Back to site
Security & data protection

Your patients' data, handled properly.

Written for the person in your practice who has to sign this off. If anything here is not enough for your compliance process, ask us and we will put it in writing.

Who is responsible for what

Under UK GDPR your practice is the data controller. You decide why patient data is collected and what happens to it. ClinicGrow acts as a data processor, handling that data only to deliver the service you have asked for, and only on your instructions.

That distinction matters, because it means patient records remain yours. We do not sell data, we do not share it with other clinics, and we never use your patient data to train models or to market to your patients on our own behalf.

A written Data Processing Agreement

We provide a DPA covering the Article 28 requirements: scope and purpose, confidentiality obligations, security measures, sub-processor terms, assistance with data subject requests, breach notification, and deletion or return of data when the contract ends. Ask for it at any point, including before you buy. Request the DPA.

What data the system holds

  • Contact details of enquirers and patients: name, phone number, email address.
  • Communication history: SMS, WhatsApp, email and web chat messages between your practice and that person, with timestamps.
  • Enquiry context: which treatment they asked about, where the enquiry came from, and which stage of your follow-up it has reached.
  • Appointment activity: booking, reminder, cancellation and rebooking events.

ClinicGrow is a communication and workflow layer. It is not a clinical records system. Clinical notes, radiographs, medical histories and treatment records stay in your practice management software, and we do not ask for them.

Sub-processors

Delivering the service means using a small number of specialist providers. Each one is bound by its own data processing terms.

ProviderWhat it is used for
HighLevelThe underlying CRM and automation platform that ClinicGrow is built on
TwilioSMS delivery and call tracking
MetaWhatsApp Business messaging, where your practice uses it
CloudflareWebsite hosting, form delivery and network security

We will tell you in advance if we intend to add or change a sub-processor that handles your patient data, so that you have the opportunity to object.

How it is protected

  • Encrypted in transit. All connections to the platform use TLS. The public sites we run for you are HTTPS only, with HSTS enabled.
  • Encrypted at rest on the underlying platform.
  • Named accounts, no sharing. Every member of your team gets their own login. We do not set up shared reception logins, because an audit trail is worthless if four people use one account.
  • Role-based access. Reception, managers and owners can be given different levels of visibility.
  • Separation between clinics. Each practice sits in its own isolated sub-account. One clinic cannot see another clinic's data, including practices in the same group unless you ask us to link them.
  • Full audit trail. Every message, note and stage change is timestamped against the user who made it. This is a core feature of the product, not an add-on.
  • Least privilege for us. ClinicGrow staff access your account only to build, support or fix something, and that access is logged.

Consent, retention and patient rights

Marketing consent

Automated marketing messages go only to people who have a lawful basis to receive them. Every SMS and email carries an unsubscribe route, opt-outs are honoured automatically across every channel, and a patient who replies STOP is suppressed immediately.

Retention

You set the retention period that fits your own policy. We do not impose one, and we do not keep patient data for longer than you tell us to.

Responding to patient requests

If a patient asks you for a copy of their data, asks for it to be corrected, or asks for it to be erased, we help you find and action it inside the statutory one calendar month. Because everything is timestamped and searchable, this is usually a matter of minutes rather than a hunt through inboxes.

If something goes wrong

If we become aware of a personal data breach affecting your practice, we will notify you without undue delay and in any case within 24 hours of confirming it. You will get what we know, what we are doing about it, and what we recommend, so that you can meet your own 72-hour obligation to the ICO.

Leaving

Your data is not held hostage. On a monthly rolling plan with 30 days' notice, you can ask for a full export of your contacts and communication history in a standard format at any time, during the contract or on the way out. Once you confirm you have it, we delete what we hold in line with the DPA.

Being straight with you: ClinicGrow is a small, founder-led business, not an enterprise vendor with a certification wall. We do not currently hold ISO 27001 or Cyber Essentials Plus. What we do have is a clear processor agreement, isolated per-clinic accounts, a complete audit trail, and a named person who answers the phone. If your practice requires a specific certification before you can proceed, tell us early and we will be honest about whether we can meet it.

Need this reviewed by your DPO?

Send us their questions and we will answer them properly, in writing, before you commit to anything.

Email hello@clinicgrow.co.uk

Last updated 5 August 2026. Data protection enquiries: hello@clinicgrow.co.uk.