Privacy Policy
Last updated: 5 August 2026
This policy explains what we do with personal data. It covers two different things, and the difference matters: the data we hold about you, and the patient data a clinic holds using our software. We are responsible for the first. The clinic is responsible for the second, and we act only on its instructions.
1.Who we are
Clovaar Ltd is a company registered in England and Wales under company number 17372298. We build and operate Clovaar, clinic management software for aesthetic and medical aesthetic practices in the United Kingdom.
This policy applies to our website at clovaar.com and to the Clovaar platform. You can reach us about anything in this policy at [email protected].
2.The two roles we play, and why it matters
Data protection law distinguishes between the organisation that decides why personal data is used, called the controller, and the organisation that handles it on the controller's behalf, called the processor. We are both, for different data, and this policy would be misleading if it did not say so plainly.
| Whose data | Our role | What that means |
|---|---|---|
| Visitors to our website, people who enquire about Clovaar, and the staff of clinics who use the platform | Controller | We decide what we collect and why. This policy is our notice to you, and the rights in section 10 are exercised against us. |
| Patients of a clinic that uses Clovaar | Processor | The clinic decides what is recorded and why. We store and process it strictly on the clinic's written instructions and never for our own purposes. The clinic's own privacy notice governs it, not this one. |
If you are a patient
If you have received an appointment reminder, a consent form or a portal link that came from Clovaar, the clinic that treats you is responsible for your records. Please contact that clinic to see, correct or delete your data. If you contact us instead, we will pass your request on and tell you we have done so, but we are not permitted to act on your records without the clinic's instruction.
The terms on which we handle patient data for a clinic are set out in our Data Processing Agreement, which forms part of every clinic's contract with us.
3.What we collect about you
What we hold depends on how you deal with us.
| If you are | We hold |
|---|---|
| A visitor to clovaar.com | Your IP address, the pages you viewed, the approximate region you connected from, and basic device and browser information. This is connection and usage data, collected so the site works and stays available. |
| Someone who enquires or asks for early access | Your name, email address, clinic name, phone number if you give one, and whatever you write in your message. |
| A member of staff at a clinic that uses Clovaar | Your name, work email address, your role and permissions, your professional qualifications where the clinic records them, your login credentials in hashed form, two-factor authentication state, trusted device records, and a log of security-relevant actions you take in the platform. |
| The person who signs a clinic up | The above, plus billing contact details, the clinic's billing address, subscription and payment history, and any correspondence about the account. |
We do not buy contact lists, and we do not collect special category data about clinic staff. Your password is stored only as a cryptographic hash, so we cannot read it and cannot tell you what it is.
4.Why we use it, and our lawful basis
We must have a lawful basis for every use of personal data. Ours are set out below.
| What we do | Lawful basis |
|---|---|
| Create and run your account, provide the platform, and give you support | Performance of our contract with your clinic, or steps taken at your request before entering into it |
| Authenticate you, run two-factor authentication, and keep an audit log of security-relevant actions | Legitimate interests: protecting an account that holds patients' medical records. Also our obligation to keep personal data secure. |
| Take subscription payments, chase unpaid invoices, and keep accounting records | Performance of our contract, our legal obligation to keep accounting records, and our legitimate interest in recovering money owed |
| Send service messages such as security alerts, billing notices and material changes to the platform or these terms | Performance of our contract. These are not marketing and cannot be switched off while you hold an account. |
| Reply to an enquiry and follow it up | Legitimate interests: responding to someone who asked to hear from us |
| Send marketing about Clovaar to a business contact | Legitimate interests, with an unsubscribe link in every message, or your consent where the law requires it |
| Diagnose faults, monitor availability and improve the platform | Legitimate interests: keeping a system that clinics depend on working and getting better |
| Detect and prevent fraud and misuse | Legitimate interests, and compliance with our legal obligations |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time using section 10. Where we rely on consent, you can withdraw it at any time without affecting anything we did before you withdrew it.
5.Artificial intelligence, and what is sent where
Some Clovaar features use a large language model supplied by Anthropic. We set this out in its own section because a general statement about "service providers" would not give you enough to judge it, and because it is the part of the platform most people want to ask about.
The features that use it are: drafting a consultation note from a recorded consultation, summarising a clinic's own dashboard figures, reading a supplier document during stock import, and interpreting information a clinic supplies when setting up. Each one produces a draft for a human to check, never a final record and never a decision.
- The recording itself is transcribed in the United Kingdom, on our own servers. Dictated audio is turned into text by software we run ourselves in the same London region as the rest of the platform. There is no transcription supplier and the audio is not sent abroad. It is held only for as long as it takes to produce the text: it is never written to disk, never stored and never logged. Only the transcript, with identifiers already removed, goes any further.
- Direct identifiers are removed before a consultation transcript leaves our systems. The patient's name, date of birth, email address, telephone number, postcode and address are replaced with placeholders inside the platform. The real values are re-inserted locally after the draft comes back, so the AI supplier never receives them.
