Privacy Policy

Effective September 28, 2026

1. Who we are and what this policy covers

Dekho LLC, a California limited liability company with its mailing address at 1247 Crescent Ter, Sunnyvale, CA 94087 ("Dekho", "we", "us"), provides cloud software for medical practices and other businesses: Dekho Cloud eFax (online fax), the Dekho Cloud Dialer (business calling), Dekho Cloud Healthcare (patient charts, clinical notes and related AI agents), and the account and billing console that ties them together (together, the "Services"). We also operate the marketing website at www.dekho.cloud (the "Site").

This policy explains what information we collect, how we use and share it, and the choices you have. It covers two different roles we play:

  • For the Site and for account, sign-in and billing information, we decide how the information is used. This policy describes that use.
  • For the content our customers put into the Services (faxes, calls, recordings, transcripts, patient charts and notes), we process it on our customer's behalf and under our customer's instructions. When that content includes protected health information ("PHI") and the customer has signed a Business Associate Agreement ("BAA") with us, the BAA governs how we may use and disclose that PHI, and it controls over this policy where the two differ. The patient-facing privacy practices for that information are the healthcare provider's, not ours. Patients with questions about their records should contact their provider.

2. Information we collect

2.1 The Site

The Site is a static website. It sets no cookies, runs no analytics, advertising or tracking scripts, and loads no fonts, scripts or other resources from third parties; its security policy restricts the browser to loading content from our own domain. It has no forms. If you email or call us from the Site, we receive what you send, such as your name, email address, phone number and message. Like any web server, our hosting infrastructure (Amazon Web Services) processes your IP address and basic request information to deliver the pages.

2.2 Account and sign-in information

  • Your email address, and your name if you or your administrator provides one.
  • Your organization ("tenant") and your role within it (for example, administrator or member), and invitations you send or receive.
  • Sign-in credentials. Passwords, passkeys and optional authenticator-app two-factor codes are handled by our identity provider (Amazon Cognito), which also applies automated threat protection to sign-in attempts. We do not see the password you choose.
  • Session information needed to keep you signed in and to sign you out automatically after a period of inactivity.
  • A small first-party cookie on our product domains that remembers your chosen display theme (light or dark) on your device. It is tagged with a one-way hash of your user id, not the id itself, and is deleted when you sign out. Our product domains also set strictly necessary sign-in and session cookies.

2.3 Billing information

Your organization's plan, subscription status, invoices, billing contact details, and usage counts (for example, fax pages, call minutes and AI usage). Usage records sent to our billing system contain counts and identifiers only, never fax, call or chart content.

2.4 Customer content processed through the Services

  • eFax: faxes you send and receive (the document images), fax numbers and routing details, your address book, delivery status, and, where enabled, AI First Look results (such as the document type, sender, patient name, date of birth and a summary). Corrections your staff make to First Look results are stored with the fax.
  • Dialer: call details (numbers, times, duration, status), and, when recording or transcription is turned on for a call, the call audio, the transcript, and AI-generated outputs such as a First Look summary. Recording, transcription and First Look on calls are clinical features, turned on only for organizations that have the Healthcare module and a BAA on file with us.
  • Healthcare: patient chart information, including demographics, appointments and visits, vitals, documents filed to the chart, encounter recordings and transcripts, clinical notes, diagnosis codes, tasks, and conversations with the in-product assistant.
  • Support requests: the message you write when you contact support from inside a product, with limited technical context. It reaches our team by email, hosted by Google Workspace, and stays in that support inbox. The Services themselves do not store the message after sending it.

2.5 Security and audit logs

We log access to patient data at two levels, so that it can be reviewed later. Access at the AWS level to the data stores that hold patient data is recorded in a separate logging account that the applications cannot reach or erase. Each product also keeps its own access log inside the product: in Dekho Cloud Healthcare, a record of who viewed, searched, added or deleted patient information and when; in Dekho Cloud eFax and the Dekho Cloud Dialer, a log of requests made to the Services.

3. How we use information

  • To provide, operate and secure the Services, including delivering faxes and calls, running the AI features you enable, and authenticating users.
  • To bill for the Services and to send account, billing and service notices.
  • To provide support and respond to your requests.
  • To detect, investigate and prevent security incidents, abuse and fraud, and to keep audit records.
  • To comply with law and enforce our agreements.

We do not sell or share personal information, and we do not use customer content for advertising.

4. Artificial intelligence features

Several features use AI models to read, summarize or draft from customer content: AI First Look on faxes and calls, encounter note drafting, the chart Agent Report, and the Healthcare assistant (chat). These features are available only to organizations that have the Healthcare module enabled and a BAA on file with us.

The language models run on Amazon Bedrock under our agreement with Amazon Web Services. Amazon Bedrock does not use prompts or outputs to train models. Content may be held briefly in a short-lived prompt cache to speed up repeated requests, and is not kept after that. We keep Bedrock's optional request logging turned off. Diagnosis-code suggestions use Amazon Comprehend Medical. Encounter recordings in Dekho Cloud Healthcare are transcribed by Amazon Transcribe. Dekho has opted its AWS organization out of AWS AI services using customer content to develop or improve those services. Call transcription in the Dekho Cloud Dialer is performed by Telnyx under our BAA with Telnyx.

