1. Who we are
This Privacy Policy explains how Clinic Flow AI, a sole trader business operating in England, collects, uses, stores and protects personal information.
Business name: Clinic Flow AI
Business structure: Sole Trader
Email: [email protected]
Website: clinicflowai.uk
For the purposes of applicable UK data protection legislation, including the UK GDPR and Data Protection Act 2018, Clinic Flow AI may act as a Data Controller for information relating to its own business activities and as a Data Processor when processing personal data on behalf of our business clients.
2. What this Privacy Policy covers
This Privacy Policy applies to personal information collected or processed through:
our website;
contact forms;
booking forms and calendars;
communications with Clinic Flow AI;
our sales and business development activities;
our services provided to clients; and
our AI-powered reception, lead management, follow-up and appointment-booking systems where Clinic Flow AI processes information on behalf of a client.
Where we process personal data on behalf of a medical aesthetic clinic, that clinic will generally determine why and how the information is processed and will therefore normally be the Data Controller.
In those circumstances, Clinic Flow AI acts on the clinic's documented instructions as a Data Processor.
3. Personal information we collect
Depending on how you interact with us, we may collect:
Information you provide directly
This may include:
name;
email address;
telephone number;
company or clinic name;
information contained in messages or enquiries;
appointment or booking information;
information you provide when communicating with us.
Information collected through our website
We may collect technical information such as:
IP address;
browser type;
device information;
pages visited;
approximate location;
website usage information;
cookie and similar technology information.
The exact information collected depends on the technologies and services active on our website.
Information relating to clinic leads
When providing services to a clinic, our systems may process information supplied by prospective patients or customers, including:
name;
telephone number;
email address;
treatment or service of interest;
preferred appointment times;
communication history;
appointment status;
responses to automated messages;
information required to qualify an enquiry; and
other information voluntarily provided by the individual.
4. Medical and health information
Clinic Flow AI's AI receptionist and automated systems are not designed to request or collect medical conditions, diagnoses, medications, medical histories or other unnecessary health information.
Our systems will be configured to avoid requesting such information where it is not necessary for the service being provided.
If an individual voluntarily provides medical or health information, this may constitute special category personal dataunder UK data protection law.
Where Clinic Flow AI processes such information on behalf of a clinic, we will generally do so only on the clinic's documented instructions and in accordance with the applicable data-processing agreement.
The clinic remains responsible for determining the appropriate lawful basis and special-category condition for its processing.
Individuals should not provide unnecessary medical information through our general website contact forms.
5. How we use personal information
We may use personal information for the following purposes:
Operating our business
Including:
responding to enquiries;
communicating with prospective and existing clients;
arranging meetings;
providing our services;
managing client accounts;
processing payments;
maintaining business records; and
providing customer support.
Providing our AI and marketing services
For our clients, we may process personal information in order to:
receive and organise leads;
respond to enquiries;
qualify enquiries according to client instructions;
send follow-up communications;
assist with appointment booking;
manage appointment information;
maintain CRM records;
provide reporting and performance information; and
support the operation of automated workflows.
Security and fraud prevention
We may use information to:
protect our systems;
detect suspicious activity;
prevent fraud or abuse;
maintain system security; and
investigate security incidents.
Legal and regulatory purposes
We may process information where necessary to:
comply with legal obligations;
establish, exercise or defend legal claims;
maintain appropriate business records; or
cooperate with lawful requests from authorities.
6. Our lawful bases for processing
Depending on the circumstances, we may rely on one or more of the following lawful bases under UK data protection law:
Contract
Where processing is necessary to enter into or perform a contract with you.
Legitimate interests
Where processing is necessary for our legitimate business interests, provided those interests are not overridden by the rights and freedoms of the individual.
Our legitimate interests may include operating and improving our business, communicating with prospective clients, providing services, maintaining security and managing client relationships.
Consent
Where we ask for consent, we will explain what the consent relates to.
