Privacy Policy

Last updated: August 11, 2026

This Privacy Policy explains how Qintara Health ("Qintara," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the Qintara Health platform, including the patient portal, provider and staff applications, and related websites and services (collectively, the "Services").

Qintara Health provides software to healthcare practices ("Clinics") so they can manage care, communicate with their patients, and run their operations. When you use the patient portal, you are using it in connection with the Clinic that provides your care. That Clinic is responsible for the medical care and records it maintains about you; Qintara acts as a service provider to the Clinic.

1. Information We Collect

Account and identity information

Health and care information

Usage and device information

2. How We Use Information

We do not sell your personal information, and we do not use your health information for advertising.

3. Sign-In With Google and Microsoft

If you sign in with Google or Microsoft, we use the email address and basic profile information from your account for one purpose: to verify your identity and connect you to your existing patient record at your Clinic. We match the verified email address from your provider to the email your Clinic has on file. We do not access your contacts, calendar, files, or any other data from your Google or Microsoft account, and we request only the basic sign-in scopes (openid, email, profile).

Qintara's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use this data only to provide and improve the sign-in feature described here, we do not transfer it to others except as necessary to provide the Services or as required by law, and we do not use it for advertising.

You can disconnect Qintara's access at any time from your Google account permissions or your Microsoft account settings.

4. How We Share Information

5. HIPAA

Your Clinic is a "covered entity" under the Health Insurance Portability and Accountability Act ("HIPAA"), and Qintara acts as a "business associate" that handles PHI on the Clinic's behalf under a Business Associate Agreement. The Clinic's own Notice of Privacy Practices governs how your PHI is used and disclosed for your care. Requests to access, amend, or restrict your medical records should be directed to your Clinic.

6. Data Security

We use administrative, technical, and physical safeguards designed to protect information, including encryption of sensitive data in transit and at rest, access controls, and audit logging. No method of transmission or storage is completely secure, but we work to protect your information and to promptly address any issues.

7. Data Retention

We retain information for as long as needed to provide the Services and to meet legal, regulatory, and recordkeeping requirements, including medical record retention periods that apply to your Clinic. When information is no longer needed, we take steps to delete or de-identify it.

8. Your Rights and Choices

9. Children's Privacy

The patient portal is intended to be used by adults or by a parent or guardian on behalf of a minor, consistent with your Clinic's policies. We do not knowingly collect information directly from children except as part of the care record maintained by your Clinic.

10. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the "Last updated" date above, and, where appropriate, provide additional notice.

11. Contact Us

If you have questions about this Policy or our privacy practices, contact us at:

Qintara Corp
8795 Ralston Rd #220, Arvada, CO 80002
privacy@qintarahealth.com