Legal

Privacy Policy

Last updated 1 September 2026

This is a demo product built to showcase a patient follow-up automation portal. This page reflects the policy such a product would run under.

1. What we collect

To run reminders and recovery sequences, we store patient names, phone numbers, treatment types, appointment dates and message logs on behalf of the clinic. We never collect patient data directly — it's entered by clinic staff.

2. How data is used

Data is used only to schedule and send the reminders, recovery messages and nudges a clinic configures. We do not sell patient data, and we do not use it to train models or for advertising.

3. Storage & encryption

Phone numbers are masked in the interface, and message logs are encrypted at rest. Access is restricted to staff accounts a clinic explicitly invites.

4. Consent & opt-outs

Every automated message respects patient consent. A patient can opt out of any channel at any time, and that opt-out is honoured immediately across every automation.

5. Data retention

Patient and message data is retained for as long as a clinic's account is active. On account closure, data is deleted within 30 days unless a longer retention period is required by law.

6. Third parties

Messages are delivered through WhatsApp Business API and SMS gateway partners solely to route the message — they do not retain patient data beyond what's required for delivery.

7. Your rights

Clinics can request an export or deletion of their data at any time by contacting Clinic Success. Patients can ask their clinic to remove them from any recall sequence.