timestamp for deletion; it does not inspect answer or email fields or use them for retention, and it does not persist, log, print, or expose those values. If the workstation or its user session is unavailable, a run can be missed and deletion occurs on the next successful catch-up run. Tally keeps deleted submissions in Trash for up to 90 additional days before permanent deletion unless Trash is emptied sooner. Tally’s paid automatic-retention feature is not represented as active.

A business contact may ask what reservation information is held, correct it, withdraw the request, or ask for deletion by emailing info@qurazone.com. Identity and authority may need to be verified before acting on a request.

Minimization is the first safeguard.

The current surface minimizes collection by keeping the fit check local and limiting the Tally reservation to controlled business-fit fields. HTTPS, hosting controls, narrow administration access, backup, logging, retention, and incident handling are part of the controlled release boundary.

No internet service can promise absolute security. ClinLedger does not claim zero risk, perfect patient-information detection, or that its own security controls certify a vendor or practice.

This notice will change before data collection changes.

The version and effective date will be updated before analytics, a material provider change, a new field, or a materially different use of information is activated. Earlier versions should be retained in the controlled release record.

Privacy or no-PHI questions can be sent to info@qurazone.com. Do not put patient information or clinical details in the message.

Review status

This plain-language notice applies only to the public pages and controlled, non-binding reservation. It is not a privacy or service agreement for a paid assurance service, and no paid service is live.