Digital Workforce System ← Home

Privacy Policy

Last updated 10 August 2026 · Effective 10 August 2026

  1. Who we are
  2. What this covers
  3. Controller and processor
  4. What we collect
  5. How we use it
  6. Google user data
  7. LINE data
  8. AI processing
  9. Who we share with
  10. How long we keep it
  11. Security
  12. Your rights
  13. International transfers
  14. Cookies
  15. Children
  16. Changes
  17. Contact

1 · Who we are

Quantum AI Solutions LLC, registered in the State of Texas, United States at 4033 Avalon Ave, Irving, TX 75061, United States, trading as Digital Workforce System ("we", "us"). We operate the website at digitalworkforcesystem.com and the ClinicText AI service.

For privacy questions, write to imtiazh@digitalworkforcesystem.com.

2 · What this covers

This policy applies to three groups of people, and what we do differs for each:

WhoRelationship
Website visitorsYou read our pages or contact us
CustomersA clinic or business that subscribes to ClinicText AI
Our customers' patients and enquirersPeople who message a customer's LINE Official Account, whose messages the service handles

3 · Controller and processor

This distinction matters, so it is stated plainly.

If you are a patient and want your data corrected or deleted, the fastest route is to ask the clinic you messaged. If you contact us instead, we will pass the request to them and support them in answering it.

4 · What we collect

From website visitors

From customers

From patients and enquirers messaging a customer's account

We do not ask for, and the service is not designed to collect, clinical records, medical history, diagnoses or treatment notes. ClinicText AI answers questions about price, availability and process. If a conversation moves toward clinical matters it is handed to clinic staff. Please do not send sensitive health information through it.

5 · How we use it

We do not sell personal data. We do not use it for advertising, and we do not share it with other customers.

6 · Google user data

When a customer connects Google Calendar, we request the narrowest access that lets the service work.

ScopeWhy
.../auth/calendar.events To work out which times are already occupied, so we offer a slot that is genuinely free; and to create, move and cancel the appointment the patient agrees to

We store the access and refresh tokens needed to keep the connection working, encrypted at rest. We store event identifiers and appointment times so the service can update or cancel a booking it created.

We keep only times, never content. Reading a calendar returns the start and end of each existing entry and nothing else. Titles, descriptions, locations, guests and organisers are discarded the moment they are received — they are never stored, logged, shown in our application, or sent anywhere. We write only the appointments the service itself creates, and we only ever modify or remove those.

Limited Use. Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we use Google user data only to provide and improve the features the user has asked for; we do not transfer it except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice; we do not use it for advertising; we do not use it to train generalised artificial intelligence or machine learning models; and we do not allow humans to read it except with the user's explicit consent, for security purposes, to comply with law, or where the data has been aggregated and de-identified.

A customer can disconnect at any time from within the service, or by revoking access at myaccount.google.com/permissions. On disconnection we delete stored Google tokens; appointments already written to the calendar remain in the customer's calendar and under their control.

7 · LINE data

ClinicText AI operates on our customer's own LINE Official Account, with the account administrator's authorisation.

8 · AI processing

Message content is sent to a large language model so that a reply can be generated. This is a sub-processing arrangement, and we name the provider rather than describing it in general terms.

What Google Calendar data reaches the model. No calendar event content ever does. When the service reads a connected calendar it keeps only the start and end times of existing entries and discards everything else at that point — titles, descriptions, locations, guests and organisers are never returned, stored or logged.

Those times are used to subtract occupied periods from the clinic's working hours. What the model is given is the remainder: a short list of times the clinic is free, such as "Tue 12 Aug 14:00". This is data derived from a Google API, so we treat it under the Limited Use requirements — and it is sent only to Google's own paid Gemini API, which does not train on it.

9 · Who we share with

We use a small number of sub-processors to run the service. A current list is available on request to imtiazh@digitalworkforcesystem.com, and customers are given reasonable notice before we add one. Categories:

We also disclose data where the law requires it, and to establish or defend legal claims.

10 · How long we keep it

DataRetention
Conversations and appointment recordsFor the life of the customer's account, or a shorter period the customer sets
Connection tokensUntil disconnected or the account closes, then deleted
Server logsUp to 12 months
Billing recordsAs tax and accounting law requires

When a customer closes their account, we provide an export on request made within 30 days and then delete their data within 90 days, except backups on their ordinary deletion cycle and records we must keep by law.

11 · Security

No system is perfectly secure. If a personal data breach occurs we will notify affected customers without undue delay, and regulators where the law requires it.

12 · Your rights

Under Thailand's Personal Data Protection Act B.E. 2562 (2019), and under the UK and EU GDPR where they apply, you may request access to your personal data, correction, erasure, restriction of processing, portability, and you may object to processing or withdraw consent.

Contact imtiazh@digitalworkforcesystem.com. We respond within 30 days. If you are a patient of one of our customers, see section 3 — the clinic is the controller and we will route your request to them.

You also have the right to complain to a supervisory authority, including Thailand's Personal Data Protection Committee.

13 · International transfers

We are a United States company serving customers in Thailand and elsewhere. Thailand's PDPA applies to us because we offer services to people in Thailand, and we comply with it regardless of where our infrastructure sits.

Our infrastructure and sub-processors may be located outside Thailand, including in the United States and the European Union. Where personal data is transferred across borders we rely on appropriate safeguards, including contractual protections with each sub-processor requiring a standard of protection consistent with this policy and applicable law.

14 · Cookies

Our public marketing pages use only what is necessary to serve the site. We do not run advertising or cross-site tracking cookies on them. Where the application uses cookies, they are strictly necessary — keeping you signed in and keeping the session secure.

15 · Children

The service is sold to businesses and is not directed at children. We do not knowingly collect personal data from children. Where a parent or guardian messages a clinic about a child's appointment, that content is handled under the clinic's own controllership as set out in section 3.

16 · Changes

We may update this policy. The date at the top always reflects the current version. Where a change materially affects how we handle personal data, we will notify customers by email before it takes effect.

17 · Contact

Quantum AI Solutions LLC
4033 Avalon Ave, Irving, TX 75061, United States
imtiazh@digitalworkforcesystem.com