Privacy Policy
Last updated: June 2026
Sondaggio ("Sondaggio," "we," "us," or "our") is a patient-satisfaction survey platform operated by Telio, LLC, a Pennsylvania limited liability company. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to the Sondaggio website at sondagg.io, the operator dashboard, the SMS survey experience, and any related services we provide (collectively, the "Service").
We designed Sondaggio to collect as little personal information as possible. We do not sell information, we do not use patient feedback for advertising, and we do not knowingly receive Protected Health Information (PHI). Read on for the details.
1. Scope and who this applies to
Sondaggio has two categories of users, and this policy treats them differently:
- Practice Operators — the healthcare practices, clinics, and authorized staff who create an account, configure surveys, and view results. Operators are our direct customers and have a contractual relationship with us.
- Patients — the individuals who text a 5-character code to a practice-provisioned number and complete a survey about their visit. Patients interact with Sondaggio on behalf of, and at the invitation of, the Operator.
When an Operator uses Sondaggio to collect feedback from Patients, the Operator is the controller of that data and Sondaggio is the processor. Operators are responsible for ensuring they have a lawful basis to invite Patients to provide feedback.
2. Information we collect from Operators
When you create and use an Operator account, we collect:
- Account information: your name, work email address, password (stored only as a salted hash), practice name, role, and time zone.
- Practice and location data: practice address(es), phone number(s), location names, and the Google or Yelp listings you connect for the reputation module.
- Billing information: billing contact, billing address, and the last four digits and brand of the card on file. Full card numbers are tokenized and held by our payment processor; Sondaggio never stores them.
- Usage and diagnostic data: login timestamps, IP address, browser type, pages viewed inside the dashboard, feature interactions, and error logs.
- Communications: support tickets, emails, and any feedback you send us.
3. Information we collect from Patients
A Patient interaction begins when the Patient sends a 5-character code via SMS to a practice-provisioned phone number. From that point forward we collect only what is required to deliver the survey and report results to the Operator:
- Phone number: the mobile number that originated the inbound SMS, used to match the Patient to a survey session and to deliver the survey link.
- Survey responses: ratings, multiple-choice selections, and free-text answers submitted by the Patient through the web survey.
- Technical metadata: the timestamp of the response, the device type and browser used to render the survey, and a session token. We do not set advertising identifiers.
- Carrier data passed through SMS: when a Patient texts us, the underlying carrier exchanges routing data with our SMS provider. We do not retain carrier metadata beyond what is needed for delivery and compliance recordkeeping.
What we do not collect from Patients: we do not store a Patient's name, date of birth, address, email, insurance information, medical record number, diagnosis, treatment, or any other clinical information. If a Patient voluntarily types such information into a free-text field, we treat it as ordinary survey content and do not attempt to associate it with an identity.
4. How we use information
We use the information described above only for the following purposes:
- Service delivery: creating and authenticating accounts, sending survey links, recording responses, and rendering analytics dashboards for the Operator.
- Billing and account management: charging subscription fees, sending receipts, and contacting Operators about their account.
- Customer support: diagnosing issues, answering questions, and improving onboarding.
- Product analytics: understanding how Operators use features, in aggregate, to prioritize improvements. We do not use Patient survey content for analytics beyond what the Operator sees.
- Security and abuse prevention: detecting fraudulent signups, abusive SMS patterns, and policy violations.
- Legal compliance: responding to lawful requests, enforcing our Terms, and complying with applicable laws and carrier regulations.
We do not use any information for advertising, profiling, or sale to third parties.
5. SMS messaging and carrier data
Sondaggio's SMS flow is Patient-initiated: a Patient texts a 5-character code to a number the Operator has displayed in their practice, and we respond with a survey link. We do not send unsolicited marketing texts. Reminder messages, if enabled by the Operator, are sent only to numbers that have initiated a survey session.
- Provider: we use an enterprise SMS infrastructure provider that is registered with U.S. carriers under the Campaign Registry framework. The provider acts as our processor and is contractually prohibited from using Patient phone numbers for marketing.
- Frequency: typical message volume is two to four messages per survey (acknowledgement, link, optional reminder, optional thank-you).
- Message and data rates: standard message and data rates from the Patient's carrier may apply.
- Opt-out: a Patient may reply STOP at any time to opt out. We honor STOP within 24 hours across all numbers associated with that Patient. A Patient may reply HELP to receive contact information.
- No sharing for marketing: mobile information, including phone numbers and consent status, is not shared with third parties for marketing or promotional purposes.
6. How we share information
We do not sell personal information. We share information only with the categories of recipients listed below, and only to the extent necessary for them to perform their function:
- Payment processor — to charge subscription fees and store tokenized card data.
- SMS / messaging carrier — to deliver and receive text messages.
- Cloud hosting and infrastructure provider — to run the application, databases, and backups.
- Transactional email provider — to send account, billing, and alert emails to Operators.
- Error monitoring and logging providers — to detect and diagnose technical problems.
- Review platforms (Google, Yelp) — only the review identifiers and metadata required to display reviews you have connected. We do not push Patient survey content to these platforms.
- Professional advisors — accountants and attorneys bound by professional duties of confidentiality.
