Legal
Privacy policy
What data Clinicify handles, why, and what we will never do with it. This includes a full account of what happens when you connect your Google Calendar or your Zoom account.
Last updated: 6 August 2026
1. Who we are
Clinicify is practice software for small private clinics in the UK. Clinics use it to manage
appointments, patient records, lab results, payments and CQC compliance evidence. The software
itself runs at app.clinicifyapp.com. This website, clinicifyapp.com, is
our public site.
Clinicify is operated by CLINICIFY LTD, a company registered in England and Wales (company number 17386702), registered office 16 Mansfield Road, Poole, BH14 0DF, UK.
We are a UK business processing UK health data, so this policy is written to the UK GDPR and the Data Protection Act 2018.
For anything about data protection, email [email protected].
2. Controller and processor: who decides what
This distinction matters, so we will be precise about it.
For patient data, the clinic is the data controller and Clinicify is the processor. The clinic decides what patient data to record, why, and how long to keep it. We only act on the clinic's instructions, as set out in our contract with them and in our data processing agreement. We do not decide how patient data is used, and we do not use it for our own purposes.
For our own customer data, Clinicify is the controller. That means the clinic's staff accounts, billing details and how the clinic uses the product. We decide how that data is handled, and this policy explains it.
3. Data we hold about clinic staff
We are the controller for this data. We collect:
- Account details: name, work email address, role in the clinic, and the credentials held by our authentication provider, Clerk.
- Clinic details: clinic name, address, contact details and CQC registration details where you give them to us.
- Billing details: subscription plan, invoices and payment records. Card details go straight to Stripe and are never stored on our systems.
- Usage and technical data: sign-in times, IP address, browser and device type, and application logs. We use these to keep the service secure, to fix faults and to see which features are used.
- Support correspondence: emails and messages you send us.
4. Patient data we process for clinics
Here we are the processor and the clinic is the controller. Depending on how the clinic uses Clinicify, this can include patient names and contact details, appointment history, clinical notes, lab results, prescriptions and medication records, consent records, photographs where the clinic records them, payment records, and messages between the clinic and the patient.
Most of this is health data, which the UK GDPR treats as a special category. We hold it under our contract with the clinic and our data processing agreement, we act only on the clinic's instructions, and we apply the security measures in section 5.
Appointment emails and text messages. Patients receive booking confirmations, reminders, and sign-in codes for the patient portal. These are transactional messages: they are part of delivering the appointment the patient booked, not marketing. They are sent regardless of marketing preferences, because switching them off would mean a patient not being told about their own appointment.
We never use patient data to train AI models, and we never sell personal data.
If you are a patient and you want to see, correct or delete your records, contact your clinic. They control your data and they are the right people to ask. If you contact us directly we will pass your request to the clinic and tell you we have done so.
5. How we protect data
- Encryption in transit. Everything travels over TLS. There is no unencrypted route into the service.
- Encryption at rest. Stored data is encrypted.
- Per-clinic encryption keys for patient data, so one clinic's records are not protected by the same key as another's.
- Role-based access within a clinic. Clinical staff, receptionists and administrators see different things.
- Audit logging of access to patient records, so a clinic can see who looked at what. This is also what makes shared logins a bad idea.
- Multi-factor authentication is available to staff accounts.
- Integration tokens for Google and Zoom are encrypted at rest with AES-256-GCM, with the key held as a platform secret separate from the database.
If there is a personal data breach affecting a clinic's patient data, we notify the clinic without undue delay and in any event within 72 hours of becoming aware of it. The clinic, as controller, has its own 72-hour duty to the ICO and cannot meet it if we are slow.
6. Lawful bases
Where we are the controller, we rely on:
- Contract: to provide the service to the clinic, manage staff accounts and take payment.
- Legitimate interests: to keep the service secure, prevent abuse, fix faults, and improve the product. We have considered your interests and use the least data that works.
- Consent: for analytics cookies on this website, for optional things you switch on such as connecting Google Calendar or Zoom, and for marketing emails. You can withdraw consent at any time.