Where processing is based on consent, you may withdraw your consent at any time.
Legal obligation
Where processing is necessary for us to comply with a legal obligation.
The applicable lawful basis depends on the particular processing activity. We do not rely on one lawful basis for every use of personal information.
7. Marketing communications
We may communicate with prospective and existing business customers about Clinic Flow AI's services.
Where electronic direct marketing rules apply, we will comply with applicable UK requirements, including the Privacy and Electronic Communications Regulations (PECR).
You can ask us to stop sending marketing communications at any time by contacting:
Client clinics are responsible for ensuring that their own marketing communications to their leads comply with applicable data protection and electronic marketing laws.
Clinic Flow AI does not assume responsibility for a clinic's marketing compliance merely because we provide the technology used to send or manage communications.
8. AI and automated processing
Clinic Flow AI uses artificial intelligence and automation as part of its services.
AI may be used to assist with activities such as:
responding to enquiries;
categorising enquiries;
asking predefined qualification questions;
assisting with appointment scheduling;
generating or sending follow-up communications;
organising information; and
supporting customer-service workflows.
AI systems are configured according to the requirements and instructions of the relevant client.
Clinic Flow AI does not intentionally use client lead information to train general-purpose AI models or sell such information to third parties.
Our systems are not intended to make decisions producing legal or similarly significant effects about individuals solely through automated processing.
Where automated processing is used, it is intended primarily to support communication, administration, qualification and appointment-management activities.
9. Data relating to our clients' leads
Where Clinic Flow AI processes personal data on behalf of a clinic:
The clinic is generally the Data Controller.
Clinic Flow AI is generally the Data Processor.
The clinic determines:
what information is collected;
why it is collected;
the lawful basis for processing;
how long it should be retained;
how it should be used; and
when it should be deleted.
Clinic Flow AI will process that information only in accordance with the client's instructions and the applicable Data Processing Agreement, subject to applicable law.
The clinic is responsible for providing appropriate privacy information to its patients and prospective patients.
The clinic should also ensure that its forms, advertisements, website, consent mechanisms and communications comply with applicable UK data protection and marketing laws.
10. Data Processing Agreements
Where required, Clinic Flow AI will enter into a Data Processing Agreement with clients for whom it processes personal data as a processor.
Such agreements may address matters including:
processing instructions;
confidentiality;
security;
sub-processors;
international transfers;
data-subject rights;
data breaches;
retention and deletion;
audits and compliance assistance; and
return or deletion of personal data when the relationship ends.
This Privacy Policy does not replace a Data Processing Agreement between Clinic Flow AI and a client.
11. Who we share personal information with
We may use carefully selected third-party service providers to operate our business and deliver our services.
Depending on the service being provided, these may include:
GoHighLevel — CRM, forms, calendars, communications, workflows and automation;
Stripe — payment processing;
Zoom — video meetings;
Meta — advertising and lead-generation services;
Twilio — communications and messaging services; and
technology providers supporting AI and automation functionality.
We do not sell personal information.
We do not share personal information with third parties for their own unrelated marketing purposes.
Where third parties process personal data on our behalf, we take appropriate steps to ensure that the processing is subject to appropriate contractual and security arrangements.
The ICO expects privacy information to identify recipients or categories of recipients and to explain applicable international transfers where relevant.
12. International transfers
Some technology providers we use may process personal information outside the United Kingdom.
Where personal information is transferred outside the UK, we will take appropriate steps to ensure that the transfer is lawful under applicable UK data protection legislation.
Depending on the circumstances, this may involve:
an applicable adequacy regulation or decision;
appropriate contractual safeguards;
the UK International Data Transfer Agreement (IDTA);
the UK Addendum to approved international transfer mechanisms; or
another lawful transfer mechanism.
The exact safeguards applicable to a particular provider may depend on the services being used and their current data-processing arrangements.
