Privacy Policy
Version and effective date: 12 July 2026. This policy explains how we handle personal data. Clinics remain responsible for their own patient-facing privacy notices.
Provider identity and contact
The service is operated by Aryan Rao, sole proprietor trading as Smart Clinic Reception, Mahendragarh, Haryana – 123029, India. The business is not incorporated and is not registered for GST. General contact: connect@smartclinicreception.online. Privacy, legal, support, and security contact: support@smartclinicreception.online.
Controller and processor roles
For a clinic's own account and website data, Smart Clinic Reception AI is the controller. For patient and prospect data that a clinic captures and manages through the platform, the clinic is the controller and Smart Clinic Reception AI acts as the processor, handling data only on the clinic's documented instructions.
What we collect
- Account and clinic workspace details (name, email, clinic settings).
- Lead and prospect intake details submitted by clinics or lead forms (name, phone, email, treatment interest, message).
- Consent evidence (consent text, source, timestamp, and form origin).
- Conversation, email, and SMS delivery records.
- Booking and appointment records.
- Technical and security logs needed to operate the service.
How we use data
To provide lead intake, staff-reviewed follow-up, booking and reminders, reporting, account access, security, support, and service improvement. We do not use the service to provide clinical advice, diagnosis, or treatment decisions.
Checkout acceptance evidence includes the accepted document versions, timestamp, buyer email, clinic name, and hashed network/browser identifiers. Raw payment-card data is handled by Razorpay and is not stored by this website.
Legal bases (UK/EU GDPR)
- Performance of a contract for account and service operation.
- Consent for marketing follow-up to leads, captured and recorded at the point of collection.
- Legitimate interests for security, fraud prevention, and service reliability.
- Where clinics process special category (health) data, the clinic is responsible for its own lawful basis; the platform is designed for intake and scheduling, not clinical records.
Consent and marketing
Public lead forms require a consent checkbox before submission. Marketing follow-up includes an opt-out: email messages carry one-click unsubscribe, and SMS messages support STOP/START keywords. Service messages such as appointment confirmations and reminders are distinguished from marketing messages.
Your rights and how we support them
Clinics can export a lead's data and erase a lead and its related records directly from the platform, supporting access, portability, and erasure requests. To exercise rights for data we control, or for help with a request, contact us using the details below. Email recipients can unsubscribe at any time; SMS recipients can reply STOP.
Sharing and subprocessors
We do not sell personal data. We use vetted service providers for hosting, email, SMS, calendar, payments, and AI drafting under appropriate contracts. The current list is published at Subprocessors.
Data location and international transfers
Application data is stored in Cloudflare D1 (a globally distributed SQLite service) on the account operating this service, and may be replicated within Cloudflare's network. Personal data may also be processed by our subprocessors — Cloudflare (hosting), Resend (email), Twilio (SMS/voice), Google (calendar, optional per clinic), and the configured payment provider — some of which operate outside your country. Where required, these transfers rely on recognized safeguards such as Standard Contractual Clauses or equivalent mechanisms. We do not sell personal data or transfer it outside this processing chain. Specific data-location options can be discussed for production deployments.
Retention
We retain data only as long as needed to provide the service, meet legal obligations, and resolve disputes, or as configured by the clinic. Retention periods are set per data category and enforced by a scheduled retention job:
- Transient security data (one-time codes, OAuth state, expired sessions and links) is purged automatically within minutes to days of expiry.
- Email and SMS provider/diagnostic events are purged on a rolling window (typically 60 and 90 days).
- Lead, message, appointment, and provider-calendar data is retained for the life of the clinic contract and removed on erasure or offboarding.
- Opt-out and suppression evidence is retained indefinitely as compliance proof so an opted-out contact is never re-messaged, even after a lead is erased.
Contract, legal-acceptance, payment, audit, and dispute records may be retained for the applicable limitation, tax, accounting, fraud-prevention, and legal-defense periods even after workspace data is deleted. The full per-category schedule and operational procedure are maintained in our internal data-retention and privacy-operations runbook.
Your rights: export and erasure
Clinics can export a lead's data (including consent and opt-out evidence, provider-calendar metadata, and the lead's audit trail) and erase a lead and its related records directly from the platform. Erasure removes message content and personal data but preserves the minimal opt-out/suppression record required to honor an earlier unsubscribe or STOP. Every export and erasure is logged with who requested and who approved it.
Security
We use encryption in transit, encrypted storage of sensitive tokens, hashed credentials, access controls with clinic isolation, audit logging, and security headers. No system is perfectly secure, but we work to protect data appropriately.
Contact
For privacy questions or data requests, contact support@smartclinicreception.online. See also our DPA and BAA readiness, Subprocessors, and paid-client legal pack.