- Legal obligation: to keep accounting records and to answer lawful requests.
Where we are the processor for patient data, the lawful basis is the clinic's to establish, not ours. For a clinic providing healthcare that is normally Article 6(1) with the special category condition in Article 9(2)(h), health or social care, but the clinic is responsible for its own record of processing.
7. Cookies and analytics
We use Google Analytics 4 on this marketing site, and nowhere else. It does not run in the staff app, and it does not run in the patient portal. There is no third-party analytics anywhere inside the product.
On this marketing site
We use it to understand how the site is used: which pages people visit, how they arrived, roughly where in the world they are, and what device they use. It tells us whether the site is doing its job. It is not used to build a profile of you as an individual.
Analytics only runs after you accept it. The analytics script is not loaded and no analytics cookie is set until you press Accept on the cookie banner. If you press Reject, or ignore the banner entirely, nothing analytics-related loads and the site works exactly the same. There is no cookie wall here.
You can change your mind at any time. Use the cookie settings control, which is also in the footer of every page. Choosing Reject stops any further analytics collection.
Not in the staff app, not in the patient portal
Analytics stops at this website. We do not run Google Analytics, or any other third-party analytics, inside the staff app or the patient portal. Clinic staff using the software are not measured by Google, and neither are patients reading their own results and messages.
So no patient identifier, appointment detail or search term can reach an analytics provider from the product, because there is no analytics provider in the product to reach.
Google's role, transfers and retention
Google acts as our processor for analytics. This involves a transfer of data to Google in the United States. We rely on the UK Extension to the EU-US Data Privacy Framework, with Google's standard contractual clauses as a fallback safeguard. IP addresses are not stored by GA4 in a form we can use to identify you.
Two different clocks run here, and they are worth separating. The _ga cookie sits in
your browser for 13 months. Google keeps the underlying event data for 14 months, after which it
is deleted automatically.
Cookies on this website
| Cookie | Purpose | How long |
|---|---|---|
_ga, _ga_* | Google Analytics. Distinguishes one browser from another so visits can be counted. Set only if you accept. | 13 months. |
| None | This site sets no strictly necessary cookies. Your cookie choice is kept in your browser's local storage rather than in a cookie, so refusing cookies does not need a cookie. | Until you clear your browser storage. |
Waitlist and contact form
If you join the waitlist, we store the email address you give us and, if you fill them in, your clinic name and clinic type, along with the date. We use it to email you about early access and nothing else. If you use the contact form, your message is emailed to us and not stored on the website.
We check the IP address of form submissions in memory to block automated abuse. It is not written to a database.
8. Google Calendar and Google user data
Connecting a Google Calendar is optional. A clinician chooses to connect their own Google account so their Clinicify diary and their Google Calendar stay in step. This section sets out exactly what we access, what we do with it, what we store, and what we never do.
What we ask for, and why
openidandemail- To identify which Google account has been connected, so the clinician can see it in their settings and tell two accounts apart.
https://www.googleapis.com/auth/calendar.events- To read and write calendar events. This one scope powers the three features described below. Google classes it as a sensitive scope, which is why this section exists in the detail it does.
The three features that use your calendar
1. Appointment sync (writing to your calendar). Clinic appointments assigned to you are written to your Google Calendar as private events. The event title is always the same fixed generic string, "Clinicify appointment". There is deliberately no patient name, no treatment type and no clinical detail in the event. The event also contains a link back to the appointment in Clinicify, which only works for someone signed in to your clinic's Clinicify account.
2. Busy-time import (reading your calendar). We read your other calendar events so that Clinicify does not offer those times to patients as bookable slots. We store only the start time, the end time and the Google event id. We never store the titles, descriptions, locations, attendees or guests of those events.
3. Google Meet links. For appointment types marked as virtual consultations, we create the calendar event with Google Meet conferencing attached, and email the patient the join link.
What we store, and how it is protected
- The OAuth refresh token, encrypted at rest with AES-256-GCM. The encryption key is held as a platform secret, separate from the database.
