Last updated: July 2026
Privacy Policy
Maxwell (“Maxwell,” “we,” “us”) provides practice management software to optometry practices (each, a “Practice”). This Privacy Policy explains how we collect, use, and protect information when a Practice and its patients use Maxwell.
Our role with patient health information
For any protected health information (PHI) a Practice enters into Maxwell — appointments, clinical notes, prescriptions, insurance and billing information — Maxwell acts as a business associate of the Practice under HIPAA, not as an independent data controller. The Practice is the covered entity and determines how that PHI is used; Maxwell processes it solely to provide the software, under a signed Business Associate Agreement (BAA) with the Practice.
Information we collect
- Account information — name, email, and role for practice staff who log in to Maxwell.
- Patient information entered by a Practice — demographics, appointment history, clinical encounter data, prescriptions, insurance details, and billing/payment records.
- Communications— appointment reminders, confirmations, and related messages sent by SMS or email on a Practice’s behalf.
- Usage data — basic technical logs (device, browser, timestamps, IP address) used for security monitoring and troubleshooting.
How information is used
Information is used only to operate Maxwell for the Practice: scheduling, clinical documentation, patient communication, billing and claims, and the AI-assisted features a Practice enables. We do not sell patient information, and we do not use it for advertising.
Service providers
Maxwell uses a small set of vetted subprocessors to operate the platform, each bound by contract to protect the information it processes:
- Amazon Web Services (AWS) — hosting, database, and file storage, under a HIPAA BAA.
- RingCentral — sending SMS appointment reminders and confirmations.
- Stripe — processing patient card payments (Maxwell does not store full card numbers).
- Claim.MD — submitting insurance eligibility checks and claims, where enabled.
Data security
Technical and organizational safeguards are described in full on our Security & Compliance page, including encryption at rest and in transit, network isolation, role-based access control, and audit logging of every access to patient records.
Data retention
Patient records are retained for as long as a Practice’s account is active, plus any period required by applicable law or the Practice’s own retention policy. A Practice may request export or deletion of its data by contacting us; deletion requests are handled consistent with legal recordkeeping requirements for medical records.
Your rights
If you are a patient of a Practice using Maxwell and have questions about your own health information — including requests to access, amend, or restrict it — please contact the Practice directly; they control that information. Questions about how Maxwell itself handles data can be sent to the address below.
Changes to this policy
We may update this policy as Maxwell evolves. Material changes will be reflected by an updated “Last updated” date above.
Contact
Questions about this policy can be sent to hello@maxwellsuite.com.