Skip to content
clinvaleBack to site

Privacy policy

How this service handles the information a clinic and its patients entrust to it.

Last updated 2026-09-10.

Who we are, and what our role is

This service is operated by [Legal entity name — add this in config/company.php before launch], of [Registered address — add this in config/company.php before launch].

The distinction that matters: the clinic is the controller of its patient records, and we are only a processor. The clinic decides what is recorded and why. We hold and process it on the clinic's instructions in order to provide the software, and for nothing else.

What is held

  • Clinic account data — staff names, email addresses, phone numbers, roles, and the clinic's own settings.
  • Patient records entered by the clinic — contact details, appointments, treatments and clinical notes, prescriptions, consent forms, invoices and payments, and clinical photographs where the clinic uses that feature.
  • Messages sent on the clinic's behalf — the recipient's number, the message content, and its delivery state, kept so the clinic can see whether a reminder arrived.
  • Operational records — an audit log of significant actions, and ordinary server logs.

Health information is sensitive by nature. It is entered by the clinic, belongs to the clinic, and is not used by us for any purpose of our own.

What we do not do

  • We do not sell data. There is no circumstance in which we would.
  • We do not use patient records for advertising, profiling, or to train machine-learning models.
  • We do not share one clinic's data with another. Records are separated per clinic at the database layer and every query is scoped to the signed-in clinic.
  • We do not read patient records except where a member of the clinic asks us to in order to resolve a support issue, or where we are legally required to.

Who else processes it

Running the service means relying on a small number of providers. Each of these may hold clinic data in the course of doing its job:

  • Hetzner Online GmbHApplication and database hosting (Germany / Finland).
  • Meta Platforms IrelandWhatsApp message delivery (only if a clinic enables it) (Ireland / United States).
  • ResendTransactional email delivery (United States).

WhatsApp messaging is off unless a clinic switches it on and connects its own account. A clinic that leaves it off sends nothing to Meta.

How it is protected

In plain terms, and only what is actually in place: traffic is encrypted in transit; passwords are hashed; access is governed by per-clinic roles and permissions; two-factor authentication and passkeys are available to every account; significant actions are written to an audit log; and third-party API credentials a clinic stores with us are encrypted before they are saved.

Our security page sets out both what is in place and what is not yet, in more detail. We would rather a clinic knew the limits than assumed protections that are not there.

How long it is kept

Clinic data is retained for as long as the clinic's account is open. If a subscription lapses, the workspace becomes read-only rather than closed — the records stay, and the clinic can still read and export them. Locking a clinic out of its own patient history over a failed payment is not something we will do.

A clinic may ask us to delete its workspace at any time. We will do so within 30 days, other than anything we are required to retain by law. Backups age out on their own cycle.

Patients' rights

A patient's relationship is with their clinic, so requests to see, correct, export or delete a record should go to the clinic. The clinic can do all of these from within the software. Where a clinic asks for our help to fulfil such a request, we will give it.

A patient can stop WhatsApp messages at any time by telling the clinic, which records the preference against the patient's record. Once set, no further messages are sent to that patient.

Where data is held

Servers are located in the European Union. Some sub-processors listed above operate outside it, which means data may be transferred internationally in the course of delivering messages or email.

If your clinic is subject to UK or EU data protection law, or to health-data rules in your own country, please raise it with us before signing up. Some of those regimes carry obligations — a data processing agreement, specific transfer safeguards, or national health-data integrations — that we will confirm we can meet rather than assume.

Changes, and how to reach us

If this policy changes materially we will tell account owners by email before it takes effect, rather than quietly changing the date at the top.

Questions about anything here go to privacy@clinvale.com.

A note on the limits of this page

This policy is written to be accurate and readable, but it is not legal advice and it has not been reviewed by a lawyer. If you are a clinic in a regulated market, or we are, it should be.