Data Processing Agreement
Version 1.2 · 6 September 2026. This Agreement forms part of the subscription agreement between AesthetiClinic and the Customer (the clinic) and governs the processing of personal data under UK GDPR. Draft pending final legal review. The previous version is archived at version 1.1.
What changed in version 1.2 (6 September 2026)
The security measures are described accurately. Version 1.0 of this Agreement said your data was encrypted at rest. That was not true. Our servers hold data on ordinary disks; what protects it is access control, tenant isolation and encrypted backups, not disk encryption. Version 1.1 removed the claim on 24 August 2026, and this version states the measures positively: encryption of all data in transit, private access-controlled storage, and encrypted off-site backups, alongside encryption of the integration credentials you give us, database-enforced role-based access, row-level tenant isolation and audit logging. Nothing about how your data is held has changed. The description of it is now true.
The sub-processor annex is complete. Six services that were already in use are now named: Google Maps Places (address autocomplete when you set up your clinic address), Google Calendar and Microsoft 365 calendar, Xero, Mailchimp, and Heidi Health. The calendar, accounting, marketing and scribe connectors carry data only if you switch them on, and the last two run on your own account with the provider, which makes that provider your processor rather than ours (section 8). Anthropic's entry now also names the "Tidy note" clean-up of a treatment-record narrative, which its purpose line had missed. Listing these is a disclosure of what already happens, not a new use of your data.
Nothing else in the Agreement has changed, and there is nothing for you to accept. Under section 6 you may object to a sub-processor on reasonable data-protection grounds: email hello@aestheticlinic.io. The text you accepted before this version stays readable at version 1.1.
1. Roles and scope
For the personal data processed through the AesthetiClinic application, the Customer (the clinic) is the controller and AesthetiClinic is the processor. AesthetiClinic processes personal data only on the Customer's documented instructions, which include using the application in the ordinary way and the terms of this Agreement, unless required to do otherwise by law (in which case AesthetiClinic will inform the Customer first, unless the law prohibits it).
2. Subject-matter, duration, nature and purpose
The subject-matter is the provision of clinic-management software. The duration is the term of the subscription plus any period required for return or deletion. The nature and purpose is the hosting, storage, organisation and transmission of clinic and patient data so the Customer can run bookings, clinical records, consent, payments, messaging and reporting.
3. Types of personal data and categories of data subject
Data subjects: the Customer's patients, prospective patients and staff. Personal data includes contact and demographic details, appointment and payment records, marketing preferences, and staff account data. It includes special-category data: health and medical information (treatment records, medical histories, prescriptions, complications) and clinical photographs. The Customer is responsible for establishing a lawful basis and, for special-category data, an Article 9 condition for its own processing.
4. AesthetiClinic's obligations as processor
- Instructions. Process personal data only on the Customer's documented instructions.
- Confidentiality. Ensure personnel authorised to process the data are under a duty of confidentiality.
- Security (Article 32). Implement appropriate technical and organisational measures, including encryption of all data in transit (TLS), private access-controlled storage, and encrypted off-site backups, together with application-layer encryption of stored third-party integration credentials, role-based access control enforced at the database, tenant isolation between clinics enforced by row-level security, and audit logging. Clinical photographs and signed documents are held in private storage, reachable only through short-lived signed links and never on a public URL. Data held on our EU servers is protected by access control rather than by full-disk encryption at rest.
- Sub-processors. Engage sub-processors only under the terms in section 6.
- Data-subject rights. Assist the Customer, by appropriate technical and organisational measures, to respond to requests to exercise data-subject rights (access, rectification, erasure, portability, objection). The application provides a one-click full export, and a patient-erasure function that deletes the patient's record outright, or where a signed clinical record must be retained under professional or statutory obligations, removes the identifying details from the retained record. Some technical records kept for security and audit purposes, and any free text a practitioner wrote inside a retained signed record, are not automatically scrubbed; we will remove those on request.
- Assistance. Assist the Customer with data-protection impact assessments, prior consultation, and security obligations, taking into account the information available to AesthetiClinic.
- Breach notification. Notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal-data breach affecting the Customer's data, with the information the Customer needs to meet its own reporting duties.
- Return or deletion. At the Customer's choice, return or delete all personal data at the end of the provision of services, and delete existing copies unless retention is required by law.
- Audit. Make available the information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, by the Customer or an auditor it mandates, on reasonable notice.
5. International transfers
Personal data is hosted within the EU. Where a sub-processor processes data outside the UK or EEA (see the Annex), such transfers are made under an appropriate safeguard, in particular the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an adequacy decision where one applies.
6. Sub-processors
The Customer gives general authorisation for AesthetiClinic to engage the sub-processors listed in the Annex. AesthetiClinic imposes data-protection obligations on each sub-processor that are no less protective than those in this Agreement and remains liable to the Customer for their performance. AesthetiClinic will give the Customer reasonable prior notice of the addition or replacement of a sub-processor, and the Customer may object on reasonable data-protection grounds.