- The connected account's email address.
- The target calendar id, so we write to the right calendar.
- A sync token, so we can fetch changes without re-reading everything.
- Imported busy times, as start and end times plus the Google event id, and nothing else.
This data is held in the UK and the EU, on Cloudflare Workers and Neon Postgres.
What we do not do with Google user data
- We do not sell it. Ever.
- We do not share it with third parties, except where sharing is necessary to provide the feature you turned on.
- We do not use it for advertising or ad targeting.
- We do not use it to train or improve any AI or machine-learning model, whether ours or a third party's.
- No humans read it, other than your own clinic staff seeing your calendar availability inside the app.
How long the connection lasts
Until you disconnect it, or until the clinic account is closed. You can disconnect at any time in the app: Settings, then Integrations, then Google Calendar, then Disconnect.
Disconnecting immediately deletes the stored tokens and every imported busy-time record. Calendar events we have already written to your Google Calendar stay in your calendar, because they are yours. You can delete them in Google Calendar.
You can also revoke Clinicify's access directly from your Google account at myaccount.google.com/permissions.
9. Google API Services Limited Use
Clinicify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
10. Zoom video consultations
Connecting Zoom is optional, and it is done per clinician. The clinician connects their own Zoom account, and every consultation is hosted from that account. Clinicify schedules the meeting; Zoom runs it.
What we ask for, and why
meeting:write:meeting- To create the consultation when a patient books.
meeting:update:meeting- To move the meeting if the appointment is rescheduled.
meeting:delete:meeting- To delete the meeting if the appointment is cancelled.
user:read:user- To read the connected account's email address, so the clinician can see which Zoom account is connected.
What we store
- The OAuth refresh and access tokens, encrypted at rest with AES-256-GCM. The encryption key is a platform secret held separately from the database.
- The connected Zoom account's email address.
- For each virtual appointment, the Zoom meeting ID and the join URL.
What we create in Zoom
A scheduled meeting, with the waiting room on and join-before-host off. Nobody enters until the clinician admits them, and two consultations can never overlap in the same room.
The meeting topic is deliberately generic: "[Clinic name] video consultation". It contains no patient name and no treatment detail, because the topic appears in Zoom's systems, in calendar invitations and on desktop clients.
What we never do with Zoom data
- We do not access, store or process meeting recordings.
- We do not access transcripts, chat messages or any meeting content.
- We do not access participant lists, meeting reports or usage analytics.
- We do not use Zoom's real-time media stream, and the app has no in-meeting component.
- We do not use any Zoom data for advertising, or to train AI models.
- We do not sell Zoom data.
Retention and deletion
Tokens are held until the clinician disconnects, in Settings, then Integrations, then Zoom, then Disconnect, or until the clinic account closes. They are deleted immediately on disconnect. Cancelling an appointment deletes the corresponding Zoom meeting.
You can also remove the app from the Zoom App Marketplace at any time, which revokes our access.
The meeting itself is governed by Zoom's own privacy policy and terms. Zoom is the controller of what happens inside the meeting, including anything a participant records or types there.
11. Sub-processors
We use other companies to run the service. Each is bound by a contract that holds them to the same obligations we owe you, and each gets only the data it needs to do its job.
- Cloudflare
- Application hosting (Workers) and file storage (R2). UK and EU.
- Neon
- PostgreSQL database. UK and EU.
- Clerk
- Authentication for clinic staff accounts.
- Resend
- Transactional email: appointment confirmations, reminders and sign-in codes.
- Twilio
- SMS appointment reminders.
- Stripe
- Subscription billing, and card payments taken by clinics from their patients through Stripe Connect.
- Anthropic
- The AI drafting used by the question-and-answer feature. Zero-data-retention is enabled on our account, and Anthropic is contractually barred from training any model on our data.
- Xero
- Optional accounting sync, only for clinics that connect it.
- Calendar sync and Google Meet, only for clinicians who connect it.
- Zoom
- Video consultations, only for clinicians who connect it.
