Terms of service
For the business taking the service, in plain language on purpose. In effect from 2 September 2026. Last updated 2 September 2026.
1. What the service does
Brin Front Desk answers your telephone when your team cannot. It answers questions you have approved, refuses ones it must, takes messages, and records what each caller wanted so your staff can follow up.
You are the business taking the service. These terms are between you and Brin Solutions. They are not a contract with your callers, and nothing in them gives a caller a right against either of us.
2. What it never does
- It never answers a clinical or medical question. Not about symptoms, side effects, complications, healing, medication, pregnancy, or whether a treatment is safe for a particular person. Such questions are refused and routed to your team.
- It never invents an answer. If you have not approved it, the assistant says it does not have that and takes a message.
- It never confirms an appointment. It records a requested time and tells the caller a person will call back to confirm. Nothing is held in a calendar.
- It never quotes a price you have not published, and offers no discounts, financing or insurance interpretation.
The first of those is enforced in code rather than by instruction, and is tested on every build. See section 3.
3. The medical boundary, and its honest limits
Every caller utterance is checked against a fixed vocabulary of emergency and clinical language before the assistant is permitted to answer. An emergency produces your approved emergency script. A clinical question produces a refusal and a message to your team. Both are spoken word for word and neither can be softened, reworded or skipped.
What this does not do: it does not diagnose, it does not decide whether a caller is really in danger, and it is not a substitute for a clinician. A caller in an emergency should call 911. The assistant will say so, but the service is not a medical device and must not be relied on as one.
4. Protected health information, and HIPAA
If you are a covered entity under HIPAA, Brin Solutions is your business associate. This section says what that means in practice, in the order HIPAA sets the obligations out.
4.1 The agreement that governs it
Before your line carries real calls, you and Brin sign a Business Associate Agreement. It is a separate document and it is required rather than optional: HIPAA does not permit you to disclose protected health information to us without one in place.
- Where that agreement and these terms differ on anything to do with protected health information, the agreement controls. This section states our obligations; it cannot narrow what we signed.
- Until it is signed, your line carries test traffic only. Do not route real callers to it and do not enter real patient information into it. That is a term of the service rather than a formality: it is the thing standing between a caller's words and a vendor chain not yet permitted to hold them.
4.2 What we do with it
- We use and disclose protected health information only to provide this service to you, and where the law requires it of us. Nothing else.
- Minimum necessary. We ask for, use and disclose the least information the service needs to work.
- We do not sell it. Not to anyone, under any arrangement.
- We do not use it to train or improve models, ours or anybody else's, and our agreements with our subcontractors carry that same restriction.
- We do not use it for marketing and we do not contact your patients. Every message the service takes goes to you.
- We may use de-identified and aggregated operating information, such as call volumes, response times and how often the assistant refused, to run and improve the service. De-identified means identifiers removed to HIPAA's own standard, so it can no longer be traced back to a person.
4.3 How we protect it
- Administrative, physical and technical safeguards as the HIPAA Security Rule requires, covering protected health information we create, receive, hold or transmit for you.
- Encrypted in transit and at rest.
- Access limited to the Brin personnel who need it for your account, each under their own named login, never a shared one.
- Nobody at Brin is given access to your data before being trained on handling protected health information, and their access ends when their role does.
- Changes made to your account are recorded in an audit log, with who made them and when. So is every time somebody at Brin opens a page in our operations console, with who they were and which of your records they were looking at. Reading your data leaves a trace here in the same way changing it does.
- Caller speech never reaches an operational log. Neither do transcripts, credentials, or password reset links. Deployment logs are readable by a wider group of people than the data permits, so the product withholds it rather than trusting the log to stay private.
4.4 Subcontractors
- We use subcontractors to run the service: telephony, speech, hosting and the database.
- A subcontractor that could handle protected health information is under a written agreement carrying these same obligations before any of your data reaches it. There is no exception to this, and no verbal arrangement counts as one.
- We keep a current list of them and we will tell you before it changes, with enough notice for you to object.
- Our voice vendor is a deliberate exception in the other direction. It receives only the answers you have approved, as text, so it can read them aloud. It never receives anything a caller says.
4.5 If something goes wrong
- We report to you any use or disclosure of protected health information our agreement does not permit, any breach of unsecured protected health information, and any security incident affecting it.
- Reporting is without unreasonable delay and in no case later than 60 days after we discover it, which is the outer limit HIPAA sets. Our intention is always sooner, and immediately where the problem is still happening.
- We tell you what happened, when, whose information was involved, what kinds of information, what we have done about it, and what we recommend, so you have what you need to meet your own notification duties.
- Notifying affected individuals is yours to do, not ours. HIPAA puts that duty on the covered entity. We give you everything we have and help you do it, and we do not do it on your behalf unless you ask us to.
4.6 The rights of the people you treat
- Access. If a patient asks you for their information and some of it is held in Brin, we provide it to you promptly, in time for you to meet the deadline HIPAA gives you.
- Correction. We make the amendments you direct us to make.
- Accounting of disclosures. We keep the records you would need to answer a request for one, and we give them to you on request.
- Requests come to you rather than to us. A caller who asks the assistant is directed to your team, because the assistant does not look a person up and will not confirm that we hold anything about them.