- If that removal cannot run, nothing is sent. The feature fails and reports that it failed, rather than falling back to sending the raw transcript. This is deliberate and it is tested.
- No automated decision is made about anyone. Nothing in Clovaar produces a legal or similarly significant effect by automated means. A clinician reviews and is responsible for every clinical record.
- Your data is not used to train anyone's model. We do not permit our AI supplier to train on data submitted through Clovaar.
- A clinic can turn the AI features off. Where they are off, nothing is sent to the AI supplier at all.
Where this data goes
Anthropic processes this data in the United States. That is an international transfer, and section 8 explains the safeguard we rely on for it. If a clinic would rather no data left the United Kingdom, it should keep the AI features disabled.
7.Where data is stored
The platform and its database run in the United Kingdom. Clinical records, documents and images are stored in our hosting provider's London region and are not routinely moved outside it.
The exceptions are the suppliers in the table above that operate outside the United Kingdom. Where personal data goes to a country without a UK adequacy decision, we rely on the International Data Transfer Addendum to the European Commission's standard contractual clauses, or on the UK International Data Transfer Agreement, together with an assessment of the risk in the destination country. You can ask us for details of the safeguard used for any particular supplier.
8.How we protect it
Security measures are only worth stating if they are specific. Ours include:
- All traffic to and from the platform is encrypted in transit using TLS.
- The database is encrypted at rest, and clinical free text and identifying fields are separately encrypted at the application layer so they are unreadable in a database dump.
- Each clinic's data is isolated at the database level, not only in application code, so a query cannot reach another clinic's records even if the application is at fault.
- Access inside a clinic is limited by role, so staff see what their role requires and no more.
- Two-factor authentication is required for password sign-in.
- Security-relevant actions are written to an audit log, and signed consent records are held in a form that cannot be silently altered after the fact.
- Backups are taken daily and held for 30 days.
- Access by our own staff is restricted, logged, and used only where it is needed to run or support the service.
No system is perfectly secure, and we will not claim otherwise. If a personal data breach affects you and is likely to result in a high risk to your rights, we will tell you without undue delay, and we will notify the Information Commissioner's Office where the law requires it. Where the breach concerns patient data, we notify the clinic so it can meet its own obligations, on the timescale set out in the Data Processing Agreement.
9.How long we keep it
| Data | How long |
|---|---|
| Enquiry and early-access records | Two years from your last contact with us, unless you become a customer |
| Clinic account and user records | For as long as the clinic holds an account, then 12 months, so an account can be restored after an accidental closure |
| Billing, invoices and accounting records | Six years from the end of the accounting period, because tax law requires it |
| Security and audit logs | Up to two years, because investigating a security incident often means looking further back than the incident itself |
| Website connection logs | Up to 12 months |
| Marketing preferences and unsubscribe records | Kept indefinitely, because the only way to honour an opt-out permanently is to remember it |
Patient records are different, and are not ours to time-limit
How long a patient record is kept is decided by the clinic, not by us. There is no single statutory retention period for a private UK aesthetics clinic, so a clinic has to justify the period it chooses against its professional guidance, its insurer's conditions and the relevant limitation periods. We provide the tools to hold, lock and erase records; we do not set the clock. When a clinic leaves, its patient data is deleted on the timetable in the Data Processing Agreement.
10.Your rights
In relation to the personal data we hold about you as controller, you have the right to:
- Be informed about how we use your data, which is what this policy is for.
- Access a copy of the personal data we hold about you.
- Rectify it if it is inaccurate or incomplete.
- Erase it, where we no longer have a good reason to keep it.
- Restrict how we use it while a dispute about it is resolved.
- Object to processing based on our legitimate interests, and to direct marketing at any time and without giving a reason.
- Portability: receive data you gave us in a structured, commonly used, machine-readable format, where we process it by automated means on the basis of consent or contract.
- Withdraw consent at any time, where consent is what we relied on.
To exercise any of these, email [email protected]. We will respond within one month. If a request is complex or you have made several, we may extend that by up to two further months, and we will tell you within the first month if we do. There is no charge unless a request is manifestly unfounded or excessive.
We may ask you to verify your identity before we act, because releasing data to the wrong person is itself a breach.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
12.Children's data
Our website and platform are for businesses, and we do not knowingly collect data from children through them. A clinic may lawfully treat and therefore record data about a person under 18, and where it does, that record is the clinic's responsibility as controller and the additional protections in the Data Processing Agreement apply.
13.Changes to this policy
We update this policy when what we do changes, or when the law does. The date at the top always reflects the current version. If a change materially affects how we use your personal data, we will tell account holders by email before it takes effect rather than relying on you noticing.
14.Contact us
Email [email protected].
We are not required to appoint a Data Protection Officer and have not appointed one. Responsibility for data protection sits with the company's directors, and the email address above reaches them.
Our registration with the Information Commissioner's Office is in progress under application reference C2000584. We will publish the registration number here as soon as it is issued.