7. Public API, API keys and webhooks
AesthetiClinic offers a scoped, key-authenticated REST API and webhooks so that your clinic can connect its own EPOS, accounting, marketing and operations tools. Each API key is created by you, limited to the data scopes you choose, and can be rolled or revoked by you at any time. All API requests are logged.
When you create an API key or configure a webhook and give it to another service, that service acts on your instructions and becomes your own data processor (a sub-processor of your clinic), not a sub-processor of AesthetiClinic. AesthetiClinic provides and secures the API mechanism; it does not control, and is not responsible for, how the recipient service stores or uses the data you send it.
You are responsible for putting an appropriate data-processing agreement in place with every service you connect in this way, for choosing the narrowest scopes that service needs, and for revoking keys you no longer use. Keys you mint are not counted among the AesthetiClinic sub-processors listed in the Annex.
8. Built-in connectors you enable (e.g. AI scribes)
AesthetiClinic offers optional connectors to third-party tools that you choose to enable, such as an AI medical scribe, your accounting system, your marketing platform or your work calendar. You connect each one yourself, either by supplying your own credentials for that tool or by authorising the connection through our integration, and data then flows to it on your instructions. Where the connection is authorised through our integration, the technical connection is ours; the account at the far end, and the relationship with that provider, are yours.
That tool is your own data processor (a sub-processor of your clinic), not a sub-processor of AesthetiClinic. You must hold your own data-processing agreement with the provider. For connectors that handle health data, you confirm in-app that your clinic is the controller, that your lawful basis includes UK GDPR Article 9(2)(h) and DPA 2018 Schedule 1, and you may disconnect at any time to stop further data flow.
AesthetiClinic provides and secures the connection and keeps your credentials encrypted; it does not control, and is not responsible for, how the connected provider stores or uses the data you send it.
9. Liability and law
This Agreement is governed by the law of Northern Ireland. Liability under this Agreement is subject to the limitations set out in the subscription agreement. Nothing in this Agreement limits liability that cannot be limited by law.
Annex: Sub-processors
The current sub-processors engaged in providing the application. This list is kept up to date; the Customer is notified before a new sub-processor is added.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting and infrastructure for the application and its database | Germany / EU |
| Supabase (self-hosted) | Database, authentication and file storage, running on our EU Hetzner infrastructure | Germany / EU |
| Cloudflare | DNS, TLS termination and content delivery for the application and website; processes traffic in transit | United States, under Standard Contractual Clauses |
| Google Cloud Storage | Encrypted off-site storage of database and file backups | United States, under Standard Contractual Clauses |
| Stripe Payments Europe | Payment processing for deposits and balances (on the clinic's own connected account) | Ireland / EU, with onward transfers under SCCs |
| Resend | Transactional and patient email delivery | United States, under Standard Contractual Clauses |
| Twilio | SMS reminders and messaging (when the clinic enables SMS) | United States, under Standard Contractual Clauses |
| Anthropic | Optional AI assistance: drafting replies on the platform support desk, and the "Tidy note" clean-up of a treatment-record narrative when a clinician chooses to use it; customer data is not used for model training | United States, under Standard Contractual Clauses |
| Google Maps Platform (Places) | Address autocomplete under our own API key, used when clinic staff enter the clinic's own business address during setup | United States and other countries where Google operates, under Standard Contractual Clauses |
| Google Calendar | Optional calendar sync, switched on by the clinic and authorised through our OAuth integration. Sends appointment times, and the treatment name with the patient's first name or initial, depending on the detail level the clinic chooses (a clinic may choose "busy" only) | The clinic's own Google account. United States and other countries where Google operates, under Standard Contractual Clauses |
| Microsoft 365 (Outlook calendar) | Optional calendar sync, switched on by the clinic and authorised through our OAuth integration, with the same detail levels as above | The clinic's own Microsoft 365 tenant; its region is set by the clinic (to confirm per clinic). Microsoft Ireland Operations Limited, with transfers outside the UK and EEA under Standard Contractual Clauses |
| Xero | Optional accounting sync of invoices and payments, switched on by the clinic and authorised through our OAuth integration | Xero (UK) Limited, with processing in Australia, New Zealand and the United States under Standard Contractual Clauses |
| Mailchimp | Optional marketing-audience sync of patient contact details and marketing preferences, switched on by the clinic using the clinic's own Mailchimp API key | Intuit Mailchimp (The Rocket Science Group LLC), United States, under the EU-US Data Privacy Framework and the UK Addendum to the Standard Contractual Clauses |
| Heidi Health | Optional AI medical scribe, switched on by the clinic using the clinic's own Heidi API key. Because the clinic holds that account, Heidi is the clinic's own processor rather than a sub-processor of AesthetiClinic (section 8); it is listed here so the clinic can see every service its data can reach | Heidi Health Ltd, United Kingdom. Heidi states that data for UK customers is stored in the UK and processed in the UK or the EEA |
Questions about this Agreement or a signed counterpart: hello@aestheticlinic.io.