- Legal and safety — when required by law, subpoena, or court order, or to protect the rights, property, or safety of Sondaggio, Operators, Patients, or the public.
- Successor entities — in connection with a merger, acquisition, financing, or sale of assets, subject to the protections of this policy.
Each subprocessor is bound by a written agreement that requires them to safeguard information consistent with this policy. A current list of subprocessor categories is available on request to [email protected].
7. Healthcare and HIPAA notice
Sondaggio is not a HIPAA-covered entity and, in its standard configuration, is not a HIPAA business associate. We deliberately designed the Service so that Protected Health Information (PHI) is not required to operate it. Specifically:
- We do not request, store, or transmit Patient names, dates of birth, addresses, insurance information, diagnoses, procedures, or treatment plans.
- Patient survey sessions are keyed off of an inbound SMS code and the originating phone number; they are not keyed off of a medical record identifier.
- Survey questions configured by the Operator should not solicit clinical details. Operators must not customize surveys to collect PHI.
Operators remain fully responsible for their own HIPAA compliance, including how they invite Patients to leave feedback and how they use any information they receive back from the Service. If an Enterprise customer has a use case that may involve PHI, contact [email protected] to discuss a Business Associate Agreement (BAA); a BAA is not in effect unless executed in writing.
8. Data retention
- Operator account data: retained for the life of the account and for 90 days after the account is closed, after which it is deleted from primary systems. Backups roll off within an additional 30 days.
- Patient phone numbers: retained for 12 months from the last survey interaction tied to that number, then automatically purged. We retain a one-way hash of the number for the same 12-month window to honor STOP requests and prevent re-contact.
- Survey responses: retained for the life of the Operator account because they form the analytical record the Operator paid for. Operators may request deletion of specific responses at any time; deletion is completed within 30 days.
- Billing records: retained for at least seven years as required by tax and accounting law.
- Aggregate, de-identified data: may be retained indefinitely.
9. Security
We protect information with administrative, technical, and physical safeguards appropriate to the sensitivity of the data:
- Encryption in transit: all connections to Sondaggio use TLS 1.2 or higher with modern cipher suites.
- Encryption at rest: databases and backups are encrypted with AES-256.
- Access control: production access is restricted to a small number of authorized engineers, requires multi-factor authentication, and is audit-logged.
- SOC 2–aligned practices: we follow security, availability, and confidentiality controls modeled on the AICPA SOC 2 trust services criteria.
- Vulnerability management: dependencies are scanned continuously and patched on a documented schedule.
- Breach notification: if we confirm a security incident that affects your personal information, we will notify affected Operators within 72 hours of confirmation, in addition to any disclosures required by law.
No system is perfectly secure. We strongly recommend that Operators enable available account protections and use unique, strong passwords.
10. Cookies and tracking
Sondaggio uses cookies sparingly:
- Session cookie: the operator dashboard sets a first-party session cookie that keeps you signed in. It is required for the Service to function.
- CSRF token: a small first-party cookie used to protect form submissions.
- No advertising trackers: we do not use Google Analytics, Meta Pixel, or any other cross-site advertising or behavioral tracking technology on sondagg.io or the dashboard.
- No "Do Not Track" override: because we do not track across sites, browser Do Not Track signals have no additional effect on our processing.
11. Children's privacy
Sondaggio is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. The survey experience is intended for the adult who attended or accompanied a Patient at a healthcare visit. If you believe we have collected information from a child under 13, contact [email protected] and we will promptly delete it.
12. Your rights
Depending on where you live, you may have rights to:
- Access — request a copy of the personal information we hold about you.
- Correct — ask us to correct inaccurate information.
- Delete — ask us to delete your personal information, subject to limited exceptions (such as legal recordkeeping obligations).
- Port — receive a machine-readable copy of the data you provided to us, in CSV or JSON.
- Object or restrict — object to or restrict certain processing, where applicable.
- Withdraw consent — where we process information on the basis of consent, withdraw that consent.
To exercise a right, email [email protected]. We will acknowledge your request promptly and respond substantively within 30 days. To protect you, we may need to verify your identity before fulfilling a request. Patients should be aware that survey content is owned by the Operator; deletion requests for survey content may be directed to the Operator that invited the survey.
13. California residents
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, grants you the rights to know, delete, correct, and limit the use of sensitive personal information, and the right to opt out of the sale or sharing of personal information. Sondaggio does not sell personal information and does not share personal information for cross-context behavioral advertising. We have not done so in the prior 12 months. To exercise your California rights, email [email protected] with "California Privacy Request" in the subject line. You may designate an authorized agent to make a request on your behalf; we will require reasonable verification of that authorization.
14. International users
Sondaggio is operated from the United States and is intended for U.S.-based healthcare practices. If you access the Service from outside the United States, you understand that your information will be processed in the United States, where data protection laws may differ from those in your country.
15. Changes to this policy
We may update this policy from time to time. If we make a material change, we will notify Operators by email and post a notice in the dashboard at least 14 days before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
16. Contact us
Questions, requests, or concerns about privacy? We want to hear from you.
Email: [email protected]
Legal: [email protected] or [email protected]
Mail:
Telio, LLC — Privacy
8 Atkinson Drive, Unit 296
Doylestown, PA 18901
(267) 601-0119
United States