AI output can be wrong. It is offered as an aid to the people using the Services and does not replace their professional judgment. Clinical notes drafted by AI must be reviewed and signed by a clinician before they are filed.

5. How we share information

We share information only as described here:

  • Service providers (subprocessors) that host or deliver parts of the Services for us, under contracts that restrict their use of the information:
    • Amazon Web Services: hosting, storage, databases, sign-in (Amazon Cognito), email delivery (Amazon SES), AI models (Amazon Bedrock), medical coding (Amazon Comprehend Medical), transcription (Amazon Transcribe) and the clinical record store (AWS HealthLake). Covered by our BAA with AWS.
    • Telnyx: fax transmission and phone calls, including call recording and call transcription. Covered by our BAA with Telnyx.
    • Google (Google Workspace): company email, including support requests.
  • Within your organization: content in the Services is visible to the users your organization authorizes, according to the roles your administrators set.
  • At your direction: for example, when you send a fax or place a call, the recipient receives what you send.
  • For legal reasons: when required by law, subpoena or court order, or to protect the rights, safety or property of Dekho, our customers or others. Where PHI is involved, we disclose it only as the BAA and HIPAA permit.
  • Business transfers: in connection with a merger, acquisition or sale of assets, subject to this policy and any BAA in force.

Our billing system is software we run ourselves inside our own cloud accounts, not a third-party service.

6. Where information is stored

We store data in the United States, in the AWS US East (N. Virginia) region. When an AI language-model feature runs, the content is processed in memory in one of three US regions (US East (N. Virginia), US East (Ohio) or US West (Oregon)) and is not stored there. We offer the Services only in the United States.

7. How we protect information

  • Patient data is kept in dedicated cloud accounts, separate from the accounts that run sign-in and billing.
  • Stored patient data is encrypted with encryption keys dedicated to each product's data.
  • Connections to and between our services use TLS. Faxes and calls that travel over the public telephone network are not encrypted on that network.
  • AWS-level access to the data stores that hold patient data is recorded in a separate, access-restricted logging account, and each product keeps its own access log.
  • Sign-in supports passkeys and optional two-factor authentication, with automated threat protection. Sessions are short-lived and end automatically after inactivity.
  • Our production accounts run continuous threat detection, security posture checks and web application firewalls.

Dekho is built for HIPAA. Our SOC 2 program is in progress. No system is perfectly secure, and we cannot guarantee that information will never be accessed without authorization.

8. Retention and deletion

We keep information for as long as your organization uses the Services and as the settings below describe, unless your organization deletes it sooner, a longer period is required by law, or your agreement with us says otherwise.

  • Archive and Shred. Users can Archive items, which takes them out of the everyday view without deleting them, and Shred items, which permanently erases the content. After a Shred we keep only a record that the item existed (identifiers and timestamps, no content).
  • Faxes are kept until they are shredded. After 30 days they move to lower-cost storage that can still be read instantly. Our telephony provider may keep its own copy of transmitted faxes under its retention practices and our BAA with it.
  • Call recordings in the Dekho Cloud Dialer are deleted automatically 90 days after they are stored. Once we have saved a recording, we delete the copy held by our telephony provider. A call that is added to a patient's chart keeps its recording in Dekho Cloud Healthcare with the chart, beyond the Dekho Cloud Dialer's 90 days.
  • Healthcare encounter recordings that are never approved are flagged after 30 days and their audio is deleted 14 days after that; the transcript and draft note remain. Audio for approved, filed recordings is kept until deliberately removed.
  • Healthcare assistant (chat) conversations are deleted automatically 90 days after each message is written, and users can delete a conversation at any time.
  • Access logs. Dekho Cloud Healthcare's per-user access records and shred records are kept for at least six years. Dekho Cloud eFax and Dekho Cloud Dialer request logs are kept for three months.
  • Invitations expire after seven days.

When your organization's subscription ends, we delete its content on written request to legal@dekho.cloud, subject to the BAA and legal holds. Files you download to your own device are outside our control and are not affected by deletion in the Services.

9. Your choices and rights

  • Account users can update their name and sign-in settings in the account console, and can ask us to access, correct or delete their account information by contacting us.
  • Patients and others whose information is in a customer's records should contact that customer (for example, their healthcare provider). We will help our customers respond to such requests as the BAA requires.
  • Depending on where you live, you may have additional rights under state privacy laws; contact us to exercise them.

We will not discriminate against you for exercising any right you have.

10. Children

The Services are for businesses and are not directed to children. Users must be at least 18. We do not knowingly collect personal information from children through the Site or accounts. Patient information about minors that a healthcare customer places in the Services is processed on that customer's behalf under the BAA.

11. Changes to this policy

We may update this policy. If we make material changes, we will notify account administrators by email or in the Services before the changes take effect, and we will update the effective date above.

12. Contact us

Dekho LLC, 1247 Crescent Ter, Sunnyvale, CA 94087

Email: legal@dekho.cloud

Phone: (715) 587-2429

Talk to us

Talk to the people building Dekho.

Call the founder directly, or email sales. We'll set you up ourselves.

Already use Dekho? Sign in