Skip to content

Security and data protection

Built for clinical data, from the first line of code.

You are trusting us with medical histories, consent records and clinical photographs. This page sets out, plainly, how that data is hosted, isolated and protected. We would rather under-claim than over-claim: everything here is something we actually do.

  • EU-hosted. Your patient data stays in the EU.
  • Isolated per clinic. Row-level security at the database, deny by default.
  • Yours to take. One-click full export, any time, no fee.

UK and EU data hosting

The application and its database run on EU infrastructure (Hetzner, in Germany). Your patient data stays in the EU. Where a sub-processor sits outside the EEA, the transfer is covered by the UK International Data Transfer Addendum to the Standard Contractual Clauses.

Encrypted connections and private clinical storage

All traffic runs over TLS. Clinical photos and signed consent PDFs are held in private storage, reachable only through short-lived signed links and never on a public URL, and access to every record is controlled at the database.

Per-clinic isolation, enforced at the database

Every record is fenced to your clinic by row-level security applied in the database itself and denied by default, so the boundary holds even if a query is wrong, not just hidden in the interface. Access inside your clinic is role-based: owners, prescribers, practitioners and reception each see only what their role allows.

A full audit trail on every record

Who did what, and when, is recorded across the platform. Signed consent forms are timestamped and locked to the exact version the patient signed, with a full history of what each patient agreed to.

A signed DPA with every clinic

You are the data controller and AesthetiClinic is your processor. The UK GDPR Article 28 Data Processing Agreement, including the full list of sub-processors, is recorded against your account when you onboard.

Read the DPA

Your data is portable, and erasable

A one-click full export gives you everything, any time, at no cost, and GDPR-ready erasure removes a patient's data on request. Portability is a built-in right here, not a paid add-on or an exit tax.

The switch guarantee

Insurer-verified consent templates

The built-in consent and medical-history library was reviewed with an insurer, so the forms your patients sign are ones that stand up where it matters, rather than something we drafted alone.

Who else touches your data

We keep the list of sub-processors short and current, and we notify you before adding a new one. Each is bound by data-protection terms no less protective than our own. The full list, with the purpose and location of each, lives on the DPA.

  • Hetzner (EU hosting)
  • Our own database, authentication and file-storage layer, on our EU infrastructure
  • Stripe (payments, on your own connected account)
  • Amazon SES and Resend (transactional and patient email)
  • Twilio (SMS, when you enable it)

What we don't claim

We will not put a badge on this page we have not earned. As we complete formal certifications, they will appear here, with dates, not before. If a security question is not answered above, ask us directly and we will give you a straight answer.

Security questions

Where is my patient data stored?

In the EU. The application and its database run on Hetzner infrastructure in Germany. Your data does not leave the EU; where a sub-processor operates outside the EEA, the transfer is covered by the UK International Data Transfer Addendum to the Standard Contractual Clauses.

How is one clinic's data kept separate from another's?

By row-level security enforced in the database itself, denied by default. Every clinic's records are fenced off at the data layer, not merely hidden in the interface, so the boundary holds even if a query is wrong. Inside your clinic, access is role-based by staff role.

Do you sign a Data Processing Agreement?

Yes. You are the controller and we are your processor under a UK GDPR Article 28 Data Processing Agreement, which is recorded against your account at onboarding and lists every sub-processor. You can read it on the DPA page.

Can I get all of my data out if I leave?

Yes, in one click, at any time, at no cost: a full structured export including your files. There is no exit fee. Data portability is written into your subscription contract.

Trust is built on how the software behaves.

14-day free trial. One-click export if you ever leave.