Draft template. Replace the bracketed placeholders in lib/company.js and have a qualified solicitor review these documents before launch. Hide this notice by setting draft: false.

Privacy Policy

Last updated: 8 July 2026

This Privacy Policy explains how Wellspring Scheduling Ltd (“Wellspring”, “we”, “us”) collects and uses personal data, and your rights under the UK GDPR, the EU GDPR and applicable data-protection law. Our registered address is [Registered office address], and we are registered with the ICO under [ICO registration number]. This policy applies to everyone who uses Wellspring, wherever they are based; where your local law (for example, Australia’s Privacy Act 1988) gives you different or additional rights, we honour those alongside the rights described below.

1. Two different roles

It matters in which capacity we handle data:

  • As a controller — for personal data about our own website visitors, prospects and account holders (the practice owners and staff who sign up).
  • As a processor — for the client/patient records, appointments, notes and payments that a practice enters into Wellspring. There, the practice is the controller and we process that data on their instructions. See our Data Processing Agreement.

This policy focuses on the data for which we are the controller. If you are a patient of a practice that uses Wellspring, please contact that practice about your data.

2. Data we collect

  • Account data — name, business name, email, phone, password (hashed), and your role.
  • Billing data — subscription plan and payment status. Card details are handled by our payment providers, not stored by us.
  • Usage data — log data, device/browser information and how you use the app, to keep it secure and improve it.
  • Support requests — when you use the in-app Help button, we store what you write, plus the page you were on, your role and your browser, so we can answer you. We ask you not to include client/patient details in a support request.
  • Cookies & similar — see our Cookie Policy. Advertising/analytics cookies load only with your consent.

Practices may enter special category data (health information) about their own clients. We process that only as a processor, under the practice’s instructions and appropriate safeguards.

3. How we use data and our legal bases

  • To provide the service and your account — performance of a contract.
  • To take payment and manage subscriptions — performance of a contract.
  • To secure, maintain and improve the service and prevent fraud — our legitimate interests.
  • To send service messages (and, with consent or on a soft-opt-in basis, marketing) — consent or legitimate interests.
  • To meet legal obligations such as tax and accounting — legal obligation.

4. Sharing & sub-processors

We do not sell personal data. We share it only with service providers that help us run Wellspring, under contract:

  • NeonDatabase hosting (EU region).
  • VercelApplication hosting.
  • StripePayments & subscriptions.
  • PayPal / SquarePayment processing (if enabled).
  • Meta PlatformsAdvertising pixel (only with cookie consent).
  • Resend (AWS, EU region)Email delivery — confirmations, reminders, campaigns.
  • TwilioSMS delivery — reminders and campaigns.
  • XeroAccounting sync (if connected).
  • AirtableHelpdesk ticket metadata (internal support triage).

We may also disclose data where required by law, or to protect our rights, users or the public.

5. International transfers

Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses. We aim to host primary data within the EU/EEA. If you are an account holder based outside the UK/EEA (for example, in Australia), using Wellspring means your account data is sent to and stored in the UK/EU — we apply the same safeguards described in this policy to that data.

6. Retention

We keep account and billing data for as long as your account is active and then only as long as needed for legal, accounting or dispute-resolution purposes. Client data we hold as a processor is retained and deleted per the practice’s instructions and our DPA.

7. Security

We use encryption in transit, access controls, isolated per-practice data, secure authentication and audit logging. No system is perfectly secure, but we take reasonable and appropriate measures to protect your data.

8. Your rights

Subject to law, you can request to:

  • access a copy of your data;
  • correct inaccurate data;
  • erase data (“right to be forgotten”);
  • restrict or object to processing;
  • port your data to another provider; and
  • withdraw consent at any time.

To exercise a right, email privacy@wellspring.example.

9. Complaints

If you have concerns we haven’t resolved, you may complain to the UK Information Commissioner's Office (ICO) or your local data-protection authority — for example, the Office of the Australian Information Commissioner (OAIC) if you are based in Australia.

10. Changes

We may update this policy; material changes will be notified in-app or by email. The date above shows the latest revision.

Questions about this page? Contact us at privacy@wellspring.example.