Data security

Keep access limited and client-controlled

The baseline starts with public search results and public web pages. When approved platform data improves the analysis, we use restricted read-only access.

01

Least access

When data is needed, we ask for the lowest practical permission: read-only Search Console, analytics or business-profile access.

02

Revoke anytime

The client controls platform access and can remove it. Access needs are reviewed when scope changes.

03

Contract before sensitive scope

If a project could require regulated data, work pauses for security, legal and contracting review.

Default data

What the baseline uses

  • Public Google Search + Maps results
  • Dated Google AI Overviews and ChatGPT + Gemini captures
  • Public clinic, competitor and source pages
  • Read-only aggregate search and analytics data, when approved
  • Service, market and location information supplied by the client

AI audit data flow

What enters a platform and what we retain

The baseline records only the business context and evidence needed for the agreed search questions.

01

Client input

Clinic domain, priority treatment, market, patient language, locations and selected competitors.

02

Platform input

Only approved patient questions plus clinic, service and location context enter search and AI platforms.

03

Evidence retained

Dated answer captures, visible sources, public pages, metrics and prioritized improvements.

04

Account state

Platform, visible model label, market, language and signed-in or signed-out state are logged where observable.

05

Optional access

Read-only aggregate Search Console, analytics or profile access only after client approval.

06

Offboarding

Revoke platform access, close shared accounts and complete the deletion schedule agreed in scope.

Procurement summary

Confirm controls before paid access

The free public-data audit can start without this pack. Paid work that uses client systems starts only after the required facts and controls are accepted.

Required in the scope or security pack

Contracting entity and incident contact

Data classes, approved accounts and processors

Processing locations and applicable transfer terms

Retention and deletion schedule

MFA, least-access and credential rules

Offboarding and access-revocation checklist

Contracting

Confirm requirements before access

NDA or DPA terms can be reviewed as part of the agreement. Rotgar does not claim a healthcare, GDPR or HIPAA certification on this site.

Security questions

Email evgeniy.yudin@rotgar.com to request the procurement checklist before sharing credentials or data.

Read the current site privacy notice

Free audit

Get a free public-data audit

The simplest free audit starts with one clinic or selected location, one priority market and one patient language.

Best fit Clinics, hospitals and medical groups in:
  • Dental
  • Aesthetic medicine
  • Physiotherapy
  • Fertility & IVF
  • Dermatology
  • Hair transplant
  • Plastic surgery
  • Mental health
  • Multi-specialty groups
  • Your current visibility and named competitors
  • The sources AI answers rely on
  • A prioritized list of improvements to implement

Need to include several clinics, locations, countries, markets or patient languages? Book a 20-minute call We’ll agree the scope and tailor the audit at no cost.

Preferred reply method
What are you most interested in?

Select all that apply.

This opens a prepared email in your mail app. Review it and press Send there.