4.7 Records and audits
We make our internal practices, books and records relating to the protected health information we handle for you available to the Secretary of Health and Human Services as HIPAA requires, and to you on reasonable request. We will tell you when that happens, unless we are prohibited from telling you.
4.8 Retention, and the end of the relationship
- Your account keeps transcripts for 30 days and call records, including the messages taken from your callers, for 90 days. Both are yours to change during setup, and whatever you choose is what we keep to.
- Deleting to that schedule is not yet automatic, so today it happens when you ask and when we stop working together. We would rather say so than have you assume a timer is running.
- You can ask us for an export of your data at any time, including on your way out, and we will provide it. It is a request to us rather than a download, because there is no self-service export yet.
- When we stop working together we return or destroy the protected health information we hold for you, and we require the same of our subcontractors.
- Where destruction is genuinely not feasible, a backup that has not yet rotated out for instance, the protections in this section keep applying to it for as long as we hold it, we make no further use of it, and we tell you what remains and when it goes.
5. Recording and transcription
Calls are transcribed, and that cannot be switched off. The safety checks in section 3 read the transcript, so turning transcription off would turn the medical gates off with it. Recording the audio itself is a separate setting and is yours to choose.
Consent law for recording and transcribing a telephone call is a state matter and it varies. Some states need only one party to agree, which you satisfy. Others need every party, which means the caller has to be told.
So the disclosure is part of your greeting and you cannot remove it. We add it to whatever greeting you write, your setup screen shows you the whole thing as a caller will hear it, and every path that answers your telephone says it. If you write your own disclosure into your greeting, ours steps aside rather than saying it twice, and it steps back in if yours stops covering what your settings do.
It also follows your recording setting rather than overstating it. With recording off, your callers are told the call is transcribed. With recording on, they are told it is recorded and transcribed.
You are still responsible for meeting the consent requirements that apply where you and your callers are. We can make sure something is said on every call. We cannot judge whether our wording is sufficient for every state you take calls from, so check it, and tell us if you need it changed.
6. Your data
- Caller information belongs to you, not to Brin.
- We process it to run the service, on your instructions, and for nothing else.
- We do not sell it, and we do not use it to train models.
- Our subcontractors are listed in our data handling document, and we will tell you before that list changes.
- On termination you can ask us for an export, and we delete what we hold. Section 4.8 says exactly how both of those work today, including what is not yet automatic.
7. Your responsibilities
- Approve the answers. The assistant says what you approved, and the quality of the line is the quality of the library.
- Never put patient information into an approved answer or an uploaded document. Those are read aloud to whoever telephones. They are the wrong place for anything about a person, and the product cannot tell that a sentence you approved was about somebody real.
- Keep prices, hours and policies current.
- Work your tickets. Brin captures a caller's request; it does not fulfil it. A message nobody reads is a caller nobody rang back.
- Meet your own consent, licensing and advertising obligations.
- Sign the Business Associate Agreement before real callers reach the line.
8. Accounts and access
- Each person at your practice gets their own login. A shared login defeats the audit log, and that log protects you at least as much as it protects us.
- Deactivate a user the day their role ends. You can do it yourself and it takes effect immediately.
- Tell us promptly if you think an account has been compromised.
- You are responsible for what is done through your accounts.
9. Billing and refunds
- a duplicate charge;
- a billing error;
- a service failure on our part that prevented the line from answering for a material portion of the billing period.
10. Availability
The service depends on third parties. If the voice provider is unavailable, the line may not answer. This is a real limitation and is stated rather than buried. Any uptime commitment we make will be one the underlying vendors actually support, and we do not make one here.
Your call list shows you every occasion the line did not answer. We would rather you saw that than took our word for it.
11. Pilot scope
During the pilot the service is limited to appointment requests only, one location, English, and a fixed call allowance. It is not a medical device, not an answering service of record, and not a substitute for staff.
Features outside that scope are disabled rather than quietly absent, and we will not switch one on without telling you.
12. Responsibility, and its limits
- We are responsible for the service doing what these terms say it does, and for the obligations in section 4.
- We are not responsible for clinical decisions, for treatment, or for what your team does with a message the assistant took.
- We are not responsible for a caller acting on something the assistant refused to answer, or for a caller who does not call 911 when told to.
- Neither of us is liable to the other for indirect or consequential loss, and our total liability in any twelve month period is limited to the fees you paid us in that period. Nothing here limits liability that cannot lawfully be limited.
- The obligations in section 4 are not capped by the sentence above. Protected health information is not a commercial risk to be traded against a subscription fee.
13. Changes to these terms
We will tell you at least 30 days before a material change takes effect, by email to your account administrator and on this page. Continuing to use the service after that date means you accept the change. If you do not, you may cancel, and section 9 says what happens to the money.
The Business Associate Agreement is not changed this way. It changes only by agreement between us, in writing, because a notice period is not consent where protected health information is concerned.
14. Ending the agreement
- You may cancel at any time. Section 9 covers the billing consequence.
- We may end the agreement if fees go unpaid after notice, or if the service is being used in a way that breaks the law or puts callers at risk. We will tell you why.
- Either of us may end it if the other materially breaches the Business Associate Agreement and does not put it right within 30 days.
- On the way out: export your data, and section 4.8 applies to protected health information.
Questions about these terms: hello@brinsolutions.com. Anything about protected health information, section 4, or your own data: privacy@brinsolutions.com.