Legal

Enterprise Privacy Policy

Last Updated: 20 February 2026

This Privacy Policy explains how Finit Systems Inc., a corporation organized under the laws of the State of New York ("Finit Systems," the "Company," "we," "us," or "our"), collects, uses, processes, discloses, and protects personal information and Protected Health Information ("PHI") in connection with EZAppointo, a platform developed, owned, and operated by Finit Systems, including its scheduling, messaging, and telehealth video consultation services (the "Platform").

EZAppointo is a product and brand of Finit Systems Inc. The Platform is designed to meet healthcare privacy expectations and incorporates administrative, technical, and operational safeguards.

1. Role of Finit Systems

Finit Systems provides the EZAppointo Platform as software infrastructure for healthcare Providers.

  • Providers are the data controllers of patient medical and appointment data.
  • Finit Systems acts as a data processor or service provider on behalf of Providers.

Finit Systems is not a healthcare provider and does not diagnose, treat, or provide medical care.

2. Information Collected

Patient Data:

  • Name, phone number, email;
  • Appointment date, time, provider, location;
  • Intake information entered by the Provider;
  • Communications metadata.

Provider Data:

  • Provider name, clinic name, contact information;
  • Account credentials;
  • Scheduling configurations.

Technical Data:

  • IP address;
  • Device identifiers;
  • Log activity.

Payment Data:

  • Stripe payment tokens;
  • Subscription billing information;
  • Transaction metadata.

Finit Systems does not store full credit card numbers.

Video Consultation Data:

  • Session timestamps;
  • Connection diagnostics;
  • In-session communications.

Sessions are not recorded by default.

3. Protected Health Information (PHI)

Finit Systems may process PHI on behalf of Providers.

Finit Systems implements safeguards including:

  • access control restrictions;
  • encryption in transit;
  • authentication protections; and
  • monitoring and logging.

Providers are responsible for determining the PHI content entered into the Platform.

4. HIPAA Compliance and Business Associate Role

Where applicable under U.S. law, Finit Systems may function as a Business Associate with respect to PHI processed through the EZAppointo Platform.

Providers must execute a Business Associate Agreement with Finit Systems where required.

Finit Systems processes PHI solely to provide Platform services and does not use PHI for advertising or resale.

Providers are responsible for HIPAA compliance in their clinical workflows.

5. SMS Reminders and Communication

Finit Systems sends transactional SMS messages through the EZAppointo Platform to users who have explicitly opted in during the appointment booking or account registration process. Message types include appointment confirmations, appointment reminders, rescheduling notifications, video consultation links, and one-time verification (OTP) codes.

Opt-In: By providing your phone number and checking the SMS consent checkbox on our booking form, you agree to receive SMS messages from the EZAppointo Platform. Consent is not a condition of purchase.

Message Frequency: Message frequency varies based on your appointment activity. You may receive up to five (5) messages per appointment (confirmation, reminder, follow-up).

Message & Data Rates: Standard message and data rates may apply depending on your mobile carrier plan.

Opt-Out: You may opt out at any time by replying STOP to any message. You will receive one final confirmation, after which no further messages will be sent.

Help: Reply HELP to any message or contact us at info@finitsystems.com for assistance.

Carriers: SMS messages are transmitted via third-party telecommunications providers. Delivery cannot be guaranteed. Finit Systems is not liable for delayed or undelivered messages.

5.1 SMS Consent and Data Sharing

We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. We may share your Personal Data, including your SMS opt-in or consent status, with third parties that help us provide our messaging services, including but not limited to platform providers, phone companies, and any other vendors who assist us in the delivery of text messages. All of the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.

6. Data Retention

Data is retained only as necessary for operational, contractual, and legal purposes.

Providers are responsible for medical record retention requirements.

7. Breach Notification

If Finit Systems becomes aware of a confirmed unauthorized access event affecting regulated PHI, Finit Systems will notify affected Providers without unreasonable delay, consistent with applicable law and contractual obligations (including any applicable Business Associate Agreement).

Providers are responsible for regulatory reporting and patient notification unless otherwise agreed in writing.

8. International and Non-U.S. Providers

Providers outside the United States must comply with their local privacy laws.

Finit Systems provides reasonable safeguards but does not assume regulatory responsibility for compliance within a Provider's jurisdiction.

9. User Rights

Users may request:

  • access to their personal information;
  • correction of their personal information; and
  • deletion of their personal information.

Requests may be sent to info@finitsystems.com.

Patients should contact their Provider for medical record requests.

10. Limitation of Liability Related to Data

To the maximum extent permitted by law, Finit Systems shall not be liable for:

  • Provider misuse of the Platform;
  • Provider PHI handling violations;
  • user credential compromise;
  • third-party integration security failures; or
  • telecommunication delivery failures.

To the maximum extent permitted by law, Finit Systems' liability in connection with data processing under this Policy is limited as set forth in the applicable Underlying Agreement.

11. Cookies

Finit Systems uses cookies on the EZAppointo Platform to:

  • maintain sessions;
  • improve performance; and
  • enhance security.

Users may disable cookies through their browser settings, though doing so may affect Platform functionality.

12. Policy Changes

Finit Systems may update this Privacy Policy from time to time. The "Last Updated" date indicates the latest revision. Continued use of the Platform constitutes acceptance of the revised Policy.

13. Contact

Finit Systems Inc.

Operator of the EZAppointo Platform

Email: info@finitsystems.com

Address: 45 West John Street, Suite 207, Hicksville, NY 11801

Enterprise Privacy Policy | EZAppointo