Privacy Policy

MedFlow AI Limited · Last updated 6 August 2026

MedFlow AI Limited ("MedFlow", "we", "us"), a company registered in England and Wales (company number 17250952), provides an AI receptionist service that helps clinics respond to patient enquiries, manage bookings, and collect deposits ("the Service"). This policy explains how we handle personal data. We act as a data processor for patient data handled on behalf of clinics using the Service, and as a data controller for clinic account data and for visitors to our website.

1. Data we process

Patient data (on behalf of clinics). When a patient messages a clinic on WhatsApp or Instagram, we process the message content, the sender's phone number or social media handle and name, booking details (procedure, date, time), and payment status. The clinic is the data controller for this data; we process it solely on the clinic's instructions to operate the Service.

Clinic account data. Names, email addresses, and login credentials of clinic staff; clinic business details, procedures, and pricing; and configuration settings.

Website data. Basic technical information (IP address, browser type) when you visit medflowai.io.

2. How we use data

3. Google user data

Where a clinic connects its Google Calendar, we access calendar free/busy information and create, update, and delete calendar events solely to check availability and manage that clinic's bookings. We store OAuth tokens securely and do not use Google user data for any other purpose.

MedFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train generalised artificial intelligence or machine learning models, and we do not transfer it to third parties except as necessary to provide the Service, comply with law, or as part of a merger or acquisition with prior notice.

4. Third parties we rely on

We use a small number of service providers to run the Service: cloud hosting and databases (Vercel, Supabase), AI model providers (Anthropic) to generate responses, Meta Platforms for WhatsApp and Instagram messaging, Google for calendar integration, and Stripe for payment processing. Payments are processed through the clinic's own Stripe account; MedFlow does not store card details. Each provider processes data only as needed to deliver its function.

5. Legal bases and roles

For patient data we act on the clinic's documented instructions under a data processing agreement. Clinics are responsible for ensuring they have a lawful basis to use the Service with their patients. For clinic account and website data, we rely on performance of a contract and our legitimate interests in operating and securing the Service.

6. Retention

Patient conversation and booking data is retained for as long as the clinic uses the Service and is deleted or returned on the clinic's instruction or on termination of the clinic's contract. Account data is retained for the life of the account plus any period required by law.

7. Security

Data is encrypted in transit, access is restricted by role-based authentication, and messaging webhooks are cryptographically verified. We review our security measures regularly.

8. International transfers

Some providers process data outside the UK. Where they do, transfers are protected by appropriate safeguards such as the UK International Data Transfer Addendum or adequacy regulations.

9. Your rights

Under UK GDPR you may have rights to access, correct, delete, or restrict the use of your personal data, and to object or request portability. Patients should direct requests to their clinic (the controller); we assist clinics in fulfilling them. You may also complain to the Information Commissioner's Office (ico.org.uk).

10. Contact

MedFlow AI Limited, registered in England and Wales, company number 17250952.
Email: support@medflowai.io

11. Changes

We will post any changes to this policy on this page and update the date above.