Privacy Policy

Last updated: 5 August 2026

This policy explains what we do with personal data. It covers two different things, and the difference matters: the data we hold about you, and the patient data a clinic holds using our software. We are responsible for the first. The clinic is responsible for the second, and we act only on its instructions.

1.Who we are

Clovaar Ltd is a company registered in England and Wales under company number 17372298. We build and operate Clovaar, clinic management software for aesthetic and medical aesthetic practices in the United Kingdom.

This policy applies to our website at clovaar.com and to the Clovaar platform. You can reach us about anything in this policy at [email protected].

2.The two roles we play, and why it matters

Data protection law distinguishes between the organisation that decides why personal data is used, called the controller, and the organisation that handles it on the controller's behalf, called the processor. We are both, for different data, and this policy would be misleading if it did not say so plainly.

Whose dataOur roleWhat that means
Visitors to our website, people who enquire about Clovaar, and the staff of clinics who use the platformControllerWe decide what we collect and why. This policy is our notice to you, and the rights in section 10 are exercised against us.
Patients of a clinic that uses ClovaarProcessorThe clinic decides what is recorded and why. We store and process it strictly on the clinic's written instructions and never for our own purposes. The clinic's own privacy notice governs it, not this one.

If you are a patient

If you have received an appointment reminder, a consent form or a portal link that came from Clovaar, the clinic that treats you is responsible for your records. Please contact that clinic to see, correct or delete your data. If you contact us instead, we will pass your request on and tell you we have done so, but we are not permitted to act on your records without the clinic's instruction.

The terms on which we handle patient data for a clinic are set out in our Data Processing Agreement, which forms part of every clinic's contract with us.

3.What we collect about you

What we hold depends on how you deal with us.

If you areWe hold
A visitor to clovaar.comYour IP address, the pages you viewed, the approximate region you connected from, and basic device and browser information. This is connection and usage data, collected so the site works and stays available.
Someone who enquires or asks for early accessYour name, email address, clinic name, phone number if you give one, and whatever you write in your message.
A member of staff at a clinic that uses ClovaarYour name, work email address, your role and permissions, your professional qualifications where the clinic records them, your login credentials in hashed form, two-factor authentication state, trusted device records, and a log of security-relevant actions you take in the platform.
The person who signs a clinic upThe above, plus billing contact details, the clinic's billing address, subscription and payment history, and any correspondence about the account.

We do not buy contact lists, and we do not collect special category data about clinic staff. Your password is stored only as a cryptographic hash, so we cannot read it and cannot tell you what it is.

4.Why we use it, and our lawful basis

We must have a lawful basis for every use of personal data. Ours are set out below.

What we doLawful basis
Create and run your account, provide the platform, and give you supportPerformance of our contract with your clinic, or steps taken at your request before entering into it
Authenticate you, run two-factor authentication, and keep an audit log of security-relevant actionsLegitimate interests: protecting an account that holds patients' medical records. Also our obligation to keep personal data secure.
Take subscription payments, chase unpaid invoices, and keep accounting recordsPerformance of our contract, our legal obligation to keep accounting records, and our legitimate interest in recovering money owed
Send service messages such as security alerts, billing notices and material changes to the platform or these termsPerformance of our contract. These are not marketing and cannot be switched off while you hold an account.
Reply to an enquiry and follow it upLegitimate interests: responding to someone who asked to hear from us
Send marketing about Clovaar to a business contactLegitimate interests, with an unsubscribe link in every message, or your consent where the law requires it
Diagnose faults, monitor availability and improve the platformLegitimate interests: keeping a system that clinics depend on working and getting better
Detect and prevent fraud and misuseLegitimate interests, and compliance with our legal obligations

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time using section 10. Where we rely on consent, you can withdraw it at any time without affecting anything we did before you withdrew it.

5.Artificial intelligence, and what is sent where

Some Clovaar features use a large language model supplied by Anthropic. We set this out in its own section because a general statement about "service providers" would not give you enough to judge it, and because it is the part of the platform most people want to ask about.

