Privacy Policy
Benejam CRM · Last updated September 22, 2026
What this application is
Benejam CRM is a private, internal case-management application used by the clinical practice of Dr. Gustavo Benejam, Psy.D. It is not a public service and it is not open for general sign-up. Only authorized staff of the practice hold accounts, and every staff account requires a second authentication factor.
Information we hold
The application stores the records the practice needs to run its work: client contact details, case records, appointments, payments and referring-attorney information. Clinical content — notes, medical history and medication — is encrypted at the application level before it reaches the database, and is visible only to authorized staff.
Data we access through Google APIs
The practice connects the application to a Google account it owns. With that connection the application may access:
- Google Contacts (https://www.googleapis.com/auth/contacts) — to keep client and referring-attorney contact records consistent between the practice’s address book and the application.
- Account identity (openid, https://www.googleapis.com/auth/userinfo.email) — used for one purpose only: to confirm which Google account granted access, so that a connection cannot be established with the wrong account.
- Google Calendar and Google Drive — used, through a separate connection, to place appointments on the practice’s own calendars and to keep each case’s documents in its own folder.
What the contact sync does, and what it will not do
The synchronization is limited to contacts carrying one of two labels in the practice’s address book. Contacts without one of those labels are not read and are not modified.
When the application creates or completes a contact, it writes only name, phone number, email address and date of birth. It never writes clinical notes, medical history, medication, immigration case type, case identifiers, amounts or balances, and it does not read the notes field of a Google contact.
The synchronization fills in blanks and does not overwrite. When the two sides disagree, the application records the disagreement for a person to resolve rather than choosing a value on its own. It never deletes a contact, in either direction: a deletion in Google is reported as a conflict, not applied.
How we use and share it
Information obtained through Google APIs is used only to provide the features described above, for the practice that granted the connection. We do not sell it, we do not use it for advertising, and we do not transfer it to third parties, except where required by law.
Benejam CRM’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
No human reads this data other than the authorized staff of the practice using the application, except where it is necessary to resolve a support request, to address a security incident, or where the law requires it.
Storage, retention and withdrawal
The access credential Google issues is encrypted before it is stored and is never exposed to the browser. Case records are retained for the period required of clinical records in the State of Florida.
The practice can end the connection at any time from within the application, which revokes the credential with Google and deletes the stored copy. Access can also be withdrawn directly at myaccount.google.com/permissions. Withdrawing it stops all further synchronization.
Contact
Questions about this policy, or requests concerning information held about you, go to info@drbenejam.com.