Legal
Privacy Policy
This Privacy Policy describes how ActiveClinic processes information when people use the public website, clinic registration, clinic websites, and authenticated clinic tools.
Operational draft pending professional legal review. Unresolved operator details are listed for confirmation and are not stated as facts on this page.
1. Information Collected
Depending on how the service is used, ActiveClinic may process:
- Clinic registration details such as clinic name, contact name, email, phone, location, and optional notes.
- Administrator account details used to sign in.
- Staff, role, and facility information entered by the clinic.
- Patient and clinical information entered by authorized clinic users in the authenticated application.
- Public website content a clinic chooses to publish.
- Technical data such as IP address, browser and device information, timestamps, request identifiers, and security logs.
ActiveClinic does not require extra personal information solely to record Terms acceptance beyond the registration association, Terms version, and acceptance time.
2. Account and Clinic Registration Data
When you register a clinic, we store the details you submit so we can create the organisation and administrator account, prevent duplicate registrations, communicate about the account, and keep an audit of Terms of Service acceptance (version and timestamp) linked to that registration.
Passwords are stored as one-way hashes, not in recoverable form.
3. Patient and Clinical Data Roles
Clinics decide which patient and clinical information to enter and which staff may access it. Clinical records are not published on public clinic websites.
ActiveClinic provides the software used to store and process that information for the clinic. Formal legal roles (for example controller or processor) depend on jurisdiction and contract and are subject to legal review. This policy does not claim ISO, HIPAA, or other certifications that are not independently confirmed.
4. Purposes of Processing
Information may be used to operate the platform; create and administer clinic organisations; authenticate users; provide unpublished and published clinic websites; support booking requests where enabled; protect accounts; prevent fraud and abuse; diagnose errors; maintain audit trails; send service communications; and comply with legal obligations.
ActiveClinic does not use public marketing pages for targeted third-party advertising.
5. Service Providers
Hosting, databases, email delivery, storage, security, and similar infrastructure providers may process information on behalf of the platform. Vendor names are not listed on this page unless confirmed for publication.
If a clinic enables a third-party integration, that provider’s privacy terms apply to the integrated function.
6. Security
Access to authenticated clinic tools requires sign-in. Role-based permissions, CSRF protection on forms, hashed passwords, and transport encryption (HTTPS on public hosts) are used to protect the service.
No method of transmission or storage is completely secure. Clinics should use strong unique passwords and limit staff access.
7. Retention
Registration, account, and operational records are retained while the clinic account is active and for a further period needed for security, dispute, or legal obligations. Specific retention schedules by record type are pending owner confirmation and are not invented here.
Public website content remains published until the clinic unpublishes it or the account is closed.
8. Data Subject Rights
Depending on applicable law, individuals may have rights to access, correct, delete, or restrict certain information, or to object to certain processing. Clinic-managed patient records should usually be requested from the clinic first.
Requests about platform account data may use the contact routes below. A named data protection officer and supervisory authority are not listed pending confirmation.
9. International Processing and Transfers
Information may be hosted or processed in countries different from the user’s country, depending on infrastructure used to operate the service.
Specific data-centre locations and transfer mechanisms are not listed on this page unless confirmed for publication.
10. Cookies and Session Information
ActiveClinic uses essential cookies and related mechanisms required for security and signed-in sessions. Cookie names follow the deployment profile and typically include a session cookie (for example activeclinic_org_sid) and a CSRF cookie (for example activeclinic_org_csrf).
These cookies are necessary for core functionality and are not used for advertising. Public ActiveClinic pages do not load third-party advertising analytics trackers. Fonts may be loaded from Google Fonts to display typography.
11. Contact
For clinic onboarding questions, use Register your clinic. To find a published clinic, use the clinic directory. Authorized staff can sign in. For questions about information held by a specific clinic, contact that clinic’s administrators.
12. Policy Changes
This Privacy Policy may be updated. The version and effective date appear at the top of this page. The current Privacy Policy version is 2026-08-19.
13. Effective Date and Version
Effective date: 19 August 2026. Document version: 2026-08-19.
Operational draft pending professional legal review. Unresolved operator details are listed for confirmation and are not stated as facts on this page.