shieldLegal

Privacy Policy

We take privacy seriously. Here's exactly what data we collect, how we use it, and the rights you have over it.

Last updated: July 13, 2026

lock

Your data is yours

We never sell patient or clinic data to third parties.

encrypted

Encrypted end-to-end

All data is encrypted in transit (TLS) and at rest.

manage_accounts

You stay in control

Request export or deletion of your data at any time.

Contents

1. Information We Collect

2. How We Use Your Data

3. Data Storage & Security

4. Data Retention

5. Third-Party Services

6. Your Rights

7. Cookies

8. Children's Privacy

9. Changes to This Policy

10. Contact Us

1

Information We Collect

ClinicFlow collects the minimum data necessary to provide a secure and functional clinic management platform. We collect:

Account & clinic data
Name, email address, phone number, clinic name, and billing contact when you register.
Patient health records
Clinics store patient demographics, medical history, prescriptions, lab results, and appointment records. ClinicFlow processes this data as a data processor — you, the clinic, are the data controller.
Usage & diagnostic data
Anonymised logs of feature usage, page views, and error reports used solely to improve the product. Not linked to patient identities.
Payment data
When your clinic collects payments from its own patients through the platform, billing is handled by Stripe. We store only Stripe-generated tokens and transaction identifiers — never raw card numbers.
2

How We Use Your Data

We use collected data only for the following purposes:

  • To provide, operate, and maintain the ClinicFlow platform
  • To send appointment reminders, invoices, OTP codes, and system notifications
  • To process patient invoice payments your clinic collects through the platform
  • To respond to support requests and troubleshoot issues
  • To improve platform reliability, performance, and user experience
  • To comply with applicable legal and regulatory obligations
block

We do not sell your data or patient data to advertisers, data brokers, or any third parties.

3

Data Storage & Security

All data is stored on servers within secured, access-controlled data centres. We implement industry-standard protections including:

  • TLS 1.2+ encryption for all data in transit
  • Encryption at rest for all databases and file storage
  • Role-based access control — staff only access data relevant to their clinic
  • Production database access restricted to authorised personnel only
  • Regular security audits and dependency updates

Our multi-tenant architecture provides logical isolation per clinic — no clinic can access another clinic's data under any circumstance.

4

Data Retention

We retain your data for as long as your account is active. Upon account termination:

  • Your data is retained for 90 days to allow for export and recovery
  • After 90 days, all clinic and patient data is permanently and irreversibly deleted
  • Billing and payment records are retained for 7 years as required by financial regulations
  • Anonymised, aggregate usage statistics may be retained indefinitely

You may request data deletion before the 90-day period by contacting clinicflow.amcodr@gmail.com.

5

Third-Party Services

ClinicFlow uses a limited set of third-party sub-processors. Each is bound by its own privacy policy and data processing agreements that meet applicable data protection standards:

payments

Stripe

Payment processing for patient invoice payments.

sms

Twilio

SMS appointment reminders and OTP verification codes.

mail

SMTP provider

Transactional email delivery (booking confirmations, invoices, invitations).

6

Your Rights

Depending on your jurisdiction (GDPR, CCPA, PDPA, etc.), you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate or incomplete data
  • Deletion — request erasure of your personal data ("right to be forgotten")
  • Portability — receive your data in a structured, machine-readable format
  • Restriction — request that we restrict processing of your data
  • Objection — object to processing based on legitimate interests

To exercise any of these rights, email clinicflow.amcodr@gmail.com. We will respond within 30 days.

info

Clinic administrators who handle patient data are independently responsible for honouring patient data rights under applicable healthcare privacy laws.

7

Cookies

We use one first-party cookie:

cf_token — authentication session cookie, expires in 7 days

We do not use advertising cookies, tracking pixels, or third-party analytics scripts. No cross-site tracking occurs.

8

Children's Privacy

ClinicFlow is a B2B healthcare platform intended for use by licensed clinics and their staff. It is not directed at individuals under the age of 13.

Clinics may store health records for minor patients as part of their clinical operations. Clinics are responsible for obtaining appropriate parental or guardian consent under applicable laws when doing so.

9

Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will:

  • Notify all clinic administrators by email at least 14 days before changes take effect
  • Update the "Last updated" date at the top of this page
  • Maintain an archive of previous versions upon request

Continued use of the platform after the effective date constitutes acceptance of the updated policy.

Terms of Service · Back to Home