Plain-language summary
We collect your business contact information when you request an audit or use our service. We record and transcribe calls on behalf of client clinics. We do not sell your data, run ads, or use third-party tracking. This site uses only essential cookies. For clients who are HIPAA-covered entities, a separate Business Associate Agreement governs protected health information.
1. Who We Are
Katalyst ("Katalyst," "we," "our," or "us") is a revenue recovery automation company headquartered in Miami, Florida. We provide automated workflow services to independent medical spas, including missed-call recovery, lead follow-up, appointment reminders, no-show recovery, and daily operational reporting. Contact: hello@katalyst.io · Miami, FL · United States.
2. Information We Collect
Information you provide directly: When you submit an audit request or contact us, we collect your name, business name, email address, phone number, and any information you include in your message. When you become a client, we also collect onboarding details about your clinic (operating hours, booking links, service menu, staff details).
Call recordings and transcripts: As part of our service, we record and transcribe inbound and outbound calls routed through our platform on behalf of client clinics. These recordings may incidentally contain information about clinic patients (caller names, appointment inquiries, treatment interests). This data is processed under a Business Associate Agreement (BAA) where the client clinic is a HIPAA-covered entity. See Section 9.
Usage data: We collect limited technical information when you visit our website — your IP address, browser type, pages visited, and referral URL — for security and basic operational purposes only. We do not use third-party analytics or advertising trackers.
Cookies: This website uses only essential first-party cookies necessary for it to function (session management, security). No advertising, analytics, or third-party cookies are set. You may disable cookies in your browser settings; this will not materially affect your ability to use this website.
3. How We Use Your Information
We use the information we collect to: (a) respond to audit requests and deliver the mystery shop report; (b) provide and operate our automation services for client clinics; (c) process call recordings and generate transcripts and daily briefings; (d) communicate with you about your account, service updates, and support; (e) maintain security and prevent fraud; (f) comply with applicable legal obligations; and (g) generate aggregated, de-identified industry benchmarks (no individual is identifiable in these).
We do not use your information for targeted advertising, behavioral profiling, or sale to third parties.
4. Legal Basis for Processing
For business contacts and audit requesters: processing is necessary for the performance of a contract or to take steps at your request before entering a contract, and in pursuit of our legitimate business interest in operating and improving our services. For call recordings and transcripts processed on behalf of a covered-entity client: processing is authorized by the Business Associate Agreement and governed by HIPAA.
5. Call Recording Disclosure — Florida Law
Florida Statutes § 934.03 requires all parties to a phone call to consent to recording. Every call processed through Katalyst's platform includes an automated pre-call disclosure: "This call is being recorded by [clinic name] and its service provider for quality, training, and business-record purposes. By continuing this call, you consent to being recorded. If you do not wish to be recorded, you may hang up now." This disclosure plays before any substantive conversation begins on both inbound and outbound calls. Timestamped logs of each disclosure are retained.
6. Sharing and Disclosure
We share your information only as follows: (a) Sub-processors: We use third-party vendors to operate our platform (cloud hosting, telephony, AI transcription). Each sub-processor is bound by a written data processing agreement. A current list of sub-processors is available on request at hello@katalyst.io. (b) Client clinics: Call recordings, transcripts, and briefing reports are shared with the client clinic on whose behalf they were created. (c) Legal compliance: We may disclose information if required by law, subpoena, or court order, or to protect the rights, property, or safety of Katalyst, our clients, or others. (d) Business transfer: In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information is transferred and becomes subject to a different privacy policy.
We do not sell, rent, or share your personal information with third parties for their own marketing or advertising purposes.
7. Data Retention
Call recordings and transcripts are retained for 6 years from the date of creation (aligned with HIPAA documentation requirements under 45 C.F.R. § 164.530(j)) or shorter if the applicable BAA specifies otherwise. Web form contact data (audit request submissions) is retained for 24 months from collection or the duration of the client relationship, whichever is longer. Briefing reports and operational data are retained for 12 months. You may request earlier deletion (see Section 8).
8. Your Rights
You may request access to, correction of, or deletion of personal information we hold about you by emailing hello@katalyst.io. We will respond within 30 days. Note: for call recordings or transcripts that contain a patient's information, those rights must be directed to the client clinic (the HIPAA-covered entity) under its Notice of Privacy Practices, not to Katalyst. We cannot independently fulfil patient rights requests over PHI held on behalf of a covered entity. Rights of access, amendment, and accounting of disclosures over PHI are governed by 45 C.F.R. §§ 164.524–164.528.
9. HIPAA and Protected Health Information
Many of Katalyst's med-spa clients qualify as HIPAA Covered Entities. In those relationships, Katalyst acts as a Business Associate as defined at 45 C.F.R. § 160.103. Call recordings and transcripts processed on behalf of a covered entity are Protected Health Information (PHI) under HIPAA. Katalyst's handling of that PHI is governed by the executed Business Associate Agreement, which includes: permitted uses and disclosures; Security Rule safeguards (encryption at rest and in transit, access controls, audit logs); Breach Notification Rule obligations; subcontractor BAA requirements; and PHI return or destruction upon termination. Katalyst's Security Rule program includes administrative, physical, and technical safeguards required under 45 C.F.R. Part 164, Subpart C.
10. Security
We implement technical and organizational measures appropriate to the risk, including: AES-256 encryption at rest for call recordings and transcripts; TLS 1.2+ encryption in transit; multi-factor authentication on all administrative accounts; role-based access controls; immutable audit logs; regular security assessments; and an incident response plan. No security measure is perfect. In the event of a data breach affecting your information, we will notify you and the applicable regulators as required by law.
11. Children's Privacy
Our services are directed exclusively to business operators aged 18 and over. We do not knowingly collect personal information from anyone under 13 years of age. If you believe we have inadvertently collected information from a minor, please contact us immediately at hello@katalyst.io and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to active clients by email at least 14 days before they take effect. The "Last reviewed" date at the top of this page indicates when the policy was last updated. Continued use of our services after a material change constitutes acceptance of the updated policy.
13. Contact
Privacy questions, data subject requests, and BAA inquiries: hello@katalyst.io · Katalyst · Miami, FL · United States.