Legal

Privacy Policy

How GetClinic handles personal data in the clinic portal and the Clinic Portal mobile app. Written for the clinic teams who use it — patients are covered by the marketplace policy.

Effective

This policy explains how GetClinic, Inc., a Delaware corporation, handles personal data in the GetClinic clinic portal at app.getclinic.com and in the GetClinic Clinic Portal mobile app for iOS and Android.

It is written for clinic owners, administrators, doctors and staff who hold a portal account. If you are a patient using GetClinic to find or book treatment, the policy that applies to you is at getclinic.com/privacy.

Who is responsible for your data

Responsibility splits by what is being done with the data, not by who entered it. Two things are worth separating:

  • Your own account data. GetClinic is the data controller. We decide what we collect to run the portal, and this policy governs it.
  • Patient records. Your clinic is the independent controller for clinical evaluation, treatment, and the medical record it has to keep. GetClinic is an independent controller for marketplace matching and enquiry routing, for running and securing the platform, for support and fraud prevention, and for its own legal obligations. GetClinic acts as a processor on your clinic's instructions only for the portal functions your agreement expressly designates as a processor service. We do not use clinical content for unrelated purposes and we do not sell it. The full split is set out in the Data Protection and Data Sharing Addendum between your clinic and GetClinic.

What we collect

  • Account and identity. Name, work email, phone number, job role, and the clinic or organisation you belong to. Sign-in is handled by our identity provider; we hold the resulting session, not your password.
  • Clinic and business data. Clinic profile, doctors, treatment packages, pricing, availability, documents, subscription and billing records.
  • Patient and enquiry data you enter or receive. Patient names and contact details, enquiries, bookings, appointments, messages, and any files or clinical documents you attach. Your clinic and GetClinic each hold this data in the roles set out above.
  • Content you create in the app. Photos and files you choose to attach from your device, and messages you send through the portal.
  • Video consultation media. When you join a consultation, camera and microphone audio and video are transmitted between the participants to carry the call. The media server that carries it runs on GetClinic's own infrastructure in the EU, so no video vendor receives the call, and recording is off by default — the app does not record a consultation's audio or video.
  • Device and technical data. Device model, operating system, app version, language, IP address, crash reports and diagnostic logs.
  • Usage data. Which screens you open and which actions you take in the app, used in aggregate to understand how the product is used.
  • Audit records. What you do in the portal — the action, the record it touched, the fields that changed, and the application, IP address and browser you used — attributed to your account. Being shown a patient's contact details, or downloading a patient's document or attachment, is recorded the same way. Sensitive values such as contact details, patient names and medical notes are replaced in the record by a one-way hash, so it shows that a field changed without holding the value.
  • Push notification token. A device identifier issued by Apple or Google so we can deliver notifications about leads, messages and appointments.

We do not collect your location, your contacts, your calendar, or anything from your device beyond what is listed above. We do not use your data to train machine-learning models, and we do not sell personal data.

Device permissions the app asks for

Every permission is requested at the moment the feature needs it, and the app remains usable without the optional ones:

  • Camera and microphone — video consultations with patients, and screen sharing during a call when you start it.
  • Photos and files — attaching images and documents to clinic content and patient records. We access only the items you pick.
  • Notifications — alerts for new leads, messages, and upcoming appointments.
  • Bluetooth — routing call audio to a headset or speaker. It is not used for location or proximity.
  • Local network (iOS) — establishing a direct, low-latency connection for video calls.

Why we use it

  1. To give you access to your clinic's account and keep it secure.
  2. To deliver the features you use: leads, bookings, messaging, video consultations, documents and analytics.
  3. To take payments and manage your subscription.
  4. To send service communications — notifications, security alerts and changes to the product or this policy.
  5. To keep the platform working and safe: diagnosing crashes, preventing fraud and automated abuse, and enforcing our terms.
  6. To keep an accountable record of what is done on a clinic's account.
  7. To meet legal obligations, including tax, accounting and healthcare record-keeping requirements.

Where the GDPR or Turkey's KVKK applies, we rely on performance of our contract with your clinic, our legitimate interest in running and securing the platform and in measuring how the product is used, your consent for optional device permissions, and compliance with legal obligations.

