Security and data protection
Built for clinical data, from the first line of code.
You are trusting us with medical histories, consent records and clinical photographs. This page sets out, plainly, how that data is hosted, isolated and protected. We would rather under-claim than over-claim: everything here is something we actually do.
- EU-hosted. Your patient data stays in the EU.
- Isolated per clinic. Row-level security at the database, deny by default.
- Yours to take. One-click full export, any time, no fee.
UK and EU data hosting
The application and its database run on EU infrastructure (Hetzner, in Germany). Your patient data stays in the EU. Where a sub-processor sits outside the EEA, the transfer is covered by the UK International Data Transfer Addendum to the Standard Contractual Clauses.
Encrypted connections and private clinical storage
All traffic runs over TLS. Clinical photos and signed consent PDFs are held in private storage, reachable only through short-lived signed links and never on a public URL, and access to every record is controlled at the database.
Per-clinic isolation, enforced at the database
Every record is fenced to your clinic by row-level security applied in the database itself and denied by default, so the boundary holds even if a query is wrong, not just hidden in the interface. Access inside your clinic is role-based: owners, prescribers, practitioners and reception each see only what their role allows.
A full audit trail on every record
Who did what, and when, is recorded across the platform. Signed consent forms are timestamped and locked to the exact version the patient signed, with a full history of what each patient agreed to.
A signed DPA with every clinic
You are the data controller and AesthetiClinic is your processor. The UK GDPR Article 28 Data Processing Agreement, including the full list of sub-processors, is recorded against your account when you onboard.
Read the DPAYour data is portable, and erasable
A one-click full export gives you everything, any time, at no cost, and GDPR erasure removes a patient's data on request, or strips every identifying detail where a signed clinical record has to be kept. You can close your account yourself, and ask us to delete your data with it. Portability is a built-in right here, not a paid add-on or an exit tax.
The switch guaranteeWho else touches your data
We keep the list of sub-processors short and current, and we notify you before adding a new one. Each is bound by data-protection terms no less protective than our own. The full list, with the purpose and location of each, lives on the DPA.
- Hetzner (EU hosting)
- Our own database, authentication and file-storage layer, on our EU infrastructure
- Cloudflare (DNS, TLS and content delivery)
- Google Cloud Storage (encrypted off-site backups)
- Stripe (payments, on your own connected account)
- Resend (transactional and patient email)
- Twilio (SMS, when you enable it)
- Anthropic (optional AI assistance for our support desk, drafting replies only; your data is never used for training)
What we don't claim
We will not put a badge on this page we have not earned. As we complete formal certifications, they will appear here, with dates, not before. If a security question is not answered above, ask us directly and we will give you a straight answer.
Security questions
Where is my patient data stored?
In the EU. The application and its database run on Hetzner infrastructure in Germany. Your data does not leave the EU; where a sub-processor operates outside the EEA, the transfer is covered by the UK International Data Transfer Addendum to the Standard Contractual Clauses.
How is one clinic's data kept separate from another's?
By row-level security enforced in the database itself, denied by default. Every clinic's records are fenced off at the data layer, not merely hidden in the interface, so the boundary holds even if a query is wrong. Inside your clinic, access is role-based by staff role.
Do you sign a Data Processing Agreement?
Yes. You are the controller and we are your processor under a UK GDPR Article 28 Data Processing Agreement, which is recorded against your account at onboarding and lists every sub-processor. You can read it on the DPA page.
Can I get all of my data out if I leave?
Yes, in one click, at any time, at no cost: a structured export including your files, not just a spreadsheet of text. If your media library is larger than a single download sensibly holds, we supply the remainder on request, still free. There is no exit fee, and data portability is written into your subscription contract.
Trust is built on how the software behaves.
14-day free trial. One-click export if you ever leave.