13. Data security
We take reasonable and appropriate technical and organisational measures to protect personal information against:
unauthorised access;
accidental loss;
destruction;
alteration;
disclosure; and
other unlawful or unauthorised processing.
Security measures may include:
access controls;
authentication;
permissions management;
secure cloud services;
appropriate account security;
limiting access to information where reasonably necessary; and
reviewing our systems and processes where appropriate.
No method of electronic transmission or storage can be guaranteed to be completely secure.
14. How long we keep information
We do not keep personal information indefinitely.
Our own enquiries
Information relating to enquiries to Clinic Flow AI will normally be retained only for as long as reasonably necessary for the purpose for which it was collected, including managing potential or existing business relationships.
Where there is no ongoing relationship or legitimate business reason to retain the information, it will be deleted or securely disposed of in accordance with our retention procedures.
Client lead information
Where we process personal data on behalf of a client, the client determines the appropriate retention period.
When a client relationship ends, Clinic Flow AI will return or delete client personal data in accordance with the applicable Data Processing Agreement and the client's instructions, subject to legal obligations and limited technical backup requirements.
Legal and financial records
Certain information may need to be retained for longer where required by law, accounting requirements, dispute resolution or the establishment, exercise or defence of legal claims.
The ICO allows organisations to specify retention criteria where an exact retention period is not appropriate, provided the criteria are explained clearly.
15. Cookies and similar technologies
Our website may use cookies and similar technologies.
Some cookies may be strictly necessary for the website to operate.
Other cookies, such as analytics, advertising or tracking technologies, may require consent before being placed or used.
Where required, we will provide users with appropriate choices regarding non-essential cookies.
UK cookie requirements are governed in part by PECR, and the ICO states that non-essential cookies generally require appropriate consent before being set.
Our use of cookies may change as our website and services develop.
16. Your data protection rights
Depending on the circumstances and applicable law, you may have rights including:
the right to be informed;
the right of access;
the right to rectification;
the right to erasure;
the right to restrict processing;
the right to object to processing;
the right to data portability; and
rights relating to automated decision-making and profiling where applicable.
Where processing is based on consent, you have the right to withdraw that consent.
These rights are not absolute and certain legal exceptions may apply.
The ICO states that privacy information should explain the rights available and how individuals can exercise them.
17. How to exercise your rights
To exercise a data protection right or ask a question about how we process personal information, contact:
Email: [email protected]
We may need to request additional information where reasonably necessary to verify the identity of the person making a request.
We will respond within the time period required by applicable data protection law.
18. Complaints
If you have concerns about how Clinic Flow AI handles your personal information, please contact us first so that we can attempt to resolve the issue.
You also have the right to complain to the UK's data protection regulator:
Information Commissioner's Office (ICO)
You can find information about making a complaint on the ICO's website.
The ICO recommends that organisations tell individuals about their right to complain to the relevant supervisory authority.
19. Children's information
Our services are primarily intended for businesses and their customers.
Clinic Flow AI does not intentionally target children through its services.
Where our systems process information belonging to individuals who may be under 18, the relevant client remains responsible for determining whether the processing is appropriate and lawful.
For medical aesthetic advertising and services, clients must comply with applicable restrictions relating to under-18s.
20. Third-party websites and services
Our website or communications may contain links to websites or services operated by third parties.
We are not responsible for the privacy practices, security or content of third-party websites.
We recommend reviewing the privacy information of any third-party service before providing personal information to it.
21. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
changes to our services;
changes to technology;
changes to our data-processing activities;
changes to legal or regulatory requirements; or
changes to our business.
The latest version will be made available through our website.
The ICO recommends reviewing and updating privacy information when processing activities change.
22. Contact us
If you have any questions about this Privacy Policy or how Clinic Flow AI handles personal information, contact:
Clinic Flow AI
Email: [email protected]
Website: clinicflowai.ukClinic Flow AI
Copyrights 2025 | AI Agency Mastermind | Terms & Conditions | Privacy Policy