Who we share it with

We share data with service providers who process it on our behalf, under contract, and only for the purposes above. Some, such as Stripe, are also independent controllers for parts of what they do, and process data under their own notices:

  • Amazon Web Services — hosting and data storage, in the EU (Frankfurt) region.
  • Google Firebase — push notifications, app integrity checks, and product analytics.
  • Google Analytics 4 and Google Tag Manager — usage measurement. Usage events, device and browser data, the pages you open, and identifiers that tie the session to your portal account and to your clinic.
  • Microsoft Clarity — usage measurement and interaction recording, including a replay of what was on screen during your session, and the same identifiers that tie the session to your portal account and to your clinic.
  • Sentry — crash and error diagnostics.
  • Stripe — subscription and payment processing. Card details go directly to Stripe; GetClinic never receives or stores your full card number.
  • LaunchDarkly — feature rollout and configuration.
  • Mailgun (Sinch) — delivery of notification and service emails, through an EU endpoint.
  • Cloudflare — Turnstile bot protection on sign-up and other public forms.
  • OpenAI — translation of live consultation transcript text, on sessions where that feature is turned on. The text is processed in the United States, and everyone in the session is told before it starts.

The list your clinic's agreement refers to is published at getclinic.com/legal/subprocessors. Sign-in, the video consultation media server and the signing of your clinic's contracts run on GetClinic's own infrastructure; no vendor is engaged for them.

We also disclose data where the law requires it, and to a successor entity in the event of a merger or acquisition — in which case this policy continues to apply until you are told otherwise.

Where your data is stored

Platform data is stored in the European Union, in Amazon Web Services' Frankfurt region. Some of the providers above process data outside the EU; where they do, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.

How long we keep it

We keep your account data for as long as your clinic holds an active account, and afterwards only where a law requires it — financial and invoicing records in particular carry statutory retention periods. Diagnostic and application logs are kept for around 90 days on our own systems; crash reports held by our diagnostics provider are kept for that provider's default period, which we have not shortened. Identifiers set by the usage-measurement providers persist for up to 24 months at Google and 12 months at Microsoft; we have not agreed a shorter retention period with either. Patient data held on the GetClinic platform is kept for the periods in the marketplace privacy policy, and longer where a booking or payment record has to be retained. Your clinic's own clinical record is separate, and is kept under the healthcare record-keeping rules that apply to you.

Audit records of what is done through the portal are kept for 13 months in our live system and then for 7 years in a locked archive built so that records cannot be deleted or their retention shortened. Your clinic's administrators can see the actions its own team members took, by name, under Settings > Audit log; that view does not include patient records, or any record of who viewed patient information. Authorised GetClinic staff can read audit records for security, support and compliance; an export requires a stated reason and is itself recorded. A regulator may be given access where the law requires it.

Your rights

Under the GDPR, the KVKK and comparable laws you may ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. You may also withdraw consent for anything you consented to, without affecting what came before.

Write to privacy@getclinic.com and we will respond without undue delay, and generally within one month of receiving your request. Where a request is complex we may need longer, and we will tell you why within that first month. If a request concerns patient data, we answer for the copy GetClinic controls and refer you to the clinic for its own clinical record, which the clinic controls.

If you are not satisfied with our response you can complain to your national data protection authority — the Kişisel Verileri Koruma Kurumu (KVKK) in Turkey, the Information Commissioner's Office in the United Kingdom, or your own supervisory authority in the EU. You can also contact our Article 27 representative, listed under Contact us. Contacting a representative does not affect your right to complain to your own supervisory authority.

Deleting your account

An administrator at your clinic can permanently delete a team member's account from the portal, under Team — this removes the sign-in account and the member's account records. To delete your own account, or your clinic's entire account and its data, email privacy@getclinic.com from your registered address. Records we are legally obliged to keep, such as invoices, are retained for the required period and then deleted.

Deleting an account does not delete the audit record of what that account did. The email address and account identifiers in our live records are replaced with a pseudonym and identifying values in the recorded changes are removed, but the record of each action stays. The archived copy cannot be rewritten, so it is masked the same way each time it is read. Free text someone typed about an action, such as a reason given for a change, is kept as written.

Security

Data is encrypted in transit and at rest. Sign-in runs through a dedicated identity provider, session tokens are held in the operating system's secure storage on your device, and access to production systems is restricted and logged. Access to clinic data inside the product is limited by role, so staff see only what their role allows.

Children

The portal and the mobile app are professional tools for clinic staff. They are not directed at children and we do not knowingly create accounts for anyone under 18.

Changes to this policy

If we make a material change we will update the effective date above and notify account holders in the product or by email before it takes effect.

Contact us

  • Email: privacy@getclinic.com
  • Post: GetClinic, Inc., 74 E Glenwood Ave, Unit #5895, Smyrna, DE 19977, United States
  • EU representative (GDPR Article 27): Prighter EU Rep GmbH, Schellinggasse 3, 1010 Vienna, Austria
  • UK representative (UK GDPR Article 27): Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom