Privacy policy
Last updated: 4 August 2026
MedicalSuite is practice-management software for clinics. This policy explains what personal data we handle, why, and what rights you have.
Our role
MedicalSuite is used by clinics, and the clinic decides what data it collects and keeps.
- The clinic is the data controller.
- MedicalSuite is the processor: we store and process data on the clinic's instructions and do not use it for our own purposes.
If you are a patient, your first point of contact is the clinic. We will help them respond.
Data we handle
From clinic staff using MedicalSuite: name, email address, role, and audit records of actions taken in the system.
From patients and enquirers, entered by the clinic or submitted through its forms: name, contact details, appointment details, clinical notes and documents the clinic records, and billing records.
From connected messaging channels (Facebook Messenger, Instagram, WhatsApp, SMS and calls):
| Data | Why |
|---|---|
| Message content, including photos and files you send | So clinic staff can read and answer you |
| Your name and profile picture on that platform | So staff know who they are talking to |
| A platform identifier (page-scoped ID, Instagram ID, phone number) | So replies reach the right conversation |
| Timestamps and delivery status | To show conversation history in order |
We receive this only for conversations with a clinic that has connected its own accounts. We never receive your password, friends list, posts, or anything you have not sent to that clinic.
What we do not do
- We do not sell personal data.
- We do not use patient data for advertising.
- We do not use patient data to train machine-learning models.
- We do not share data between clinics. Each clinic's data is held in a separate database.
Chatbot assistants
A clinic may enable an automated assistant to answer first and hand over to staff. Where that is enabled:
- The assistant receives the messages you send to that clinic.
- A member of staff can take over at any time, and does so automatically the moment they reply.
- Access to clinical information is restricted and requires identity verification before any appointment or record detail is shared.
Sub-processors
We use a small number of service providers to run MedicalSuite: cloud hosting (Amazon Web Services), file storage (Cloudinary), email delivery (Resend, Brevo, Amazon SES), telephony and SMS (CallHippo), payments (Stripe), and the messaging platforms a clinic chooses to connect (Meta Platforms for Facebook, Instagram and WhatsApp). Each processes data only as needed to provide its part of the service.
Retention
We keep data for as long as the clinic's account is active and the clinic instructs us to. Clinics can delete records at any time. On account closure, data is deleted or returned within 90 days, except where law requires longer retention.
Government and law enforcement requests
We do not give anyone access to personal data because they asked. Every request from a public authority — police, regulator, court or government agency, in any country — is handled the same way:
- We check that it is lawful. Each request is reviewed before we respond: that it comes from an authority with jurisdiction, that it is served through valid legal process, and that it is specific about what is sought. Requests that are invalid, overbroad or improperly served are rejected, and we challenge them where we have grounds to.
- We tell the clinic. MedicalSuite is a processor, and the data belongs to the clinic. Unless we are legally barred from doing so, we notify the clinic before responding, so they can object.
- We disclose the minimum. Where we must respond, we disclose only the narrowest set of data that answers the request. We do not hand over whole records or whole accounts when a single field will do.
- We write it down. Every request, our legal reasoning, who was involved and exactly what was disclosed is recorded and retained.
We have no arrangement with any government for bulk or direct access to data, and we do not build one.
Security
Data is encrypted in transit. Credentials and access tokens are encrypted at rest. Access is restricted by role, and actions in the system are logged. Each clinic's records are stored in a separate database.
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its processing, or receive a copy in portable form.
To exercise any of these, contact the clinic, or email us and we will pass it on. For deletion specifically, see Data deletion instructions.
Contact
Changes
We will update this page when our practices change, and revise the date at the top.