The features that use it are: drafting a consultation note from a recorded consultation, summarising a clinic's own dashboard figures, reading a supplier document during stock import, and interpreting information a clinic supplies when setting up. Each one produces a draft for a human to check, never a final record and never a decision.

  • The recording itself is transcribed in the United Kingdom, on our own servers. Dictated audio is turned into text by software we run ourselves in the same London region as the rest of the platform. There is no transcription supplier and the audio is not sent abroad. It is held only for as long as it takes to produce the text: it is never written to disk, never stored and never logged. Only the transcript, with identifiers already removed, goes any further.
  • Direct identifiers are removed before a consultation transcript leaves our systems. The patient's name, date of birth, email address, telephone number, postcode and address are replaced with placeholders inside the platform. The real values are re-inserted locally after the draft comes back, so the AI supplier never receives them.
  • If that removal cannot run, nothing is sent. The feature fails and reports that it failed, rather than falling back to sending the raw transcript. This is deliberate and it is tested.
  • No automated decision is made about anyone. Nothing in Clovaar produces a legal or similarly significant effect by automated means. A clinician reviews and is responsible for every clinical record.
  • Your data is not used to train anyone's model. We do not permit our AI supplier to train on data submitted through Clovaar.
  • A clinic can turn the AI features off. Where they are off, nothing is sent to the AI supplier at all.

Where this data goes

Anthropic processes this data in the United States. That is an international transfer, and section 8 explains the safeguard we rely on for it. If a clinic would rather no data left the United Kingdom, it should keep the AI features disabled.

6.Who else sees the data

We do not sell personal data, we do not share it for anyone else's marketing, and we do not run third-party advertising trackers on our site.

We do rely on suppliers to run the platform. Each one acts on our instructions under a written contract that holds it to the same standards we accept, and each is listed here rather than described vaguely.

SupplierWhat we use it forWhere it processes data
DigitalOceanApplication hosting, managed database and file storage. This is where the platform runs, where clinical records are held, and where dictated audio is transcribed.United Kingdom (London region)
AnthropicThe AI features: drafting consultation notes, summarising the dashboard, reading supplier documents during stock import, and interpreting information supplied during onboarding.United States
StripeTaking the clinic subscription payment, and, where a clinic chooses to enable it, processing card payments from that clinic's own patients.United States and European Union
ResendSending email: appointment confirmations and reminders, consent links, receipts and account notices.European Union
The SMS WorksSending text messages, where a clinic has enabled SMS.United Kingdom
NylasOptional. Connects a clinic's own mailbox so replies from patients appear in the platform.European Union
GoogleOptional. Sign in with a Google account, and connecting a Google Workspace mailbox.United States and European Union
FirecrawlOptional. Reads a clinic's public website during setup so its treatment list can be drafted automatically instead of typed.United States
CloudflareServing and protecting our public website at clovaar.com.Global content delivery network

We will also disclose personal data where we are legally required to, for example in response to a court order or a lawful request from a regulator, and to our professional advisers where they need it. If our business or part of it is sold or reorganised, personal data may transfer with it, and the buyer would be bound by this policy until it lawfully notified you of a change.

Clinics are told before we add or replace a supplier that handles patient data, and can object. That commitment is in section 6 of the Data Processing Agreement.

7.Where data is stored

The platform and its database run in the United Kingdom. Clinical records, documents and images are stored in our hosting provider's London region and are not routinely moved outside it.

The exceptions are the suppliers in the table above that operate outside the United Kingdom. Where personal data goes to a country without a UK adequacy decision, we rely on the International Data Transfer Addendum to the European Commission's standard contractual clauses, or on the UK International Data Transfer Agreement, together with an assessment of the risk in the destination country. You can ask us for details of the safeguard used for any particular supplier.