- Google Analytics
- Analytics on this marketing site only, and only for visitors who accept. Not in the staff app, not in the patient portal. See section 7. No patient data reaches it.
We will tell clinic account holders before we add or change a sub-processor, so they have time to object. That process is set out in our data processing agreement.
12. International transfers
Patient data, Google Calendar data and Zoom connection data are held in the UK and the EU.
Google Analytics involves a transfer to the United States. We rely on the UK Extension to the EU-US Data Privacy Framework, with Google's standard contractual clauses as a fallback. This applies only to visitors to this marketing site who accept analytics. It does not apply to clinic staff using the app, to patients, or to patient data, because analytics does not run inside the product.
Where any other sub-processor involves a transfer outside the UK, we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment on file.
13. How long we keep data
- Free trial: 14 days.
- When a clinic account ends: the same 90 days for everyone, whether a paid subscription was cancelled or a free trial finished without one. The clinic and its data are kept for 90 days, then permanently deleted. We email 14 days and 3 days before the deletion date, and subscribing again at any point during the 90 days stops the deletion. See the terms for what you can and cannot do during that window.
- Patient records where the patient never books: the patient is warned at 21 days and again at 28 days, then the record is deleted at 30 days.
- Patient records where the patient does book: kept for as long as the clinic instructs. The clinic sets the retention period, because the clinic is the controller and has its own clinical record-keeping duties.
- Data export download links: expire after 7 days.
- Patient portal sign-in codes: valid for 10 minutes, single use, locked after 5 failed attempts. Patient portal sessions last 7 days.
- Google Calendar connection data: deleted immediately on disconnect.
- Zoom connection data: deleted immediately on disconnect.
- Billing and accounting records: 6 years, as UK tax law requires.
- Application logs: we do not store them. They can be observed in real time while an incident is being investigated, and are not written to any persistent store.
- Access and audit logs: a record of each time a patient record is opened, and of each staff sign-in, kept for the life of the clinic account and deleted with it.
- Waitlist entries: until we launch and you either become a customer or ask us to remove you.
14. Deleting your data
To disconnect Google Calendar or Zoom and delete the stored tokens: Settings, then Integrations, then the integration, then Disconnect. It takes effect immediately, with no request to us needed.
To delete a clinic account and its data, email [email protected] from the account holder's address, or ask through the app. We will confirm the request, let you export your data first, and then delete it. We aim to complete deletion within 30 days and will tell you when it is done.
If you are a patient, contact your clinic. They control your records.
Backups are the one exception to immediate deletion, and they work differently for records and for files. Deleted database records can persist in encrypted backups for up to 6 hours before those backups expire. Uploaded files, such as lab reports and photographs, are deleted immediately and are not held in any backup. Neither is restored to the live service.
15. Your rights
Under the UK GDPR you can ask us to:
- tell you what data we hold about you, and give you a copy
- correct data that is wrong or incomplete
- delete data, where there is no reason for us to keep it
- restrict how we use it, while a question about it is resolved
- send your data to you or another provider in a portable format
- object to processing we do on the basis of legitimate interests
- withdraw consent you have given, at any time
To exercise any of these, email [email protected]. We will respond within one month. If a request is complicated we may take up to two further months, and we will tell you if so. We do not charge for this. We may ask you to confirm who you are first, so we do not hand your data to the wrong person.
We do not make automated decisions about you that have a legal or similarly significant effect.
16. Complaints to the ICO
Our supervisory authority is the Information Commissioner's Office. If you think we have handled your data badly, please tell us first so we can put it right. You have the right to complain to the ICO either way, and going to us first does not affect that right.
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk
17. Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we handle your data, we will email clinic account holders before it takes effect. Changes to how we handle Google or Zoom user data will always be reflected here before the change goes live.
18. Contact us
Data protection and privacy: [email protected]
Anything else: our contact page.
Post: 16 Mansfield Road, Poole, BH14 0DF, UK
Our terms of service and data processing agreement sit alongside this policy. You can also change your cookie choice.