8.How we protect it

Security measures are only worth stating if they are specific. Ours include:

  • All traffic to and from the platform is encrypted in transit using TLS.
  • The database is encrypted at rest, and clinical free text and identifying fields are separately encrypted at the application layer so they are unreadable in a database dump.
  • Each clinic's data is isolated at the database level, not only in application code, so a query cannot reach another clinic's records even if the application is at fault.
  • Access inside a clinic is limited by role, so staff see what their role requires and no more.
  • Two-factor authentication is required for password sign-in.
  • Security-relevant actions are written to an audit log, and signed consent records are held in a form that cannot be silently altered after the fact.
  • Backups are taken daily and held for 30 days.
  • Access by our own staff is restricted, logged, and used only where it is needed to run or support the service.

No system is perfectly secure, and we will not claim otherwise. If a personal data breach affects you and is likely to result in a high risk to your rights, we will tell you without undue delay, and we will notify the Information Commissioner's Office where the law requires it. Where the breach concerns patient data, we notify the clinic so it can meet its own obligations, on the timescale set out in the Data Processing Agreement.

9.How long we keep it

DataHow long
Enquiry and early-access recordsTwo years from your last contact with us, unless you become a customer
Clinic account and user recordsFor as long as the clinic holds an account, then 12 months, so an account can be restored after an accidental closure
Billing, invoices and accounting recordsSix years from the end of the accounting period, because tax law requires it
Security and audit logsUp to two years, because investigating a security incident often means looking further back than the incident itself
Website connection logsUp to 12 months
Marketing preferences and unsubscribe recordsKept indefinitely, because the only way to honour an opt-out permanently is to remember it

Patient records are different, and are not ours to time-limit

How long a patient record is kept is decided by the clinic, not by us. There is no single statutory retention period for a private UK aesthetics clinic, so a clinic has to justify the period it chooses against its professional guidance, its insurer's conditions and the relevant limitation periods. We provide the tools to hold, lock and erase records; we do not set the clock. When a clinic leaves, its patient data is deleted on the timetable in the Data Processing Agreement.

10.Your rights

In relation to the personal data we hold about you as controller, you have the right to:

  • Be informed about how we use your data, which is what this policy is for.
  • Access a copy of the personal data we hold about you.
  • Rectify it if it is inaccurate or incomplete.
  • Erase it, where we no longer have a good reason to keep it.
  • Restrict how we use it while a dispute about it is resolved.
  • Object to processing based on our legitimate interests, and to direct marketing at any time and without giving a reason.
  • Portability: receive data you gave us in a structured, commonly used, machine-readable format, where we process it by automated means on the basis of consent or contract.
  • Withdraw consent at any time, where consent is what we relied on.

To exercise any of these, email [email protected]. We will respond within one month. If a request is complex or you have made several, we may extend that by up to two further months, and we will tell you within the first month if we do. There is no charge unless a request is manifestly unfounded or excessive.

We may ask you to verify your identity before we act, because releasing data to the wrong person is itself a breach.

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

11.Cookies

Our public website uses only what is necessary to serve pages and keep the site available. We do not use advertising cookies and we do not track you across other websites.

The platform itself sets cookies that are strictly necessary to keep you signed in, to protect your session, and to remember a device you have chosen to trust for two-factor authentication. These cannot be switched off without making sign-in impossible, and the law does not require consent for them.

12.Children's data

Our website and platform are for businesses, and we do not knowingly collect data from children through them. A clinic may lawfully treat and therefore record data about a person under 18, and where it does, that record is the clinic's responsibility as controller and the additional protections in the Data Processing Agreement apply.

13.Changes to this policy

We update this policy when what we do changes, or when the law does. The date at the top always reflects the current version. If a change materially affects how we use your personal data, we will tell account holders by email before it takes effect rather than relying on you noticing.

14.Contact us

Email [email protected].

We are not required to appoint a Data Protection Officer and have not appointed one. Responsibility for data protection sits with the company's directors, and the email address above reaches them.

Our registration with the Information Commissioner's Office is in progress under application reference C2000584. We will publish the registration number here as soon as it is issued.